Privacy Policy
Introduction
This privacy policy (the "Policy") explains how Ray Studios Tattoo Removal Ireland Limited collects and processes the personal data of users of www.ray-studios.com/ie (the "Site").
We take the privacy of our users, prospective clients and clients seriously. This Policy is issued in accordance with Regulation (EU) 2016/679 of 27 April 2016 (the "GDPR"), the Irish Data Protection Act 2018, and the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011, S.I. No. 336 of 2011 (the "ePrivacy Regulations").
Please read this Policy carefully before using the Site.
Article 1. Identity of the data controller
The controller of the personal data collected through the Site is:
Ray Studios Tattoo Removal Ireland Limited, a company registered in Ireland
• Company number: 809551
• Registered office: Ground Floor, 71 Lower Baggot Street, Dublin 2, Co. Dublin, D02 P593, Ireland
• Phone: +353 1 263 3170
• Contact email: contact@ray-studios.com
(Referred to below as "Ray studios", "we", "us" or "our".)
Joint controllership. The Site, its analytics and its advertising tools are operated at group level by our French parent company Ray Studios Holdings SAS (901 049 767 R.C.S. Nanterre, 90 rue Brancas, 92310 Sèvres, France). For the processing described in Articles 3.3, 3.4 and 3.6 of this Policy, the two companies act as joint controllers within the meaning of Article 26 GDPR. The essence of the arrangement between them is as follows: Ray Studios Holdings SAS selects and configures the tools and defines the purposes of the analytics and advertising processing; Ray Studios Tattoo Removal Ireland Limited is your point of contact and handles enquiries and requests from individuals in Ireland. Whichever company you contact, you may exercise your rights against either of them.
Data Protection Officer (DPO). The Ray studios group has appointed an external Data Protection Officer, CODPO SAS, who acts for Ray Studios Tattoo Removal Ireland Limited. For any question about this Policy or to exercise your rights, you can contact our DPO at rgpd@ray-studios.com.
Article 2. Personal data we collect
We collect and process different categories of personal data depending on how you interact with the Site.
2.1 Data collected automatically while you browse
When you visit the Site we automatically collect, subject to your consent where required:
• technical information about your device (browser type and version, operating system, screen resolution);
• your IP address (anonymised for analytics purposes);
• your time zone and language preferences;
• the pages you view, how long you stay, traffic sources and your navigation path;
• advertising identifiers and click identifiers passed on by advertising platforms (for example gclid, fbclid, ttclid), used to measure and attribute our campaigns.
2.2 Data collected through the contact form
When you complete our contact form, we collect:
• your first name and surname;
• your email address;
• your phone number;
• the content of your message and any information you choose to include in it.
Please note: we ask you not to send health information (medical history, current treatments, photographs of tattoos on intimate areas, and similar) through the contact form. Information of this kind should be shared only during an in-studio consultation with one of our skin therapists, or through our secure booking tool Pabau, which is covered by a separate privacy notice.
If you do include health information in your message, we process it only to answer you, on the basis of your explicit consent under Article 9(2)(a) GDPR, and we delete it from the enquiry record as soon as your enquiry is closed.
2.3 Data collected through the booking form
When you request an appointment, we collect your first name, surname, email address and phone number. We need this information to take steps at your request before entering into a contract for our services. Without it we cannot process your appointment request or contact you to confirm or arrange it.
Our booking engine and the associated client records are operated by Pabau, a software platform designed for clinic management. Health information as such is covered by a separate privacy notice available directly from the booking form.
Article 3. Purposes, legal bases and retention periods
Under Article 6 GDPR, every processing operation rests on a specific legal basis. The purposes, legal bases and retention periods that apply are set out below.
3.1 Responding to contact form enquiries
• Data concerned: identity, email, phone number, content of the message
• Legal basis: legitimate interests (Article 6(1)(f) GDPR), namely responding to enquiries from prospective clients and clients through our Gorgias helpdesk
• Retention: 3 years from the last contact
3.2 Handling appointment requests
• Data concerned: identity, email, phone number
• Legal basis: steps taken at your request prior to entering into a contract (Article 6(1)(b) GDPR)
• Retention: 3 years from the last contact where no appointment follows. Where the enquiry leads to a treatment, client records are held in Pabau under the retention periods set out in the dedicated privacy notice.
3.3 Site analytics and statistics
• Data concerned: browsing data, analytics cookies (Google Analytics)
• Legal basis: consent (Article 6(1)(a) GDPR and Regulation 5(3) of the ePrivacy Regulations), given through the cookie banner
• Retention: your consent choice is stored for 6 months and then requested again, in line with Data Protection Commission guidance. Individual analytics identifiers expire at the end of their own lifespan, which does not exceed 13 months.
3.4 Digital marketing and targeted advertising (Meta, TikTok, Snapchat)
• Data concerned: advertising identifiers, click identifiers, browsing data, conversion events
• Legal basis: consent (Article 6(1)(a) GDPR and Regulation 5(3) of the ePrivacy Regulations), given through the marketing category of the cookie banner
• Retention: your consent choice is stored for 6 months and then requested again. Retention of data by the advertising platforms themselves (Meta, TikTok, Snapchat) is governed by their own privacy policies, in their capacity as controllers or processors.
3.5 Site security and fraud prevention
• Data concerned: IP address, connection logs
• Legal basis: legitimate interests (Article 6(1)(f) GDPR)
• Retention: 12 months
3.6 Electronic marketing
• Data concerned: email address, phone number, engagement data (opens, clicks)
• Legal basis: consent (Article 6(1)(a) GDPR). Where you are an existing client, we may also contact you about services similar to those you have already received without asking for consent again, on the basis of our legitimate interests (Article 6(1)(f) GDPR) and within the conditions of Regulation 13(11) of the ePrivacy Regulations, which limits this to twelve months from the sale and requires that you were offered the chance to opt out when your details were collected
• Retention: until you withdraw your consent or object. Every message we send includes a free and simple way to opt out, and we act on it immediately.
Article 4. Cookies and tracking technologies
The Site uses cookies and similar technologies (pixels, tags, trackers) to support your browsing experience, measure traffic and personalise advertising content.
4.1 Categories of cookies used
• Strictly necessary cookies: required for the Site to work (session management, security). Under Regulation 5(5) of the ePrivacy Regulations these do not require your consent.
• Analytics cookies: Google Analytics, set to analyse how the Site is used. Consent required.
• Marketing and advertising cookies: Meta Pixel (Facebook and Instagram), TikTok Pixel and Snapchat Pixel, set for advertising retargeting and to measure how our campaigns perform. Consent required.
4.2 Managing your consent
On your first visit, a consent banner lets you accept, reject or configure non-essential cookies by purpose. Rejecting is as easy as accepting, and no non-essential cookie is set before you have made an affirmative choice.
Your choice is stored for 6 months, after which we ask you again, in line with Data Protection Commission guidance. You can change or withdraw your choice at any time through the "Cookie settings" link at the foot of every page.
Rejecting non-essential cookies does not affect your ability to browse the Site, but may limit certain features.
Article 5. Phone calls and messages
When you contact us by phone or by text message, we process:
• your first name, surname and phone number;
• the content of your enquiry and of our exchanges;
• where applicable, a recording of the call.
Phone calls. Calls may be recorded to improve the quality of our service, train our teams and keep track of your enquiry. You are told at the start of each call and can object to the recording, in which case your enquiry is handled without one.
• Legal basis: legitimate interests (Article 6(1)(f) GDPR) in improving the quality of our services and following up on enquiries.
• Retention: call recordings are kept for a maximum of 6 months. Notes and information relating to your enquiry are kept for 3 years from the last contact.
Text messages. Messages are kept so we can follow up on your enquiry.
• Legal basis: legitimate interests (Article 6(1)(f) GDPR), or steps taken prior to entering into a contract where the exchange concerns an appointment request.
• Retention: 3 years from the last contact.
Health information. Please do not share health information (medical history, treatments, the precise location of a tattoo, and similar) during these exchanges. Information of this kind should be shared only during an in-studio consultation with one of our skin therapists, which is covered by a separate privacy notice.
Article 6. Recipients and processors
Your personal data is handled by authorised staff of Ray Studios Tattoo Removal Ireland Limited and, for the group-level processing described in Article 1, of Ray Studios Holdings SAS. It may also be shared with technical suppliers acting as processors within the meaning of Article 28 GDPR, strictly to the extent needed for them to perform their services.
The advertising platforms listed at 6.4, 6.5 and 6.6 are a separate case. For part of the processing carried out through their pixels and conversion APIs, they act as joint controllers with us, and for the rest, including the use of the data for their own purposes, they act as controllers in their own right. Their own privacy policies apply to that processing.
Our main suppliers and partners are:
6.1 Gorgias
• Purpose: helpdesk ticketing and contact form
• Data shared: first name, surname, email address, phone number, message content and exchange history
• Data location: European Union and United States (covered by the EU-US Data Privacy Framework)
6.2 Pabau
• Purpose: booking engine and clinic management software (separate privacy notice)
• Data shared: first name, surname, email address, phone number and appointment data. Any health information is covered by the dedicated privacy notice.
• Data location: United Kingdom (European Commission adequacy decision renewed on 19 December 2025) and European Union
6.3 Google
• Purpose: Site analytics and usage statistics
• Data shared: analytics cookie identifiers, IP address (truncated or anonymised), browsing data (pages viewed, duration, traffic source), device and browser type
• Data location: contracted with Google Ireland Limited, with onward transfers to the United States covered by the EU-US Data Privacy Framework
6.4 Meta Platforms
• Purpose: targeted advertising and retargeting (Facebook and Instagram)
• Data shared: advertising and click identifiers (fbclid), browsing and conversion events, IP address, and, through the Conversions API, hashed contact data (email, phone number) used to match conversions
• Data location: United States (covered by the EU-US Data Privacy Framework)
6.5 TikTok (ByteDance)
• Purpose: targeted advertising and conversion measurement
• Data shared: advertising and click identifiers (ttclid), pixel session identifiers, browsing and conversion events, IP address, and, where applicable through the Events API, hashed contact data
• Data location: Ireland, Singapore and United States (covered by standard contractual clauses)
6.6 Snapchat (Snap Inc.)
• Purpose: targeted advertising and conversion measurement
• Data shared: advertising and click identifiers (sclid), visitor and session identifiers, browsing and conversion events, IP address
• Data location: United States (covered by standard contractual clauses and, where applicable, the EU-US Data Privacy Framework)
6.7 Webflow
• Purpose: hosting platform for the public pages of the Site
• Data shared: technical connection data (IP address, server logs). Webflow hosts the public pages and does not process form data.
• Data location: United States (covered by the EU-US Data Privacy Framework)
6.8 Cloudflare
• Purpose: content delivery network, security, and technical handling of requests sent through the forms (very short-lived temporary caching)
• Data shared: IP address, technical request data, and data passing through the forms (name, email, phone number) held in very short-lived temporary cache
• Data location: European Union
6.9 Supabase
• Purpose: storage and management of form data (contact and appointment requests, attribution data)
• Data shared: first name, surname, email address, phone number, request content, and attribution data (UTM parameters, click identifiers) attached to contact and appointment requests
• Data location: European Union
6.10 OVH
• Purpose: data hosting and related services
• Data shared: all data hosted on the infrastructure, including form data and associated technical data
• Data location: European Union (France)
6.11 Ringover
• Purpose: telephony and call recording
• Data shared: first name, surname, phone number, call content and recordings
• Data location: European Union
6.12 SMS Mode
• Purpose: sending and receiving text messages
• Data shared: phone number and message content
• Data location: European Union (France)
Every processor is engaged under a contract that meets the requirements of Article 28 GDPR. Some of these contracts are entered into at group level by Ray Studios Holdings SAS on behalf of the companies in the group, including Ray Studios Tattoo Removal Ireland Limited.
Your data may also be disclosed to administrative or judicial authorities where the law requires it.
We never sell your personal data.
Article 7. Transfers outside the European Economic Area
Some of our processors are located outside the European Economic Area, in particular in the United States and the United Kingdom. Where that is the case, we make sure the transfer is covered by appropriate safeguards under Articles 44 and following of the GDPR:
• a European Commission adequacy decision, including for the United Kingdom;
• the EU-US Data Privacy Framework for transfers to certified organisations in the United States;
• standard contractual clauses adopted by the European Commission, supplemented where needed by additional security measures.
You can request a copy of the safeguards in place by writing to contact@ray-studios.com.
Article 8. Your rights
Under Articles 15 to 22 GDPR and the Data Protection Act 2018, you have the following rights over your personal data:
• Right of access (Article 15): confirm whether we process your data and obtain a copy of it.
• Right to rectification (Article 16): have inaccurate or incomplete data corrected.
• Right to erasure (Article 17): ask us to delete your data in the circumstances set out in law.
• Right to restriction (Article 18): ask us to suspend processing of your data temporarily.
• Right to data portability (Article 20): receive your data in a structured, commonly used, machine-readable format.
• Right to object (Article 21): object to processing based on legitimate interests, and to direct marketing at any time.
• Right to withdraw your consent at any time, without affecting the lawfulness of processing carried out beforehand. As a visitor to the Site, you can adjust or withdraw your consent directly through the consent banner or the "Cookie settings" link.
8.1 How to exercise your rights
To exercise your rights, email your request to rgpd@ray-studios.com. Where we have reasonable doubts about your identity, we may ask for proof of identity.
We will respond within one month of receiving your request, in line with Article 12 GDPR. That period may be extended by a further two months for complex requests or where we receive several requests, in which case we will let you know.
8.2 Right to complain and to a judicial remedy
You have the right to lodge a complaint with the Data Protection Commission:
Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland. www.dataprotection.ie
The Data Protection Commission is the supervisory authority for Ray Studios Tattoo Removal Ireland Limited. For the processing carried out jointly with our French parent company, whose main establishment is in France, the French supervisory authority (CNIL) may act as lead supervisory authority under the one-stop-shop mechanism in Article 56 GDPR. In that case your complaint is still made to the Data Protection Commission and is handled through cooperation between the two authorities.
You also have the right to an effective judicial remedy, including a data protection action before the Circuit Court or the High Court under section 117 of the Data Protection Act 2018.
Article 9. Data security
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in line with Article 32 GDPR. These include:
• encryption of communications through HTTPS/TLS;
• access controls (authentication, permission management);
• logging of access to sensitive systems;
• training and awareness for our staff on data protection;
• confidentiality agreements with our processors;
• regular backups.
No method of transmitting or storing information over the internet can be guaranteed to be completely secure, so we cannot promise absolute security. Where a personal data breach is likely to result in a high risk to your rights and freedoms, we will inform you without undue delay in line with Article 34 GDPR.
Article 10. Children
The Site is not intended for children under 16. Under section 31 of the Data Protection Act 2018, the digital age of consent in Ireland is 16. We do not knowingly collect personal data relating to children under that age on the basis of consent without the authorisation of a parent or guardian.
Separately, we do not provide treatment to anyone under 18 without the consent of a parent or guardian.
If you are a parent or guardian and believe your child has given us personal data, please contact us at contact@ray-studios.com so we can delete it.
Article 11. Links to third-party sites
The Site may contain links to third-party websites that we do not control. We are not responsible for the privacy practices or the content of those sites. We encourage you to read their privacy policies.
Article 12. Changes to this Policy
We may update this Policy at any time, in particular to reflect changes in law, case law, regulatory guidance or technology. The version that applies is the one in force when you visit the Site, available at all times from the footer.
Where a change is significant, we will tell you by an appropriate means (a notice on the Site, for example) before it takes effect.
Article 13. Contact
For any question about this Policy or about how we process your personal data, you can contact us:
• By email: rgpd@ray-studios.com
• By phone: +353 1 263 3170
• By post: Ray Studios Tattoo Removal Ireland Limited, Ground Floor, 71 Lower Baggot Street, Dublin 2, Co. Dublin, D02 P593, Ireland