Privacy Policy
This policy applies to cultofsamma.com and to all personal data collected by Cult of Samma in connection with applications, bookings, and studio operations. Cult of Samma is operated by Samma Charles Art Studios. This policy was last updated in April 2026.
1. Who We Are
Cult of Samma is a private tattoo and piercing atelier operating from Oxford, UK and Boston, MA. Our contact addresses are oxford@cultofsamma.com (UK) and boston@cultofsamma.com (US). We are the data controller for information collected through this website.
2. What Data We Collect
We collect personal data only when you actively provide it. Through the application form on this site we collect: your full name, email address, location preference, session type preference, artist preference, a description of the work you have in mind, and optionally how you found us.
We do not use cookies, analytics scripts, tracking pixels, or any third-party advertising technology on this website. No data is collected passively from visitors.
3. How We Use Your Data
Application data is used for one purpose only: to assess whether your request is a good fit for the studio and to respond accordingly. We do not use it for marketing, profiling, or any purpose unrelated to your application. If your application is successful, we will retain relevant information to manage your booking and ongoing relationship with the studio. If your application is unsuccessful or you do not proceed, we will delete your submission data within 12 months.
4. Legal Basis for Processing (UK/EU)
For clients in the United Kingdom and European Union, our legal basis for processing application data is legitimate interests — specifically, the legitimate interest of assessing applications to our private studio. For active clients, processing is necessary for the performance of a contract. Where we require your consent for a specific purpose, we will ask for it separately and explicitly.
5. Where Your Data Is Stored
Application form submissions are handled by Netlify Forms, a service provided by Netlify, Inc. Netlify stores form submission data on servers within the United States. Netlify is certified under appropriate data transfer frameworks. You can review Netlify's privacy policy at netlify.com/privacy. We do not use any other third-party data processors for information collected on this website.
6. How Long We Keep Your Data
Application submissions that do not lead to a booking are deleted within 12 months of receipt. Client records — including contact details, health disclosures, and appointment history — are retained for as long as required by applicable law or as necessary for the studio's legitimate operational needs, and no longer. Financial records are retained for 7 years in line with HMRC requirements (UK) and IRS requirements (US).
7. Your Rights (UK Residents)
Under UK data protection law (UK GDPR), you have the right to: access the personal data we hold about you; request correction of inaccurate data; request deletion of your data where there is no lawful reason for us to retain it; object to or restrict our processing of your data; request a copy of your data in a portable format; and lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Your Rights (US Residents — Massachusetts)
Massachusetts residents may request access to or deletion of personal information we hold about them. We do not sell personal data to third parties. To exercise your rights, please contact us at the email addresses above. We will respond within 45 days.
9. Data Security
We take reasonable technical and organisational measures to protect the personal data we hold. Access to application and client data is restricted to the studio's operating team. In the unlikely event of a data breach that poses a risk to your rights or freedoms, we will notify you and any relevant regulatory authority as required by law.
10. Changes to This Policy
We may update this policy from time to time. The current version will always be available at this address. Material changes will be communicated directly to active clients.
11. Contact
For any questions about this policy or to exercise your data rights, please contact us at oxford@cultofsamma.com (UK) or boston@cultofsamma.com (US).