Last updated: 28 August 2026
1. Scope
This policy covers only the Mia Porfiria Studio management application. It is an internal business tool used by the staff of Mia Porfiria Ink to run appointments, treatments, inventory, staff earnings and reporting.
Self sign-up is not possible. Accounts are created only by studio management. Clients do not download or use this application; client records are entered by staff during service.
The website and the Mia Porfiria AI application are outside the scope of this policy — see the website privacy policy.
2. Data controller
Mia Porfiria Ink
Kurtuluş Mah. 2013 Sok. No: 3/B, Efeler / Aydın, Türkiye
Email: info@miaporfiriaink.com
Phone: +90 507 006 01 69
3. Data processed
3.1 Staff account and authentication
- Email address (required for sign-in)
- Full name
- Phone number (optional)
- Staff code, title, start and end dates
- Role and permission assignments
Passwords are stored irreversibly by the authentication provider. The application never stores, copies or logs a password.
3.2 Client records
- Full name, phone, email
- Date of birth, gender
- Address and social media handle (optional)
- Free-form notes
- Marketing contact preference
3.3 Health and treatment records
Because tattooing, piercing and tattoo removal carry health implications, the following is recorded:
- Reported allergies and medical notes
- Treatment area, session records and aftercare notes
- Tattoo removal session parameters and observations
This is special category personal data. It is processed solely to deliver the service safely, on the basis of the individual's explicit consent. The application does not produce any medical diagnosis or treatment recommendation; previous session values are shown as records only.
3.4 Photographs
Before/after and reference photographs may be stored. Photographs are kept in private storage, are never published publicly or exposed to search engines, and can only be viewed by authorised staff through short-lived, individually issued links.
3.5 Financial and operational records
- Transaction amounts, discounts, payment method (cash / card / transfer)
- Deposits and collections
- Staff earnings, shifts and end-of-day records
- Inventory movements and stock counts
No card numbers, IBANs or bank details are stored. Only the payment method and amount are recorded. The application does not process payments and is not connected to any payment provider.
3.6 Appointments and notifications
- Appointment date, duration, assigned staff member and status
- Reminder delivery status
- Device notification registration token
- Device platform, app version and language preference
Notification text never contains client names or phone numbers. To deliver notifications to the right device, a randomly generated per-installation identifier is used; it is lost when the app is uninstalled.
No hardware identifiers are collected. Advertising IDs (IDFA/AAID), MAC addresses and similar persistent identifiers are never read.
3.7 Security and audit records
Critical actions (creating, correcting, voiding a record, changing permissions) are written to an immutable audit trail together with who performed them and when, so that erroneous or malicious changes can be detected.
4. Data NOT collected
- Location (no location permission is requested)
- Contacts, calendar, SMS, call history
- Advertising identifiers; advertising or marketing tracking
- Biometric data
- Third-party analytics or usage statistics
- Web browsing history
The application contains no advertising and no in-app purchases. Your data is never used to track you across apps or websites.
5. Purposes of processing
- Scheduling and reminding of appointments
- Delivering the service safely (allergy and treatment history)
- Keeping transaction, collection and inventory records
- Calculating and paying staff earnings
- Meeting statutory retention and accounting obligations
- Detecting unauthorised access and erroneous entries
6. Access control
Each staff member can only see the data their role requires. Access control is enforced at the data layer, not merely by hiding menu items: a staff member without the relevant permission cannot retrieve another staff member's financial data even by requesting it directly. Commercial information such as purchase costs is restricted to management.
7. Infrastructure providers
The following providers act as data processors. They do not use the data for their own purposes and it is never sold:
- Supabase — database, authentication and file storage. Data is hosted in the Singapore region.
- Google Firebase Cloud Messaging — delivery of notifications to staff devices.
- Apple Push Notification service — delivery of notifications to iPhone and iPad devices.
No data is shared with any other third party, and no data is sold or shared for advertising.
8. Security
- All traffic uses encrypted connections (HTTPS).
- Photographs are kept in private storage; access is granted through short-lived links.
- Authorisation is enforced at the data layer.
- Financial records and the audit trail are immutable; corrections are made by reversing entries.
- Personal data is masked in application logs.
9. Retention
- Financial records are retained for the statutory period and are never deleted; corrections are made by reversing entries.
- Audit records cannot be modified or deleted.
- Client records are kept for the duration of the service relationship and statutory obligations; on request they are anonymised.
- Staff records are deactivated rather than deleted, so past transactions remain traceable.
- Notification registrations are deactivated once they become invalid.
10. Your rights
Under Turkish data protection law (KVKK) you may ask whether your personal data is processed, request information about the processing, request correction of inaccurate data, request erasure or destruction where the conditions are met, learn the third parties data has been transferred to, and claim compensation for damages.
11. Deletion and anonymisation requests
Send your request to info@miaporfiriaink.com.
Staff accounts: closure requests are handled by studio management and access is revoked. Past transaction and audit records are not deleted, due to statutory retention obligations.
Client records: on request, identifying fields are anonymised. After anonymisation the record can no longer be attributed to a person, while the integrity of accounting records is preserved.
12. Children's privacy
The application is not directed at children and is used only by studio staff. Where a service is provided to a minor, the record is created with the parental or guardian consent required by applicable law.
13. Changes to this policy
This policy may be updated. Changes are published on this page and the update date at the top is revised.
14. Contact
Mia Porfiria Ink
Kurtuluş Mah. 2013 Sok. No: 3/B, Efeler / Aydın, Türkiye
Email: info@miaporfiriaink.com
Phone: +90 507 006 01 69