Privacy Policy — Clinics, Clinic Staff, and Marketplace Vendors

Privacy Policy — Clinics, Clinic Staff, and Marketplace Vendors

Last updated: 20 September 2026 · Version: 1.0 (draft — pending legal review)

This Privacy Policy applies to clinics, spas, and dermatology practices ("Clinics") that register on DermaId (the "Platform", "we", "us"), to the staff members Clinics invite onto the Platform, and to marketplace vendors/suppliers ("Vendors") that list products for sale. A separate policy applies to individual consumer users — see /en/pages/privacy — and that policy continues to govern any of your own personal data you provide as an individual (for example, if a staff member is also, separately, a consumer of the Service).


1. Who we are

COMPANY LEGAL INFORMATION — REGISTRATION DETAILS STILL OUTSTANDING — see /en/pages/privacy §1 for the fields required. The same legal entity is the data controller under this policy.

2. Two different relationships, two different roles

This policy addresses two distinct relationships, and it matters which one applies to a given piece of data:

  • As the Platform, we are the data controller for a Clinic's or Vendor's own business and staff data — the information in §3 below, collected to onboard, bill, and operate the relationship.
  • A Clinic is an independent data controller for its own clients' clinical information — the notes it writes, the routine adjustments it makes, and the treatment decisions it records about a client who has consented to link with that Clinic. We act as a processor for the purpose of hosting and securing that relationship on the Clinic's behalf, under the Clinic's instructions, and only to the extent the client has consented to share their information with that specific Clinic. [Legal review note: this allocation should be formalized in a data processing agreement between us and each Clinic — see /en/pages/data-handling/clinics-vendors §3, and is a prerequisite to onboarding Clinics that will process EU client data at any meaningful scale.]
  • A Vendor is an independent data controller for its own product listings and business records; we process order and fulfillment data on the Vendor's behalf as necessary to complete a sale the Vendor has made through the Platform.

3. What we collect from Clinics, staff, and Vendors

3.1 Clinic business information

Legal/trading name, country, business registration details, contact person, contact email and phone, website, social media links, treatment-type categories, business address and location (for the "Find a Clinic" directory), and, where applicable, external booking links.

3.2 Clinic staff accounts

Each staff member's name, email, and the role(s) assigned to them (for example, Owner, Catalog Manager, Specialist, Receptionist, or Billing Viewer) — a role determines what that person can see and do, defined as a set of granular permissions rather than a fixed job title, so a Clinic controls exactly who on its team can view clinical notes, manage the product catalog, or view billing, independently of one another.

3.3 Clinic subscription and billing

The Clinic's chosen platform plan, billing history and invoices, staff-seat count, and the commission rate individually agreed with that Clinic on marketplace sales it refers.

3.4 Vendor business and payout information

Vendor/brand name, country, commission rate, and payout account details, handled through our payment processor's connected-account (Stripe Connect) product — we do not ourselves hold your bank account number; it is provided directly to the payment processor during onboarding.

3.5 What Clinic staff may access about a client — only with the client's consent

Once a client has actively linked to a Clinic and separately consented to share their information with that specific Clinic, staff whose role permits it may see: the client's contact details; the parts of their Skinprofile and skin-analysis history they consented to share; their routine, including any clinic-authored adjustments; messages the client sends to that Clinic; and, for a specialist role specifically, clinical notes written about the engagement. Staff never see the client's conversation with our AI assistant — see /en/pages/privacy §3.6, which applies without exception to every Clinic. Every access a staff member makes to a client's data is logged (actor, action, timestamp).

4. How we use Clinic and Vendor information

To operate the account (staff invitations, permission management, billing); to process the Clinic's platform subscription and, separately, Vendor payouts; to resolve the Clinic in "Find a Clinic" search results; to route a client's messages, appointment requests, and routine-approval requests to the right Clinic; to calculate and pay commission owed on marketplace sales a Clinic refers; to detect and prevent fraud or misuse; and to comply with our own legal, tax, and accounting obligations.

5. Legal bases

Data Legal basis
Clinic/Vendor business onboarding, staff accounts, billing Performance of the contract between us and the Clinic/Vendor
Payout account details Performance of contract; processed principally by our payment processor as a sub-processor
A client's data made visible to Clinic staff The client's own explicit consent, per Clinic — we process it as the client's chosen processor for that Clinic's benefit, not on a basis we independently hold
Audit logs of staff access to client data Legitimate interest (accountability and security) and, where the Clinic is a controller for that data, a joint obligation to be able to demonstrate appropriate access controls
Commission calculation and financial records Performance of contract; legal obligation (tax/accounting)

6. Sharing

We share Clinic and Vendor information only as necessary to operate the Platform: with our payment processor for billing and payouts; with our hosting and email sub-processors listed in /en/pages/data-handling/clinics-vendors §6; and, where a Clinic has connected an alert channel such as Telegram or (once activated) WhatsApp, with that channel, limited to the specific alert content the Clinic has chosen to receive that way. A Clinic's own registered contact address and, where none is set, its active Owner/Specialist staff, receive service alerts about client activity (new messages, requests, appointments) so a request is never left unseen simply because nobody happened to be looking at the portal.

We do not sell Clinic, staff, Vendor, or client data.

7. International transfers

See /en/pages/privacy §7 and /en/pages/data-handling/clinics-vendors §7 — the same sub-processors and transfer mechanisms apply.

8. Retention

Data Retention
Clinic/Vendor business and staff account data For as long as the account is active, plus any period required by tax/accounting law thereafter for financial records
Commission ledger, payout records, invoices Per applicable tax/accounting retention law
Client data visible to a Clinic Governed by the client's own consent and the individual policy's retention rules; a Clinic's own clinical notes about its engagement with a client are the Clinic's business record and are retained as such, independent of whether the client later deletes their own Platform account
Audit logs of staff access to client data Retained as an accountability record, including after a staff member's access is revoked

9. Client requests directed to a Clinic

Where a client exercises a data-subject right (access, rectification, erasure, or objection) in relation to information a Clinic itself controls (its own clinical notes, for example), the Clinic is responsible for responding as the controller of that data, and we will support the Clinic in doing so as its processor. Where the request concerns data we control directly (the client's Platform account), we handle it under /en/pages/data-handling §9, including where relevant closing out any pending request the client had open with the Clinic and notifying the Clinic's own record accordingly.

10. Confidentiality obligations on Clinic staff

Access to client data through the Platform is granted solely for the purpose of providing the client's requested consultation or treatment guidance. Clinic staff must not export, copy, or reuse client personal data outside the Platform for any other purpose, and must not attempt to access a client's data beyond what their assigned role and that client's consent permit. [Legal review note: this should be reflected in the Clinic-facing terms of service / data processing agreement as a binding contractual obligation, not only a policy statement.]

11. Termination

If a Clinic's or Vendor's account is closed, we retain the records described in §8 for the periods stated there; other operational data (active staff sessions, cached catalog data) is deactivated. A closed Clinic's existing clients are not automatically unlinked from their own individual accounts' data, which continues to be governed by /en/pages/privacy.

12. Rights of individual staff members

A person who holds a Clinic staff account is also an individual whose own personal data (name, email, login activity) we process — they hold the same rights described in /en/pages/privacy §9 over that data, distinct from any client data they access in the course of their role, which is the client's data, not theirs.

13. Region-specific notices

See /en/pages/privacy §15, which applies equally here, including the open item on Gulf-region data-protection law review and the Syria cash-only payment restriction, which applies to Vendor and Clinic transactions in the same way.

14. Changes to this policy

See /en/pages/privacy §16 — the same update and notice process applies.

15. Contact us

contact@dermaid.se · [registered postal address]


This document is a draft prepared for legal review and has not yet been finalized by counsel.

Related documents