Privacy Policy — Clinics, Clinic Staff, and Marketplace Vendors
Privacy Policy — Clinics, Clinic Staff, and Marketplace Vendors
Last updated: 20 September 2026 · Version: 1.0 (draft — pending legal review)
This Privacy Policy applies to clinics, spas, and dermatology practices ("Clinics") that register on DermaId (the "Platform", "we", "us"), to the staff members Clinics invite onto the Platform, and to marketplace vendors/suppliers ("Vendors") that list products for sale. A separate policy applies to individual consumer users — see /en/pages/privacy — and that policy continues to govern any of your own personal data you provide as an individual (for example, if a staff member is also, separately, a consumer of the Service).
1. Who we are
COMPANY LEGAL INFORMATION — REGISTRATION DETAILS STILL OUTSTANDING — see /en/pages/privacy §1 for the fields required. The same legal entity is the data controller under this policy.
2. Two different relationships, two different roles
This policy addresses two distinct relationships, and it matters which one applies to a given piece of data:
- As the Platform, we are the data controller for a Clinic's or Vendor's own business and staff data — the information in §3 below, collected to onboard, bill, and operate the relationship.
- A Clinic is an independent data controller for its own clients' clinical information — the notes it writes, the routine adjustments it makes, and the treatment decisions it records about a client who has consented to link with that Clinic. We act as a processor for the purpose of hosting and securing that relationship on the Clinic's behalf, under the Clinic's instructions, and only to the extent the client has consented to share their information with that specific Clinic. [Legal review note: this allocation should be formalized in a data processing agreement between us and each Clinic — see /en/pages/data-handling/clinics-vendors §3, and is a prerequisite to onboarding Clinics that will process EU client data at any meaningful scale.]
- A Vendor is an independent data controller for its own product listings and business records; we process order and fulfillment data on the Vendor's behalf as necessary to complete a sale the Vendor has made through the Platform.
3. What we collect from Clinics, staff, and Vendors
3.1 Clinic business information
Legal/trading name, country, business registration details, contact person, contact email and phone, website, social media links, treatment-type categories, business address and location (for the "Find a Clinic" directory), and, where applicable, external booking links.
3.2 Clinic staff accounts
Each staff member's name, email, and the role(s) assigned to them (for example, Owner, Catalog Manager, Specialist, Receptionist, or Billing Viewer) — a role determines what that person can see and do, defined as a set of granular permissions rather than a fixed job title, so a Clinic controls exactly who on its team can view clinical notes, manage the product catalog, or view billing, independently of one another.
3.3 Clinic subscription and billing
The Clinic's chosen platform plan, billing history and invoices, staff-seat count, and the commission rate individually agreed with that Clinic on marketplace sales it refers.
3.4 Vendor business and payout information
Vendor/brand name, country, commission rate, and payout account details, handled through our payment processor's connected-account (Stripe Connect) product — we do not ourselves hold your bank account number; it is provided directly to the payment processor during onboarding.
3.5 What Clinic staff may access about a client — only with the client's consent
Once a client has actively linked to a Clinic and separately consented to share their information with that specific Clinic, staff whose role permits it may see: the client's contact details; the parts of their Skinprofile and skin-analysis history they consented to share; their routine, including any clinic-authored adjustments; messages the client sends to that Clinic; and, for a specialist role specifically, clinical notes written about the engagement. Staff never see the client's conversation with our AI assistant — see /en/pages/privacy §3.6, which applies without exception to every Clinic. Every access a staff member makes to a client's data is logged (actor, action, timestamp).
4. How we use Clinic and Vendor information
To operate the account (staff invitations, permission management, billing); to process the Clinic's platform subscription and, separately, Vendor payouts; to resolve the Clinic in "Find a Clinic" search results; to route a client's messages, appointment requests, and routine-approval requests to the right Clinic; to calculate and pay commission owed on marketplace sales a Clinic refers; to detect and prevent fraud or misuse; and to comply with our own legal, tax, and accounting obligations.
5. Legal bases
| Data | Legal basis |
|---|---|
| Clinic/Vendor business onboarding, staff accounts, billing | Performance of the contract between us and the Clinic/Vendor |
| Payout account details | Performance of contract; processed principally by our payment processor as a sub-processor |
| A client's data made visible to Clinic staff | The client's own explicit consent, per Clinic — we process it as the client's chosen processor for that Clinic's benefit, not on a basis we independently hold |
| Audit logs of staff access to client data | Legitimate interest (accountability and security) and, where the Clinic is a controller for that data, a joint obligation to be able to demonstrate appropriate access controls |
| Commission calculation and financial records | Performance of contract; legal obligation (tax/accounting) |
6. Sharing
We share Clinic and Vendor information only as necessary to operate the Platform: with our payment processor for billing and payouts; with our hosting and email sub-processors listed in /en/pages/data-handling/clinics-vendors §6; and, where a Clinic has connected an alert channel such as Telegram or (once activated) WhatsApp, with that channel, limited to the specific alert content the Clinic has chosen to receive that way. A Clinic's own registered contact address and, where none is set, its active Owner/Specialist staff, receive service alerts about client activity (new messages, requests, appointments) so a request is never left unseen simply because nobody happened to be looking at the portal.
We do not sell Clinic, staff, Vendor, or client data.
7. International transfers
See /en/pages/privacy §7 and /en/pages/data-handling/clinics-vendors §7 — the same sub-processors and transfer mechanisms apply.
8. Retention
| Data | Retention |
|---|---|
| Clinic/Vendor business and staff account data | For as long as the account is active, plus any period required by tax/accounting law thereafter for financial records |
| Commission ledger, payout records, invoices | Per applicable tax/accounting retention law |
| Client data visible to a Clinic | Governed by the client's own consent and the individual policy's retention rules; a Clinic's own clinical notes about its engagement with a client are the Clinic's business record and are retained as such, independent of whether the client later deletes their own Platform account |
| Audit logs of staff access to client data | Retained as an accountability record, including after a staff member's access is revoked |
9. Client requests directed to a Clinic
Where a client exercises a data-subject right (access, rectification, erasure, or objection) in relation to information a Clinic itself controls (its own clinical notes, for example), the Clinic is responsible for responding as the controller of that data, and we will support the Clinic in doing so as its processor. Where the request concerns data we control directly (the client's Platform account), we handle it under /en/pages/data-handling §9, including where relevant closing out any pending request the client had open with the Clinic and notifying the Clinic's own record accordingly.
10. Confidentiality obligations on Clinic staff
Access to client data through the Platform is granted solely for the purpose of providing the client's requested consultation or treatment guidance. Clinic staff must not export, copy, or reuse client personal data outside the Platform for any other purpose, and must not attempt to access a client's data beyond what their assigned role and that client's consent permit. [Legal review note: this should be reflected in the Clinic-facing terms of service / data processing agreement as a binding contractual obligation, not only a policy statement.]
11. Termination
If a Clinic's or Vendor's account is closed, we retain the records described in §8 for the periods stated there; other operational data (active staff sessions, cached catalog data) is deactivated. A closed Clinic's existing clients are not automatically unlinked from their own individual accounts' data, which continues to be governed by /en/pages/privacy.
12. Rights of individual staff members
A person who holds a Clinic staff account is also an individual whose own personal data (name, email, login activity) we process — they hold the same rights described in /en/pages/privacy §9 over that data, distinct from any client data they access in the course of their role, which is the client's data, not theirs.
13. Region-specific notices
See /en/pages/privacy §15, which applies equally here, including the open item on Gulf-region data-protection law review and the Syria cash-only payment restriction, which applies to Vendor and Clinic transactions in the same way.
14. Changes to this policy
See /en/pages/privacy §16 — the same update and notice process applies.
15. Contact us
contact@dermaid.se · [registered postal address]
This document is a draft prepared for legal review and has not yet been finalized by counsel.