Skip to content
SkinVizo

Legal

Data Processing Agreement

Version 1.0Last updated

In short

  • Your clinic is the data controller. SkinVizo is the processor and acts only on your instructions.
  • Face photos are deleted once the analysis is done, unless the patient separately agrees to let you keep them.
  • Health details patients give you are encrypted, and every read is logged.
  • You get 30 days’ notice before we add a sub-processor, and can leave without penalty if you object.
  • We tell you about a personal data breach without undue delay, and within 72 hours.
  • When you leave, you get a full export; everything is deleted 30 days later.

1. Parties and scope

This Data Processing Agreement (“DPA”) is between SkinVizo (“SkinVizo”, “we”, “us”) and the clinic that has created a SkinVizo account (“the Clinic”, “you”). It forms part of the agreement under which the Clinic uses the SkinVizo service — the skin-analysis widget, the reports and the clinic dashboard (the “Service”).

It applies whenever SkinVizo processes personal data on the Clinic’s behalf under the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, or any other data protection law that applies to that processing (together, “Data Protection Law”). Terms such as controller, processor, personal data, processing and data subject have the meanings given to them in the GDPR.

The Clinic accepts this DPA when it creates an account. It continues for as long as SkinVizo processes personal data for the Clinic.

2. Roles

The Clinic is the controller of the personal data of its website visitors and patients. SkinVizo is its processor.

  • The Clinic decides why and how patient data is used, and is responsible for having a lawful basis for it, including explicit consent where special category data is involved.
  • The widget shows the Clinic’s own privacy policy, and asks for the visitor’s consent before the camera opens.
  • Each patient belongs to exactly one clinic. SkinVizo does not combine patients across clinics or keep a profile of anyone across clinics.
  • For the Clinic’s own account data — the names and email addresses of its staff users, and its billing details — SkinVizo is a controller, and our privacy notice applies.

3. Processing on your instructions

SkinVizo processes personal data only on the Clinic’s documented instructions. Those instructions are this DPA, the agreement for the Service, the settings the Clinic chooses in its dashboard, and the scans its website visitors start. We do not use the Clinic’s patient data for any other purpose, sell it, or use it to train AI models.

If we are required by law to process personal data in another way, we will tell the Clinic first unless the law forbids it. If we believe an instruction breaks Data Protection Law, we will say so promptly.

4. Details of the processing

Subject matterProviding the Service: AI skin analysis from a photo, skin reports, treatment and product recommendations, and lead, patient and booking management.
DurationFor the term of the agreement, then until deletion under section 10.
Data subjectsVisitors to the Clinic’s website who use the widget, and the Clinic’s patients.
Nature of processingCollection, storage, analysis, display, transmission and deletion.

Categories of personal data and how long they are kept:

CategoryDataKept
Face photograph (biometric, special category)The photo taken for the analysis.Deleted once the analysis is complete. Kept only if the Clinic has enabled retention and the visitor gives separate, explicit consent — and then only for the period the Clinic sets.
Health information (special category)Optional answers such as allergies, current medication, pregnancy and previous treatments.For the life of the patient record. Encrypted at the application layer; every read is logged.
Contact and identityName, email address, phone number, date of birth.For the life of the patient record.
TechnicalIP address, browser user agent, consent records.For the life of the patient record.
Analysis resultsSkin scores, skin age, skin type, phototype, recommendations.For the life of the patient record. These are not the photo.

5. Confidentiality

Everyone at SkinVizo who can access personal data is bound by a duty of confidentiality, and has access only where their work needs it.

6. Security

We maintain technical and organisational measures appropriate to the risk, as Article 32 GDPR requires. They include:

  • Isolation between clinics — every clinic’s data is separated in the application and again by row-level security in the database, verified by automated tests before each release.
  • Encryption in transit (TLS 1.2 or later) and at rest, with health information additionally encrypted at the application layer (AES-256-GCM) under a key held separately from the database.
  • Role-based access in the dashboard — owner, admin, practitioner and front desk — enforced on the server.
  • An audit log of reads of health information, exports and consent changes, recording who, what and when.
  • Strong password hashing (Argon2id) and session tokens that are revoked if reuse is detected.
  • Two independent mechanisms for deleting photos, so a photo cannot be left behind by one failure.
  • Encrypted backups, kept for 30 days.

7. Sub-processors

The Clinic gives general authorisation for SkinVizo to use sub-processors. We impose data protection obligations on each one that are no less protective than this DPA, and we remain responsible to the Clinic for their work. Our current sub-processors are:

Sub-processorPurposeDataLocation
Google (Gemini API)Skin analysisFace photograph, only while it is analysedEU / US
Cloudflare (R2, CDN, bot protection)Storage and deliveryPhotos until deleted, report PDFs, IP addressesEU storage for EU clinics
ResendTransactional emailName, email addressEU / US
StripePaymentsBilling contact and payment detailsEU / US
TwilioSMS reminders, when the Clinic turns them onPhone numberEU / US
SentryError monitoringTechnical diagnostics, with personal data removed before sendingEU
Our hosting providerRunning the ServiceAll data processed in the ServiceEU

We will notify the Clinic at least 30 days before adding or replacing a sub-processor. If the Clinic objects on reasonable data protection grounds, it may terminate the Service without penalty before the change takes effect.

8. International transfers

Where personal data is transferred outside the UK or the European Economic Area, we rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses, with the UK Addendum where UK data is involved, together with any supplementary measures needed. Photos and files for clinics in the EU are stored in the EU.

9. Helping you meet your obligations

  • Data subject requests — the dashboard lets the Clinic export or erase a patient’s data in one action. If a request reaches us directly, we pass it to the Clinic without delay and do not answer it ourselves.
  • Personal data breaches — we notify the Clinic without undue delay, and in any case within 72 hours of becoming aware, with the information the Clinic needs to meet its own reporting duties.
  • Impact assessments — we provide reasonable information to help with data protection impact assessments and any consultation with a supervisory authority.

10. Deletion or return

When the Clinic’s account ends, the Clinic can download a complete, machine-readable export of its data straight away and keeps read-only access for 30 days. After that, we permanently delete the Clinic’s personal data, including stored files and photos, unless the law requires us to keep it. Copies in encrypted backups are deleted as those backups expire, within a further 30 days.

11. Information and audits

We make available the information needed to show compliance with this DPA and Article 28 GDPR, including this document, our sub-processor list and reasonable answers to security questionnaires. Audits or inspections by the Clinic, or by an auditor it appoints, can be arranged on reasonable notice and under confidentiality.

12. General

If this DPA and the agreement for the Service conflict on the protection of personal data, this DPA prevails. Liability under this DPA is subject to the limits in that agreement, except where Data Protection Law does not allow them. We may update this DPA to reflect changes in law or in the Service; material changes will be notified to the Clinic in advance, and the version and date at the top of this page always show the current one.