1. Parties and scope
This Data Processing Agreement (“DPA”) is between SkinVizo (“SkinVizo”, “we”, “us”) and the clinic that has created a SkinVizo account (“the Clinic”, “you”). It forms part of the agreement under which the Clinic uses the SkinVizo service — the skin-analysis widget, the reports and the clinic dashboard (the “Service”).
It applies whenever SkinVizo processes personal data on the Clinic’s behalf under the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, or any other data protection law that applies to that processing (together, “Data Protection Law”). Terms such as controller, processor, personal data, processing and data subject have the meanings given to them in the GDPR.
The Clinic accepts this DPA when it creates an account. It continues for as long as SkinVizo processes personal data for the Clinic.
2. Roles
The Clinic is the controller of the personal data of its website visitors and patients. SkinVizo is its processor.
- The Clinic decides why and how patient data is used, and is responsible for having a lawful basis for it, including explicit consent where special category data is involved.
- The widget shows the Clinic’s own privacy policy, and asks for the visitor’s consent before the camera opens.
- Each patient belongs to exactly one clinic. SkinVizo does not combine patients across clinics or keep a profile of anyone across clinics.
- For the Clinic’s own account data — the names and email addresses of its staff users, and its billing details — SkinVizo is a controller, and our privacy notice applies.
3. Processing on your instructions
SkinVizo processes personal data only on the Clinic’s documented instructions. Those instructions are this DPA, the agreement for the Service, the settings the Clinic chooses in its dashboard, and the scans its website visitors start. We do not use the Clinic’s patient data for any other purpose, sell it, or use it to train AI models.
If we are required by law to process personal data in another way, we will tell the Clinic first unless the law forbids it. If we believe an instruction breaks Data Protection Law, we will say so promptly.
4. Details of the processing
| Subject matter | Providing the Service: AI skin analysis from a photo, skin reports, treatment and product recommendations, and lead, patient and booking management. |
|---|---|
| Duration | For the term of the agreement, then until deletion under section 10. |
| Data subjects | Visitors to the Clinic’s website who use the widget, and the Clinic’s patients. |
| Nature of processing | Collection, storage, analysis, display, transmission and deletion. |
Categories of personal data and how long they are kept:
| Category | Data | Kept |
|---|---|---|
| Face photograph (biometric, special category) | The photo taken for the analysis. | Deleted once the analysis is complete. Kept only if the Clinic has enabled retention and the visitor gives separate, explicit consent — and then only for the period the Clinic sets. |
| Health information (special category) | Optional answers such as allergies, current medication, pregnancy and previous treatments. | For the life of the patient record. Encrypted at the application layer; every read is logged. |
| Contact and identity | Name, email address, phone number, date of birth. | For the life of the patient record. |
| Technical | IP address, browser user agent, consent records. | For the life of the patient record. |
| Analysis results | Skin scores, skin age, skin type, phototype, recommendations. | For the life of the patient record. These are not the photo. |
5. Confidentiality
Everyone at SkinVizo who can access personal data is bound by a duty of confidentiality, and has access only where their work needs it.
6. Security
We maintain technical and organisational measures appropriate to the risk, as Article 32 GDPR requires. They include:
- Isolation between clinics — every clinic’s data is separated in the application and again by row-level security in the database, verified by automated tests before each release.
- Encryption in transit (TLS 1.2 or later) and at rest, with health information additionally encrypted at the application layer (AES-256-GCM) under a key held separately from the database.
- Role-based access in the dashboard — owner, admin, practitioner and front desk — enforced on the server.
- An audit log of reads of health information, exports and consent changes, recording who, what and when.
- Strong password hashing (Argon2id) and session tokens that are revoked if reuse is detected.
- Two independent mechanisms for deleting photos, so a photo cannot be left behind by one failure.
- Encrypted backups, kept for 30 days.
7. Sub-processors
The Clinic gives general authorisation for SkinVizo to use sub-processors. We impose data protection obligations on each one that are no less protective than this DPA, and we remain responsible to the Clinic for their work. Our current sub-processors are:
| Sub-processor | Purpose | Data | Location |
|---|---|---|---|
| Google (Gemini API) | Skin analysis | Face photograph, only while it is analysed | EU / US |
| Cloudflare (R2, CDN, bot protection) | Storage and delivery | Photos until deleted, report PDFs, IP addresses | EU storage for EU clinics |
| Resend | Transactional email | Name, email address | EU / US |
| Stripe | Payments | Billing contact and payment details | EU / US |
| Twilio | SMS reminders, when the Clinic turns them on | Phone number | EU / US |
| Sentry | Error monitoring | Technical diagnostics, with personal data removed before sending | EU |
| Our hosting provider | Running the Service | All data processed in the Service | EU |
We will notify the Clinic at least 30 days before adding or replacing a sub-processor. If the Clinic objects on reasonable data protection grounds, it may terminate the Service without penalty before the change takes effect.
8. International transfers
Where personal data is transferred outside the UK or the European Economic Area, we rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses, with the UK Addendum where UK data is involved, together with any supplementary measures needed. Photos and files for clinics in the EU are stored in the EU.
9. Helping you meet your obligations
- Data subject requests — the dashboard lets the Clinic export or erase a patient’s data in one action. If a request reaches us directly, we pass it to the Clinic without delay and do not answer it ourselves.
- Personal data breaches — we notify the Clinic without undue delay, and in any case within 72 hours of becoming aware, with the information the Clinic needs to meet its own reporting duties.
- Impact assessments — we provide reasonable information to help with data protection impact assessments and any consultation with a supervisory authority.
10. Deletion or return
When the Clinic’s account ends, the Clinic can download a complete, machine-readable export of its data straight away and keeps read-only access for 30 days. After that, we permanently delete the Clinic’s personal data, including stored files and photos, unless the law requires us to keep it. Copies in encrypted backups are deleted as those backups expire, within a further 30 days.
11. Information and audits
We make available the information needed to show compliance with this DPA and Article 28 GDPR, including this document, our sub-processor list and reasonable answers to security questionnaires. Audits or inspections by the Clinic, or by an auditor it appoints, can be arranged on reasonable notice and under confidentiality.
12. General
If this DPA and the agreement for the Service conflict on the protection of personal data, this DPA prevails. Liability under this DPA is subject to the limits in that agreement, except where Data Protection Law does not allow them. We may update this DPA to reflect changes in law or in the Service; material changes will be notified to the Clinic in advance, and the version and date at the top of this page always show the current one.