Last updated: March 2026

Privacy Policy

This Privacy Policy describes how Estetika Professional ("we", "us", "our") collects, uses, and protects your personal data when you use our mobile application and website.

1. Data Controller

The data controller responsible for your personal data is Estetika Professional, a company registered in Belgium. [LEGAL REVIEW NEEDED: Insert full company name, registration number, and registered address.]

Data Protection Officer contact: privacy@estetikaprofessional.com

2. Data We Collect

2.1 Account Data (Practitioners)

  • Full name, email address, phone number
  • Business name, specialty (e.g., PMU artist, lash technician, esthetician)
  • Business address, VAT number (if applicable)
  • Profile photo, professional certifications
  • Payment and billing information (processed by Stripe)

2.2 Client Data (Entered by Practitioners)

  • Client name, email, phone number, date of birth
  • Treatment history and appointment records
  • Signed digital consent forms with timestamps
  • Portfolio photographs (before-and-after images)

2.3 Medical & Health Data

  • Allergies and skin sensitivities
  • Current medications
  • Skin conditions and relevant medical history
  • Pregnancy or nursing status
  • Previous treatment reactions

This data constitutes special category data under GDPR Article 9 and is processed with explicit consent.

2.4 Technical Data

  • Device type, operating system, app version
  • IP address (anonymized for analytics)
  • Usage patterns and feature interaction data
  • Crash reports and performance metrics

4. Special Categories of Data

Medical history and health-related data entered into Estetika Professional constitutes "special category data" under GDPR Article 9. This data is processed solely on the basis of explicit consent (Art. 9(2)(a)) provided by the client through our digital consent form system. The practitioner (our user) acts as a joint controller for this data within the context of their client relationship.

[LEGAL REVIEW NEEDED: Confirm joint controller vs. processor relationship for practitioner-entered client medical data.]

5. How We Use Your Data

  • Providing and maintaining the Estetika Professional application
  • Processing subscriptions and payments
  • Storing and organizing client records for practitioners
  • Generating and securely storing digital consent forms
  • Sending transactional emails (confirmations, receipts, reminders)
  • Improving app functionality through anonymized usage analytics
  • Providing customer support
  • Complying with legal obligations

6. Data Processors & Third Parties

We use the following third-party processors, all of whom are GDPR compliant with appropriate Data Processing Agreements (DPAs) in place:

ProcessorPurposeData Location
Supabase (US, EU servers)Database, authentication, file storageEU (Frankfurt)
Stripe (US, EU)Payment processingEU
Resend (US)Transactional email deliveryUS (SCCs in place)
Plausible Analytics (EU)Privacy-friendly website analyticsEU

7. Data Retention

  • Account data: Retained for the duration of your subscription plus 30 days after account deletion.
  • Client records & consent forms: Retained as long as the practitioner's account is active. Practitioners can delete individual client records at any time.
  • Medical history: Same retention as client records. Subject to any applicable Belgian healthcare record retention requirements. [LEGAL REVIEW NEEDED: Verify Belgian retention requirements for aesthetic treatment records.]
  • Payment records: Retained for 7 years as required by Belgian tax law.
  • Analytics data: Anonymized and retained indefinitely (no personal data).

8. Your Rights Under GDPR

Under the General Data Protection Regulation, you have the following rights:

  • Right of access (Art. 15): Request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): Request correction of inaccurate personal data.
  • Right to erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
  • Right to restrict processing (Art. 18): Request that we limit how we use your data.
  • Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Right to object (Art. 21): Object to processing based on legitimate interest or for direct marketing.
  • Right to withdraw consent: Withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at privacy@estetikaprofessional.com. We will respond within 30 days as required by GDPR.

You also have the right to lodge a complaint with the Belgian Data Protection Authority (Autoriteit Persoonsgegevens / Autorité de protection des données): www.dataprotectionauthority.be

9. International Data Transfers

Your data is primarily stored on EU-based servers. Where data transfer to third countries is necessary (e.g., certain sub-processors based in the US), we ensure adequate protection through EU Standard Contractual Clauses (SCCs) or adequacy decisions as per GDPR Chapter V. We do not transfer special category (health) data outside the EU.

10. Data Security

  • 256-bit AES encryption for data at rest
  • TLS 1.3 encryption for data in transit
  • Row Level Security (RLS) on all database tables
  • Regular security audits and penetration testing
  • Secure authentication with bcrypt password hashing
  • Automated backups with point-in-time recovery

11. Children's Privacy

Estetika Professional is designed for professional beauty practitioners and is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If client records include minors (e.g., parental consent for treatments), the practitioner is responsible for obtaining appropriate parental or guardian consent.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification at least 30 days before they take effect. Continued use of the service after changes constitutes acceptance of the updated policy.

13. Contact Us

For any privacy-related questions or to exercise your data rights: