SkinMate LogoSKINMATE

Privacy Policy

Your privacy and data protection are our highest priorities

Last Updated: December 15, 2025

1. INTRODUCTION

This Privacy Policy ("Policy") describes how SkinMate collects, uses, processes, stores, and protects personal data and biometric information when you use the SkinMate application ("App") and related services ("Services"). This Policy applies to end users ("User") who access SkinMate through our business clients, including skincare companies, skin clinics, and retailers ("Business Partners").

By using SkinMate, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with this Policy, please do not use our Services.

1.1 Legal Framework and Compliance

SkinMate is designed to comply with:

  • EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679)
  • ePrivacy Directive (Directive 2002/58/EC) and national implementations
  • EU AI Act (Regulation (EU) 2024/1689) – particularly provisions on biometric categorization systems and transparency requirements
  • California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
  • ISO/IEC 29134:2023 – Privacy Impact Assessment guidelines
  • ISO/IEC 29151 – Code of practice for personally identifiable information protection
  • The Privacy Act of Nepal (2018)
  • Other applicable international and local data protection regulations

1.2 Age Restrictions

Important Age Restriction: SkinMate is not intended for use by individuals under the age of 16 years. We do not knowingly collect personal information from users under 16. If you are under 16, you are discouraged from using this App. If we become aware that we have collected personal data from a person under 16, we will take immediate steps to delete such information.

Compliance Note: This age restriction complies with GDPR Article 8 (child consent requirements) and exceeds the Children's Online Privacy Protection Act (COPPA) minimum age of 13 in the United States.

2. DATA CONTROLLER AND CONTACT INFORMATION

2.1 Joint Controllers

The data processing activities under SkinMate involve joint controllership arrangements:

  • Primary Controller: SkinMate, Kupondole, Lalitpur, Nepal.
  • Business Partner (Co-Controller): The specific skincare company, clinic, or retailer through which you access SkinMate
  • Contact Email: privacy@skinmate.ai
  • Phone: 9841112555
  • Data Protection Officer (DPO): Subin Hachhethu

Our DPO can be contacted at: dpo@skinmate.ai

2.2 EU Representative (if applicable)

If your company is not established in the EU but processes data of EU residents:

EU Representative: Subin Hachhethu, SkinMate, Kupondole, Lalitpur, Nepal

3. CATEGORIES OF PERSONAL DATA WE COLLECT

We collect and process the following categories of personal data:

3.1 Account and Profile Information

  • Identity Data: Name, username, date of birth (for age verification)
  • Contact Data: Email address, phone number (optional)
  • Demographic Data: Age, gender (self-reported)

3.2 Biometric Data and Facial Analysis Information

IMPORTANT: Biometric Data Processing Under GDPR Article 9

SkinMate processes biometric data as defined under GDPR Article 9(1) – special category personal data. Specifically:

  • Facial Images: Temporary capture of your facial photograph for analysis purposes
  • Extracted Biometric Features: Facial landmarks, skin texture patterns, pigmentation characteristics, and other physiological features derived from specific technical processing

Processing Method and Data Minimization:

  • When you capture a selfie, the App identifies and crops the facial region required for analysis
  • The cropped image undergoes automated skin analysis using signal processing technology
  • The system extracts skin-related parameters, analyzes them, and provides a score for each parameter
  • The original photograph and cropped facial image are NOT stored in our database
  • Only the analysis results (skin scores, identified concerns, recommendations) are retained

Legal Basis for Biometric Data Processing: Explicit consent (GDPR Article 9(2)(a)), obtained through the consent mechanism described in Section 4.

EU AI Act Compliance: Our biometric categorization system is classified as limited risk under the EU AI Act (Regulation (EU) 2024/1689). We provide transparent disclosure that AI is used for skin analysis and categorization for skincare recommendations. This system is NOT used for identification or verification purposes.

3.3 Analysis Results and Skin Profile Data

  • Skin analysis scores
  • Identified skin concerns
  • Skin type categorization
  • Historical analysis results and tracking data

3.4 Product Interaction and Purchase Data

  • Product recommendations provided to you
  • Products viewed and purchased through the App
  • Purchase history, transaction details
  • Payment information (processed by third-party payment processors; we do not store full payment card details)

3.5 Technical and Device Data

  • Device Information: Device type, operating system, unique device identifiers (UDID, advertising ID)
  • Usage Data: App features accessed, session duration, interaction patterns
  • Log Data: IP address, browser type, access times, crash logs
  • Cookies and Similar Technologies: See Section 10

3.6 Communication Data

  • Customer support inquiries and correspondence
  • Feedback, reviews, and survey responses
  • Marketing communication preferences

4. LEGAL BASIS FOR PROCESSING PERSONAL DATA

We process your personal data only when we have a valid legal basis under applicable law:

4.1 Consent (GDPR Article 6(1)(a) and Article 9(2)(a))

Explicit consent is our primary legal basis for processing biometric data and special category data. You provide consent when you:

  • Accept this Privacy Policy and Terms of Service
  • Actively capture your facial photograph within the App
  • Opt-in to specific data processing activities (like marketing communications)

Your consent rights:

  • Consent is freely given, specific, informed, and unambiguous
  • You may withdraw consent at any time through App settings or by contacting us by sending your request to support@skinmate.ai
  • Withdrawal does not affect the lawfulness of processing before withdrawal
  • Withdrawal may limit your ability to use certain App features

4.2 Contract Performance (GDPR Article 6(1)(b))

Processing is necessary to provide the Services you requested, including:

  • Delivering personalized skin analysis
  • Generating product recommendations
  • Facilitating product purchases
  • Providing customer support

4.3 Legitimate Interests (GDPR Article 6(1)(f))

We may process data based on legitimate interests, provided these interests are not overridden by your rights:

  • Improving App functionality and user experience
  • Fraud prevention and security measures
  • Internal analytics and business intelligence
  • Network and information security

Balancing Test: We have conducted assessments to ensure our legitimate interests do not override your fundamental rights and freedoms.

4.4 Legal Obligations (GDPR Article 6(1)(c))

Processing necessary to comply with legal obligations, such as:

  • Tax and accounting regulations
  • Law enforcement requests (with appropriate legal basis)
  • Regulatory compliance (consumer protection laws, product safety)

5. HOW WE USE YOUR PERSONAL DATA

5.1 Primary Purposes

We use your personal data for the following purposes:

a) Skin Analysis and Personalized Recommendations

  • Analyzing facial images to assess skin conditions and characteristics
  • Generating personalized skincare recommendations
  • Creating and maintaining your skin profile
  • Tracking skin improvement over time

b) Service Delivery and Account Management

  • Creating and managing your user account
  • Authenticating users and maintaining account security
  • Processing product recommendations and purchases
  • Providing customer support and responding to inquiries

c) Product Recommendations and Marketing

  • Recommending skincare products available through our Business Partners
  • Sending personalized product suggestions based on your skin profile
  • Delivering promotional communications (with your consent)
  • Conducting surveys and collecting feedback

d) App Improvement and Analytics

  • Analyzing usage patterns to improve App functionality
  • Conducting research and development for enhanced AI algorithms
  • Testing new features and conducting A/B testing
  • Generating aggregated, anonymized statistics

e) Legal Compliance and Safety

  • Complying with applicable laws and regulations
  • Preventing fraud, abuse, and security threats
  • Enforcing our Terms of Service
  • Protecting rights and property of SkinMate and users

5.2 Automated Decision-Making and Profiling

AI-Powered Skin Analysis

SkinMate uses automated processing, including AI and machine learning algorithms, to analyze your skin and provide recommendations. This constitutes automated decision-making with profiling under GDPR Article 22.

Your Rights:

  • You have the right to obtain human intervention
  • You may express your point of view regarding automated decisions
  • You may contest automated decisions
  • You have the right to an explanation of the logic involved

To exercise these rights, contact us at privacy@skinmate.ai.

EU AI Act Transparency: You are interacting with an AI-powered skin analysis system. Analysis results and product recommendations are generated by artificial intelligence based on image processing algorithms.

5.3 Scientific Research and Algorithm Improvement

With your explicit consent, we may use anonymized or pseudonymized analysis data for:

  • Scientific research in dermatology and skincare science
  • Improving AI algorithm accuracy and performance
  • Developing new analysis capabilities
  • Contributing to peer-reviewed research (data is fully anonymized)

GDPR Article 89 Safeguards: Research uses appropriate technical and organizational measures, including pseudonymization, data minimization, and restricted access controls.

6. DATA SHARING AND THIRD-PARTY DISCLOSURES

We respect the confidentiality of your personal data and limit sharing to the following circumstances:

6.1 Business Partners (Joint Controllers)

Your data is shared with the Business Partner (skincare company, clinic, or retailer) through whom you access SkinMate. Business Partners have access to:

  • Your account and profile information
  • Skin analysis results
  • Product interaction and purchase history

Purpose: To enable Business Partners to provide you with recommended products, customer support, and relevant services.

Data Processing Agreement: Each Business Partner enters into a data processing agreement with SkinMate establishing joint controller responsibilities per GDPR Article 26.

6.2 Service Providers and Processors (GDPR Article 28)

We engage third-party service providers who process personal data on our behalf:

a) Cloud Hosting and Infrastructure

  • Provider: Azure or AWS
  • Purpose: Secure data storage, computation, and App hosting
  • Location: Multiple Regions including India, US, and EU

b) Payment Processing

  • Provider: Depends on the Payment Processing systems used by the Business Partners
  • Purpose: Processing payments and transactions
  • Data Shared: Transaction information, billing details (we do not store full payment card numbers)

c) Customer Support Platforms

  • Provider: In-app support form
  • Purpose: Managing customer inquiries and support tickets
  • Data Shared: Contact information, communication history

d) Analytics and Performance Monitoring

  • Providers: Google Analytics
  • Purpose: App performance monitoring, usage analytics
  • Data Shared: Technical data, device information, usage patterns

e) Email and Communication Services

  • Provider: Google Workspace or Microsoft 365 Outlook
  • Purpose: Sending transactional and marketing communications
  • Data Shared: Email address, name, communication preferences

Data Processing Agreements: All service providers are bound by data processing agreements (GDPR Article 28) requiring appropriate security measures and prohibiting unauthorized use of personal data.

6.3 Legal Disclosures and Law Enforcement

We may disclose personal data when required by law or to:

  • Comply with legal obligations, court orders, or government requests
  • Enforce our Terms of Service and investigate violations
  • Protect the rights, property, or safety of SkinMate, users, or the public
  • Detect, prevent, or address fraud, security, or technical issues

Data Subject Rights: In case of law enforcement requests, we will notify affected users unless prohibited by law.

6.4 Business Transactions

In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred to the acquiring entity. You will be notified of any such change and provided options regarding your data.

6.5 With Your Consent

We may share personal data with other third parties when you provide explicit consent for specific purposes.

7. INTERNATIONAL DATA TRANSFERS

7.1 Transfer Mechanisms

SkinMate operates globally, and your personal data may be transferred to and processed in countries outside the European Economic Area (EEA) or your country of residence.

For data transfers from the EEA to third countries:

We implement appropriate safeguards as required by GDPR Chapter V:

a) Adequacy Decisions (GDPR Article 45)

Transfers to countries recognized by the European Commission as providing adequate data protection

b) Standard Contractual Clauses (SCCs) (GDPR Article 46(2)(c))

  • We use the European Commission's Standard Contractual Clauses (2021 version) for transfers to third countries without adequacy decisions
  • SCCs establish contractual guarantees for data protection equivalent to GDPR standards

c) Transfer Impact Assessment (TIA)

  • We conduct Transfer Impact Assessments per the Schrems II ruling (Case C-311/18) to ensure recipient countries provide adequate protection
  • We evaluate local laws, surveillance practices, and data subject rights in recipient countries
  • Additional safeguards (e.g., encryption, pseudonymization) are implemented where necessary

7.2 Data Localization

  • Primary Data Processing Location: Multiple Regions including India, EU and US
  • Cloud Infrastructure Locations: Multiple Regions including India, EU and US

For specific information about where your data is processed, contact privacy@skinmate.ai.

8. DATA RETENTION AND STORAGE LIMITATION

8.1 Retention Principles (GDPR Article 5(1)(e))

We retain personal data only for as long as necessary to fulfill the purposes outlined in this Policy, comply with legal obligations, resolve disputes, and enforce agreements.

Storage Limitation Principle: Personal data is not kept longer than necessary for its specified purpose.

8.2 Retention Periods by Data Category

Data CategoryRetention PeriodLegal/Business Justification
Account InformationDuration of account + 30 days after deletion requestContract performance; user access
Biometric Data (Facial Images)NOT RETAINED – deleted immediately after analysisData minimization; only analysis results are stored
Skin Analysis ResultsDuration of account + 3 yearsHistorical tracking; service improvement
Purchase Transaction Data7 years from transaction dateTax and accounting regulations; legal obligations
Customer Support Records5 years from last interactionLegal claims; service quality improvement
Marketing Consent RecordsDuration of consent + 3 yearsDemonstrating compliance; GDPR Article 7(1)
Technical Logs (IP addresses, device IDs)90 daysSecurity monitoring; legitimate interests
Anonymized Analytics DataIndefinitely (no personal data)Research; product improvement

8.3 Data Deletion and Anonymization

Active Deletion:

  • Users may request account deletion at any time (see Section 11)
  • Upon deletion request, personal data is permanently removed within 30 days
  • Certain data may be retained in anonymized form for statistical and research purposes

Automated Deletion:

  • Inactive accounts (no login for 3 years) are automatically flagged for deletion
  • Users are notified 60 days before automated deletion

Backup Data:

  • Deleted data may persist in backup systems for up to 90 days before permanent deletion

9. DATA SECURITY AND PROTECTION MEASURES

9.1 Technical and Organizational Measures (GDPR Article 32)

We implement industry-standard security measures to protect personal data against unauthorized access, alteration, disclosure, or destruction:

a) Encryption

  • Data in Transit: TLS 1.3 encryption for all data transmission
  • Data at Rest: AES-256 encryption for stored data
  • Biometric Processing: Secure enclave processing where available (iOS Secure Enclave, Android Keystore)

b) Access Controls

  • Role-based access control (RBAC) limiting employee access to personal data
  • Multi-factor authentication (MFA) for administrative access
  • Principle of least privilege applied to all data access

c) Network Security

  • Firewall protection and intrusion detection systems
  • Regular security audits and penetration testing
  • DDoS protection and rate limiting

d) Data Minimization by Design

  • Immediate deletion of facial images after analysis
  • Collection of only necessary data for service delivery
  • Pseudonymization and anonymization where applicable

e) Organizational Measures

  • Employee training on data protection and security
  • Confidentiality agreements for all personnel with data access
  • Incident response and breach notification procedures
  • Regular compliance audits and reviews

9.2 Privacy by Design and Default (GDPR Article 25)

SkinMate is built with Privacy by Design principles:

  • Data minimization: We collect only necessary data
  • Default privacy settings: Most privacy-protective settings are enabled by default
  • User control: Easy-to-use privacy settings and controls
  • Transparency: Clear information about data processing

9.3 Data Breach Notification

In the event of a personal data breach, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware (GDPR Article 33)
  • Notify affected data subjects without undue delay if the breach poses a high risk to their rights and freedoms (GDPR Article 34)
  • Document all data breaches and remedial actions taken

To report a security concern: security@skinmate.ai

10. COOKIES AND TRACKING TECHNOLOGIES

10.1 Types of Cookies We Use (ePrivacy Directive Article 5(3))

SkinMate uses cookies and similar tracking technologies. Cookies are small text files stored on your device that help us provide and improve the App.

Cookie Categories:

a) Strictly Necessary Cookies (No Consent Required)

  • Purpose: Essential for App functionality, authentication, and security
  • Examples: Session cookies, load balancing, security tokens
  • Retention: Session-based or up to 1 year

b) Functional Cookies (Consent Required)

  • Purpose: Remember your preferences and settings
  • Examples: Language preferences, theme settings, user interface customization
  • Retention: Up to 2 years

c) Analytics Cookies (Consent Required)

  • Purpose: Understand how users interact with the App
  • Providers: Google Analytics, Firebase Analytics, etc.
  • Data Collected: Page views, session duration, device information
  • Retention: Up to 2 years

d) Marketing Cookies (Consent Required)

  • Purpose: Deliver personalized advertisements and measure campaign effectiveness
  • Providers: Facebook Pixel, Google Ads, etc.
  • Retention: Up to 1 year

10.2 Cookie Consent and Control

Prior Consent Requirement: Non-essential cookies are only activated after you provide explicit consent through our cookie banner.

Managing Cookies:

  • In-App Settings: Access cookie preferences in Settings > Privacy
  • Browser Settings: Configure the browser to block or delete cookies
  • Opt-Out Tools: Use industry opt-out mechanisms (e.g., NAI, DAA)

Withdrawing Consent: You may withdraw cookie consent at any time through App settings. Note that disabling certain cookies may limit App functionality.

10.3 Do Not Track Signals

SkinMate respects browser "Do Not Track" (DNT) signals where technically feasible. When DNT is enabled, we limit non-essential tracking.

11. YOUR RIGHTS AND CHOICES

11.1 Rights Under GDPR (for EEA/UK Users)

You have the following rights regarding your personal data:

a) Right of Access (Article 15)

  • Request confirmation of whether we process your personal data
  • Obtain a copy of your personal data
  • Request: privacy@skinmate.ai or through App Settings > Privacy > Download My Data

b) Right to Rectification (Article 16)

  • Correct inaccurate or incomplete personal data
  • Update your profile information directly in the App

c) Right to Erasure / "Right to be Forgotten" (Article 17)

  • Request deletion of your personal data under certain circumstances
  • Request: App Settings > Privacy > Delete My Account or privacy@skinmate.ai
  • Note: Some data may be retained for legal obligations (e.g., transaction records for tax purposes)

d) Right to Restriction of Processing (Article 18)

e) Right to Data Portability (Article 20)

  • Receive your personal data in a structured, machine-readable format (JSON, CSV)
  • Transmit your data to another controller
  • Request: App Settings > Privacy > Export My Data

f) Right to Object (Article 21)

  • Object to processing based on legitimate interests
  • Object to direct marketing at any time (opt-out links in marketing emails)
  • Request: privacy@skinmate.ai

g) Right to Withdraw Consent (Article 7(3))

  • Withdraw consent for biometric processing or other consent-based activities
  • Withdrawal does not affect prior lawful processing
  • Request: App Settings > Privacy > Manage Consents

h) Right to Lodge a Complaint (Article 77)

i) Rights Related to Automated Decision-Making (Article 22)

  • Request human review of automated decisions
  • Contest AI-generated skin analysis results
  • Request explanation of algorithmic logic

11.2 Rights Under CCPA/CPRA (for California Residents)

California residents have the following rights:

a) Right to Know

  • Request disclosure of personal information collected, sold, or shared in the past 12 months
  • Request: privacy@skinmate.ai

b) Right to Delete

  • Request deletion of personal information (subject to exceptions)

c) Right to Correct

  • Request correction of inaccurate personal information

d) Right to Opt-Out of Sale/Sharing

  • Important: SkinMate does NOT sell personal information as defined by CCPA
  • If data sharing occurs, opt-out by sending a request to privacy@skinmate.ai

e) Right to Limit Use of Sensitive Personal Information

  • Request limitation of use of sensitive personal information (including biometric data)

f) Right to Non-Discrimination

  • You will not receive discriminatory treatment for exercising your privacy rights

Authorized Agent: You may designate an authorized agent to submit requests on your behalf. We may require verification of authorization.

Verification Process: To protect your privacy, we verify your identity before fulfilling requests. Verification may require matching information you provide with information in our records.

Response Time: We respond to verified requests within 45 days (may be extended by 45 days with notice).

11.3 Marketing Communications Opt-Out

Email Marketing:

  • Unsubscribe link in every marketing email
  • App Settings > Notifications > Marketing Communications

Push Notifications:

  • Device settings > SkinMate > Notifications

SMS/Text Messages:

  • Reply STOP to any marketing text
  • App Settings > Notifications > SMS Marketing

12. THIRD-PARTY LINKS AND INTEGRATIONS

SkinMate may contain links to third-party websites, services, or Business Partner platforms. We are not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any external sites or services you access.

Business Partner Privacy Policies: When you purchase products through SkinMate, you may be redirected to our Business Partner's website or checkout system. Those transactions are governed by the Business Partner's privacy policy and terms.

13. DATA PROTECTION IMPACT ASSESSMENT (DPIA)

ISO/IEC 29134:2023 Compliance

SkinMate has conducted a comprehensive Data Protection Impact Assessment (DPIA) as required by GDPR Article 35 for high-risk processing activities involving:

  • Biometric data processing (special category data)
  • Automated decision-making and profiling
  • Large-scale processing of personal data

DPIA Summary:

  • Necessity and Proportionality: Processing is necessary for service delivery and proportionate to purpose
  • Risk Identification: Risks to data subject rights have been identified and mitigated
  • Safeguards: Technical and organizational measures minimize risks
  • Privacy by Design: Privacy protections embedded in system architecture

Full DPIA: Available upon request to data protection authorities. Summary request at privacy@skinmate.ai.

14. CALIFORNIA "SHINE THE LIGHT" LAW

California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for direct marketing purposes. SkinMate does not disclose personal information to third parties for their direct marketing purposes without your explicit consent.

15. NEVADA PRIVACY RIGHTS

Nevada residents may opt-out of the sale of personal information. SkinMate does not sell personal information as defined under Nevada Revised Statutes Chapter 603A. If this changes, Nevada residents will be notified and provided an opt-out mechanism.

16. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy periodically to reflect changes in:

  • Our data processing practices
  • Applicable laws and regulations
  • App features and functionality
  • Business operations

Notification of Changes:

  • Material Changes: We will notify you via email, in-App notification, or prominent notice 30 days before changes take effect
  • Minor Changes: Updated policy will be posted with a new "Last Updated" date
  • Continued Use: Your continued use of SkinMate after changes take effect constitutes acceptance of the updated Policy

17. CONTACT US AND EXERCISE YOUR RIGHTS

For questions, concerns, or to exercise your privacy rights, contact us:

Response Time: We will respond to inquiries within 30 days (GDPR) or 45 days (CCPA).

18. SUPERVISORY AUTHORITY CONTACT INFORMATION

For EU/EEA Users:

You have the right to lodge a complaint with your national data protection supervisory authority:

For UK Users:

For California Residents:

19. DEFINITIONS AND INTERPRETATION

  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Biometric Data: Personal data resulting from specific technical processing relating to physical, physiological, or behavioral characteristics (GDPR Article 4(14)).
  • Processing: Any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
  • Data Controller: The entity that determines the purposes and means of processing personal data.
  • Data Processor: An entity that processes personal data on behalf of the data controller.
  • Consent: Any freely given, specific, informed, and unambiguous indication of the data subject's wishes.

APPENDIX A: BUSINESS PARTNER DATA PROCESSING RESPONSIBILITIES

Under joint controller arrangements (GDPR Article 26), responsibilities are allocated as follows:

ResponsibilitySkinMateBusiness Partner
Obtaining user consent
Skin analysis processing
Product recommendations (AI)
Product inventory and fulfillment
Purchase processingShared
Customer supportShared
Marketing communications✓ (with user consent)
Data subject rights requests✓ (coordination)✓ (cooperation)

APPENDIX B: DATA SUBJECT RIGHTS REQUEST FORM

To exercise your rights, complete the following information:

Request Type:

☐ Access ☐ Deletion ☐ Rectification ☐ Portability ☐ Restriction ☐ Object ☐ Other: _______

Your Information:

  • Full Name: _______________________
  • Email Address: ____________________
  • Account Username: _________________
  • Phone Number: ____________________

Verification:

To protect your privacy, we will verify your identity. Please provide:

  • Last 4 digits of phone number on account
  • Date of last App usage
  • Any other identifying information

Submit to: privacy@skinmate.ai

END OF PRIVACY POLICY

IMPORTANT LEGAL NOTICE: This Privacy Policy template is provided for informational purposes and should be reviewed and customized by qualified legal counsel familiar with data protection laws applicable to your specific jurisdiction and business model. Laws and regulations vary by country and region, and this document may not address all legal requirements specific to your circumstances.