Legal

Privacy policy

Last updated: 7 October 2026

DermLux respects your privacy. As a medical aesthetics clinic we also handle information about your health, and we treat it with matching care. This policy explains what personal data we collect when you visit our clinics or our website, book an appointment or buy products, why we use it, and the rights you have under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and Cyprus Law 125(I)/2018.

Who we are

  • Data controller: DERMLUX LASER & AESTHETICS LTD (registration no. HE 460016), Arch. Makariou III 160, 8250 Chloraka, Paphos, Cyprus, trading as DermLux.
  • Contact: hello@dermluxclinics.com · 77 787801

The data we collect

  • Identity and contact details: name, phone number, email, the city or clinic you prefer and, where needed, date of birth and sex.
  • Health information: what you tell us so that we can judge whether a treatment suits you — medical history, allergies, medication, skin type, questionnaire answers — and your consultation notes, treatment record and clinical photographs.
  • Appointments and payments: bookings, deposits, purchases and invoices. Card payments are processed by Stripe; we never see or store your full card number.
  • Communications: your messages and calls with us by form, phone, email, SMS, WhatsApp, Viber or social media.
  • Technical data: IP address, device and browser, the pages you visit and how you reached us. Anything beyond what the site needs to work is collected only with your consent (see Cookie policy).

We collect most of this directly from you. Sometimes a parent or guardian gives it to us on your behalf.

Why we use it, and on what legal basis

  • To book and carry out your treatments — managing appointments, reminders, payments, invoices and your questions. Necessary for the contract with you or for steps before it (Art. 6(1)(b) GDPR).
  • For your safety — we process health information to provide care, by professionals bound by confidentiality (Art. 9(2)(h) GDPR).
  • To call you back — when you leave your details or start a booking without finishing it, we may contact you to help (legitimate interest, Art. 6(1)(f) GDPR).
  • To meet legal obligations — tax and accounting records and anything else the law requires (Art. 6(1)(c) GDPR).
  • News and offers — only with your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. These messages never contain anything about your health or treatments.
  • Statistics and advertising on the website — only with your consent to cookies (see Cookie policy).

Before-and-after photographs

Clinical photographs are part of your record. We never use them for anything else — our website, social media, training — without your separate, explicit, written consent, which you can withdraw at any time.

Who we share it with

We never sell your personal data. We share it only as far as needed, with:

  • Our team: doctors, aestheticians and administrative staff, on a need-to-know basis.
  • Payment providers: Stripe processes online payments.
  • Technology providers: website hosting, booking and records systems, email and SMS delivery — always under a data processing agreement (Art. 28 GDPR).
  • Measurement and advertising providers: Google (Analytics, Ads), Meta (Facebook, Instagram) and Microsoft (Clarity) — only with your consent to cookies.
  • Advisers and authorities: accountants, auditors, lawyers and insurers, and public authorities where the law requires it.

Transfers outside the EU

Some providers (for example Stripe, Google, Meta and Microsoft) may process data outside the European Economic Area, for instance in the United States. Such transfers are made with the safeguards the GDPR provides, such as an adequacy decision of the European Commission or standard contractual clauses.

How long we keep it

We keep your data only for as long as the purpose it was collected for requires. Medical records and tax and accounting records are kept for as long as the law and our professional obligations require. Details for news and offers are kept until you withdraw your consent. When data is no longer needed, we delete or anonymise it securely.

Security

We use appropriate technical and organisational measures to protect your data against unauthorised access, loss or alteration, such as access controls, encrypted connections and confidentiality obligations for our staff.

Your rights

  • Access — a copy of the data we hold about you.
  • Rectification — correction of inaccurate or incomplete data.
  • Erasure — in the cases the GDPR provides. Some records, such as the medical record and invoices, must be kept for as long as the law requires.
  • Restriction — limiting how we use your data in certain cases.
  • Portability — receiving data you gave us in a commonly used format.
  • Objection — to processing based on legitimate interest, and to direct marketing at any time.
  • Withdrawal of consent — at any time, without affecting what was done before.

To exercise any of these rights, write to us at hello@dermluxclinics.com. We reply within one month, as the GDPR requires, and may ask you to confirm your identity first.

If you are not satisfied with our reply, you can complain to the Office of the Commissioner for Personal Data Protection (dataprotection.gov.cy).

Automated decisions

We do not take decisions that significantly affect you by automated means alone. Advertising tools may use data to show you relevant adverts, only with your consent.

Minors

Our services are for adults. People under 18 are seen only with the consent and in the presence of a parent or guardian.

Changes to this policy

We may update this policy. The current version is always on this page, with the date of the last update at the top.

CallBook appointment
EL