Privacy Policy
DermLux
Last updated: 4 June 2026
1. Introduction
DermLux Laser & Aesthetics LTD ("DermLux", "we", "us", or "our") is committed to protecting and respecting your privacy. As a medical aesthetics clinic, we handle sensitive information about your health and treatments, and we take that responsibility seriously.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you visit our clinics, use our website and mobile application, book or receive treatments, or otherwise interact with us. It also explains your rights under the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Cyprus law that implements it, Law 125(I)/2018 (the Law Providing for the Protection of Natural Persons with regard to the Processing of Personal Data).
Please read this policy carefully. By using our services, you acknowledge that you have read and understood it.
2. Who we are (Data Controller)
The data controller responsible for your personal data is:
- Legal entity: DermLux Laser & Aesthetics LTD, trading as DermLux
- Company registration number: HE460016
- Registered address: Archiepiskopou Makariou III, Chloraka, Paphos, Cyprus
- Clinic locations: Limassol, Nicosia, Paphos, and Larnaca
- Email: hello@dermluxclinics.com
- Telephone: +357 97 736138
- Website: www.dermluxclinic.com
3. The personal data we collect
Depending on how you interact with us, we may collect the following categories of personal data.
Identity and contact data: full name, date of birth, gender, postal address, email address, and telephone/mobile number.
Health and treatment data (special category data): medical history, allergies, skin conditions, medications, contraindications, consultation notes, treatment records, before-and-after photographs, consent forms, and any other information necessary to deliver aesthetic and medical treatments safely.
Appointment and transaction data: booking history, treatments purchased, products purchased, payment records, and invoicing information. (We do not store full card numbers; card payments are processed by our payment providers — see Section 8.)
Communications data: records of your correspondence with us by email, phone, SMS, Viber, WhatsApp, or social media, and notes from consultations.
Marketing and preferences data: your preferences for receiving marketing from us and your communication preferences.
Technical and usage data: when you use our website or app, your IP address, device and browser information, login data, and usage data collected through cookies and similar technologies (see Section 13).
Booking-link usage data: when you open a personal booking link we send you by SMS, we record how you used that page — when you opened it, how long you stayed, and how far you got through the booking (for example whether you chose a centre or a time). We record this ourselves, on our own systems, so that we can follow up on your enquiry and improve the booking process. It is not collected through cookies, it does not track you on any other website, and it is not shared with any third party.
We collect this data directly from you, but in some cases we may receive it from a referring physician, a parent or legal guardian acting on your behalf, or through our online booking system.
4. Legal bases for processing
Under the GDPR we must have a valid legal basis to process your personal data. We rely on the following.
For ordinary personal data (Article 6 GDPR):
- Contract (Art. 6(1)(b)): to provide the treatments and services you book with us and to manage your account and appointments.
- Legal obligation (Art. 6(1)(c)): to comply with tax, accounting, health, and consumer-protection laws.
- Legitimate interests (Art. 6(1)(f)): to run and improve our business, keep our premises and systems secure, understand how our own booking pages are used so that we can follow up on enquiries and improve them, and (where permitted) send certain communications. We balance these interests against your rights.
- Consent (Art. 6(1)(a)): for marketing communications and for non-essential cookies, which you can withdraw at any time.
For special category (health) data (Article 9 GDPR):
- Health or medical care (Art. 9(2)(h)): to provide aesthetic and medical treatments, assess suitability and contraindications, and ensure your safety, where this data is handled by or under the responsibility of a professional subject to an obligation of confidentiality.
- Explicit consent (Art. 9(2)(a)): where required — for example, to use before-and-after photographs for purposes beyond your treatment record (such as marketing), which we will only do with your separate, explicit, written consent.
- Legal claims (Art. 9(2)(f)): where necessary to establish, exercise, or defend legal claims.
5. How we use your personal data
We use your personal data to:
- assess your suitability for treatments and carry out consultations;
- plan, deliver, and follow up on treatments and aftercare;
- maintain accurate medical and treatment records;
- manage bookings, reminders, payments, invoicing, and your account;
- respond to your enquiries and communicate with you about your care, including following up when you have started a booking but not completed it;
- send you marketing and promotional information where you have consented (see Section 6);
- operate, maintain, and improve our website, mobile application, and online booking pages;
- comply with our legal, regulatory, and professional obligations;
- protect the health and safety of clients and staff; and
- establish, exercise, or defend legal claims.
6. Marketing communications
We will only send you marketing communications where you have given your consent, or where otherwise permitted by law. We may contact you for marketing purposes by email, SMS, Viber, WhatsApp, and through social media platforms such as Meta (Facebook and Instagram). Marketing communications never contain details of your treatments or health.
You can withdraw your consent and opt out at any time by:
- clicking the "unsubscribe" link in any marketing email;
- replying STOP to a marketing SMS, or asking us to stop on Viber/WhatsApp; or
- contacting us at hello@dermluxclinics.com.
Withdrawing consent does not affect treatment-related or administrative messages (such as appointment confirmations and reminders), which we send to manage our service to you.
7. Before-and-after photographs
Clinical photographs taken as part of your treatment record are kept as part of your medical file and processed on the basis of providing your care (Art. 9(2)(h)).
We will only use your photographs for marketing, training, social media, our website, or any purpose beyond your own record if you have given separate, explicit, written consent. You may withdraw this consent at any time, although withdrawal will not affect material already published before we received your request.
8. Sharing your personal data
We do not sell your personal data, and our booking and client-records system is our own custom-built system — we do not share your treatment records with a third-party booking provider. We may share your personal data with the following categories of recipients, who are required to keep it secure and use it only for the agreed purposes:
- Our clinical and administrative staff, on a need-to-know basis.
- Payment processors — PBT and Stripe — to process card payments. We do not store your full card details.
- Communications and marketing providers that help us deliver email, SMS, Viber, and WhatsApp messages, and Meta (Facebook/Instagram) for advertising.
- Professional advisers, such as lawyers, auditors, and insurers.
- Public authorities and regulators, where we are required to disclose by law.
- A buyer or successor, in the event of a sale, merger, or reorganisation of our business.
Where third parties process personal data on our behalf, we have data processing agreements in place as required by Article 28 GDPR.
9. International transfers
We process your personal data within the European Economic Area (EEA) wherever possible. However, some of our service providers — in particular our payment processor Stripe and Meta (for advertising) — may transfer or process personal data outside the EEA, for example in the United States.
Where this happens, we ensure an appropriate level of protection through one of the safeguards permitted by the GDPR, such as:
- an adequacy decision by the European Commission for the destination country; or
- Standard Contractual Clauses approved by the European Commission, together with any additional measures required.
You may request a copy of the relevant safeguards by contacting us.
10. Data retention
We keep your personal data only for as long as necessary for the purposes set out in this policy.
- Medical and treatment records are retained for 10 years from the date of your last treatment, in line with our retention policy and our professional and legal obligations.
- Accounting and tax records are retained for at least the period required by Cyprus tax law (a minimum of 6 years).
- Marketing data is retained until you withdraw consent or object, after which we suppress your details to honour your request.
When data is no longer needed, we securely delete or anonymise it.
11. Data security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. These include access controls and authentication, encryption where appropriate, secure storage of clinical records, staff confidentiality obligations and training, and contractual safeguards with our processors.
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Commissioner for Personal Data Protection within 72 hours where required, and we will notify you where the breach is likely to result in a high risk to you.
12. Your rights
Under the GDPR, you have the following rights in relation to your personal data:
- Right of access — to obtain a copy of the personal data we hold about you.
- Right to rectification — to have inaccurate or incomplete data corrected.
- Right to erasure ("right to be forgotten") — to have your data deleted in certain circumstances. Note that we may be legally required to retain medical records for a minimum period.
- Right to restriction — to limit how we use your data in certain circumstances.
- Right to data portability — to receive certain data in a structured, commonly used, machine-readable format.
- Right to object — to object to processing based on our legitimate interests, and to object to direct marketing at any time.
- Right to withdraw consent — where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Rights relating to automated decision-making — see Section 14.
To exercise any of these rights, contact us at hello@dermluxclinics.com. We will respond within one month, as required by the GDPR. We may need to verify your identity before acting on your request. Exercising your rights is free of charge unless your request is manifestly unfounded or excessive.
13. Cookies, website, and mobile application
Our website and mobile application may use cookies and similar technologies. Essential cookies are necessary for the site/app to function. Non-essential cookies — including the Meta Pixel, Google Ads/Analytics tags, and Microsoft Clarity, which we use for advertising, measuring the performance of our campaigns, and understanding how visitors browse our online shop (including anonymised session replays and heatmaps with sensitive form fields masked) — are used only with your consent, which you can give or withdraw via our cookie banner or your device/browser settings. For more on how Microsoft Clarity processes data, see Microsoft's privacy statement.
The Meta Pixel shares certain data with Meta (Facebook/Instagram), which may involve a transfer of data outside the EEA (see Section 9).
[If you publish a separate, more detailed Cookie Policy, link to it here.]
14. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Our advertising tools (such as the Meta Pixel) may use profiling to show you relevant advertising; this operates only on the basis of your consent, and you can object or withdraw consent at any time.
15. Children
Our services are intended for adults. We treat persons under the age of 18 only when they are accompanied by, and with the approval and consent of, a parent or legal guardian, who must be present. We collect and process a minor's data only to the extent necessary to provide the treatment safely and with that guardian's involvement.
16. Changes to this policy
We may update this Privacy Policy from time to time. The current version will always be available at www.dermluxclinic.com, and the "Last updated" date at the top will reflect the most recent changes. Where changes are significant, we will take reasonable steps to notify you.
17. How to contact us and complain
If you have any questions about this policy or wish to exercise your rights, please contact us:
- Email: hello@dermluxclinics.com
- Address: Archiepiskopou Makariou III, Chloraka, Paphos, Cyprus
- Telephone: +357 97 736138
If you are not satisfied with our response, you have the right to lodge a complaint with the Cyprus supervisory authority:
Office of the Commissioner for Personal Data Protection
Office: Kypranoros 15, 1061 Nicosia, Cyprus
Postal: P.O. Box 23378, 1682 Nicosia, Cyprus
Tel: +357 22 818 456 · Fax: +357 22 304 565
Email: commissioner@dataprotection.gov.cy
Website: www.dataprotection.gov.cy
