Effective Date: 15-AUG-2025
Last Updated: 18-AUG-2025
Skin Galore (“we,” “our,” “us”) values your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and safeguard your information when you visit our website or use our services. It applies to all visitors, patients, and users located in India and abroad.
📌 1. Information We Collect
We may collect the following types of information:
- Personal Identification Data: Name, age, gender, date of birth, postal address, email address, phone number.
- Medical & Health Information: Medical history, treatment records, prescriptions, dermatological photographs, diagnostic test results — collected only with your explicit consent.
- Website Usage Data: IP address, browser type, device identifiers, pages visited, and cookies.
- Appointment & Transaction Details: Booking history, payment information (processed via secure payment gateways; we do not store card details).
📌 2. Lawful Basis for Processing (GDPR Compliance)
We process personal data under the following legal bases:
- Consent: For medical history, photographs, and communications.
- Contractual Necessity: To provide dermatology and skin treatment services you request.
- Legal Obligation: For compliance with applicable laws and regulations.
- Legitimate Interests: For improving services, patient safety, and operational efficiency.
📌 3. How We Use Your Information
Your data may be used for:
- Medical consultation and treatment planning
- Appointment scheduling and reminders
- Secure communication and follow-up care
- Processing payments and invoices
- Website performance monitoring and analytics
- Sending educational materials and health tips (with opt-out option)
- Compliance with legal and regulatory requirements
📌 4. Sharing & Disclosure
We will never sell your personal data. We may share information only:
- With medical professionals and staff directly involved in your care
- With third-party service providers (e.g., payment processors, lab services) under confidentiality agreements
- When required by law, regulation, or court order
- In case of merger, acquisition, or clinic restructuring (with notice)
📌 5. Data Retention
- Medical Records: Retained for the period required under applicable Indian laws (currently a minimum of 3 years) and GDPR.
- Other Data: Retained only as long as necessary for the purposes outlined in this policy.
📌 6. International Data Transfers
If your data is transferred outside India, we ensure adequate safeguards as per GDPR (Art. 46) and Indian IT Rules.
📌 7. Your Rights
Under GDPR:
- Right to Access, Rectification, and Erasure
- Right to Restrict Processing
- Right to Data Portability
- Right to Withdraw Consent at any time
- Right to Lodge a Complaint with a Data Protection Authority
Under Indian IT Act & Rules:
- Right to review, correct, and update your personal data
- Right to withdraw consent by notifying us in writing
📌 8. Cookies & Tracking
We use cookies to enhance user experience. You can adjust your browser settings to disable cookies, but this may impact website functionality.
📌 9. Data Security Measures
We implement ISO/IEC 27001-aligned security controls, including encryption, firewalls, access control, and regular vulnerability assessments, as required under the IT Rules.
📌 10. Third-Party Links
Our website may link to other sites. We are not responsible for the privacy practices or content of external websites.
📌 11. Children’s Privacy
We do not knowingly collect data from individuals under 18 without parental or guardian consent.
📌 12. Contact Us
For privacy concerns, data requests, or complaints:
Data Protection Officer (DPO)
Skin Galore
Mira Road, Maharashtra, INDIA
Email: privacy@skingalore.in
Phone: +91 9876 543 210
