Effective 10 August 2026

Privacy policy

This policy explains how SKINTRACE processes personal data on skintrace.fr and in the Skintrace SaaS service.

Contact the data controller
On this page
  1. Controller and scope
  2. Data we process
  3. Purposes and legal bases
  4. Data entrusted by studios
  5. Recipients and providers
  6. Location and international transfers
  7. Retention
  8. Security
  9. Your rights
  10. Cookies and local storage
  11. Changes and contact

1. Controller and scope

SKINTRACE SAS, a French simplified joint-stock company with capital of EUR 2,000 and registered office at 4 rue Saint-Nicolas, 59400 Cambrai, France, is the controller for website, account, subscription, security and support processing. Contact: skintrace.pro@gmail.com.

For data that studios record about their own clients, including consent forms, health information, photographs, procedures and traceability records, the relevant studio determines the purposes and remains the controller. SKINTRACE then acts as its processor under the studio’s instructions and contract.

This policy covers website visitors, prospects, account holders, operators invited by a studio and, where relevant, clients whose information is processed through the service.

2. Data we process

We process only the categories needed to operate the website and service. The data actually processed depends on the features used and the information supplied by a studio.

  • Account and identity data: name, email address, credentials, role, associated studio and security settings.
  • Contract and billing data: plan, subscription status, billing details, invoices and payment references. Complete card details are processed by Stripe and are not stored by SKINTRACE.
  • Studio content: client records, consent forms, procedure information, products, batches, sterilization cycles, documents, photographs, appointments, transactions and follow-up entered by authorized users.
  • Communication data: support requests, messages, attachments and correspondence history.
  • Technical and security data: IP address, date and time, browser, device, authentication events, application logs and operational diagnostics.
  • Local website preferences: consent version and choices stored in the browser’s local storage.

3. Purposes and legal bases

Each activity relies on a legal basis under the GDPR. We do not sell service data for prospecting or use it to create advertising profiles.

  • Contract performance: create and administer accounts, provide requested features, manage subscriptions, support users and enable exports.
  • Legal obligation: retain accounting records, answer legally valid requests and comply with applicable tax or judicial duties.
  • Legitimate interests: secure the service, prevent abuse, diagnose incidents, maintain availability and defend legal rights, after balancing those interests against individual rights.
  • Consent: use an optional storage or script category on the website when offered. Consent can be withdrawn at any time through Cookie settings.

4. Data entrusted by studios

The studio must have a valid legal basis, inform its clients, limit collection and configure suitable access. Health information and other special-category data also require a condition under Article 9 GDPR. SKINTRACE does not decide which information a studio should collect.

A person concerned by a studio record should normally contact the studio that created it first. We help the studio answer requests and may refer a request to it when SKINTRACE acts only as processor.

5. Recipients and providers

Data is available to authorized SKINTRACE personnel who need it for their work and to authorized users of the relevant studio. We may use contractually controlled providers according to the features enabled.

  • OVH for website hosting; Cloudflare R2 for service object and document storage.
  • Stripe for payments, subscriptions and related billing documents.
  • Amazon Web Services for SMS delivery when that feature is used.
  • The production-configured SMTP provider for transactional and support email.
  • Google for optional authentication with a Google account.
  • Scanbot and the delivery networks required by its components when scanning is used.
  • Authorities or professional advisers when required by law or to establish, exercise or defend a legal claim.

6. Location and international transfers

Primary hosting is organized in the European Economic Area. Some international providers may nevertheless process data from a country outside the EEA to deliver their services, support customers or secure infrastructure.

Where a transfer is required, it relies as appropriate on an adequacy decision, the recipient’s valid participation in the EU-US Data Privacy Framework, or European Commission Standard Contractual Clauses with appropriate supplementary measures. Information about the relevant safeguard can be requested from our contact address.

7. Retention

We retain data for the period needed for its purpose, then delete it or place it in a restricted archive where the law or a legal claim requires this. Plan settings and studio instructions may result in a shorter period for some service data.

  • Account and service content: for the contractual relationship and the operational period needed for closure, recovery or deletion, subject to mandatory archives.
  • Sales and support enquiries: 3 years after the last relevant contact.
  • Technical and security logs: up to 12 months, unless longer retention is needed to investigate an incident or comply with law.
  • Invoices and accounting records: 10 years under French accounting rules.
  • Contract evidence: up to 5 years in a restricted archive after the relationship ends, according to the applicable limitation period.
  • Evidence of parental consent for a procedure involving a minor: set by the studio under its duties; the specific French 3-year period may apply to this evidence. It is not a general retention period for every record.

8. Security

SKINTRACE applies technical and organizational measures proportionate to risk, including access controls, logical separation between studio workspaces, security logging, encryption in transit, backups and incident-management procedures.

No system provides absolute security. Each studio must manage its users, use strong authentication, promptly remove unnecessary access and limit entered data to what is needed.

9. Your rights

Depending on your situation, you may request access, correction, erasure, restriction or portability, and object to processing based on legitimate interests. You may withdraw consent without affecting earlier processing. Send requests to skintrace.pro@gmail.com with enough information to identify the relevant processing.

We may request identity evidence only where needed to avoid disclosure to a third party. We answer within the GDPR time limit. You may also lodge a complaint with the French data protection authority, the CNIL, through cnil.fr, or with the competent authority where you live or work.

10. Cookies and local storage

The website currently uses no audience analytics tool or advertising script. It stores only your privacy choice in browser local storage so that the same decision is not requested on every visit. This storage is necessary to manage your choice.

Analytics and Marketing are off by default, and no scripts in those categories are currently loaded. If purposes or providers change, the consent version will be renewed so that an up-to-date choice is requested. You can change or withdraw your choice at any time with the Cookie settings button in the footer.

11. Changes and contact

This policy may change to reflect updates to the service, providers or applicable law. The date at the top identifies the current version. We will provide more prominent information where a change materially affects individual rights.

For questions about this policy or processing carried out directly by SKINTRACE, contact skintrace.pro@gmail.com.

A question about your data?

Email us to exercise a right or ask for details about processing.

skintrace.pro@gmail.com