Updated September 14, 2026
Practical guide for professionals
Practical guidance for using Skintrace, informing your clients and limiting the data your piercing, tattoo or permanent makeup studio keeps.
This guide provides practical information. It does not replace the rules applicable to your activity, your professional obligations or legal advice tailored to your situation.
In this guide
1. Understand your role
You decide why and how your clients’ data is used: you are generally the controller for client records, appointments, consent forms, photographs and documents. Skintrace provides the platform and acts as a technical processor for this data under your documented instructions and the contract with you.
This allocation also applies when clients enter their information directly in your booking portal. Skintrace does not perform the service or decide your professional practices.
2. Collect only what you need
Before adding a question or requesting a document, identify why it is needed for the service, appointment management or an applicable obligation. Do not collect information simply because a field allows it.
Explain which information is required, which is optional and how it will be used. Avoid excessive comments and attachments unrelated to the service.
3. Do not record medical details
Skintrace is not intended to collect or store detailed medical information. If a health-related situation may affect the service, invite the client to share the necessary information with you orally.
Do not transcribe conditions, treatments, allergies, diagnoses, pregnancy or other medical details into questionnaires, comments, notes, free-text fields or documents uploaded to Skintrace. An oral discussion should not become a medical report stored in the client record.
4. Check identity without keeping unnecessary copies
Where a visual check is sufficient, prefer it to retaining a complete copy or photograph of an identity document. You can record that identity was checked, the document type, the date and the person who checked it without copying unnecessary information.
The technical ability to store a document does not itself justify collecting it. If you retain a copy, you must be able to explain its necessity and legal basis, inform the person, restrict access and set a proportionate retention period.
5. Apply the rules for minors
Check the age requirements, the minor’s identity and, where necessary, their legal representative’s identity. Determine the authorisations, supporting documents and attendance requirements under the rules applicable to your activity and the service.
Do not treat a completed form as automatic permission to perform a service. You remain responsible for the required checks and restrictions. Keep supporting documents to the minimum needed.
6. Distinguish different kinds of consent
Consent to a procedure, the legal basis for processing personal data and permission to receive marketing are separate matters. A signed form does not automatically resolve all of them.
Providing an email address for an appointment confirmation or reminder does not, by itself, authorise advertising. Clearly inform people and obtain the permissions needed for each use.
7. Explain your studio’s conditions
Set out your rules for accompanying people, minors, lateness, cancellations, missed appointments, rescheduling, required documents and payment. Make them understandable and accessible before booking.
Skintrace’s portal terms do not replace your studio’s own conditions. You are responsible for their content and compliance with applicable rules.
8. Keep booking information up to date
Check the services offered, their duration and prices, time slots, opening hours and operator availability. Indicate whether appointments are confirmed immediately or require your approval.
Explain how bookings can be changed or cancelled. In the current portal version, booking does not involve an online payment to Skintrace: payment for the service is made directly to the professional.
9. Separate record photographs from advertising
A photograph kept to document a service or follow-up is not automatically available for your website, social media or advertising. Define each use separately, inform the client and obtain the necessary permissions.
Take particular care with minors, the areas of the body photographed and information that could identify someone. Limit access and retention to the stated purpose.
10. Secure your team’s access
Use individual accounts, strong passwords and permissions suited to each person’s tasks. Avoid shared credentials and unnecessary administrator privileges.
Promptly remove access when someone leaves the studio. Lock unused devices and keep software up to date.
11. Protect the confidentiality of records
Restrict records to people who need them, particularly when they contain contact details, identity documents, information about minors, photographs, signatures, consent forms or parental authorisations.
Confidentiality also applies to downloads, printouts and emails. Check recipients before sending, protect exported files and do not leave documents accessible to the public.
12. Define retention periods
Set a period for each category: appointments, service records, consent forms, photographs, parental authorisations and supporting documents. Consider their purpose, your obligations and applicable time limits; one period does not suit every document.
Do not keep everything indefinitely. Arrange deletion or restricted archiving where necessary, taking your Skintrace plan’s limits into account. Recover documents you must keep before your access ends.
13. Respond to client requests
As controller, you are your clients’ contact for requests for access, correction, erasure, restriction, objection, portability or withdrawal of consent, subject to the applicable conditions.
Define a contact and a process for handling requests. Verify identity when necessary without routinely requesting a copy of an identity document. Skintrace can assist with technical matters within its processor role.
14. Respond promptly to incidents
Contact Skintrace promptly if you suspect a compromised account, unauthorised access, a leak, a message sent to the wrong recipient or unusual behaviour. Restrict the affected access and avoid increasing the exposure.
Keep the useful facts: date, circumstances, data and people potentially affected, and measures taken. Assess your obligations to notify authorities and affected individuals; informing Skintrace does not replace them.
15. Keep practical GDPR documentation
Document your studio’s processing, client notices, legal bases, retention periods, security measures and providers. Plan how you handle rights requests, incidents and the processing relationship with Skintrace.
Adapt these documents to your actual activity. This guide and Skintrace’s privacy policy replace neither your own client privacy notice nor the applicable data-processing agreement.
16. Ten habits to remember
- Ask only for necessary information.
- Do not record medical information shared orally.
- Prefer identity checks without unnecessary copies.
- Apply the safeguards required for minors.
- Inform clients before collection and booking.
- Keep scheduling information up to date.
- Use protected individual accounts.
- Restrict access to records and exports.
- Separate record photographs from advertising use.
- Respond to and report incidents promptly.
17. Remember who is responsible for what
Skintrace is responsible for its role as the technical platform provider and its own obligations. You remain responsible for your activity, services, conditions, appointments and the data you request from clients.
Good use combines a suitable tool, sound professional practices and clear information. Software alone does not guarantee your studio’s compliance.
A technical question or an incident? Contact Skintrace.
skintrace.pro@gmail.com