Privacy Policy
Last updated: May 30, 2026
At Dermafix, we are committed to protecting the privacy and security of your personal data. This privacy policy describes how we collect, use, and safeguard your personal information when you use our online booking platform and clinical services.
1. Information We Collect
We collect personal information that you voluntarily provide to us when scheduling an appointment, including your full name, email address, phone number, treatment preferences, appointment history, and any clinical notes or sensitivities you disclose to help us perform your sessions safely.
2. How We Use Your Information
Your data is used strictly to register and schedule your treatments, send transactional confirmations and digital tickets via Resend, secure online payment deposits through Stripe, and synchronize appointment bookings securely to our specialists' internal Google Calendars. We never sell or share your personal data with third-party advertisers.
3. Google Calendar & Data Sync
To provide a seamless scheduling system, our backend integrates with Google Calendar API using a secure, closed Google Cloud Service Account. Only the client's name, selected treatments, and duration are synced to the practitioner's internal calendar. No private financial logs or sensitive medical histories are shared with external Google APIs.
4. Data Security
We implement industry-standard administrative and technical security measures (including SSL/TLS encryption, secure MongoDB database tokens, and PCI-DSS compliant Stripe payment gateways) to protect your personal data from unauthorized access, modification, or disclosure.
5. Your Rights Under GDPR
Under the General Data Protection Regulation (GDPR), you have the right to access the personal information we hold about you, request corrections to inaccurate data, or request the complete deletion of your customer profile from our records. To exercise these rights, please contact us at info@dermafix.nl.
