Privacy Policy
Rejuvené Beauty Mobile Application
1. Introduction
Welcome to the Rejuvené Beauty mobile application ("App"). This Privacy Policy explains how Rejuvene Beauty Clinic ("we," "us," or "our") collects, uses, shares, and protects your personal information when you use our App, available on iOS (Apple App Store) and Android (Google Play Store).
We are committed to protecting your privacy and ensuring transparency about our data practices. This policy complies with the General Data Protection Regulation (GDPR) (EU) 2016/679, Greek data protection laws, and the requirements of both Apple's App Store and Google Play Store.
By downloading, installing, or using the Rejuvené Beauty App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the App.
2. Data Controller
The data controller responsible for your personal data is:
Rejuvene Beauty Clinic
Location: Greece, European Union
Website: rejuvene.gr
Email: info@rejuvene.gr
Data Protection Inquiries: privacy@rejuvene.gr
As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring compliance with applicable data protection laws.
3. Data We Collect
We collect the following categories of personal data to provide and improve our services:
3.1 Account Information
| Data Type | Purpose | Required |
|---|---|---|
| Full name (first and last name) | Account identification, appointment booking, personalized service | Yes |
| Email address | Account login, appointment confirmations, important notifications | Yes |
| Phone number | Appointment reminders, urgent communications, account verification | Yes |
| Date of birth | Age verification, treatment eligibility, birthday offers | Yes |
| Gender | Service personalization, treatment recommendations | Optional |
| Physical address | Service delivery, invoicing, location-based services | Optional |
| Profile photo | Account personalization, staff identification | Optional |
3.2 Service-Related Data
- Appointment history: Records of your bookings, including dates, times, services, and assigned staff
- Loyalty program data: Points earned, redeemed rewards, transaction history
- Communication records: Chat messages with clinic staff, support inquiries
- Preferences: Favorite services, preferred staff members, communication preferences
3.3 Technical Data
- Device information: Device type, operating system version, unique device identifiers
- App usage data: Features used, navigation patterns, session duration
- Push notification tokens: For delivering appointment reminders and updates
- Authentication data: Login timestamps, authentication method used
4. Sensitive & Health Data
⚠️ Special Category Data
Under GDPR Article 9, health-related data requires explicit consent and additional protections. We process this data only with your explicit consent and solely for providing safe beauty treatments.
To ensure your safety during beauty and aesthetic treatments, we may collect:
| Health Data Type | Why We Need It |
|---|---|
| Known allergies | To avoid products or treatments that could cause adverse reactions |
| Relevant medical notes | To customize treatments safely (e.g., skin conditions, medications affecting treatment) |
| Treatment history | To track your progress and avoid contraindicated procedures |
| Equipment settings | To maintain consistency and safety across treatments |
Your Consent: During registration, you will be asked to provide explicit consent for the processing of health-related data. You may withdraw this consent at any time, though this may affect our ability to provide certain treatments safely.
5. App Permissions
The Rejuvené Beauty App requests the following device permissions:
| Permission | Purpose | When Requested |
|---|---|---|
| Camera | To capture profile photos directly within the app | When you choose to take a new profile photo |
| Photo Library | To select existing photos for your profile | When you choose to upload a profile picture |
| Face ID / Biometrics | For secure, convenient login authentication | When you enable biometric login in settings |
| Push Notifications | For appointment reminders, booking confirmations, and important updates | During initial app setup or in notification settings |
Your Control
All permissions are optional and requested only when needed. You can manage these permissions at any time through your device settings. Denying permissions may limit certain app features but will not prevent you from using core booking functionality.
6. How We Use Your Data
We process your personal data for the following purposes:
6.1 Service Delivery
- Creating and managing your user account
- Processing appointment bookings and modifications
- Providing personalized treatment recommendations
- Enabling real-time chat communication with clinic staff
- Managing your loyalty points and rewards
6.2 Communication
- Sending appointment reminders and confirmations
- Notifying you of booking changes or cancellations
- Responding to your inquiries and support requests
- Sending service-related updates (e.g., clinic hours changes)
6.3 Marketing (with your consent)
- Promotional offers and special discounts
- New service announcements
- Seasonal campaigns and birthday offers
- Newsletter communications
6.4 Safety & Improvement
- Ensuring treatment safety through health data review
- Preventing fraud and unauthorized access
- Analyzing usage patterns to improve app functionality
- Maintaining audit trails for regulatory compliance
7. Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
| Processing Activity | Legal Basis (GDPR Article 6) |
|---|---|
| Account creation and management | Contract performance (Art. 6(1)(b)) |
| Appointment booking and service delivery | Contract performance (Art. 6(1)(b)) |
| Health data processing | Explicit consent (Art. 9(2)(a)) |
| Push notifications (service-related) | Legitimate interest (Art. 6(1)(f)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Fraud prevention and security | Legitimate interest (Art. 6(1)(f)) |
| Legal and tax compliance | Legal obligation (Art. 6(1)(c)) |
| Loyalty program management | Contract performance (Art. 6(1)(b)) |
8. Data Sharing & Third Parties
We do not sell your personal data. We share your information only with trusted service providers necessary to operate our services:
8.1 Service Provider Categories
| Service Category | Purpose | Data Location |
|---|---|---|
| Cloud Infrastructure Provider | Secure hosting and data storage | European Union |
| Email Service Provider | Transactional emails (confirmations, reminders) | EU/US (with SCCs) |
| Mobile App Distribution Platform | App updates, builds, and distribution | EU/US (with SCCs) |
| Platform Push Notification Services | iOS and Android push notifications | Platform provider infrastructure |
Sub-Processor Information
A detailed list of our current sub-processors, including specific vendor names and their data processing locations, is available upon request. Please contact privacy@rejuvene.gr to request this information.
8.2 Data Processing Agreements
All third-party service providers are bound by Data Processing Agreements (DPAs) that ensure:
- Processing only on our documented instructions
- Appropriate security measures
- Confidentiality obligations
- Assistance with data subject rights
- Data deletion upon termination
8.3 Other Disclosures
We may disclose your data when required by:
- Greek law or EU regulations
- Court orders or legal proceedings
- Requests from competent supervisory authorities
- Protection of our legal rights or safety
9. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account data (profile information) | Duration of active account + 30 days after deletion request | Service provision |
| Appointment and treatment history | 7 years from last appointment | Greek tax and medical record requirements |
| Chat messages | 2 years | Customer service, dispute resolution |
| Loyalty program data | Duration of account + 2 years | Program management, auditing |
| Audit and security logs | 1 year | Security monitoring, compliance |
| Marketing consent records | Duration of consent + 3 years | Proof of consent (GDPR compliance) |
| Invoices and financial records | 10 years | Greek tax law requirements |
After the retention period expires, your data will be securely deleted or anonymized for statistical purposes.
10. Security Measures
We implement comprehensive technical and organizational measures to protect your personal data:
10.1 Technical Security
- Encryption in transit: All data transmitted between the App and our servers is encrypted using HTTPS/TLS 1.3
- Encryption at rest: Sensitive data stored in our databases is encrypted using AES-256
- Authentication: Secure JWT-based authentication with refresh token rotation
- Biometric security: Optional Face ID/fingerprint authentication for enhanced account protection
- Password requirements: Enforced minimum complexity standards for account passwords
10.2 Organizational Security
- Staff training on data protection and confidentiality
- Role-based access controls limiting data access to authorized personnel
- Regular security assessments and vulnerability testing
- Incident response procedures for potential data breaches
- Secure development practices following OWASP guidelines
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Hellenic Data Protection Authority within 72 hours and inform you without undue delay, as required by GDPR Articles 33 and 34.
11. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights regarding your personal data:
Right of Access (Art. 15)
Request a copy of all personal data we hold about you, including the purposes of processing and recipients of your data.
Right to Rectification (Art. 16)
Request correction of inaccurate personal data or completion of incomplete data. You can update most information directly in the App.
Right to Erasure (Art. 17)
Request deletion of your personal data ("right to be forgotten") when it's no longer necessary or you withdraw consent.
Right to Restriction (Art. 18)
Request limitation of processing while we verify accuracy or assess legitimate grounds for processing.
Right to Data Portability (Art. 20)
Receive your personal data in a structured, commonly used, machine-readable format and transfer it to another controller.
Right to Object (Art. 21)
Object to processing based on legitimate interests or for direct marketing purposes at any time.
Right to Withdraw Consent (Art. 7)
Withdraw consent at any time for processing activities based on consent, without affecting prior lawful processing.
Right to Lodge a Complaint
File a complaint with the Hellenic Data Protection Authority (HDPA) at www.dpa.gr.
How to Exercise Your Rights
You can exercise your rights in the following ways:
- In-App: Access Settings → Privacy → Manage My Data to view, edit, export, or delete your data
- Email: Send your request to privacy@rejuvene.gr
- In Person: Visit our clinic with valid identification
We will respond to your request within 30 days. This period may be extended by two further months for complex requests, in which case we will inform you within the first month.
12. Age Restrictions
18+ Only
The Rejuvené Beauty App is intended solely for users aged 18 years and older. We do not knowingly collect personal data from individuals under 18.
During registration, you must confirm that you are at least 18 years old. If we discover that we have inadvertently collected data from a minor, we will promptly delete such information and terminate the associated account.
If you believe a minor has provided us with personal data, please contact us immediately at privacy@rejuvene.gr.
13. International Data Transfers
Your personal data is primarily stored and processed within the European Union, using infrastructure located in EU data centers.
When we use service providers located outside the EU/EEA, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs): EU-approved contractual terms ensuring adequate data protection
- Adequacy Decisions: Transfers to countries recognized by the European Commission as providing adequate protection
- Privacy Shield successor frameworks: Where applicable and valid
You may request information about the specific safeguards used for any international transfer by contacting us.
14. Cookies & Tracking Technologies
The Rejuvené Beauty mobile App does not use cookies in the traditional web browser sense. However, we may use similar technologies:
- Local storage: To save your preferences and session data on your device
- Device identifiers: For push notification delivery and fraud prevention
- Analytics data: Anonymous usage statistics to improve app performance
We do not use third-party advertising trackers or sell your data to advertisers.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons.
When we make changes:
- Minor changes: We will update the "Effective Date" at the top of this policy
- Significant changes: We will notify you via push notification, email, or in-app notice before the changes take effect
- Material changes to health data processing: We will request renewed consent where required
We encourage you to review this policy periodically. Your continued use of the App after changes become effective constitutes acceptance of the updated policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Rejuvene Beauty Clinic
General Inquiries: info@rejuvene.gr
Privacy & Data Protection: privacy@rejuvene.gr
Website: rejuvene.gr
Supervisory Authority
You have the right to lodge a complaint with the Greek supervisory authority:
Hellenic Data Protection Authority (HDPA)
Address: Kifisias 1-3, 115 23 Athens, Greece
Phone: +30 210 6475600
Website: www.dpa.gr
Email: contact@dpa.gr