Privacy Policy

1. Introduce

This Privacy Policy explains how Skindex Tech Co Ltd (“Skindex” or “we”) collects, stores, uses, transmits and shares the Personal Data of users (“you”) in connection with to the Skindex mobile application, and the Skindex.vn website including any products and services related to the website (“Site”) (collectively “Services”). Skindex Tech Co Ltd is the “data controller”.

We reserve the right to change and may change this Privacy Policy from time to time. If we make material changes, we will notify you by email (sent to the email address you provided when registering), through the App by presenting to you a new version of this Privacy Policy. If permitted by applicable law, your continued use of the Services after the updated version of the Privacy Policy becomes effective constitutes your acceptance of the modifications in the new Privacy Policy. In some cases, you can choose whether to explicitly accept changes to the Privacy Policy. If you do not accept the terms of the Privacy Policy, please do not use the Services.

Please see the Privacy Policy posted on our Website and in the App for the most recent updates on our data security practices.

 

2. Personal data we collect from you

We collect Personal Data about you in a variety of ways. Sometimes we collect Personal Data automatically when you interact with the Services, and sometimes we collect Personal Data directly from you. From time to time, we may receive Personal Data about you from other sources and third parties.

2.1. Personal data that you directly provide to us:

General information. When you register to use the Service, we may collect Personal Data about you such as:

Images of the face and facial lesions (including but not limited to: acne, pigmentation disorders, pores, wrinkles, red skin,..

Full name;

Email address;

Year of Birth;

Password or passcode;

Place of residence and related location information, including time zone and language;

Physical and mental health. When you register to use the Services, you may choose to provide Personal Data about your physical and mental health, such as:

Information about health status, pathology, pregnancy;

Other information about your physical and mental health, and related activities, including your personal life.

2.2. Personal data we collect automatically:

When you access or use the Services, we may automatically collect the following information:
Location information:

  • IP address;
  • Time zone;
  • Data about your use of the Services, including, for example:
  • Frequency of use;
  • The areas and features of the Service that you access or use; Engagement for specific features.
  • To collect this data and other information, we may use cookies and other tracking technologies.
  • Data from external sources. 

We may receive Personal Data about you from third parties. For example, we may collect information from third parties, to enhance or supplement existing user information, including to customize and personalize your experience, and for other purposes. statistics and analysis, as described below.

3. How we use your Personal Data

We will not collect and use your Personal Data without your knowledge. Depending on the type of Service features you use, we will process your Personal Data on one or more of the following legal bases on your consent. For example, on the registration screen when you give us your consent to process your

  • Personal Data;
  • Facial lesion photo data: We use artificial intelligence to analyze lesions and recommend a personalized report about your lesions
  • To carry out our contractual obligations to you to provide the Services to you;
  • Legitimate interests. We may process your Personal Data in connection with our interests in providing the Services to you, our commercial interests, including our interests in maintaining security and integrity. integrity of the Services as well as broader social benefits;
  • Legal obligations. We may be required to process some of your Personal Data to comply with applicable laws and regulations.

4. Processing principles

  • Minimize data and limit purposes. 

We will not process Personal Data in a manner contrary to the purposes for which it was collected or subsequently authorized by you, or collect any Personal Data that is not necessary for the purposes stated. access. If we need to process your data for any other purpose, we will obtain your separate consent.
We do not disclose, do not sell, or rent your personal data. We will not disclose your Personal Data unless otherwise stated in this Privacy Policy.

  • Your privacy

No matter which country or region you come from, we are committed to providing you with a full range of privacy rights regarding your Personal Data.

  • What are those rights?

Editing Your Personal Data: If you believe that your Personal Data is inaccurate, you have the right to contact us to request correction of that Personal Data.
Limit processing: You have the right to request restriction of the processing of your Personal Data in certain circumstances. For example, you have the right to request restriction of your Personal Data if you are in doubt about the accuracy of your Personal Data and we will need some time to verify its accuracy.
Access to Your Personal Data (including in mobile form): You have the right to request information about what Personal Data we process about you, to access all of your Personal Data and to receive a copy of that data, in structured and portable form (.json file). For Skindex Premium users on iOS, the App also allows you to download a report including some of your Personal Data from within the App.
Delete your Personal Data: You can request that we erase your Personal Data if you withdraw your consent to processing if you believe that the processing is unlawful. Please note that deleting certain Personal Data may affect your experience using certain features of the Service that rely on historical data.
Right to object to the processing of your Personal Data: In some cases, you can object to the processing of your Personal Data, for example, if we process it on the basis of legitimate interests by contacting us at admin@skindex .VN

5. How to implement your privacy rights

Contact us at admin@skindex.vn to execute your privacy rights.
We will process your request within 30 days of receipt. In some cases, it may take up to 90 days, for example, to delete all of your Personal Data stored on our backup systems. We will let you know if we need more time and explain the reason for the delay.

  • What else?

Please note that if the request is unclear, we may contact you to better understand the request. We may also refuse to comply with clearly unfounded requests and excessive (repetitive) requests.
We may also ask you to verify your identity in some cases. We will typically verify whether the request was sent from the same email address you provided when you registered. In cases where you have not registered an account, we may require you to undertake additional verification measures to ensure we respond appropriately to the request.
Subject to applicable law, you may have the right to complain to your local data protection authority about any of our activities (relating to your privacy, or other rights). that you think is not in compliance with the regulations of Current law. If you have any concerns about our privacy practices, please contact us at admin@skindex.vn

6. Third parties process your Personal Data

We will not share your Personal Data with third parties except as set out below.

a. Process to find new users for Skindex and keep in touch with you

With your consent, we may share certain Personal Data excluding your image data for marketing and advertising purposes. We can reach you and people like you across multiple platforms, promoting Skindex widely.

b. Process data to enable the Application to function

In some situations, we use other companies to process your Personal Data on our behalf. We call these companies “processors”.
These processors are companies that help us operate the Services, assist us in communicating with you or perform other activities related to the Application. They may process certain Personal Data on our behalf to fulfill purposes related to the functionality of the Application and related activities. We remain responsible for any acts or omissions of processors and commit to enter into formal data processing agreements with these parties to the extent required by applicable law.

TypeInfrastructure – Security
Processing PartyAmazon Web Service

Data Processor Privacy Policy

AWS Privacy Policy 

Type of Collected Data                                                                                                 

All Personal Data

Objectives

Stores all personal data when you use the application

Type

Payment

Processing Party

Apple

Data Processor Privacy Policy

 

Apple Privacy Policy

Type of Collected Data

Payment and Banking Information
Personally Identifiable information

Objectives

To collect information and process application subscription payments

TypePayment, Calendar
Processing PartyGoogle
Types of data collected                                                                  Google Privacy Policy

Type of Collected Data

  • Payment and Banking Information
  • Personally identifiable information
  • Information about the user’s calendar
Objectives
  • To collect information and process application subscription payments
  • To book an appointment through Google

Type

Payment

Processing Party

VNPAY

Data Processor Privacy Policy

VNPAY Privacy Policy 

Type of Collected Data

  • Payment and Banking Information
  • Personally identifiable information

Objectives

To collect information and process application subscription payments

Type

Website, web service

Types of data collected                                                                                                                                                                                                                                                                                                                                                                               

When you use the Site and Web Services, certain third parties may collect information about your sessions and activities through cookies and other tracking technologies.

7. General information

We may aggregate, anonymize or de-identify your Personal Data so that it cannot reasonably be used to identify you. Such data will no longer be Personal Data. We may share such data with our partners or research facilities or use it for statistical purposes. For example, we may share or use general demographic information, age, and aggregate statistics about certain activities or symptoms from collected data to help identify trends in users in articles, blog posts, and scientific publications. Sharing this data will contribute to the advancement of scientific research on women’s skin care. Legitimate interests are our legal basis for processing your data for this purpose.

  • Information posted by you

The app has several community areas, such as Private Chats, where users with similar interests can share information and support each other.
Any information (including Personal Data) that you share in any online community area or online discussion is considered open data to the Skindex community. You should think carefully before posting any Personal Data in any public forum. What you post may be seen, disclosed to or collected by third parties and may be used by others in ways we cannot control or predict, including contacting you to carry out illegal purposes. If you mistakenly post Personal Data in our community areas and wish to have it removed, you may email us at admin@skindex.vn.

 
  • Special case

We may also share some of your Personal Data in the following special cases:
– To comply with subpoenas, court orders, or legal processes, to the extent permitted or limited by law (including to meet national security or law enforcement requirements) ;
– When disclosure is required to maintain the security and integrity of the Service or to protect user safety or the safety of others, as required by applicable law. In such cases, we may also delete some of your Personal Data (e.g. reset your password to avoid unauthorized access);
– Upon instruction or consent of the user who entered such Personal Data; In the event we undergo a business transition, such as a merger, divestiture, acquisition, liquidation or sale of all or a portion of our assets, your information will, in most cases, case, is part of the transferred assets.
Depending on the circumstances, we may consider legitimate interests or legal obligations as the legal basis for the above processing activities.

  • Retention of your Personal Data

Except as set forth below, we will retain your Personal Data for as long as necessary to provide you with the Services or fulfill the purposes for which the data was collected.
Impact of account deactivation/Personal Data deletion request: You may deactivate your account and delete your Personal Data at any time by sending an email to admin@skindex.vn. If you choose to deactivate your account, Skindex will generally delete all of your Personal Data, which will not be recoverable if you later create another account.
Impact of deleting an App or inactive account: If you choose to delete an App from your device or your account becomes inactive, we will retain your Personal Data for a period of 18 months to in case you decide to reactivate the Services or reinstall the Application. Apps serve different stages of the user lifecycle; Therefore, preserving your data is necessary
necessary in some cases to ensure you can enjoy other functions of the Application smoothly
Limitations: Please note that although we will anonymize or de-identify your data where feasible, we may retain some Personal Data and certain other information after your account is terminated or deleted as necessary to comply with legal obligations, resolve disputes, and perform agreements.

8. Security of your Personal Data

  • General security measures

– We take technical and organizational measures in an effort to protect Personal Data against loss, theft, misuse and unauthorized access, disclosure, alteration and destruction, taking into account the nature of the Personal Data we process and the associated risks of the special categories of Personal Data we collect (health information). These measures include using pseudonyms and tokenizing certain categories of your Personal Data.
– Encrypt your Personal Data during transmission and storage. – System vulnerability testing and penetration testing.
– Protect data integrity.
– Organizational and legal measures. For example, our employees may access your Personal Data at different levels, and only those responsible for data management have access to your Personal Data and only for for the limited purposes necessary to operate the Services. We will hold our employees strictly liable for any disclosure, unauthorized access, alteration, destruction, or misuse of your Personal Data.
– Conduct periodic assessments of the impact of data protection to ensure the Service fully complies with the principles of “security by design”, “security by default” and others. We are also committed to performing security checks in the event of a merger or transfer of Skindex.
Please understand that you can help keep your information secure by choosing and protecting your password appropriately, not sharing your password, and not letting others use your mobile device. However, no security system is perfect and therefore we cannot guarantee the absolute security of the Services and do not
We can ensure that your information will not be intercepted during transmission to us.

  • Security hole

If we discover a security system vulnerability, we may post a notice or attempt to notify you by email and will take reasonable steps to remediate the vulnerability as provided under applicable law. and this Privacy Policy. If we become aware of a Personal Data breach, in addition to other actions outlined in our Privacy Policy (such as notifying you in some cases), we will also take action. specifically to fix the vulnerability, if appropriate depending on the circumstances. These actions may include signing you out of all devices, resetting your password (sending you a temporary password to use), and performing other activities and actions reasonably necessary.
If you wish to report a security incident related to the Services, please contact us at admin@skindex.vn.

  • Exchange information with you

From time to time, we may contact you by email or otherwise (such as pop-up notifications or push notifications) to inform you about products, services, offers, promotions, rewards and events offered by us and others, as well as share news and information we think will be of interest to you.
You can always opt out of receiving emails by unsubscribing via the “Unsubscribe” link included in the email. By opting out of these emails or notifications, you will still receive important service-related emails necessary for your use of the Service. You can also opt out of receiving pop-up or push notifications by adjusting your device settings. Subject to applicable law, we may require some users to provide additional consent for these communications.
Please note, we may contact you to send you information about our products, services, offers, promotions, rewards and events as well as those of others through our platform. third parties (such as social networks). For more information, including instructions on how to opt-out, please see the section titled “Processes for finding new users for Skindex and keeping in contact with you” above.

9. Contact us

  • General information

If you have any questions or concerns about privacy, you can contact us at:
Skindex Tech Co Ltd, No. 21 corner 360/4 La Thanh, O Cho Dua, Dong Da, Hanoi, Vietnam. Email: admin@skindex.vn