Introduction
We are committed to protecting the privacy and security of our clients’ personal information. This Policy explains how we collect, use, and disclose personal information provided by our clients through our global online mole check service operated from the UK. For detailed information regarding the data processing related to our services, please read this privacy notice.
The data controller
Dermatic Ltd (incorporated in England, Company Registration Number: 08475464 hereinafter referred to as “We“, “Our” or “Data Controller“).
Our contact details: contact@onlinemolecheck.com
Purpose and legal basis of the processing, the retention period
Please find detailed information below on the data processing activities of the Data Controller.
Purpose of the processing |
Affected data |
Legal basis |
Retention period |
To register on our website |
identity data, contact data, address, information regarding your skin |
Art. 6 (1) b) GDPR – performance of a contract (in order to provide you with our services) and Art. 9 (2) a) GDPR – consent You have the right to withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. |
15 years in line with the applicable legal regulations |
To provide you with our services (e.g. mole check) |
images you send us |
Art. 6 (1) b) GDPR – performance of a contract (in order to provide you with our services) and Art. 9 (2) h) GDPR – consent You have the right to withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. |
15 years in line with the applicable legal regulations |
To analyse data and images for scientific purposes |
Data collected during the mole check and the images received from the data subject |
Art. 6 (1) a) GDPR – consent And Art. 9 (2) a) GDPR – consent You have the right to withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. |
15 years in line with the applicable legal regulations |
To provide you with our services (e.g. mole check) and to receive the respective fees |
payment data |
Art. 6 (1) b) GDPR – performance of a contract (in order to provide you with our services) |
15 years in line with the applicable legal regulations |
To manage communication with you if you contact us (providing information on our services, information requests, concluding contracts) |
identity data (e.g. name, username) contact data (e.g. email, phone number) content of such communications |
Art. 6 (1) f) GDPR – legitimate interest of the Controller (to ensure flawless communication with the clients) |
until it is necessary for the purpose of the processing but no more than 5 years (general statutory limitation period) |
To administer and protect our business, service and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data) |
identity data (e.g. name, username) contact data (e.g. email, phone number) technical data |
Art. 6 (1) f) GDPR – legitimate interest of the Controller (to carry out business, provision of IT and administrative services, network security, prevention of fraud) |
until it is necessary for the purpose of the processing |
To use data analytics to improve our website, service, marketing, customer relationships and experiences |
technical usage data |
Art. 6 (1) f) GDPR – legitimate interest of the Controller (to define the relevant clients, to keep the website up-to-date, business developments, to develop our market strategy) |
until it is necessary for the purpose of the processing |
To contact you and send you via electronic means (such as e-mail, text messages, MMs, private messages etc.) newsletters, information about the services of the Controller, to make suggestions and recommendations to you about services that may be of interest to you |
identity data (e.g. name, username) contact data (e.g. email, phone number) profile data |
Art. 6 (1) a) GDPR – consent You have the right to withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. |
until the withdrawal of consent; or in case of inactivity, 1 year after the last activity performed with regard to the Controller |
Complaint handling (to manage quality complaints concerning the services provided by the Controller, to investigate the complaints, request information, draft the minutes, and take the necessary measures) |
identity data (e.g. name, username, complaint ID) contact data (e.g. email, phone number)content of the complaint |
Art. 6 (1) b) GDPR – performance of a contract |
until it is necessary for the purpose of the processing but no more than 5 years (general statutory limitation period) |
All references to GDPR shall also mean the similar provisions of the data protection laws of the UK.
In case your personal data is necessary to fulfil a legal obligation or to conclude / perform an agreement and you refuse to provide your data, then the Data Controller might not be able to perform the agreement (i.e. the provision of the service is not possible).
Data recipients, data processors
The following data processors are engaged in the processing:
-
Client facing website hosting:
Paragon Internet Group Limited, registered number 07573953, registered address 5th Floor, The Shipping Building, Old Vinyl Factory, 252-254 Blyth Road, Hayes, UB3 1HA.
-
Firewall protected safe data storage:
Company name: OfficeLink Kft.
Address: 1138 Budapest, Váci út 188.
Tax code: HU23596175
Company number: Cg. 01-09-194726
Email: info@officelink.hu
International data transfers
The data controller transfers data to the following third countries: Hungary.
Your rights
Right |
Meaning |
Right to access |
You have the right to access your personal data, including requesting information on whether we processes your data, which data are processed, etc. |
Right to rectification |
You have the right to the correction of your personal data. This enables you to ask that any incomplete or inaccurate data we hold about you be corrected. |
Right to erasure |
Subject to certain conditions and in certain cases, you have the right to the erasure of your personal data. This means that you may request that we delete your personal data that we may have processed unlawfully or where the use of your data is no longer needed for a purpose. Please keep in mind that we may not be able to meet your request for specific medico-legal reasons that will be notified to you, if applicable. |
Right to restriction of the processing |
You may also request the restriction of the processing of your personal data. For instance, you may request that we suspend the processing of your personal data where our use of the data is unlawful, but you do not want us to delete it. We restrict the processing of your personal data for a period to verify the accuracy of such data if you request to obtain the restriction of the processing of your personal data, and you challenge the accuracy of such data. We restrict the processing of your personal data if you request to obtain the restriction of the processing of such data, the processing of which is unlawful, and you oppose the erasure of such data. We restrict the processing of your personal data if we do not need such data for the purposes of the processing, but you require your data for the establishment, exercise or defence of legal claims. We restrict the processing of your personal data if you object to the processing of your personal data that are necessary for the purposes of the legitimate interests that we pursue, and you wait to verify that the processing of your personal data has a legitimate ground that does not override your objection. |
Right to data portability |
Where the processing of your data is either based on your consent, or is necessary for the performance of a contract, you may request the provision of your personal data that you have provided to us in a standard format, and you may also request that such data be transferred to another entity. Portability of your data doesn’t mean the erasure of your data from our systems. Also see the Right to erasure section. |
Right to object |
Importantly, when we process your data on the basis of our legitimate interests you may object to such processing and request that any of those activities be stopped. In such cases we shall no longer process your personal data, unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims. |
Right to withdraw your consent |
You may withdraw your consent at any time (under the following contact details) where we rely on your consent for processing your data. Remember that the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Email: contact@onlincemolecheck.com Per post: Dermatic Ltd, 46 Stamford Brook Road, London W6 0XL UK By clicking on the unsubscribe link place in the footer of each newsletter. |
Right to lodge a complaint |
Without prejudice to any other administrative or judicial remedy that you may have (such as the right to claim compensation for damages suffered as a result of our breach of the GDPR), you have the right to lodge a complaint with a data protection supervisory authority in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of personal data relating to you infringes the GDPR. For the contact details of the data protection authorities, please visit the following websites: https://edpb.europa.eu/about-edpb/about-edpb/members_en#member-hu or in case of the UK: https://ico.org.uk/ |
You will be notified about our changes to our Privacy Notice after logging into our website.