
Privacy Information
Privacy Information
Miiskin Group ApS — Effective October 23th, 2026 for patients registered before September 18th, 2026, and upon registration for patients registered after the date.
This Privacy Information describes how Miiskin (“Miiskin,” “we,” “us,” or “our”) collects, uses, and shares your personal information when you use our website, mobile applications, and services (collectively, the “Service” or “Platform”). We are committed to protecting your privacy and handling your personal information in a transparent and secure manner. We process your personal data in accordance with this Privacy Information. Before using our Service, please read this document carefully. If you do not agree with how we process your personal data, please do not use the Service. Miiskin processes your personal data in compliance with the European General Data Protection Regulation (“GDPR”) and the Health Insurance Portability and Accountability Act (HIPAA).
Miiskin Group ApS (“Miiskin”) is a Danish, internationally operating company with headquarters in Denmark, which supplies the Service to users with needs hereof. The Platform allows registered users to self-examine their skin and moles by uploading images, and, in the United States and in Mexico, to share information with a dermatologist for a tele-dermatology consultation. Self-monitoring — keeping and comparing images of your own skin — is available to users wherever the Platform is offered. Tele-dermatology consultations with a board-certified dermatologist are available only in the United States and in Mexico. If you reside outside the United States and Mexico, you do not have a medical record on Miiskin, and the sections of this Privacy Information dealing with Consultations, medical records and dermatologists do not apply to you. Miiskin Group ApS is registered at Østerfælled Torv 4, 2100 København Ø, Denmark.
Your rights depend on where you reside. If you are in the United States, the rights described in Section 4 are those given by the privacy laws of your state, and by federal health information law where a medical record is involved. If you are in Mexico, your rights are those given by the Ley Federal de Protección de Datos Personales en Posesión de los Particulares, including your ARCO rights of access, rectification, cancellation and opposition. If you reside outside the United States and Mexico, your rights are those given by the data protection law that applies where you are, which for users in the European Union is the General Data Protection Regulation. Where a right is available only to users in one of these, this Privacy Information says so.
1 Information We Collect
We collect various types of information to provide and improve our Service.
1.1 How we describe the information in your account
Your account holds two kinds of information: the first is what you add for your own use, and the second is what you submit to a Consultation, together with what your dermatologist writes and supplies to you. The second part constitutes the medical record on Miiskin, which is owned by your dermatologist. The two parts are not stored separately; they sit together within your account and are separated logically, and the nature of the information determines what rights you have to control it. This Privacy Information uses three terms for these. The “Platform” means the software, systems, interfaces, and infrastructure Miiskin makes available. The Platform is Miiskin’s property. The Platform is not medical information and is not a medical record; what is treated as a medical record is the content stored on it.
Everyone who uses the Platform is a User. You become a patient when you request a Consultation, and you are the patient of the dermatologist you choose, not of Miiskin. Miiskin does not practice medicine and has no patients. Consultations are offered in the United States and in Mexico; if you are anywhere else you use the Platform for self-monitoring and you are a User, not a patient. A “Consultation” means a request you submit through the Platform to a board-certified dermatologist you have chosen, that dermatologist’s review of what you submit, and their response to you. A Consultation is the practice of medicine by that dermatologist, not by Miiskin. “Patient Data” means all information and images you submit to, or generate through, your own account, whether or not you also submit them to a Consultation. Patient Data is yours. You may permit any person to use your Patient Data, including an image that also forms part of your medical record. This Privacy Information governs how Miiskin handles it.
“Consultation Record” means the Patient Data you submit to a Consultation, together with the clinical content your dermatologist creates. The Consultation Record is your medical record. Your dermatologist authors it and their practice owns it, and Miiskin holds it on the practice’s behalf. Patient Data you submit to a Consultation remains yours and at the same time forms part of your medical record. Submitting it adds an obligation to keep it; it does not transfer ownership and it does not limit what you may permit. Once information forms part of your medical record it stays part of it, and it cannot be deleted or altered while your dermatologist’s obligation to retain the record continues. If you close your account, your access ends and the information you supplied outside your medical record is deleted. Your medical record remains. It is your dermatologist’s record of your care, they are required by law to keep it, and Miiskin holds it for them.
1.2 Personal Information
This includes information that can directly or indirectly identify you. The types of Personal Information we collect may include:
• Contact and Account Information: Your name, email address, phone number, mailing address, date of birth, and account login credentials. Upon signing up, users provide an email, birth year, and gender.
• Health Information (Consumer Health Data): “Consumer Health Data” means personal information that identifies your past, present or future physical or mental health status, and is the term used by the consumer health privacy laws of Washington, Nevada and Connecticut. As a service focused on skin health, we collect information related to your physical and mental health. This “Consumer Health Data” may include:
– Images of your skin, moles, or other dermatological conditions.
– Information you provide in health questionnaires, surveys, or during Consultations (e.g., medical history, symptoms, diagnoses, treatments, medications, lifestyle factors).
– Inferences drawn from your health data to create a profile about your health status or preferences.
– Precise geolocation data, if enabled, which may be considered sensitive if it indicates an attempt to acquire or receive health services.
• Demographic Information: Such as your gender, racial or ethnic origin, and zip code.
• Payment Data: If you make payments via our Services, we may require that you provide your financial and billing information, such as billing name and address, credit card number or bank account information.
• Government-Issued Identifiers: In certain circumstances, for identity verification or legal compliance, we may collect government-issued identification numbers (e.g., driver’s license number, passport number, social security number) and images of such identification cards.
• Communications: Content of your communications with us, including emails, chat messages, and customer support inquiries.
• Purchase History: Information related to your purchases on the Platform.
1.3 Sensitive Personal Information
Certain categories of Personal Information are considered “Sensitive Personal Information” under various state laws due to their heightened risk if misused. This includes, but is not limited to:
• Health Information: As described above, including mental and physical health diagnoses, laboratory results, clinical conditions, and treatments.
• Precise Geolocation Data: Information that identifies your exact location.
• Account Log-in Details, Financial Account Information, Debit or Credit Card Numbers combined with security codes, passwords, or credentials allowing account access.
• Contents of a consumer’s communications when Miiskin is not the intended recipient.
• Pregnancy status.
The collection of Sensitive Personal Information is handled with the utmost care and in accordance with applicable laws, including GDPR’s requirements for special categories of personal data and HIPAA’s protections for Protected Health Information (PHI). Where the law that applies to you requires your express consent before we process sensitive personal information, including information about your health, we ask for it separately and record it.
1.4 Information Collected Automatically
When you use our Service, we automatically collect certain information about your device and usage:
• Device and Usage Data: Internet Protocol (IP) address, device identifiers (e.g., MAC address), device type, operating system, browser type, version, language settings, pages viewed, time spent on pages, access times, and referring URLs. We also collect data related to the use of the Platform, such as who images are shared with.
• Support Data: If you contact us for support or to lodge a complaint, we may collect technical or other information from you through log files and other technologies, some of which may qualify as Personal Data (e.g., Internet Protocol (“IP”) address). Such information will be used for the purposes of troubleshooting, customer support, software updates, and improvement of the Services in accordance with this Privacy Information. Calls with Miiskin may be recorded or monitored for training, quality assurance, customer service, and reference purposes.
• Cookies and Similar Technologies: We use cookies, mobile IDs, and similar technologies to collect information about your browsing activities, preferences, and interactions with our Service. This helps us personalize your experience, analyze usage patterns, and deliver relevant content.
1.5 Information from Third-Party Sources
We may obtain information about you from third-party sources, such as service providers, partners, or publicly available sources, to supplement the information we collect directly.
2 How We Use Your Information
We use your Personal Information and Sensitive Personal Information for the following purposes, based on appropriate legal bases as required by HIPAA and GDPR and other applicable privacy laws. Some of these purposes are necessary to provide the Service to you, and some are voluntary and happen only if you agree to them. Where a purpose is voluntary, this Privacy Information says so, and you can decline it without losing access to the Service. If we want to use information we already hold for a purpose that is not described here, we will ask for your consent first.
• Managing User Relationship: Personal data is processed to manage user accounts and provide access to the Platform, based on the fulfillment of contractual obligations. This enables users to self-monitor their skin and moles and seek medical services by sharing data with their chosen medical practitioner.
• Processing Images and Metadata: Large images (full body, face, or large skin parts) and associated metadata are processed to facilitate core functionality, based on your explicit consent, which can be withdrawn at any time via App settings or by emailing [email protected].
• Platform Improvement and Development: Personal data, including skin and face images (if opted in), is used to deliver and improve the Platform, manage the business, develop new features, updates, personalization services, algorithms, and machine learning. This processing is based on Miiskin’s legitimate interest to improve its platform and services. This includes developing, training, testing and validating the software and models used in the Platform. How Miiskin may use your images for this purpose, and the limits that apply to it, are set out in Section 8 of our Terms of Service, and that Section governs.
• To Provide and Maintain the Service: To deliver the core functionalities of Miiskin, including processing your images, providing skin tracking features, and facilitating communication with healthcare professionals, including pharmacies and central laboratories, if applicable.
• To Improve and Personalize the Service: To understand how you use our Service, develop new features, enhance user experience, and tailor content and recommendations.
• To Communicate with You: To send you updates and notifications about the Service, to respond to your inquiries, and to send you other communications where you have consented to receive them or where the law permits us to. Communication and notification settings can be changed in the App settings. For support inquiries concerning these settings, please contact [email protected].
- Relevant information and invitations: Miiskin uses what it knows about you — including your age, where you are, the services you have used, and information about your skin, including your medical record — to work out which information, surveys, product assessments and campaigns are likely to be relevant to you, so that we contact you only about things that might actually matter. If we conduct an assessment on behalf of another organization, and they pay us to run such activity, we will tell you so when we invite you. We do not share your personal information with them in any form that identifies you. Taking part is always optional and declining does not affect your care or your use of the Platform. This purpose is voluntary. You can decline it at any time by writing to [email protected], and we will stop using your information for it.
- Where this would involve information in your medical record, we do not rely on this Privacy Information. We ask for your permission separately, in a document of its own, at the time you have a Consultation and we can name the dermatologist’s practice whose record it is. We use your medical record for this purpose only if you give that permission, and you can withdraw it at any time.
• For Communicating with You: Miiskin sends two kinds of message. Transactional messages are those needed to provide the Service — sign-in links, security and account notices, payment and refund notices, replies to your support requests, messages from your dermatologist, and notifications about a Consultation or a prescription. They are part of the Service; you receive them by email while your account is open and cannot unsubscribe from them. Marketing messages are newsletters, surveys, offers, campaign invitations and information about Miiskin products and features; every marketing email carries an unsubscribe link, and unsubscribing stops marketing messages only. Any text message Miiskin sends is transactional; Miiskin does not send marketing text messages, and you can stop all text messages by replying STOP, though doing so means you will miss notifications about your care. This is described in full in the Section of the Terms of Service headed Electronic Communications, which also describes how Miiskin sends notices required by law.
• For Security and Fraud Prevention: To protect the security and integrity of our Service, prevent fraudulent activities, and ensure compliance with our terms of service.
• For Legal and Regulatory Compliance: To comply with applicable laws, regulations, legal processes, and governmental requests, including those under HIPAA and GDPR.
• For Research and Analytics: To perform internal research, analysis, and reporting to understand trends, improve our products, and for other business purposes. We may aggregate, de-identify, or anonymize your data for these purposes, and such aggregated or de-identified data may be used and disclosed to third parties and with external research partners. This does not extend to your images: Miiskin never shares an identifiable image with a third party without your consent, as set out in Section 8 of our Terms of Service. You may decline to have your data used for these purposes by opting out in the settings of our App. A current list of our partners can be found at https://miiskin.com/partners/.
• For Campaigns and Patient Stories: With your separate written permission, to use images and information you supply, and your story, in information and promotional material about Miiskin and the Platform, including material published publicly such as on social media or on our website. This purpose is voluntary. It happens only if you agree to it for a particular campaign, it is never a condition of your care, and you can withdraw your permission at any time. Withdrawal stops further publication but cannot recall material already published, and material that has been published may be copied or shared by others beyond Miiskin’s control. Where you take part, you choose which images to supply and Miiskin uses only what you supply. Campaigns are open to adults only. If you volunteer and are not selected, the permission you gave expires after ninety (90) days and the material you supplied for the campaign is deleted. Miiskin may ask you to complete a questionnaire when you volunteer, and the answers are used only to decide whom to select.
2.1 Data Minimization and Purpose Limitation
We adhere to principles of data minimization and purpose limitation, which are core tenets of GDPR and many U.S. state privacy laws. We collect and process only the Personal Information that is adequate, relevant, and limited to what is necessary for the disclosed purposes for which it is processed, in accordance with Article 5(1)(c) of the GDPR. For Sensitive Personal Information, our collection, processing, and sharing are limited to what is strictly necessary to provide or maintain the product or service you have requested. We will not collect data for purposes unrelated to the offered product or service, even with your consent, if such collection is not reasonably necessary and proportionate. The voluntary purposes described in Section 2 sit outside this paragraph, and we ask for your agreement to them separately.
3 How We Share Your Information
We may share your Personal Information with the following categories of third parties:
• Service Providers: We engage third-party companies and individuals to perform services on our behalf (e.g., hosting, data analysis, customer support, payment processing). These service providers are contractually obligated to protect your information and use it only for the purposes for which they were engaged, in line with GDPR processor requirements and HIPAA business associate agreements.
• Affiliates: Miiskin has no affiliates with access to your information. If that changes, we will name them in this Privacy Information before any access is given.
• Healthcare Professionals and Organizations: If you use features that connect you with healthcare professionals, we will share relevant health information with them to facilitate your care, in compliance with HIPAA and other applicable health data privacy laws. When images are transferred to doctors, other healthcare professionals, or third parties such as pharmacies and central laboratories, they become the data controller, and their privacy policy applies. Where your dermatologist issues a prescription, it is transmitted from the Platform to a third-party prescription service, and from there to the pharmacy you choose. Once a pharmacy receives your prescription it is responsible for that information in its own right, its own privacy notice applies, and its own retention rules govern how long it keeps it. Miiskin does not dispense medication and is not a pharmacy.
• Record of Your Choice About Electronic Notices: Where your dermatologist, or a health plan, hospital or other organization involved in your care or in paying for it, asks Miiskin for it, we provide the record of the choice you made about receiving notices electronically and of any withdrawal of that choice. We provide it on request only; there is no continuing feed of it. What that record contains, and how notice of a breach reaches you, are set out in Section 12.6.
• Payors: We may share your Personal Data and medical information with payors, including insurance companies and other reimbursement entities, to facilitate billing, claims processing, and payment for the services provided. This sharing is conducted in compliance with applicable laws and regulations, such as HIPAA, to ensure the privacy and security of your information.
• Professional Advisors: We may share your Personal Data with our lawyers, auditors, accountants, or banks when we have a legitimate business interest in doing so.
• Legal and Regulatory Authorities: We may disclose your information if required by law, subpoena, or other legal process, or if we believe it’s necessary to protect our rights, property, or safety, or the rights, property, or safety of others. This includes disclosures required by HIPAA or GDPR.
• Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred to the acquiring entity.
• Other Third Parties: We may share your information with other third parties when we have your explicit consent to do so.
Miiskin does not sell or transfer personal data for marketing purposes. We do not sell your Sensitive Personal Information.
3.1 International Data Transfers
Generally, Miiskin does not transfer your personal data out of the EU if it is stored there, or out of the USA if it is stored there, but you may share or transfer your personal data outside of the EU by using the sharing or transfer functionality that we offer you for your convenience. If you are in the United States, your information is stored in the United States. Miiskin is a Danish company and some of its staff work from Denmark and need access to the Platform in order to run, support and secure it. Four commitments apply to that access: the information stays stored in the United States; access from outside the United States is limited to Miiskin’s own staff and requires them to sign in; that access is logged; and everyone who has it completes HIPAA privacy and security training before it is granted. That access does not extend to anyone outside Miiskin. Where we transfer personal data internationally we implement appropriate safeguards, including GDPR’s requirements for international transfers (e.g., Standard Contractual Clauses).
4 Your Privacy Rights
You have certain rights regarding your Personal Information, subject to applicable state laws and GDPR. To exercise any of these rights, please contact us using the information in the “Contact Us” section. We will respond to a request under this Section within forty-five (45) days of receiving it. Where a request is complex, or where we receive a number of requests from you, we may extend that period by a further forty-five (45) days and will tell you if we do. Different periods apply to your medical record, and are described in the Sections titled Data Retention and Face Data Privacy.
4.1 Right to Access and Confirmation
You have the right to confirm whether we are processing your Personal Information and to access a copy of the Personal Information we hold about you. We do not charge for responding to a request under this Section. Where the law allows a reasonable, cost-based fee for an additional copy, we will tell you the amount before we proceed. Access to your medical record is never conditional on payment of any amount you owe.
4.2 Right to Correction
You have the right to request that we correct inaccuracies in your Personal Information, or to complete incomplete data, by updating your account.
4.3 Right to Deletion
You have the right to request that we delete your Personal Information, subject to certain exceptions. Miiskin will delete Patient Data that does not form part of your medical record on request, and you may close your account at any time. Your medical record is treated differently. It is governed by the laws that apply to medical information and to health care providers, rather than by the consumer privacy rights described in this Section, and the right to delete does not extend to it. Your dermatologist is required by law to retain it. A request concerning your medical record should be directed to your dermatologist, who decides what can be done; if you send such a request to Miiskin, we will direct you to them. If you request that any required Consumer Health Data be deleted or withdraw your consent for future collection or sharing of any required Consumer Health Data, we may not be able to provide the Service or certain features of the Service to you. Information you supply for your own use is held only by Miiskin and by the service providers that operate the Platform on our behalf. It is not disclosed to anyone else except where you have consented to a specific disclosure. When you ask us to delete it, it is deleted from our systems; where you have consented to a disclosure before then, we cannot recall a copy already provided to the recipient.
4.4 Right to Data Portability
If you are in the United States, and where technically feasible, you have the right to obtain a copy of the personal information you have provided to us in a portable and readily useable format that allows you to transmit it to another entity without hindrance. If you are in the European Union, you have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible. Your medical record, if you have one, is dealt with in Section 6; your dermatologist’s practice owns that record and a request for a copy of it should be directed to them.
4.5 Right to Opt-Out of Certain Processing Activities
You have the right to opt-out of the “sale” or “sharing” of your Personal Information, targeted advertising, and profiling that produces legal or similarly significant effects.
• Do Not Track (DNT): Some web browsers offer a “Do Not Track” (DNT) signal. There is no common understanding of how to interpret the DNT signal; therefore, our websites do not respond to browser DNT signals. Instead, you can use the range of other tools to control data collection and use, including the GPC, cookie controls, and advertising controls described above.
• Mobile Advertising ID Controls: iOS and Android operating systems provide options to limit tracking and/or reset the advertising IDs.
• Global Privacy Control (GPC): We recognize and respond to Global Privacy Control (GPC) signals or similar universal opt-out preference signals where required or widely acknowledged by regulation. If you use a GPC-enabled browser, we will make reasonable efforts to respect your choices indicated by a GPC setting or similar control that is recognized by regulation or otherwise widely acknowledged as a valid opt-out preference signal.
• Do Not Sell or Share My Personal Information: Miiskin engages in activities that may be considered “selling” or “sharing” of personal information under applicable state laws only where you have approved it. You may withdraw that approval and opt out at any time by contacting our privacy department at [email protected]. You are not required to create an account to exercise this right. If you opt out, we will not ask you to approve it again for at least twelve months.
4.6 Right to Limit the Use or Disclosure of Sensitive Personal Information
Where the law of your state gives you the right to limit the use or disclosure of Sensitive Personal Information, including the use of such information to infer characteristics about you, you may exercise that right by contacting us. See Section 14 (Compliance framework).
4.7 Right to Appeal
If we deny your privacy request, you may have the right to appeal our decision. If applicable, our response denying your request will provide information on how to submit an appeal.
4.8 Identity Verification
To protect your privacy and security, we may need to verify your identity before processing your request. This may involve asking you to verify information we already have on file for you. If we cannot verify your identity based on the information we have, we may request additional information, such as government identification, which will only be used for identity verification and security/fraud prevention purposes.
4.9 California Residents – “Shine the Light” Law
If you are a California resident, you may request and obtain from us, once a year, free of charge, a list of third parties, if any, to which we disclosed their Personal Data for direct marketing purposes during the preceding calendar year and the categories of Personal Data shared with those third parties. If you are a California resident and wish to obtain that information, please submit your request by sending us an email at [email protected] with “California Privacy Rights” in the subject line.
4.10 Nevada Residents
Nevada residents may contact us to inquire about your right to opt out of the sale of your Personal Information.
4.11 Right to Complain to Supervisory Authority
If you are in the European Union, you have the right to complain about our processing of your personal data to a supervisory authority, including the supervisory authority in the country where you live. Miiskin’s lead supervisory authority is the Danish Data Protection Agency: Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby. Phone no.: +45 33 19 32 00. E-mail: [email protected] If you are in Mexico, the authority responsible for personal data protection is the Secretaría de Anticorrupción y Buen Gobierno, and you may bring a complaint to it. A Spanish version of this Privacy Information is provided for users in Mexico.
5 Children’s Privacy
Account holders must be 18 or older. An adult may open an account and submit a Consultation on behalf of a child for whom that adult holds legal authority as a parent or legal guardian; in that case the adult is the account holder and the child is not a user of the Platform. By doing so you confirm that you hold that authority. Our Service is not directed to children and we do not permit a person under 18 to open an account. We do not knowingly collect Personal Information from children under 13 without verifiable parental consent, in compliance with the Children’s Online Privacy Protection Act (COPPA). If we learn that we have collected Personal Information from a child under 13 without appropriate consent, we will take steps to delete it. We may use a registration of age as a tool to try and prevent users under the legal age in the jurisdiction where the user resides to read content not rated for minors.
For minors between the ages of 13 and 17, certain state laws (e.g., New Jersey, Maryland) impose additional protections. We will not process or sell the Personal Information of consumers under the age of 18 for targeted advertising if we know, or should know, their age. If our Service is likely to be accessed by minors, we aim to implement privacy-by-design principles, including default privacy settings and parental controls where applicable. We also prohibit the collection of precise geolocation data of children unless strictly necessary for the service, collected for a limited time, and with clear notice and consent. These measures align with the spirit of GDPR’s heightened protections for children’s data.
6 Data Retention
We retain your Personal Information and Consumer Health Data only for as long as necessary to fulfill the purposes for which it was collected, including for the provision of the Service, to comply with legal obligations, resolve disputes, and enforce our agreements. Our data retention practices are guided by an internal data retention schedule that considers federal, state, industry-specific, country-specific, and international record-retention mandates, including those under GDPR and HIPAA. The period for which each category is retained is determined by the purpose for which it was collected: Patient Data and Consultation Records are retained as set out below; account and contact information is retained while your account is open and for twelve (12) months afterwards. Patient Data is retained for the period set out below, wherever you are. A Consultation Record exists only where you have had a Consultation, and Consultations are offered in the United States and in Mexico only; that record is retained for the period set out below. Where a health plan, hospital or other organization refers you to Miiskin, the referral information that organization sends to Miiskin is deleted no later than fifteen (15) months after Miiskin receives it. Other categories are kept only for as long as their purpose requires. Support and communications records are kept for as long as is needed to deal with your inquiry and anything arising from it. Device and usage data is kept for as long as is needed to keep the Platform secure and working properly. Payment records depend on what you paid for. Where you pay Miiskin for a Miiskin service, Miiskin is the merchant of record, holds that record, and keeps it for the period Danish bookkeeping and tax law requires. Where you pay for a Consultation, the dermatologist’s practice is the merchant of record and holds that payment record under the law that applies to them; Miiskin keeps only what it needs to operate the Platform and to meet its own obligations. If you are outside the United States and Mexico you cannot have a Consultation, so any payment record concerning you relates to a Miiskin service. Miiskin reviews these periods at least once every twelve months. Miiskin does not retain personal information for longer than is reasonably necessary for the purposes described in this Privacy Information.
Miiskin retains Patient Data so that you have a durable record of your own skin over time. Changes to skin, moles and lesions are often only detectable by comparison with earlier images, and a long baseline is of real clinical value if you later experience a problem. Miiskin therefore retains Patient Data for ten (10) years from the date you last add to it, and makes it available to you throughout that period. Miiskin may delete Patient Data before the end of that period where: you ask us to; your account is closed or your access is terminated; we are required to by law, or by a court, regulator or other authority; we discontinue the Platform, the relevant feature, or your account type; or we reasonably believe the content was submitted unlawfully or in breach of our Terms. Except where we are prevented from doing so by law, or where the account is closed at your request, we will give you not less than thirty (30) days’ notice before deleting Patient Data under this paragraph. We will send that notice to the email address held in your Miiskin account, and you will be able to export your Patient Data during the notice period. Your use of the Platform, including the storage of Patient Data, is subject to our Terms of Service. You may ask us to delete your Patient Data at any time, and we will do so. A Consultation Record is retained separately, and is not deleted when your account is closed or on request. Miiskin retains each Consultation Record for ten (10) years from your most recent Consultation, or, where you were a minor at the time of treatment, until the later of one (1) year after you reach the age of eighteen and ten (10) years from your most recent Consultation, on behalf of your dermatologist, who is responsible for meeting the record-keeping requirements that apply to them. Some personal data may be stored to comply with legal obligations. Updated information may have unrevised copies maintained in system backups for a period. Users can request account deletion by emailing [email protected] or using the in-app support function. Deleting your account removes your Patient Data from Miiskin servers, but does not remove a Consultation Record, which is retained for the period above. You must uninstall the app to remove data stored locally on your device. Some information may remain in records after deletion, and anonymized data (no longer personal data) may be retained indefinitely for business purposes.
7 Data Security
We implement appropriate technical and organizational measures to protect your Personal Information from unauthorized access, disclosure, alteration, or destruction. These measures include encryption, access controls, and regular security assessments, in accordance with the security principles of GDPR and the security rule requirements of HIPAA. Specifically, our website and mobile application employ the following data security measures:
• Your user account on our website is protected with an email verification.
• Access to our App on your phone is only restricted if you apply access protection to your phone.
• If you use our premium product, you can make use of a passcode provided with the premium version of the App, in particular to protect your large images.
• All images are stored encrypted on your phone to prevent other mobile applications from gaining access to your images.
• Only our App can decrypt the images for you to access and view.
• All images and other personal information that have been synched with our cloud are also encrypted when stored.
• All images and other personal information are encrypted when transmitted between your phone and our cloud solution (storage).
However, users should be aware that internet data transmissions, whether wired or wireless, cannot be guaranteed to be 100% secure. As a result, we cannot guarantee the security of information you transmit to us. By using the Services and transmitting data to our platform, you are assuming this risk of possible disclosure despite the security measures Miiskin uses to protect your information. Additionally, users should be aware that images exported from the App to the phone or from the website account are no longer encrypted/protected, and this export is the user’s sole responsibility.
7.1 Your Responsibilities for Data Security
You are solely responsible for protecting information entered or generated via the Services that is stored on your device and/or removable device storage. Miiskin has no access to or control over your device’s security settings, and it is up to you to implement any device-level security features and protections you feel are appropriate (e.g., password protection, encryption, remote wipe capability, etc.). We recommend that you take any and all appropriate steps to secure any device that you use to access our Services.
In addition, we will NEVER send you an email requesting confidential information such as account numbers, usernames, passwords, or social security numbers, and you should NEVER respond to any email requesting such information. If you receive such an email purportedly from Miiskin, DO NOT RESPOND to the email and DO NOT click on any links and/or open any attachments in the email, and notify Miiskin support at [email protected].
8 Service Provider Contracts
We require our third-party service providers and data processors to adhere to similar privacy and security standards through robust contractual agreements. These contracts ensure that they process your Personal Information only for specified purposes and implement appropriate safeguards, consistent with GDPR’s requirements for data processing agreements and HIPAA’s requirements for business associates.
9 Cookies and Other Technologies
Cookies are small files that a web server sends to your computer or device when you visit a website that uses cookies to keep track of your activity on that site. Cookies hold a small amount of data specific to that website, which can later be used to help remember information you enter into the website (like your email or other contact info), preferences selected, and movement within the site. If you return to a previously visited website (and your browser has cookies enabled), the website sends the small file to the web server, which tells it what activity you engaged in the last time you used the website, and the server can use the cookie to do things like expedite logging in and retrieving user data and keeping your browser session secure. For more information on the cookies Miiskin uses on our website, please review our Cookie Information.
We use essential cookies to provide user authentication and other technologies to, among other things, better serve you with more tailored information, and to facilitate efficient and secure access to the Service. Essential cookies are those necessary for us to provide Services to you. We may also collect information using pixel tags, web beacons, clear GIFs or other similar technologies. These may be used in connection with some Service pages and HTML-formatted email messages to, among other things, track the actions of users and email recipients, and compile statistics about usage and response rates. Cookies and similar technologies that are not essential to providing the Service are used only where you have consented, and you may withdraw that consent at any time through the cookie controls on our website or in the App. Miiskin does not permit any third-party tracking technology to receive the content of a Consultation Record, and does not permit a third party to receive Consumer Health Data through such a technology except where you have consented and any further authorization required by law has been obtained. Miiskin does not operate geofences around hospitals, clinics, pharmacies or other health care facilities, and does not use location data to identify people entering or leaving them.
9.1 How to Manage Your Cookies
Most web browsers let you choose whether to accept cookies. Most also let you delete cookies already set. The choices available, and the mechanism used, will vary from browser to browser. Such browser settings are typically found in the “options”, “tools” or “preferences” menu. You may also consult the browser’s “help” menu.
There are online tools available for clearing all cookies left behind by the websites you have visited, such as www.allaboutcookies.org. Usually, deletion of cookies will anonymize the information associated with the pixel and a website will not receive any further associated information.
Please note that if you choose to set your browser to remove cookies or reject cookies, or if you enable a “Do Not Track” (DNT) signal or otherwise configure your browser to prevent Miiskin from collecting any cookies, you may no longer be able to access certain features or the full functionality of the Service.
10 Responsible Entity / Data Controller
Miiskin acts in two capacities at the same time, and which applies depends on the information concerned. For Patient Data that is not part of a Consultation Record, Miiskin is the controller and is responsible for that information in its own right under this Privacy Information and applicable law. For a Consultation Record, your dermatologist is the health care provider responsible for it, and Miiskin holds it for them; your dermatologist’s own privacy notice governs how they use it, and you should refer to that notice. Both capacities apply concurrently to the same account. Miiskin will process your personal data in compliance with GDPR and HIPAA rules. Miiskin does not create, author, review, or approve any clinical content. Your dermatologist does, and is an independent practitioner who is not employed by Miiskin. Miiskin does not practice medicine.
11 Face Data Privacy
If you choose to take photographs of your face for the purpose of monitoring your skin, Miiskin will store those photographs to facilitate that purpose, so that you can refer to them over time and look for changes. When you take photographs of your face, the Platform detects the position of your head so that the image captures your facial contour and skin fully across the three required views. This detection happens on your device, guides image capture only, and is not retained after the photograph is taken. It is not used to identify you, is not used to verify your identity within the Platform or for any legal purpose, is not transmitted to Miiskin or to any third party, and no facial measurement or template is created or stored.
• If you choose to take photographs of your face to undertake a telehealth Consultation with your chosen medical provider, Miiskin will store your photographs so that your chosen medical provider can access them on the Platform and make a clinical assessment.
•Photographs of your face taken for the purpose of monitoring your skin are Patient Data and are retained as set out in Section 6.
• Photographs of your face taken to undertake a telehealth Consultation with your chosen medical provider will be stored for 10 years, to allow for compliance with legal requirements for medical record keeping that allow tracing and medical audits.
• Photographs of your face will be shared with our data storage partner (currently IBM) for them to store the photographs and back them up on your behalf. IBM comply with HIPAA and GDPR laws controlling the use and storage of facial data and Miiskin have an agreement with IBM to verify this.
• Photographs of your face will also be shared with your chosen provider of medical services if you provide explicit consent for the purpose of them medically assessing the images you provide. If you agree to their privacy policy, your chosen medical service provider may store your personal data including images you share with them (and face images) in their own systems for the purposes of medical record keeping as required by applicable laws. All medical providers who use the Platform comply with HIPAA laws controlling the use and storage of facial data. They all enter into an agreement with Miiskin to verify this.
12 HIPAA Privacy Information
This section describes how Miiskin (“Miiskin”) collects, uses, and shares your Protected Health Information (PHI) as a HIPAA Business Associate in accordance with the Health Insurance Portability and Accountability Act (HIPAA) as amended, including, without limitation, amendments by the Health Information Technology for Economic and Clinical Health (HITECH) Act (collectively, “HIPAA/HITECH”).
Miiskin sends and receives your PHI with your HIPAA Covered Entity, with whom you have a relationship for health care services, to perform certain functions or services on behalf of the Covered Entity.
12.1 Definitions
• Business Associate: An entity that performs functions or activities on behalf of a Covered Entity when those services involve access to, or the use or disclosure of, Protected Health Information. For the purpose of this Policy, Miiskin is the Business Associate.
• Business Associate Agreement (BAA): A formal written contract between a Business Associate and a Covered Entity that requires the Business Associate to comply with specific requirements related to PHI.
• Covered Entity: A health plan, healthcare provider, or healthcare clearinghouse. For the purpose of this Policy, a dermatologist or other physician delivering services to patients in the United States, who signs up to Miiskin’s telemedicine platform, is a Covered Entity. Where a health plan, hospital or other organization refers you to Miiskin, that organization is also a Covered Entity in respect of the referral information it sends, and Miiskin holds that information for it as a Business Associate under a separate Business Associate Agreement with that organization. The two relationships are distinct and each is covered by its own Business Associate Agreement.
• Protected Health Information (PHI): Identifiable health information about you (such as your name, social security number, or address) that relates to (a) your past, present, or future physical or mental health or condition, (b) the provision of health care to you, or (c) your past, present, or future payment for the provision of health care.
12.2 Uses and Disclosures of PHI
Miiskin will use or disclose PHI on behalf of, or to provide services to, Covered Entities for purposes of performing our obligations under our services agreements to Covered Entities, provided that such use or disclosure is permitted or required by the applicable Business Associate Agreement and would not violate HIPAA, including its Privacy Rule or Security Rule as applicable to Business Associates.
Miiskin may use PHI only to the extent such use of PHI is permitted or required by Miiskin’s policies including, but not limited to, the applicable Business Associate Agreement and would not violate HIPAA, including its Privacy Rule or Security Rule as applicable to Business Associates. Miiskin may use de-identified data (i.e., data that does not identify an individual and cannot be re-identified) derived from PHI for the improvement of Miiskin service, in accordance with both HIPAA de-identification standards and the GDPR. Any such use will require either your explicit consent or another valid legal basis under the GDPR, which you may withdraw at any time.
Miiskin may disclose PHI for law enforcement purposes as required by law or in response to a valid subpoena.
Miiskin may disclose PHI to downstream subcontractors or agents that provide supporting services to us; however, Miiskin will require such subcontractors and agents to comply with the same terms and conditions that apply to us under the applicable Business Associate Agreement, and in any case in accordance with the main BAA with your Covered Entity, including the implementation and maintenance of required safeguards.
Other uses and disclosures not described in this Policy will be made only with your express written consent or authorization.
12.3 Your Rights (Specific to PHI under HIPAA)
The following rights apply to your Protected Health Information (PHI). For EU residents, these rights are in addition to your rights under the GDPR: We will act on a request for access to your PHI no later than thirty (30) calendar days after we receive it. If we cannot act within that period we may take one further thirty (30) days, and will tell you in writing before the first period ends, explaining the delay and when you will receive a response. A request to amend your PHI, or for an accounting of disclosures, is answered within sixty (60) days, with one thirty (30) day extension on the same basis. These periods are set by federal health information law and apply instead of the period in Section 4.
• Right to Access: You have the right to access and obtain a copy of your PHI that Miiskin maintains, with certain limited exceptions. We will provide your PHI in the form and format you reasonably request, including electronically where it is readily producible in that form. Any fee for a copy is limited to the cost of labor, supplies and postage, we do not charge a retrieval or processing fee, and access is never withheld because an amount is owed.
• Right to Request Restrictions: You have the right to request restrictions on our processing of your PHI, with certain limited exceptions. One restriction must be granted: if you pay in full, out of pocket, for a service, you may require that information about that service is not disclosed to a health plan, and that request will be honored.
• Right to Request Confidential Communications: You have the right to request that communication with you about your PHI is done in a certain way or at a certain location.
• Right to Request Amendment: You have the right to request the amendment of your PHI if you believe it is incorrect or incomplete, with certain limited exceptions.
• Right to an Accounting of Disclosures: You have the right to request an accounting of certain disclosures Miiskin has made of your PHI.
• Right to File a Complaint: You have the right to file a complaint with us or with the Secretary of Health and Human Services if you believe Miiskin has violated your privacy rights.
Miiskin will make available to Covered Entities information necessary for the Covered Entity to give individuals the ability to exercise their rights in accordance with HIPAA/HITECH regulations.
Upon request, Miiskin will make our internal practices, books, and records, including policies and procedures relating to the use and disclosure of PHI received from, or created or received by the Business Associate on behalf of a Covered Entity, available to the Covered Entity or the Secretary of the U.S. Department of Health and Human Services for the purpose of determining compliance with the terms of the BAA and HIPAA/HITECH regulations.
12.4 Our Responsibilities (as a HIPAA Business Associate)
As a Business Associate, Miiskin has a number of privacy responsibilities, including:
• Entering into written Business Associate Agreements with Covered Entities that require us to maintain the privacy of PHI, limit our use or disclosure of PHI to those purposes authorized by the Covered Entities, and assist Covered Entities in responding to your requests concerning your PHI;
• Amending your PHI when requested by a Covered Entity;
• Making certain disclosures available to a Covered Entity in order for the Covered Entity to fulfill its obligations to you and to provide you with accountings of such disclosures;
• Entering into a BAA with each of our subcontractors who may have access to your PHI;
• Complying with the HIPAA Privacy Rule provisions, including rules governing the uses and disclosure of PHI and your rights concerning your PHI;
• Performing a Security Rule risk analysis;
• Implementing Security Rule safeguards;
• Training personnel on the HIPAA Rules and sound compliance practices;
• Responding immediately to any security violation or breach;
• Timely reporting security incidents and breaches to appropriate parties; and
• Maintaining all required documentation.
12.5 Mitigation of Harm
In the event of a use or disclosure of PHI that is in violation of the requirements of the BAA, Miiskin will mitigate, to the extent practicable, any harmful effect resulting from the violation. Such mitigation will include the following:
• Reporting any use or disclosure of PHI not provided for by the BAA and any security incident of which Miiskin become aware to the Covered Entity;
• Documenting such disclosures of PHI and information related to such disclosures as would be required for the Covered Entity to respond to a request for an accounting of disclosure of PHI in accordance with HIPAA/HITECH.
12.6 How Notice of a Breach Reaches You
Where the law requires that you be notified of a breach of your health information, that notice reaches you in one of two ways. Where you have agreed to receive notices electronically and have not withdrawn that agreement, notice is sent by electronic mail to the email address on your account, in accordance with 45 C.F.R. § 164.404(d)(1)(i). Where you have not given that agreement, have withdrawn it, or your email address is not working, notice is sent to you by post, at no charge to you. You are asked to make this choice by a separate tick when you create your account, it is not part of accepting the Terms of Service, and you can change it at any time by contacting [email protected].
Miiskin records the choice you make, the date you made it, the version of the Terms of Service in force at the time, and the email address on your account, together with any withdrawal of that choice. Miiskin provides that record to a covered entity involved in your care on request only, so that the covered entity can meet its own notification obligations. There is no continuing feed of it, and it is not provided for any other purpose.
13 Changes to this Privacy Information
Miiskin reviews this Privacy Information at least once every twelve (12) months and updates it when our practices change. The date the current version took effect is shown at the top of this document. If we make a material change, we will post the updated Privacy Information at least thirty (30) days before it takes effect, unless a change in law or regulation requires it to take effect sooner, in which case we will publish it as soon as we are able and include a rationale in the updated document. Where a change adversely affects your rights under this Privacy Information, we will also you about the new Privacy Information by contacting you by email at the address held in your Miiskin account. Where the law requires your consent before we use information we already hold for a new purpose, or have a need to share it with a new category of recipient, we will ask for that consent and will not do so until you give it.
14 Compliance framework
Miiskin operates across all fifty United States. Requirements governing health information, consumer health data, medical records, and consumer privacy differ between states and are amended from time to time. Our practices are designed to meet the federal requirements applicable to health information and the requirements of the states in which the Platform is available. Where the applicable requirements of two or more states differ, we apply the standard that affords the greater protection to you, unless doing so would prevent us from complying with a legal obligation in another state. Where the law of your state gives you a right that is not set out in this Privacy Information, that right is not excluded, and you may exercise it by contacting us. If we decline a request, we will tell you why and how to appeal, and we will respond to an appeal within the period your state allows.
15 Contact Us
If you have any questions or concerns about this Privacy Information or our privacy practices, please contact us at [email protected].
16 Previous version
This Privacy Information replaces the version previously published at miiskin.com. It takes effect on the date shown at the top of this document. The reason for this version is general updating and an extension of Miiskin’s data retention commitment. Miiskin keeps every previous version of this Privacy Information and will provide the version that was in force on any given date on request to [email protected].