PRIVACY POLICY AND PERSONAL DATA PROCESSING
Last updated: 27.09.2026
1. General Provisions
1.1. This Privacy Policy defines the procedure for processing and protecting the personal data of clients of Mezoestet OÜ (registry code 14220076, clinic address: Sõpruse pst 145, Tallinn, Estonia; hereinafter referred to as "SKINRENEW CLINIC" or the "Clinic") [1.1].
1.2. The Clinic is the data controller (chief processor) of its Clients' personal and medical data [1.2].
1.3. Data processing is carried out in strict accordance with the EU General Data Protection Regulation (GDPR), the Personal Data Protection Act of Estonia, and other legal acts of the Republic of Estonia [1.3].
1.4. For any questions related to the processing and protection of personal data, the Client may contact the Clinic's designated responsible person via email: info@skinrenewclinic.ee [1.4].
2. Types of Data We Collect and Process
The Clinic collects only the data necessary for the high-quality provision of services and compliance with statutory requirements:
-
Personal data: first name, last name, personal identification code (isikukood), date of birth.
-
Contact data: phone number, email address.
-
Medical data (special categories of data): information about health status, chronic diseases, allergies, medications taken, contraindications, as well as completed health charts and informed consent forms.
-
Documentation materials: photographs and/or video recordings of the treatment areas (before and after the procedure) for quality control and treatment history purposes.
-
Technical data: IP address, cookies, and user behavior data on the Clinic's website during online booking.
3. Legal Basis for Processing
We process your data based on the following grounds:
3.1. For the performance of a contract and provision of services (Art. 6(1)(b) GDPR): for registration for procedures, identity verification, booking management, communication with the Client, and the direct performance of medical and aesthetic manipulations [3.1].
3.2. For compliance with legal obligations and the provision of healthcare services (Art. 6(1)(c) and Art. 9(2)(h) GDPR): for maintaining official medical records, health charts, and for the mandatory transfer of data on provided medical services to the Estonian national health information system (Health Portal / Terviseportaal) in accordance with the requirements of Estonian legislation [3.2].
3.3. Based on the Clinic's legitimate interest (Art. 6(1)(f) GDPR): photo and video documentation before/after procedures is conducted for an objective evaluation of results, quality control, and the protection of the Clinic's interests in the event of unsubstantiated claims [3.3].
3.4. Based on the Client's consent (Art. 6(1)(a) GDPR): for sending marketing offers, appointment reminders via SMS/Email, or publishing photos of results on social media (only with separate written consent) [3.4].
4. Disclosure of Data to Third Parties
The Clinic strictly observes confidentiality. Data may be transferred to third parties only in the following cases:
4.1. To the Estonian national health information system (Terviseportaal) in accordance with the requirements of Estonian legislation [4.1].
4.2. To official state and supervisory authorities (such as the Health Board / Terviseamet, the Data Protection Inspectorate / Andmekaitse Inspektsioon, police, or court) only upon their official and lawful request [4.2].
4.3. To authorized processors (volitatud töötlejad) — IT partners who ensure the operation of the online booking system, website hosting, and SMS/Email notifications. Confidentiality agreements have been concluded with these partners, and they have no right to use your data for other purposes [4.3].
5. Data Retention Periods
5.1. Contact data and booking history are stored as long as the client uses the services of the Clinic, or within the time limits established for the protection of legal claims (usually 3 years from the date of the last visit) [5.1].
5.2. Medical documentation, health charts, and mandatory before/after photographs/video recordings, which form part of the treatment history, are stored in accordance with the time limits established by the legislation of the Republic of Estonia for medical institutions (up to 30 years) [5.2].
6. Rights of the Client
In accordance with the GDPR, you have the right to:
-
Request access to your personal data and obtain a copy of it.
-
Request the correction of inaccurate or outdated data.
-
Request the deletion of data ("the right to be forgotten"), except for medical data that the Clinic is legally obliged to store under Estonian law.
-
Restrict or object to the processing of data (for example, withdraw consent for receiving promotional newsletters).
-
File a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, Väike-Ameerika 19, 10129 Tallinn, info@aki.ee) if you believe that your rights have been violated.
