Security
Data Security & Controls
Health data requires strong protection. Here are the controls we use to safeguard it.
GDPR / DSGVO Framework
As a German company (drylabs GmbH), GDPR is our primary data protection framework. Our controls are designed to support applicable GDPR obligations.
Data Protection Principles
Your Rights
Under GDPR, you have the right to access, rectify, erase, port, and restrict processing of your data. You can exercise these rights directly in the app or by contacting us.
Technical Security
Data Hosting & Delivery
Core application data is stored in Supabase's West EU (Ireland) region. Cloudflare provides global web delivery, protection, and image infrastructure; our Privacy Policy describes the safeguards used for international processing.
Not a Medical Device
Aesthetic Pass is not a medical device under EU Medical Device Regulation (MDR 2017/745). It is a record-keeping and information platform for aesthetic treatments. It is categorised as Health & Fitness on the App Store, not Medical.
International Privacy Approach
GDPR is our primary privacy framework. We use it as a baseline for platform controls while assessing additional obligations according to the user's location and the processing context.