Security
Data Security & Controls
Health data requires strong protection. Here are the controls we use to safeguard it.
GDPR / DSGVO Framework
As a German company (drylabs GmbH), GDPR is our primary data-protection framework. Our technical and organisational controls are designed to support applicable GDPR obligations; each clinic remains responsible for its own use of the service and legal duties.
Data Protection Principles
Your Rights
Under GDPR, you have the right to access, rectify, erase, port, and restrict processing of your data. You can exercise these rights directly in the app (Settings → Privacy & Data) or by contacting us at info@drylabs.de.
Technical Security
Data Hosting & Delivery
The primary database is hosted in Supabase West EU (Ireland). Cloudflare provides global web delivery, DDoS protection, and image hosting; image bytes may be processed and served through Cloudflare’s global network. Standard Contractual Clauses (SCCs) and the safeguards described in our Privacy Policy govern applicable international transfers.
Not a Medical Device
Aesthetic Pass is not a medical device under EU Medical Device Regulation (MDR 2017/745). It is a record-keeping and information platform for aesthetic treatments. It does not provide medical advice, diagnosis, or treatment recommendations. On the App Store, it is categorised as Health & Fitness, not Medical.
International Privacy Approach
We use GDPR-derived data-protection principles as a baseline for users worldwide. The laws and obligations that apply depend on the user, clinic, processing context, and location; our controls do not replace each organisation’s own legal assessment.