Security

Data Security & Controls

Health data requires strong protection. Here are the controls we use to safeguard it.

GDPR / DSGVO Framework

As a German company (drylabs GmbH), GDPR is our primary data-protection framework. Our technical and organisational controls are designed to support applicable GDPR obligations; each clinic remains responsible for its own use of the service and legal duties.

Data Protection Principles

Purpose limitation — data collected only for specified, legitimate purposes
Data minimisation — only data necessary for the service is collected
Storage limitation — data retained only as long as necessary
Integrity & confidentiality — appropriate security measures at all times

Your Rights

Under GDPR, you have the right to access, rectify, erase, port, and restrict processing of your data. You can exercise these rights directly in the app (Settings → Privacy & Data) or by contacting us at info@drylabs.de.

Technical Security

Encryption: Provider-managed encryption at rest and HTTPS/TLS for supported data transfers
Certificate pinning: The iOS app uses certificate pinning as an additional control intended to reduce man-in-the-middle risk
Row-level security: Authenticated app access is authorized by account role and active provider-patient relationships. Time-limited passport links use a separate bearer-access flow
Photo privacy: EXIF metadata (GPS, camera, timestamps) stripped from all photos before upload
Device authentication: Supported iOS and Android devices use operating-system authentication; Aesthetic Pass receives only the result
Backups: Encrypted daily backups with automated drift detection

Data Hosting & Delivery

The primary database is hosted in Supabase West EU (Ireland). Cloudflare provides global web delivery, DDoS protection, and image hosting; image bytes may be processed and served through Cloudflare’s global network. Standard Contractual Clauses (SCCs) and the safeguards described in our Privacy Policy govern applicable international transfers.

Not a Medical Device

Aesthetic Pass is not a medical device under EU Medical Device Regulation (MDR 2017/745). It is a record-keeping and information platform for aesthetic treatments. It does not provide medical advice, diagnosis, or treatment recommendations. On the App Store, it is categorised as Health & Fitness, not Medical.

International Privacy Approach

We use GDPR-derived data-protection principles as a baseline for users worldwide. The laws and obligations that apply depend on the user, clinic, processing context, and location; our controls do not replace each organisation’s own legal assessment.