1. Who is responsible and which role applies?
drylabs GmbH, Straße der Jugend 18, 14974 Ludwigsfelde, Germany, registered with Amtsgericht Potsdam under HRB 41588 P, operates Aesthetic Pass. Email: privacy@aestheticpass.com.
drylabs GmbH is the controller for consumer account administration, platform security, subscription administration, the public website, direct support, and product decisions for patient-led features.
Our protection commitment: We handle health and treatment information as specially protected data. Our privacy framework combines purpose limitation and data minimisation with role- and treatment-relationship-based access, layered technical and organisational safeguards, documented retention and deletion rules, and defined incident-response procedures. We do not sell health data, use it for behavioural advertising, or train models on patient records or patient photographs.
When a clinic or practitioner decides why and how a provider-created treatment record is made, used, corrected, retained, or disclosed, that clinic or practitioner is normally the controller for that medical record. drylabs GmbH generally acts as its processor under Article 28 GDPR to the extent it processes the record on documented instructions. The facts and the applicable agreement determine the role; a contract label cannot override reality. Contact the relevant clinic first for requests about its treatment file. We will assist the clinic and will handle any part for which drylabs GmbH is itself controller.
Data Protection Officer: Dr. Csilla Geleta, Fachärztin für Arbeitsmedizin (specialist physician in occupational medicine). Contact her directly about the processing of personal data or the exercise of data-protection rights at csillageleta@aestheticpass.com.