How DermaVue Skin & Hair Clinics collects, uses, stores and protects your personal data.
Last updated: 9 March 2026DermaVue Skin & Hair Clinics ("DermaVue", "we", "us", "our") is a physician-owned dermatology clinic network operating across Kerala and Tamil Nadu, India. We are registered under the laws of India and operate the website dermavue.com (the "Website").
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our Website, book appointments, use our services, or interact with us through social media, advertising platforms, or third-party tools.
By using our Website or services, you consent to the practices described in this policy. If you do not agree, please discontinue use of our services.
| Category | Examples |
|---|---|
| Identity | Full name, title, date of birth, gender |
| Contact | Phone number, email address, postal address, WhatsApp number |
| Booking | Preferred clinic location, consultation type, preferred date/time, service requested |
| Health | Medical history, skin/hair condition details, photographs of affected areas, treatment records (collected only with explicit consent at the clinic) |
| Financial | Payment information for treatments or EMI processing (processed via secure payment gateways; we do not store card numbers) |
| Communication | Messages sent via website forms, WhatsApp, email, or social media |
| Category | Examples |
|---|---|
| Device & Browser | IP address, browser type and version, operating system, device identifiers, screen resolution |
| Usage | Pages visited, time on page, referral URL, click paths, scroll depth |
| Location | Approximate geographic location derived from IP address (city/region level) |
| Cookies | Session IDs, preference tokens, analytics identifiers (see Section 8) |
Health-related data (skin/hair condition details, medical photographs, treatment history) is classified as sensitive personal data under the DPDPA 2023. We collect this data only when:
| Purpose | Data Used |
|---|---|
| Appointment booking & management | Name, phone, email, clinic location, service type |
| Providing dermatological care | Health data, identity, contact details |
| Sending appointment reminders | Phone, email, WhatsApp |
| Treatment follow-ups & aftercare | Health data, contact details, treatment records |
| CRM and lead management | Name, phone, email, clinic location, enquiry details |
| WhatsApp automation & notifications | Phone number, name, booking status |
| Email marketing (with consent) | Name, email, service interests |
| Advertising & remarketing | Cookie identifiers, device data, page visit history |
| Analytics & website improvement | Usage data, device data, aggregated statistics |
| Legal compliance | All categories as required by law |
We process your personal data under the following legal bases:
Where consent is the basis, you may withdraw it at any time (see Section 13).
We use a Customer Relationship Management (CRM) system to manage appointment bookings, patient enquiries, and follow-ups. When you submit a booking form on our Website or contact us via phone/WhatsApp, your information may be stored in our CRM.
Our CRM may send automated communications including:
We use advertising platforms to reach potential patients and measure campaign effectiveness. These platforms may collect data via pixels, SDKs, or server-side integrations placed on our Website.
| Platform | Purpose | Data Shared |
|---|---|---|
| Meta (Facebook & Instagram) | Lead generation ads, remarketing, conversion tracking, custom audiences, lookalike audiences | Meta Pixel data (page views, events), hashed email/phone for custom audiences, conversion events |
| Google Ads | Search ads, display remarketing, conversion tracking | Google Ads tag data (page views, conversions), click identifiers (GCLID) |
| YouTube | Video advertising, remarketing via Google Ads | Video view events, cookie identifiers, ad interaction data |
| Google Analytics 4 | Website analytics, audience building for ads | Pseudonymised usage data, device data, page visit patterns |
In compliance with Meta's Platform Terms and Data Policy:
Our Website uses cookies and similar technologies (pixels, local storage, beacons) to provide functionality, analyse usage, and serve relevant advertisements.
| Cookie Type | Purpose | Duration |
|---|---|---|
| Strictly Necessary | Session management, security, form submission (CSRF tokens, WordPress session) | Session / 24 hours |
| Functional | Remembering your preferred clinic location, language, form pre-fills | Up to 1 year |
| Analytics | Google Analytics 4 (_ga, _ga_*) — page views, traffic sources, user journeys | Up to 2 years |
| Advertising | Meta Pixel (_fbp, _fbc), Google Ads (GCLID, _gcl_*), remarketing audiences | Up to 2 years |
You can control cookies through:
Disabling cookies may affect website functionality, including the booking form and clinic selector.
We use trusted third-party services to operate our Website and deliver care. Each provider processes data under their own privacy policy and our contractual agreements.
| Service | Provider | Purpose | Data Processed |
|---|---|---|---|
| CRM | ProDoc AI | Lead management, appointment scheduling, WhatsApp automation | Name, phone, email, clinic, enquiry details |
| Website Hosting | WordPress / Hosting Provider | Website delivery, server logs | IP address, request data |
| Analytics | Google (GA4) | Website usage analytics | Pseudonymised browsing data |
| Advertising | Meta Platforms, Google | Ad serving, conversion tracking | Cookie data, conversion events |
| WordPress Mail / SMTP Provider | Transactional emails, booking confirmations | Name, email, booking details | |
| Maps | Google Maps | Clinic location display | IP address, location data |
| Video | YouTube (Google) | Embedded patient education videos | Cookie data, view events |
| Messaging | WhatsApp (Meta) | Patient communication, appointment reminders | Phone number, message content |
| reCAPTCHA | Spam prevention on forms | Device data, interaction patterns | |
| Fonts | Google Fonts | Typography rendering | IP address (at load time) |
| Payments | Payment Gateway Provider | Treatment payment processing | Handled entirely by the gateway (PCI DSS compliant) |
Some of our third-party providers (Google, Meta) process data outside India, including in the United States and European Economic Area. These transfers are protected by:
| Data Type | Retention Period | Reason |
|---|---|---|
| Booking enquiries (non-patients) | 2 years | Legitimate interest in follow-up |
| Patient medical records | Minimum 3 years after last visit (or as required by Indian medical regulations) | Legal compliance, continuity of care |
| CRM lead data | 2 years from last interaction | Lead management, service improvement |
| Payment records | 7 years | Tax and accounting laws |
| Website analytics | 26 months (GA4 default) | Analytics and improvement |
| Advertising data | Per platform retention (typically 1-2 years) | Campaign measurement |
| Communication records | 2 years | Service quality, dispute resolution |
After the retention period, data is securely deleted or anonymised. You may request earlier deletion (see Section 13).
We implement appropriate technical and organisational measures to protect your personal data:
While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to industry best practices.
Depending on your location, you have the following rights regarding your personal data:
Submit a request via:
We will verify your identity and respond within 30 days (DPDPA/GDPR) or 45 days (CCPA). Complex requests may require an extension, in which case we will inform you.
Our Website is not directed at individuals under the age of 18. We do not knowingly collect personal data from children without verifiable parental or guardian consent.
For dermatological consultations involving minors, we require a parent or legal guardian to provide consent for data collection and treatment. This consent is obtained in-clinic and documented in the patient record.
If you believe we have inadvertently collected data from a child without appropriate consent, please contact us immediately and we will delete the data.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or regulatory guidance. When we make material changes:
We encourage you to review this policy periodically.
For any questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us:
DermaVue Skin & Hair Clinics
Data Protection Officer
Email: help@dermavue.com
Phone: +91 8086 000 608
Address: TC 42/3003-2, Poojappura Main Rd, Kesari Nagar, Poojapura, Thiruvananthapuram, Kerala 695012
If you are not satisfied with our response, you have the right to file a complaint with the Data Protection Board of India (under DPDPA 2023) or your local data protection authority (under GDPR).