Privacy Policy
Last updated 29 September 2026. In force from 29 September 2026.
This policy explains what personal data we collect when you visit this website or buy a course, why we collect it, who else processes it and how you can exercise your rights. It is written to meet the EU General Data Protection Regulation (GDPR), Portuguese Law 58/2019 which implements it, the UK GDPR and, for California residents, the California Consumer Privacy Act (CCPA).
Who is responsible for your data
The controller of your personal data is:
| Seller | Gabriella Cardoso da Silva, trading as Dermatooh |
|---|---|
| Legal status | Sole trader (empresária em nome individual) resident in Portugal |
| Tax number (NIF) | 313852138 |
| Address | Rua do Moinho, 252, 8005-424 Faro, Portugal |
| support@dermatooh.com | |
| Telephone | +351 918 999 470, Monday to Friday, 9:00 to 18:00 Lisbon time (WET/WEST) |
| Website | https://dermatooh.com |
| Card statement descriptor | DERMATOOH |
Please send any privacy request to privacy@dermatooh.com. Because of the size of this business we are not required to appoint a Data Protection Officer; Gabriella Cardoso da Silva handles these requests personally.
What we collect and why
| Data | Purpose | Legal basis | How long we keep it |
|---|---|---|---|
| Name, email address and billing country | To process your order, deliver the course, send your access link and answer you | Performance of a contract (GDPR art. 6(1)(b)) | 10 years after the purchase, the period Portuguese tax law requires for sales records |
| Payment details: amount, currency, date, card brand, last four digits, Stripe reference | To take payment, issue invoices and refunds, handle disputes and keep tax records | Contract and legal obligation (GDPR art. 6(1)(b) and (c)) | 10 years |
| Proof of your checkout choices: acceptance of the terms and the medical disclaimer, and request for immediate delivery, with date and time | To show that the purchase and immediate delivery were requested by you | Legal obligation and legitimate interest (GDPR art. 6(1)(c) and (f)) | 10 years |
| Messages you send us, including through the contact form | To answer and keep a record of what was agreed | Contract, or our legitimate interest in answering you (GDPR art. 6(1)(b) and (f)) | 2 years |
| Technical logs: IP address, browser, date and page requested | Security, fraud prevention and fixing faults | Legitimate interest (GDPR art. 6(1)(f)) | Up to 6 months |
| Measurement and advertising data, only if you accept them in the cookie banner | To see which pages work and whether our adverts lead to purchases | Your consent (GDPR art. 6(1)(a)) | As set by each provider, never more than 13 months |
Health data: we do not collect it
Information about your skin, hair or health is a special category of personal data. We do not ask for it and we do not want it: we never ask for photos of your skin or scalp, symptoms, diagnoses or medication. The trackers and checklists in the courses are for you to fill in privately, on paper or on your own device. Please do not send us photos or health details; if you do, we use them only to reply that we cannot give individual advice, and delete them straight away.
What we never do
- We never see or store your full card number. Stripe handles it.
- We do not sell or rent personal data, and we do not share it for other companies' marketing.
- We do not make automated decisions that have legal or similarly significant effects on you.
- We do not load advertising or measurement scripts unless you accept them in the cookie banner.
Who processes data for us
| Provider | What it does | Location |
|---|---|---|
| Stripe Payments Europe, Ltd. and its affiliates | Payment processing, refunds and fraud prevention. Stripe is also an independent controller for its own legal and fraud prevention duties | Ireland, United States and other countries |
| Vercel Inc. | Hosting of this website and its server functions, technical logs | United States, with worldwide delivery network |
| Resend (Plus Five Five, Inc.) | Sending the delivery email and replies to your messages | United States |
| Our email mailbox provider | Receiving and storing the messages you send us | European Union or United States |
| Our certified accountant | Bookkeeping and tax returns required by Portuguese law | Portugal |
Each provider may only use your data to provide its service to us, under a data processing agreement or a duty of professional secrecy.
International transfers
We are based in Portugal and some of our providers are in the United States. Transfers outside the European Economic Area rely on the EU-US Data Privacy Framework where the provider is certified, or on the European Commission's standard contractual clauses. You can ask for a copy at privacy@dermatooh.com.
Emails we send
After a purchase we send transactional emails: the access link, the receipt and important notices about the course you bought. They are part of the service, so you cannot unsubscribe from them. We only send occasional news about new courses if you have agreed, and every such email includes a one-click unsubscribe link.
Your rights
Under the GDPR you can ask us to:
- confirm whether we hold your data and give you a copy (access);
- correct inaccurate or incomplete data (rectification);
- delete data we no longer need (erasure);
- restrict a particular use, or object to a use based on legitimate interest;
- give you your data in a portable format;
- withdraw a consent you gave, at any time, without affecting what was done before.
California residents also have the right to know, to delete and to correct, and the right not to be discriminated against for exercising them. We do not sell or share personal information for cross-context behavioural advertising as those terms are defined in the CCPA, unless you accept advertising cookies.
Send your request to privacy@dermatooh.com from the email address you used to buy. We answer within one month, as the GDPR requires, and usually much sooner. It is free unless a request is clearly excessive. If you ask us to delete your data, we can no longer confirm your purchase or resend your access link, and records we must keep by law, such as invoices, will be kept until the legal period ends.
Complaints
If you are unhappy with how we handle your data, please tell us first. You also have the right to complain to a supervisory authority: in Portugal the Comissão Nacional de Proteção de Dados (cnpd.pt), in another EU country the data protection authority of that country, and in the United Kingdom the Information Commissioner's Office (ico.org.uk).
Security
The site uses HTTPS on every page. Access links are digitally signed so they cannot be guessed or altered. Card data never reaches our servers. Access to our Stripe, hosting and email accounts is protected by two-factor authentication. If a data breach creates a risk to you, we will notify the CNPD within 72 hours and tell affected customers without undue delay, as the GDPR requires.
Children
Our courses are sold only to adults. We do not knowingly collect data from anyone under 18. If you believe a minor has sent us personal data, write to privacy@dermatooh.com and we will delete it.
Changes to this policy
If we change this policy in a way that matters to you, we will tell customers by email before the change takes effect. The date at the top of this page shows the current version.