Legal
Privacy policy
Reproduced from e-skin's published policy. Because we provide cosmetic skin services and collect health information, we are treated as a health service provider under the Privacy Act.
Privacy Policy (Australia)
Operator: e-skin (“we”, “us”, “our”)Applies to: Our clinics, website, booking systems, communications and social mediaContact (privacy): admin@e-skin.com.au • 0413 822 633Location/Time Zone: Queensland, Australia (Australia/Brisbane)Version: Rev 2.8 • Effective date: 25 July 2026
Collection Notice (APP 5)We collect personal information (including health information) directly from you and from third-party booking, payment and messaging platforms to provide our cosmetic services (including HIFU), manage appointments, process payments, provide aftercare and communicate with you. If you do not provide requested information, we may be unable to assess suitability or deliver services safely. We may disclose information to service providers (e.g., booking, payment, CRM, email/SMS, IT hosting) and, where legally required, to regulators. Some providers may store data outside Australia (see clause 10). See this Policy for details on access/correction (clause 13), complaints (clause 14) and marketing choices (clause 5).
1. About this Policy
We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Because we provide cosmetic skin services and collect health information, we are treated as a health service provider under the Privacy Act. This Policy explains what we collect, how we use and disclose it, and your rights.
2. What we collect
- Identity & contact: name, DOB, address, email, phone, sex.
- Booking & account: appointment history, preferences, notes, intake/consent forms, photographs taken in-clinic for clinical records, before/after images (see clause 6).
- Health information (sensitive information): medical history, medications, implanted devices, allergies, skin concerns, pregnancy/breastfeeding status, contraindications, pre/post-care compliance and clinician observations.
- Payment & transactions: amounts, methods, refunds/credits (we do not store full card numbers; see clause 7).
- Communications & UGC: emails, SMS, DMs, testimonials, comments, images/videos you provide or authorise us to use.
- Technical/cookies: device, browser, IP address, session IDs, pages viewed, referral sources, advertising identifiers (see clause 8).
- Premises security (if used): CCTV in clinic common areas for safety and loss prevention; signage will indicate CCTV operation.
3. How we collect
- Directly from you: in person, via forms, by phone/SMS/email/DM, or through our website/booking pages.
- Automatically: through cookies, pixels and analytics tools on our digital channels.
- From third parties: booking/payment/messaging providers, advertising platforms and, with your consent where required, from your authorised representative (e.g., guardian/carer).
4. Why we collect (purposes)
We collect, use and disclose information to:(a) assess suitability and deliver cosmetic services safely;(b) schedule, confirm and manage bookings;(c) process payments, credits and refunds;(d) maintain clinical records and provide aftercare;(e) respond to enquiries and manage complaints;(f) operate, secure and improve our website and systems;(g) send operational messages (confirmations, reminders, forms) and, where permitted, marketing (see clause 5);(h) create de-identified statistics and insights to improve services; and(i) comply with laws (e.g., health, privacy, taxation) and manage risk.
5. Marketing communications
We may send you marketing by email/SMS/online about our services, offers and events. You can opt out at any time (unsubscribe link in email, reply STOP to SMS, or contact us). Operational messages (e.g., appointment reminders, forms) are not marketing and are necessary to administer your booking.
6. Photos, before/after images & testimonials
- Clinical records: We may take treatment-area photos to support clinical care; these are stored in your file.
- Marketing use: We will only publish identifiable photos, videos or testimonials with your express written consent. You may withdraw consent prospectively; we will take reasonable steps to remove content under our control, noting that prior shares/caches/third-party reposts may persist.
- UGC: Content you post/tag may be used under the licence in our User Generated Content clause in the Terms.
7. Payment information
We use PCI-DSS compliant third-party payment processors. We do not store full card numbers on our systems. Processors may provide us a token to process future payments (e.g., deposits, late-cancellation/no-show charges) consistent with your booking consents.
8. Cookies, analytics & ad tech
We use cookies/pixels and similar technologies (e.g., website analytics, conversion tracking and remarketing tools) to operate and improve our site and measure campaign performance. You can manage cookies via your browser settings and opt-out of some interest-based advertising through platform controls. Blocking cookies may impact site functionality.
9. Disclosures to third parties
We may disclose personal information to:
- Service providers: booking/scheduling, payments, CRM, email/SMS, cloud hosting, IT support, analytics, marketing platforms and document storage;
- Professional advisers & insurers (for claims, audits and compliance);
- Regulators or law enforcement where legally required; and
- Your authorised representatives (with appropriate authority/consent).
We require service providers to handle personal information in accordance with the APPs and this Policy, and to use it only for the services they provide to us.
10. Overseas disclosures (APP 8)
Some service providers may store or access information from outside Australia (for example, the United States, European Union or Singapore). Where we disclose personal information overseas, we take reasonable steps to ensure the recipient will handle it in a way that is consistent with the APPs (e.g., contractual safeguards and vendor due diligence). By using our services, you consent to such overseas disclosures.
11. Security
We implement technical and organisational measures appropriate to the sensitivity of the information we hold, including encryption at rest/in transit where applicable, access controls, audit logging and staff training. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
12. Retention & de-identification
- Clinical/booking records: retained for as long as reasonably necessary for the purposes in clause 4 and to meet legal/insurance requirements. As a guideline, we generally keep adult clinical records for at least 7 years from the date of last service, unless a longer period is required by law.
- Other records: kept for periods reflecting operational and legal needs, then securely destroyed or de-identified.
13. Access & correction (APPs 12–13)
You may request access to, or correction of, your personal information by emailing admin@e-skin.com.au. We will respond within a reasonable time (usually 30 days). For security we may need to verify your identity. If we refuse access or correction (where permitted by law), we will tell you why and how to complain.
14. Complaints & the Notifiable Data Breaches (NDB) scheme
If you have a privacy concern, contact us at admin@e-skin.com.au. We will investigate and respond within a reasonable time.If we experience an eligible data breach that is likely to cause serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the NDB scheme.If you are not satisfied with our response, you may contact the OAIC: oaic.gov.au • 1300 363 992 • GPO Box 5218, Sydney NSW 2001.
15. Children & minors
Our services and bookings are for adults (18+). We do not knowingly collect personal information from children. If you believe we have collected information about a minor, contact us and we will take appropriate steps (including deletion where applicable).
16. Changes to this Policy
We may update this Policy by publishing a new version on our website. Changes take effect on publication unless stated otherwise. Your continued use after publication constitutes acceptance.
17. Definitions
- Personal information: information or an opinion about an identified individual or an individual who is reasonably identifiable.
- Sensitive information: a subset of personal information including health information, which we only collect with consent or as otherwise permitted by law.
- Health information: information or an opinion about the health, disability or health services provided to an individual, and other information defined in the Privacy Act.
- APPs: the Australian Privacy Principles in the Privacy Act 1988 (Cth).
- CCTV: closed-circuit television systems operating at our premises (if used).
Contact
For questions or notices, contact admin@e-skin.com.au or 0413 822 633.
Terms & Conditions, Disclosures & Privacy Policy
All content copyright 2026 e-skin – Last Updated July 25, 2026
