Data Processing Addendum (Overview)

An overview of the Data Processing Addendum available to enterprise customers. The full executed DPA is provided on request.

Purpose of the DPA

The Data Processing Addendum (DPA) sets out the terms under which DermaGenome processes personal data on behalf of enterprise customers to comply with GDPR, UK GDPR, CCPA/CPRA, and equivalent laws. This page is an overview; the binding terms are in the executed DPA supplied during procurement.

Roles

The enterprise customer is the controller (or processor, where it acts for its own controller) of end-user personal data. DermaGenome acts as a processor or sub-processor, processing data only on documented instructions from the customer.

Categories of Data

The DPA covers account data, analysis inputs including images, derived intelligence outputs, and technical logs, to the extent these constitute personal data under applicable law.

Processing Purposes & Duration

Processing is limited to providing the contracted services for the agreement term plus any retention period required for security, legal compliance, or transition. Purpose limitation is enforced contractually and technically.

Sub-processors

DermaGenome engages sub-processors under written contracts with equivalent protections. The DPA includes a sub-processor notification mechanism and objection rights where applicable. A current list is provided to customers under NDA.

Security Measures

The DPA incorporates the security measures described in the Security Center and the executed agreement, including encryption, access control, audit logging, and incident response. Specific technical and organizational measures are appended to the executed DPA.

Data-Subject Rights & Assistance

DermaGenome assists the customer in responding to data-subject requests and regulatory inquiries, taking into account the nature of processing and the information available to us. Assistance timelines are defined in the DPA.

Personal Data Breach Notification

DermaGenome notifies the customer of a confirmed personal data breach without undue delay and provides information reasonably necessary for the customer to meet its own notification obligations. Notification timelines and channels are specified in the DPA.

Data Return & Deletion

After termination, DermaGenome returns or deletes customer personal data per the DPA and the agreement, retaining only what is required by law, with that data minimized and protected.

Audits & International Transfers

The DPA provides for audit rights consistent with the service and relies on Standard Contractual Clauses or equivalent safeguards for international transfers. The full executed DPA is available on request to enterprise customers.

Last reviewed: June 2026 · Contact: editorial@kdermai.com

Before you continue — important notice

DermaGenome provides AI-assisted skincare guidance reviewed by licensed specialists. By using this platform you agree to our terms and acknowledge the following:

Not a substitute for medical advice or diagnosis
Photos processed by AI for skincare analysis only
Specialist recommendations are professional opinions, not prescriptions
Data retained per our Privacy Policy — delete anytime in Settings