1. Data Controller
VM Aesthetics Exop Oy
Business ID: 2325428-1
Email: info@vmestetiikka.fi
Phone: 044 901 3411
2. Data Protection Officer
Hanna Miettola-Järvinen
Marketing and Training Manager
Does not participate in patient care
3. Registers
- Patient Information Registry (Assisdent)
- Online Store Customer Database
- Newsletter and Marketing Database
4. Purpose of the processing of personal data
Delivery of Health Care
- treatment planning
- delivery of care
- treatment follow-up
- ensuring patient safety
Customer Relationship Management
- appointment
- customer service
- communication
Billing and Payments
- payment processing
- accounting
Online Store
- order processing
- payment
- delivery
Marketing and Communications
- newsletters
- communication regarding services
5. Legal basis for processing
- legal obligation (patient information)
- contract (customer relationship)
- eligible benefit (operational development)
- consent (marketing)
6. Data Content of the Registry
Patient Information Registry (Assisdent)
- name and social security number
- contact information
- health information
- treatment information and procedures
- photos and documentation
- prescription information
- appointments
Online Store Customer Database
- name
- contact information
- order details
- payment information
- customer information
Newsletter Archive
- email address
- marketing consent
- Message open and click data
7. Standard sources of information
- from the customer themselves
- in a care setting
- through the online store
- when subscribing to the newsletter
8. Data Retention Period
- Patient information: the period required by law
- Online store information: in accordance with the Accounting Act
- Marketing information: until consent is withdrawn
9. Disclosure of Information
- Core Services (Legislation)
- to the authorities in situations required by law
- to insurance companies, if necessary
We do not share your information with third parties for marketing purposes.
10. Data Location and Processing
VM-estetiikka's website and online store are based in Finland.
Personal data is generally processed within the EU/EEA.
The software used for newsletters and marketing communications is a European service, and data is processed in accordance with EU data protection laws.
11. Information Security
- access management
- password protection
- log monitoring
- technical information security solutions
Patient data is processed in the Assisdent patient information system.
12. Rights of the Data Subject
- the right to access one's own data
- the right to request the correction of data
- the right to restrict processing
- the right to withdraw consent
- the right to file a complaint with the supervisory authority
It is not possible to delete patient data due to legal obligations.
13. Cookies
This website uses cookies to ensure the site functions properly, for analytics, and for marketing purposes.
Essential cookies are always enabled to ensure that the website functions properly.
User consent for the use of non-essential cookies is requested via a cookie banner. Users can accept or reject cookies and change their settings at any time.
Cookies are not activated without the user's consent; however, this does not apply to cookies that are essential for the website to function.
14. Updating the Privacy Policy
This Privacy Policy will be updated as necessary.
