← Back to home

Privacy Policy

Last updated: May 3, 2026

Overview

DermVault is a HIPAA-compliant skin assessment platform. We process protected health information (PHI) only as required to deliver clinical services to your aesthetic clinic. All patient data is hosted in Canada (AWS ca-west-1 with backup in ca-central-1) and is never sent to external AI systems without de-identification.

What we collect

  • Account information (name, email, phone) for authentication and notifications.
  • Health information you submit through questionnaires, including allergy and medication history.
  • Assessment results and treatment recommendations associated with your clinic.
  • Usage and audit logs required for HIPAA compliance.

How we protect your data

All PHI is encrypted in transit and at rest. Access is restricted to authorized clinic staff via role-based access control. We maintain Business Associate Agreements (BAAs) with all subprocessors that handle PHI. AI-driven recommendations are generated from de-identified data only.

Your rights

You may request a copy, correction, or deletion of your information by contacting your clinic or emailing privacy@dermvault.io.

Contact

Questions about this policy can be sent to privacy@dermvault.io.