Last updated: May 3, 2026
DermVault is a HIPAA-compliant skin assessment platform. We process protected health information (PHI) only as required to deliver clinical services to your aesthetic clinic. All patient data is hosted in Canada (AWS ca-west-1 with backup in ca-central-1) and is never sent to external AI systems without de-identification.
All PHI is encrypted in transit and at rest. Access is restricted to authorized clinic staff via role-based access control. We maintain Business Associate Agreements (BAAs) with all subprocessors that handle PHI. AI-driven recommendations are generated from de-identified data only.
You may request a copy, correction, or deletion of your information by contacting your clinic or emailing privacy@dermvault.io.
Questions about this policy can be sent to privacy@dermvault.io.