Skip to content
Legal

Privacy Policy

Last updated 29 September 2026. In force from 29 September 2026.

This policy explains what personal data we collect when you visit this website or buy a course, why we collect it, who else processes it and how you can exercise your rights. It is written to meet the EU General Data Protection Regulation (GDPR), Portuguese Law 58/2019 which implements it, the UK GDPR and, for California residents, the California Consumer Privacy Act (CCPA).

Who is responsible for your data

The controller of your personal data is:

SellerGabriella Cardoso da Silva, trading as Dermatooh
Legal statusSole trader (empresária em nome individual) resident in Portugal
Tax number (NIF)313852138
AddressRua do Moinho, 252, 8005-424 Faro, Portugal
Emailsupport@dermatooh.com
Telephone+351 918 999 470, Monday to Friday, 9:00 to 18:00 Lisbon time (WET/WEST)
Websitehttps://dermatooh.com
Card statement descriptorDERMATOOH

Please send any privacy request to privacy@dermatooh.com. Because of the size of this business we are not required to appoint a Data Protection Officer; Gabriella Cardoso da Silva handles these requests personally.

What we collect and why

DataPurposeLegal basisHow long we keep it
Name, email address and billing countryTo process your order, deliver the course, send your access link and answer youPerformance of a contract (GDPR art. 6(1)(b))10 years after the purchase, the period Portuguese tax law requires for sales records
Payment details: amount, currency, date, card brand, last four digits, Stripe referenceTo take payment, issue invoices and refunds, handle disputes and keep tax recordsContract and legal obligation (GDPR art. 6(1)(b) and (c))10 years
Proof of your checkout choices: acceptance of the terms and the medical disclaimer, and request for immediate delivery, with date and timeTo show that the purchase and immediate delivery were requested by youLegal obligation and legitimate interest (GDPR art. 6(1)(c) and (f))10 years
Messages you send us, including through the contact formTo answer and keep a record of what was agreedContract, or our legitimate interest in answering you (GDPR art. 6(1)(b) and (f))2 years
Technical logs: IP address, browser, date and page requestedSecurity, fraud prevention and fixing faultsLegitimate interest (GDPR art. 6(1)(f))Up to 6 months
Measurement and advertising data, only if you accept them in the cookie bannerTo see which pages work and whether our adverts lead to purchasesYour consent (GDPR art. 6(1)(a))As set by each provider, never more than 13 months

Health data: we do not collect it

Information about your skin, hair or health is a special category of personal data. We do not ask for it and we do not want it: we never ask for photos of your skin or scalp, symptoms, diagnoses or medication. The trackers and checklists in the courses are for you to fill in privately, on paper or on your own device. Please do not send us photos or health details; if you do, we use them only to reply that we cannot give individual advice, and delete them straight away.

What we never do

  • We never see or store your full card number. Stripe handles it.
  • We do not sell or rent personal data, and we do not share it for other companies' marketing.
  • We do not make automated decisions that have legal or similarly significant effects on you.
  • We do not load advertising or measurement scripts unless you accept them in the cookie banner.

Who processes data for us

ProviderWhat it doesLocation
Stripe Payments Europe, Ltd. and its affiliatesPayment processing, refunds and fraud prevention. Stripe is also an independent controller for its own legal and fraud prevention dutiesIreland, United States and other countries
Vercel Inc.Hosting of this website and its server functions, technical logsUnited States, with worldwide delivery network
Resend (Plus Five Five, Inc.)Sending the delivery email and replies to your messagesUnited States
Our email mailbox providerReceiving and storing the messages you send usEuropean Union or United States
Our certified accountantBookkeeping and tax returns required by Portuguese lawPortugal

Each provider may only use your data to provide its service to us, under a data processing agreement or a duty of professional secrecy.

International transfers

We are based in Portugal and some of our providers are in the United States. Transfers outside the European Economic Area rely on the EU-US Data Privacy Framework where the provider is certified, or on the European Commission's standard contractual clauses. You can ask for a copy at privacy@dermatooh.com.

Emails we send

After a purchase we send transactional emails: the access link, the receipt and important notices about the course you bought. They are part of the service, so you cannot unsubscribe from them. We only send occasional news about new courses if you have agreed, and every such email includes a one-click unsubscribe link.

Your rights

Under the GDPR you can ask us to:

  • confirm whether we hold your data and give you a copy (access);
  • correct inaccurate or incomplete data (rectification);
  • delete data we no longer need (erasure);
  • restrict a particular use, or object to a use based on legitimate interest;
  • give you your data in a portable format;
  • withdraw a consent you gave, at any time, without affecting what was done before.

California residents also have the right to know, to delete and to correct, and the right not to be discriminated against for exercising them. We do not sell or share personal information for cross-context behavioural advertising as those terms are defined in the CCPA, unless you accept advertising cookies.

Send your request to privacy@dermatooh.com from the email address you used to buy. We answer within one month, as the GDPR requires, and usually much sooner. It is free unless a request is clearly excessive. If you ask us to delete your data, we can no longer confirm your purchase or resend your access link, and records we must keep by law, such as invoices, will be kept until the legal period ends.

Complaints

If you are unhappy with how we handle your data, please tell us first. You also have the right to complain to a supervisory authority: in Portugal the Comissão Nacional de Proteção de Dados (cnpd.pt), in another EU country the data protection authority of that country, and in the United Kingdom the Information Commissioner's Office (ico.org.uk).

Security

The site uses HTTPS on every page. Access links are digitally signed so they cannot be guessed or altered. Card data never reaches our servers. Access to our Stripe, hosting and email accounts is protected by two-factor authentication. If a data breach creates a risk to you, we will notify the CNPD within 72 hours and tell affected customers without undue delay, as the GDPR requires.

Children

Our courses are sold only to adults. We do not knowingly collect data from anyone under 18. If you believe a minor has sent us personal data, write to privacy@dermatooh.com and we will delete it.

Changes to this policy

If we change this policy in a way that matters to you, we will tell customers by email before the change takes effect. The date at the top of this page shows the current version.