Precision Skin LLC SPC is a company registered in the United Arab Emirates. We operate the Agent Portal as a software service enabling retail outlets and their agents to manage personalised skincare orders and AI-assisted skin analysis for their clients.
For data protection purposes, Precision Skin LLC SPC acts as a data processor when handling client personal data submitted through the Portal. The retail outlet (agent) acts as the data controller for their clients' data.
Through the Portal, the following categories of personal data may be collected and processed:
Skin analysis scores derived from facial images may constitute biometric data or health-related data under applicable law (including UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection and GDPR where applicable). We treat all such data with the highest level of care.
We process personal data on the basis of:
It is the retail outlet's responsibility to obtain valid, informed consent from clients before their data — especially facial photographs — are submitted to the Portal.
Data entered into the Portal is used exclusively to:
We do not sell, rent, or share personal data with third parties for marketing purposes.
All data is stored in Supabase-hosted infrastructure with encryption at rest and in transit (TLS 1.2+). Access is restricted to authorised EXACT personnel and the submitting retail outlet only. We apply role-based access controls and maintain audit logs of data access.
Facial photographs submitted for skin analysis are stored securely and are accessible only to the relevant retail outlet and EXACT operations staff as necessary for order fulfilment.
Client data is retained for the duration of the retail outlet's commercial relationship with EXACT plus a period of 3 years thereafter, unless a shorter retention period is required by law or requested by the data subject. Agents may request deletion of specific client records via privacy@exactcosmetics.com.
End clients whose data is processed through the Portal have the right to access, rectify, erase, or port their personal data. Such requests should be directed to the retail outlet in the first instance, who may then engage EXACT to fulfil them. Requests can also be submitted directly to privacy@exactcosmetics.com.
Some personal data processed through the Portal is transferred to and processed in jurisdictions outside the United Arab Emirates. In particular:
By submitting client data through the Portal, the retail outlet confirms it has informed clients that their data — including facial photographs — may be processed outside the UAE, and has obtained any consent required for such transfer under applicable law. We require all third-party processors to maintain appropriate technical and organisational security measures.
This Privacy Policy is governed by the laws of the United Arab Emirates. Any disputes arising in connection with it shall be subject to the exclusive jurisdiction of the courts of Abu Dhabi, UAE.
We may update this Privacy Policy from time to time. Continued use of the Portal following notification of changes constitutes acceptance of the revised policy.
For privacy-related queries, contact our Data Protection Officer at privacy@exactcosmetics.com.