Legal
Privacy Policy
- Bien Etre app
- Bien Etre Diagnostics FZCO
- Effective date: 2 September 2026
- Version 1.0
1. Who we are and what this Policy covers
This Privacy Policy explains how Bien-Etre Diagnostics FZCO (trading as Bien Etre and/or SkinIQ), a company registered in IFZA, Dubai, United Arab Emirates, licence number 66538, with its registered office at DSO-IFZA, Dubai (“Bien Etre”, “SkinIQ”, “we”, “us”, “our”), collects, uses, stores, shares and protects personal data when you download and use the Bien Etre mobile application (the “App”), purchase products or a Membership through the App, complete a SkinIQ blood panel, use the SkinIQ Coach, or interact with our website, customer support and communications (together, the “Services”).
We are the data controller of the personal data described in this Policy. Where we operate in the United Kingdom, our UK affiliate Bien-Etre Ltd (company number 14639762, registered office 123 Minories, London EC3N 1NT) acts as our UK representative and, for UK Members, as joint controller. Our Data Protection Officer can be reached at [email protected] or by post at the address above.
This Policy applies in addition to our Terms of Use. By creating an account or using the Services you acknowledge that you have read this Policy. Where we rely on your consent (for example, to process face images, skin readings, blood-biomarker results or wearable data), we will ask for it separately and clearly, and you may withdraw it at any time as described in Section 12.
2. Summary — the key points
- Face scans. When you take a scan, the App analyses images of your face to produce skin readings (for example hydration, redness, pores, fine lines) and a SkinIQ Score. We do not use your images to identify you, to build a facial-recognition template, or to match you against any database.
- Health data. Skin readings, blood-biomarker results and data from Apple Health or Health Connect are health data. We process them only with your explicit consent, only to provide the Services to you, and never for advertising, credit, insurance or employment purposes. Health data is never sold.
- Where your data lives. Health data relating to UAE users is stored on servers located inside the United Arab Emirates in accordance with UAE health-data law. Other data may be processed on secure cloud infrastructure in the UAE, the European Economic Area or the United Kingdom under appropriate safeguards.
- Who sees it. Trusted service providers who help us run the App (cloud hosting, licensed laboratories, delivery partners, payment processors, customer-support tools), bound by contract. We share only what each partner needs.
- Your control. You can view, export, correct and delete your data, withdraw consent, disconnect wearables, and delete your account entirely from inside the App (Settings → Account → Delete account).
- Age. The App is for adults aged 18 and over. We do not knowingly collect data from anyone under 18.
3. SkinIQ is a wellness service, not a medical service
The SkinIQ Score, the individual skin readings, the 30- and 90-day trait forecasts, the blood-panel “skin drivers”, the SkinIQ Coach and any product suggestions are generated for general wellness, self-awareness and cosmetic skincare purposes. They are not intended to diagnose, treat, cure, mitigate or prevent any disease or medical condition, and they do not create a doctor–patient relationship. Blood panels are processed by independent licensed laboratories and are reported to you as wellness biomarkers, not as a clinical diagnosis. Where a reading falls outside a reference range, the App may suggest you speak to a healthcare professional; that suggestion is informational only. Never disregard professional medical advice, or delay seeking it, because of something you have seen in the App.
4. The personal data we collect
We collect personal data in the following categories. Items marked with † are sensitive / special-category data (health data or, in some laws, biometric data) and are collected only with your explicit consent.
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, email address, mobile number, password (hashed), date of birth or age band, gender (optional), profile photo (optional), language and country settings, login identifiers if you sign in with Apple or Google. | You |
| Face images and skin readings † | Selfie images captured through the App camera (or uploaded from your gallery), derived facial-region measurements, skin type, skin tone and tone depth, the 29 skin readings and their 0–100 index values, SkinIQ Score, skin age, score bands and forecasts, and each re-scan over time. | You / generated by us |
| Blood biomarker results † | For Members: results of the quarterly finger-prick or venous blood panel processed by our partner laboratory (for example markers of glycation, inflammation, barrier vitamins and lipids, oxygen delivery), reference ranges, collection date, sample identifiers, and the resulting skin-driver scores (Firmness & Structure, Calm & Resilience, Repair & Renewal, Barrier & Glow). | Partner laboratory / generated by us |
| Connected wearable and health-platform data † | If you choose to connect Apple Health (HealthKit) or Android Health Connect: the specific data types you authorise, which may include sleep, steps and activity, heart-rate variability, resting heart rate, and (if authorised) skin temperature or cycle data. We request only the types the feature needs and you can revoke access at any time in the App or in your device settings. | Your device, with your permission |
| Lifestyle and questionnaire answers † | Answers to optional in-App questions (for example sun exposure, sleep, diet, current skincare routine, known sensitivities or allergies to ingredients, pregnancy or breastfeeding status where relevant to product suitability). | You |
| SkinIQ Coach conversations † | Messages you exchange with the SkinIQ Coach (which may be delivered by a human skin coach, by our automated coaching engine, or a combination), and any photos you attach. | You |
| Orders, delivery and payment | Products ordered, order history, delivery name, address and instructions, contact number for the courier, order value, currency, VAT invoices, refund and return records. Card details are collected and processed by our payment processor or by Apple/Google — we do not store full card numbers. | You / payment provider / app store |
| Membership and subscription | Subscription tier, start and renewal dates, App Store or Google Play transaction identifiers and receipts, trial status, cancellation. | Apple / Google / you |
| Device, technical and usage data | Device model and OS version, App version, unique App instance identifier, push-notification token, IP address, approximate location derived from IP or from the delivery address you enter (we do not collect precise GPS location unless you enable it for delivery), crash logs, screens viewed, features used, time spent, and diagnostics. | Your device / automatically |
| Communications | Support tickets, emails, in-App chat, survey responses, reviews and feedback, and records of your marketing preferences. | You |
| Referral and marketing | Referral codes, campaign or attribution source, and interactions with our emails or notifications. | You / automatically |
5. How we use your data and our legal bases
We use personal data only for the purposes below. The “legal basis” column explains the lawful ground we rely on under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “PDPL”), the UK GDPR / Data Protection Act 2018 and the EU GDPR (together, “GDPR”). Where a purpose involves sensitive data we rely on your explicit consent (PDPL Article 4(1); GDPR Article 9(2)(a)).
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and manage your account; authenticate you; provide customer support | Account, device, communications | Performance of a contract (our Terms of Use) |
| Perform the face scan and generate skin readings, SkinIQ Score, skin age and forecasts | Face images, skin readings, questionnaire answers | Explicit consent |
| Arrange, process and present your blood panel and skin-driver scores | Blood biomarker results, account, delivery details for the sample kit | Explicit consent; contract (Membership) |
| Integrate wearable data into your readings and forecasts | Connected wearable data | Explicit consent (granted through Apple Health / Health Connect permissions) |
| Deliver the SkinIQ Coach service | Coach conversations, skin readings, biomarkers, questionnaire answers | Explicit consent; contract (Membership) |
| Generate personalised product suggestions inside the App | Skin readings, questionnaire answers (including stated ingredient sensitivities), order history | Explicit consent (for health-based personalisation); legitimate interests (order history) |
| Process orders, take payment, deliver products, handle returns and warranty claims, issue VAT invoices | Orders, delivery and payment, account | Performance of a contract; legal obligation (tax and consumer law) |
| Manage Memberships, renewals, trials and cancellations | Membership and subscription, account | Performance of a contract |
| Send service messages (scan reminders, order updates, security alerts, changes to terms) | Account, device | Performance of a contract; legitimate interests |
| Send marketing communications and personalised offers | Account, communications, order history (never health data unless you separately opt in) | Consent (which you may withdraw at any time); soft opt-in for existing customers where the law permits |
| Maintain, secure, debug and improve the App; prevent fraud and abuse | Device, technical and usage data | Legitimate interests (running a secure and reliable service) |
| Research and improve our skin-analysis and forecasting models (the SkinIQ Predictive Health Intelligence Engine) | De-identified or aggregated skin readings, biomarkers and outcomes; face images only where you have separately opted in | Explicit consent (identifiable data); legitimate interests (aggregated or anonymised data) |
| Comply with law, respond to lawful requests, establish or defend legal claims | Any category as required | Legal obligation; legitimate interests |
| Corporate transactions (merger, financing, sale of assets) | Any category, subject to confidentiality | Legitimate interests |
Where we rely on legitimate interests we have balanced those interests against your rights and freedoms; you may object to such processing at any time (Section 12). We will not use your data for a purpose incompatible with those described here without telling you first and, where required, obtaining your consent.
6. Face images and skin readings — how we handle them
- Purpose limitation. Your images are analysed solely to derive skin readings, skin type and tone, scores and forecasts, and to show you your progress over time. We do not use them to identify or verify who you are, to create facial-recognition templates, to infer emotion, age for legal purposes, ethnicity or any protected characteristic, or to match against third-party databases.
- Processing location. Image analysis is performed by our own systems and, where indicated in the App, by a specialist skin-analysis technology provider acting as our processor under contract (Haut AI). The provider is permitted to process images only on our instructions and may not retain them beyond the analysis session except as described below.
- Retention. Original scan images are retained for 90 days by default so that you can compare scans and we can re-run analysis if you report an error, after which they are deleted or irreversibly de-identified. Derived readings and scores (which cannot be reversed into an image) are retained for the life of your account so that your history and forecasts work. You may delete any individual scan at any time.
- Model improvement. We only use identifiable images to train or evaluate our analysis models if you have ticked the separate “Help improve SkinIQ” option. If you do, images are stripped of account identifiers, stored in a segregated research environment, and never shared with brands or advertisers. You can turn this off at any time and we will stop using your images going forward.
- Accuracy limits. Readings depend on lighting, camera quality, make-up and skin tone. They are estimates, not clinical measurements. See the Terms of Use.
7. Apple Health, Health Connect and other health-platform data
If you connect Apple Health (HealthKit) or Android Health Connect, the following commitments apply in addition to the rest of this Policy, and reflect the Apple Developer Program License Agreement, the Apple App Store Review Guidelines, and the Google Play Health Apps and Health Connect policies:
- We access only the data types you expressly authorise and use them only to provide the SkinIQ features that need them (for example combining sleep and HRV with your skin readings to improve your forecast).
- We do not use health-platform data for advertising, marketing, or any use-based data mining; we do not sell it, share it with data brokers or advertising networks, or use it to determine eligibility for employment, insurance, credit or housing; and we do not disclose it to third parties except processors who help us provide the feature, or with your separate explicit consent.
- Health-platform data is stored encrypted and is not written to iCloud or other third-party cloud services except as necessary for the Services under this Policy.
- You can disconnect at any time in the App (Settings → Connected devices) or in the Health app / Health Connect settings. Disconnecting stops new data flowing; you may separately ask us to delete previously imported data.
- The privacy policy shown to you within Health Connect is this same Policy.
8. Automated processing, AI and the SkinIQ Coach
Skin readings, scores and forecasts are generated automatically by our proprietary analysis engine. Product suggestions are generated by matching your readings and stated preferences to product attributes. The SkinIQ Coach may respond using automated systems, a human coach, or both; where an answer is automated the App will say so. None of these processes produces a decision that has a legal or similarly significant effect on you: they do not determine your access to the Services, pricing, insurance, employment or credit, and you always remain free to ignore a suggestion, request that a human coach review a response, or contest a reading by contacting support. We periodically test our models for accuracy across skin tones and phototypes and for unintended bias.
9. Who we share your data with
We do not sell personal data, and we never sell or rent health data. We share personal data only as follows:
| Recipient | What is shared and why |
|---|---|
| Cloud hosting and infrastructure providers | Storage and processing of App data on our behalf. Health data for UAE users is hosted in UAE-located data centres (AWS) |
| Skin-analysis technology provider | Face images and device data, solely to compute readings (see Section 6). |
| Licensed partner laboratories and phlebotomy/sample-collection providers | Name, contact details, date of birth, sample identifiers and delivery address so the kit can be dispatched, the sample collected and analysed, and results returned to us. Laboratories are licensed by the relevant UAE health authority (DHA / DoH / MOHAP) or, in the UK, by the appropriate regulator. |
| Partner clinics (for example Kaya Skin Clinic) | Only if you book a treatment through the App: your name, contact details and the booking. Your scan readings are shared only if you tick the option to share them with the clinic. |
| Product brands and fulfilment/delivery partners | Order contents, delivery name, address and phone number, so products can be picked, packed and delivered within the UAE. Brands never receive your skin readings, biomarkers or health data. |
| Payment processors and app stores | Payment and subscription data handled by Apple (App Store), Google (Google Play) and our card processor (Stripe). Their own privacy policies apply to the data they hold. |
| Customer-support, email, push-notification and analytics tools | Account, device and usage data to run support and send service or (with consent) marketing messages, and to measure how the App performs. We configure analytics tools so that health data and images are not sent to them. |
| Professional advisers, insurers, auditors | As needed to obtain advice, insurance or audit services, under confidentiality. |
| Regulators, courts and law enforcement | Where required by law, a valid legal order, or to protect the rights, safety or property of SkinIQ, our users or the public. |
| A buyer or successor | In connection with a merger, acquisition, financing or sale of all or part of our business, subject to this Policy continuing to apply. |
Each service provider is bound by a written data-processing agreement requiring it to act only on our instructions, to keep data confidential and secure, and to delete or return it when the engagement ends. A current list of our principal sub-processors is available on request.
10. International transfers and data localisation
UAE health data. Federal Law No. 2 of 2019 on the Use of Information and Communication Technology in Health Fields (the “ICT Health Law”) and its implementing resolutions require health information relating to individuals in the UAE to be stored and processed within the UAE except in cases permitted by the competent health authority. Accordingly, blood-biomarker results, skin readings and connected-health data belonging to users in the UAE are stored on servers located in the UAE, and we transfer such data outside the UAE only where a permitted exception applies (for example with your explicit request and consent, or as approved by the relevant authority) and with appropriate safeguards.
Other transfers from the UAE. Where other personal data is transferred outside the UAE (for example to service providers in the EEA, the UK or the United States), we do so under PDPL Articles 22 and 23: to jurisdictions with an adequate level of protection as recognised by the UAE Data Office, or otherwise under contractual clauses that impose PDPL-equivalent obligations on the recipient, or where another lawful ground applies, including your express consent.
Transfers from the UK and EEA. If you use the Services from the UK or the EEA, your data will be transferred to the UAE, which has not been the subject of an adequacy decision by the UK or the European Commission. We protect such transfers using the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses, supplemented where necessary by additional technical measures such as encryption, and we carry out transfer risk assessments. A copy of the relevant clauses can be obtained from our DPO.
11. How long we keep your data
| Data | Retention period |
|---|---|
| Account data | For as long as your account is open, then deleted within 30 days of account deletion, save for records we must keep by law. |
| Original face-scan images | 90 days from capture (then deleted or irreversibly de-identified), unless you delete them sooner or have opted in to model improvement. |
| Derived skin readings, scores and forecasts | Life of the account; deleted with the account. Anonymised, aggregated statistics may be retained indefinitely. |
| Blood-biomarker results | Life of the account. Where UAE health regulations require the laboratory or us to retain health records for a minimum statutory period (currently up to 25 years under the ICT Health Law framework), the record is retained in restricted archive form for that period only and is not used for any other purpose. |
| Connected wearable data | Rolling 24 months, or until you disconnect and request deletion. |
| SkinIQ Coach conversations | Life of the account or 24 months from the last message, whichever is shorter. |
| Orders, invoices, payment records | Minimum 5 years after the end of the tax year, as required by UAE VAT law and equivalent UK/EU rules. |
| Support communications | 3 years from closure of the ticket. |
| Marketing preferences and suppression lists | Until you withdraw consent; suppression records kept indefinitely so we can honour opt-outs. |
| Technical logs | 12 months (security logs up to 24 months). |
12. Your rights and choices
Subject to the conditions and exemptions in applicable law, you have the right to:
- Access the personal data we hold about you and receive a copy, together with information about how it is processed (PDPL Art. 13; GDPR Art. 15).
- Portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible (PDPL Art. 13; GDPR Art. 20). The App includes an “Export my data” function.
- Rectification of inaccurate or incomplete data (PDPL Art. 15; GDPR Art. 16).
- Erasure of your data (PDPL Art. 15; GDPR Art. 17), including by deleting your account in-App.
- Restriction of processing in the circumstances set out in law (PDPL Art. 16; GDPR Art. 18).
- Object to processing based on legitimate interests, and to direct marketing at any time (PDPL Art. 17; GDPR Art. 21).
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (PDPL Art. 6; GDPR Art. 7). Withdrawing consent to process face images, biomarkers or wearable data will mean the related features stop working.
- Not be subject to solely automated decisions producing legal or similarly significant effects, and to request human intervention (PDPL Art. 18; GDPR Art. 22).
- Complain to a supervisory authority: in the UAE, the UAE Data Office (and, for health data, the relevant health authority); in the UK, the Information Commissioner’s Office (ico.org.uk); in the EEA, the data protection authority of your country of residence. We would appreciate the chance to address your concern first.
To exercise any right, use the tools in the App (Settings → Privacy), email [email protected], or write to our DPO. We may need to verify your identity. We respond within one month (extendable by two further months for complex requests, in which case we will tell you), and we do not charge a fee unless a request is manifestly unfounded or excessive.
13. Deleting your account
You can delete your account at any time from within the App (Settings → Account → Delete account) without contacting support, in line with Apple and Google requirements. Deletion removes your profile, scans, readings, scores, coach history, connected-health data and preferences from our active systems within 30 days. We retain only what we are legally required to keep (for example invoices and any health records subject to a statutory retention period), in restricted form, and anonymised data that can no longer be linked to you. Deleting the App from your device does not delete your account; deleting your account does not cancel an App Store or Google Play subscription, which you must cancel in your store settings.
14. Children
The Services are intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18, and the App asks you to confirm your age at sign-up. If you believe a person under 18 has provided us with personal data, please contact us and we will delete it. In jurisdictions where the applicable age of digital consent differs, we apply the higher of 18 and that age.
15. Marketing, notifications and tracking
- Marketing. We send marketing emails or push notifications only with your consent (or, where permitted, to existing customers about similar products with an easy opt-out). You can opt out at any time via the unsubscribe link, in Settings → Notifications, or by contacting us. We never use your skin readings, biomarkers or health-platform data to target marketing unless you separately and explicitly opt in to personalised offers.
- Push notifications. Used for scan reminders, order updates and, with consent, offers. Control them in your device settings.
- App Tracking Transparency. We do not track you across other companies’ apps or websites for advertising, and we do not share data with advertising networks for cross-app tracking. If this changes, we will request your permission through Apple’s App Tracking Transparency prompt or the Android equivalent.
- Cookies and SDKs. The App uses a small number of third-party software development kits for crash reporting, analytics and customer support. Our website uses cookies as described in our Cookie Notice at https://bien-etre.ai
16. How we protect your data
We apply technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit (TLS 1.2 or higher) and at rest, segregation of health data from other data, role-based access controls and multi-factor authentication for staff, logging and monitoring, regular vulnerability testing, secure development practices, staff confidentiality obligations and training, and vendor due diligence. Health data hosted in the UAE is held on infrastructure that meets the requirements of the relevant UAE health authority (including, where applicable, the ADHICS standard in Abu Dhabi and DHA information-security requirements in Dubai). No system is completely secure; if we become aware of a personal-data breach that is likely to result in a risk to you, we will notify the competent authority within the period required by law and inform you without undue delay where the risk is high.
17. Third-party services and links
The App is distributed through the Apple App Store and Google Play, and relies on services provided by Apple and Google (for example sign-in, payments, Health platforms, push notifications). Those companies process data under their own privacy policies. The App may contain links to partner clinics, brand websites or educational content that we do not control; this Policy does not apply to them.
18. Region-specific information
18.1 United Kingdom and European Economic Area
For users in the UK, Bien-Etre Ltd is our UK establishment and representative. For users in the EEA, our representative under GDPR Article 27 is George Skinitis, 4th floor, Akti Miaouli & Skouze 1, Piraeus 185 35 Greece and may be contacted at [email protected]. The legal bases in Section 5, the rights in Section 12 and the transfer safeguards in Section 10 apply. The lead supervisory authority for our UK processing is the ICO.
18.2 California and other US states
If you are a resident of California or another US state with a comprehensive privacy law, you have the rights to know, access, correct, delete and obtain a portable copy of your personal information, to opt out of the sale or sharing of personal information and of targeted advertising, to limit the use of sensitive personal information, and not to be discriminated against for exercising your rights. We do not sell or share personal information for cross-context behavioural advertising, and we use sensitive personal information (including health and biometric-adjacent data) only for the purposes permitted by law to provide the Services you request. The categories of personal information we collect, our purposes and the categories of recipients are set out in Sections 4, 5 and 9. You may exercise your rights via the App or [email protected]; an authorised agent may act for you with written permission. We do not knowingly collect data of consumers under 16. Consumer Health Data (for the purposes of the Washington My Health My Data Act and similar laws) is collected and shared only as described in this Policy and with your consent.
18.3 Other countries
If you use the App from a country not listed above, we process your data as described in this Policy and, where local law gives you additional rights, we will honour them to the extent required.
19. Changes to this Policy
We may update this Policy from time to time. We will post the updated version in the App and on our website with a new effective date and, if the changes are material or affect how we use sensitive data, we will notify you in the App or by email and, where required, ask for your consent again before the change takes effect. Continued use after the effective date of a non-material change constitutes acceptance of the updated Policy.
20. Contact us
Bien-Etre Diagnostics FZCO (SkinIQ) — DSO-IFZA, Dubai, United Arab Emirates. Data Protection Officer: [email protected]. Customer support: [email protected] UK affiliate: Bien-Etre Ltd, 123 Minories, London EC3N 1NT. Website: https://bien-etre.ai
Last updated: 02 September 2026.