Skip to content

Legal

Privacy Policy

Bien Etre app
Bien Etre Diagnostics FZCO
Effective date: 2 September 2026
Version 1.0

1. Who we are and what this Policy covers

This Privacy Policy explains how Bien-Etre Diagnostics FZCO (trading as Bien Etre and/or SkinIQ), a company registered in IFZA, Dubai, United Arab Emirates, licence number 66538, with its registered office at DSO-IFZA, Dubai (“Bien Etre”, “SkinIQ”, “we”, “us”, “our”), collects, uses, stores, shares and protects personal data when you download and use the Bien Etre mobile application (the “App”), purchase products or a Membership through the App, complete a SkinIQ blood panel, use the SkinIQ Coach, or interact with our website, customer support and communications (together, the “Services”).

We are the data controller of the personal data described in this Policy. Where we operate in the United Kingdom, our UK affiliate Bien-Etre Ltd (company number 14639762, registered office 123 Minories, London EC3N 1NT) acts as our UK representative and, for UK Members, as joint controller. Our Data Protection Officer can be reached at [email protected] or by post at the address above.

This Policy applies in addition to our Terms of Use. By creating an account or using the Services you acknowledge that you have read this Policy. Where we rely on your consent (for example, to process face images, skin readings, blood-biomarker results or wearable data), we will ask for it separately and clearly, and you may withdraw it at any time as described in Section 12.

2. Summary — the key points

3. SkinIQ is a wellness service, not a medical service

The SkinIQ Score, the individual skin readings, the 30- and 90-day trait forecasts, the blood-panel “skin drivers”, the SkinIQ Coach and any product suggestions are generated for general wellness, self-awareness and cosmetic skincare purposes. They are not intended to diagnose, treat, cure, mitigate or prevent any disease or medical condition, and they do not create a doctor–patient relationship. Blood panels are processed by independent licensed laboratories and are reported to you as wellness biomarkers, not as a clinical diagnosis. Where a reading falls outside a reference range, the App may suggest you speak to a healthcare professional; that suggestion is informational only. Never disregard professional medical advice, or delay seeking it, because of something you have seen in the App.

4. The personal data we collect

We collect personal data in the following categories. Items marked with † are sensitive / special-category data (health data or, in some laws, biometric data) and are collected only with your explicit consent.

CategoryExamplesSource
Account and identityName, email address, mobile number, password (hashed), date of birth or age band, gender (optional), profile photo (optional), language and country settings, login identifiers if you sign in with Apple or Google.You
Face images and skin readings †Selfie images captured through the App camera (or uploaded from your gallery), derived facial-region measurements, skin type, skin tone and tone depth, the 29 skin readings and their 0–100 index values, SkinIQ Score, skin age, score bands and forecasts, and each re-scan over time.You / generated by us
Blood biomarker results †For Members: results of the quarterly finger-prick or venous blood panel processed by our partner laboratory (for example markers of glycation, inflammation, barrier vitamins and lipids, oxygen delivery), reference ranges, collection date, sample identifiers, and the resulting skin-driver scores (Firmness & Structure, Calm & Resilience, Repair & Renewal, Barrier & Glow).Partner laboratory / generated by us
Connected wearable and health-platform data †If you choose to connect Apple Health (HealthKit) or Android Health Connect: the specific data types you authorise, which may include sleep, steps and activity, heart-rate variability, resting heart rate, and (if authorised) skin temperature or cycle data. We request only the types the feature needs and you can revoke access at any time in the App or in your device settings.Your device, with your permission
Lifestyle and questionnaire answers †Answers to optional in-App questions (for example sun exposure, sleep, diet, current skincare routine, known sensitivities or allergies to ingredients, pregnancy or breastfeeding status where relevant to product suitability).You
SkinIQ Coach conversations †Messages you exchange with the SkinIQ Coach (which may be delivered by a human skin coach, by our automated coaching engine, or a combination), and any photos you attach.You
Orders, delivery and paymentProducts ordered, order history, delivery name, address and instructions, contact number for the courier, order value, currency, VAT invoices, refund and return records. Card details are collected and processed by our payment processor or by Apple/Google — we do not store full card numbers.You / payment provider / app store
Membership and subscriptionSubscription tier, start and renewal dates, App Store or Google Play transaction identifiers and receipts, trial status, cancellation.Apple / Google / you
Device, technical and usage dataDevice model and OS version, App version, unique App instance identifier, push-notification token, IP address, approximate location derived from IP or from the delivery address you enter (we do not collect precise GPS location unless you enable it for delivery), crash logs, screens viewed, features used, time spent, and diagnostics.Your device / automatically
CommunicationsSupport tickets, emails, in-App chat, survey responses, reviews and feedback, and records of your marketing preferences.You
Referral and marketingReferral codes, campaign or attribution source, and interactions with our emails or notifications.You / automatically

We use personal data only for the purposes below. The “legal basis” column explains the lawful ground we rely on under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, “PDPL”), the UK GDPR / Data Protection Act 2018 and the EU GDPR (together, “GDPR”). Where a purpose involves sensitive data we rely on your explicit consent (PDPL Article 4(1); GDPR Article 9(2)(a)).

PurposeData usedLegal basis
Create and manage your account; authenticate you; provide customer supportAccount, device, communicationsPerformance of a contract (our Terms of Use)
Perform the face scan and generate skin readings, SkinIQ Score, skin age and forecastsFace images, skin readings, questionnaire answersExplicit consent
Arrange, process and present your blood panel and skin-driver scoresBlood biomarker results, account, delivery details for the sample kitExplicit consent; contract (Membership)
Integrate wearable data into your readings and forecastsConnected wearable dataExplicit consent (granted through Apple Health / Health Connect permissions)
Deliver the SkinIQ Coach serviceCoach conversations, skin readings, biomarkers, questionnaire answersExplicit consent; contract (Membership)
Generate personalised product suggestions inside the AppSkin readings, questionnaire answers (including stated ingredient sensitivities), order historyExplicit consent (for health-based personalisation); legitimate interests (order history)
Process orders, take payment, deliver products, handle returns and warranty claims, issue VAT invoicesOrders, delivery and payment, accountPerformance of a contract; legal obligation (tax and consumer law)
Manage Memberships, renewals, trials and cancellationsMembership and subscription, accountPerformance of a contract
Send service messages (scan reminders, order updates, security alerts, changes to terms)Account, devicePerformance of a contract; legitimate interests
Send marketing communications and personalised offersAccount, communications, order history (never health data unless you separately opt in)Consent (which you may withdraw at any time); soft opt-in for existing customers where the law permits
Maintain, secure, debug and improve the App; prevent fraud and abuseDevice, technical and usage dataLegitimate interests (running a secure and reliable service)
Research and improve our skin-analysis and forecasting models (the SkinIQ Predictive Health Intelligence Engine)De-identified or aggregated skin readings, biomarkers and outcomes; face images only where you have separately opted inExplicit consent (identifiable data); legitimate interests (aggregated or anonymised data)
Comply with law, respond to lawful requests, establish or defend legal claimsAny category as requiredLegal obligation; legitimate interests
Corporate transactions (merger, financing, sale of assets)Any category, subject to confidentialityLegitimate interests

Where we rely on legitimate interests we have balanced those interests against your rights and freedoms; you may object to such processing at any time (Section 12). We will not use your data for a purpose incompatible with those described here without telling you first and, where required, obtaining your consent.

6. Face images and skin readings — how we handle them

7. Apple Health, Health Connect and other health-platform data

If you connect Apple Health (HealthKit) or Android Health Connect, the following commitments apply in addition to the rest of this Policy, and reflect the Apple Developer Program License Agreement, the Apple App Store Review Guidelines, and the Google Play Health Apps and Health Connect policies:

8. Automated processing, AI and the SkinIQ Coach

Skin readings, scores and forecasts are generated automatically by our proprietary analysis engine. Product suggestions are generated by matching your readings and stated preferences to product attributes. The SkinIQ Coach may respond using automated systems, a human coach, or both; where an answer is automated the App will say so. None of these processes produces a decision that has a legal or similarly significant effect on you: they do not determine your access to the Services, pricing, insurance, employment or credit, and you always remain free to ignore a suggestion, request that a human coach review a response, or contest a reading by contacting support. We periodically test our models for accuracy across skin tones and phototypes and for unintended bias.

9. Who we share your data with

We do not sell personal data, and we never sell or rent health data. We share personal data only as follows:

RecipientWhat is shared and why
Cloud hosting and infrastructure providersStorage and processing of App data on our behalf. Health data for UAE users is hosted in UAE-located data centres (AWS)
Skin-analysis technology providerFace images and device data, solely to compute readings (see Section 6).
Licensed partner laboratories and phlebotomy/sample-collection providersName, contact details, date of birth, sample identifiers and delivery address so the kit can be dispatched, the sample collected and analysed, and results returned to us. Laboratories are licensed by the relevant UAE health authority (DHA / DoH / MOHAP) or, in the UK, by the appropriate regulator.
Partner clinics (for example Kaya Skin Clinic)Only if you book a treatment through the App: your name, contact details and the booking. Your scan readings are shared only if you tick the option to share them with the clinic.
Product brands and fulfilment/delivery partnersOrder contents, delivery name, address and phone number, so products can be picked, packed and delivered within the UAE. Brands never receive your skin readings, biomarkers or health data.
Payment processors and app storesPayment and subscription data handled by Apple (App Store), Google (Google Play) and our card processor (Stripe). Their own privacy policies apply to the data they hold.
Customer-support, email, push-notification and analytics toolsAccount, device and usage data to run support and send service or (with consent) marketing messages, and to measure how the App performs. We configure analytics tools so that health data and images are not sent to them.
Professional advisers, insurers, auditorsAs needed to obtain advice, insurance or audit services, under confidentiality.
Regulators, courts and law enforcementWhere required by law, a valid legal order, or to protect the rights, safety or property of SkinIQ, our users or the public.
A buyer or successorIn connection with a merger, acquisition, financing or sale of all or part of our business, subject to this Policy continuing to apply.

Each service provider is bound by a written data-processing agreement requiring it to act only on our instructions, to keep data confidential and secure, and to delete or return it when the engagement ends. A current list of our principal sub-processors is available on request.

10. International transfers and data localisation

UAE health data. Federal Law No. 2 of 2019 on the Use of Information and Communication Technology in Health Fields (the “ICT Health Law”) and its implementing resolutions require health information relating to individuals in the UAE to be stored and processed within the UAE except in cases permitted by the competent health authority. Accordingly, blood-biomarker results, skin readings and connected-health data belonging to users in the UAE are stored on servers located in the UAE, and we transfer such data outside the UAE only where a permitted exception applies (for example with your explicit request and consent, or as approved by the relevant authority) and with appropriate safeguards.

Other transfers from the UAE. Where other personal data is transferred outside the UAE (for example to service providers in the EEA, the UK or the United States), we do so under PDPL Articles 22 and 23: to jurisdictions with an adequate level of protection as recognised by the UAE Data Office, or otherwise under contractual clauses that impose PDPL-equivalent obligations on the recipient, or where another lawful ground applies, including your express consent.

Transfers from the UK and EEA. If you use the Services from the UK or the EEA, your data will be transferred to the UAE, which has not been the subject of an adequacy decision by the UK or the European Commission. We protect such transfers using the UK International Data Transfer Agreement or Addendum and the EU Standard Contractual Clauses, supplemented where necessary by additional technical measures such as encryption, and we carry out transfer risk assessments. A copy of the relevant clauses can be obtained from our DPO.

11. How long we keep your data

DataRetention period
Account dataFor as long as your account is open, then deleted within 30 days of account deletion, save for records we must keep by law.
Original face-scan images90 days from capture (then deleted or irreversibly de-identified), unless you delete them sooner or have opted in to model improvement.
Derived skin readings, scores and forecastsLife of the account; deleted with the account. Anonymised, aggregated statistics may be retained indefinitely.
Blood-biomarker resultsLife of the account. Where UAE health regulations require the laboratory or us to retain health records for a minimum statutory period (currently up to 25 years under the ICT Health Law framework), the record is retained in restricted archive form for that period only and is not used for any other purpose.
Connected wearable dataRolling 24 months, or until you disconnect and request deletion.
SkinIQ Coach conversationsLife of the account or 24 months from the last message, whichever is shorter.
Orders, invoices, payment recordsMinimum 5 years after the end of the tax year, as required by UAE VAT law and equivalent UK/EU rules.
Support communications3 years from closure of the ticket.
Marketing preferences and suppression listsUntil you withdraw consent; suppression records kept indefinitely so we can honour opt-outs.
Technical logs12 months (security logs up to 24 months).

12. Your rights and choices

Subject to the conditions and exemptions in applicable law, you have the right to:

To exercise any right, use the tools in the App (Settings → Privacy), email [email protected], or write to our DPO. We may need to verify your identity. We respond within one month (extendable by two further months for complex requests, in which case we will tell you), and we do not charge a fee unless a request is manifestly unfounded or excessive.

13. Deleting your account

You can delete your account at any time from within the App (Settings → Account → Delete account) without contacting support, in line with Apple and Google requirements. Deletion removes your profile, scans, readings, scores, coach history, connected-health data and preferences from our active systems within 30 days. We retain only what we are legally required to keep (for example invoices and any health records subject to a statutory retention period), in restricted form, and anonymised data that can no longer be linked to you. Deleting the App from your device does not delete your account; deleting your account does not cancel an App Store or Google Play subscription, which you must cancel in your store settings.

14. Children

The Services are intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18, and the App asks you to confirm your age at sign-up. If you believe a person under 18 has provided us with personal data, please contact us and we will delete it. In jurisdictions where the applicable age of digital consent differs, we apply the higher of 18 and that age.

15. Marketing, notifications and tracking

16. How we protect your data

We apply technical and organisational measures appropriate to the sensitivity of the data, including encryption in transit (TLS 1.2 or higher) and at rest, segregation of health data from other data, role-based access controls and multi-factor authentication for staff, logging and monitoring, regular vulnerability testing, secure development practices, staff confidentiality obligations and training, and vendor due diligence. Health data hosted in the UAE is held on infrastructure that meets the requirements of the relevant UAE health authority (including, where applicable, the ADHICS standard in Abu Dhabi and DHA information-security requirements in Dubai). No system is completely secure; if we become aware of a personal-data breach that is likely to result in a risk to you, we will notify the competent authority within the period required by law and inform you without undue delay where the risk is high.

The App is distributed through the Apple App Store and Google Play, and relies on services provided by Apple and Google (for example sign-in, payments, Health platforms, push notifications). Those companies process data under their own privacy policies. The App may contain links to partner clinics, brand websites or educational content that we do not control; this Policy does not apply to them.

18. Region-specific information

18.1 United Kingdom and European Economic Area

For users in the UK, Bien-Etre Ltd is our UK establishment and representative. For users in the EEA, our representative under GDPR Article 27 is George Skinitis, 4th floor, Akti Miaouli & Skouze 1, Piraeus 185 35 Greece and may be contacted at [email protected]. The legal bases in Section 5, the rights in Section 12 and the transfer safeguards in Section 10 apply. The lead supervisory authority for our UK processing is the ICO.

18.2 California and other US states

If you are a resident of California or another US state with a comprehensive privacy law, you have the rights to know, access, correct, delete and obtain a portable copy of your personal information, to opt out of the sale or sharing of personal information and of targeted advertising, to limit the use of sensitive personal information, and not to be discriminated against for exercising your rights. We do not sell or share personal information for cross-context behavioural advertising, and we use sensitive personal information (including health and biometric-adjacent data) only for the purposes permitted by law to provide the Services you request. The categories of personal information we collect, our purposes and the categories of recipients are set out in Sections 4, 5 and 9. You may exercise your rights via the App or [email protected]; an authorised agent may act for you with written permission. We do not knowingly collect data of consumers under 16. Consumer Health Data (for the purposes of the Washington My Health My Data Act and similar laws) is collected and shared only as described in this Policy and with your consent.

18.3 Other countries

If you use the App from a country not listed above, we process your data as described in this Policy and, where local law gives you additional rights, we will honour them to the extent required.

19. Changes to this Policy

We may update this Policy from time to time. We will post the updated version in the App and on our website with a new effective date and, if the changes are material or affect how we use sensitive data, we will notify you in the App or by email and, where required, ask for your consent again before the change takes effect. Continued use after the effective date of a non-material change constitutes acceptance of the updated Policy.

20. Contact us

Bien-Etre Diagnostics FZCO (SkinIQ) — DSO-IFZA, Dubai, United Arab Emirates. Data Protection Officer: [email protected]. Customer support: [email protected] UK affiliate: Bien-Etre Ltd, 123 Minories, London EC3N 1NT. Website: https://bien-etre.ai

Last updated: 02 September 2026.