Legal
Privacy policy
Last updated 21 August 2026
FacialSense is an aesthetic consultation platform used by clinics and their clients. This policy explains what personal information we handle, why, who it is shared with, and the rights you have over it. It is written for both audiences: clinic owners who hold an account with us, and clients who are scanned by a clinic.
1. Who we are
FacialSense (facialsense.app) is operated by Yorkshire Technology Solutions Ltd, registered in the United Kingdom. You can reach us any time at support@facialsense.app.
2. The two relationships
If you run a clinic account, we are the data controller for your account information (your name, email, business details, billing status).
If you are a client scanned by a clinic, your clinic is the data controller for your consultation records, and FacialSense processes that data on the clinic's behalf as their data processor. Your clinic decides how long your records are kept and can delete them at your request; their own privacy policy also applies.
3. Information we collect
Clinic account data
Clinic name, login email, business contact details, logo, booking link, and subscription status.
Consultation data
The client's name and contact details captured at intake, their consent record, facial photographs, and the AI-generated assessment (scores, findings, recommendations, aftercare).
Consent and intake forms
Where a clinic attaches its own forms, whether the client ticked or signed them, and a copy of any document the client uploads back. This can include health-history information the clinic's own form asks for.
Purchase data
When a client buys from a clinic, the item, amount, and the buyer's name and email. Card details are entered directly with our payment processor and never pass through or get stored on FacialSense systems.
Reviews
If a client chooses to leave a review, their rating and any comment are shown publicly on the clinic's booking page to anyone with the link, alongside their first name and last initial only.
Technical data
Anonymous page-view analytics to understand product usage. We do not run advertising trackers.
4. Facial images, special category data
Facial photographs are sensitive personal information and are handled with extra care, processed only with the explicit consent recorded before every scan. Images are stored encrypted in access-controlled private storage and are never published to public URLs.
Images are used for exactly two purposes: producing the AI assessment, and comparing the client's own scans over time so their progress can be measured. To keep comparisons fair, images may be adjusted for brightness and colour consistency. They are never used to identify anyone across other services, never used for surveillance, never used for advertising, and never sold.
Images are kept until the client's record or the clinic's account is deleted, since that retention is what supports the progress-tracking feature the client consented to.
5. How the AI processing works
Each scan is analysed by a third-party AI model provider acting under our instructions as a processor: alongside the image (and, for returning clients, their previous image for direct comparison), the model also receives the client's name and any answers they've given the clinic through an intake or Skin Profile form (see below for how each is used). Our AI and infrastructure providers are contractually prohibited from using this data to train their models, build profiles, or serve advertising. Assessments are aesthetic estimates, not medical findings.
Each finding also carries a confidence level (High, Moderate, or Low), based on how clearly the image supports it, shown to the practitioner alongside the finding itself. The assessment is designed to judge pigmentation, redness, and similar findings relative to each individual's own skin tone, not a fixed standard, and results are always shown as qualitative bands rather than precise scores, since a single photograph cannot support that level of precision. See Keeping your data safe for the fuller explanation.
If a clinic collects a Skin Profile (skin type, goals, routine, sun exposure) through a form built in FacialSense, those answers are used to personalise which of the clinic's treatments and products the AI recommends. This is separate from any medical or consent form answers, which are used only to avoid recommending something unsafe, and neither ever changes the AI's visual findings.
Clients may consent to their data being used to help us continuously improve the FacialSense service.
6. Who we share data with
We share data only with the service providers needed to run the platform, each under a data processing agreement: cloud database, authentication, and encrypted file-storage providers (hosted within the European Economic Area); AI model providers for analysis of scan images; payment processors for subscription billing and clinic sales; email delivery providers for transactional email; and application-hosting providers for the platform and anonymous analytics.
We do not sell personal data and we do not share it with advertisers.
7. Emails we send
Most emails to clinic clients are transactional and sent on the clinic's behalf, carrying the clinic's name and branding: scan invites, scan results, approved recommendations, purchase confirmations, booking confirmations, a link to complete any outstanding forms, and, where the clinic has opted in, follow-up reminders, limited to one per visit. Replies route to the clinic.
8. Marketing emails
A clinic on our Professional plan can also choose to send its own marketing campaigns to its clients - offers, announcements, newsletters. A clinic sends these deliberately and chooses who receives them (for example, everyone, or just clients who haven't visited recently); FacialSense does not send marketing email on its own initiative or choose the audience. Every marketing email carries the clinic's branding and a working unsubscribe link, as the law requires - unsubscribing never affects results, receipts, or appointment emails.
9. Payments and bookings
When a client buys a product or service, checkout runs through the clinic's own account with our designated payment processor: the clinic is the merchant, the charge appears under the clinic's name, and refunds are handled by the clinic. FacialSense never holds funds or card details. Booking links route to the clinic's own booking system, where that provider's privacy policy applies.
10. Retention and deletion
- Consultation records are kept while the clinic's account is active, so clients can see their history and progress.
- Deleting a client's record removes their data, facial images, reports, and any uploaded form copies in a single action.
- Deleting a clinic account removes the practice's client records and images. Order records are anonymised instead of destroyed; names and contact details are scrubbed while amounts and dates are retained, as financial record-keeping requires.
- Deleted data leaves our operational systems immediately and expires from short-term recovery backups on a rolling schedule.
11. Your rights
You can ask to see the data we hold about you, to correct it, or to have it deleted, and you can withdraw consent at any time. Clients should contact their clinic first (as the holder of their records); either way, we support every request. Just email support@facialsense.app.
12. What FacialSense is not
FacialSense provides aesthetic assessments for consultation and documentation purposes. It is not a medical device, does not diagnose conditions, and its outputs are estimates, presented as qualitative bands, not clinical measurements.
FacialSense
Operated by Yorkshire Technology Solutions Ltd · 5 Brayford Square, London E1 0SG, United Kingdom
support@facialsense.app