Privacy Policy
Effective Date: April 21, 2025
This Privacy Policy explains how J-META ("we","our", or "us"), the operator of
Aestifora ("Service"), collects, uses, discloses, and protects your personal information
when you use our global online platform for medical aesthetic professionals. This policy is designed
to comply with international privacy laws including the
EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA/CPRA),
and other applicable data protection standards.
1. Information We Collect
We collect personal information that you provide us directly, from third party sources,
and automatically when you use the Services as follows:
A. Information You Provide
Required Information:
- Full Members (verified medical professionals): Tracks Partner engagement in co-marketing initiatives, event participation, training programs, and other partner- related activities. Data may be used for partner evaluation and program eligibility.
- Associate Members: Name, email address
Optional Information (Provided at Your Discretion):
You may voluntarily provide additional information to enhance your
profile or participation in the Service, including:
- Associate Members
- Date of birth
- Mobile phone number
- Address (city, state, country)
- Career history
- Educational background
- Major/field of study
- Degree acquisition date
- Company/Institution affiliation
- Areas of interest
- Publications
- Research activities
- Professional awards
- Academic society memberships or activities
- Payment details via PayPal (we do not store sensitive financialdata)
- Purchase history
- Usage logs, error logs
2. Purpose and Legal Basis for Processing (for GDPR)
We process your personal data for the following purposes, based on the listed legal bases:
Purpose | Legal Basis |
---|---|
Account registration and user verification | Legal Basis |
Credential verification for Full Members | Legitimate interest |
Access to content and services | Contract |
Payment processing via PayPal | Contract |
Customer service and technical support | Legitimate interest |
Service improvement and analytics | Legitimate interest |
Marketing communications (optional) | Consent |
Fraud prevention and legal compliance | Legal obligation / Legitimate interest |
3. How We Share Your Information
We do not sell or share your personal information with third parties for commercial purposes.
However, we may share your data in the following situations:
- Service Providers: We use trusted third-party services such as: PayPal – for payment processing
- Legal Compliance: If required by law, court order, or legal process
- With Your Consent: When you give explicit permission
4. Data Retention
Your data may be stored or processed in countries outside your residence, including countries that may not provide the same level of data protection. In such cases, we take appropriate safeguards (e.g., Standard Contractual Clauses, data transfer agreements) to ensure your rights are protected.5. Retention of Personal Data
We retain personal data only as long as necessary:
- Member account data: Until account deletion
- Purchase and payment data: 5 years (as required by tax and commercial law)
- Access and log data: 3 months (per security guidelines)
6. Your Rights
Depending on your jurisdiction (e.g., EU/EEA or California), you may have the following rights:
- Access to your personal data
- Correction of inaccurate information
- Deletion ("right to be forgotten")
- Restriction of processing
- Data portability
- Objection to processing
- Withdrawal of consent (for marketing, etc.)
-
California (CCPA/CPRA) Specific Rights:
- - Right to know what data we collect
- - Right to opt-out of sale or sharing of data (we do not sell)
- - Right to non-discrimination for exercising rights
To exercise these rights, please contact us through
the contact form available on our website.
7. Data Security Measures
We implement industry-standard safeguards to protect your personal information:
- Encryption of sensitive data (e.g., passwords)
- SSL/TLS for secure transmission
- Access controls and staff training
- Network firewalls and intrusion detection
8. Children’s Privacy
Our service is not intended for children under the age of 16. We do not knowingly collect personal data from minors. If you believe a child has provided personal data to us, please contact us for deletion.9. Changes to This Policy
We may update this Privacy Policy to reflect legal or service changes. We will notify users of significant changes via email or prominent notice on our site prior to the effective date.10. Contact Us
If you have any questions or concerns about this Privacy Policy or your personal data, please contact us:
Data Protection Officer (DPO)
- E-mail: [Insert email address]
- Customer Support: [Insert contact or URL]