← Back to Phimetra

Regulatory Compliance

Last updated: April 30, 2026

1. Product status

Phimetra is an informational decision-support tool for aesthetics. It is not a medical device within the meaning of Regulation (EU) 2017/745 (MDR). The results provided are indicative algorithmic estimates and never replace the advice of a qualified practitioner.

The system makes no medical diagnosis, prescription or therapeutic recommendation. Biometric scores (facial symmetry, golden triangle, youth vectors) are statistical measurements, not medical assessments.

2. GDPR — Biometric data (Article 9)

Morphological analysis involves processing data that may be classified as biometric within the meaning of Article 9 GDPR. This processing relies on the user's explicit consent, collected before each analysis via a dedicated consent form.

  • Photos stored encrypted for 30 days, then automatically deleted.
  • No biometric template database is created.
  • Diagnostic results are kept for a maximum of 12 months, then automatically deleted.

3. GDPR — Data protection principles (Article 35)

Phimetra applies the data-protection principles set out in the GDPR for image processing: data minimisation, encryption, limited retention period (30 days) and automatic deletion.

  • The necessity and proportionality of biometric processing
  • Risks to the rights and freedoms of data subjects
  • Technical and organisational security measures in place
  • Automated data-deletion mechanisms

4. EU Artificial Intelligence Regulation (AI Act)

Phimetra is self-classified as a limited-risk AI system within the meaning of Regulation (EU) 2024/1689. In accordance with Article 50 (transparency obligations), we inform users that:

  • Results are generated by artificial intelligence
  • The system makes no autonomous decision affecting users' rights
  • A clear notice is displayed before and after each analysis
  • The system is not a medical device and is not intended for diagnostic use

5. Data location and security

  • Hosting: France (self-hosted PocketBase)
  • Photos: stored encrypted for 30 days, then automatically deleted
  • Diagnostics: kept for a maximum of 12 months
  • Encryption: TLS 1.3 in transit (AES-256-GCM). At rest: restricted access and automatic deletion after 30 days
  • No transfer outside the EU

6. Your rights

Under the GDPR you have the following rights:

  • Right of access: obtain a copy of your personal data
  • Right of rectification: correct inaccurate data
  • Right of erasure: request deletion of your data
  • Right to object: object to the processing of your data
  • Right to portability: receive your data in a structured format

To exercise these rights, contact us at: [email protected]

You may also lodge a complaint with the CNIL (French data-protection authority): www.cnil.fr

Compliance | Phimetra - Clinical beauty measurement