1. Product status
Phimetra is an informational decision-support tool for aesthetics. It is not a medical device within the meaning of Regulation (EU) 2017/745 (MDR). The results provided are indicative algorithmic estimates and never replace the advice of a qualified practitioner.
The system makes no medical diagnosis, prescription or therapeutic recommendation. Biometric scores (facial symmetry, golden triangle, youth vectors) are statistical measurements, not medical assessments.
2. GDPR — Biometric data (Article 9)
Morphological analysis involves processing data that may be classified as biometric within the meaning of Article 9 GDPR. This processing relies on the user's explicit consent, collected before each analysis via a dedicated consent form.
- Photos stored encrypted for 30 days, then automatically deleted.
- No biometric template database is created.
- Diagnostic results are kept for a maximum of 12 months, then automatically deleted.
3. GDPR — Data protection principles (Article 35)
Phimetra applies the data-protection principles set out in the GDPR for image processing: data minimisation, encryption, limited retention period (30 days) and automatic deletion.
- The necessity and proportionality of biometric processing
- Risks to the rights and freedoms of data subjects
- Technical and organisational security measures in place
- Automated data-deletion mechanisms
4. EU Artificial Intelligence Regulation (AI Act)
Phimetra is self-classified as a limited-risk AI system within the meaning of Regulation (EU) 2024/1689. In accordance with Article 50 (transparency obligations), we inform users that:
- Results are generated by artificial intelligence
- The system makes no autonomous decision affecting users' rights
- A clear notice is displayed before and after each analysis
- The system is not a medical device and is not intended for diagnostic use
5. Data location and security
- Hosting: France (self-hosted PocketBase)
- Photos: stored encrypted for 30 days, then automatically deleted
- Diagnostics: kept for a maximum of 12 months
- Encryption: TLS 1.3 in transit (AES-256-GCM). At rest: restricted access and automatic deletion after 30 days
- No transfer outside the EU
6. Your rights
Under the GDPR you have the following rights:
- Right of access: obtain a copy of your personal data
- Right of rectification: correct inaccurate data
- Right of erasure: request deletion of your data
- Right to object: object to the processing of your data
- Right to portability: receive your data in a structured format
To exercise these rights, contact us at: [email protected]
You may also lodge a complaint with the CNIL (French data-protection authority): www.cnil.fr