Privacy Policy
Last updated: 2026-09-15
The data controller is Agress Beauty SRL (reg. no. 28935388, Trade Register J2011001002179), operator of the aBeauty Clinique brand and the yes.abeauty.ro website.
Data Protection Officer (DPO): Gabriel Ursan, [email protected]. You may contact the DPO with any question about your data or to exercise your rights.
This policy explains what data we collect through the consultation form on yes.abeauty.ro, why, on what legal basis, who we share it with, and your rights.
This is a translation for your convenience. The Romanian version of this document is the authoritative one; in case of any discrepancy, the Romanian text prevails.
Who we are
Agress Beauty SRL, registered office at B-dul Siderurgiștilor nr. 15, Bl. SD10B, Et. P, Cam. 7, 800479 Galați, județul Galați, România, Trade Register no. J2011001002179 (EUID ROONRC.J2011001002179), tax ID 28935388 (VAT RO28935388).
The 10 aBeauty Clinique locations are workpoints of the same company. When you choose a clinic, your request is routed internally to that location of the controller, not to a separate company.
What data we collect
Identification and contact data: name, email address, phone number, and the aBeauty clinic you choose.
Health data (special category): your questionnaire answers about skin type and concerns and a medical check, e.g. pregnancy or breastfeeding, oncology history, recent isotretinoin use, recent injectable treatments. See the dedicated section below.
Preference and intent data: your aesthetic goals, age band, urgency, and the recommended treatment.
Technical and usage data: IP address (stored as a hash), browser type (user-agent, truncated), the referring page, and campaign parameters (UTM).
Email interaction data: whether a message was opened, which link you clicked and when. See the email-tracking section of the Cookie Policy.
Advertising identifiers (only with marketing consent): click identifiers (gclid, gbraid, wbraid, fbclid) and the _fbp/_fbc cookies, plus irreversibly hashed (SHA-256) versions of your email and phone, used to measure conversions.
Usage analytics data (only with analytics consent): via Hotjar we record how you interact with the site (mouse movements, clicks, scrolls, interaction heatmaps) to understand how it is used. Hotjar is configured to mask displayed and typed text, so questionnaire answers, including health answers, are not recorded.
Purposes and legal bases
Assessing your request and generating a personalised recommendation: we analyse your answers to check whether a treatment suits you and to produce a recommendation. Basis: your consent (Art. 6(1)(a) GDPR) and, for health data, your explicit consent (Art. 9(2)(a) GDPR).
Routing your request to the chosen clinic: we forward the request to the selected aBeauty location so they can contact you. Basis: Art. 6(1)(a) and Art. 9(2)(a) GDPR.
Recovering unfinished requests: if you enter your contact details (name, email, phone) but leave without submitting, we keep them so we can contact you about the interest you expressed. We do not send health answers to external platforms for this purpose. Basis: our legitimate interest (Art. 6(1)(f) GDPR). You can object at any time, while filling in the form (by ticking “Do not keep my data if I do not complete the request”) or later, by writing to the DPO.
Marketing communications by email/SMS: only if you give separate marketing consent. Basis: your consent (Art. 6(1)(a) GDPR and Art. 4(5) of Law 506/2004). You can withdraw it at any time.
Measuring campaign effectiveness (analytics and advertising): only with analytics or marketing cookie consent respectively. Basis: your consent (Art. 6(1)(a) GDPR and Art. 4(5) of Law 506/2004).
Security, abuse prevention and technical operation: anti-bot protection and error monitoring. Basis: our legitimate interest (Art. 6(1)(f) GDPR) in keeping the platform secure and working.
WhatsApp messages
From 2 September 2026 we may write to you on WhatsApp in three distinct situations. (1) Confirming your request from this form and that a colleague will contact you: only if you ticked the dedicated box, on the basis of your consent (Art. 6(1)(a) GDPR). (2) Confirming the activation and each payment of your PRIVE subscription, if you have one, at the number given when subscribing, in performance of the contract (Art. 6(1)(b) GDPR). (3) aBeauty Clinique offers and news: only if you ticked this separately, or if you left your phone number in this form before 2 September 2026, when we introduced the consent boxes, and have not asked us not to contact you; in that case the basis is our legitimate interest in following up the request you left (Art. 6(1)(f) GDPR), and you can object at any time, free of charge. Consent for email or SMS does not extend to WhatsApp, nor the other way round.
Messages are sent through Twilio Inc. (United States), our messaging processor, and delivered through the WhatsApp platform of Meta Platforms Ireland Limited. Transfers to the United States rely on the EU-U.S. Data Privacy Framework and, as a fallback, on the European Commission’s Standard Contractual Clauses. Data processed: phone number, first name, clinic, the content of messages sent and received, and their delivery status. We do not send health information on WhatsApp and do not choose whom to write to on the basis of your questionnaire answers.
Message content is anonymised after 90 days. The proof of your consent, with the exact wording you read, is kept for 3 years. A number with no activity for 12 months is anonymised.
You can opt out at any time, free of charge: reply UNSUBSCRIBE or STOP to any message, use the rights centre on this site, or tell the clinic. Opting out takes effect immediately. After UNSUBSCRIBE or STOP you receive nothing further from us on WhatsApp, confirmations included, until you write START; if you want to drop offers only and keep the confirmations, tell us through the rights centre or at the clinic.
Health data
Your skin answers and the medical check are health data, a special category given extra protection by Art. 9 GDPR.
We process them solely on the basis of your explicit consent (Art. 9(2)(a) GDPR), which you give by ticking a dedicated, separate checkbox at the start of the questionnaire, before you answer the skin questions and the medical check. This consent is needed only to generate your personalised recommendation and to forward your request to the chosen clinic, it is not conditioned on marketing consent.
You can withdraw your consent at any time, with a single click on the link in your confirmation email or by writing to the DPO ([email protected]), without affecting the lawfulness of processing before withdrawal.
We do NOT send health data to advertising or analytics platforms (Meta, Google, OpenAI). To those we send only hashed contact identifiers and the conversion event, never your conditions or treatments.
Profiling and automated processing
To give you a relevant recommendation, our system automatically analyses your answers (skin type and concerns, aesthetic goals, age band, urgency and the chosen treatment) together with usage data, producing a treatment recommendation and an internal interest score (high/medium/low). The logic is rule-based: your answers are compared against predefined criteria, with no opaque algorithm. The score only determines the order and speed at which a human consultant contacts you; it does not affect price, eligibility for a treatment, or the medical recommendation.
This processing is NOT a decision based solely on automated processing producing legal effects concerning you or similarly significantly affecting you within the meaning of Art. 22(1) GDPR: the score denies you no service, does not change your price, does not condition access to a treatment, and replaces no human decision. It is used only to personalise and prioritise how a human consultant at the clinic contacts you; any final decision about a treatment is always made by a physician after a direct conversation.
Even so, we expressly grant you the safeguards set out in Art. 22(3) GDPR: you have the right to obtain human intervention on our part, to express your point of view, and to contest the recommendation or the score. You also have the right to object at any time to processing for direct marketing, including profiling related to it (Art. 21(2) GDPR). Write to [email protected] and a person will review your case.
Who we share data with
The chosen clinic: your request reaches the selected aBeauty location (the same controller).
The clinic's scheduling software: so that the clinic can contact and book you, your request (your name, phone number, email and the treatment you are interested in) is taken into the scheduling application the clinics use. It belongs to the same controller and is maintained by a supplier engaged as a processor. The outcome of the conversation (appointment, attendance, service purchased) comes back to us from there.
Processors acting strictly on our behalf and on our instructions, only within the purposes and the consent you granted: Brevo (Sendinblue), sending emails and measuring their opens and clicks; Twilio, sending SMS; Cloudflare, anti-bot protection and site delivery; Sentry, error monitoring; Render, hosting; Hotjar (Hotjar Ltd, Malta), usage analytics via session recording and interaction heatmaps (only with analytics consent); Google (Google Workspace / Google Sheets), the responsible clinic's operational tracking of lead outcomes (this processor role is distinct from Google's independent-controller role in advertising/analytics).
Trustindex (Trustindex.io): displays the Google-reviews badge on the homepage; on widget load it receives the visitor's IP. It is functional content and is not used for analytics or advertising.
Meta and Google: for advertising measurement and optimisation we send them hashed contact identifiers and the conversion event, only with marketing consent (Meta, Google Ads) or analytics consent (Google Analytics) as applicable. We use Google Tag Manager to load the Google browser tags ONLY after consent (Google Consent Mode v2), namely Google Analytics 4 (analytics) and Google Ads, including remarketing (marketing); these may set cookies in your browser (see the Cookie Policy). For this processing Meta and Google act as controllers (independent or, where applicable, joint), not as mere processors, under their own terms and privacy policies. OpenAI (ChatGPT Ads): since September 2026 we also advertise inside ChatGPT. To measure those campaigns we send OpenAI OpCo, LLC (United States) hashed contact identifiers and the conversion event, plus the click identifier you arrive with from the ad, only with marketing consent. We do not send the treatment type, the funnel you went through, or the questionnaire page address. We load no OpenAI script in your browser and set no OpenAI cookie: the transfer leaves from our own servers only, and if you withdraw your consent nothing further is sent. For this processing OpenAI acts as an independent controller, under its own terms.
We do not sell your data and do not disclose it to other third parties for their own purposes. We may disclose data to authorities where the law requires it.
International data transfers
Some of our providers are in the United States (Meta Platforms Inc., Google LLC, Twilio Inc., Cloudflare Inc., OpenAI OpCo, LLC). Transfers to them rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework, for certified organisations, and/or on the European Commission's Standard Contractual Clauses (SCCs) with supplementary measures, as a fallback. OpenAI does not appear in the list of certified organisations (checked on 7 September 2026), so transfers to OpenAI rely solely on the Standard Contractual Clauses.
Brevo, Sentry (EU region), Render and Hotjar (Hotjar Ltd, Malta) host the data in the European Union. To the extent a provider with a US parent accesses data for technical support, that transfer is covered by the same safeguards (the EU-US Framework and/or SCCs).
You can obtain a copy of the safeguards applied (for example the SCCs), or information about them, by contacting the DPO at [email protected]. The certification of US providers can be checked on the official list at www.dataprivacyframework.gov/list.
As with any transfer outside the EU, the possibility of public-authority access cannot be entirely excluded; we reduce that risk by hashing the contact identifiers and by never sending health data to advertising or analytics providers.
How long we keep data
We keep your contact data and questionnaire answers (including health data) for a maximum of 12 months from the moment you submit your request.
The criteria behind that period are: the usual length of the decision process for an aesthetic treatment, the need to act on your request and get back to you, and the obligation to minimise the processing of sensitive data.
When the period ends, the contact data is deleted, the health answers are removed, and the record remains only in anonymised form (statistics, no personal data). We separately keep proof of consent (without personal data) as a compliance record.
If you withdraw your consent or ask for erasure sooner, we remove the data without delay, except where the law requires us to keep it (for example to establish or defend a legal claim).
Cookies and tracking technologies
We use cookies and similar technologies. Strictly necessary ones work without consent; analytics and marketing ones activate only with your choice in the consent banner. Full details in the Cookie Policy.
The tracking does not stop at the site: the emails we send you carry an open-tracking pixel, and the links in the HTML version are rewritten to pass through Brevo’s servers. We explain exactly what that means, including for the link that opens your data-management page, in the email-tracking section of the Cookie Policy.
Is providing data required?
Providing data is voluntary. If you do not fill in the form or do not give explicit consent for health data, we cannot generate your personalised recommendation and cannot forward your request to the clinic; the rest of the site stays accessible.
Your rights
Under the GDPR you have the right of access to your data and to receive a copy of it (Art. 15), rectification of inaccurate or incomplete data (Art. 16), erasure, the right to be forgotten (Art. 17), restriction of processing (Art. 18), portability, meaning to receive your data in a structured, commonly used and machine-readable format (Art. 20), objection (Art. 21), and the right not to be subject to a decision based solely on automated processing with significant effects (Art. 22).
You can exercise most of these rights yourself, immediately: the link in your confirmation email opens a rights centre where you can download your data as JSON and PDF (Art. 15 and 20), correct your contact details (Art. 16), and withdraw your consent with erasure of your data (Art. 7(3) and Art. 17). No account is needed and you do not have to wait for a reply from us.
Because our processing relies on consent, you may withdraw it at any time, as easily as you gave it: from the rights centre opened by the link in your confirmation email (an action that erases your contact data and questionnaire answers), via the unsubscribe link in marketing messages, or by writing to the DPO, without affecting the lawfulness of earlier processing.
For any other request, or if you no longer have the link, write to the DPO: Gabriel Ursan, [email protected]. We respond within one month.
If you believe the processing infringes your rights, you may lodge a complaint with the Romanian Data Protection Authority (ANSPDCP), B-dul G-ral Gheorghe Magheru no. 28-30, Sector 1, 010336 Bucharest, Romania; tel. +40 318 059 211 / +40 318 059 212; e-mail [email protected]; www.dataprotection.ro. You may also complain to the supervisory authority in the country of your habitual residence or place of work (Art. 77(1) GDPR).
Data security
We apply appropriate technical and organisational measures: encryption in transit, hashing of identifiers, access control, data minimisation, and automatic removal of health data from error logs.
Minors
Aesthetic services are aimed primarily at adults. In Romania, a minor under 16 can consent to online services only with the approval of their legal representative. For minors, the questionnaire routes to a consultation with the expert and requires the parent's or legal representative's approval, and minors' health data is handled exclusively at the clinic. We do not knowingly collect data from minors without that approval.
Changes
We may update this policy; the version in force is the one published here, with the last-updated date above. Significant changes will be flagged on the site.