Edit Content

Privacy Policy

Updated: October 1, 2025 

PHENICIA MEDICAL SPA is a beauty and medical beauty treatment center. Address: 111 Route de la Valentine, 13011 Marseille – France 

Website: https://phenicia-medical-spa.com

Summary

  1. Personal data collected 
  2. Purposes of processing 
  3. Legal basis 
  4. Recipients of the data 
  5. Hosting and security 
  6. Shelf life 
  7. Cookies and trackers 
  8. Transfers outside the European Union 
  9. Your rights 
  10. Contact and Data Protection Officer (DPO) 
  11. Policy update

 

1. Personal data collected

PHENICIA MEDICAL SPA collects only data that is strictly necessary for the management of its activities and the care of patients: 

  • Contact and information request forms : last name, first name, email address, phone number. 
  • Care referral or pre-eligibility forms (if applicable): information useful for aesthetic or medical-aesthetic assessment, which may include health data within the meaning of Article 9 of the GDPR. 
  • Appointment scheduling : when made via Doctolib, data is processed in accordance with Doctolib's privacy policy. ● Browsing data : IP address, anonymized technical logs, browser information, and cookies (see Cookies section). 
  • Comments or interactions (if applicable): data voluntarily entered by the user, IP address, and user agent for moderation and anti-spam purposes.

2. Purposes of processing

Personal data is collected for the following purposes: 

  • respond to user requests and provide the requested information, ● organize and manage appointments, 
  • provide and monitor cosmetic or medical-cosmetic care, ● comply with applicable legal and regulatory obligations, 
  • improve the quality of the site and the services offered (statistics, audience measurement), 
  • ensure the security of the site and prevent fraudulent use.

3. Legal basis

Data processing is based on the following legal grounds: 

  • Consent (Article 6-1-a GDPR): forms, communications, non-essential cookies, 
  • Execution of pre-contractual or contractual measures (Article 6-1-b GDPR): making appointments and organizing care, 
  • Legal obligations (Article 6-1-c GDPR) and public interest in health matters (Article 9-2-h GDPR) for the processing of health data,
  • Legitimate interest (Article 6(1)(f) GDPR): security, prevention of abuse, and continuous improvement of services.

4. Recipients of the data

Access to personal data is strictly limited: 

  • authorized medical and administrative teams at PHENICIA MEDICAL SPA, ● technical service providers involved in hosting, maintenance, security, or technical tools, acting solely on instruction and subject to a contractual obligation of confidentiality, 
  • to Doctolib, where applicable, for appointment management. 

Personal data is under any circumstances sold or transferred to third parties.

5. Hosting and security

The data is hosted on servers located in France or within the European Union.

When health data is processed, it is hosted by an HDS-approved hosting provider, in accordance with current regulations. 

Appropriate technical and organizational measures are implemented: secure HTTPS connection, access control, regular backups, security updates, and internal data protection procedures. 

Technical maintenance of the site is provided by Charles-Henry Lamitié

6. Retention periods

Data is retained only for as long as necessary for the purposes pursued: 

  • Health data : in accordance with the legal obligations applicable to healthcare institutions (in principle up to 20 years from the last visit, unless otherwise specified by law). 
  • Contact information : 3 years from the last exchange. 
  • Cookies and trackers : Maximum 13 months ; retention of proof of consent: 6 months.
  • Technical data and logs : duration strictly necessary for security and abuse prevention.

7. Cookies and trackers

The site uses: 

  • of cookies strictly necessary for its operation, 
  • cookies audience measurement and/or personalization cookies, subject to your consent. 

During your first visit, a banner allows you to set your preferences. You can change your choices at any time via the cookie management module or your browser settings. 

For more information, see the Cookie Management Policy – PHENICIA MEDICAL SPA.

8. Transfers outside the European Union

In principle, no personal data is transferred outside the European Union. If such a transfer were to occur, it would be governed by standard contractual clauses or any other mechanism recognized as offering an adequate level of protection by the European Commission.

9. Your rights

In accordance with the GDPR and the French Data Protection Act, you have the following rights: 

  • right of access, rectification, and erasure, 
  • right to restriction and objection to processing, 
  • right to data portability, 
  • right to define guidelines regarding the fate of your data after your death. 

You may also lodge a complaint with the competent supervisory authority: CNIL.

10. Contact and Data Protection Officer (DPO)

PHENICIA MEDICAL SPA 

111 Route de la Valentine, 13011 Marseille – France 

Email: contact@cliniquephenicia.com 

To exercise your rights, please specify the subject of your request and attach proof of identity if necessary. 

You will receive a response within maximum of 30 days.

11. Policy update

This privacy policy may be amended at any time to reflect legal, regulatory, technical, or organizational changes. The date of the last update is indicated at the top of the document.