PRIVACY POLICY
Sooma Aesthetics
Last updated: 10 Ferbruary 2026
1. Data Controller
Legal Name: Polina Kazakova
Clinic Name: Sooma Aesthetics
Registered Address:
RUA SARAIVA DE CARVALHO nº 388, 4B
1350-304 Lisbon, Portugal
Service Address:
Av. Liberdade 129, 6º
Lisbon, Portugal
Email: polina.kazakova.med@gmail.com
Phone: +351 913 463 877
Polina Kazakova acts as the Data Controller for the purposes of the General Data Protection Regulation (GDPR).
2. Purpose of Data Processing
Sooma Aesthetics processes personal data strictly for:
- Patient identification and medical record creation
- Medical evaluation and dermatological treatment
- Aesthetic procedures and follow-up
- Appointment scheduling and communication
- Invoicing and legal compliance
- Clinical documentation and consent management
- Legal defense and regulatory obligations
3. Categories of Data Collected
We may process:
- Identification data (name, date of birth, ID, tax number if required for invoice)
- Contact details (phone, email, address)
- Medical history and health-related information
- Photographs (before/after treatment) — only with explicit written consent
- Payment and billing information
Health data constitutes special category data under Article 9 GDPR and is processed exclusively for medical purposes.
4. Legal Basis for Processing
Processing is based on:
- Provision of healthcare services (Art. 9(2)(h) GDPR)
- Explicit patient consent (Art. 9(2)(a))
- Compliance with legal obligations (Portuguese health and tax law)
- Legitimate interest in managing clinical operations
5. Data Retention
Medical records are retained for the period required by Portuguese healthcare law.
Administrative and billing data are retained for up to 10 years in accordance with tax regulations.
Photographs are stored only for clinical documentation unless additional consent is granted for marketing purposes.
6. Data Sharing
Personal data may be shared only with:
- Certified laboratories (if clinically required)
- Accounting services (for invoicing purposes)
- Portuguese tax authorities (legal obligation)
- Healthcare regulatory authorities if required
We do not sell or transfer patient data for commercial purposes.
7. Security Measures
We implement appropriate technical and organizational measures, including:
- Restricted access to medical files
- Encrypted digital storage
- Secure physical storage of paper records
- Confidentiality obligations
8. Patient Rights
Under GDPR, you have the right to:
- Access your data
- Request correction
- Request restriction of processing
- Request deletion (where legally permissible)
- Withdraw consent
- File a complaint with the Portuguese Data Protection Authority (CNPD)
CNPD: www.cnpd.pt
9. Contact for Data Protection
All privacy-related requests should be addressed to:
polina.kazakova.med@gmail.com