Welcome to LYNETTEARLENEMAVEN.COM. We are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, and safeguard your data in compliance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
DPO: Not appointed, as there is currently no legal requirement under Article 37 of the GDPR.
3. Data Collected
We may collect and process the following data:
Identification data (name, surname)
Contact details (email, IP address, country)
Questionnaire responses (skin type, preferences, optional allergies or skin conditions)
Technical data (browser, device, cookies, logs)
Location data (if user consent is given)
4. Purpose of Processing
Your data is processed for the following purposes:
To provide the personalized skincare service based on questionnaire responses
To manage and improve the Website and user experience
To respond to inquiries or support requests
To comply with legal obligations
To prevent fraud or misuse
To send marketing or promotional emails, only with explicit consent
5. Legal Basis for Processing
The processing of data is based on:
Performance of a contract (service delivery)
Explicit user consent
Legitimate interest (security and analytics)
Legal obligations
6. Data Retention
Personal data will be retained only for as long as necessary to provide the service or comply with legal obligations, and will then be deleted or anonymized.
7. Data Sharing
We may share personal data with:
Service providers acting as data processors, listed below
Public authorities, when legally required
Business partners, only with user consent
Our current processors and the data they receive:
Vercel Inc. (USA) — website hosting, cookieless web analytics and performance metrics (consent-gated)
Amazon Web Services (USA) — databases (RDS Postgres, DynamoDB) and encrypted image storage (S3)
PostHog Inc. (USA) — product analytics, error tracking, and masked session replay, only after consent; identified by a pseudonymous user ID, never by email
Google Cloud (USA) — Cloud Vision image analysis for facial skin analysis and product-label scanning; Google OAuth for sign-in
Anthropic PBC (USA) — AI analysis of facial images (with your explicit biometric consent), scanned label text, and skincare questions
Upstash Inc. (USA) — rate limiting and caching; IP addresses are HMAC-hashed before storage
Cloudinary Ltd. — delivery of product and editorial images (CDN)
Adobe Inc. (Typekit) — web font delivery
We do not sell or trade personal data to third parties.
8. International Transfers
We are a US-based controller and the processors listed above are primarily located in the United States, so data of EEA users is transferred to the USA. Transfers rely on the EU–US Data Privacy Framework where the processor is certified, and on EU Standard Contractual Clauses otherwise. Details are available on request.
9. User Rights
Under Articles 15–22 of the GDPR, you have the right to:
Access your data
Rectify or delete it
Restrict or object to processing
Request data portability
Withdraw consent at any time
To exercise these rights, contact us at lynettearlenebrand@gmail.com.
10. Data Security
We implement appropriate technical and organizational measures to protect personal data from unauthorized access, alteration, loss, or misuse.
11. Facial Image Data (Special Category)
If you choose our optional photo-based skin analysis, we process an image of your face. Under Article 9 of the GDPR this is special-category (biometric) data, processed only on the basis of your explicit, separate consent. Specifically:
Your image is sent to Google Cloud Vision to confirm a face is present, and to Anthropic to estimate your skin attributes (these providers act as our sub-processors).
The image is stored encrypted (AES-256) in a private, access-controlled bucket; only a reference key is kept alongside your results.
Where you consent, your image is retained for up to 7 years and used to train and improve our skin-analysis models; otherwise only the derived scores are kept.
You may withdraw consent and request deletion of your image at any time, and we will delete it unless we are legally required to retain it.
Photo-based analysis is for cosmetic purposes only and is not a medical or dermatological diagnosis.
12. California Privacy Rights (CCPA/CPRA)
We do not sell personal information for money. Analytics involving third parties may qualify as "sharing" under the CPRA; you can opt out at any time via the cookie banner, the Cookie Settings link in the footer, or automatically by enabling Global Privacy Control (GPC) in your browser — we honor GPC as a binding opt-out.
California residents may also exercise access, deletion, correction, and portability rights using the tools described in the User Rights section, without discrimination for doing so.
Essential
Required for sign-in, security, and core features.
Always on
Analytics
Usage analytics and anonymized, masked session replay to help us improve the site.
13. EU Representative
As a controller outside the EU offering services to EU users, we are appointing a representative in the Union pursuant to Art. 27 GDPR. Contact details will be published here once the appointment is finalized.
14. Contact Information
For any questions or to exercise your rights, please contact: