Derma OS

privacy notice.

What we hold about you, where it lives, who can see it, and what you may ask for. Every sentence here describes what the system does today.

who we are, and who is responsible

Derma OS is the system that runs the day to day of Derma Bar (the clinic) and Skin Aesthetics Canada College (the college), in Toronto, Ontario.

The clinic is responsible for the information it holds about its clients, and the college for the information it holds about its students.

The person to write to about anything on this page is the owner of the clinic, through the front desk, or the college at its own address, info@skinaestheticscanadacollege.com.

Steven Lansangan, who runs the system for asapcontent, the agency that built and operates Derma OS, answers questions about how it works and passes anything else to the person responsible.

what we hold, and where it comes from

We keep one record per person across the clinic and the college, because the same person is often a client of one and a student of the other.

About a client of the clinic: your name; your date of birth if you gave it; your email addresses and phone numbers; whether you are a prospect or a client, when you were last here, and the standing the clinic gives you from what you have spent with it over the last two years (a tier, explained below); the services you have said you are interested in; your appointments, with the service, the provider, the time, and whether the visit was kept, moved, cancelled or missed; your payments, refunds and tips, the tax on them, and what was bought; short notes the desk writes about your visit or your account; where you first came to us from, and who at the clinic is following you up; any address or note that the card machine's own records of you carry; and your choices about email and text messages, when you made them and how they were recorded.

About a student or a prospective student of the college: the same person record, plus your interest in a course, your enrolment, whether you finished or withdrew, what you paid, when your access to the course materials ends, and a reference to your certificate.

About the staff: name, title, whether they see clients; a login and its role; clock in and clock out times with a note and who entered them; the commission rules and pay periods the owner sets; which person records each of them opened and which files they took out, and why; their commission, their working hours and their time off; which bookings each of them made, moved or cancelled in Acuity from Derma OS, with when, how a booking came in, and the reason given when one went ahead outside what Acuity offered or at a time that meets another visit; and every change any of them makes to any record, with who and when.

About everyone who signs in, a client, a student or a member of staff: for each session of a login, and for each kind of device it is used from, the kind of device (a phone, a tablet or a computer), its system and its browser, the city, region and country the application's host attaches to the request, and when that sign in was first seen, last seen and signed out. The text a browser sends to describe itself and the internet address a request came from are not kept.

Where it comes from: the desk types a person in; a file of existing contacts is uploaded and reviewed row by row before it is kept; the booking system, Acuity, sends each appointment as it is made, and once a night Derma OS reads the last two days and the next two weeks of appointments from it again, so one that was missed is caught; the card machine and online payments, Square, send each payment; and the agency's planning tool, Notion, sends the content calendar, which holds no personal information.

What we do not keep, on purpose: intake forms, treatment notes, consent forms for procedures, and before and after photographs. They stay in the systems that hold them today. When Derma OS reads an appointment from the booking system, the booking system's answer carries that appointment's notes with it, and when it reads one appointment as it is made or changed, its intake form as well; Derma OS keeps none of them, and what it keeps of an appointment is its service, provider, time and outcome, who it was for, and any payment the booking system took for it. When the front desk books, moves or cancels a visit in Acuity from Derma OS, Acuity's answer is that appointment as Acuity holds it, which can carry its notes and its intake form, and when Derma OS reads a provider's appointments for a day to check that a time is free, the answer carries each of those appointments with the client's name, contact details and notes, and no intake form; Derma OS keeps none of it, and uses only an appointment's number, time and length.

The record of which service you had, with which provider, on which day, is information about care you received, even though it is not the clinic's clinical chart. The owner, an administrator, the front desk and the marketing team can read it; a provider reads the visits booked with them and, where the clinic lets its providers book, every visit at the clinic with the client's name. Where the clinic has turned on the client card, a provider also sees the day and service of the last and next visits of a client booked with them.

About cards: we never see or hold a card number. From the card machine we keep the amount, the tax, the tip, the card's brand, and a code that lets us recognise the same card again so a payment can be matched to the right person. The card machine's own message about each payment is kept as it arrived as well, and it can carry the buyer's email address, a billing or shipping address and a note typed at the till; the last four digits of the card are inside it until the housekeeping narrows it, and how long each copy is kept is in the section on how long we keep it.

why we hold it

To book, move and confirm visits and courses; to keep your account and the record of what you bought and paid; to run the desk, which is who is here today and who is arriving; to run the college, which is who is enrolled, what they may open and who has finished; to pay staff and work out commission; to reach you about your own appointment or enrolment; to send offers only where you have said yes, or where a purchase or an enquiry of yours gives the consent the law implies, for as long as the section on your consent says; to keep the business's books; to show a member of staff where their own login is signed in and tell them when it signs in somewhere new; and to keep the system working, secure and provable.

What it is not used for: nothing here is sold, shared or sent to advertisers; no profile is built for anyone else; no analytics or tracking runs on the application, and the record of where a login signed in from is kept for the person whose login it is, shown to nobody else, and used for nothing but showing them where they are signed in and telling them when their account signs in somewhere new; and the record of care you received is not used to market to you unless you have said yes to that in particular.

your consent

In Canada, the rule for a business is your knowledge and consent. Giving the desk your phone number to hold a booking is consent to use it for that booking; saying yes to offers, to the clinic or in your account, is consent to those messages, and it is recorded with when and how it was given.

Some things happen without a separate yes, because they are what you came for or what the law requires: keeping the appointment, keeping the books, paying the staff, keeping the system secure. Marketing is not one of those, except in the one way the law itself allows: a purchase from the clinic is taken as consent for two years from your latest purchase, and an enquiry for six months from when it was recorded, but only where the one it rests on has been recorded on your record, and it lapses on its own when that time runs out. Telling us to stop ends it from the moment that is recorded.

Before a campaign could go out, the owner or an administrator can rehearse it, and a rehearsal sends nothing: Derma OS works out who on the campaign's list it would reach and at which address, and why each other person on the list would not be written to (no consent, a consent whose time has run out, a withdrawal, no address, an address somebody else on the list already gets, or a yes dated no later than the import that brought their record in), and keeps that as a record beside the messages sent. A list drawn from the treatment a person received is refused whole, and every message has to carry the clinic's mailing address.

the tier, and what the reports say about you

The clinic gives each client a standing (a tier) worked out from what they have spent with it over the last twenty four months. It is arithmetic over your purchases, not a judgement about you as a person or about your health, and it changes on its own as time passes, unless the owner or an administrator sets it by hand, which is recorded with the reason they gave.

The clinic also keeps reports of missed and cancelled visits and of clients it has not seen in a while, drawn from the same appointment records.

The clinic also groups its clients by how often they come, from the same appointment records, counting a day at the clinic as one visit however many appointments it held and looking back over the two years it holds; the groups are new, regular, occasional, once, lapsed and no visit on record, and the lines between them are the clinic's own choice. A list the clinic keeps for its messages may be drawn from one of those groups, and nobody on such a list is sent anything without the consent described above.

You may ask how your tier was worked out, which of those groups you are in, and what those reports say about you.

where it lives

The records are in a database in Canada, in Montréal. The pages are put together on servers in Montréal as well; the first step of each visit, which reads the cookie that keeps you signed in, runs at whichever of the host's sites is nearest you. Backups are taken every day and kept for seven days. The address you open is served over an encrypted connection only.

These leave Canada: the emails that carry an invitation to sign in or a link to set a new password are sent by the platform's own mail service, which is outside Canada, and carry your email address and a link and nothing else; the cookie that keeps you signed in, which holds your login's email address, is read at the host's site nearest you, which is outside Canada when you are; the platforms that host the database and the application keep operational logs of each request, as every host does; while the front desk books in Acuity from Derma OS, what Derma OS sends Acuity for a booking, a move or a cancel, which the section on what leaves lists, goes to Acuity, whose servers are outside Canada; and, once Derma OS sends appointment reminders, a reminder by text goes through Twilio and a reminder by email through Resend, both outside Canada, and each carries your number or email address, the service, the provider's public name and the time of the visit, and nothing else about you.

The city, region and country beside a sign in are worked out by the application's host, Vercel, from the internet address the request came from, and handed to the application with the request; the application keeps those three and never the address.

who can see what

Access is by invitation only; nobody can sign up. A forgotten password is recovered only by a link mailed to the login's own address. The owner's and an administrator's logins can be set up to ask for a six digit code from an app on their phone after the password. Every person who signs in has a role, and the role decides what they can see, enforced inside the database itself rather than only on the screens.

The owner and an administrator see everything except where other people's logins signed in from, and are the only ones who can export a list, invite a person, connect an outside system, rehearse a campaign or read the log of changes. The front desk sees the clients and the choices each has made about messages, which it may also record at the counter, the book and, while it books a client in Acuity, which of that client's prepaid packages there can pay for the visit, with the sessions or minutes left and until when, the notes, the day, its own hours on the clock and who else is on the clock right now, whose clock it may stop, the list of records that may be the same person, the reports on who has not been back, who missed a visit, whose birthday is coming, where new clients come from and which first visits bring people back, and the content plan and the campaigns, which it reads and does not change; not the money, and not anyone else's pay. A provider sees their own book, the names of the clients booked with them, their own hours and their own pay, and nobody else's hours or pay. Where the clinic lets its providers book, a provider also sees every provider's day at the clinic with each client's name, the service and the time, books, moves and cancels a visit with any provider, adds a new client, and finds a client by name, email or phone, shown with only the last four digits of their phone or a partly hidden email address; when a provider books a visit in Acuity, Derma OS hands Acuity the client's name, email address and phone number without showing them to the provider, and records each time it does. A client's full email address and phone number are shown to a provider only for a client booked with them, and only where the clinic has turned on the client card, which shows a provider, for a client booked with them in the last 30 days or ahead, that client's tier, their birthday, their email address and phone number, how many visits they have kept, and the day and service of their last and next visits at the clinic; never what they paid, and each card opened is recorded. Where the clinic both lets its providers book and has turned on the client card, a provider also sees the tier of each client on their own book. Marketing works with the client list, each client's visits and notes and message choices, the content calendar, the campaign tools, the open house and the college's enrolments, and the money, the pay and the hours on the clock are kept from it by the database itself rather than by the screens. Where a consent rests on a purchase, the desk and marketing are told only whether a purchase falls inside its two years, never what it was or what it cost. The college's administrator sees the college's courses, sessions, enrolments, payments, content and campaigns, and the shared person record described in the next section. A client signing into the portal sees exactly themselves: their own bookings, their standing and their own message choices. A student sees their own courses and the materials for the ones they are enrolled in, for as long as their access runs.

Where a login signed in from is shown to nobody but the person whose login it is, the owner and the administrators included. A member of staff finds theirs on their settings page, with a way to sign out that device or every other one, and is told on their next page when their account signs in somewhere new; the portal does not show a client or a student theirs.

Every change the staff make to a person's record, a booking, a sale, the hours or the pay is written to a permanent log with who made it and when, and that log cannot be edited or deleted by anyone who uses the system; a removal and each step of the housekeeping write one entry saying how much they changed rather than a copy of what they removed. Corrections are new entries beside the old ones, never over them.

When a member of staff opens a person's record, or takes a list out of the system as a file, that is logged too, with who, when and how many records; a file that leaves also has to say what it is for, from a short list of reasons.

one record, two businesses

Because the clinic and the college keep one record per person, a person's name and contact details are visible to the staff of both. The college's administrator does not see what happened at the clinic, which is visits, payments and notes; the front desk does not see what happened at the college, which is enrolments; the owner and an administrator see both, and the marketing team sees both except the payments.

what leaves, and to whom

These are the only outside systems that touch the information, and this list is kept current.

Square, the clinic's card machine and online payments, sends Derma OS the payments it took; nothing goes back and no card is ever charged from here. Acuity, the booking system, sends the bookings as they are made, and Derma OS reads the recent and coming ones again once a night. Until booking moves over to Derma OS, the front desk also books, moves and cancels visits in Acuity from Derma OS: for a booking, Derma OS sends Acuity the client's name, email address and phone number, the service, the provider and the time, whether the client said yes to text reminders, and the code of a prepaid package when one pays for the visit; for a move, the new time; for a cancel, only which visit. It asks Acuity which days and times it offers, which of a client's packages can pay for a service, looked up by the client's email address, and which visits a provider has on the day, to see whether the time is free. Acuity then sends the client its usual confirmation, notice of a change or of a cancellation, and reminders, under Acuity's terms. The booking link in your account opens Acuity's own page in a new tab, under Acuity's terms. Notion, the agency's planning tool, sends the content calendar; nothing is edited there. The database and the application are hosted by Supabase and by Vercel, both in Montréal apart from the first step of each visit, which the section on where it lives describes; they process the records to serve them, and the invitation and password emails go through Supabase's mail service. Twilio and Resend will send the clinic's appointment reminders, by text and by email, once reminders are switched on; they receive only what a reminder carries, which the section on where it lives lists. One feed goes outward, to the agency that built and runs Derma OS: counts and titles only, such as how many bookings this week and which posts are planned, never a name, a number or a payment.

A list exported by the owner or an administrator, or a file uploaded into the system, is a copy in the hands of whoever asked for it, and it is theirs to look after; the agency keeps no separate copy of the database.

cookies

The only cookies here are the ones that keep you signed in. They travel over an encrypted connection only and only to this site. Nothing on any page tracks you: there is no analytics, no pixel, no tag manager, and no content from another company. The one thing noted about the device you use is the record of where your login signed in from, described above, which is kept for you and shown to nobody else.

Because the only cookies are the ones that make signing in work, this notice is what Canadian law asks for, not a banner. If that ever changes, this section changes and a way to say no comes with it.

how long we keep it

This is the schedule we work to. The housekeeping that enforces it does not run on its own: the people who run the system run it by hand, so a period below that the housekeeping enforces is reached only when they do; the backups age out on their own, and the log of changes is pruned only by a change made on purpose.

The raw messages the outside systems send: ninety days, then the message itself is emptied and only the record that it arrived is kept. A message from an outside system that could not be processed: thirty days, for someone to read it and enter it by hand. An enquiry that arrived through a door we could not verify: the words of it are not kept at all, and the few kept before that rule, thirty days. The rows of an uploaded file: ninety days after the file is kept or abandoned; the people it created stay as people. The card machine's raw records: two years, then cut down to the few details the payment records are worked out from, the note typed at the till among them; the payment records stay. The card machine's copy of a customer: two years after it was last seen, then its name, address and number are emptied. A guest written down at an open house who never became a client: a year after the event, then the name and notes go. The record of who opened which record and which files left: two years. Where a login signed in from: ninety days from the sign in, then the row is deleted. The messages sent to a person: two years from when each was written, then the address it went to and the words it opened with are removed, and the record that it was sent, when, whether by email or by text, and with what result stays. The rows a rehearsal of a campaign writes: the same two years, then emptied the same way. Notes on a person: for as long as the person's record. Staff hours: at least three years after the end of the year, because Ontario's employment law says so. Sales and the books: at least six years, because the tax rules say so. The log of changes: seven years, and it never leaves the database. Backups: seven days.

These have no period at all, and the section on being removed sends you to this one for them. The sign in service's own record that a login existed, which holds the address the login was set up with: it stays. Removing your details closes the login and takes your name and your address off our own record of it, and no screen anywhere removes the sign in service's copy. It can be taken away by hand only for a login nothing else in the system still names: an invitation it sent, a record of who opened what, or a follow up given to that person all name it, and all of them would have to go with it. The snapshot kept when two records of the same person are folded into one, which holds what the record that was folded away said: it stays. It is what makes a fold undoable, and once your details are removed the fold is never undone: the record that was folded away is removed with the record it was folded into, and neither of them is put back. The snapshot stays after that as the record that the two were ever one. The reasons typed when a tier was set by hand, when two records were folded into one and when two were kept apart as different people: they stay beside what they explain, and a removal does not reach them. The clinic's own note that an enquiry arrived: it stays, holding only the record it was written about, the day, and whether it came through the website, and removing your details empties the record it points to, so the note names nobody after that.

your rights, and how to use them

To see what is held about you: ask, and the owner or an administrator puts together what we hold about you and gives it to you, normally within thirty days.

To correct it: ask. Two screens change a name or a date of birth: your record, where the front desk adds, changes or clears your birthday, with or without the year; and the one that folds two records of the same person into one, which can choose only between what those two records already say; the screen that undoes such a fold moves a contact detail back to the record it came from. Nothing else on any screen changes your name or a contact detail already on your record; a new one can be added, and that is all, so today such a correction is made by hand by the people who run the system, and it is written to the log of changes. A tier is corrected on a screen by the owner or an administrator, with the reason they gave recorded beside it. Where a correction cannot be agreed, your statement of disagreement is attached to the record.

To stop messages: change your choice on your record, or yourself in your account, and the choice changes the moment you make it. Derma OS sends no offers by email or text today. It sends no appointment reminders yet either; when it does, a reminder of a visit you booked goes by text, or by email where a text cannot be sent to you, carries the clinic's name, its mailing address and a way to stop it, and is never sent on a channel you have stopped. A link to stop messages, in a message from Derma OS, opens a page with one button: pressing it records at once your choice to stop that kind of message from the business that sent it, and opening the page alone changes nothing. A reply of STOP to a text from Derma OS records your choice to stop texts from the clinic for every record that holds the number the reply came from, so a household that shares one number stops together until the desk records otherwise for one of them; it is queued and recorded by a job that runs every minute, not at once. Each is honoured from the moment it is recorded.

To be removed: ask. An administrator records your request on a screen, and one of the people who run the system then carries it out by hand and the messages stop; we aim to answer within thirty days. When your details are removed, your name, your date of birth, the words of any note written about you, and the evidence a member of staff wrote beside a marketing choice all go. So do the addresses and numbers on your record, in the copies of your contact details the outside systems left with us, in the rows an uploaded file created, in the messages we sent you or a rehearsal of a campaign wrote down for you, and on your portal login, which is closed, and the record of where that login signed in from is deleted. So do the services you said you were interested in and who was following you up, because those are the one thing left on your record that can say which treatment you asked about. And the earlier pictures of your record in the log of changes are emptied of what they held: that log still says a change was made, when, by whom, and which details it touched, and it no longer says what those details were. The copies that stay are: the raw messages the outside systems sent us; the card machine's own records of each payment, order and refund, which can carry an email address, a billing or shipping address, the name and contact details of the person an order was for, or a note typed at the till; the reasons typed when a tier was set by hand, when two records were folded into one and when two were kept apart as different people; the request you made, in the words it was recorded with, which is kept on the request and on the removed record; the record of who opened yours; where you first came from; your enrolments; the pairs of records the system once held as possibly the same person, which name the two records and why they were matched; the sign in service's own record that a login existed; a snapshot kept when two records of the same person were folded into one; the clinic's own note that an enquiry arrived, which points to your record and holds nothing else of you; and the backups, which hold your record as it stood until they age out. What stays, and for how long, is what the section on how long we keep it says. The record that each marketing choice was made stays, with its date, its channel and what was decided, because that is what keeps anyone from contacting you again, and a withdrawal is recorded beside it rather than over it. Some things stay because the law requires them: the record that a payment was made, kept for the six years the tax rules require; the record of visits and of care you received, kept for the period a clinic keeps its records; and the log that records the change was made.

To complain: write to the owner of the clinic, through the front desk, or to the college at its own address, first. Then to the Office of the Privacy Commissioner of Canada, which oversees the private sector rules, or, for anything about health information held by the clinic, to the Information and Privacy Commissioner of Ontario.

children

Derma OS is not for children. The clinic's and the college's services are for adults; no record is knowingly created for a person under the age of majority, and if one is found, its contact details are removed by hand and it is not contacted again.

changes

This page changes when the system changes; the date below says when. A change that affects how your information is used is told to you rather than left here for you to find.

Written for Derma Bar and Skin Aesthetics Canada College by the people who run Derma OS.

Last changed: 2026-10-06.