Privacy Policy
This English version is provided for convenience. The legally binding version is the German original.
Last updated: August 27, 2026
This privacy policy describes how Meda Esthetic, Branislav Lukic, based in Zurich, Switzerland, collects, processes, and protects personal data in accordance with the Swiss Federal Act on Data Protection (FADP).
Our services are provided in Switzerland and directed primarily to persons residing in Switzerland. The English version serves Switzerland's multilingual community; it does not constitute an offer of services outside Switzerland.
Responsible party
Branislav Lukić
Meda Esthetic, Branislav Lukic
Goldbrunnenstrasse 149
8055 Zürichinfo@meda-esthetic.ch
+41 79 840 88 13
https://meda-esthetic.chUID: CHE-245.867.775
VAT No.: CHE-245.867.775 MWST
CH-ID: CH-020-1102525-2
We are responsible for all processing described in this policy.
For customers receiving treatments at our studio
This section describes the personal data we process when you visit Meda Esthetic, Branislav Lukic for an aesthetic treatment, separately from our website. If you scanned the QR code in the studio, this is the relevant section for you.
Persons under 18
Treatments may be performed on persons under 18 only with the written consent of a parent or legal guardian; the guardian must be present during the appointment. The same requirement applies to photographs and any other personal data we process about a minor.
Information you share verbally before each treatment
Before every treatment, we ask you to inform the practitioner of anything that affects treatment safety — current conditions, medications, allergies, recent treatments, pregnancy or breastfeeding, and similar.
This information is provided verbally and is not recorded, transcribed, or stored in any file, paper or digital. The practitioner uses what you share in the moment to decide whether the treatment is safe and how to adjust it. Because nothing is carried forward, we ask you the same questions again at every visit.
You are responsible for keeping the practitioner informed each time you come in. If you choose not to share information that is relevant to treatment safety, we cannot proceed with the treatment.
What we record about your treatment
We keep an operational record of each visit so we can plan follow-ups, support continuity across sessions, and meet our accounting obligations. The record contains:
- The treatment(s) performed
- Device settings (e.g. Candela Nordlys parameters)
- Products applied
- Date of the visit
- Practitioner
This record contains no health, condition, or anamnesis fields. It is stored in our studio management system (see Booking and customer management below).
Photographs and video
We take photographs (and occasionally short video) of the treatment area before, during, and after a treatment only with your written consent. We use them in two clearly distinct ways and obtain consent for each purpose separately:
a) For your treatment record
Used internally so the practitioner can compare results across sessions, plan adjustments, and document what was done. Stored alongside the rest of your treatment record. Legal basis: your written consent, which we obtain before the treatment.
Without your consent we do not take record photographs. In most cases we can still treat you. For some treatments, photographs are necessary to plan follow-up sessions safely — without consent we may not be able to perform those treatments; we will tell you before the treatment starts if that applies. You can withdraw your consent at any time with effect for the future; we will then delete the photographs from your treatment record.
b) For marketing or educational use (Instagram, website, advertising)
Only with your separate, explicit, opt-in consent. You can withdraw it at any time, in writing, by email or in person. After withdrawal we will stop using your photographs in any new marketing or educational material, and we will remove them from channels we directly control (e.g. our website and Instagram account) as quickly as we reasonably can. We cannot guarantee removal in every case: material that has already been printed, distributed, indexed by search engines, embedded in third-party platforms, cached, or saved by other users may remain in circulation outside our control.
We will not use any photograph of you for marketing without your consent on record.
Other marketing communication
We do not send promotional newsletters or unsolicited marketing emails. We do not publish customer reviews or testimonials on our website or social media.
Communication with you
When you book or visit, we may contact you by:
- Email (appointment confirmation, follow-up care, reminders)
- WhatsApp Business or SMS (the same purposes, and to answer questions you send us)
- Appointment availability: we may proactively message you via WhatsApp or SMS if a relevant slot becomes available — only in connection with a stated interest from you (waiting list, prior request)
WhatsApp messages are processed by Meta, including a transfer to the United States — see WhatsApp (Meta) below for the processor details. If you prefer not to use WhatsApp, you can always use email or phone.
Booking and payment
Your bookings, contact details, and operational treatment record are stored in our studio management system (Phorest — see Booking and customer management). Payment data is processed by SumUp or TWINT — see Payment processing. We do not retain card numbers ourselves.
Effect of declining
- Declining to share safety-relevant information with the practitioner before treatment — we cannot perform the treatment.
- Declining marketing consents — no impact on the treatment itself.
- Declining consent to record photographs — in most cases we can still treat you. Certain treatments where photographs are required for safe planning may not be possible.
Your rights as a customer
The same rights described in Your rights under Swiss law apply to your customer data: access, correction, deletion (where the law allows), portability, objection, and complaint to the FDPIC.
To exercise any of these rights, contact us at info@meda-esthetic.ch.
How long we keep customer data
- Operational treatment record (treatments performed, device settings, products, dates, practitioner): 3 years after your last appointment.
- Photographs taken for the treatment record: 3 years after your last appointment, or until you withdraw your consent — whichever comes first.
- Photographs you have consented to for marketing or educational use: as long as your consent stands; on withdrawal we stop new use and remove from channels we directly control as quickly as we reasonably can — see Photographs and video above for limits.
- Booking and contact data: 3 years after your last appointment.
- Payment-related records (invoices, receipts): 10 years (Swiss Code of Obligations, Art. 958f).
- Customer communication (email, WhatsApp, SMS): 12 months; longer in case of a dispute.
For website visitors
This section describes the personal data we process for visitors to our website and people who contact us without booking a treatment. If you are a customer receiving treatment at our studio, see the section above.
Scope
This privacy policy applies to personal data we process in connection with our website, enquiries, and aesthetic services, including:
- Visitors to our website
- Customers and potential customers
- Persons who contact us (email, phone, WhatsApp)
- Anyone whose personal data we process for our aesthetic services in Switzerland
Our services are provided in Switzerland and are directed primarily to persons residing in Switzerland. The website may also be accessed from abroad; in that case, our infrastructure providers process the technical data described below.
Categories of personal data we process
We may collect and process the following data from website visitors and people who contact us without booking a treatment:
- Identity and contact data (when you reach out): name, email address, phone number
- Communication data: emails, WhatsApp or SMS messages
- Technical data: IP address, browser and device information, access time (used for security and aggregated analytics)
For data processed when you receive treatments at our studio, see For customers receiving treatments at our studio above.
We do not request health data through the website. If you send health information to us unsolicited by email, WhatsApp, or SMS, we process it only as necessary to answer your enquiry or plan an appointment safely. The specific information about verbal safety data, treatment records, and photographs in For customers receiving treatments at our studio applies to processing in the studio.
We collect personal data directly from you unless otherwise indicated in this policy.
Purpose of data processing
We use your data only for:
- Booking, managing, and confirming appointments
- Responding to enquiries and communicating with customers
- Sending reminders and service-related messages
- Operating, securing, and improving our website
- Complying with applicable retention and legal obligations in Switzerland
Data sharing and service providers
We work with service providers to host, secure, and run our digital infrastructure. Where a provider processes personal data on our behalf, the data-protection and security terms agreed for that service apply.
a) Website hosting
Our website is hosted by:
Vercel Inc.
440 N Barranca Ave #4133
Covina, CA 91723
USA
www.vercel.com
Our application functions are configured to execute in Frankfurt, Germany. Vercel also operates a globally distributed delivery, security, and logging infrastructure. Technical data such as IP address, access time, requested URL, browser information, and access logs may therefore be processed in the United States and other countries. See Vercel's Privacy Policy and Data Processing Addendum for details.
b) DNS and security services
We use:
Cloudflare, Inc.
101 Townsend Street
San Francisco, CA 94107
USA
www.cloudflare.com
Cloudflare provides DNS, security, and performance services through a global infrastructure. Depending on the active configuration, Cloudflare may process technical data worldwide, in particular IP address, requested domain, timestamp, and security events. See Cloudflare's Privacy Policy for details.
c) Analytics
We use the following analytics service:
Plausible Insights OÜ
Västriku tn 2, 50403 Tartu
Estonia
https://plausible.io
Plausible Analytics uses no cookies or permanently stored visitor identifiers. When an analytics request is made, the IP address and user agent are technically received, used to create a daily rotating identifier, and not stored in raw form. Stored statistics are aggregated and processing takes place within the European Union.
We do not sell or rent your personal data.
d) Google Maps
Our website uses Google Maps to display maps.
Google Ireland Limited
Gordon House, Barrow Street
Dublin 4, Ireland
https://policies.google.com/privacy
When the map loads, your IP address is transmitted to Google. Google typically transfers it to a server in the USA and stores it there.
The use of Google Maps only occurs when you click "Load map" and thereby give your consent to data transmission.
Legal basis: Your consent under the Swiss Federal Act on Data Protection (FADP). While Google Ireland Limited is an EU entity, our use of Google Maps and the processing of your data in this context is governed by Swiss law (FADP), not the EU General Data Protection Regulation (GDPR).
e) WhatsApp (Meta)
We offer WhatsApp as one way to contact us and book appointments.
WhatsApp Ireland Limited
4 Grand Canal Square
Dublin 2, Ireland
https://www.whatsapp.com/legal/privacy-policy
When you contact us via WhatsApp, your phone number, name, message content, and metadata (e.g., timestamps) are processed by WhatsApp (Meta Platforms). WhatsApp uses end-to-end encryption for messages. Meta may process metadata under its own privacy policy.
The use of WhatsApp is voluntary. You may always contact us via email or phone instead.
f) Instagram (Meta)
Our website contains a link to our Instagram profile (@meda_estheticzh).
Meta Platforms Ireland Limited
4 Grand Canal Square
Dublin 2, Ireland
https://privacycenter.instagram.com/policy
We do not embed Instagram content on our website. However, if you visit our Instagram profile by following the link, Meta's privacy policy applies to your interaction with that platform. No data is transferred to Meta by visiting our website alone.
g) Email hosting
Our email is hosted by:
Infomaniak Network SA
Rue Eugène-Marziano 25
1227 Genève
Switzerland
https://www.infomaniak.com/en/legal/privacy-policy
Infomaniak stores all email data exclusively in Switzerland.
h) Booking and customer management
We use:
Phorest (nDevor Systems Ltd)
9 Anglesea Row
Dublin 7, D07 W5NE
Ireland
https://www.phorest.com/privacy/
Phorest is our studio management system used for appointment booking, customer profiles, service history, and appointment reminders. When you book an appointment, your name, contact details, and booking information are stored in Phorest. Phorest processes data under EU data-protection rules.
Geographic scope and data transfers
Personal data may be processed in particular in Switzerland, the EU or EEA, and the United States. Where data is disclosed to a country without a recognised adequate level of data protection, we use recognised standard data-protection clauses or other safeguards under the FADP where required. A transfer may also rely on an applicable adequacy decision or statutory exception. The specific safeguard depends on the provider and its current certification or contractual arrangements.
Cookies and website analytics
Our website stores your consent choices in your browser's local storage. The choices expire after twelve months and are then requested again. Google Maps is loaded only with your functional consent.
We use Plausible Analytics for website statistics. It is loaded only after you opt in to analytics in our privacy settings. It sets no analytics cookies; the technical and aggregated processing is described under Analytics.
We use no advertising cookies or behavioural profiling. You can manage your privacy choices at any time using the settings in the footer of every page, or restrict local storage and cookies directly in your browser.
For more details, please see our Cookie Policy.
Country-based language redirect
When you visit the site root, Vercel's edge infrastructure tells our application which country your request is coming from (derived from your IP address). We use this to send you to the German or English version of the site. Our application does not create a separate record or profile for this purpose; Vercel's technical processing is described under Website hosting.
Payment processing
Payments at our studio are processed via card terminals, TWINT, or cash. We do not store credit card numbers or payment details ourselves.
Card payments are processed by:
SumUp Limited
Block 8, Harcourt Centre
Charlotte Way, Dublin 2
Ireland
https://www.sumup.com/privacy
SumUp processes payment data in accordance with applicable security standards (PCI DSS). We only retain proof of payment as required for accounting purposes.
TWINT transactions are processed by:
TWINT AG
Stauffacherstrasse 41
3014 Bern
Switzerland
https://www.twint.ch/en/privacy
Purposes and grounds for justification
We process personal data for the purposes described in this policy. Where processing requires a ground for justification, we rely in particular on:
- Performance of a contract — for processing needed to deliver the treatments and services you book with us, including the operational treatment record, appointment confirmations, follow-up care, and reminders.
- Legitimate interest — for security and operational integrity of our website and infrastructure (e.g. server logs, abuse prevention), and for keeping treatment records (excluding photographs) to support follow-ups and defend against potential claims.
- Legal obligation — primarily to retain accounting and invoice records as required by the Swiss Code of Obligations (Art. 958f, ten years).
- Consent — for any processing where we ask for it explicitly: photographs and video (both for the treatment record and for marketing or educational purposes), loading of Google Maps, optional analytics services, and proactive availability messages where you have asked to be contacted.
Automated decision-making
We do not use automated decision-making or profiling that produces legal effects or similarly significant effects on you. All decisions regarding your treatments and services are made by the practitioner personally.
AI-assisted tools
We use AI-assisted tools for limited administrative purposes — drafting communications, scheduling assistance, marketing content, and reviewing aggregate financial summaries. We avoid entering customers' personal data and use anonymized or aggregated information where possible. If processing personal data is necessary in an individual case, we do so only with appropriate safeguards and a legal basis.
AI is not used for treatment decisions, treatment-safety assessment, or any decision affecting how we treat a customer. Treatment decisions are made by the practitioner, in person.
Data security
We implement technical and organisational measures to protect personal data, including:
- Encrypted communication (TLS)
- Two-factor authentication on administrative accounts
- Access to customer data restricted to staff on a need-to-know basis
- Secure access control for service providers
- Regular infrastructure backups
We notify the Federal Data Protection and Information Commissioner (FDPIC) of a data-security breach as soon as possible where it is likely to pose a high risk to the personality or fundamental rights of the people affected. We inform affected persons where necessary for their protection or where required by the FDPIC.
Data storage
We store personal data only as long as necessary, according to Swiss legal provisions. Customer-specific retention is detailed in How long we keep customer data above. For website and general enquiries:
- Financial and accounting records: 10 years (Swiss Code of Obligations, Art. 958f)
- General communication (email, WhatsApp, SMS not tied to a customer record): 12 months
- Plausible statistics: aggregated, while the website account remains active or until we delete the website data
Your rights under Swiss law
Under the FADP, you have the right to:
- Access to your personal data
- Correction of incorrect or outdated data
- Deletion of your data (to the extent legally permitted)
- Data portability where the statutory requirements are met
- Objection to processing in certain cases
- Information about how your data is used
To exercise these rights, please contact us at info@meda-esthetic.ch. We may require proof of identity to verify your request.
If you believe that our processing of your personal data violates data-protection law, you may contact the Federal Data Protection and Information Commissioner (FDPIC):
FDPIC (EDÖB)
Feldeggweg 1
3003 Bern
https://www.edoeb.admin.ch
Changes to this privacy policy
We may update this privacy policy. The current version is always on this page.