Our Privacy Policy
Essential Advanced Skincare and Medspa ("we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal information. This policy explains how we collect, use, and safeguard your data.
Information We Collect
We may collect and process the following types of information:
-
Personal Information: Name, contact details, and any information you provide when registering for services or making a purchase.
-
Transaction Data: Records of purchases, payments, and services received.
-
Technical Data: IP addresses, browser type, operating system, and website navigation data (collected via cookies and analytics tools).
-
Health Information: Any medical details you voluntarily provide for treatment purposes (protected under HIPAA).
How We Use Your Information
We use your data to:
-
Provide and personalize our services.
-
Process transactions and send confirmations.
-
Communicate promotions, special offers, and updates (opt out at any time).
-
Improve website functionality and customer experience.
-
Comply with legal, regulatory, and security obligations.
We do not sell or rent your personal data.
Data Protection & Security
We implement strict security measures, including:
-
Encrypted servers and password-protected databases.
-
Limited employee access to sensitive data.
-
Secure payment processing through PCI-compliant providers.
Despite our safeguards, electronic transmission of data carries some risks. By using our services, you acknowledge and accept these risks.
HIPAA & Data Privacy Compliance
As a healthcare provider, we comply with the Health Insurance Portability and Accountability Act (HIPAA) and other U.S. privacy regulations.
This includes:
-
Protecting your Protected Health Information (PHI) from unauthorized access.
-
Disclosing PHI only with patient consent or when legally required.
-
Allowing patients to request access to or correction of their health records.
Data Sharing & Third Parties
We may share data with:
-
Service Providers (e.g., payment processors, EMR, shipping companies)
-
Regulatory Authorities to comply with legal requirements.
-
Marketing Partners (only with consent).
All third parties must adhere to strict confidentiality agreements and data protection standards.
Telehealth & Digital Communication Risks
If you use telehealth services (Zoom or phone consultations), you acknowledge that:
-
These platforms may have security limitations beyond our control.
-
While we take precautions, there is a risk of unauthorized data interception.
-
By scheduling a telehealth appointment, you release us from liability for potential HIPAA risks associated with third-party communication platforms.
Retention & Deletion of Data
We retain personal data as long as necessary for:
-
Compliance with medical and financial regulations.
-
Business and legal record-keeping requirements.
-
If you wish to have your information deleted, contact us at info@essentialmedspa.com.
Your Rights & How to Contact Us
You may:
-
Request a copy of your stored data.
-
Update or correct inaccurate information.
-
Opt out of marketing emails.
-
File a complaint about data handling.
Contact Us
📧 Email: info@essentialmedspa.com
📍 Address: 358 Washington Street, Dedham, MA 02026
Policy Updates
We may update this policy periodically. Changes take effect immediately upon posting on our website. Continued use of our services constitutes acceptance of any updates.