AesthetiConfAesthetic & beauty congresses

Privacy policy

Updated: 29 September 2026
Requires legal review before go-live. This text follows the obligations set out in the specification but has not yet been reviewed by counsel. Remove this warning block once legal review is complete.

1. What we collect

AesthetiConf collects ordinary personal data: your email address when you subscribe to the digest, and name, organisation, email and phone when an organiser submits an event.

We collect no health data about any individual. This is an important difference from a clinic website: health data is sensitive personal data under Vietnam's Personal Data Protection Law 2025, and this system is designed never to touch that category.

2. Legal basis and consent

The digest is sent on the basis of your consent, collected by double opt-in: after entering your email you must click a confirmation link. The consent checkbox is never pre-ticked.

We store the exact wording you consented to and the moment of consent, so it can later be shown precisely what you read and agreed to.

3. Where data is stored

The database and uploaded files sit on servers in Vietnam. No cross-border personal data transfer file arises under the Personal Data Protection Law 2025 and Decree 356/2025.

Subscriber email addresses are encrypted with AES-256-GCM at rest and decrypted only at the moment of sending. The encryption key lives in an environment variable, not in the database.

4. Who we share with

We do not sell, rent or share personal data with third parties for marketing.

Email is sent through a Vietnamese SMTP provider. Any export of the subscriber list requires editor-in-chief approval and is written to the immutable audit log.

5. Your rights

You may: see the data we hold about you, request correction, request deletion, and withdraw consent at any time. Every digest email carries an unsubscribe link.

To exercise these rights, write to [email protected]. We respond within the statutory period.

6. Retention

Subscriber data is kept until you unsubscribe. Audit logs are kept for 24 months for internal audit purposes.

7. Cookies

The site uses exactly one piece of browser storage: your light/dark theme choice. That is a personal convenience, stored in localStorage, never sent to the server and never used to identify you. There are no advertising tracking cookies.

Internal staff sessions use an httpOnly cookie — strictly necessary for the function, not for marketing.