Privacy Notice
This Privacy Notice explains how personal data is processed in connection with the website and the TrichoScan FAST online portal.
Roles in data processing
Datinf is the controller for data required to operate the website, manage user accounts, conduct business communications, provide support, maintain security and administer its own contracts. Where professional users upload images or information relating to other people, the relevant user or organization is generally the controller for that processing. Datinf processes such data under a data processing agreement and documented instructions where legally required. This policy does not replace the privacy information that the relevant professional user must provide to people shown in images.
1. Controller
Datinf GmbH
Wilhelmstr. 42
72074 Tübingen
Germany
Email: support@trichoscan.net
2. Categories of data processed
Depending on use, we process company, contact and account data; contract and subscription data; uploaded scalp images; pseudonymous internal references; technical information about the image, device, attachment and scale; analysis jobs, status data, measured hair parameters, annotated result images and PDF reports; technical log and security data; and communication and support data.
3. Purposes and legal bases
We process data to provide and secure the website and portal, create and administer accounts, perform the requested image analysis, display and provide results, manage contracts, subscriptions and support, prevent and investigate misuse and security incidents, and comply with legal obligations. Where the data subject is both the contracting party and a professional user, processing for pre-contractual steps and contract performance is based on Article 6(1)(b) GDPR. Contact and user data of an organization are processed on the basis of our legitimate interest in conducting and administering the business relationship under Article 6(1)(f) GDPR. Processing required by law is based on Article 6(1)(c) GDPR. Where Datinf processes images and results on behalf of a controller, that controller determines the applicable legal basis.
4. Automated image analysis
The software automatically detects and quantifies visible hair structures in the analyzed image area and produces measurements and annotated result images. Processing is used solely for cosmetic hair assessment and comparative documentation. It does not result in an automated decision producing legal or similarly significant effects. The system does not create health, risk or eligibility categories and does not provide medical recommendations.
5. Source of data about depicted persons
Images and related information about depicted persons are provided by the relevant professional user or their authorized users. That professional user is responsible for informing the depicted person about processing and ensuring the required legal basis.
6. Paddle
The subscription is purchased and billed through Paddle as authorized reseller and merchant of record. Paddle processes buyer, company, transaction, invoice, tax and payment data under its own privacy information. Uploaded scalp images, internal references and analysis results are not sent to Paddle. The email address used for professional purposes, an internal checkout reference and subscription status may be processed to assign the purchase.
7. Recipients and service providers
Data may be disclosed to service providers used for hosting, technical image analysis, email delivery, support, monitoring and payment processing. Service providers receive only the data required for the relevant purpose. Where they act as processors, they are contractually bound under Article 28 GDPR. Paddle processes buyer and payment data under its own responsibility as merchant of record. An up-to-date list of subprocessors is made available to contracting parties as part of the data processing agreement.
8. Transfers to third countries
Where data is processed outside the European Union or European Economic Area, transfers are based on an adequacy decision or appropriate safeguards, in particular the European Commission's standard contractual clauses. Details of relevant providers and safeguards are made available in the contract and privacy documentation.
9. Retention
Uploaded scalp images, internal references, analysis results and result images are available for 30 days from upload and are then deleted automatically. Account and subscription data are retained for the contractual relationship and thereafter only as required for statutory retention, evidence or limitation periods. Password and setup links become invalid after use or expiry. Technical logs, webhook data, support communications and backups are retained only as long as required for security, troubleshooting, contract performance or legal duties; backups are overwritten according to the defined backup cycles.
10. Cookies and local storage
The portal uses a technically necessary session cookie for sign-in and security functions. The selected language may be stored in a cookie for up to one year. Color and display settings are stored locally in the browser until deleted or reset by the user and are not used to create usage profiles. Paddle may use technically necessary storage and security mechanisms when the checkout is opened.
11. Server and security logs
When the website is accessed, we process technically necessary access data, including IP address, date and time, requested address, status code, browser and device information, and referring page where transmitted. The data is used for secure technical delivery, troubleshooting, prevention of misuse and investigation of security incidents and is deleted when no longer required for these purposes or legal evidence.
12. Security
We use appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration and disclosure. Measures include encrypted transmission, access controls, logging of security-relevant events, backups and regular updates of the systems used.
13. Data subject rights
Subject to the statutory requirements, data subjects have rights of access, rectification, erasure, restriction, data portability and objection. Where processing is based on consent, consent may be withdrawn for the future. If a request concerns images or results uploaded by a professional user acting as controller, the request should generally be directed to that controller. Datinf supports the controller in handling the request as part of the processing relationship.
14. Right to lodge a complaint
Data subjects also have the right to complain to a data protection supervisory authority. The authority generally responsible for Datinf is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg; a complaint may also be filed with another competent supervisory authority.
15. Contact
Privacy inquiries should be sent to support@trichoscan.net.
Version 1.0 · Last updated: 1 September 2026