Privacy Policy

We are committed to protecting your personal data and your right to privacy. This policy explains exactly what we collect, why, and how we protect it.

Last updated: 1 January 2025 Reading time: ~8 minutes GDPR compliant
Your Privacy Matters

ETERNAL Clinic International ("ETERNAL Clinic") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect information about you when you use our website, services, or purchase our products. We comply with the GDPR, Indonesian Personal Data Protection Law (UU PDP), and equivalent legislation in Spain, Italy, and Switzerland.

Who We Are (Data Controller)

ETERNAL Clinic International is the data controller responsible for your personal data. We operate hair restoration clinics and provide related health services across four international locations:

  • Bali, Indonesia — Jl. Sunset Road No.77B, Kuta, Bali 80361
  • Madrid, Spain — C. de Arsenio Fuster, 2, 28100 Alcobendas
  • Fiesso Umbertiano, Italy — Piazza Caduti della Repubblica, 71, 45024
  • Cham, Switzerland — Zugerstrasse 51, 6330 Cham

If you have any questions about how we handle your data, please contact us at info@cliniceternal.com.

Data We Collect

We collect different categories of personal data depending on how you interact with us:

👤 Identity Data
Full name, date of birth, gender, passport or ID number (for procedures requiring verification).
📧 Contact Data
Email address, phone number, WhatsApp number, country and city of residence, mailing address.
🏥 Medical Data
Hair loss history, medical conditions, medications, allergies, surgical history, photographs of scalp and hair.
💳 Financial Data
Payment transaction records, invoice data. We do not store full card numbers — payments are processed by PCI-compliant providers.
🌐 Technical Data
IP address, browser type and version, device type, operating system, pages visited, time on site, referral source.
💬 Communication Data
Messages sent via contact forms, WhatsApp, email, or the AI consultation widget, including content and timestamps.

We collect this data directly from you when you submit a form, book a consultation, undergo a procedure, make a purchase, or contact us by any channel. We also collect technical data automatically when you browse our website.

How We Use Your Data

We use your personal data only for the purposes for which it was collected:

  • To provide and manage medical consultations, hair restoration procedures, and post-treatment care.
  • To process orders for products and deliver them to you.
  • To communicate with you about your appointment, treatment plan, or order status.
  • To generate preliminary AI assessments of your hair condition when you use our consultation widget.
  • To send you service updates, appointment reminders, and aftercare guidance.
  • To send marketing communications about our services and promotions — only where you have given explicit consent.
  • To improve our website, services, and the accuracy of our AI assessment tools.
  • To comply with our legal and regulatory obligations, including medical record-keeping requirements.
  • To prevent fraud, protect the security of our systems, and enforce our Terms of Service.

We will never use your data for purposes incompatible with those listed above without first informing you and, where required, obtaining your consent.

Legal Basis for Processing

Under the GDPR and applicable data protection law, we process your personal data under the following legal bases:

Contractual Necessity

Processing is necessary to fulfil the contract we have with you — for example, to perform your procedure, process your payment, or fulfil a product order.

Legitimate Interests

We process certain data based on our legitimate business interests, including improving our services, preventing fraud, and maintaining the security of our systems. We ensure these interests are balanced against your rights.

Legal Obligation

We are required by law to retain medical records, financial records, and other data for specified periods. We process data to meet these obligations.

Consent

Where we rely on consent — such as for marketing emails or the processing of sensitive health data — you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.

Health & Medical Data

⚕ Sensitive Data — Special Category

Health and medical information is classified as "special category data" under the GDPR and receives the highest level of protection. We process it only where strictly necessary for providing healthcare services and with your explicit consent.

Medical data we hold — including consultation notes, photographs, procedure records, and AI-generated assessments — is treated with the strictest confidentiality. Access is restricted to:

  • The surgeon(s) and medical staff directly involved in your care.
  • Administrative staff who require it to manage your appointment or correspondence.
  • Our secure, encrypted medical records system (accessible only to authorised ETERNAL Clinic personnel).

We will never share your medical data with third parties for commercial purposes, including advertisers, insurers, or employers, without your explicit written consent.

Before and after photographs are stored securely and may be used for internal quality review or educational purposes only with your explicit, separately-obtained consent. We will always ask before displaying any photographs on our website or marketing materials.

Sharing Your Data

We do not sell your personal data. We may share it only in the following limited circumstances:

Service Providers

We work with carefully selected third-party providers who process data on our behalf under strict data processing agreements. These include: payment processors (Stripe, PayPal), email delivery services, and our secure cloud hosting provider. They are permitted to use your data only for the specific purpose we instruct and cannot use it for their own purposes.

Group Entities

Your data may be shared between ETERNAL Clinic locations (e.g., if you transfer care between our Bali and Madrid clinics) for continuity of care purposes only.

Legal Requirements

We may disclose your data if required by law, court order, or regulatory authority, or if we believe disclosure is necessary to protect the rights, property, or safety of ETERNAL Clinic, our patients, or others.

Business Transfers

If ETERNAL Clinic undergoes a merger, acquisition, or sale of assets, your data may be transferred to the new entity. We will notify you before your data is transferred and becomes subject to a different privacy policy.

Cookies & Tracking

Our website uses cookies and similar tracking technologies to improve your experience and analyse how the site is used.

Essential Cookies

Required for the website to function. These cannot be disabled. They include session cookies that keep you logged in and security tokens that protect forms against abuse.

Analytics Cookies

Help us understand how visitors interact with our website (e.g., pages visited, time spent). We use anonymised data and do not share individual tracking data with third parties.

Marketing Cookies

Used only with your consent to serve relevant advertising about our services on third-party platforms. You can opt out at any time through your browser settings or our cookie preferences panel.

Your Cookie Choices

Most browsers allow you to control cookies through settings. You can also use browser extensions to block tracking. Please note that disabling non-essential cookies will not affect your ability to access our services. For more information, visit aboutcookies.org.

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law.

  • Medical records (consultation notes, procedure records, photographs): retained for a minimum of 10 years from the date of last treatment, as required by Indonesian medical regulations. Records for EU patients are retained for the period required by the applicable national law (typically 10–15 years).
  • Financial and transaction records: retained for 7 years for tax and accounting compliance.
  • Marketing consent records: retained until consent is withdrawn plus 3 years.
  • Consultation enquiries that did not result in treatment: retained for 2 years, then securely deleted.
  • Website analytics data: retained in anonymised form for up to 26 months.

When data is no longer required, it is securely deleted or anonymised so it can no longer be associated with you.

International Data Transfers

Because ETERNAL Clinic operates internationally, your personal data may be transferred between our clinic locations in Indonesia, Spain, Italy, and Switzerland for continuity of care purposes.

For transfers of personal data from the European Economic Area (EEA) to Indonesia or other countries that the European Commission has not deemed to provide an adequate level of data protection, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, which impose equivalent data protection obligations on the recipient.

Our third-party service providers may also process data in countries outside your own. In all such cases, we ensure that appropriate safeguards are in place in accordance with applicable law, and that the transfer is subject to a binding Data Processing Agreement.

You may request a copy of the safeguards we have put in place for international transfers by contacting us at the address below.

Your Rights

Depending on your location, you have a number of rights regarding your personal data. EU/EEA residents have all GDPR rights. Indonesian residents have rights under UU PDP. We honour these rights for all our patients globally:

👁
Right of Access
Request a copy of all personal data we hold about you.
✏️
Right to Rectification
Request correction of inaccurate or incomplete data.
🗑️
Right to Erasure
Request deletion of your data where there is no legal basis for retention.
⏸️
Right to Restriction
Request that we restrict processing of your data in certain circumstances.
📦
Right to Portability
Receive your data in a structured, machine-readable format to transfer to another provider.
🚫
Right to Object
Object to processing based on legitimate interests or for direct marketing.
🤖
Automated Decisions
Request human review of any automated decisions that significantly affect you.
↩️
Withdraw Consent
Withdraw consent at any time where processing is based on consent.

To exercise any of these rights, contact us at info@cliniceternal.com. We will respond within 30 days. We may ask you to verify your identity before processing your request. If you are dissatisfied with our response, EU/EEA residents have the right to lodge a complaint with their national data protection supervisory authority.

Children's Privacy

Our services are intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will delete it without delay.

Patients aged 16–17 may be considered for consultation in limited circumstances, in which case we require verifiable parental or guardian consent before collecting any personal or medical data and before providing any services.

Security

We implement appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, disclosure, alteration, or destruction. Our security measures include:

  • TLS/SSL encryption for all data transmitted between your browser and our servers.
  • Encrypted storage for all medical records and sensitive personal data.
  • Role-based access controls ensuring staff can only access data relevant to their function.
  • Regular security audits and vulnerability assessments of our systems.
  • Staff training on data protection and confidentiality obligations.
  • PCI-DSS compliant payment processing — we never store your full card details.

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by applicable law.

Third-Party Links

Our website may contain links to third-party websites, including social media platforms (Instagram, Facebook, TikTok), review platforms (Google), and payment providers. These sites have their own privacy policies and we have no responsibility or liability for their content or practices.

We encourage you to read the privacy policy of any third-party website you visit. The presence of a link on our site does not constitute our endorsement of that site's privacy practices.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. The "Last Updated" date at the top of this page shows when the policy was last revised.

Where changes are material, we will notify you by email (if you are a registered patient or have made a purchase) or by displaying a prominent notice on our website before the changes take effect. We encourage you to review this page periodically.

Your continued use of our services after the effective date of any changes constitutes your acceptance of the revised policy.

Contact Us & Data Protection Officer

For any questions, requests, or concerns regarding this Privacy Policy or our data practices, please contact us:

Privacy Email info@cliniceternal.com
WhatsApp / Phone +62 877 77276824
Head Office Jl. Sunset Road No.77B, Kuta, Bali 80361, Indonesia
EU/EEA residents who are unsatisfied with our response to a data request have the right to lodge a complaint with their national Data Protection Authority (DPA). For Spain: AEPD. For Italy: Garante. For Switzerland: FDPIC.

We aim to respond to all data-related enquiries within 30 days.

Start Your Hair Restoration Journey Today

Book a free, no-obligation consultation with one of our medical experts. We'll assess your case and create a personalised treatment plan.

Your Cart 0

Added!
🔬 Free AI Hair Analysis