1. In brief
This privacy policy explains how MB “Feme Care” (“Feme Care”, “we”) processes your personal data when you use the “Feme Care” mobile application, website, account, AI skin analysis function, e-commerce, subscriptions, service bookings with partners and other related services (“Services”).
Key information: The Services are intended only for persons aged 16 and over. Skin analysis data may be considered health data, therefore we ask for explicit consent for skin analysis and personalized recommendations. A photo taken for analysis is stored on the Feme Care server for no longer than 1 hour and is then automatically deleted – without exceptions. We transfer data only to necessary service providers, payment partners and booked Partners. For privacy questions, contact: privacy@feme.care
We invite you to read the full policy – it explains what data we process, on what legal bases, how long we store it and what rights you have.
2. Terms we use
To make the policy clearer, below we provide the main terms used in this document:
“Services” – the “Feme Care” mobile application, website, account, AI skin analysis, e-commerce functions, subscriptions, service bookings with Partners and all related digital solutions.
“Application” – the “Feme Care” mobile application available through the “Apple App Store” and “Google Play”.
“User”, “You” – a natural person who uses the Services or registers as a user.
“Partner” – a third-party beauty or health service provider (salon, cosmetologist, dermatologist, other specialist) with whom a user may book a Service.
“Controller” – a natural or legal person who determines the purposes and means of personal data processing (GDPR Art. 4(7)). In the context of this policy, the main controller is MB “Feme Care”.
“Processor” – a natural or legal person who processes personal data on behalf of the controller and according to its instructions (GDPR Art. 4(8)).
“GDPR” – Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (General Data Protection Regulation).
“Special categories of data” – data specified in Article 9 of the GDPR, including data concerning health.
3. Data controller and contacts
The controller of your personal data is MB “Feme Care”, legal entity code 307636331, Perkūnkiemio g. 19, LT-12120 Vilnius, Lithuania.
For privacy and GDPR matters, contact us by email: privacy@feme.care
We respond to requests related to your rights within the deadlines established by the GDPR (usually within 1 month). We aim to respond to other inquiries as quickly as possible.
Feme Care has not appointed a data protection officer because the scale of our activities and the nature of the data processed do not create such an obligation under Article 37 of the GDPR. Nevertheless, we regularly assess this need and, if it changes, we will appoint an officer and update the contact information.
4. Who may use the Services?
The Services may be used only by persons aged 16 and over. By registering, you confirm that you are at least 16 years old. Younger persons may not create an account or use the skin analysis, purchase, subscription or booking functions.
This age restriction was chosen taking into account: (i) the sensitivity of the data processed during skin analysis; (ii) the transactional nature of subscriptions and payments, for which minors need parental consent within the meaning of Article 2.7 of the Civil Code of the Republic of Lithuania; (iii) Apple and Google platform requirements.
If we learn that an account has been created by a person under 16 years old, we may close it and delete the related data, unless legal acts require us to store it longer. If you believe that data of a younger person is being processed improperly, contact privacy@feme.care.
5. Where do we get your data from?
We receive most data directly from you when:
you register and create an account;
you fill in profile information;
you use the skin analysis function (take a photo with the device camera);
you make a purchase, subscription order or booking;
you communicate with our customer support team;
you provide feedback or participate in surveys.
We receive some data automatically when you use the Services – this is technical usage data, error reports, interaction events with the Application, device and network information.
We receive certain data from third parties:
from Apple – when you sign in via “Sign in with Apple” (we receive a private recognition identifier and, if you choose, email through Apple’s relay service);
from Google – when you sign in via “Sign in with Google” (we receive a unique Google account identifier and, depending on the permissions you grant, email address, name and profile photo);
from payment providers (Paysera, Apple, and when using “Android” subscriptions – “Google Play”) – payment status, transaction number, amount, invoice details;
from Partners – information about a completed booking, its status, cancellations;
from the AI skin analysis provider (“YouCam” / Perfect Corp.) – analysis results after photo processing;
from analytics and advertising attribution solutions – pseudonymous data about how you arrived at the Application and how you use it.
6. What data do we process?
Account and login data: first name, last name, email, phone number, language, city / country, account settings, identifiers for login via email, Apple ID or Google ID, profile photo (if you provide it).
Face photos and skin analysis data: your face photo taken with the device camera; AI analysis results of skin condition (skin type, problem areas, parameter evaluations); AI-generated recommendations; skin zone / mask data without a face image. Even if the masks do not contain a face, they may be linked to your account (while the account is active) and considered personal data. More about the processing of face photos and masks – in Section 8.
Purchase, subscription and booking data: purchased products, subscription plan, booked service, Partner, date, time, order history, delivery or invoice data, used discounts and promotions.
Payment and accounting data: payment method, payment status, transaction number, invoice data. Feme Care does not store the card number, expiry date or CVV – this information is processed directly in the systems of the payment service provider.
Technical, security and usage data: device type, operating system, Application version, IP address, pseudonymous identifiers, error logs, usage events, advertising identifiers (IDFA / Advertising ID), if consent has been given for this.
Communication and user-created content: your inquiries, replies, feedback, ratings, comments, survey results, photos or other content that you provide to us or choose to publish.
Marketing consents and communication choices: consents to receive newsletters, push notifications, personal recommendations; consent withdrawals; marketing segmentation tags.
7. Purposes, legal bases and storage periods
We process personal data only when we have one of the legal bases provided for in the GDPR:
GDPR Art. 6(1)(a) – your consent (e.g., optional functions, direct marketing by newsletters and push notifications, profiling, third-party analytics and advertising attribution solutions);
GDPR Art. 6(1)(b) – performance of a contract with you or steps taken at your request prior to entering into a contract (e.g., account creation and administration, performance of AI skin analysis, purchases, subscriptions, bookings, customer support);
GDPR Art. 6(1)(c) – a legal obligation applicable to Feme Care (e.g., accounting, tax, consumer protection obligations);
GDPR Art. 6(1)(f) – legitimate interests of Feme Care or a third person, where they do not override your rights and freedoms (e.g., Application security, fixing failures, fraud and abuse prevention, establishment, exercise and defense of legal claims);
GDPR Art. 9(2)(a) – your explicit consent for the processing of special categories of (health) data when such data arises, for example, when performing skin analysis or transferring a short note about skin condition to a Partner.
The table below sets out the main processing activities, the legal bases applicable to them and indicative storage periods. More detailed information may be provided in a privacy notice for a specific function.
| What we use it for | What data | Basis | How long we store it |
|---|---|---|---|
| To create and manage an account | Account, contact, login data | Performance of contract | While the account is active and up to 2 years after closure, if needed for security or disputes |
| To perform skin analysis | Photo, skin results, recommendations | Performance of contract; explicit consent for special categories of data | Photo on the Feme Care server – no longer than 1 hour (without exceptions); results – while the account is active |
| To store skin masks (while the account is active) | Masks without a face, analysis history | Performance of contract; explicit consent if the data is considered health data | While the account is active or until you delete / withdraw consent |
| To store skin masks (after account closure) | Masks detached from the person | Legitimate interest (GDPR Art. 6(1)(f)) for service quality and improvement of the AI solution | Indefinitely, while useful for ensuring service quality or improving AI |
| For purchases, payments, bookings and subscriptions | Order, payment status, booking, invoice data | Performance of contract; legal obligation for accounting | Accounting documents are stored for 10 years under the Law on Financial Accounting of the Republic of Lithuania |
| For customer support | Inquiries, complaints, correspondence | Performance of contract or legitimate interest | Up to 2 years from the last contact, unless longer is needed to resolve a dispute |
| For fraud prevention and control of account abuse | Account activity logs, IP, device identifiers | Legitimate interest | Up to 2 years from the incident or last activity |
| For security and error fixing | Technical logs, crash report, IP, device data | Legitimate interest | Up to 12 months, unless longer is needed to investigate an incident |
| For analytics and improvement of the Application | Usage events, consents | Consent | Until consent is withdrawn |
| For advertising attribution and campaign measurement | Advertising identifiers, campaign attributes | Consent | Until consent is withdrawn |
| For direct marketing by email | Email, usage segments | Consent; for marketing to existing customers – Article 81(2) of the Law on Electronic Communications of the Republic of Lithuania with the right to opt out | Until consent is withdrawn or opt-out |
| For push notifications (marketing) | Push subscription identifier | Consent (separate from email) | Until consent is withdrawn |
| For personalized recommendations (profiling) | Skin analysis results, purchase history | Explicit consent for health data | Until consent is withdrawn |
| For legal claims | Significant account, payment, communication data | Legitimate interest or legal obligation | According to applicable limitation periods, up to 10 years |
After the storage period expires, the data is deleted, destroyed or anonymized so that a specific person cannot be identified.
8. Skin analysis and AI recommendations
This section explains in detail how Feme Care processes your face photo and skin analysis data – why it is needed, with whom we share it and how you can control the processing of this data.
| Why we use your face photo: to perform AI (artificial intelligence) analysis of skin condition and to provide personal skin care recommendations. |
| With whom we share the photo: the third-party artificial intelligence (third-party AI) service provider “YouCam” (Perfect Corp.), which acts as our data processor under an executed data processing agreement. Your face photo is not transferred to any other third parties. If you book a service with a Partner, with your separate consent only a short note about skin condition may be transferred to the Partner – not the photo itself. |
| How we process it: the photo is taken with the device camera and transferred through a secure channel (TLS / HTTPS) to the “YouCam” AI system, which returns the analysis results. The photo is stored on the Feme Care server for no longer than 1 hour and is then automatically and permanently deleted. |
| How you can withdraw / delete: you can withdraw consent at any time through the Application settings → “Profile” → “Delete account” or by writing to privacy@feme.care. More about the consequences of withdrawal – at the end of this section. |
How the analysis works. When using the skin analysis function, you take a face / skin photo with the device camera. This photo is transferred to a third-party AI skin analysis provider – Feme Care uses the “YouCam” (Perfect Corp.) skin analysis API. The system generates an assessment of skin condition, identifies zones that may need care and returns the results to the Application. Recommendations for products or services are provided on the basis of these results.
Health data and explicit consent. Taking into account that skin condition assessments may be classified as special categories of (health) data under Article 9 of the GDPR, before starting the analysis we will obtain your explicit separate consent within the meaning of GDPR Art. 9(2)(a). This consent is separate from confirmation of the general Terms of Services. You may withdraw consent at any time, but this means that you will no longer be able to use the skin analysis functionality.
Biometrics and identity recognition. The face image is used only for skin condition assessment and is not used for identity recognition, “face unlock” functions or any other biometric identification purposes. We do not create or store biometric templates from the photo within the meaning of GDPR Art. 9(1).
The photo itself after analysis. A photo taken for analysis is stored on the Feme Care server for no longer than 1 hour and is then automatically deleted. After this period, we do not store face photos in any form. Feme Care does not have a “before and after” function – photos after analysis are not saved in the account.
Skin masks without a face image while the account is active. Masks without a face image are stored in the account so that history and changes can be shown. While the account is active, they are linked to your account and skin condition, therefore we process them as personal data and, where applicable, as special categories of data. The legal basis – performance of the contract with you and your explicit consent to the processing of health data (GDPR Art. 6(1)(b) and Art. 9(2)(a)).
Storage of masks after account closure or withdrawal of consent. When the account is deleted or consent is withdrawn, the masks are detached from your personal identity – all identifiers and links to the account related to a specific user are removed – and left in a separate database indefinitely. At this stage, the masks are no longer linked to a specific user and are used only to ensure the quality of the Application services and to improve the AI solution. The legal basis for this processing – Feme Care’s legitimate interest in improving services and the quality of the AI model (GDPR Art. 6(1)(f)). We note that pseudonymized (detached) data technically may still be considered personal data if there were theoretically a possibility to link it to a specific person by other means; therefore we continue to apply GDPR requirements for security and confidentiality to it. You may object to such processing at any time by writing to privacy@feme.care.
“YouCam” / Perfect Corp. as a third-party AI data processor. “YouCam” (Perfect Corp.) is a third-party artificial intelligence (third-party AI) service provider acting as our data processor under an executed data processing agreement and processing photos only on Feme Care’s instructions. The agreement with “YouCam” includes terms ensuring that the provider applies a level of data protection equivalent to the requirements of this Policy and the GDPR, including confidentiality obligations, technical and organizational security measures, restriction to process data only on Feme Care’s instructions and, where applicable, standard contractual clauses (SCC) for data transfers outside the EEA. You can read the “YouCam”/Perfect Corp. privacy policy here: https://www.perfectcorp.com/business/privacy.
Withdrawal of consent for the face photo and data deletion. You can withdraw consent to process the face photo and related skin analysis data at any time:
through the Application settings → “Profile” → “Delete account”;
by writing to privacy@feme.care.
After withdrawing consent or deleting the account: (i) new skin analyses will no longer be performed; (ii) your personal data – account information, contacts, analysis results linked to a specific user – will be deleted within 30 days; (iii) personal data will be removed from backups within 90 days; (iv) skin masks are detached from your identity (strictly anonymized) and left in a separate database for service quality assurance and improvement of the AI solution, as described above. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Recommendations are not medical advice. AI-generated results and recommendations are informational. They are not a medical diagnosis, treatment plan or doctor’s consultation. If you have health problems, allergic reactions or serious questions about skin condition, contact a dermatologist or another qualified specialist.
9. Purchases, payments and subscriptions
Through Feme Care you can purchase products and services, as well as order digital subscriptions inside the Application.
Payment methods. Payments are made through:
Paysera LT, UAB – the main payment service provider for e-commerce and bookings. Card data is entered in the secure “Paysera” environment. Feme Care does not store the card number, expiry date or CVV. “Apple Pay” and “Google Pay” support is provided by “Paysera”.
“Apple In-App Purchase” – for digital subscriptions and digital content purchases according to the requirements of the “Apple App Store Review Guidelines”. The payment transaction is managed by “Apple”; Feme Care receives information only about the purchase / subscription status.
“Google Play Billing” – for digital subscriptions and digital content purchases on “Android” according to the requirements of the “Google Play Payments Policy”. The payment transaction is managed by “Google”; Feme Care receives information only about the purchase / subscription status.
Allocation of responsibility. Payment service providers act as independent data controllers when performing their services and apply their own privacy policies. Feme Care – as the seller / service provider – becomes the data controller in relation to the transaction data it needs (transaction amount, status, invoice details).
Invoices and accounting. After a purchase is made, we generate an invoice and store it for accounting purposes. Accounting services are provided to us by an external accounting service provider, in whose accounting system invoice and payment data is processed for accounting, tax calculation and declarations. The accounting service provider and its accounting system act as data processors. Storage period – 10 years under the Law on Financial Accounting of the Republic of Lithuania.
Subscriptions. If you use an auto-renewing subscription, subscription terms, cancellation procedure and renewal information are provided separately before purchase and in the Feme Care terms of use. You manage “Apple In-App Purchase” subscriptions through your Apple ID settings (“Settings” → Apple ID → “Subscriptions”). You manage “Google Play Billing” subscriptions through the “Google Play” store settings (“Play Store” → account menu → “Payments & subscriptions” → “Subscriptions”).
More information:
“Paysera” privacy policy: https://www.paysera.com/v2/lt-LT/teisine-informacija/privatumo-politika
“Apple” privacy policy: https://www.apple.com/legal/privacy
“Google” privacy policy: https://policies.google.com/privacy
10. Bookings with Partners
Through Feme Care you can book services with third-party beauty and health service providers – salons, cosmetologists, dermatologists and other specialists (“Partners”).
What data we transfer to the Partner. When you book a service with a Partner, we transfer to them only what is necessary to provide the service:
first name (and, where applicable, last name);
contact details (email, phone number);
booking details (date, time, service);
where needed and after receiving your separate explicit consent – a short note about skin condition, if this is necessary to properly provide the service.
We follow the principle of data minimization – we transfer to the Partner only the data that is reasonably necessary to provide the specific service.
Partner’s role. After receiving your data, the Partner usually becomes an independent data controller for the purpose of providing its services and processes the data according to its own privacy practices. In certain cases (e.g., when bookings are administered on the Feme Care platform), joint controllership (GDPR Art. 26) relationships may apply – the specific allocation of roles is disclosed before booking.
Health data to the Partner. Transfer of notes about skin condition to the Partner includes special categories of (health) data. Such transfer takes place only after receiving your explicit consent within the meaning of GDPR Art. 9(2)(a).
Booking cancellation, “no-show” and advances. Certain Partners may apply cancellation rules, “no-show” fees or an advance payment. These rules and any advance requirements are provided in the Application before each booking; by confirming them, you agree to the booking terms of the specific Partner.
11. Analytics, crash logging and advertising
We use technical tools that help the Application operate stably, measure usage, fix errors and, when you give consent, measure advertising campaigns.
Crash and error logging. We use “Sentry” – technical data about the incident is collected (error message, device model, Application version, actions taking place during the error). It operates on the basis of legitimate interest and helps solve Application problems.
Advertising attribution and campaign measurement. This solution allows us to measure which marketing campaign encouraged you to install the Application or take an action. Pseudonymous identifiers, IDFA (iOS) or “Advertising ID” (“Android”), campaign attributes are collected. It operates only after receiving your consent.
iOS “App Tracking Transparency”. According to “Apple” requirements, in iOS before starting to use advertising attribution or cross-site tracking functionality, we will ask for your consent through the standard ATT window. If you refuse, the advertising identifier (IDFA) will not be available and some analytics will operate only on an anonymous / aggregate basis.
“Android” advertising identifier. On “Android”, advertising attribution solutions use “Advertising ID” – only after receiving your consent through the consent banner. You can disable “Advertising ID” in phone settings.
12. Personalization and profiling
In order to provide you with personal product and service recommendations, we use profiling within the meaning of GDPR Art. 4(4) – automated evaluation of your skin analysis results and purchase history. On this basis, products, services or subscription plans are recommended.
Important:
profiling takes place only after receiving your consent;
profiling may include special categories of (health) data – in such case the explicit consent under GDPR Art. 9(2)(a) applies;
profiling does not produce any legal or similarly significant effects within the meaning of Article 22 of the GDPR – i.e., we do not make decisions based solely on automated processing that could significantly affect your rights.
You can withdraw consent to profiling at any time in the application settings – in that case recommendations become more general, i.e., not adapted to you personally.
13. Direct marketing
Email newsletters. We send them only after receiving your consent during registration or later in profile settings. You may withdraw consent at any time by clicking the “unsubscribe” link at the bottom of the newsletter or by writing to privacy@feme.care.
Marketing push notifications. Push notifications may be transactional (e.g., about booking confirmation, payment, account changes) or marketing (e.g., about new products, promotions, personal recommendations). Marketing push notifications are sent only with your separate consent. You can disable them at any time in the Application settings or in the phone operating system settings.
Marketing to existing customers. Under Article 81(2) of the Law on Electronic Communications of the Republic of Lithuania, we may send existing customers offers of our goods and services similar to those purchased, having provided a clear opportunity to object to such use in every message sent.
Right to object at any time. At any time you have the right to object to the processing of your personal data for direct marketing purposes. After that we will no longer send you marketing messages.
14. Apple App Privacy and Google Play Data Safety
According to Apple and Google requirements, privacy declarations are provided in the “App Store” and “Google Play” stores – “Apple App Privacy” and “Google Play Data Safety”. These declarations reflect what data the Application collects and how it uses it.
The declarations are updated when the SDK set used or the data processing logic changes.
15. To whom do we transfer data?
The table below sets out the main categories of entities to whom your data may be transferred and their role from the GDPR perspective.
| Recipient category | Why we transfer | Role from the GDPR perspective |
|---|---|---|
| Third-party AI provider “YouCam” / Perfect Corp. | To process the face photo and obtain skin analysis results | Data processor |
| Hosting, database, file storage providers (Laravel Cloud, etc.) | For Application backend, database, file storage and security functions | Data processor |
| Payment providers: Paysera, Apple and Google | For payments, subscriptions, payment statuses and fraud prevention | Independent controller |
| Apple Inc. / Apple Distribution International | “Sign in with Apple”, “In-App Purchase”, “App Store” declarations | Independent controller |
| Google LLC / Google Ireland Limited | “Sign in with Google”, “Google Play Billing”, “Google Play” Data Safety declarations, “Advertising ID” | Independent controller |
| Crash logging service provider (“Sentry”) | For logging and resolving Application errors and crashes | Data processor |
| Partners (salons, cosmetologists, specialists) | To provide the service, confirm the booking and contact regarding the visit | Independent controller / joint controller (depends on the model) |
| Advertising platforms: Meta Platforms Ireland Ltd. (Meta / Facebook SDK), TikTok Technology Limited (TikTok Ads SDK) | For measuring advertising campaigns, conversion tracking and attribution according to your consent | Joint controller (GDPR Art. 26) for conversion and audience data; independent controller for further use of this data on their platforms |
| Push notification, email marketing, customer support providers | For communication with you according to choices | Data processor |
| Accounting system and accounting service provider | For invoices, accounting, taxes and declarations | Data processor |
| Legal, tax, audit consultants | Professional services | Data processor / independent controller |
| State institutions (VDAI, VMI, bailiffs, courts) | For compliance with legal obligations | Independent controller |
| In the event of company reorganization / sale – transaction participants | For business transfer | Independent controller |
We do not transfer your personal data to third parties for their independent marketing purposes.
Third-party websites and links. The Application and our website may contain links to third-party websites and services (e.g., Partner websites, privacy policies of payment service providers, our social network accounts). When you click such links, the respective third party’s privacy practices apply – this Policy does not apply to them. We recommend reading third-party privacy policies before providing your data to them.
16. Where data is stored and international transfer
Feme Care uses Laravel Cloud (https://laravel.com/legal). The App cluster and MySQL database are in EU Central (Frankfurt, Germany), and user files are stored in the European Union.
Some of the service providers we use may operate outside the European Economic Area (EEA) – for example, in the United States of America (“Apple”, “Google”, “Meta”) or other jurisdictions (“YouCam” / Perfect Corp.). In such cases, we ensure that data is transferred only in compliance with the requirements of Chapter V of the GDPR:
we use providers certified under the EU–US Data Privacy Framework when applicable;
we enter into agreements with standard contractual clauses (SCC) under European Commission Decision 2021/914;
we perform a transfer impact assessment (TIA) and, where necessary, apply additional technical and organizational safeguards.
17. How do we protect data?
We apply technical and organizational security measures corresponding to Article 32 of the GDPR, taking into account the nature of the data and the risk. This includes:
encryption of data transmission (TLS / HTTPS);
encryption of data at rest on servers, where technically possible;
access control according to the need-to-know principle;
authentication and, for administrators, multi-factor authentication (MFA);
regularly updated security solutions and physical security in the case of providers;
pseudonymization, where technically possible;
backups and business continuity plans;
confidentiality obligations of employees and partners;
DDoS protection and edge network layer on the website and Application API.
According to the provided architecture scheme, edge network, DDoS protection, CDN and edge caching are used, and the API domain api.feme.care is marked as approved.
Although we take reasonable security measures, no electronic system can guarantee complete security. If you notice suspicious activity in your account, contact privacy@feme.care.
Notification of security breaches. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the State Data Protection Inspectorate within 72 hours in accordance with Article 33 of the GDPR. If the breach poses a high risk, we will also inform you directly in accordance with Article 34 of the GDPR.
18. Anonymization and pseudonymization
In certain cases we depersonalize (anonymize) your data so that a specific person cannot be identified – such data is no longer personal data and may be used for statistics, improvement of the Application or business analysis.
In some activities we apply pseudonymization – data is processed using identifiers that we store separately from the person’s identity itself (e.g., pseudonymous identifiers are used in analytics instead of email). Pseudonymized data is still considered personal data and is protected under the GDPR.
19. Your rights and choices
Under the GDPR you have the following rights:
the right to receive information about the processing of your data (GDPR Arts. 13–14);
the right to access the data processed and receive a copy of it (GDPR Art. 15);
the right to rectification if the data is inaccurate or incomplete (GDPR Art. 16);
the right to erasure (“right to be forgotten”) where there is a basis (GDPR Art. 17);
the right to restriction of processing (GDPR Art. 18);
the right to data portability in a machine-readable format (GDPR Art. 20);
the right to object to processing based on legitimate interest and to direct marketing (GDPR Art. 21);
the right to withdraw consent at any time if processing is based on consent;
the right not to be subject to automated decisions within the meaning of GDPR Art. 22 – we note that Feme Care does not make such decisions;
the right to lodge a complaint with the State Data Protection Inspectorate or another supervisory authority of an EU Member State.
How to submit a request. Contact privacy@feme.care. We respond to requests within the deadlines established by the GDPR, usually within 1 month. If the request is complex or many requests have been submitted, the deadline may be extended by up to another 2 months – we will inform you about this.
Identity verification. Before carrying out a request, we may ask you to reasonably confirm your identity in order to protect data from unauthorized access.
Complaints. If you believe that your data is being processed improperly, you may contact us or lodge a complaint with the State Data Protection Inspectorate: L. Sapiegos g. 17, LT-10312 Vilnius, email ada@ada.lt, website vdai.lrv.lt.
20. Withdrawal of consent and its consequences
You can withdraw consent in the following ways:
through the Application settings – direct marketing, profiling, push notification consents;
through phone operating system settings – iOS “App Tracking Transparency”, push notification permissions;
by clicking “unsubscribe” at the bottom of the newsletter;
by writing by email to privacy@feme.care.
Withdrawal usually takes effect within 48 hours from receipt. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Consequences of withdrawal. After withdrawing certain consents, some functions may become unavailable:
after withdrawing consent to skin analysis – you will no longer be able to perform new analyses; already received results will be deleted according to your choice;
after withdrawing consent / deleting the account – skin masks are detached from your identity and continue to be stored in a separate database on the basis of legitimate interest (service quality and AI improvement), as described in Section 8;
after withdrawing consent to profiling – recommendations will become more general and not adapted to you personally;
after withdrawing consent to analytics and advertising attribution – the Application will operate normally, but marketing will not be personalized.
21. User-created content, feedback and public publication
If the application provides the possibility to leave feedback or comments, we will publish such content only when you clearly choose to publish it yourself. Publicly published content may be visible to other users or third parties, therefore before publishing do not disclose information that you do not want to make public.
You may request removal of your publicly published content, but we cannot control copies that other persons may have saved or shared before removal.
We reserve the right to remove content that violates legal acts, our terms of use or the rights of third persons.
22. Cookies
Our website (feme.care) uses cookies and similar technologies that help ensure the operation of the website, analyze traffic and, with consent, display relevant advertisements. The Application itself does not use cookies — separate SDK tools operate in it, described in Section 11.
Under GDPR Art. 6(1)(f), necessary cookies are used on the basis of our legitimate interest – so that the website works properly. Analytical or marketing cookies are used only after receiving your consent (GDPR Art. 6(1)(a)), which you can withdraw at any time in browser settings or the cookie bar.
Types of cookies used
Necessary – required for website operation (e.g., shopping cart, login);
Functional – remember your settings (e.g., language, region);
Analytical – help understand how visitors use the website (e.g., “Google Analytics”);
Marketing – allow showing personalized offers or advertisements (“Google Ads”, “Meta Pixel”).
Cookies
| Cookie | Type | Purpose | Validity |
|---|---|---|---|
| cookiehub | Necessary | Manages the user’s consent regarding cookies on the website | 1 year |
| _ga_* | Analytical | “Google Tag Manager” cookies; through the “Google” platform, the connected “MailerLite” newsletter solution | According to “Google” settings |
Cookie management
You can delete cookies or change settings in your browser at any time. More information can be found in the browser help section (e.g., Google Chrome, Firefox).
If necessary cookies are disabled, some website functions may not work properly.
23. Policy changes
We may update this Policy if the Services, providers, technologies, legal acts or data processing processes change. We will inform you about significant changes through the Application, on the website or by email when required by law. The latest version of the Policy will always be available in the Application and on our website, indicating the update date.
If you do not agree with the changes, you have the right to stop using the Services and request deletion of your account.
24. Contacts
MB “Feme Care” Company code: 307636331 Address: Perkūnkiemio g. 19, LT-12120 Vilnius, Lithuania Privacy questions: privacy@feme.care
Submitting complaints: State Data Protection Inspectorate L. Sapiegos g. 17, LT-10312 Vilnius Tel. +370 5 271 2804 Email: ada@ada.lt Website: vdai.lrv.lt