GDPR & Data Protection

Last updated: April 2026

Our Commitment to Data Protection

Dermme Health Ltd, operating as MoleScan™, is committed to protecting personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Data Controller

Dermme Health Ltd is the data controller for personal data collected through the MoleScan website. For clinical platform data, the relationship between Dermme Health Ltd and deploying organisations is governed by data processing agreements.

UK Data Residency

All personal and clinical data processed by MoleScan is stored within the United Kingdom. We do not transfer personal data outside the UK.

Security Measures

We implement appropriate technical and organisational measures including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls
  • Regular security assessments
  • Incident response procedures

Data Subject Rights

Individuals have the right to access, rectify, erase, restrict, and port their personal data, as well as the right to object to processing. Requests can be submitted to hello@molescan.co.uk.

Data Protection Impact Assessments

MoleScan conducts Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in a high risk to individuals, in line with ICO guidance.

ICO Registration

Dermme Health Ltd is registered with the Information Commissioner's Office (ICO).