
KVKK
Your clinic is the data controller, HekimBis the processor
Under Law No. 6698 (KVKK) the roles are kept clearly apart. The clinic decides and is responsible for patient and clinical record data, and HekimBis is the party that processes data on the clinic's instruction. This page explains how the product supports those roles.
For data subject requests: [email protected]
Who is responsible for what?
The clinic gives patients the privacy notice and obtains explicit consent when needed. It manages users, roles and branch scope, reviews and answers data subject requests, and is responsible for applying the retention and disposal policy.
HekimBis processes data within the clinic's instructions and the data processing agreement. It provides access control, isolation, encryption and the audit log, supplies the application tools for notices, consent, requests and retention, and opens support access only with approval, a time limit and audit.
Visitors to this website are covered by a separate privacy notice.
How does a data subject request move forward?
A patient's request is recorded, identity-verified, reviewed and answered. The response time follows the period set by the law.
Response
A data copy, correction, or destruction/anonymization is carried out and a reasoned reply is given.
- The process is complete here.
All steps
- 01 Request (Data subject) The request is received and its scope and date are recorded.
- 02 Identity verification (Clinic) The requester's identity and authority are verified.
- 03 Assessment (Clinic) Legal retention duties and scope are assessed.
- 04 Response (HekimBis) A data copy, correction, or destruction/anonymization is carried out and a reasoned reply is given.
Alternative path from 02 Identity verification; it returns to the main flow at 02 Identity verification.
- 02a Identity not verified (Clinic) Additional information is requested.
- 02b Additional information provided (Data subject) Verification is retried.
Alternative path from 03 Assessment; it returns to the main flow at 04 Response.
- 03a Partial or full refusal (Clinic) Records that cannot be deleted because of legal retention move to restricted archive; the reason is communicated in writing.
04 Response
Privacy notice, explicit consent and clinical consent are separate concepts
HekimBis does not merge these three into one checkbox; it keeps each as a separate record.
Privacy notice
- Purpose
- To tell who processes the data and for what purpose.
- When
- Shown before the data is processed.
- Record
- Version and time shown.
- Withdrawal
- Not withdrawn; a new version is shown.
Explicit consent
- Purpose
- To obtain permission, given freely, for a specific processing that needs consent.
- When
- Only for the processing that needs it, as a separate action.
- Record
- Version, time, channel and scope.
- Withdrawal
- Can be withdrawn; affected processing becomes visible.
Clinical consent
- Purpose
- The patient's informed consent to a medical procedure or intervention.
- When
- With text specific to the procedure, before it.
- Record
- Procedure-specific text, signature components, signer, version and channel.
- Withdrawal
- Handled in the clinical process according to the state of the procedure.
The class of data sets its life cycle
Every data class is tied to a versioned retention policy: purpose, owning module, active, restricted archive and disposal stages, trigger event, legal basis and legal hold behavior. Retention periods are not coded until their legal basis is verified.
Signed clinical records, results, reports and consents
There is no permanent deletion, and the correction chain is preserved.
Patient identity and operational records
Kept active or in a restricted archive while the purpose and legal obligations last; access narrows immediately when membership ends.
Finance and subscription
Kept under financial and legal policy; card data is not stored in HekimBis.
Documents and images
Kept encrypted and separated by organization; retention and legal hold are applied in two layers.
Audit and security records
Append-only, masked and open only to a narrow group of authorized users.
Trial data
Holds sample data only; writing closes when the period ends, and after a waiting period the data is disposed of and proof of disposal is produced.
What we commit to as the data processor
- Hosting in Türkiye
- Production health data is hosted in Türkiye, and backups stay inside the same data residency boundary.
- Data processing agreement
- The agreement defines the data processed, the purpose, the security measures and what happens to the data when the agreement ends.
- Sub-processors
- The use of sub-processors is governed within the data processing agreement.
- Organization closure
- When an organization closes, an encrypted export with an audited scope is prepared for the authorized owner; legal retention obligations protect records outside that scope.
- Support access
- The support team works with time-limited, approved and audited access.
- Incident procedure
- A defined procedure covers security incidents and data breaches.
Frequently asked questions about KVKK
Who is the data controller and who is the processor?
You are responsible for your patients' clinical and identity data, and HekimBis processes it on your instructions. Visitors to this website are covered by a separate privacy notice.
Does HekimBis help me meet my KVKK obligations?
Compliance is the clinic's responsibility. The software provides tools such as notice and consent records, access control, the audit log, retention and disposal policy, and data subject request management.
What if a patient asks for their data to be deleted?
The request is reviewed. Records under a legal retention obligation are not deleted but moved to a restricted archive; for data outside that scope, an approved disposal or anonymization job runs and its proof is produced.
What happens when a patient withdraws consent?
The withdrawal is recorded and processing based on that consent becomes visible. Processing that rests on the clinic's clinical and legal obligations is not affected by a withdrawal.
Does data leave the country?
Production health data is kept in Türkiye. In flows that receive patients from abroad, sharing needs its own basis, purpose, minimum fields and an audit record.
Can I export my data?
Yes. There is an encrypted export with an audited scope for the authorized owner, and it is not restricted in any plan.
Keep reading
Related pages
Company and support
- Payment securityCard data, verification, and invoicing for subscription and patient payments.
- TechnologyHosting in Türkiye, redundancy, restore drills, and monitoring.
- ContactReach us for a demo, a quote, data migration, or support.
- KVKK privacy noticeOur privacy notice as data controller under KVKK, Law No. 6698.
