Skip to content

Create an account

HekimBis home
A locked filing cabinet drawer with a key and a navy folder on top.

KVKK

Your clinic is the data controller, HekimBis the processor

Under Law No. 6698 (KVKK) the roles are kept clearly apart. The clinic decides and is responsible for patient and clinical record data, and HekimBis is the party that processes data on the clinic's instruction. This page explains how the product supports those roles.

For data subject requests: [email protected]
A clinic administrator hands a new staff member a blank ID badge on a lanyard

Who is responsible for what?

The clinic gives patients the privacy notice and obtains explicit consent when needed. It manages users, roles and branch scope, reviews and answers data subject requests, and is responsible for applying the retention and disposal policy.

HekimBis processes data within the clinic's instructions and the data processing agreement. It provides access control, isolation, encryption and the audit log, supplies the application tools for notices, consent, requests and retention, and opens support access only with approval, a time limit and audit.

Visitors to this website are covered by a separate privacy notice.

KVKK privacy noticeData processing agreement

How does a data subject request move forward?

A patient's request is recorded, identity-verified, reviewed and answered. The response time follows the period set by the law.

HekimBis04End

Response

A data copy, correction, or destruction/anonymization is carried out and a reasoned reply is given.

  • The process is complete here.
4 / 11

All steps

  1. 01 Request (Data subject) The request is received and its scope and date are recorded.
  2. 02 Identity verification (Clinic) The requester's identity and authority are verified.
  3. 03 Assessment (Clinic) Legal retention duties and scope are assessed.
  4. 04 Response (HekimBis) A data copy, correction, or destruction/anonymization is carried out and a reasoned reply is given.

Alternative path from 02 Identity verification; it returns to the main flow at 02 Identity verification.

  1. 02a Identity not verified (Clinic) Additional information is requested.
  2. 02b Additional information provided (Data subject) Verification is retried.

Alternative path from 03 Assessment; it returns to the main flow at 04 Response.

  1. 03a Partial or full refusal (Clinic) Records that cannot be deleted because of legal retention move to restricted archive; the reason is communicated in writing.

04 Response

Privacy notice, explicit consent and clinical consent are separate concepts

HekimBis does not merge these three into one checkbox; it keeps each as a separate record.

Privacy notice

Purpose
To tell who processes the data and for what purpose.
When
Shown before the data is processed.
Record
Version and time shown.
Withdrawal
Not withdrawn; a new version is shown.

Explicit consent

Purpose
To obtain permission, given freely, for a specific processing that needs consent.
When
Only for the processing that needs it, as a separate action.
Record
Version, time, channel and scope.
Withdrawal
Can be withdrawn; affected processing becomes visible.

Clinical consent

Purpose
The patient's informed consent to a medical procedure or intervention.
When
With text specific to the procedure, before it.
Record
Procedure-specific text, signature components, signer, version and channel.
Withdrawal
Handled in the clinical process according to the state of the procedure.

The class of data sets its life cycle

Every data class is tied to a versioned retention policy: purpose, owning module, active, restricted archive and disposal stages, trigger event, legal basis and legal hold behavior. Retention periods are not coded until their legal basis is verified.

  • Signed clinical records, results, reports and consents

    There is no permanent deletion, and the correction chain is preserved.

  • Patient identity and operational records

    Kept active or in a restricted archive while the purpose and legal obligations last; access narrows immediately when membership ends.

  • Finance and subscription

    Kept under financial and legal policy; card data is not stored in HekimBis.

  • Documents and images

    Kept encrypted and separated by organization; retention and legal hold are applied in two layers.

  • Audit and security records

    Append-only, masked and open only to a narrow group of authorized users.

  • Trial data

    Holds sample data only; writing closes when the period ends, and after a waiting period the data is disposed of and proof of disposal is produced.

What we commit to as the data processor

Hosting in Türkiye
Production health data is hosted in Türkiye, and backups stay inside the same data residency boundary.
Data processing agreement
The agreement defines the data processed, the purpose, the security measures and what happens to the data when the agreement ends.
Sub-processors
The use of sub-processors is governed within the data processing agreement.
Organization closure
When an organization closes, an encrypted export with an audited scope is prepared for the authorized owner; legal retention obligations protect records outside that scope.
Support access
The support team works with time-limited, approved and audited access.
Incident procedure
A defined procedure covers security incidents and data breaches.

Frequently asked questions about KVKK

FAQ
Who is the data controller and who is the processor?

You are responsible for your patients' clinical and identity data, and HekimBis processes it on your instructions. Visitors to this website are covered by a separate privacy notice.

Does HekimBis help me meet my KVKK obligations?

Compliance is the clinic's responsibility. The software provides tools such as notice and consent records, access control, the audit log, retention and disposal policy, and data subject request management.

What if a patient asks for their data to be deleted?

The request is reviewed. Records under a legal retention obligation are not deleted but moved to a restricted archive; for data outside that scope, an approved disposal or anonymization job runs and its proof is produced.

What happens when a patient withdraws consent?

The withdrawal is recorded and processing based on that consent becomes visible. Processing that rests on the clinic's clinical and legal obligations is not affected by a withdrawal.

Does data leave the country?

Production health data is kept in Türkiye. In flows that receive patients from abroad, sharing needs its own basis, purpose, minimum fields and an audit record.

Can I export my data?

Yes. There is an encrypted export with an audited scope for the authorized owner, and it is not restricted in any plan.