Data processing agreement
The clinic is the data controller for its patients' data, and HekimBis processes it on the clinic's instructions. The agreement sets the processing scope, security measures, sub-processor approval, breach notification, and data handover at contract end.
1. Parties
Data Controller: The health organization or physician subscribed to the HekimBis service; identity details are in the subscription record.
Data Processor: The provider of the service. Details are below; empty lines are not shown.
- Legal name: MTY Teknoloji A.Ş.
- Address: Mersin Üniversitesi Teknopark (TechnoScope), 33110 Çiftlikköy, Yenişehir, Mersin, Türkiye
- Data protection applications: [email protected]
2. Definitions
In this Agreement "personal data", "special-category personal data", "processing", "data subject", "data controller" and "data processor" have the meanings in the Law. "Service" means the HekimBis software service; "Instruction" means the processing directions given by the Data Controller by using the Service and through contracts.
3. Subject, duration and nature
The Data Processor processes personal data on behalf of the Data Controller to deliver the Service. Processing covers activities such as hosting, storage, backup, display, transmission, matching where needed, and deletion. The duration of processing runs for the subscription term and until the completion of the end-of-contract operations in Article 13.
4. Types of data and data subjects
Data subjects: The Data Controller's patients, patient relatives and representatives, prospective patients, the Data Controller's physicians and staff, employees of intermediary organizations and suppliers.
Types of data: Identity and contact data; appointment, examination, test, image, report, consent and other health data (special-category personal data); finance and payment status; communication preferences; user accounts and activity records. The Data Controller decides what data to enter into the system and is responsible for data minimization.
5. Instruction and purpose limitation
The Data Processor processes personal data only in line with the Data Controller's written instructions or instructions given through the Service, and for delivering the Service. If it considers an instruction unlawful, it notifies the Data Controller immediately and may refrain from applying it until the necessary change is made. The Data Processor does not use patient data for its own purposes, does not process it for marketing or profiling, does not use it for general-purpose training of AI models, and does not sell it to third parties.
6. Confidentiality
The Data Processor puts employees who may access personal data under a confidentiality obligation and limits access to what the task requires, on a least-privilege basis. Support access is not permanent; where needed it is granted with a reason, for a limited time and on record. The confidentiality obligation continues after the Agreement ends.
7. Technical and administrative measures
Under Article 12 of the Law, the Data Processor takes and maintains measures covering the following headings to ensure an appropriate level of security:
- Data separation per tenant (organization) and access control at branch and organization boundaries
- Role-based and context-based authorization; blocking access to records without a care relationship, and a reasoned, time-limited, separately recorded exception route for emergency access
- A tamper-resistant audit record tracking access to and changes in patient records
- Encryption in transit and at rest; masking so that sensitive data does not reach general logs and support tools
- Regular backups and restore tests; a control that prevents deleted or access-revoked data from becoming visible again after a restore
- A defined procedure for detecting, recording and managing security incidents
- Confidentiality and data protection awareness for employees
- Rate limiting and abuse protection to limit unauthorized access
Measures are updated in line with technological developments and risk assessment; the level of security is not reduced.
8. Data location and transfer
Production health data is kept in Türkiye. Backup sets are also kept in Türkiye. Even subprocessors that do not touch health data are not connected to the system without a separate data flow and risk assessment. Personal data is not transferred abroad unless the Data Controller's written instruction and the conditions of Article 9 of the Law are met.
9. Subprocessors
The Data Processor may delegate part of the processing to subprocessors. In that case it concludes a written contract with the subprocessor containing data protection obligations equivalent to this Agreement and remains responsible for the subprocessor's activities. The current subprocessor list is provided at the Data Controller's request. If a new subprocessor that can access health data will be added, the Data Controller is notified in reasonable advance and may object on justified grounds.
10. Data subject requests
The Data Processor assists the Data Controller to a reasonable extent in answering data subjects' requests under Article 11 of the Law. If a data subject's request reaches the Data Processor directly, it is forwarded to the Data Controller; no substantive reply is given without the Data Controller's instruction. For deletion requests, records that must legally be kept (such as signed clinical records, consent and audit records) are handled under the restricted archive or approved policy instead of deletion.
11. Data breach notification
When the Data Processor learns that personal data has been obtained unlawfully or that its security has been breached, it notifies the Data Controller without delay. The notification includes, to the extent known, the nature of the breach, the categories of data and persons affected, possible consequences and the measures taken or proposed. It provides the information and support needed for the Data Controller's notifications to the persons concerned and to the Personal Data Protection Board under the Law.
12. Audit and information
The Data Processor provides the Data Controller the information necessary to demonstrate compliance with this Agreement and permits audits conducted with reasonable prior notice, in a way that does not disrupt operations and does not breach the confidentiality of other customers' data. Audits are conducted within a jointly defined scope and confidentiality conditions.
13. Termination: export, archive and destruction
When the subscription ends or is cancelled:
- New operations and user access are closed in line with the contract; the support team does not gain permanent access.
- A scope-controlled, manifested and encrypted export is prepared for the authorized Data Controller.
- Records that must be kept by legislation are moved from active use to a restricted archive; the retention obligation is not overridden by a deletion request.
- Integration keys, device connections and active sessions are revoked.
- Data whose retention period has ended goes through controlled destruction or approved anonymization; scope, policy version and operation records are produced as evidence.
A plan downgrade or capacity change does not delete clinical records. Trial data is synthetic only and is deleted after the stated waiting period following the trial. Backups follow a fixed life cycle and are not used as a hidden exception to active data retention. If there is an authorized reason, scope, start and end, and an approved retention decision because of a legal retention ground or a dispute, the destruction process may be suspended.
14. Liability
The parties bear liability for their own fault and for breach of their obligations under this Agreement, within the mandatory provisions of law. The Data Controller is responsible for lawful collection of data, fulfilling privacy notice and, where needed, explicit consent obligations, authorizing its users and the accuracy of data it enters. The Data Processor is responsible for processing that breaches this Agreement and the instructions. Liability limits are subject to the provisions of the Subscription Agreement.
15. Governing law
Turkish law applies to this Agreement. In disputes the jurisdiction provisions in the Subscription Agreement apply.
16. Version information
Related texts: Subscription Agreement, KVKK Privacy Notice, Privacy Policy.
