DATA PROCESSING
Data Processing Agreement (summary)
Last updated / Son güncelleme: 2026-10-02
English
This is a summary of the Data Processing Agreement (KVKK Art. 12; GDPR Art. 28) between the Customer clinic (controller) and DATACALYX YAZILIM TEKNOLOJİLERİ ANONİM ŞİRKETİ (processor). The full DPA is signed on request: info@navmediq.com.
Subject matter, duration, nature and purpose
Processing of end-user conversation data to provide the NavMedIQ by Emediquality patient-communication service (receiving and answering messages, collecting contact and appointment preferences, handing over to the clinic). Duration: the term of the subscription, plus the deletion period below. Nature: storage, retrieval, AI-assisted generation of replies, transmission to the clinic.
Categories of data and data subjects
Data: contact details, message and voice-transcript content, language, appointment preferences, and any health information the user chooses to share (special-category data). Data subjects: the clinic's patients, prospective patients and other end users; the clinic's staff using the console.
Controller's instructions and confidentiality
We process data only on the Customer's documented instructions (the agreement, console configuration), and inform the Customer if an instruction appears unlawful. Personnel with access are bound by confidentiality.
Security measures (TOMs)
- TLS encryption in transit; encrypted storage of integration tokens
- Role-based access control and authenticated admin console
- Masking of personal data in logs
- Configurable retention (default 30 days) with automatic deletion or anonymisation
- Webhook signature verification for WhatsApp
- Separation of customer configurations; least-privilege access
Sub-processors and change notice
Meta Platforms (WhatsApp Cloud API), Google (Gemini API), Railway (hosting, region as configured), Cloudflare (DNS/CDN), GitHub (source code; no personal data). We give the Customer prior notice of new or replaced sub-processors, and the Customer may object on reasonable grounds.
Assistance with data subject requests
We assist the Customer, by appropriate technical and organisational means, in responding to requests under KVKK Art. 11 and GDPR Art. 15–22, and forward requests we receive directly.
Breach notification
We notify the Customer without undue delay and in any case within 48 hours after becoming aware of a personal data breach affecting its data, with the information reasonably available to support the Customer's own notification duties.
Audit
The Customer may request information necessary to demonstrate compliance and, with reasonable notice and subject to confidentiality, audit our processing (generally by document review; on-site only where required by law).
Deletion or return
At the end of the agreement we return (export) or delete the Customer's data on request within 30 days, unless law requires retention.
International transfers
Transfers outside Türkiye/EEA rely on Standard Contractual Clauses or other lawful mechanisms (KVKK Art. 9; GDPR Chapter V).
Türkçe
Bu sayfa, Müşteri klinik (veri sorumlusu) ile DATACALYX YAZILIM TEKNOLOJİLERİ ANONİM ŞİRKETİ (veri işleyen) arasındaki Veri İşleme Sözleşmesi'nin (KVKK m.12; GDPR m.28) özetidir. Sözleşmenin tam metni talep üzerine imzalanır: info@navmediq.com.
Konu, süre, nitelik ve amaç
NavMedIQ by Emediquality hasta iletişim hizmetinin sunulması amacıyla son kullanıcı sohbet verilerinin işlenmesi (mesajların alınması ve yanıtlanması, iletişim ve randevu tercihlerinin toplanması, kliniğe devir). Süre: abonelik süresi ve aşağıdaki silme süresi. Nitelik: saklama, erişim, yapay zekâ destekli yanıt üretimi, kliniğe iletim.
Veri ve ilgili kişi kategorileri
Veriler: iletişim bilgileri, mesaj ve ses dökümü içeriği, dil, randevu tercihleri ve kullanıcının paylaşmayı seçtiği sağlık bilgileri (özel nitelikli veri). İlgili kişiler: kliniğin hastaları, aday hastalar ve diğer son kullanıcılar; konsolu kullanan klinik çalışanları.
Veri sorumlusunun talimatları ve gizlilik
Verileri yalnızca Müşterinin yazılı talimatları (sözleşme, konsol yapılandırması) doğrultusunda işler, bir talimat hukuka aykırı görünüyorsa Müşteriyi bilgilendiririz. Erişimi olan personel gizlilik yükümlülüğü altındadır.
Güvenlik önlemleri (TOM)
- İletimde TLS şifreleme; entegrasyon token'larının şifreli saklanması
- Rol tabanlı erişim kontrolü ve kimliği doğrulanmış yönetim konsolu
- Loglarda kişisel verilerin maskelenmesi
- Yapılandırılabilir saklama (varsayılan 30 gün) ve otomatik silme veya anonimleştirme
- WhatsApp webhook imza doğrulaması
- Müşteri yapılandırmalarının ayrıştırılması; asgari yetki ilkesi
Alt işleyenler ve değişiklik bildirimi
Meta Platforms (WhatsApp Cloud API), Google (Gemini API), Railway (barındırma, bölge yapılandırıldığı şekilde), Cloudflare (DNS/CDN), GitHub (kaynak kodu; kişisel veri yok). Yeni veya değişen alt işleyenleri Müşteriye önceden bildiririz; Müşteri makul gerekçelerle itiraz edebilir.
İlgili kişi taleplerine yardım
KVKK m.11 ve GDPR m.15–22 kapsamındaki taleplerin yanıtlanmasında Müşteriye uygun teknik ve idari önlemlerle yardım eder, doğrudan bize ulaşan talepleri iletiriz.
İhlal bildirimi
Müşterinin verilerini etkileyen bir kişisel veri ihlalini öğrendiğimiz andan itibaren gecikmeksizin ve her halde en geç 48 saat içinde Müşteriye bildirir, Müşterinin kendi bildirim yükümlülüklerini yerine getirmesine yardımcı olacak makul ölçüdeki bilgiyi sunarız.
Denetim
Müşteri, uyumu göstermek için gerekli bilgileri isteyebilir; makul ön bildirimle ve gizlilik çerçevesinde işleme faaliyetlerimizi denetleyebilir (genellikle belge incelemesiyle; yerinde denetim yalnızca yasanın gerektirdiği hallerde).
Silme veya iade
Sözleşme sonunda, yasal saklama yükümlülüğü yoksa Müşterinin verilerini talep üzerine 30 gün içinde iade (dışa aktarım) eder veya sileriz.
Yurt dışı aktarım
Türkiye/AEA dışına aktarımlar Standart Sözleşme Maddeleri veya diğer hukuka uygun mekanizmalara dayanır (KVKK m.9; GDPR Beşinci Bölüm).
Company information / Şirket bilgileri
- Legal name / Ticaret unvanı
- DATACALYX YAZILIM TEKNOLOJİLERİ ANONİM ŞİRKETİ
- Company type / Şirket türü
- Anonim Şirket (Joint Stock Company)
- Registered address / Tescilli adres
- Görükle Mah. Üniversite-1 Cad. Ulutek Teknoloji Geliştirme Bölgesi No: 933 İç Kapı No: B027, 16285 Nilüfer/Bursa, Türkiye
- MERSIS no / MERSİS no
- 0271210934100001
- Tax office / Vergi dairesi
- Nilüfer Vergi Dairesi
- Tax ID (VKN) / Vergi kimlik no (VKN)
- 2712109341
- Trade registry / Ticaret sicil
- Bursa Ticaret Sicil Müdürlüğü 140280
- Phone / Telefon
- +90 555 022 89 16
- KEP (registered e-mail) / KEP adresi
- datacalyxyazilim@hs01.kep.tr
- E-mail / E-posta
- info@navmediq.com
- Website / Web sitesi
- https://navmediq.com