medicalgrow.aiTR

Data privacy: KVKK and GDPR

The basics of handling patient data in line with KVKK and GDPR — access control, deleting data, exports and patient requests.

5 min read

Medical-tourism clinics handle sensitive data under both Turkey's KVKK (Personal Data Protection Law No. 6698) and, for patients from Europe, the GDPR. Health information, photos and X-rays count as special-category personal data under both and are more strictly protected. This page sets out the basics of using MedicalGrow in line with these rules.

Note

This page is general information and doesn't replace legal advice. Work with a legal adviser on your privacy notice, explicit consent forms, retention periods and VERBIS registration.

Who is responsible for what

TopicResponsible
Which data is collected from patients and why; privacy notices and explicit consentThe clinic (data controller)
Giving the team the right permissions, separate users, closing accounts of staff who leaveThe clinic
Responding to patient requests (access, correction, deletion)The clinic, using the panel's tools
Technical security and infrastructure of the platformMedicalGrow (data processor)

In short: MedicalGrow provides a secure tool; collecting and using the data lawfully is the clinic's responsibility.

Core principles and how they apply in the panel

PrincipleHow to apply it in the panel
Lawful collectionInclude a link to your privacy notice and, where required, a consent checkbox on your lead forms. See Facebook lead forms.
Data minimisationOnly create the custom fields you need. Don't store passport numbers, card details and similar data unless necessary. See Custom fields.
Purpose limitationDon't use photos taken for treatment in marketing without separate consent. See Storage best practices.
Confidentiality and access controlA separate user per staff member, permissions that fit their role and, if needed, a restriction to their own patients.
AccuracyUpdate the contact record when a patient's details change; merge duplicates. See Duplicates and merging.
RetentionRegularly review and delete records whose retention period has expired.

Access control

  • Separate users: Don't use shared accounts. Only then can you track who looked at or changed which record. See Adding users.
  • Least privilege: Coordinators usually don't need settings, export or bulk-delete permissions. See Roles and permissions.
  • Assigned records only: In larger teams, restrict users to the contacts and conversations assigned to them. See Restricting data access.
  • Two-factor authentication: Ask every user to turn on 2FA. See First login and account security.
  • Leavers: Deactivate or delete a user on the day they leave, and reassign their records to someone else.
  • Auditing: Track who changed what and when under Settings → Audit Logs. See Audit logs.

Patient requests

KVKK (Article 11) and the GDPR give patients rights over their data. How they map to the panel:

Patient requestWhat you do
"What data do you hold about me?" (access)Gather the contact record, conversation history and files in the patient folder; you can export the contact data. See Export and delete.
"Correct my details" (rectification)Update the fields on the contact record.
"Delete my data" (erasure / right to be forgotten)Delete the contact record, delete the files in the patient folder and remove them permanently from Trash too. For medical records with legal retention obligations, consult your legal adviser.
"Stop sending me marketing" (objection)Tag the contact (e.g. no-marketing), remove them from marketing lists and turn off channel communication preferences (DND).
"Send my data to another provider" (portability, GDPR)Export the contact data as a CSV and send it to the patient securely.

Important

Under KVKK, requests must be answered within 30 days at the latest; under the GDPR the general deadline is one month. Log every request and note who did what, and when.

Deleting data

  • To delete one person, open their contact record and delete it. When bulk deleting, always double-check the filter; the wrong filter can delete real patients too. See Bulk actions.
  • Deleting a contact doesn't automatically delete their files in Media Storage. Delete the patient folder separately.
  • Deleted media files stay in Trash for a set period; remove them from Trash for permanent deletion.
  • Make sure only authorised people can delete.

Exporting data

  • You can export contact lists as CSV. See Export and delete.
  • An exported file is a copy outside the panel: keep it in an encrypted folder, don't pass it around by email and delete it when you're done.
  • Give export permission to admins only.

Patients abroad and data transfers

European patients' data is processed on cloud infrastructure. In your privacy notice, state the purposes, the service providers involved and the countries where data may be processed. Work with your legal adviser on KVKK's cross-border transfer rules and the GDPR's international transfer requirements. For contract and data processing agreement requests, message our support team on WhatsApp.

Suspected data breach

If a file is sent to the wrong patient, a phone is lost or you suspect unauthorised access:

  1. Tell your manager immediately.
  2. If needed, change the user's password or deactivate the user.
  3. Use the audit logs to establish what happened.
  4. Assess notification obligations with your legal adviser (KVKK sets a short deadline for notifying the Board; under the GDPR it's 72 hours).
  5. Message our support team on WhatsApp.

Didn't solve your problem?

Ask the assistant or message our support team.

WhatsApp support