Back to Home

Data Processing Agreement

Veri İşleme Sözleşmesi

Effective / Yürürlük: June 28, 2026

English
Scope of this Agreement. These Data Processing Terms ("Agreement") apply automatically to all clinics and organisations ("Controller") that subscribe to the Hipocra platform. By accessing the platform, the Controller accepts these terms. Hipocra Health Technologies ("Processor") enters into this Agreement in its capacity as a data processor under KVKK Law No. 6698 and, where applicable, GDPR Article 28.

1. Definitions

  • "Controller" — the subscribing clinic that determines the purposes and means of processing personal data through the platform.
  • "Processor" — Hipocra Health Technologies, which processes personal data on behalf of the Controller.
  • "Platform" — the Hipocra CRM software and related services.
  • "Personal Data" — any information relating to an identified or identifiable natural person processed through the Platform.
  • "Special Category Data" — health and other data within the meaning of KVKK Article 6.
  • "KVKK" — Turkish Personal Data Protection Law No. 6698.

2. Subject Matter and Duration

This Agreement governs the Processor's processing of personal data on behalf of the Controller for the purpose of providing the Platform services. It remains in force for the duration of the Controller's active subscription and survives termination to the extent necessary to fulfil post-termination obligations (Section 8).

3. Categories of Personal Data and Data Subjects

Data subjects

  • Patients and prospective patients (leads) of the Controller
  • Clinic staff and administrators using the Platform

Categories of personal data

  • Standard data: Name, surname, date of birth, gender, contact details (email, phone, address), nationality
  • Special category (health) data: Medical history, diagnosis, treatment plans, consultation notes, procedures, medications — as entered by authorised clinic personnel
  • Account data: Platform roles, credentials (hashed), audit logs, session data

4. Controller's Obligations

  • Ensure a lawful basis exists for each category of personal data processed through the Platform, including obtaining valid patient consent where required by KVKK or applicable health law.
  • Maintain VERBIS registration where required under KVKK and applicable KVK Board decisions.
  • Provide patients with the data controller information and disclosures required by KVKK Article 10.
  • Configure the Platform's access controls and permissions in a manner appropriate to the sensitivity of the data processed.
  • Notify the Processor in writing of any restriction on processing or data subject rights exercise that the Processor must give effect to.

5. Processor's Obligations

5.1 Process Only on Instructions

The Processor will process personal data only on the documented instructions of the Controller — as set out in this Agreement, the Service Agreement, and the Platform's configurable settings. If applicable law requires the Processor to process data beyond those instructions, the Processor will inform the Controller before such processing (unless prohibited by law).

5.2 Confidentiality of Personnel

The Processor ensures that all personnel authorised to process Controller's personal data are bound by enforceable confidentiality obligations.

5.3 Security Measures

The Processor implements appropriate technical and organisational measures per KVKK Article 12, including:

  • Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls (RBAC) limiting data access to authorised users
  • Comprehensive audit logging of data access and modifications
  • Regular security assessments and vulnerability management
  • Logical separation of Controller data from other clients' data

5.4 Sub-Processors

The Controller grants general authorisation to the Processor to engage the sub-processors listed in Schedule A below. The Processor will:

  • Impose equivalent data protection obligations on sub-processors via binding agreements
  • Notify the Controller at least 30 days before adding a new sub-processor; the Controller may object in writing within 14 days
  • Remain liable to the Controller for sub-processor acts or omissions that breach this Agreement

5.5 Assistance with Data Subject Rights

The Processor will provide reasonable assistance to the Controller in responding to data subject rights requests under KVKK Article 11 (access, correction, deletion, objection) within timeframes that allow the Controller to meet its 30-day obligation.

5.6 Data Breach Notification

The Processor will notify the Controller without undue delay, and no later than 72 hours, upon becoming aware of a personal data breach affecting Controller's data. The notification will include, to the extent available: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.

5.7 Data Protection Impact Assessments

The Processor will provide reasonable assistance to the Controller when the Controller is required to conduct a Data Protection Impact Assessment under applicable law, to the extent such assessment relates to the Platform's processing activities.

5.8 Audit Rights

The Processor will provide the Controller with all information reasonably necessary to demonstrate compliance with this Agreement. The Processor will permit and contribute to audits or inspections conducted by the Controller or a mandated auditor, subject to at least 30 days' written notice and reasonable confidentiality arrangements.

5.9 Data Return and Deletion upon Termination

Within 30 days of termination of the Service Agreement, the Processor will, at the Controller's election: (a) return all personal data to the Controller in a machine-readable format, or (b) securely delete or destroy all personal data, and certify such deletion in writing. Anonymised or aggregated data from which the Controller's data cannot be reconstructed may be retained.

6. Schedule A — Approved Sub-Processors

Sub-ProcessorPurposeLocation
Supabase Inc.PostgreSQL database hosting, authentication, real-time servicesUSA (AWS)
Vercel Inc.Platform hosting, serverless functions, CDNUSA / Global Edge

7. International Data Transfers

Where sub-processors are located outside Turkey, the Processor relies on the safeguards available under KVKK Article 9 (adequacy decisions or appropriate safeguards as determined by the KVK Board) and, where applicable, Standard Contractual Clauses under GDPR. The Controller authorises such transfers subject to these safeguards.

8. Governing Law and Jurisdiction

This Agreement is governed by the laws of the Republic of Turkey. Any dispute arising under or in connection with this Agreement shall be subject to the exclusive jurisdiction of the courts of Istanbul, Turkey.

Applicable law: KVKK Law No. 6698 Art. 12 (security) Art. 8–9 (transfers) GDPR Art. 28 (where applicable)

Türkçe Versiyon
Türkçe
Sözleşmenin Kapsamı. Bu Veri İşleme Koşulları ("Sözleşme"), Hipocra platformuna abone olan tüm klinik ve kuruluşlara ("Veri Sorumlusu") otomatik olarak uygulanır. Platforma erişim sağlanmasıyla Veri Sorumlusu bu koşulları kabul etmiş sayılır. Hipocra Health Technologies ("Veri İşleyen"), 6698 Sayılı KVKK ve uygulanabildiği ölçüde GDPR Madde 28 kapsamında veri işleyen sıfatıyla bu Sözleşmeyi akdetmektedir.

1. Tanımlar

  • "Veri Sorumlusu" — Platform aracılığıyla kişisel verilerin işlenme amaçlarını ve yöntemlerini belirleyen abone klinik.
  • "Veri İşleyen" — Kişisel verileri Veri Sorumlusu adına işleyen Hipocra Health Technologies.
  • "Platform" — Hipocra CRM yazılımı ve ilgili hizmetler.
  • "Kişisel Veri" — Platform üzerinden işlenen, kimliği belirli veya belirlenebilir gerçek kişilere ilişkin her türlü bilgi.
  • "Özel Nitelikli Kişisel Veri" — KVKK Madde 6 kapsamındaki sağlık verileri ve diğer özel nitelikli veriler.
  • "KVKK" — 6698 Sayılı Kişisel Verilerin Korunması Kanunu.

2. Konu ve Süre

Bu Sözleşme, Veri İşleyen'in Platform hizmetlerini sunmak amacıyla Veri Sorumlusu adına kişisel verileri işlemesini düzenlemektedir. Veri Sorumlusu'nun aktif aboneliği süresince yürürlükte kalır ve sözleşme sonrası yükümlülüklerin (Bölüm 8) yerine getirilmesi için gerekli ölçüde fesihten sonra da geçerliliğini korur.

3. Kişisel Veri Kategorileri ve İlgili Kişiler

İlgili Kişiler

  • Veri Sorumlusu'nun hastaları ve potansiyel hastaları (adaylar)
  • Platformu kullanan klinik personeli ve yöneticileri

Kişisel Veri Kategorileri

  • Genel kişisel veriler: Ad, soyad, doğum tarihi, cinsiyet, iletişim bilgileri (e-posta, telefon, adres), uyruk
  • Özel nitelikli (sağlık) veriler: Tıbbi geçmiş, tanı, tedavi planları, konsültasyon notları, uygulanan işlemler, ilaçlar — yetkili klinik personeli tarafından sisteme girilen bilgiler
  • Hesap verileri: Platform rolleri, kimlik bilgileri (şifrelenmiş), denetim logları, oturum verileri

4. Veri Sorumlusu'nun Yükümlülükleri

  • Platform aracılığıyla işlenen her kişisel veri kategorisi için KVKK veya ilgili sağlık mevzuatının öngördüğü durumlarda hasta onayı alınması dahil, geçerli bir hukuki dayanak bulunmasını sağlamak.
  • KVKK ve ilgili Kurul kararları çerçevesinde zorunlu olan hallerde VERBİS kaydını yaptırmak ve güncel tutmak.
  • KVKK Madde 10 uyarınca hastalara veri sorumlusu bilgileri ve aydınlatma yükümlülüğü kapsamındaki bildirimleri yapmak.
  • Platform'un erişim kontrollerini ve izinlerini, işlenen verilerin hassasiyetiyle orantılı biçimde yapılandırmak.
  • Veri İşleyen'in uygulaması gereken herhangi bir işleme kısıtlamasını veya ilgili kişi hakkı kullanımını Veri İşleyen'e yazılı olarak bildirmek.

5. Veri İşleyen'in Yükümlülükleri

5.1 Yalnızca Talimatlara Göre İşleme

Veri İşleyen; kişisel verileri yalnızca bu Sözleşme'de, Hizmet Sözleşmesi'nde ve Platform'un yapılandırılabilir ayarlarında yer alan Veri Sorumlusu'nun belgelenmiş talimatları doğrultusunda işler. Uygulanabilir hukuk, söz konusu talimatların ötesinde bir işleme zorunlu kılıyorsa Veri İşleyen, bu işlemden önce Veri Sorumlusu'nu bilgilendirir (hukuken yasaklı olmadıkça).

5.2 Personelin Gizlilik Yükümlülüğü

Veri İşleyen, Veri Sorumlusu'na ait kişisel verileri işlemeye yetkili tüm personelin uygulanabilir gizlilik yükümlülükleriyle bağlı olmasını sağlar.

5.3 Güvenlik Tedbirleri

Veri İşleyen, KVKK Madde 12 kapsamında uygun teknik ve idari tedbirleri uygular:

  • İletim sırasında (TLS 1.2+) ve depolamada (AES-256) kişisel veri şifreleme
  • Veri erişimini yetkili kullanıcılarla sınırlayan rol tabanlı erişim kontrolü (RBAC)
  • Veri erişimi ve değişikliklerinin kapsamlı denetim kaydı
  • Düzenli güvenlik değerlendirmeleri ve güvenlik açığı yönetimi
  • Veri Sorumlusu'nun verilerinin diğer müşteri verilerinden mantıksal ayrımı

5.4 Alt İşleyenler

Veri Sorumlusu, Veri İşleyen'e aşağıdaki Ek A'da listelenen alt işleyenleri kullanmak için genel yetki vermektedir. Veri İşleyen:

  • Alt işleyenlere bağlayıcı sözleşmeler aracılığıyla eşdeğer veri koruma yükümlülükleri yükler
  • Yeni bir alt işleyen eklemeden en az 30 gün önce Veri Sorumlusu'nu bilgilendirir; Veri Sorumlusu 14 gün içinde yazılı itiraz hakkına sahiptir
  • Alt işleyen'in bu Sözleşmeyi ihlal eden eylem veya ihmalleri nedeniyle Veri Sorumlusu'na karşı sorumlu kalmaya devam eder

5.5 İlgili Kişi Haklarının Kullanımında Yardım

Veri İşleyen, Veri Sorumlusu'nun KVKK Madde 11 kapsamındaki ilgili kişi hakları taleplerine (erişim, düzeltme, silme, itiraz) yanıt verebilmesi için, Veri Sorumlusu'nun 30 günlük yükümlülüğünü karşılamasına olanak tanıyacak sürelerde makul yardımı sağlar.

5.6 Veri İhlali Bildirimi

Veri İşleyen, Veri Sorumlusu'na ait kişisel verileri etkileyen bir veri ihlalinden haberdar olduğunda, gereksiz gecikme olmaksızın ve en geç 72 saat içinde Veri Sorumlusu'nu bilgilendirir. Bildirimde mümkün olduğunca şunlar yer alır: ihlalin niteliği, etkilenen ilgili kişi kategorileri ve tahmini sayısı, olası sonuçlar ile alınan veya önerilen tedbirler.

5.7 Veri Koruma Etki Değerlendirmesi

Veri İşleyen, Veri Sorumlusu'nun uygulanabilir hukuk kapsamında bir Veri Koruma Etki Değerlendirmesi yürütmesi gerektiğinde, bu değerlendirmenin Platform'un işleme faaliyetleriyle ilgili kısmında makul ölçüde yardım sağlar.

5.8 Denetim Hakkı

Veri İşleyen, Veri Sorumlusu'na bu Sözleşmeye uyumu kanıtlamak için gerekli tüm makul bilgileri sağlar. Veri Sorumlusu veya yetkilendirdiği denetçi tarafından yürütülecek denetim veya incelemelere en az 30 günlük yazılı ihbar ve makul gizlilik düzenlemeleri çerçevesinde izin verir ve katkıda bulunur.

5.9 Sözleşme Sona Ermesinde Veri İadesi ve Silme

Hizmet Sözleşmesi'nin sona ermesinden itibaren 30 gün içinde Veri İşleyen, Veri Sorumlusu'nun tercihine bağlı olarak: (a) tüm kişisel verileri makine tarafından okunabilir formatta iade eder veya (b) tüm kişisel verileri güvenli biçimde siler ya da imha eder ve bunu yazılı olarak teyit eder. Veri Sorumlusu'nun verileri yeniden oluşturulamayacak şekilde anonimleştirilmiş veya toplanmış veriler saklanabilir.

6. Ek A — Onaylı Alt İşleyenler

Alt İşleyenAmaçKonum
Supabase Inc.PostgreSQL veritabanı barındırma, kimlik doğrulama, gerçek zamanlı hizmetlerABD (AWS)
Vercel Inc.Platform barındırma, sunucusuz fonksiyonlar, CDNABD / Global Edge

7. Yurt Dışı Veri Aktarımı

Alt işleyenlerin Türkiye dışında bulunduğu durumlarda Veri İşleyen, KVKK Madde 9 kapsamındaki güvencelere (Kurul tarafından belirlenen yeterlilik kararları veya uygun güvenceler) ve uygulanabildiği ölçüde GDPR Standart Sözleşme Maddelerine dayanır. Veri Sorumlusu, söz konusu güvenceler çerçevesinde bu aktarımlara onay vermektedir.

8. Uygulanacak Hukuk ve Yetki

Bu Sözleşme, Türkiye Cumhuriyeti hukukuna tabidir. Sözleşmeden kaynaklanan veya bununla bağlantılı her türlü uyuşmazlık, İstanbul Mahkemeleri'nin münhasır yargı yetkisine tabidir.

Uygulanabilir mevzuat: KVKK Kanun No. 6698 Madde 12 (güvenlik) Madde 8–9 (aktarım)