Gizlilik Politikası
Bu politika, BA Kayıt mobil uygulamasının klinik personeli tarafından kullanımını ve uygulama üzerinden işlenen verileri kapsar.
1. Bu belge kimi bağlar, roller nasıl ayrılır
BA Kayıt, diş kliniklerinin hasta before/after fotoğraflarını ve onam formlarını kendi bulut arşivlerine kaydetmelerini sağlayan bir işletmeden işletmeye (B2B) uygulamadır. Uygulamada hasta kaydı yoktur — hesaplar yalnızca klinik yönetimi tarafından davet sistemiyle açılır. Bu nedenle iki farklı veri ilişkisi vardır:
- Hasta verileri (fotoğraf, onam formu, vaka bilgisi) için: Hastanın kliniğe başvurusu ve tedavi ilişkisi esas alındığından klinik, 6698 sayılı Kişisel Verilerin Korunması Kanunu ("KVKK") uyarınca veri sorumlusudur. Titanesswork LLC, klinikle yaptığı abonelik sözleşmesi çerçevesinde bu verileri yalnızca kliniğin talimatıyla işleyen veri işleyendir — verileri kendi amaçları için kullanmaz, üçüncü kişilerle paylaşmaz, klinik talimatı dışında saklamaz.
- Klinik personeli hesap verileri (ad soyad, e-posta, kullanım kaydı) için: Bu veriler, uygulamanın işleyişi ve abonelik sözleşmesinin ifası amacıyla Titanesswork LLC tarafından idari amaçlarla da (hesap yönetimi, faturalama, destek, güvenlik) işlenir.
2. İşlenen veri kategorileri
| Kategori | Örnekler | Kaynak |
|---|---|---|
| Sağlık verisi (özel nitelikli, KVKK md. 6) | Hastaya ait ağız/diş fotoğrafları (before/after), vaka notları | Klinik personeli, uygulama üzerinden |
| Kimlik/iletişim bilgisi | Klinik personeli ad-soyad, e-posta, telefon; hasta adı/vaka eşleşmesi | Klinik personeli girişi |
| Onam kaydı | İmzalı Görsel İçerik Onam Formu görüntüsü, onam durumu (imzalı/aktif/geri çekilmiş), kapsam | Uygulama içi onam akışı |
| Kullanım verisi | Uygulama içi işlem kayıtları (kim, ne zaman, hangi işlemi yaptı — denetim kaydı) | Otomatik, sistem tarafından |
| Tanılama/çökme verisi | Çökme raporları, hata izleri | Sentry (bkz. madde 11) |
3. İşleme amaçları
- Hasta before/after fotoğraflarının ve onam formlarının klinik adına güvenli şekilde arşivlenmesi
- Onam durumunun vaka bazında izlenmesi ve onamsız vakaların yayın/paylaşım hattında yapısal olarak engellenmesi
- Klinik hesap ve kullanıcı yönetimi (davetle hesap açma, yetkilendirme)
- Her işlemin kişi bazında denetim kaydına alınması — hesap güvenliği ve hesap verilebilirliği amacıyla
- Teknik destek ve hata giderme
- Uygulamanın güvenliğinin sağlanması (yetkisiz erişimin tespiti ve önlenmesi)
4. Hukuki sebep
- Hasta sağlık verisinin işlenmesi: KVKK md. 6 — açık rıza. Rıza, klinik tarafından hasta ile imzalanan Görsel İçerik Onam Formu üzerinden alınır. Titanesswork, bu rızanın alınmasından değil; alınmış rızanın sistemde doğru yansıtılmasından ve onamsız içeriğin engellenmesinden sorumludur.
- Klinik personeli hesap verisinin işlenmesi: KVKK md. 5 — sözleşmenin kurulması ve ifası (klinik–Titanesswork abonelik sözleşmesi) ile meşru menfaat (hesap güvenliği, denetim kaydı).
5. Veri güvenliği önlemleri
- İletim güvenliği: Uygulama ile sunucu (
api.bakayit.com) arasındaki tüm trafik TLS ile şifrelenir. - Depolama güvenliği: Fotoğraflar ve dosyalar sunucu tarafında nesne depoda, durağan veri (at-rest) şifrelemesiyle saklanır.
- Erişim kontrolü: Her klinik kendi verisine izole erişir; klinik personeli yalnızca kendi klinik hesabının verilerini görür.
- Denetim kaydı: Fotoğraf, onam ve vaka üzerindeki her işlem, işlemi yapan kişiyle birlikte kayıt altına alınır.
- Kimlik doğrulama: Uygulamaya giriş yetkilendirme kontrolünden geçer; hatalı giriş denemelerine karşı hız sınırlaması uygulanır.
- Olay müdahalesi: Kişisel veri güvenliğini etkileyen bir olay tespit edilirse ilgili klinik gecikmeksizin bilgilendirilir; klinik, veri sorumlusu sıfatıyla mevzuattan doğan bildirim yükümlülüklerini yerine getirir.
6. Onam geri çekme ve içerik kaldırma
Hasta, kliniğe verdiği görsel içerik onamını istediği zaman, gerekçe göstermeksizin geri çekebilir. Geri çekme talebi klinik aracılığıyla iletilir. Onam geri çekildiğinde:
- Onam durumu sistemde "geri çekildi" olarak işaretlenir ve bu andan itibaren ilgili görsel için yeni hiçbir paylaşım veya yayın yapılmaz; sistem onamsız ve geri çekilmiş içeriği yayın hattında yapısal olarak engeller.
- Daha önce yayınlanmış içerik varsa, ilgili mecralardan makul bir süre içinde — en geç 30 gün — kaldırılması için klinikle birlikte hareket edilir.
7. Saklama süresi
- Klinik aboneliği süresince veriler klinik adına saklanır.
- Abonelik sona erdiğinde saklama ve imha, klinik ile yapılan abonelik sözleşmesindeki saklama/imha hükümlerine göre yürütülür.
- Onam formu ve onam durum kayıtları, ispat yükümlülüğü nedeniyle ayrı bir saklama süresine tabi olabilir.
8. Veri lokasyonu ve yurt dışı aktarım
- Ana uygulama verisi (fotoğraf, onam kaydı, vaka bilgisi, hesap verisi): Türkiye'de barındırılır. Bu veriler için yurt dışına aktarım yapılmaz.
- Çökme/tanılama verisi: Uygulamanın çökme raporları Sentry'nin Avrupa Birliği (Almanya) altyapısına iletilir. Bu, KVKK md. 9 kapsamında bir yurt dışı aktarımdır ve teknik hata verisiyle sınırlıdır.
- Bildirim (push) altyapısı: Uygulama bildirimleri Apple ve Google'ın bildirim altyapıları üzerinden iletilir. Bu kapsamda cihaz bildirim kimliği (token) ilgili sağlayıcıya iletilir; bildirim içeriğine hasta sağlık verisi konulmaz.
9. Hasta hakları (KVKK md. 11)
Hasta, kişisel verileriyle ilgili KVKK md. 11 kapsamındaki haklarını kullanmak için önce kliniğe (veri sorumlusu sıfatıyla) başvurur. Klinik, BA Kayıt üzerinden Titanesswork'e ilettiği taleple ilgili teknik desteği alır. Talep edilebilecek haklar: verilerin işlenip işlenmediğini öğrenme, işleme amacını öğrenme, aktarıldığı üçüncü kişileri bilme, eksik veya yanlış işlenmişse düzeltilmesini isteme, silinmesini ya da yok edilmesini isteme, bu işlemlerin aktarılan üçüncü kişilere bildirilmesini isteme, otomatik analiz sonucu aleyhe bir durum oluşmasına itiraz etme, kanuna aykırı işleme nedeniyle zarara uğranmışsa tazminat talep etme.
10. Uygulama izinleri (cihaz düzeyinde)
BA Kayıt aşağıdaki cihaz izinlerini yalnızca belirtilen amaçla ister:
- Kamera: Hasta vaka fotoğraflarının çekilmesi için.
- Fotoğraf kitaplığı (okuma): Mevcut klinik fotoğraflarının içe aktarılması için.
- Fotoğraf kitaplığı (yazma): Kullanıcı filigranlı dışa aktarma seçerse, işlenmiş fotoğrafın cihaz galerisine kaydedilmesi için.
- Mikrofon: Yalnızca klinik personeli vaka videosu çektiğinde.
- Face ID: Uygulamaya güvenli erişim için. Biyometrik veri cihaz üzerinde işlenir, sunucuya gönderilmez.
11. Üçüncü taraf işleyiciler
| Taraf | Amaç | Veri | Bölge |
|---|---|---|---|
| Sunucu barındırma | Uygulama verisinin depolanması | Tüm uygulama verisi (fotoğraf, onam, vaka, hesap) | Türkiye |
| Sentry | Çökme ve hata raporlama | Teknik hata verisi, cihaz/işletim sistemi bilgisi | AB (Almanya) |
| Apple / Google | Bildirim (push) iletimi | Cihaz bildirim kimliği | Sağlayıcı altyapısı |
İzleme (tracking) yapılmaz. BA Kayıt reklam amaçlı izleme yapmaz; uygulamada reklam ağı, reklam kimliği (IDFA) kullanımı veya pazarlama analitiği SDK'sı bulunmaz. Uygulama, App Tracking Transparency izni istemez.
12. Çocuklara ait veriler
Diş klinikleri reşit olmayan hastalara da hizmet verebilir. Bu durumda görsel içerik onamının veli veya vasi tarafından verilmesi gerekir; onam kaydı bu esasa göre tutulur. Reşit olmayan hastalara ait sağlık verisinin işlenmesinde KVKK'nın küçüklere ilişkin ek koruma hükümleri geçerlidir.
13. Politika değişiklikleri
Bu politika güncellendiğinde, güncel sürüm bakayit.com/gizlilik.html adresinde yayınlanır ve yukarıdaki "son güncelleme" tarihi değiştirilir. Önemli değişikliklerde klinik hesabı üzerinden bilgilendirme yapılır.
14. İletişim ve künye
Titanesswork LLC (ürün sahibi)
1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, Amerika Birleşik Devletleri
E-posta: apps@titanesswork.com
Yasemin Neslihan Yaşar — şahıs işletmesi (Türkiye operasyonları ve faturalama)
Sarıyer Vergi Dairesi Müdürlüğü · İstanbul, Türkiye
E-posta: apps@titanesswork.com
Privacy Policy
This policy covers use of the BA Kayıt mobile app by clinic staff and the data processed through it. In case of any discrepancy, the Turkish text above prevails.
1. Who this document binds, and how roles are separated
BA Kayıt is a business-to-business (B2B) app that lets dental clinics capture patient before/after photos and consent forms into their own cloud archive. There is no patient registration in the app — accounts are provisioned only by clinic administrators through an invite system. This creates two distinct data relationships:
- For patient data (photos, consent forms, case records): Because the relationship is between the patient and the clinic, the clinic is the data controller under Turkish Law No. 6698 on the Protection of Personal Data ("KVKK"). Titanesswork LLC processes this data solely on the clinic's instructions, under the subscription agreement, as data processor — it does not use the data for its own purposes, does not share it with third parties, and does not retain it beyond the clinic's instructions.
- For clinic staff account data (name, email, usage logs): This data is also processed by Titanesswork LLC for administrative purposes (account management, billing, support, security) required to operate the app and perform the subscription agreement.
2. Categories of data processed
| Category | Examples | Source |
|---|---|---|
| Health data (special category, KVKK Art. 6) | Patient oral/dental before-after photos, case notes | Clinic staff, via the app |
| Identity/contact data | Clinic staff name, email, phone; patient name to case mapping | Entered by clinic staff |
| Consent record | Image of the signed visual content consent form, consent status (signed/active/revoked), scope | In-app consent flow |
| Usage data | In-app action records (who did what, and when — audit log) | Automatic, by the system |
| Diagnostics/crash data | Crash reports, error traces | Sentry (see section 11) |
3. Purposes of processing
- Securely archiving patient before/after photos and consent forms on behalf of the clinic
- Tracking consent status per case and structurally blocking cases without valid consent from the publication/sharing pipeline
- Clinic account and user management (invite-based provisioning, authorisation)
- Recording every action in a per-user audit log, for account security and accountability
- Technical support and troubleshooting
- Securing the app (detecting and preventing unauthorised access)
4. Legal basis
- Patient health data: KVKK Art. 6 — explicit consent, obtained by the clinic from the patient through a signed visual content consent form. Titanesswork is not responsible for obtaining that consent, but for reflecting it accurately in the system and blocking content that lacks it.
- Clinic staff account data: KVKK Art. 5 — performance of a contract (the clinic–Titanesswork subscription agreement) and legitimate interest (account security, audit logging).
5. Security measures
- In transit: All traffic between the app and the server (
api.bakayit.com) is encrypted with TLS. - At rest: Photos and files are stored in object storage with at-rest encryption.
- Access control: Each clinic accesses only its own data; tenant isolation is enforced server-side.
- Audit logging: Every action on a photo, consent record or case is logged together with the acting user.
- Authentication: Sign-in is subject to authorisation checks, with rate limiting against repeated failed attempts.
- Incident response: If an event affecting personal data security is detected, the affected clinic is notified without undue delay; the clinic, as data controller, fulfils its statutory notification duties.
6. Consent withdrawal and content takedown
A patient may withdraw their visual content consent at any time, without giving a reason. The request is submitted through the clinic. Upon withdrawal:
- The consent status is marked "revoked" in the system, and from that moment no new sharing or publication takes place for the affected images; the system structurally blocks content without valid consent.
- If content was previously published, we act together with the clinic to have it removed from the relevant channels within a reasonable period — no later than 30 days.
7. Retention
- Data is retained on behalf of the clinic for the duration of the subscription.
- After the subscription ends, retention and deletion follow the retention/destruction terms of the clinic's subscription agreement.
- Consent forms and consent status records may be subject to a separate retention period for evidentiary purposes.
8. Data location and international transfers
- Core application data (photos, consent records, case data, account data) is hosted in Türkiye. This data is not transferred abroad.
- Crash/diagnostic data: Crash reports are sent to Sentry's European Union (Germany) infrastructure. This constitutes an international transfer under KVKK Art. 9 and is limited to technical error data.
- Push notification infrastructure: Notifications are delivered through Apple's and Google's notification infrastructure. The device notification token is transmitted to the relevant provider; notification payloads do not contain patient health data.
9. Patient rights (KVKK Art. 11)
To exercise rights under KVKK Art. 11, the patient applies first to the clinic, which is the data controller for patient data. The clinic receives technical support from Titanesswork for the request submitted through BA Kayıt.
10. Device permissions
- Camera: to capture patient case photos.
- Photo library (read): to import existing clinic photos.
- Photo library (write): only when the user chooses watermarked export, to save the processed photo to the device gallery.
- Microphone: only when clinic staff record a case video.
- Face ID: for secure access to the app. Biometric data is processed on-device and never sent to the server.
11. Third-party processors
| Party | Purpose | Data | Region |
|---|---|---|---|
| Server hosting | Storage of application data | All application data (photos, consent, cases, accounts) | Türkiye |
| Sentry | Crash and error reporting | Technical error data, device/OS information | EU (Germany) |
| Apple / Google | Push notification delivery | Device notification token | Provider infrastructure |
No tracking. BA Kayıt does not perform advertising-related tracking; the app contains no ad network, no advertising identifier (IDFA) usage and no marketing analytics SDK. The app does not request App Tracking Transparency permission.
12. Children's data
Dental clinics may treat patients who are minors. In such cases the visual content consent must be given by a parent or legal guardian, and the consent record is kept on that basis. Additional protections under KVKK for minors apply.
13. Changes to this policy
When this policy is updated, the current version is published at bakayit.com/gizlilik.html and the "last updated" date above is revised. Clinics are notified of material changes through their clinic account.
14. Contact and legal entities
Titanesswork LLC (product owner)
1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, United States
Email: apps@titanesswork.com
Yasemin Neslihan Yaşar — sole proprietorship (Türkiye operations and invoicing)
Sarıyer Tax Office · Istanbul, Türkiye
Email: apps@titanesswork.com