Privacy Policy

Version 1.2 · Published: October 2, 2026

This policy explains which personal data MedoraLab processes about its clinic customers, clinic staff and visitors to medoralab.com, for what purposes and on what legal grounds. Data belonging to clinics’ patients is described in the Data Protection Notice, and information stored in your browser in the Cookie Policy.

MedoraLab Yazılım Hizmetleri

Eren Kutay

Maslak Mah. Eski Büyükdere Cad. Giz 2000 Plaza No: 7 D: 34, 34485 Sarıyer/İstanbul

info@medoralab.com

Maslak Vergi Dairesi / 5990550580

Data controller

For the data described in this policy, the data controller is Eren Kutay (trading as “MedoraLab”). Address: Maslak Mah. Eski Büyükdere Cad. Giz 2000 Plaza No: 7 D: 34, 34485 Sarıyer/İstanbul. E-mail: info@medoralab.com.

For data belonging to clinics’ patients, the clinic is the data controller and MedoraLab is the data processor. That data is described in the Data Protection Notice and in the Data Processing Agreement made with the clinic.

What data we process

Demo form and Custom package application form: full name, clinic name, phone number, e-mail address, the specialties you are interested in, the settings you chose for the Custom package and your optional message.

Support form: your name, e-mail address, clinic name, subject and message. A request opened from the panel also carries the clinic, the user’s role and technical context (browser, application version); a screenshot is accepted only as a link.

Sign-up and billing: the clinic’s registered name, tax identification number and tax office, address, the authorised person’s name, e-mail address and phone number, and the website or Instagram address. Card details are stored by the payment institution; we hold only the card token issued by the payment institution and the last four digits of the card. The tax certificate requested for verification is sent only by e-mail and is not saved in the application.

Setup call: your name, e-mail address, phone number and the time you chose.

Panel users: name, e-mail address, role, an irreversible digest of the password and session records (device type, sign-in time and time of last use).

Agreement records: which version of which document was accepted or read, by whom, in which role and when, a digest of the accepted text and an irreversible digest of the IP address.

Security: an irreversible digest of the IP address, to limit failed sign-in attempts and abuse of the forms. The IP address itself is not stored.

Help bubble: the question you type is sent to the artificial intelligence provider to generate an answer and is not stored; a usage count and a digest of the IP address are kept to limit abuse.

Purposes and legal grounds

Responding to your demo request, Custom package application or support request: being directly related to the formation or performance of a contract (Article 5(2)(c) of the Law).

Opening and running the membership, taking payment, verifying access to the panel and holding the setup call: the formation and performance of a contract (Article 5(2)(c) of the Law).

Invoices and financial records: compliance with a legal obligation (Article 5(2)(ç) of the Law).

Keeping agreement acceptances as evidence: the establishment, exercise or protection of a right (Article 5(2)(e) of the Law).

Preventing abuse and keeping the service secure: our legitimate interest, provided that it does not harm your fundamental rights and freedoms (Article 5(2)(f) of the Law).

We do not ask for your explicit consent for the processing described in this policy, and we do not use your data to send marketing messages.

Access

Access is limited to the MedoraLab staff needed to run the service. The message contents, names and phone numbers of clinic patients cannot be viewed even during support: the panel has no button, setting or record that opens them to support staff.

Retention periods

Demo requests and Custom package applications: kept for at most 12 months where no commercial relationship follows, then deleted.

Support requests: kept for at most 12 months, then deleted.

Incomplete sign-up requests: deleted after 30 days. The sign-up request itself becomes unusable after 45 minutes.

Setup call records: deleted after 90 days.

Panel user records and agreement records: kept for as long as the clinic’s membership continues. An agreement record remains even if the account of the person who accepted it is deleted; it is deleted when the clinic account is permanently deleted.

Session records: kept for as long as the account exists; deleted through “Sign out on all devices” or when the account is deleted.

Failed sign-in attempts: deleted after 1 day.

Help bubble: the IP address digest is deleted after 24 hours and the usage counter after 90 days; the question you type is never stored.

Confirmation codes of data deletion requests received through Meta: deleted after 180 days.

Payment and invoice records: kept for the period required by financial legislation; if the clinic account is deleted, they are kept detached from the clinic.

Freezing and ending a clinic’s membership

A clinic does not freeze or cancel its membership itself; it opens a request from the Membership page in the panel, the help bubble, the WhatsApp support line or by e-mail. The request is resolved within 30 days at the latest.

A freeze lasts up to six months. During it the AI assistant and the messaging channels stop, the data stays in place and the panel is read-only. No fee is charged during the freeze; the remaining time of the paid period resumes where it left off when the freeze ends. When the period runs out, the membership moves to cancellation.

On cancellation the service continues to the end of the paid month on monthly billing, or of the paid period on yearly billing; the remaining time is not refunded. When the service ends, a link to download the clinic’s data as an Excel file is sent by e-mail, and the cancellation can be undone within 30 days; at the end of that period all records belonging to the clinic are permanently deleted.

A patient’s request to delete their own data is handled at once, even if the membership is frozen or cancelled.

Sub-processors and transfer abroad

We use the providers below to deliver the service. Each receives only the data needed for its own task; we do not sell your data to third parties or transfer it to them for marketing purposes.

As some of the providers are established in the United States, personal data may be transferred abroad under Article 9 of the Law. In this context, the standard contract process is being carried out with the sub-processors. The transfer is not based on explicit consent.

ProviderCountryUsed for
Anthropic, PBCUnited StatesArtificial intelligence model: the assistant that writes to patients, and the help bubble on the site and in the panel
Vercel Inc.United StatesHosting and running the application
Neon, LLC (Databricks, Inc.)United StatesDatabase
Plus Five Five, Inc. (Resend)United StatesSending the e-mails that go to clinics and to the operator; contains no patient data
Microsoft CorporationUnited StatesMailbox: demo, support and corporate correspondence, and clinic contact details; contains no patient data
iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş. (iyzico)TürkiyeTaking clinic payments and storing the card; contains no patient data
Meta (WhatsApp, Instagram)United StatesThe clinic’s own WhatsApp and Instagram account: patient messages come in and go out through this channel, which the clinic connects
Eleven Labs Inc. (ElevenLabs)United StatesVoice-over for promotional videos only; contains no patient data

If a clinic connects its own Google Calendar account, Google LLC (United States) also becomes a sub-processor, for that clinic alone.

What you write in the help bubble on the site and in the panel is sent to Anthropic to generate an answer and is not stored.

Your rights and how to apply

Under Article 11 of the Law you have the right to learn whether your personal data is processed; to request information about it if it has been processed; to learn the purpose of processing and whether the data is used in accordance with that purpose; to know the third parties in Türkiye or abroad to whom it is transferred; to request its correction if it has been processed incompletely or inaccurately; to request its erasure or destruction under the conditions in Article 7 of the Law; to request that these operations be notified to the third parties to whom the data has been transferred; to object to a result against you arising from analysis exclusively by automated systems; and to claim compensation for damage you suffer due to unlawful processing.

You can send your application by e-mail to info@medoralab.com or in writing to Maslak Mah. Eski Büyükdere Cad. Giz 2000 Plaza No: 7 D: 34, 34485 Sarıyer/İstanbul. We may ask for the information needed to verify your identity. Your request is concluded free of charge within 30 days at the latest.

If your application is rejected, you find the response inadequate or no response is given in time, you may lodge a complaint with the Personal Data Protection Board within 30 days of learning of the response and, in any event, within 60 days of the date of your application.

Contact

For privacy questions: info@medoralab.com

WhatsApp and Instagram account connections

When a clinic connects its WhatsApp Business or Instagram account to MedoraLab, we receive an access token, the account ID and the display name from Meta. The token is stored encrypted, used only to send and receive that clinic’s messages, and deleted when the connection is removed.

Data deletion requests that reach us through Meta are handled by the same process as a patient’s own “Please delete my data” request. Details are on the Data Deletion Instructions page: medoralab.com/en/veri-silme