Guides

Personal data on WhatsApp for clinics: what to watch in patient messaging

Updated:

The moment a patient types "hello", the clinic starts processing personal data. This article explains what Turkey's data protection law (Law No. 6698) expects from a conversation, and how MedorAI meets it. It is not legal advice and does not replace your own adviser.

What data a conversation holds

The phone number, the name and the message itself are personal data. "My tooth hurts" or "I want my nose done" is health information, which the law treats as a special category. An ordinary-looking chat therefore carries one of the clinic's most sensitive data sets.

The clinic is the data controller. The software that runs the conversation and the providers beneath it are processors; responsibility does not change with who speaks in the clinic's name.

The notice is given in the first message

The law requires patients to be informed before personal data is collected. In a conversation there is only one place for that: the first reply. This is why MedorAI's first reply is fixed: a welcome in the clinic's name, a link to "how your personal data is handled", and one question. The clinic may write its own welcome, but the notice line cannot be removed.

This line is not a request for consent. The data of a patient writing to book an appointment is processed to form the contract; the patient is never asked to say "I agree", and no consent phrasing is used in any language.

Minimum data: name, treatment, time

Three things are enough for an appointment: a name, a treatment and a time. The phone number arrives with the message and is never asked for. ID number, medical history, insurance details and date of birth are never requested; if a patient volunteers them, MedorAI leaves the matter to the doctor.

A treatment name is health information. MedorAI writes it into the appointment note only if the patient agreed, and the agreement itself is recorded: time, channel, the version of the consent text. The message text is not kept. If the patient declines, the treatment is discussed but not written into the appointment.

How long it is kept

The conversation is not permanent. When it closes, the message contents are deleted; a conversation silent for 24 hours closes by itself. The appointment record is deleted 30 days after the appointment. In long-term records the patient's number is kept only as an irreversible digest; that is how a returning patient is recognised without the number ever being read.

A patient can ask for their data to be deleted, and can do so inside the conversation. If the clinic leaves, all of the clinic's data is deleted.

Transfers abroad

Replies are generated by an AI provider, and that provider may be abroad. The package sent to the model contains neither the patient's name nor their number: the name is replaced by a placeholder and put back when the reply returns. The legal basis is the standard contract under Article 9 of the law; the details are in the privacy notice.

A clinic may want to mention this transfer in its own notice. Which providers are in which country is listed by name in MedoraLab's own notice, and a clinic can quote from it.

What the team has to do

Do not share screenshots: the moment an image of a patient conversation leaves the clinic, it is out of control. Do not message patients from a personal phone; write from the panel. In the panel every bubble shows who wrote it, so there is no later argument about who said what.

The support team cannot see the patient's name, number or messages in the clinic's panel; it sees only settings and figures. Every action taken in support mode is recorded in the clinic's panel.

What this article does not say

It gives no guarantee of compliance. Every clinic has its own notice, its own registration duties and its own adviser; this article explains how the messaging layer is built, and the rest is for the clinic's adviser to assess.