Allis Health

Privacy Policy and Data Protection Notice

This notice fulfils the duty to inform under Article 10 of the Turkish Personal Data Protection Law (KVKK) for personal data processed through the Allis Health mobile app and clinician panel.

DRAFT. This text is awaiting legal review and approval; its content may change before publication.

Version: 1.0 · Effective: __YURURLUK_TARIHI__

1. Data controller

The controller of your data is Allis Bilişim Teknolojileri Anonim Şirketi. You may send any request described in this notice to destek@alisbt.com.

2. Personal data we process

Identity and contact data
Name, surname, date of birth, gender, nationality, national identification number, phone, e-mail and emergency contact details.
Health data — measurements
Heart rate, blood pressure, blood glucose, oxygen saturation, body temperature, weight, body mass index, body fat percentage, steps and calories.
Health data — clinical records
Conditions, medication, allergies, past surgery, vaccinations, medical history, laboratory tests and results, blood type, anxiety screening results, examinations and clinician recommendations.
Health data — nutrition
The nutrition plan assigned to you, its meals, and the items you report having consumed.
Appointment and communication records
Appointment requests and their status, the questions you ask your clinician and the answers you receive.
Device and notification data
A device identifier (push token) so notifications can be delivered, and your notification preferences. The device identifier is stored only while your explicit consent is in place.
Image data
Your profile photo, if you upload one. Embedded metadata (EXIF), including location, is stripped before the file is written to the server.
Audit records
Who accessed your data and when. Your IP address is not stored in raw form; it is irreversibly digested at the database boundary.
Health data is special category personal data. Under KVKK Art. 6 it is processed only with your explicit consent. Until you give consent the parts of the app that process health data stay closed, and no data is transferred from your device.

3. Purposes of processing

  • Letting you record, view and follow your health measurements.
  • Enabling authorised staff at the healthcare organisation you are connected to to provide your care, including nutrition plans, appointments and recommendations.
  • Creating and securing your account, and auditing that only authorised people access your data.
  • Delivering the notifications you have asked for.
  • Meeting legal obligations.

The legal basis for your clinician and health staff is the care relationship. Your data is not used for advertising or profiling and is never sold.

4. How data is collected

  • Information you enter in the app yourself.
  • With your explicit consent, device data transferred through the health services on your phone: Health Connect on Android and Apple Health on iPhone. Data from a connected smartwatch or band is read through those services.
  • Clinical records entered by clinicians and health staff at the organisation you are connected to.
  • Weight measurements read from a Bluetooth scale, if you use one.

When you join, the app may also import part of the measurement history already on your device. That import covers at most 365 days; anything older is not requested and is rejected server-side.

5. Recipients

  • The healthcare organisation you are connected to: only staff with an established care relationship with you. Leaving an organisation does not delete your data; it closes that organisation's access.
  • The platform administrator: for technical operation and support, with every access recorded in the audit log.
  • Processors: database, authentication and file storage infrastructure (Supabase); network and security infrastructure (Cloudflare); mobile notification infrastructure (Google — Firebase Cloud Messaging); iOS distribution and device health services (Apple).
  • Competent public authorities, where required by law.

6. International transfers

Because the servers and services of the infrastructure providers above may be located outside Turkey, your data may be transferred abroad within the meaning of KVKK Art. 9. The legal basis and scope of that transfer is __YURTDISI_AKTARIM_DAYANAGI__. Work to move the infrastructure into Turkey is in progress.

7. Retention and erasure

  • Your measurement and clinical data is kept while your account is open and your consent remains in place.
  • Heart rate detail is reduced after 40 days: second- and minute-level detail is irreversibly reduced to an hourly summary (average, minimum, maximum, sample count). The measurement itself, its period and the fact that it belongs to you are preserved; only the resolution decreases. The reason is that no clinical screen goes below hourly detail for data this old, and no more data than necessary should be kept (KVKK Art. 4).
  • Audit records are kept for 730 days (2 years) and are then deleted automatically. These records remain after your account is deleted: the trail of who accessed your data cannot be erased.
  • Backups are kept for at most 14 days and are destroyed when they expire. For a short period after deletion a record may still exist in a backup.

8. Security

  • Authorisation is enforced server-side at row level: which rows each role may see is defined in the database. Client-side checks are not relied upon.
  • Roles and least privilege: health staff have read-only access to critical data and cannot access the national identification number.
  • All traffic is transported encrypted (TLS).
  • Files (profile photo, organisation logo) are stored in private buckets; access is granted only through time-limited signed links.
  • Administrator and break-glass access is written to the audit log.

9. Your rights (KVKK Art. 11)

You have the right to learn whether your personal data is processed, to request information about it, to learn the purpose of processing, to know the recipients, to have inaccurate or incomplete data corrected, to request erasure or destruction (the right to be forgotten), to have corrections and erasures notified to recipients, to object where an automated analysis produces a result to your detriment, and to claim compensation for damage.

Send your requests to destek@alisbt.com. Under KVKK Art. 13 your request will be answered within 30 days at the latest.

10. Withdrawing consent and deleting your account

You may withdraw your explicit consent at any time. Withdrawal stops the processing of your health data and, in practice, is handled together with a request to delete your account and data.

You can start a deletion request from Account → Delete my account in the app or from this site. For the scope of deletion, which records are kept and how long it takes, see Account and data deletion.

11. Cookies

This website does not use cookies and does not measure visitors. Session information needed for the app to work is kept only on your device, in the secure storage provided by the operating system.

12. Changes to this notice

When this text is updated its version number is raised. If the notice and explicit consent text inside the app changes, you will be asked to approve the new version the next time you open the app.