Privacy Policy
Archived version, in effect from 2026-09-02. It may have been superseded.
privacy_policy · v1.0.0 · en · 2026-09-02
58fd841dff10c22a1d44fb23698b384f24e915a574f9dacbe329d74e1dabb9e7
Who this policy is about
Medix is a clinic operating system operated by Baran Akkanat, an individual (the "Service Operator"). Medix is run by a natural person rather than a company, so the data controller named in this policy is that individual and not an organisation. This policy explains what the Service Operator does with personal data.
Two different relationships are covered, and the difference decides who to contact about what. For data about clinics and the people who work in them, the Service Operator is the data controller. For patient data held inside a clinic's workspace, the clinic is the controller and the Service Operator is a processor acting on that clinic's instructions. A patient exercising their rights should contact their clinic, which holds the relationship and makes the decisions; the Service Operator provides the technical means and assists the clinic.
What is processed
- Account data
- The name, email address, role and language of each person with a Medix account, plus authentication records and sign-in history.
- Clinic data
- The organisation's own details: locations, working hours, staff roster, subscription status and configuration.
- Patient records
- Identity and contact details, date of birth, appointments, clinical notes, medical history, procedures, consents and clinical photographs. This is health data and is treated as a special category throughout.
- Messages
- The content and delivery status of messages exchanged with patients over the channels a clinic has connected.
- Calendar data
- Appointment times, and — only where a clinic or user has chosen to share more than availability — the details attached to those appointments.
- Operational data
- Audit logs, security events, rate-limiting counters and error diagnostics, kept so the service can be run, secured and investigated after an incident.
- Billing data
- Subscription and payment status. Card details are handled by the payment provider and are never stored by Medix.
Why it is processed
- To provide the service the clinic subscribes to, which is the performance of a contract.
- To keep the service secure and to investigate misuse, which is a legitimate interest of the Service Operator and of every clinic using it.
- To meet legal obligations, including record-keeping and responding to lawful requests.
- Patient health data is processed on behalf of the clinic, under the clinic's own lawful basis for providing healthcare.
Personal data is not sold, is not used for advertising, and is not used to train machine-learning models.
How it is protected
- Encrypted in transit, and encrypted at rest by the storage providers.
- Clinical notes, medical history, message bodies and third-party access tokens are additionally encrypted by Medix itself before they are stored, using AES-256-GCM.
- Every request is authorised on the server against the clinic it belongs to; a workspace cannot read another workspace's data.
- Access is limited by role, so staff see what their role requires rather than everything.
- Actions on patient data are written to an audit log that the application cannot edit.
Medix has not undergone an independent security audit or certification, and this policy makes no such claim.
Who else is involved
The Service Operator uses the following sub-processors. Each receives only what its function requires, and none is permitted to use the data for its own purposes.
- Vercel
- Application hosting and delivery.
- Neon
- The managed database where clinic and patient records are stored.
- Cloudflare R2
- Object storage for clinical photographs and uploaded files.
- Stripe
- Subscription billing for clinics paying on the web.
- Resend
- Transactional email, such as invitations and account notices.
- Twilio
- SMS and messaging delivery: patient phone numbers and message content.
- Meta (WhatsApp Cloud API)
- WhatsApp delivery for clinics using their own connection: patient phone numbers and message content.
- Google (Calendar API)
- Calendar synchronisation. Appointment times always; appointment details only where the clinic or user has chosen to share them.
- Apple
- In-app purchases made on iOS, and the resulting receipt.
- Google Play
- In-app purchases made on Android, and the resulting token.
- Sentry
- Error diagnostics, where configured. Reports are scrubbed before they are sent and are not intended to carry patient data.
Some of these providers operate outside the country where a clinic is established. Where data is transferred internationally it is protected by the transfer mechanisms available under applicable law, including standard contractual clauses with the provider concerned.
Calendar connections
Connecting an external calendar is optional and is chosen per person and per calendar. Three settings are available: no connection at all; sharing only that a period is busy, with no details; or sharing appointment details. The setting chosen decides exactly what leaves Medix, and choosing to share details means appointment information is sent to the calendar provider.
Calendars held on an Apple device are read on that device. Events read from a device calendar are used to work out availability, and the details of a private event are not shown to anyone who is not entitled to see them.
How long it is kept
Retention periods for patient records, clinical photographs and audit logs are set by each clinic, which is the party that knows what its own professional and legal obligations require.
When a record reaches the end of its retention period Medix notifies the clinic rather than deleting it automatically. Destroying a medical record is a decision for the clinic, not for a scheduled job. Audit records are retained as an integrity measure for the period the clinic configures.
Your rights
Under the GDPR, the Turkish KVKK and comparable law, individuals have rights over their personal data.
- To know what is held and to obtain a copy of it.
- To have inaccurate data corrected.
- To have data erased, where no legal obligation requires it to be kept.
- To restrict or object to certain processing.
- To receive data in a portable form.
- To complain to a supervisory authority.
Patients should direct requests to the clinic holding their record, which is the controller. Clinic staff and account holders can contact the Service Operator directly at hello@medix.healthcare. An account can also be deleted from within Medix, and from the account-deletion page published for that purpose.
Data breaches
If a breach affecting personal data occurs, the Service Operator investigates, contains it, and notifies affected clinics without undue delay so that they can meet their own notification obligations, which under the GDPR and the KVKK are generally 72 hours.
Changes to this document
A change is published as a new version with its own effective date. Acceptance of one version is not acceptance of another, and an earlier version remains readable for as long as anyone has accepted it.
Contact
The data controller for clinic and staff data, and the processor for patient data, is Baran Akkanat, an individual, operating Medix in a personal capacity. There is no company, no company registration number and no MERSİS number, because no legal entity exists. Under KVKK the veri sorumlusu is that named individual.
Postal address: 06420 Çankaya, Ankara, Türkiye.
Privacy and data-protection enquiries: hello@medix.healthcare. Support: support@medix.healthcare.