Privacy Policy
In effect from 2026-09-13.
privacy_policy · v1.1.1 · en · 2026-09-13
Who this policy is about
Medix is a clinic operating system operated by Baran Akkanat, an individual (the "Service Operator"). Medix is run by a natural person rather than a company, so the data controller named in this policy is that individual and not an organisation. This policy explains what the Service Operator does with personal data.
Two different relationships are covered, and the difference decides who to contact about what. For data about clinics and the people who work in them, the Service Operator is the data controller. For patient data held inside a clinic's workspace, the clinic is the controller and the Service Operator is a processor acting on that clinic's instructions. A patient exercising their rights should contact their clinic, which holds the relationship and makes the decisions; the Service Operator provides the technical means and assists the clinic.
What is processed
- Account data
- The name, email address, role and language of each person with a Medix account, plus authentication records and sign-in history. Each account and each clinic also has an internal identifier used to scope every request.
- Clinic data
- The organisation's own details: locations, working hours, staff roster, subscription status and configuration.
- Patient records
- Identity and contact details, date of birth, appointments, clinical notes, medical history, procedures, consents and clinical photographs. This is health data and is treated as a special category throughout. A clinical note is free text, so it may also contain other special-category information a clinician records in the course of care.
- Messages
- The content and delivery status of messages exchanged with patients over the channels a clinic has connected.
- Calendar data
- Appointment times, and — only where a clinic or user has chosen to share more than availability — the details attached to those appointments.
- Device identifiers
- When notifications are enabled on a phone, the push token the operating system issues for that installation, so a notification can be delivered to it. It identifies an app installation rather than a person, and it is deleted with the session and with the account.
- Operational data
- Audit logs, security events, rate-limiting counters and error diagnostics, kept so the service can be run, secured and investigated after an incident.
- Billing data
- Subscription and payment status. Card details are handled by the store that took the payment and are never seen or stored by Medix.
Why it is processed
- To provide the service the clinic subscribes to, which is the performance of a contract.
- To keep the service secure and to investigate misuse, which is a legitimate interest of the Service Operator and of every clinic using it.
- To meet legal obligations, including record-keeping and responding to lawful requests.
- Patient health data is processed on behalf of the clinic, under the clinic's own lawful basis for providing healthcare.
Personal data is not sold, is not used for advertising, is not used to track anyone across other companies' apps or websites, and is not used to train machine-learning models.
How it is protected
- Encrypted in transit, and encrypted at rest by the hosting, database and storage providers named below.
- Clinical notes, medical history, message bodies and third-party access tokens are additionally encrypted by Medix itself before they are stored, using AES-256-GCM.
- Every request is authorised on the server against the clinic it belongs to; a workspace cannot read another workspace's data.
- Access is limited by role, so staff see what their role requires rather than everything.
- Actions on patient data are written to an audit log that the application cannot edit.
Medix has not undergone an independent security audit or certification, and this policy makes no such claim.
Who else is involved
The Service Operator uses the following sub-processors. Each receives only what its function requires, and none is permitted to use the data for its own purposes.
- Google Cloud (Cloud Run)
- Application hosting and delivery. The production service runs in Google's europe-west3 region, in Frankfurt, Germany.
- Google Cloud Storage
- Object storage for clinical photographs and uploaded files, in a private bucket with no public addresses; files are served only through authorised, expiring links.
- Neon
- The managed PostgreSQL database where clinic and patient records are stored.
- Resend
- Transactional email, such as invitations, password resets and account notices.
- Google (Calendar API)
- Calendar synchronisation, for users who connect a Google calendar. Appointment times always; appointment details only where the clinic or user has chosen to share them.
- Apple
- Subscriptions bought inside the iOS app, and notifications sent to iOS devices. See the two sections below for what each involves.
Providers that appeared in earlier versions of this policy are not listed because they receive nothing today. Medix has no payment processor of its own, no SMS or WhatsApp message transport, and no crash-reporting service configured in production. If any of these is enabled in future it will be named here in a new version of this policy before it begins to receive data.
These providers are established outside Türkiye, and the hosting, database and storage services are operated in the European Union. Where personal data reaches them it is handled under the data processing terms each provider publishes and which apply to the Service Operator's use of that service. No agreement negotiated specifically for Medix has been entered into with any of them, and this policy does not claim one.
Calendar connections
Connecting an external calendar is optional and is chosen per person and per calendar. Three settings are available: no connection at all; sharing only that a period is busy, with no details; or sharing appointment details. The setting chosen decides exactly what leaves Medix, and choosing to share details means appointment information is sent to the calendar provider.
Calendars held on an Apple device are read on that device, and only after iOS has asked for permission and the person has granted it. The feature is optional: Medix remains usable if permission is refused or later withdrawn. Events read from a device calendar are used to work out availability, and the details of a private event are not shown to anyone who is not entitled to see them.
If the person chooses a destination calendar on the device, Medix also writes into it: for each appointment it creates an event that reserves the time, updates that event when the appointment moves, and deletes it when the appointment is cancelled. What Medix writes is deliberately minimal. It carries a generic title, a start and an end, and marks the time as busy — no patient name, no procedure, no clinical note, no phone number, no email address, no appointment status and no location. Anyone else who can see that calendar learns only that the time is taken.
Medix does not alter events it did not create, and reading a device calendar does not send those events to the Service Operator: what leaves the device is a busy-time projection, plus titles only for calendars whose owner chose to share them. The record linking an appointment to the event it created is kept in the device's own storage and is never sent to the Service Operator.
Subscriptions bought on Apple devices
A subscription bought inside the iOS app is sold by Apple, not by the Service Operator. Apple takes the payment and holds the payment details; no card number reaches Medix. What Medix receives is a signed record of the transaction, which the server checks against Apple's own certificate before it grants access, and further signed notices from Apple when the subscription renews, lapses, is refunded or changes. These carry the identifiers of the product and the transaction, not a name or a payment instrument.
A purchase is tied to the clinic that made it by an opaque identifier generated for that purpose, so entitlement can be restored without Apple being told who the customer is. A subscription is managed and cancelled in the Apple account that bought it; deleting a Medix account does not cancel it.
Notifications sent to a phone
If notifications are enabled, Medix asks Apple's Push Notification service to deliver them to that installation, using the push token described above. The notification is written to say that something needs attention without disclosing who it concerns or why, so that a message passing through Apple's delivery infrastructure and appearing on a lock screen carries no patient information.
How long it is kept
Retention periods for patient records, clinical photographs and audit logs are set by each clinic, which is the party that knows what its own professional and legal obligations require.
When a record reaches the end of its retention period Medix notifies the clinic rather than deleting it automatically. Destroying a medical record is a decision for the clinic, not for a scheduled job. Audit records are retained as an integrity measure for the period the clinic configures.
Your rights
Under the GDPR, the Turkish KVKK and comparable law, individuals have rights over their personal data.
- To know what is held and to obtain a copy of it.
- To have inaccurate data corrected.
- To have data erased, where no legal obligation requires it to be kept.
- To restrict or object to certain processing.
- To receive data in a portable form.
- To complain to a supervisory authority.
Patients should direct requests to the clinic holding their record, which is the controller. Clinic staff and account holders can contact the Service Operator directly at hello@medix.healthcare. An account can also be deleted from within Medix, and from the account-deletion page published for that purpose.
Data breaches
If a breach affecting personal data occurs, the Service Operator investigates, contains it, and notifies affected clinics without undue delay so that they can meet their own notification obligations, which under the GDPR and the KVKK are generally 72 hours.
Changes to this document
A change is published as a new version with its own effective date. Acceptance of one version is not acceptance of another, and an earlier version remains readable for as long as anyone has accepted it.
Contact
The data controller for clinic and staff data, and the processor for patient data, is Baran Akkanat, an individual, operating Medix in a personal capacity. There is no company, no company registration number and no MERSİS number, because no legal entity exists. Under KVKK the veri sorumlusu is that named individual.
Postal address: 06420 Çankaya, Ankara, Türkiye.
Privacy and data-protection enquiries: hello@medix.healthcare. Support: support@medix.healthcare.
Previous published versions are available in the legal document archive.