This policy explains how GetClinic Ltd handles personal data in the GetClinic clinic portal at app.getclinic.com and in the GetClinic Clinic Portal mobile app for iOS and Android.
It is written for clinic owners, administrators, doctors and staff who hold a portal account. If you are a patient using GetClinic to find or book treatment, the policy that applies to you is at getclinic.com/privacy.
Who is responsible for your data
Two different relationships run through the same product, and they are worth separating:
- Your own account data. GetClinic is the data controller. We decide what we collect to run the portal, and this policy governs it.
- Patient records you enter. Your clinic is the data controller and GetClinic is a processor acting on your instructions. We handle that data to provide the service, under the agreement between your clinic and GetClinic — we do not use it for our own purposes, and we do not sell it.
What we collect
- Account and identity. Name, work email, phone number, job role, and the clinic or organisation you belong to. Sign-in is handled by our identity provider; we hold the resulting session, not your password.
- Clinic and business data. Clinic profile, doctors, treatment packages, pricing, availability, documents, subscription and billing records.
- Patient and enquiry data you enter or receive. Patient names and contact details, enquiries, bookings, appointments, messages, and any files or clinical documents you attach. This is your clinic's data, held on your behalf.
- Content you create in the app. Photos and files you choose to attach from your device, and messages you send through the portal.
- Video consultation media. When you join a consultation, camera and microphone audio and video are transmitted between the participants to carry the call. The app does not record consultations.
- Device and technical data. Device model, operating system, app version, language, IP address, crash reports and diagnostic logs.
- Usage data. Which screens you open and which actions you take in the app, used in aggregate to understand how the product is used.
- Push notification token. A device identifier issued by Apple or Google so we can deliver notifications about leads, messages and appointments.
We do not collect your location, your contacts, your calendar, or anything from your device beyond what is listed above. We do not use your data to train machine-learning models, and we never sell personal data.
Device permissions the app asks for
Every permission is requested at the moment the feature needs it, and the app remains usable without the optional ones:
- Camera and microphone — video consultations with patients, and screen sharing during a call when you start it.
- Photos and files — attaching images and documents to clinic content and patient records. We access only the items you pick.
- Notifications — alerts for new leads, messages, and upcoming appointments.
- Bluetooth — routing call audio to a headset or speaker. It is not used for location or proximity.
- Local network (iOS) — establishing a direct, low-latency connection for video calls.
Why we use it
- To give you access to your clinic's account and keep it secure.
- To deliver the features you use: leads, bookings, messaging, video consultations, documents and analytics.
- To take payments and manage your subscription.
- To send service communications — notifications, security alerts and changes to the product or this policy.
- To keep the platform working and safe: diagnosing crashes, preventing fraud and automated abuse, and enforcing our terms.
- To meet legal obligations, including tax, accounting and healthcare record-keeping requirements.
Where the GDPR or Turkey's KVKK applies, we rely on performance of our contract with your clinic, our legitimate interest in running and securing the platform, your consent for optional device permissions and analytics, and compliance with legal obligations.
Who we share it with
We share data with service providers who process it on our behalf, under contract, and only for the purposes above:
- Amazon Web Services — hosting and data storage, in the EU (Frankfurt) region.
- Google Firebase — push notifications, app integrity checks, and product analytics.
- Microsoft Clarity — anonymised usage analytics.
- Sentry — crash and error diagnostics.
- Stripe — subscription and payment processing. Card details go directly to Stripe; GetClinic never receives or stores your full card number.
- LaunchDarkly — feature rollout and configuration.
- LiveKit — real-time transport for video consultations.
We also disclose data where the law requires it, and to a successor entity in the event of a merger or acquisition — in which case this policy continues to apply until you are told otherwise.
Where your data is stored
Platform data is stored in the European Union, in Amazon Web Services' Frankfurt region. Some of the providers above process data outside the EU; where they do, transfers are covered by Standard Contractual Clauses or an equivalent safeguard.
How long we keep it
We keep your account data for as long as your clinic holds an active account, and afterwards only where a law requires it — financial and invoicing records in particular carry statutory retention periods. Diagnostic logs and analytics are kept for a short operational window and then discarded. Patient records are retained according to your clinic's instructions and the healthcare record-keeping rules that apply to you.
Your rights
Under the GDPR, the KVKK and comparable laws you may ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. You may also withdraw consent for anything you consented to, without affecting what came before.
Write to [email protected] and we will respond within 30 days. If a request concerns patient records your clinic controls, we will refer you to the clinic, which is the controller for that data.
If you are not satisfied with our response you can complain to your national data protection authority — in Turkey, the Kişisel Verileri Koruma Kurumu (KVKK).
Deleting your account
An administrator at your clinic can permanently delete a team member's account from the portal, under Team — this removes the sign-in account and the member's personal records. To delete your own account, or your clinic's entire account and its data, email [email protected] from your registered address. Records we are legally obliged to keep, such as invoices, are retained for the required period and then deleted.
Security
Data is encrypted in transit and at rest. Sign-in runs through a dedicated identity provider, session tokens are held in the operating system's secure storage on your device, and access to production systems is restricted and logged. Access to clinic data inside the product is limited by role, so staff see only what their role allows.
Children
The portal and the mobile app are professional tools for clinic staff. They are not directed at children and we do not knowingly create accounts for anyone under 18.
Changes to this policy
If we make a material change we will update the effective date above and notify account holders in the product or by email before it takes effect.
Contact us
- Email: [email protected]
- Post: GetClinic Ltd, DPO Office, Maslak Mahallesi, 34485 Istanbul, Turkey
- EU representative: GDPR.eu Compliance Services, Dublin