Who we are
Asklepion is operated by ASKLEPION SAGLIK TEKNOLOJILERI TICARET ANONIM SIRKETI, registered at İTOB OSB MAH. 10032 SK. NO: 2 MENDERES/ İZMİR ("Asklepion", "we", "us" or "our").
For data-protection purposes, ASKLEPION SAGLIK TEKNOLOJILERI TICARET ANONIM SIRKETI is the data controller responsible for the personal data described in this policy, unless another notice says otherwise.
- Privacy: privacy@asklepi.com
- Türkiye VERBİS details, if applicable: [DETAILS]
- EU representative, when required: [NAME/ADDRESS/EMAIL]
Scope
This policy applies to asklepion.health, Asklepion products and services, the Asklepi mobile application where operated by us, and communications with us. A separate notice may apply where a healthcare provider uses a service in connection with your care.
Information we collect
Depending on the service and features you use, we may collect account and profile details, health and wellbeing information, laboratory documents, AI conversations and derived context, connected-service data, device and diagnostic information, support communications, consent records, and limited payment or subscription information.
Health information is sensitive personal data. We process it only where we have a valid legal basis and, where required, your explicit consent or another applicable legal condition.
How we use information
We use information to provide and secure our services, organise health information, support AI-assisted features, process documents, synchronise connected services, respond to support requests, detect abuse and security incidents, improve reliability with minimised or de-identified data, comply with law, and send permitted communications.
We do not sell personal information or health information, and do not use health information for third-party advertising, data-broker activity, credit, employment or insurance decisions.
Our legal bases
Depending on the purpose and your location, processing may be based on contract performance, explicit consent for sensitive health data, legitimate interests in security and service operation, legal obligations, or another basis permitted by applicable law.
Under Türkiye’s Law No. 6698 on the Protection of Personal Data (KVKK), we process personal data under the applicable conditions in Articles 5 and 6 and provide information separately from any explicit-consent request.
AI-assisted features
Our services may use artificial intelligence to organise information, retrieve relevant context and generate responses. AI output may be inaccurate, incomplete or unsuitable. It is informational and is not a diagnosis, prescription or substitute for a qualified healthcare professional.
We aim to send AI providers only the minimum context needed for a requested feature. We do not use identifiable health information to train a general-purpose AI model without separate transparency, a valid legal basis and any consent required by law.
When we share information
We may share information with cloud, storage, database, authentication, AI, document-processing, notification, monitoring, support and payment providers; healthcare providers or people you choose; professional advisers and authorities where lawful; and a buyer or successor in a transaction. Providers may process information only for agreed purposes and under contractual privacy and security obligations. A current subprocessor list will be published at [SUBPROCESSOR URL].
International transfers
Some providers may process information outside Türkiye, the EEA or your country of residence. Where required, we use an approved transfer mechanism and supplementary safeguards, such as an adequacy decision, standard contractual clauses, Türkiye’s standard contracts or another method permitted by law.
Retention
We keep information only as long as needed for the purposes described above, taking account of legal, safety, contractual and dispute-resolution requirements.
- Active accounts and health records: while the account is active and until deletion is requested.
- Deleted content: removed from active systems promptly; backups expire within [30–90 days].
- Closed accounts: delete or irreversibly de-identify within [30 days], subject to required records.
- Security logs: [6–12 months]; support records: [2 years].
Security
We use safeguards designed for the sensitivity of health data, including encryption in transit and at rest, least-privilege access, environment separation, access reviews, audit logging, secrets management, secure development practices, monitoring, backups and incident response. Contact security@asklepi.com if you suspect unauthorised access.
Your rights
Subject to applicable law, you may have rights to access, correct, delete, restrict or object to processing, withdraw consent, receive portable information, object to direct marketing, learn about recipients and transfers, challenge certain solely automated decisions, and complain to a data-protection authority. Contact privacy@asklepi.com. In Türkiye, you may exercise the rights set out in Article 11 of the KVKK.
Cookies and similar technologies
We may use technologies necessary for authentication, security, preferences and service operation. We will request consent before non-essential analytics or advertising technologies where required. Details should be provided in a separate Cookie Notice and consent manager.
Children
Our services are not intended for children under [AGE TO CONFIRM BY MARKET] to create and use independently. Contact privacy@asklepi.com if you believe a child has provided information without appropriate authorisation.
Changes to this policy
We may update this policy as our services, law or processing changes. We will publish the updated version and revise the “Last updated” date. Material changes will receive additional notice and consent where required.
Contact and complaints
ASKLEPION SAGLIK TEKNOLOJILERI TICARET ANONIM SIRKETI
İTOB OSB MAH. 10032 SK. NO: 2 MENDERES/ İZMİR
privacy@asklepi.com
Türkiye: Personal Data Protection Authority, kvkk.gov.tr