Skip to content

Privacy

Clear, limited processing for account data.

This notice explains what the early-access registration flow collects, why it is used and who to contact about your rights.

Controller and contact

The Stokontrol early-access registration flow is operated by Doğuş Sevinç. Privacy and personal-data requests can be sent to info@stokontrol.com.

Data and purpose

Full name, clinic or laboratory name, work email, optional phone, selected workspace type, language preference, optional referral code and account-security data are used to create the early-access workspace, route setup, apply any referral benefit, verify identity, provide support, prevent abuse and protect the account. If you continue with Google, the account identifier, email and basic profile information supplied by Google are also received for these purposes. Passwords are not shown to the support team in plain text.

Collection and basis

Data is collected electronically through the registration form. Processing is limited to the account request and establishment or operation of the service relationship, applicable legal duties and legitimate interests in essential security. If a separate consent is required, it will be requested independently; this notice is not consent.

Service-provider groups

Data may be shared, only as necessary to operate and secure the service, with authentication, cloud-hosting, email and technical-support providers. Regional availability and any required transfer safeguards are confirmed separately before commercial activation; this page does not promise an unverified country or transfer status.

Retention and rights

Registration data is kept while the account is active and for the period required by security or applicable legal duties. You may ask whether and why data is processed, request information about recipients, correction, deletion or destruction where conditions apply, notification of those changes to recipients, object to an adverse result produced solely by automated analysis, and seek compensation for unlawful processing. Use the application procedure below to exercise these rights.

Application procedure and response time

You may write to info@stokontrol.com from the email address previously notified to and registered with your early-access account. State your full name, relationship with Stokontrol, the specific request under Article 11 of Turkish Law No. 6698 and your response address; proof of authority is required when acting for another person. Identity is checked only as necessary to match the request securely; do not send a password, card data or unnecessary health information. A procedurally valid request is concluded as soon as possible and no later than 30 days, according to its nature; where processing creates an additional cost, only the tariff set by the Turkish authority may apply. A verified physical application address and any KEP address will be published before clinical or commercial activation; unverified channels are not invented.

Roles for clinical data

The clinic is controller where it determines purposes, lawful basis, access and retention for patients and staff. The Stokontrol operator processes clinic data on the clinic's documented instructions. Stokontrol may separately be controller for limited account security, support, legal duties and consented product measurement. The Data Processing Terms describe the detailed allocation.

Clinical and special-category data

Once a clinical workspace is activated, data may include patient identity and contact, birth and address, appointments, dental charts, diagnosis- or treatment-related records, allergies, chronic conditions, medicines, blood group, images, documents, lab jobs, communication preferences and finance summaries. Health data is specially protected; a notice, explicit consent, treatment consent and marketing preference are separate evidence.

Verified patient message replies

If the clinic enables the SMS or WhatsApp reply inbox, Stokontrol processes the sender number, message text, channel, provider message identifier and time received through a signed Twilio or Meta webhook to match the reply to exactly one active patient in that clinic and present it for human review. The raw reply copy in the Stokontrol application database is retained for 90 days from provider receipt and erased by the first daily cleanup after that boundary; this 90-day boundary does not erase copies held in Twilio or Meta systems. Provider-side message, log and backup copies are subject to the provider settings, contract and subprocessor retention terms verified by the clinic before activation. Intent, channel, last four digits, opaque provider reference, time and handling evidence remain subject to the clinic's wider verified retention or erasure policy. An authorised permanent patient or clinic deletion removes linked reply records in Stokontrol; provider-side deletion is handled separately under the relevant provider terms and verified account settings. Only explicit STOP equivalents or a signed Twilio OptOutType=STOP signal withdraw communication consent; bare RET is a free reply and bare İPTAL is an appointment-cancellation request for human review, and neither changes an appointment or consent automatically.

Public questions and product feedback

If public question submission is enabled, Stokontrol processes the email, category, raw title and question, locale, request identifier and timestamps to verify the email, prevent abuse, review the question in private moderation and publish only a reviewed card stripped of personal data. Cloudflare Turnstile processes client IP address, TLS fingerprint, User-Agent, sitekey and origin plus browser-security signals to distinguish bots; it does not receive form entries. Resend processes the recipient email and the message containing the single-use verification link; the verified stokontrol.com sender routes and sends email from Tokyo (ap-northeast-1), but that choice does not change data residency and account metadata, logs and API records are stored in the United States under the provider's terms. The link expires after 30 minutes; an unverified record is deleted by the next daily cleanup after a 24-hour grace period. Verification immediately erases the encrypted email envelope, email and submission-edge HMACs, and token digest; separate rate-limit digests are removed by daily cleanup after their two-hour or two-day expiry. A pending raw question is scrubbed after at most 90 days; published, privately answered, rejected or withdrawn raw questions are scrubbed after at most 30 days. The sanitized public card and moderation evidence remain until a reviewed withdrawal or retention decision. Submission stays off until the applicable lawful basis, provider contract, region/transfer safeguard, sender domain and retention evidence are verified; this notice is not consent.

Academy, protected viewing and certificate verification

If Academy is enabled, Stokontrol may process the account and profile identifier, programme and event, educator/training provider, order and payment state, amount and currency, opaque provider payment identifiers, referral attribution, the confirmed certificate name, attendance and viewing times, device/IP/User-Agent HMAC digests, short session leases and production-readiness checks. Card number and CVV are not stored by Stokontrol, and patient health data must not be entered into Academy purchase or playback. These records evidence payment and entitlement, enforce one active viewing and the 24-hour start boundary, prevent abuse, investigate technical failure, produce the live-training certificate issued by the training provider and calculate only the first eligible live referral reward. Every issued private PDF contains a QR linked to an unguessable certificate code and a short human-readable verification fingerprint; the QR always checks the certificate's current registry state, revocation or replacement with data minimisation. Without separate public-verification consent, the public response contains no name, programme, educator, training provider, event date or issue time; it may show only anonymous minimum registry state, certificate number and revision, and non-sensitive short fingerprints. With separate masked-name consent, a masked name and the disclosed training summary are visible for the programme's stated period. A full name appears on the same QR page only when the programme has an approved new versioned full-name notice and the attendee separately, explicitly and freely opts into that notice; a legacy masked-name choice is never treated as full-name consent. Declining consent does not affect live attendance or the private PDF. Withdrawal or expiry closes personal and training details while preserving the certificate and private PDF; the QR continues to show the current anonymous registry state, including revocation or replacement. The verified-participant directory is a separate consent from every QR visibility choice; declining or withdrawing it does not affect the certificate, and no professional title is inferred from a name or profile. The rate-limit HMAC lasts 15 minutes. The playback/payment provider's own IP, device, media-request, log and retention terms are disclosed separately. Academy sale and playback remain closed until the exact retention, erasure, provider, region and transfer notice is versioned and approved before checkout.

Subprocessors, regions and transfers

The current Subprocessors page identifies an active provider, purpose, data category, region and applicable international-transfer mechanism. Supabase, Vercel, Google, Resend, Twilio, Meta, OpenAI or regional payment and fulfilment parties are used only when the relevant feature is enabled. Real clinical processing does not open with unverified operator identity, hosting region or transfer safeguards.

Retention, export and activation

Marking a patient passive is not deletion. Verified contract annexes state retention, legal hold, export, deletion or anonymisation periods. Clinical activation requires an authorised workspace representative to accept the current service and processing terms with their versions and digests, and verification of operator, region and subprocessor evidence. Do not use real patient data before that activation.