Privacy Policy and Data Protection Notice

Türkçe

Last updated: 8 August 2026

1. Who this notice is about

Ravelyn is AI-assisted patient communication and follow-up software that brings a dental clinic’s conversations with its patients — over WhatsApp, Instagram, Messenger, email and web chat — into one place.

This notice is written for two different readers and tries to serve both without confusing them: the CLINICS that use the software, and the PATIENTS who write to those clinics.

2. Who is responsible for what — and why the distinction matters

The DATA CONTROLLER for a patient’s message, phone number, name and treatment interest is the CLINIC the patient contacted. The clinic decides what data is kept, for how long, who may see it and when it is deleted.

For that data Ravelyn is a DATA PROCESSOR: it acts on the clinic’s instructions and on the clinic’s behalf. Ravelyn does not use this data for its own commercial purposes, does not sell it, does not process it for advertising, and does not share it between clinics.

Ravelyn is a controller in one narrow area only: clinic staff account details (name, email, role), session records, and technical records kept for security and fault diagnosis. Those records carry no patient content — see section 8 for why.

The practical consequence: a patient wishing to exercise rights over their own data should address the CLINIC first. If the clinic refers the request to us, we act on the clinic’s behalf and on its instructions.

3. What data is processed

The list below was derived from the fields the software actually stores; it is not a generic example list.

Data Where it comes from What for
Phone number, name, email address, social media user id The patient’s own message, or the clinic’s record Identifying the patient and being able to reply
Message content (text) Messages the patient writes and the clinic sends The conversation itself; producing an AI draft
Photo, audio, video, document Attachments the patient sends So the clinic can see them; NEVER given to the AI
Treatment interest, notes, pipeline stage, warmth score Clinic staff input and AI inference Patient follow-up
Appointment date and time Clinic or patient Appointment management and reminders
Outreach consent and its date The patient’s statement or the clinic’s record Not sending messages without consent
Language spoken Inferred from the message Replying in the right language
Clinic staff name, email, role, session record The clinic itself Authorisation and security

4. Artificial intelligence — what happens to your message

This is the most important part of this notice, which is why it sits near the front.

When a patient writes to a clinic, the TEXT of the message is sent to a third-party AI provider (Groq Inc., United States) so that a draft reply can be produced. Service and price information from the clinic’s knowledge base, and part of the earlier conversation with that patient, are sent as context.

What is NOT sent matters just as much: the patient’s PHOTOS, VOICE MESSAGES, VIDEOS and DOCUMENTS are never sent to the AI under any circumstances. A message containing media is not given to the AI at all; it goes straight to a human.

What the AI produces is a DRAFT. Whenever the draft does not clear the confidence threshold, or touches a subject requiring price or clinical information, the system does NOT send it — it is held for clinic staff approval. Staff can edit any draft, reject it, or silence the AI entirely for that patient.

The AI does not diagnose and does not recommend treatment. What it produces is a communication draft assembled from information the clinic supplied.

5. Who it is shared with

Each party below sees data only to the extent the service requires and only as much as its own function needs.

Party What it sees Where
Meta Platforms (WhatsApp, Instagram, Messenger) The messages themselves and sender/recipient identifiers Outside Türkiye
Groq Inc. Message text and conversation context — EXCLUDING media Outside Türkiye (USA)
Google (Calendar) Appointment date, time and title — if the clinic connects it Outside Türkiye
Email provider (SMTP/IMAP) Sent and received email, if the email channel is used Depends on the provider
Object storage (S3 compatible) Media files the patient sent [HOSTING REGION]
Hosting provider Database and application servers [HOSTING REGION]

6. Transfers outside Türkiye

As the table above shows, the service cannot work without transferring the patient’s message text outside Türkiye. Under Turkish data protection law (KVKK art. 9) this is a cross-border transfer.

Following the amendment made by Law No. 7499, in force since 1 June 2024, cross-border transfers follow a hierarchy: an adequacy decision first; failing that, appropriate safeguards (standard contractual clauses, binding corporate rules); and only failing those, incidental cases. The transition period for transfers relying on explicit consent ended on 1 September 2024.

The transfer in this service is NOT incidental: it is a systematic flow repeated for every patient message. Nor is there an adequacy decision covering the United States. The applicable safeguard is therefore the STANDARD CONTRACT published by the Turkish Data Protection Authority; it is signed with the recipient and notified to the Authority within five business days of signature.

[STANDARD CONTRACT STATUS: which recipients (Groq, Meta, Google) it has been signed with, and the notification dates]

Until that safeguard is in place, the service must not be used with real patient data. This sentence is here for accuracy rather than readability: consent obtained from a patient does not make a transfer lawful where the required safeguard is absent.

Clinics are also obliged to inform the patient about this transfer. Ravelyn does not collect consent directly from patients; it gives the clinic the means to record it.

7. How long it is kept

The CLINIC sets the retention period; Ravelyn does not delete data without the clinic’s instruction and does not choose to keep it longer than the clinic has determined.

When the relationship between the clinic and Ravelyn ends, the clinic’s data is deleted or returned within 30 days. That period is a window for the clinic to export its data; deletion at the end of it happens automatically and does not require a separate request.

Invoicing and accounting records are separate from that period: they are kept for as long as tax legislation requires. Those records are NOT patient data — they are the clinic’s commercial information.

Deleted notes are held marked for a period so they can be restored; at the end of that period they are permanently deleted.

Backups reflect a deletion request as soon as technically possible; because of the backup cycle this can take longer than for live data.

8. Security — and what we deliberately do NOT do

The following are verifiable properties of the software, not marketing claims.

9. Patient rights (KVKK art. 11)

Every patient has the right to learn whether their data is processed; to request information if it has been; to learn the purpose of processing and whether it is used accordingly; to know the third parties to whom it is transferred, in Türkiye or abroad; to request correction if it is incomplete or inaccurate; to request erasure or destruction; to request that such steps be notified to third parties the data was transferred to; to object to a result arising against them from analysis carried out solely by automated systems; and to claim compensation for damage arising from unlawful processing.

These rights are exercised against the CLINIC, which is the controller. Please address your request to the clinic you contacted; the clinic will involve us if it needs to.

10. Cookies

The clinic panel uses only the technical cookies needed to keep a session open. No advertising cookies, no third-party tracking cookies and no analytics trackers are used.

The chat bubble a clinic embeds on its website keeps a short-lived session key in the browser so the visitor’s conversation can continue.

11. Contact

For questions about how the software works: Ugur Dogan — ugur.do808@gmail.com

Address: Bağlaraltı Mahallesi 204. Sokak No:5, Yıldırım / Bursa, Türkiye

Data controllers’ registry (VERBİS): [VERBIS STATUS — the assessment below to be confirmed by a lawyer]. Assessment: the VERBİS obligation falls on data CONTROLLERS; for patient data the controller is the clinic. For the data we control ourselves (staff accounts) we are below both thresholds — fewer than 50 employees and an annual balance sheet under 100 million TRY.

For requests about their own data, a patient’s counterparty is the clinic they contacted (see sections 2 and 9).

12. Changes to this notice

When the text changes, the update date above changes with it. If an update materially changes how the service processes data, clinics are notified separately.