Who we are
Asklepi is operated by ASKLEPION SAGLIK TEKNOLOJILERI TICARET ANONIM SIRKETI, a company registered in [COUNTRY] with company/registration number [NUMBER] and registered address at İTOB OSB MAH. 10032 SK. NO: 2 MENDERES/ İZMİR ("Asklepi", "we", "us" or "our").
For data-protection purposes, ASKLEPION SAGLIK TEKNOLOJILERI TICARET ANONIM SIRKETI is the data controller responsible for the personal data described in this policy, unless another notice says otherwise.
- Privacy contact: privacy@asklepi.com
- Data protection contact or DPO, if appointed: [NAME/EMAIL]
- Türkiye VERBİS registration details, if applicable: [DETAILS]
- EU representative, when required: [NAME/ADDRESS/EMAIL]
Scope
This policy applies to the Asklepi mobile application, asklepi.com, related products and services, and communications with us. A separate notice may apply where a healthcare provider uses Asklepi in connection with your care. In that situation, the provider may be an independent data controller and should explain its own use of your information.
Information we collect
Depending on the features you choose to use, we may collect:
Account and profile information
Your name, email address, phone number, date of birth or age range, profile settings, language, country, authentication identifiers, subscription status and communication preferences.
Health and wellbeing information
Information you provide about symptoms, medications, reminders, diagnoses, treatments, allergies, health goals, daily check-ins, stress or wellbeing scores, lifestyle, reproductive and sexual health, menstrual cycles, fertility, pregnancy, menopause, post-operative care and other health-related information. Health information is sensitive personal data. We only process it where we have a valid legal basis and, where required, your explicit consent or another applicable legal condition.
Lab results and documents
Documents, images and files you upload, including laboratory reports and the information extracted or generated from them. Please upload only documents relating to you, or information you are lawfully authorised to provide.
AI assistant information
Your questions, messages, chat history, feedback, uploaded content, tool actions, conversation summaries and structured facts derived from your interactions. We may combine these with information from your account—such as recent lab results, symptoms, medications or connected-device data—to provide the feature you requested.
Wearables, devices and communications
If you connect Apple Health, Health Connect or another supported service, we receive only the categories you authorise. We may also collect device and app version, operating system, language, approximate location derived from IP address, timestamps, feature interactions, crash reports, performance diagnostics, security events, consent records, support messages and survey responses.
Payment information
Purchases may be processed by an app store or payment provider. We receive transaction identifiers, subscription status and limited billing information, but generally do not receive full payment-card details.
How we use your information
We use personal information to create and secure your account; provide requested features including tracking, reminders, document processing, personalised context and AI-assisted responses; synchronise connected services; send enabled service notifications; process subscriptions; provide support; detect abuse, fraud and security incidents; improve reliability with minimised or de-identified data; comply with law; and send permitted marketing communications subject to your choices.
We do not sell personal information or health information. We do not use health information for third-party advertising, data-broker activity, credit, employment or insurance decisions.
Our legal bases
The legal basis depends on where you live and the purpose of processing.
| Purpose | Typical legal basis |
|---|---|
| Account, requested features and subscriptions | Performance of our contract with you |
| Health and other sensitive data used for personalised features | Explicit consent, unless another condition permitted by law applies |
| Security and essential diagnostics | Legitimate interests and/or legal obligations |
| Required records | Compliance with legal obligations |
| Optional analytics or marketing | Consent where required; otherwise legitimate interests subject to your rights |
Under Türkiye’s Law No. 6698 on the Protection of Personal Data (KVKK), we process personal data under the applicable conditions in Articles 5 and 6. We provide an information notice separately from any explicit-consent request.
AI-assisted features and automated processing
Asklepi uses artificial intelligence to organise information, retrieve relevant context and generate responses. AI output may be inaccurate, incomplete or unsuitable for your circumstances. It is informational and is not a diagnosis, prescription or substitute for a qualified healthcare professional.
We aim to send AI providers only the minimum context needed for the feature you request. Authorised personnel access production health data only where necessary and subject to access controls and audit records. We do not permit model providers to use your health information to train general-purpose models where our provider terms and technical controls allow us to prevent this.
When we share information
We may share information with cloud, database and storage providers; authentication providers including Google/Firebase; AI and machine-learning providers; document, notification, analytics, monitoring, support and payment providers; healthcare providers or people you choose; professional advisers and authorities where lawful; and a buyer or successor in a merger, financing, reorganisation or sale.
Providers may process information only for agreed purposes and under contractual privacy and security obligations. A current list of material subprocessors and processing locations will be published at [SUBPROCESSOR URL].
International transfers
Some providers may process information outside Türkiye, the European Economic Area or your country of residence. Where required, we use an approved transfer mechanism and supplementary safeguards, such as an adequacy decision, standard contractual clauses, Türkiye’s standard contracts or another method permitted by applicable law.
Retention
We keep information only for as long as needed for the purposes described above, taking account of legal, safety, contractual and dispute-resolution requirements.
- Active account, health records, chats and uploaded documents: while the account is active and until deletion is requested.
- Deleted content: removed from active systems promptly; encrypted backups expire within [30–90 days], unless legal retention applies.
- Closed account: delete or irreversibly de-identify within [30 days], subject to required records and backups.
- Security and audit logs: [6–12 months], with health information redacted by default.
- Support records: [2 years] after resolution unless a longer period is needed for a dispute.
Security
We use administrative, technical and organisational safeguards designed for the sensitivity of health data. These include encryption in transit and at rest, least-privilege access, environment separation, access reviews, audit logging, secrets management, secure development practices, monitoring, backups and incident response.
No service can guarantee absolute security. Contact security@asklepi.com if you suspect unauthorised access.
Your choices and rights
Subject to applicable law, you may have rights to access, correct, delete, restrict or object to processing, withdraw consent, receive portable information, object to direct marketing, learn about recipients and transfers, challenge certain solely automated decisions, and complain to a data-protection authority.
Use in-product controls where available or email privacy@asklepi.com. In Türkiye, you may exercise the rights set out in Article 11 of the KVKK. In the EEA, you may contact the supervisory authority in your country of residence, work or the alleged infringement.
Cookies and similar technologies
Our website and app may use technologies necessary for authentication, security, preferences and service operation. We will request consent before non-essential analytics or advertising technologies where required. Details and controls should be provided in a separate Cookie Notice and consent manager.
Children
Asklepi is not intended for children under [AGE TO CONFIRM BY MARKET] to create and use independently. If you believe a child has provided information without appropriate authorisation, contact privacy@asklepi.com.
Changes to this policy
We may update this policy as the service, law or our processing changes. We will publish the updated version and revise the “Last updated” date. If a change materially affects your rights or how we use sensitive information, we will provide additional notice and seek consent where required.
Contact and complaints
ASKLEPION SAGLIK TEKNOLOJILERI TICARET ANONIM SIRKETI
İTOB OSB MAH. 10032 SK. NO: 2 MENDERES/ İZMİR
privacy@asklepi.com
Türkiye: Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu), kvkk.gov.tr