1. Data Controller
This privacy notice has been prepared by Moserra Software in its capacity as data controller, pursuant to Art. 10 of the Personal Data Protection Law No. 6698 (“KVKK”) and Art. 4 of the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform. Datapa is a brand operated by Moserra Software.
You can contact the data controller at info@moserra.com or by telephone at +90 850 340 0880. Further information on the identity of the data controller is provided in the Service Provider section at the end of this page.
2. Scope of This Notice — and Its Limits Regarding Patient Data
This notice applies to visitors of datapa.net and to health tourism company, agency, hospital, clinic or physician who open a Datapa account. In this context, Moserra Software is the data controller only with respect to personal data relating to its own customer accounts, subscriptions and payments, support correspondence and site traffic.
Patient data are not within the scope of this notice. Moserra Software provides software services only. With respect to the personal data of the patient served by the health tourism company, agency, hospital, clinic or physician using the Datapa service — including measurements, plans and health data —, the data controller is the relevant health tourism company, agency, hospital, clinic or physician, which determines the purposes and means of processing such data. With respect to such data, Moserra Software is solely a data processor acting on its behalf and on its instructions; it does not access such data except for providing the service and technical support, does not use them for its own purposes, does not sell them to third parties and does not process them for profiling or advertising purposes. The terms of this relationship are set out in the Service Agreement.
With respect to such data, fulfilling the obligation to inform under Art. 10 of the KVKK, determining the legal ground for processing under Art. 5 and Art. 6 and obtaining explicit consent where necessary rest with the relevant health tourism company, agency, hospital, clinic or physician in its capacity as data controller. Health data are special categories of personal data within the meaning of Art. 6 of the KVKK; ensuring that such data are processed only where one of the conditions listed in Art. 6/3 exists and with the adequate measures determined by the Board having been taken is also an obligation of the data controller. In its capacity as data processor, Moserra Software takes, jointly with the data controller, the necessary technical and organisational measures for the security of such data pursuant to Art. 12/2 of the KVKK (see §8).
If you are a patient and have a request regarding your data, you need to contact the health tourism company, agency, hospital, clinic or physician providing services to you. If such a request reaches us, we forward it to the relevant data controller.
3. Categories of Personal Data Processed
Your account-related data are processed only when you open an account, use the service or write to us of your own free will, and only to the extent you choose to share them. Transaction security and traffic data are generated automatically while you use the site and the service. Cookie and usage-analytics data are collected only if you give your consent via the cookie banner.
- Identity data: first and last name.
- Contact data: e-mail address and, if provided, phone number.
- Account and authentication data: the unique user identifier from your sign-in provider, e-mail, and profile name if any.
- Professional and business data: business name, country/city, working hours, and logo or profile photo if provided.
- Subscription and usage data: subscription status, usage activity, billing records.
- Request and correspondence content: the content of your support requests and messages, and our replies.
- Transaction security and traffic data: IP address, transaction date/time, session records, error logs.
- Cookie and usage-analytics data: cookie identifiers, IP address, page interaction.
No special categories of personal data relating to you (the health tourism company, agency, hospital, clinic or physician) are processed in this context. The health data in the system belong to the patient and, as explained in §2, the data controller for such data is the health tourism company, agency, hospital, clinic or physician.
4. Purposes of Processing and Legal Grounds
| Data category | Purpose of processing | Legal ground (KVKK Art. 5) |
|---|---|---|
| Identity data | Creating your account and recognising your identity | Art. 5/2-c: necessary for the establishment or performance of a contract |
| Contact data | Communicating with you about the service | Art. 5/2-c: necessary for the establishment or performance of a contract |
| Account and authentication data | Verifying your identity and securing access to your account | Art. 5/2-c: necessary for the establishment or performance of a contract |
| Professional and business data | Operating the panel with your own information | Art. 5/2-c: necessary for the establishment or performance of a contract |
| Subscription and usage data | Managing the subscription, billing, and statutory bookkeeping | Art. 5/2-c and Art. 5/2-a: expressly provided for by law (tax/commerce) |
| Request and correspondence content | Handling and keeping a record of support requests | Art. 5/2-f: legitimate interest |
| Transaction security and traffic data | System security, detection of misuse, and troubleshooting | Art. 5/2-f legitimate interest and Art. 5/2-ç legal obligation |
| Cookie and usage-analytics data | Visit statistics and advertising measurement | Art. 5/1: explicit consent — only when granted via the cookie banner |
With respect to processing based on explicit consent, you may withdraw your consent at any time; withdrawal does not affect the lawfulness of the processing carried out until then and has effect for the future.
5. Method of Collection
On the basis of the legal grounds set out in §4, your data are collected electronically: when you open an account, directly through your own input when you use the service, when you create a support request, and automatically through server logs, as well as through cookies if you give your consent.
6. Transfers
We do not sell your personal data. Transfers are made for the operation of the service and for compliance with legal obligations and, only with your explicit consent, for site analytics and measurement, within the following limits:
- Cloudflare (Cloudflare, Inc.) (abroad): delivery and protection of the site and panel content so the service is secure and accessible (traffic passes through this infrastructure). Legal ground: KVKK Art. 5/2-f (legitimate interest).
- WhatsApp (optional messaging module) (abroad — only if you use the feature): delivery of messages if the optional messaging module is used. Legal ground: KVKK Art. 5/2-c (using the module is not mandatory).
- Meta Platforms (Lead Ads and Conversions API) (abroad — only if you use the feature): receiving lead-form data from Meta ads and, if the User enables it, reporting conversion events back to Meta. Legal ground: KVKK Art. 5/2-c (using the integration is the User’s choice).
- Google Ads (Google LLC/Google Ireland) (abroad — only if you use the feature): advertising conversion measurement. Legal ground: KVKK Art. 5/1: explicit consent (processing); the transfer is subject to KVKK Art. 9 — only if consent is given via the cookie banner.
- Yandex Metrika (Yandex) (abroad — only if you use the feature): visit statistics. Legal ground: KVKK Art. 5/1: explicit consent (processing); the transfer is subject to KVKK Art. 9 — only if consent is given via the cookie banner.
- Meta Pixel (Meta Platforms) (abroad — only if you use the feature): advertising measurement and conversion matching. Legal ground: KVKK Art. 5/1: explicit consent (processing); the transfer is subject to KVKK Art. 9 — only if consent is given via the cookie banner.
- Competent public institutions and organisations: to authorities legally entitled to request information, after the lawfulness of the request has been examined and only to the extent requested (Art. 8 together with Art. 5/2-a and Art. 5/2-ç of the KVKK).
The legal ground stated above for each recipient relates to the processing of the data (Art. 5 of the KVKK). Transfers to recipients located abroad are additionally subject to Art. 9 of the KVKK as amended by Law No. 7499: they are based on an adequacy decision issued by the Personal Data Protection Board regarding the country, sectors within the country or international organisation concerned, where such a decision exists, or, in its absence, on one of the appropriate safeguards listed in Art. 9/4 (e.g. a standard contract announced by the Board; a standard contract is notified to the Personal Data Protection Authority within five business days of its signature). With respect to transfers abroad, explicit consent can be used as a condition for transfer only for incidental transfers that are not regular (Art. 9/6).
Except as listed above, your data are not transferred abroad. If we start using a new service that would require a transfer abroad, this notice will be updated in advance.
7. Retention Period
Data relating to your account are retained for as long as your account remains open. If you close your account, your data are deleted or anonymised to the extent that no legal ground requiring their retention remains. Invoice, payment and accounting records are retained for the period prescribed by tax and commercial legislation (as a rule, ten years), and security and traffic logs for the period prescribed by the relevant legislation. Data obtained from cookies are retained for the lifetime of the cookie concerned; if you withdraw your consent, data collection stops with effect for the future. The retention and deletion of patient data are subject to the instructions of the health tourism company, agency, hospital, clinic or physician.
When the retention periods expire or the grounds for processing cease to exist, your personal data are deleted, destroyed or anonymised, ex officio or upon your request, in accordance with Art. 7 of the KVKK and the Regulation on the Deletion, Destruction or Anonymisation of Personal Data.
8. Data Security
Pursuant to Art. 12 of the KVKK, the data controller takes the technical and organisational measures necessary to ensure an appropriate level of security in order to prevent the unlawful processing of personal data and unlawful access to personal data, and to ensure their safekeeping. The main measures applied in this respect are: TLS encryption in transit; Regular backups; Access limited to what the role requires.
If the personal data processed are obtained by others through unlawful means, this is notified to the data subjects concerned and to the Personal Data Protection Board as soon as possible, pursuant to Art. 12/5 of the KVKK.
These measures also apply to the patient data processed on behalf of the health tourism company, agency, hospital, clinic or physician in our capacity as data processor (Art. 12/2 of the KVKK).
9. Rights of the Data Subject (KVKK Art. 11)
Pursuant to Art. 11 of the KVKK, you may exercise the following rights by applying to the data controller:
- To learn whether your personal data are processed and, if so, to request information about it.
- To learn the purpose of the processing and whether the data are used for their intended purpose.
- To know the third parties to whom the data are transferred in Türkiye or abroad.
- To request the rectification of incomplete or inaccurately processed data.
- To request erasure or destruction within the framework of the conditions set out in Art. 7 of the KVKK.
- To request that rectification, erasure and destruction operations be notified to the third parties to whom the data have been transferred.
- To object to a result to your detriment arising from the analysis of the processed data exclusively through automated systems.
- To claim compensation for damages if you suffer damage as a result of unlawful processing.
Pursuant to Art. 13 of the KVKK and the Communiqué on the Procedures and Principles for Application to the Data Controller, you may submit your requests concerning your rights by one of the following means:
- by sending an e-mail signed with your secure electronic signature or mobile signature to info@moserra.com;
- by writing to info@moserra.com from the e-mail address you have previously notified to us and that is registered in our system.
Your application must contain your first name and surname and, if the application is made in writing, your signature; if you are a citizen of the Republic of Türkiye, your Turkish identity number, or otherwise your nationality and passport number or, if any, your identity number; your place of residence or business address for service; your e-mail address for notifications, if any, and your telephone number; and the subject of your request. Information and documents relating to the matter must be attached to the application.
Your request is concluded free of charge as soon as possible depending on its nature and, in any event, within 30 days at the latest. If the processing of the request entails an additional cost, a fee may be charged in accordance with the tariff set by the Board. If your application is rejected, you find the response insufficient or no response is given in due time, you may lodge a complaint with the Personal Data Protection Board within 30 days of learning of the response and, in any event, within 60 days of the date of application (Art. 14 of the KVKK). An application to the data controller is mandatory before filing a complaint with the Board.
10. Updates to This Notice
This notice is updated when our processing activities change. The current version is always published on this page, and the last updated date is shown at the top.
Service Provider
Legal name
Moserra Software
Address
İstanbul, Türkiye
Phone
+90 850 340 0880