flowdesk

Gizlilik Politikası

Son güncelleme: 19 Temmuz 2026

Bu politika, flowdesk platformunu (flowdesksolutions.com ve app.flowdesksolutions.com) kullandığınızda kişisel verilerinizin nasıl işlendiğini açıklar. flowdesk hem 6698 sayılı KVKK'ya hem de AB Genel Veri Koruma Tüzüğü'ne (GDPR) uygun olacak şekilde tasarlanmıştır.

1. Veri Sorumlusu

Kişisel verileriniz, veri sorumlusu sıfatıyla Yağız Ertuğrul Kaya (flowdesk) tarafından işlenir.

2. İşlenen Kişisel Veriler

KategoriVeriler
Kimlik & iletişimAd-soyad, e-posta, telefon
Hesap & kullanımGiriş kimliği, rol, işlem kayıtları, IP adresi ve tarayıcı bilgisi (güvenlik günlüğü)
Özel nitelikli — sağlıkYalnızca klinik/sağlık modülünde: ölçüm, tanı, tedavi notları (KVKK md.6 / GDPR md.9)
FinansalTahsilat kaydı (tutar + yöntem). Kart verisi saklanmaz.

3. İşleme Amaçları ve Hukuki Dayanaklar

4. Verilerin Aktarımı ve Yurtdışı İşleme

flowdesk altyapısını, verileri Avrupa Birliği içinde (Frankfurt, Almanya) barındıran Supabase Inc. üzerinde çalıştırır; Supabase bu kapsamda veri işleyendir. Verilerin AB'de tutulması, AB kullanıcıları için en yüksek koruma düzeyini sağlar.

Türkiye'den erişen kullanıcılar bakımından bu, KVKK md.9 anlamında yurtdışına aktarım teşkil eder ve açık rızanıza dayanılarak yapılır. Bunun dışında verileriniz üçüncü kişilere pazarlama amacıyla satılmaz veya aktarılmaz.

5. Saklama Süresi

Kişisel verileriniz, işleme amacının gerektirdiği süre ve ilgili mevzuattaki (ör. mali kayıtlar için yasal saklama) süreler boyunca saklanır; süre sonunda silinir, yok edilir veya anonim hale getirilir.

6. Haklarınız

KVKK md.11 ve GDPR md.15–22 uyarınca; verilerinize erişme, düzeltme, silme ("unutulma"), taşınabilirlik (verilerinizi indirme), işlemeye itiraz ve rızayı geri alma haklarına sahipsiniz. Giriş yaptığınız hesabınızdan verilerinizi doğrudan indirebilir veya silme talebinde bulunabilirsiniz; ayrıca yukarıdaki e-postadan başvurabilirsiniz. Başvurularınız en geç 30 gün içinde sonuçlandırılır.

Ayrıca KVK Kurulu'na (Türkiye) veya bulunduğunuz AB üyesi ülkenin veri koruma otoritesine şikâyette bulunabilirsiniz.

7. Veri Güvenliği

flowdesk; satır-seviyesi erişim denetimi (RLS), rol-bazlı yetkilendirme, sağlık verisine denetim günlüğü ve şifreli bağlantı (HTTPS) dahil teknik ve idari tedbirler uygular. Sağlık verisine her erişim kaydedilir.

8. Çerezler

flowdesk yalnızca oturumun sürdürülmesi için zorunlu çerezler kullanır; reklam veya izleme çerezi kullanmaz. Ayrıntı: Çerez Politikası.

9. Değişiklikler

Bu politika güncellenebilir; güncel sürüm bu sayfada "son güncelleme" tarihiyle yayımlanır.

10. İletişim

Sorularınız için: yagizkaya43@gmail.com

Privacy Policy

Last updated: 19 July 2026

This policy explains how your personal data is processed when you use the flowdesk platform (flowdesksolutions.com and app.flowdesksolutions.com). flowdesk is designed to comply with both the EU General Data Protection Regulation (GDPR) and Turkey's Personal Data Protection Law (KVKK No. 6698).

1. Data Controller

Your personal data is processed by Yağız Ertuğrul Kaya (flowdesk) as data controller.

2. Personal Data We Process

CategoryData
Identity & contactName, email, phone
Account & usageLogin identifier, role, activity logs, IP address and browser info (security log)
Special category — healthOnly in the clinic/health module: measurements, diagnoses, treatment notes (GDPR Art. 9 / KVKK Art. 6)
FinancialPayment records (amount + method). No card data is stored.

3. Purposes and Legal Bases

4. Data Transfers and Hosting

flowdesk runs its infrastructure on Supabase Inc., which hosts data within the European Union (Frankfurt, Germany); Supabase acts as a data processor. Keeping data in the EU provides the highest level of protection for EU users.

For users accessing from Turkey, this constitutes a cross-border transfer under KVKK Art. 9 and is carried out on the basis of your explicit consent. We do not sell your data or transfer it to third parties for marketing.

5. Retention

Your data is retained only as long as necessary for the processing purpose and any statutory retention periods (e.g. financial records); afterwards it is deleted, destroyed or anonymised.

6. Your Rights

Under GDPR Art. 15–22 and KVKK Art. 11, you have the right to access, rectify, erase ("right to be forgotten"), port (download your data), object to processing, and withdraw consent. When signed in, you can download or request deletion of your data directly from your account, or contact us at the email above. We respond within 30 days at the latest.

You may also lodge a complaint with the Turkish Data Protection Authority (KVKK) or the supervisory authority of your EU member state.

7. Security

flowdesk applies technical and organisational measures including row-level security (RLS), role-based authorisation, audit logging of all health-data access, and encrypted connections (HTTPS). Every access to health data is logged.

8. Cookies

flowdesk uses only strictly necessary cookies to keep you signed in; no advertising or tracking cookies. See the Cookie Policy.

9. Changes

This policy may be updated; the current version is published here with the "last updated" date.

10. Contact

Questions: yagizkaya43@gmail.com