Privacy Notice
Last updated:
My Health Online — Clinical Case Collaboration Platform — is a hospital-deployed tool used by licensed clinicians to share pseudonymized clinical cases across institutional borders. This notice explains what we process, why, and what rights you have under KVKK (Türkiye), the UZ Personal Data Law, and the GDPR.
1. Who is the data controller
When My Health Online is deployed inside a hospital, the hospital is the data controller for the patient cases and clinical content created on the platform. My Health Online operates as a data processor on the hospital's behalf, governed by a written Data Processing Agreement (see /dpa).
For account information about the clinicians themselves (name, email, role), My Health Online and the hospital act as joint controllers.
2. What we process
The platform processes the following categories of data:
- Clinician account data — name, email, professional title, department, specialty, hospital affiliation, role, MFA enrollment.
- Case content — clinician-authored case summaries, attached imaging studies (DICOM), documents (PDF, JPEG), structured consultation messages, and threaded replies.
- Patient data — pseudonymized only. The platform never stores names, national IDs, or insurance numbers. Identifiers are replaced by a hospital-local pseudonym before they reach My Health Online.
- Audit log — every action (case created, status changed, attachment downloaded, consultation submitted) is recorded in a hash-chained, append-only log.
- Diagnostics — minimal request metadata (timestamp, route, status) for operational monitoring.
3. Purposes and legal basis
We process the data above to (a) enable clinical consultation between hospitals, (b) maintain account security, (c) produce auditable evidence required by hospital governance and regulators, and (d) keep the service operational.
The legal basis depends on jurisdiction. Under KVKK Md. 6, processing of health data is permitted with the explicit consent of the data subject OR under the public-health exception when carried out by authorized health personnel. Under the GDPR, the equivalent basis is Art. 9(2)(h) — necessary for the provision of health care, by a health professional under a duty of secrecy. Under UZ PDL Art. 17, processing of special-category personal data is permitted for medical purposes by personnel bound by professional secrecy.
4. Retention
Case content is retained for as long as required by the hospital's clinical-records retention policy and applicable medical-records law (in Türkiye, typically 20 years per the Ministry of Health regulation). The audit log is retained for at least the same period — it is the only tamper-evident record of who accessed what.
Account data is retained while the clinician remains active and for 90 days after the hospital deactivates the account, after which it is anonymized.
5. Cross-border transfers
My Health Online's hospital deployments process and store data within the country of deployment by default. Cross-border transfers happen only when a clinician at one hospital shares a case with a clinician at another hospital in another jurisdiction.
Such transfers are documented per case, logged in the audit chain, and — for transfers leaving the EEA/UK/Türkiye — performed under the EU Standard Contractual Clauses or KVKK-approved equivalent commitments.
6. Your rights
Under KVKK Art. 11, GDPR Art. 15-22, and UZ PDL Art. 22, you have the right to be informed about, access, correct, delete, restrict, and port the personal data we hold about you, and to object to its processing.
Authenticated clinicians can exercise the right of access immediately via /api/auth/dsar/export, which returns a portable JSON snapshot of your account data and the cases you have authored.
7. Contact
For any privacy enquiry — including DSAR, breach notification, or KVKK Md. 11 requests — contact the data protection officer at privacy@cccp.health. For requests directed at the hospital as controller, please contact your institution's DPO directly.