Clinic guidePrivacy and KVKK

Privacy

Privacy and KVKK

How Voxlera helps your clinic meet its data-protection obligations under KVKK and the GDPR.

Your clinic is the data controller for your patients’ data; Voxlera processes it on your behalf. Health information is special-category data under Turkish law (KVKK), and under the GDPR for patients in the EU. This page explains what Voxlera does to protect it and what your clinic needs to do.

Note

This page describes how the product works. It isn’t legal advice — check your own obligations with your data-protection adviser.

What Voxlera does

  • Discloses every AI call. Each call opens by telling the patient they are speaking to an automated assistant and that the call is recorded. This is built into every script and can’t be removed.
  • Only contacts patients with consent. Messages need an active consent record for the channel, with evidence of where it came from. Website forms have an unticked consent box.
  • Keeps your data separate. Each clinic’s data is isolated from every other clinic’s, down to the database.
  • Protects recordings. Call recordings are stored privately and only played to staff with permission. There are no public links.
  • Encrypts secrets. Credentials you give Voxlera, such as messaging tokens and calendar tokens, are encrypted.
  • Keeps an audit log. Changes to patient data, and deliberate access to it — playing a recording, exporting or erasing a patient — are logged with who, what and when. Owners can review it under Admin → Audit Log.
  • Hides implementation details. Staff and patients see your clinic and Voxlera, not the technology vendors behind a call.

Patients’ rights

Access and portability

Use Export patient data on the patient’s record to download everything Voxlera holds about them.

Erasure

Use Erase patient data on the patient’s record. This permanently removes their name, contact details, messages, call transcripts, call recordings and clinical notes, and cancels any calls waiting for them. It can’t be undone.

Consent records are kept, but anonymised: the law requires you to be able to show that consent existed. The erased patient won’t be re-imported from your PMS.

Revoke the patient’s consent on their Consent tab. Messages on that channel stop immediately.

Correction and restriction

To correct a patient’s data, correct it in your PMS; Voxlera picks up the change on the next sync. If a patient asks you to restrict processing of their data, contact Voxlera support: while a restriction is in place, calls to that patient are blocked and marked Blocked — processing restricted.

What your clinic needs to do

  • Tell patients about AI calls and messages in your privacy notice (aydınlatma metni). If you give Voxlera the link, it’s shown under the consent box on your website forms.
  • Record consent properly. When staff record consent by hand, add evidence of how and when it was given.
  • Limit access. Give staff the least access they need — see Team, roles and permissions. By default, only the Owner can export or erase patient data and see the audit log.
  • Act on requests promptly. Data-subject requests have legal deadlines. Keep your own record of each request and when you answered it.
  • Keep your templates minimal. Don’t put more health information in messages than a patient needs — a message can be seen by others on their phone.

Data processing agreement

Voxlera signs a data processing agreement with each clinic, and keeps a list of the sub-processors it uses. Ask your Voxlera contact for both.