Doctor Website Builder
Log in
Back to home

Data Processing Agreement (DPA)

Last updated: July 5, 2026

This agreement is an annex (EK-1) to the Membership Agreement and governs the controller–processor relationship for personal data of visitors to the site published by the User (doctor/clinic).

Roles: User = DATA CONTROLLER (for site visitor/patient data) · Platform = DATA PROCESSOR.

1. Subject and Scope

The Platform processes visitor data on the User's behalf only as needed to provide the service: hosting the site, displaying content, forwarding contact-form messages to the User by email, and technical logs.

2. Categories of Data

Site visitors' name, email, phone and message content submitted via the contact form; basic technical data (IP, browser info, logs).

Contact-form messages are NOT stored in the Platform database; they are only emailed to the User (via Resend).

The Platform is not a patient-record system; the User must not collect special-category (health) data from visitors.

3. Processing on Instructions

The Platform processes visitor data only under this agreement and as the service requires, on the User's instructions; it does not use the data for its own purposes or sell it to third parties.

4. Confidentiality and Security

The Platform applies appropriate technical and organisational measures, including access control, row-level security (RLS), encrypted transport (HTTPS/TLS) and secure authentication. Persons with access are bound by confidentiality.

5. Sub-processors

The User gives general authorisation for these sub-processors: Vercel (hosting), Supabase (database/authentication), Cloudflare (CDN/DNS/media storage - R2), Resend (email delivery), iyzico and Paddle (payments).

Changes to sub-processors are announced reasonably; the User may object on reasonable grounds.

6. International Transfers

Some sub-processors may be located abroad; transfers are made only as the service requires and in accordance with applicable data-protection law.

7. Assistance with Data-Subject Requests

Visitors' data-subject requests (access, deletion, etc.) are directed to the User; the Platform provides reasonable assistance for data under its control.

8. Breach Notification

Upon becoming aware of a personal-data breach affecting visitor data, the Platform notifies the User without undue delay and cooperates reasonably to mitigate the impact.

9. Deletion and Return

When the service relationship ends, User data is deleted after the export option and the recovery window (except records whose retention is required by law).

10. Audit

No more than once a year and without breaching trade secrets, the User may request reasonable written information from the Platform about its security measures.

Governing language

The binding version of this document is the Turkish original. Translations are provided for convenience only. View the Turkish version

Contact

For any questions about this document, contact us:

Company:
FÇG SAĞLIK HİZMETLERİ LTD. ŞTİ.
Address:
Hunat Mah., Nuh Mehmet Baldöktü Sokak, Özer Plaza, No: 3/18, Melikgazi, Kayseri