Skip to content
MEDİGATES

Privacy Policy

Last updated: October 6, 2026

This is a translation. If there is any discrepancy between it and the Turkish version, the Turkish version prevails.

This policy explains how your personal data is processed when you use the MEDİGATES website and mobile app (together, the "Platform"), in line with Article 10 of the Turkish Personal Data Protection Law No. 6698 (KVKK) and its Communiqué on the Obligation to Inform. It also includes the information required by the EU General Data Protection Regulation (GDPR) for users in the European Union.

1. Data controller

Data controller: Academia Group Eğitim Danışmanlık Ltd. Şti., Merkez Mah. Marmara Cad. Ozan Bağcılar İş Merkezi No:27-29 Kat 3/56, Avcılar/İstanbul, Türkiye. MEDİGATES is a product of this company. Contact: [email protected].

MEDİGATES is not a healthcare provider; it coordinates international patients with partner healthcare facilities, doctors and accommodation services in Türkiye. Medical diagnosis and treatment are the responsibility of the relevant healthcare facility.

2. Personal data we process

Identity and contact: full name, email address, phone number, country, spoken languages, preferred language.

Health data (special category data): the treatment and specialty you request, medical documents you upload (e.g. test results, imaging reports, prescriptions) and health information you share with our coordinators.

Travel and companion: arrival and departure dates, passport details, your companion's name, relationship to you, phone number and passport details.

Account and activity: sign-in details (email/password or Sign in with Google or Apple), request and offer records, appointments, messages with coordinators, notifications.

Security: IP address, session and access logs, failed sign-in attempts.

3. How we collect your data

We collect your data electronically through forms on the Platform (request, sign-up, profile), documents you upload, messages on the Platform and — if you choose to sign in with Google or Apple — the name and email address shared by these providers; and partly by non-automated means when our coordinators record information you give during phone calls.

4. Purposes and legal bases

We process your identity, contact, travel and account data to receive your request, contact you, create and manage your account, obtain offers from healthcare facilities, coordinate appointments, accommodation and transfers and send you notifications, on the basis that this is necessary to enter into and perform our agreement with you (KVKK Art. 5(2)(c); GDPR Art. 6(1)(b)).

We process security data to keep the Platform secure, prevent unauthorised access and meet our legal retention obligations, based on our legal obligations (KVKK Art. 5(2)(ç); GDPR Art. 6(1)(c)) and legitimate interests (KVKK Art. 5(2)(f); GDPR Art. 6(1)(f)).

We process your health data only for treatment coordination (identifying suitable facilities and doctors, offers and appointments) and only on the basis of your explicit consent (KVKK Art. 6; GDPR Art. 9(2)(a)). Your explicit consent is obtained separately from this notice; you are not obliged to give it, but without health information we may not be able to obtain a treatment offer for you.

You can withdraw your explicit consent at any time by writing to [email protected]. Withdrawal does not affect processing carried out before it.

5. Sharing your data

Within Türkiye: the information needed for offers and treatment (including your health data, within the scope of your explicit consent) is shared with partner healthcare facilities, and the identity and travel details needed for accommodation and transfers are shared with the relevant service providers. Data is disclosed to public authorities only where required by law.

Outside Türkiye: the infrastructure providers we use to run the Platform, whose servers are located outside Türkiye, process your data only on our behalf and under our instructions: Supabase (database, file storage and session management — Frankfurt, Germany), DigitalOcean (application server — Frankfurt, Germany), Resend (email delivery — Ireland). If you choose to sign in with Google or Apple, authentication is handled by these companies (USA).

International transfers are made under KVKK Art. 9 on the basis of appropriate safeguards such as the standard contracts announced by the Turkish Personal Data Protection Board and data processing agreements with our providers. All parties with whom we share your data are required to provide the same or equivalent protection as described in this policy.

We do not sell or rent your data for advertising or marketing, and the Platform does not use advertising or analytics (tracking) tools.

6. Retention and deletion

We keep your personal data for as long as needed for the purposes it was collected for and for the retention periods required by law. At the end of these periods, or upon your request (except for records we are legally required to keep), your data is deleted, destroyed or anonymised.

You can permanently delete your account on the website or in the mobile app via Profile → Delete my account, or send your deletion request to [email protected]. When your account is deleted, your sign-in details, requests, uploaded documents, messages and appointments are permanently deleted; this cannot be undone.

To prove that account deletion and explicit consent took place, we keep only a technical record that does not directly identify you (action type, date and a technical ID).

If you signed in with Apple, you can also remove MediGates from your Apple Account (iPhone Settings → your name → Sign-In & Security → Sign in with Apple).

7. Your rights

Under KVKK Art. 11 you have the right to learn whether your personal data is processed; to request information about it; to learn the purpose of processing and whether it is used accordingly; to know the third parties in Türkiye or abroad to whom it is transferred; to request rectification of incomplete or inaccurate data; to request erasure or destruction under KVKK Art. 7; to request that rectification or erasure be notified to third parties to whom the data was transferred; to object to a result against you arising exclusively from automated analysis; and to claim compensation for damage caused by unlawful processing.

Users covered by the GDPR also have the right to data portability and to request restriction of processing.

8. How to make a request

You can send your requests in writing to the address above, via registered electronic mail (KEP), secure electronic or mobile signature, or from the email address registered on the Platform to [email protected]. Under Turkish law, requests to the data controller are to be made in Turkish; we will also do our best to answer requests made in English.

We respond within 30 days at the latest, free of charge. If the request involves an additional cost, a fee within the tariff set by the Personal Data Protection Board may be charged. If your request is rejected, you find the answer insufficient or we do not respond in time, you may file a complaint with the Turkish Personal Data Protection Board; users in the EU may also complain to their local supervisory authority.

9. Security

Your data is transmitted over encrypted connections (TLS). Medical documents are kept in a private, access-controlled storage area; access rights are checked every time a document is viewed, and documents are shown with a watermark identifying the viewer. Access is limited to staff assigned to your request and the relevant healthcare facility.

10. Children

The Platform is not intended to be used by persons under 18 on their own. Requests for patients under 18 must be made by a parent or legal guardian.

11. Changes

We may update this policy. The current version is always published on this page with its last updated date, and we will notify you of significant changes. For information on cookies, see our Cookie Policy.