Medart Clinic

Giriş

Privacy Policy / Gizlilik Politikası

Privacy Policy

Last updated: 28 July 2026

1. Who we are

This Privacy Policy applies to the internal WhatsApp messaging application operated by Medart Clinic (“we”, “us”, “our”). The application is a private inbox used by our authorized employees and agents to communicate with our own customers and leads via the Meta WhatsApp Cloud API and to sync related records with our Zoho CRM.

This software is for internal company use only. It is not a public product, marketplace app, or multi-tenant SaaS offering.

2. We are not a Tech Provider or Solution Provider

We use the WhatsApp Business Platform solely as a business customer for our own WhatsApp Business Account(s) and phone number(s). We do not:

  • act as a Meta WhatsApp Tech Provider or Solution Partner;
  • onboard other businesses or manage third-party WABAs;
  • offer Embedded Signup or messaging services to other companies;
  • resell, white-label, or commercially provide this application to third parties.

Message content and related data are processed only to operate Medart Clinic’s own customer communications and CRM workflows.

3. Scope of data processing

Depending on how conversations are used, we may process:

  • WhatsApp identifiers and phone numbers of contacts who message us;
  • message text, media (images, documents, audio, video), and delivery statuses;
  • reply / reaction metadata associated with messages;
  • CRM-related fields synced from Zoho (for example lead owner, lead status, and identifiers) needed to route chats to the correct agent;
  • employee account data (name, email) required to authenticate and authorize access to the inbox.

We do not use WhatsApp message content for advertising, profiling for sale, or training public AI models.

4. Purposes and legal bases (GDPR)

Where the EU General Data Protection Regulation (GDPR) or equivalent laws apply, processing is based on one or more of the following:

  • Legitimate interests — operating internal customer support and sales communications securely and assigning chats to responsible staff;
  • Contract / pre-contractual steps — responding to inquiries and providing services requested by the data subject;
  • Legal obligations — where retention or disclosure is required by applicable law;
  • Consent — where WhatsApp / Meta or local rules require consent for certain message types, which is handled in line with WhatsApp Business policies.

5. Storage, security, and processors

Data is stored in systems under our control or with carefully selected processors that provide hosting, database, object storage, CRM, and the WhatsApp / Meta messaging infrastructure. We apply appropriate technical and organisational measures, including access control (authenticated staff only), encrypted transport (HTTPS / TLS), and least-privilege credentials.

Processors are engaged under GDPR Article 28-style arrangements where required. WhatsApp / Meta process message delivery as the communications platform according to their own terms and privacy notices.

We do not sell personal data. We do not share inbox contents with unrelated third parties for their own marketing purposes.

6. Retention

Conversation and media records are retained for as long as needed for operational, customer-service, and legitimate business or legal purposes, then deleted or anonymised according to our internal retention practices. Employee accounts are removed or deactivated when access is no longer required.

7. International transfers

Some infrastructure or platform providers may process data outside the European Economic Area. Where such transfers occur, we rely on appropriate safeguards recognised under GDPR (for example Standard Contractual Clauses or an adequacy decision), together with the providers’ security commitments.

8. Your rights

Subject to applicable law, individuals may request access, rectification, erasure, restriction, objection, or portability of their personal data, and may lodge a complaint with a supervisory authority. To exercise these rights in relation to data held in this system, contact us using the details below. Requests may be limited where we must retain data for legal reasons or where Meta / WhatsApp remain the primary channel for certain conversation data.

9. Children

This internal tool is not directed at children. We do not knowingly use the application to solicit personal data from children.

10. Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page will change when we do. Continued use of the application by our staff after updates constitutes awareness of the revised policy for internal operations.

11. Contact

Controller: Medart Clinic
Privacy inquiries: privacy@medartclinic.com

Bu uygulama yalnızca Medart Clinic çalışanları ve yetkili temsilcileri tarafından, şirketin kendi müşteri iletişimleri için kullanılır. Üçüncü taraf işletmelere WhatsApp altyapısı veya Tech Provider hizmeti sunulmaz.