BLUEHAMS
Modules Features How It Works Pricing FAQ
TR EN
Sign In Request a Demo
Legal

Personal Data Retention and Disposal Policy

Last updated: August 18, 2026 · Version 1.1

  • OYOX LLC · BLUEHAMS
  • Data hosted in Türkiye
  • Press Ctrl+P / Cmd+P to print
OYOX LLC · BLUEHAMS
Data Controller
1209 Mountain Road PL NE, STE N, Albuquerque, NM 87110, United States
Registration New Mexico Secretary of State · 2026-02-23 · Reg. No 0008084103
Contact kvkk@bluehams.com · bluehams.com

This document is provided for convenience; the Turkish version prevails. This Personal Data Retention and Disposal Policy (the "Policy") sets out the rules and procedures governing the retention and disposal of personal data processed within BLUEHAMS (bluehams.com, the "Platform" or "Service"), the hearing aid center management software offered under the BLUEHAMS brand by OYOX LLC — a Domestic Limited Liability Company registered with the New Mexico Secretary of State on February 23, 2026, Registration No 0008084103 ("OYOX", the "Company" or the "Data Controller"). As a data controller established abroad, the Company's registered office and service address is 1209 Mountain Road PL NE, STE N, Albuquerque, NM 87110, United States. Version 1.1 — Effective August 18, 2026.

Contents Contents
  1. Purpose, Scope and Legal Basis
  2. Definitions
  3. Retention Principles and Criteria for Determining Periods
  4. Retention Schedule
  5. Clinic Patient Data Held as Data Processor
  6. Technical and Organizational Measures for Secure Retention
  7. Disposal Methods
  8. Automatic and Periodic Disposal
  9. Roles and Responsibilities
  10. Updates to This Policy

Purpose, Scope and Legal Basis

The purpose of this Policy is to define the maximum retention periods necessary for the purposes for which personal data are processed, and the procedures for erasing, destroying or anonymizing such data once those periods expire.

This Policy is based on Article 7 of the Turkish Personal Data Protection Law No. 6698 (the "Law" or "KVKK") and the Regulation on the Erasure, Destruction or Anonymization of Personal Data published in the Official Gazette No. 30224 dated October 28, 2017 (the "Erasure Regulation").

The Policy covers all personal data processed within the Service and addresses the two distinct roles of the Data Controller together.

  • Data processed with OYOX acting as data controller. Data relating to bluehams.com visitors, prospective customers submitting the demo request form, clinic officials and users creating accounts, and subscription and payment processes.
  • Data processed with OYOX acting as data processor. Patient records, health and hearing aid information, patient documents, collection records and SMS records maintained on the Platform by the hearing aid centers subscribing to BLUEHAMS (each a "Customer" or "Clinic"; the data controller for such data). The authority to determine retention periods for these data rests with the Clinic, as detailed in the Data Processing Agreement.
Personal Data are hosted on servers located within the Republic of Türkiye (Istanbul). Transfers abroad may be carried out only where the appropriate safeguards provided for in Article 9 of the Law are ensured; details of the transfer framework are set out in the Privacy Policy.

Definitions

The key terms in this Policy are used with the meanings given in Article 3 of the Law and in the Erasure Regulation.

  • Personal Data. Any information relating to an identified or identifiable natural person.
  • Data Subject. The natural person whose Personal Data are processed.
  • Disposal. The umbrella term covering the erasure, destruction or anonymization of Personal Data.
  • Erasure. Rendering Personal Data inaccessible and unusable in any way for the relevant users.
  • Destruction. Rendering Personal Data inaccessible, irretrievable and unusable by anyone in any way.
  • Anonymization. Rendering Personal Data incapable of being associated with an identified or identifiable natural person under any circumstances, even when matched with other data. Anonymized data cease to be personal data and may continue to be used for statistical purposes.
  • Periodic disposal. The erasure, destruction or anonymization of Personal Data whose retention period has expired, carried out automatically at recurring intervals.
  • Recording medium. Any medium containing Personal Data. For the Platform, the recording media are the application database (MySQL), the server directories holding uploaded files, system and audit logs, and encrypted backup files.

Retention Principles and Criteria for Determining Periods

Personal Data are retained in accordance with the general principles in Article 4 of the Law; lawfully and fairly, accurately and, where necessary, kept up to date, for specified, explicit and legitimate purposes, in a manner that is relevant, limited and proportionate to those purposes, and only for the period required by the applicable legislation or by the purpose of processing.

The retention period for each data category is determined by applying the following criteria in order.

  1. Where the applicable legislation prescribes an explicit retention period, that period applies (for example, the obligation under the Erasure Regulation to keep records of disposal operations for at least three years, or the minimum retention periods in the health legislation applicable to Customer clinics).
  2. Where no explicit statutory period exists, the limitation periods applicable to potential legal disputes arising from the data and the need to preserve evidence in such disputes are taken into account (including the general ten-year limitation period under Article 146 of the Turkish Code of Obligations No. 6098).
  3. Where no limitation-based requirement exists either, the continued existence of the processing purpose is assessed; once the purpose ceases, the data are disposed of in the first periodic disposal cycle.

Personal Data whose retention period has expired, or for which all processing conditions have ceased to exist, are disposed of ex officio without awaiting a request from the Data Subject. Data Subjects may also request erasure or destruction under Article 11 of the Law; see the KVKK Application Form page for the application procedure.

Retention Schedule

The table below sets out the retention periods applied both to data processed by OYOX as data controller and to records maintained as part of the operation of the system, together with the disposal action taken at the end of each period.

For records containing patient data (SMS dispatch records and the patient-related portions of activity and audit logs), the data controller is the Customer clinic; the periods applied to these records reflect the standard retention instruction agreed under the Data Processing Agreement. The controller Clinic may issue a different instruction in line with the legislation applicable to it.

Data categoryRetention periodAction at end of period
Demo request records (full name, clinic name, email, phone, number of branches, message)2 years from the date of the requestSecure erasure (as part of the periodic review)
Account and contract data (first name, last name, email, phone, username)For the duration of the membership; after termination, for the general ten-year limitation period under Article 146 of the Turkish Code of Obligations, having regard to the need to preserve evidence in potential disputesSecure erasure
Subscription payment records and uploaded payment receipts10 years from the date of payment (limitation periods and evidentiary requirements)Secure erasure
SMS dispatch records (patient phone number and message text; processed as data processor, under the standard retention instruction)180 daysAnonymization — the phone number is masked and the message body is cleared; only numerical statistics containing no personal data remain
Activity and audit logs (user activity history and administrator audit trail; for patient-related portions, under the standard retention instruction)730 days (2 years)Secure erasure
Encrypted backups (AES-256 encrypted)14 daysAutomatic disposal at the end of the 14-day cycle
Security records (login attempts, password reset records)For as long as the security purpose continuesSecure erasure as part of the periodic review once the purpose ceases
Clinic patient data (processed as data processor)Determined by the instructions of the controller Clinic and the health legislation applicable to itReturn and disposal upon contract termination (see the next section)
The periods in this table are maximum retention periods. Where all processing conditions cease to exist earlier, the data are disposed of in the first periodic disposal cycle without waiting for the period to expire.

Clinic Patient Data Held as Data Processor

With respect to the patient records maintained on the Platform by Customer clinics (identity, contact, health and hearing aid information, patient documents, payment and installment records, technical service records, notes), the Clinic is the data controller and OYOX is the data processor. The authority and obligation to determine retention periods for these data rest with the Clinic; OYOX does not dispose of these data except on the Clinic's instructions.

When determining retention periods, Clinics are obliged to observe the minimum retention periods in the health legislation applicable to them. The relevant regulations prescribe minimum retention periods, and longer periods may apply to hearing aid centers contracted with the Social Security Institution (SGK). Correctly determining these periods is the Clinic's responsibility; OYOX provides an infrastructure suitable for retaining the data held in the system in line with those periods.

The Platform does not replace the written patient registry book required by law; it provides supporting electronic records and printable document and patient-registry output. Statutory book and record-keeping obligations remain with the Clinic.

Upon termination of the subscription agreement, Clinic data are returned to the Clinic in accordance with the Data Processing Agreement; following the return, the copies in the system are disposed of using the methods in this Policy, and the disposal propagates to backup media upon completion of the backup cycle (14 days at most).

Technical and Organizational Measures for Secure Retention

In accordance with Article 5 of the Erasure Regulation, the principal technical and organizational measures taken to keep Personal Data secure throughout their retention period and to prevent their unlawful processing and unlawful access are as follows.

  • All traffic is redirected to HTTPS; communications are encrypted with TLS 1.2/1.3 and HSTS is enforced.
  • Encryption at rest is applied to the application database, protecting against stolen-disk scenarios.
  • Backups are kept encrypted with AES-256 and are automatically disposed of at the end of the 14-day cycle.
  • Passwords are stored as irreversible hashes; two-factor authentication (TOTP) with recovery codes is available for accounts.
  • Role-based authorization and tenant isolation are enforced; every query is filtered per account, and Customer clinics cannot access each other's data.
  • Session security is maintained; cookies are httponly and Secure, and sessions are terminated after 30 minutes of inactivity.
  • Protection against injection and request forgery is applied (database access via prepared statements, CSRF validation, output escaping, a content security policy).
  • File uploads are subject to a type whitelist, server-generated random file names and a 10 MB size limit.
  • Login attempt limiting protects against brute-force attacks, alongside server-level access hardening and intrusion blocking.
  • Data movements are logged through user activity history and an administrator audit trail.

Detailed information on the full set of measures and their relation to processing activities is available in the Privacy Policy.

Disposal Methods

Personal Data whose retention period has expired are disposed of using one of the following methods, depending on the nature of the data and the recording medium in which they reside.

  • Secure erasure from the database. The record is removed from the application database in a manner that renders it inaccessible and unusable in any way for the relevant users. Records deleted within the application are first moved to the trash (a soft-deleted state); permanent disposal is carried out through the trash purge operation.
  • File disposal. Documents uploaded to the server (payment receipts, patient documents) are securely deleted from the relevant directory.
  • Anonymization. As with SMS records, fields that make a person identifiable are masked and content fields are cleared; only numerical statistics that cannot be associated with any natural person remain.
  • Expiry through the encrypted backup cycle. Backups are kept encrypted with AES-256 and are automatically disposed of on a 14-day cycle. Data disposed of in the live system therefore drop out of all backup copies automatically within 14 days at most. Backup copies are not accessed in ordinary operations until the cycle completes.

Automatic and Periodic Disposal

Under the Erasure Regulation, periodic disposal must be carried out at recurring intervals not exceeding six months. In the Platform, this obligation is fulfilled — in every case within periods not exceeding six months — through an automated retention cleanup job that runs at regular intervals, together with periodic reviews for the categories outside its scope.

  1. The automated retention cleanup runs at regular intervals; it anonymizes SMS records older than 180 days and erases activity and audit logs older than 730 days.
  2. Permanent disposal of records in the trash is carried out through a separate purge operation.
  3. Encrypted backups are disposed of automatically on the 14-day cycle; the cycle requires no additional action.
  4. Categories not covered by the automated cleanup (demo request records, account and contract data, payment records, security records) are assessed in periodic reviews carried out within periods not exceeding six months; records whose retention period has expired are disposed of in that process.
  5. Data Subjects' erasure or destruction requests under Article 11 of the Law are handled independently of the periodic cycle and concluded within 30 days at the latest. Requests concerning clinic patients are forwarded to the relevant Clinic, since the Clinic holds the data controller role, and are fulfilled in line with the Clinic's instructions.

Records of completed disposal operations are kept for at least three years, without prejudice to other legal obligations.

Roles and Responsibilities

The management of OYOX LLC is responsible for the implementation of this Policy. Responsibilities are allocated as follows.

Responsible partyDuty
OYOX LLC managementPreparing and updating the Policy, determining retention periods, and overseeing implementation
System administrationKeeping the automated disposal jobs operational, running the backup cycle, and maintaining disposal records
Customer clinic (data controller)Determining retention periods for patient data in line with health legislation, and issuing disposal and return instructions

Questions regarding this Policy and applications under the Law may be submitted through the following channels, in order of priority.

  1. Primary channel — post. A written application by post to the OYOX LLC (US) address stated above: 1209 Mountain Road PL NE, STE N, Albuquerque, NM 87110, United States,
  2. Secondary channel — email. A written application to kvkk@bluehams.com (which will become active once the relevant email infrastructure is operational),
  3. Via the contact form on bluehams.com.

Detailed information on the application procedure, the valid application channels and the mandatory elements is available on the KVKK Application Form page, and information on processing activities as a whole is available in the Privacy Notice.

Updates to This Policy

This Policy is reviewed and updated as necessary in light of legislative changes, decisions of the Turkish Personal Data Protection Board, or changes in BLUEHAMS's data processing operations.

The current version is always published on bluehams.com; the version number and effective date are shown at the top of the document. Material changes are additionally announced to active Customer clinics.

Version 1.1 — August 18, 2026. This Policy has been prepared in accordance with the legislation in force as of its publication date.
BLUEHAMS Stock, patient, technical service and collection management for hearing aid centres.

Cloud-based management software that brings patient tracking, inventory, technical service and collections together in one panel for hearing aid centers.

  • Data hosted in Türkiye
  • KVKK-aligned contract framework
  • Encrypted daily backups
Request a Demo
Sign In Sign Up

Product

Modules Features How It Works Pricing FAQ

Account

Sign In Sign Up Request a Demo

Legal

Privacy & Legal Center Privacy Notice Privacy Policy Cookie Policy Terms of Service Data Processing Agreement

Contact

OYOX LLC
1209 Mountain Road PL NE, STE N
Albuquerque, NM 87110, United States
kvkk@bluehams.com LLC registered in New Mexico (USA) · Registration No 0008084103
© 2026 OYOX LLC — BLUEHAMS. All rights reserved. BLUEHAMS is a product of OYOX LLC (New Mexico, USA).
BLUEHAMS