BLUEHAMS
Modules Features How It Works Pricing FAQ
TR EN
Sign In Request a Demo
Legal

Data Processing Agreement (DPA)

Last updated: August 18, 2026 · Version 1.1

  • OYOX LLC · BLUEHAMS
  • Data hosted in Türkiye
  • Press Ctrl+P / Cmd+P to print
OYOX LLC · BLUEHAMS
Data Controller
1209 Mountain Road PL NE, STE N, Albuquerque, NM 87110, United States
Registration New Mexico Secretary of State · 2026-02-23 · Reg. No 0008084103
Contact kvkk@bluehams.com · bluehams.com

This document is provided for convenience; the Turkish version prevails. This Data Processing Agreement (the "Agreement" or "DPA") is an integral annex to the BLUEHAMS Terms of Service and sets out the terms under which OYOX LLC ("OYOX" or the "Company"), acting as data processor, processes personal data determined by the hearing aid sales and fitting center subscribing to the BLUEHAMS platform (the "Platform" or "Service") — the "Clinic" or "Customer" — acting as data controller. The Agreement gives concrete form to the parties' mutual data security obligations under Article 12(2) of Turkish Law No. 6698 on the Protection of Personal Data (the "Law" or "KVKK"). Version 1.1 — 17 August 2026. This document is updated with a version and date stamp upon any change in the applicable legislation.

Contents Contents
  1. Article 1 — Parties, Roles and Definitions
  2. Article 2 — Subject Matter, Scope and Processing on Instructions Only
  3. Article 3 — Duty of Confidentiality
  4. Article 4 — Data Security Measures
  5. Article 5 — Sub-processors
  6. Article 6 — Personal Data Breach Notification
  7. Article 7 — Audit Rights
  8. Article 8 — Data Subject Requests
  9. Article 9 — Data Location and International Transfers
  10. Article 10 — Term, Termination, Return and Destruction of Data
  11. Article 11 — Liability
  12. Article 12 — Governing Law and Jurisdiction
  13. Annex 1 — Categories of Data Processed and Groups of Data Subjects
  14. Annex 2 — Technical and Organizational Measures
  15. Annex 3 — List of Sub-processors
  16. Annex 4 — Information Note on the Clinic's KVKK Obligations and Sample Patient Privacy Notice

Article 1 — Parties, Roles and Definitions

1.1. Parties. This Agreement is entered into between the parties whose identity and title details appear below.

  • Data Processor ("OYOX" or the "Company"): OYOX LLC — a Domestic Limited Liability Company registered with the New Mexico Secretary of State on 23 February 2026 (Registration No. 0008084103); principal address 1209 Mountain Road PL NE, STE N, Albuquerque, NM 87110, United States. OYOX provides subscription-based management software for hearing aid centers (the "Platform" or "Service") under the "BLUEHAMS" brand and product name.
  • Data Controller ("Clinic" or "Customer"): The hearing aid sales and fitting center established in Türkiye that purchases a Platform subscription under the Terms of Service.

1.2. Roles. The Clinic is the data controller that determines the purposes and means of processing personal data relating to its own patients, patients' relatives and staff. OYOX is the data processor that processes such data solely on the basis of the authority granted by, and on behalf of, the Clinic. Data that OYOX processes in its own capacity as a service provider to the Clinic (account, subscription and billing contact data of Clinic representatives) falls outside this Agreement and is governed by OYOX's own Privacy Notice and Privacy Policy, in which OYOX acts as data controller.

1.3. Definitions. Terms used in this Agreement have the meanings given in Article 3 of the Law.

  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Special Categories of Personal Data: The data listed exhaustively (numerus clausus) in Article 6 of the Law; under this Agreement, in particular health data (including information on hearing loss, hearing aids and audiological assessment).
  • Data Subject: The natural person whose personal data is processed (patient, patient's relative/guardian, clinic staff).
  • Data Controller: The natural or legal person who determines the purposes and means of processing and is responsible for establishing and managing the data filing system.
  • Data Processor: The natural or legal person who processes personal data on behalf of the data controller on the basis of the authority granted by it.
  • Sub-processor: A third party to which OYOX delegates part of the personal data processing activity for the provision of the Platform service (Annex 3).
  • Board / Authority: The Turkish Personal Data Protection Board / the Turkish Personal Data Protection Authority.
  • Service: The BLUEHAMS subscription service defined in the Terms of Service (patient records and follow-up, appointments, inventory, technical service tracking, collections and installment tracking, SMS reminder templates, staff and branch management, document generation and reporting functions).

1.4. Notices and Contact Channels. For notices, applications and service of process under this Agreement, OYOX's primary contact channel is, by post, the OYOX LLC (US) address above: 1209 Mountain Road PL NE, STE N, Albuquerque, NM 87110, United States. As a secondary channel, the e-mail address kvkk@bluehams.com — which will become active once the e-mail infrastructure is established and brought into operation — and the contact form on bluehams.com may be used.

Article 2 — Subject Matter, Scope and Processing on Instructions Only

2.1. OYOX processes the personal data listed in Annex 1 only (a) in accordance with the Clinic's documentable instructions and (b) to the extent and for the duration strictly necessary to provide, maintain, secure and support the Service. Data entry, updating, deletion and similar operations carried out by the Clinic through the Platform interface, as well as written support requests, constitute instructions of the Clinic.

2.2. OYOX shall under no circumstances process the personal data covered by this Agreement for its own purposes; it shall not use such data for marketing, profiling, advertising, sale to third parties or any other commercialization, and shall not carry out any processing activity outside the Clinic's instructions, including anonymization. Any use beyond the agreed purposes is strictly prohibited.

2.3. If OYOX considers that an instruction of the Clinic infringes the Law or other legislation, it shall notify the Clinic without delay and may suspend execution of the said instruction until the infringement is remedied.

2.4. The authority to determine the purposes and means of processing rests exclusively with the Clinic. Collecting data from patients, determining the legal basis for processing, fulfilling the duty to inform and, where required, obtaining explicit consent are the Clinic's responsibility (see Annex 4).

Article 3 — Duty of Confidentiality

3.1. OYOX shall keep confidential, for an indefinite period, all personal data and trade secrets of the Clinic that it learns under this Agreement. In line with Article 12(4) of the Law, this obligation survives the termination of this Agreement or of the subscription for any reason, without any time limit.

3.2. OYOX shall ensure that its personnel and any persons it authorizes who have access to personal data are bound by an indefinite confidentiality undertaking that remains valid after their duties end, and shall inform such persons about the protection of personal data.

3.3. Access to personal data is granted only to personnel whose duties require it, within a role-based authorization framework, and access is monitored through audit logs (Annex 2).

3.4. Except where required by law (lawful requests of competent public authorities), OYOX shall not disclose personal data to any third party without the Clinic's instruction. In the event of such a mandatory request, the Clinic shall be informed immediately unless legally prohibited.

Article 4 — Data Security Measures

4.1. Pursuant to Article 12 of the Law, OYOX shall take all necessary technical and organizational measures to ensure an appropriate level of security in order to prevent unlawful processing of and unlawful access to personal data and to ensure their safekeeping. The measures are implemented on the basis of the Personal Data Security Guide (Technical and Organizational Measures) published by the Authority, and are set out in detail in Annex 2.

4.2. As the data processed on the Platform includes health data constituting special categories of personal data (hearing aid and audiological information, medical documents), OYOX applies measures consistent with the principles set out in Board Decision No. 2018/10 of 31 January 2018 on "Adequate Measures to Be Taken by Data Controllers in the Processing of Special Categories of Personal Data". These include, in particular, encrypted transmission (TLS), database-level encryption at rest, encrypted backups, two-factor authentication, a role-based authorization matrix and access logging, as specified in Annex 2.

4.3. OYOX updates its security measures in line with technological developments and legislation; no update may in any case reduce the level of protection committed to under this Agreement.

4.4. The Clinic is likewise obliged to take the measures required under Article 12 of the Law on its own side; the confidentiality of user accounts and passwords, the correct assignment of staff privileges and the monitoring of account activity on the Platform are the Clinic's responsibility. For the general retention and destruction framework, see the Retention and Destruction Policy.

Article 5 — Sub-processors

5.1. The Clinic consents to OYOX's use of the sub-processors listed in Annex 3 for the provision of the Service. OYOX enters into written agreements with its sub-processors imposing data protection obligations no less protective than those assumed by OYOX under this Agreement.

5.2. Where OYOX plans to add or replace a sub-processor, it shall notify the Clinic at least 15 days before the change takes effect. Notice is given via in-Platform announcement; to the extent e-mail delivery is technically in operation, notice is additionally sent to the Clinic's registered e-mail address.

5.3. The Clinic may object to a notified change within 15 days of the notice, on reasonable and substantiated grounds relating to the level of data protection. Where an objection is raised in time, the planned change shall not be applied to the objecting Clinic's data until the objection process is concluded. In case of objection, the parties shall seek a solution in good faith; if no reasonable solution is found, the Clinic may terminate the subscription without penalty, and the data return and destruction provisions of Article 10 shall apply.

5.4. OYOX is liable to the Clinic for the acts and omissions of its sub-processors to the same extent as it is liable for its own acts and omissions.

Article 6 — Personal Data Breach Notification

6.1. If the personal data processed are obtained by others through unlawful means, OYOX shall notify the Clinic immediately, and in any event no later than 24 hours after becoming aware of the breach. This deadline is set so that the Clinic, as data controller, can make its 72-hour breach notification to the Board in due time pursuant to Board Decision No. 2019/10 of 24 January 2019.

6.2. The notification is made via in-Platform notification and, to the extent e-mail delivery is technically in operation, additionally to the Clinic's registered e-mail address, and shall contain at least the following.

  • The nature of the breach and the time it occurred and was detected,
  • The categories of data and groups of data subjects affected and, where possible, the approximate number of records/persons,
  • The likely consequences of the breach,
  • The technical and organizational measures taken and proposed,
  • A contact point for further information (primarily the OYOX LLC (US) postal address; secondarily, once the e-mail infrastructure is in operation, kvkk@bluehams.com).

6.3. Where all information cannot be provided at the time of the initial notification, it shall be supplemented in phases without undue delay.

6.4. OYOX shall without delay take the measures necessary to limit the effects of the breach and prevent its recurrence, and shall provide all reasonable information and documentation to support the Clinic's notifications to the Board and, where required, to the data subjects. The obligation to notify the Board and the data subjects rests with the Clinic as data controller.

Article 7 — Audit Rights

7.1. The Clinic may audit OYOX's compliance with this Agreement once (1) per calendar year, subject to at least 10 business days' prior written notice, or may request written reports and documentation from OYOX demonstrating compliance.

7.2. Audits shall be conducted within a mutually agreed scope and methodology, during business hours and without disrupting the Service, and in a manner that does not compromise the confidentiality of other customers' data, tenant isolation or system security. Persons conducting the audit on behalf of the Clinic shall sign a confidentiality agreement with OYOX before the audit.

7.3. OYOX shall respond to reasonable requests for information and documentation within the scope of the audit; with respect to the technical infrastructure, the contractual limits of the sub-processor (hosting provider) are reserved. Unless otherwise agreed, the costs of the audit are borne by the Clinic.

7.4. Non-conformities identified during an audit shall be remedied by OYOX within a reasonable schedule agreed by the parties.

Article 8 — Data Subject Requests

8.1. Requests under Article 11 of the Law are addressed to the Clinic as data controller. If OYOX receives a request from a patient, a patient's relative or clinic staff concerning data covered by this Agreement, OYOX shall forward the request to the Clinic without delay and within 5 business days at the latest, and shall inform the requester that the request has been forwarded to the relevant clinic acting as data controller. OYOX shall not respond to the request on the merits without the Clinic's instruction.

8.2. OYOX shall provide reasonable assistance to enable the Clinic to respond to data subject requests within the 30-day period under Article 13 of the Law; to this end, the Platform provides functions for accessing, rectifying and deleting records relating to a data subject. For requests that cannot be met through Platform functions — including the provision of a machine-readable copy of the records relating to a data subject — OYOX provides technical support upon the Clinic's written request.

8.3. Guidance the Clinic may use when designing its own request-handling process is provided in Annex 4; the channel for requests addressed to OYOX in its own capacity as data controller is available on the KVKK Application Form page. For requests addressed to OYOX, the primary channel is, by post, the OYOX LLC (US) address, as set out in Section 1.4.

Article 9 — Data Location and International Transfers

9.1. Personal data processed under this Agreement are hosted on servers located in Istanbul, within the borders of the Republic of Türkiye (Annex 3). Backups are also kept, in encrypted form, on the same infrastructure.

9.2. OYOX's personnel responsible for system administration and technical operations are located in the United States and may remotely access the Platform infrastructure for maintenance, operation, security and technical support purposes. Under the Board's practice, remote access to systems from abroad — including viewing on screen — qualifies as an international transfer within the meaning of Article 9 of the Law; the parties enter into this Agreement with full awareness of this principle.

9.3. In order to place this access under safeguards compliant with the Law, the parties agree and undertake to execute, without any modification, the standard contract published by the Board for transfers from a data controller to a data processor, as an annex to this Agreement. The obligation to notify the Authority within 5 business days of execution of the standard contract is assumed by OYOX to the extent permitted by the applicable legislation; OYOX undertakes to make this notification in due time.

9.4. OYOX shall limit access from abroad to the minimum scope and persons strictly necessary for the operation of the Service and shall log such access. Beyond the operational access defined in Section 9.2, OYOX shall not carry out any new international transfer of the personal data covered by Annex 1 unless the appropriate safeguards provided for in Article 9 of the Law are in place.

9.5. If the factual situation regarding transfers changes, this Article and the Privacy Policy shall be updated and the Clinic shall be informed following the procedure in Section 5.2.

Article 10 — Term, Termination, Return and Destruction of Data

10.1. This Agreement enters into force upon establishment of the subscription relationship and remains in force for as long as the Terms of Service remain in effect.

10.2. Upon termination of the subscription for any reason, OYOX shall, at the Clinic's request and within a reasonable period, return the personal data recorded on the Platform to the Clinic in a commonly used, machine-readable format. The return request must be submitted within 30 days of the termination date.

10.3. After completion of the return process (or upon expiry of the 30-day period if no timely return request is received), OYOX shall permanently and irreversibly destroy the personal data on live systems. Copies in backups are automatically rotated out of the backup cycle within 14 days at the latest; during this period, backups are kept encrypted and are not used for any purpose other than restoration.

10.4. Upon the Clinic's request, OYOX shall issue and deliver to the Clinic a dated destruction record confirming that destruction has been carried out.

10.5. Cases where legislation requires OYOX to retain certain records (for example, security and transaction logs) for specific periods are reserved; such records are kept with restricted access, limited to the duration and scope required by the relevant legal obligation. For details, see the Retention and Destruction Policy.

Reminder — The return and destruction of data from the Platform does not remove the Clinic's own statutory retention obligations (including the minimum retention periods for patient records summarized in Annex 4). The Clinic is responsible for requesting the return of the data it needs before termination.

Article 11 — Liability

11.1. Under Article 12(2) of the Law, the Clinic (data controller) and OYOX (data processor) are jointly responsible for taking data security measures. Given the mandatory nature of this provision, any clause that entirely excludes or transfers a party's statutory responsibility towards the Authority or the data subjects is void; this Agreement shall not be interpreted to produce such a result.

11.2. In the internal relationship between the parties, liability is allocated in proportion to fault. If, due to one party's fault, an administrative sanction is imposed on the other party or the other party is required to pay compensation, the party at fault shall indemnify the other party, by way of recourse and in proportion to its fault, for the resulting loss.

11.3. The liability provisions of the Terms of Service apply to OYOX's liability under this Agreement to the extent they do not conflict with Sections 11.1 and 11.2.

11.4. OYOX shall not be held liable for consequences arising from the Clinic's breach of its own obligations (duty to inform, processing on a valid legal basis, user account security, staff authorization, compliance with retention periods).

Article 12 — Governing Law and Jurisdiction

12.1. This Agreement is governed by the laws of the Republic of Türkiye.

12.2. The Istanbul (Çağlayan) Courts and Enforcement Offices have exclusive jurisdiction over any dispute arising out of or in connection with this Agreement. As both parties are merchants, this jurisdiction clause is valid under Article 17 of the Turkish Code of Civil Procedure (Law No. 6100).

12.3. In the event of any conflict between this Agreement and the Terms of Service regarding the processing of personal data, the provisions of this Agreement prevail.

12.4. The invalidity of any provision of this Agreement does not affect the validity of the remaining provisions; the invalid provision shall be deemed replaced by a valid provision that most closely reflects the parties' intent.

Annex 1 — Categories of Data Processed and Groups of Data Subjects

The personal data processed by OYOX on behalf of the Clinic under this Agreement are listed below, based on the Platform's actual data fields. The Clinic is obliged to enter into the Platform only the data required for the Service.

Data categoryData fieldsData subject group
IdentityName, surname, Turkish ID number, date of birth, genderPatient
ContactTelephone number, addressPatient; guardian/relative if entered in contact records
Health (special category)Hearing aid brand, model, type and serial number; battery type; fitted ear (left/right/both); audiograms, reports and similar medical documents (PDF/JPG/PNG/DOC/XLS, max. 10 MB per record); technical service (device fault/repair) recordsPatient
FinancialPurchase status, payment and installment recordsPatient
TransactionAppointment date and time, patient transaction history, generated documents, free-text notes (patient and manager notes)Patient; guardian/relative if mentioned in notes
Communication recordsSMS reminder template content; delivery records that will arise if SMS delivery is activated (recipient telephone number and full text of the message sent)Patient
StaffStaff account details, attendance records, performance recordsClinic staff
As of today, the Platform's SMS feature operates at template-management level only; actual SMS delivery is not yet active (see Annex 3). Once delivery is activated, the delivery records above will start to be created and will be subject to the automated anonymization routine in Annex 2.

Data subject groups fall into three categories. First, the Clinic's patients. Second, guardians and relatives contacted on behalf of a patient or mentioned in records; whether records for minors and persons under guardianship are kept together with guardian details is at the Clinic's discretion. Third, the Clinic's staff who use the Platform.

The content entered into free-text fields (notes, message templates) is under the Clinic's control. Under the data minimization principle, the Clinic should not enter special categories of data into these fields beyond what the Service requires.

Annex 2 — Technical and Organizational Measures

The measures actually implemented by OYOX on the Platform and the organizational commitments assumed under this Agreement are listed below. The list is structured on the basis of the Personal Data Security Guide and Board Decision No. 2018/10.

Technical Measures

  • Encryption in transit: All traffic is encrypted with TLS 1.2/1.3; HTTP requests are redirected to HTTPS; HSTS (max-age 31536000) is enforced.
  • Encryption at rest: The database (MySQL InnoDB) is protected with tablespace-level encryption at rest; encryption keys are managed via a keyring.
  • Encrypted backups: Backups are encrypted with AES-256-CBC and PBKDF2 key derivation; they are retained on a 14-day cycle; an automatic backup is taken before each deployment.
  • Authentication: Passwords are stored with irreversible hashing; a password policy is enforced; two-factor authentication (TOTP) and recovery codes are available.
  • Session security: Strict session mode; httponly, Secure and SameSite=Lax cookie attributes; automatic session termination after 30 minutes of inactivity.
  • Application security: Prepared statements for all database queries; fail-closed CSRF protection; output escaping; nonce-based Content Security Policy (CSP).
  • File upload security: MIME type whitelist (server-side content verification), server-generated random file names, 10 MB size limit.
  • Attack prevention: Brute-force protection through failed-login tracking; fail2ban and SSH hardening at server level; defense in depth at the nginx layer with sensitive path and extension blocking; Docker container isolation.
  • Tenant isolation: Every query is filtered by clinic account; no Clinic can access another Clinic's data.
  • Automated data minimization: SMS records are anonymized after 180 days (telephone number masked, message body cleared); this routine will apply equally to records created once SMS delivery is activated. Audit records are deleted after 730 days (2 years); deleted records are managed via a trash (soft-delete) mechanism subject to a permanent destruction routine.

Organizational Measures

  • Role-based authorization: Administrator, clinic owner and staff roles; access is limited to the scope of each role's duties.
  • Audit trail: A user activity history and a separate administrator audit log are maintained.
  • Indefinite confidentiality: Personnel with access to personal data are placed under an indefinite confidentiality undertaking that survives the end of their duties, in accordance with Article 3.
  • Processing on instructions and purpose control: The prohibitions in Article 2 are enforced through internal processes.
  • Breach response: Detection and notification of personal data breaches are carried out within the framework of the 24-hour notification commitment in Article 6.
OYOX develops its measures under a continuous improvement approach. This annex contains the technical measures actually implemented and the organizational commitments assumed under this Agreement; no certification or measure not stated here is claimed or warranted.

Annex 3 — List of Sub-processors

The sub-processors used by OYOX as of the execution (acceptance) date of this Agreement are listed below.

Sub-processorServiceProcessing locationScope
Hostingdünyam — CNC Bilişim Hizmetleri Ltd. Şti.Virtual server (VDS) hostingIstanbul, TürkiyeAll data processed on the Platform and encrypted backups are hosted on this infrastructure
Note on the SMS provider: Actual delivery for the Platform's SMS reminder feature is not yet active. When actual SMS delivery is activated, the SMS provider to be used will be added to this list and the Clinic will be notified in accordance with Section 5.2 (at least 15 days in advance).
Note on content delivery networks (CDN): All static front-end components of the Platform interface (including fonts, icon and charting libraries) are served locally from the Platform's own server; no resource is loaded from any external CDN and user IP addresses are not transmitted to any third party for this purpose. These components are outside the scope of sub-processing.

Changes to this list are subject to Article 5. The current list is published on this page at all times.

Annex 4 — Information Note on the Clinic's KVKK Obligations and Sample Patient Privacy Notice

This annex is an information note intended to guide the Clinic in its capacity as data controller; it does not constitute legal advice. The Clinic should assess its own processes with its own legal counsel.

1. Duty to Inform (KVKK Article 10)

The duty to inform patients about the processing of their personal data rests with the Clinic. Under Board Decision No. 2020/71, the duty to inform may also be fulfilled through the data processor; however, responsibility remains with the data controller. The template below may be used for this purpose.

2. Legal Basis

The principal legal basis available to the Clinic for processing patient health data is the health exception in Article 6(2)(e) of the KVKK. Accordingly, health data may be processed without explicit consent by persons under a duty of confidentiality for the purposes of medical diagnosis, treatment and care services, and for the planning, management and financing of health services. Processing outside this scope (for example, marketing communications) requires a separate legal basis and, where applicable, explicit consent; explicit consent may never be made a precondition of the service.

3. The Written Patient Registry Obligation Continues

Under the Turkish Regulation on Custom-Made Prosthesis and Orthosis Centers and Hearing Aid Centers, the obligation of centers to keep a written patient registry remains in force. BLUEHAMS does not replace this registry; it provides a supporting electronic system and enables the generation of printable output. You must continue to fulfil your official registry obligation separately.

4. Retention Periods

  • For health records, a minimum retention period of at least 5 years should be observed as the regulatory baseline.
  • For centers contracted with the Turkish Social Security Institution (SGK), a minimum retention of 10 years applies to the relevant records.
  • Under Article 11(2) of the Turkish Regulation on Personal Health Data, health records are retained for at least 20 years after the data subject's death.
  • Destruction of records whose retention period has expired is governed by the Clinic's own retention and destruction policy; confirm the current periods with your legal counsel.

5. VERBIS Registration

The obligation to register with the Data Controllers' Registry (VERBIS) and the criteria for exemption from it are determined by Board decisions and are updated from time to time. The Board may provide a registration exemption for data controllers that remain below a certain annual number of employees and a certain annual balance sheet total. Nevertheless, the following points require the Clinic's attention. First, the exemption criteria must be confirmed from the current Board decision in force; whether the criteria are met is assessed according to the Clinic's own employee numbers and financial data. Second, a registration exemption concerns only the obligation to register with the Registry; it does not remove the obligations to inform, to ensure data security, to maintain a personal data processing inventory and to respond to data subject requests. Third and most importantly, Board decisions generally exclude from the registration exemption those data controllers whose main activity is the processing of special categories of personal data; as hearing aid centers, by the nature of their activity, process health data (special categories of personal data) intensively, an obligation to register with VERBIS may arise even if they meet the employee and balance sheet thresholds. The Clinic is therefore strongly advised to confirm its own registration/exemption status in light of the current Board decisions and with its own legal counsel. OYOX does not state any specific threshold value or decision number in this information note; the Clinic must rely on the current legislation.

6. Data Subject Requests

You are obliged to respond to your patients' requests under Article 11 of the KVKK within 30 days at the latest, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller (Article 5). Patient requests received by BLUEHAMS are forwarded to you in accordance with Article 8.

Sample Patient Privacy Notice Template

You may use the template below by completing the bracketed fields and adapting it to your own processes.

[CLINIC NAME] Patient Privacy Notice

>

This notice has been prepared pursuant to Article 10 of Turkish Law No. 6698 on the Protection of Personal Data by [CLINIC NAME, address, MERSIS/tax number] acting as data controller.

>

Personal data processed: Your identity data (name, surname, Turkish ID number, date of birth, gender), contact data (telephone, address), health data (hearing aid brand/model/serial information, fitted ear, your audiograms and reports, technical service records), financial data (payment and installment records) and your appointment and transaction history.

>

Purposes of processing: Provision of hearing aid sales and fitting services, conduct of medical assessment and device fitting processes, appointment and reminder communications, tracking of device technical service processes, execution of collection and accounting operations, and fulfilment of statutory record-keeping obligations.

>

Legal bases: Your health data is processed under Article 6(2)(e) of the KVKK by our personnel bound by a duty of confidentiality, for the purpose of conducting medical diagnosis, treatment and care services; your other data is processed under Article 5(2)(c) (establishment and performance of a contract), Article 5(2)(ç) (compliance with our legal obligations) and Article 5(2)(e) (establishment, exercise or protection of a right) of the KVKK.

>

Transfers and data processor: Your records are kept in the BLUEHAMS clinic management software (OYOX LLC), which we use as data processor; the data is hosted on servers located in Istanbul, Türkiye. A limited number of the software provider's technical personnel located abroad may remotely access the records for the operation and maintenance of the system; such access is conducted within the framework of the appropriate safeguards under Article 9 of the KVKK (the standard contract published by the Turkish Personal Data Protection Board). Your data may also be transferred to competent public authorities within the scope of our legal obligations.

>

Method of collection: Your data is collected verbally and in writing during application and examination processes, through forms and documents, and by recording in the clinic management software, by partially automated means.

>

Your rights: You may exercise your rights under Article 11 of the KVKK (including requesting information, rectification, erasure, learning the third parties to whom data has been transferred, and claiming compensation for damages) via [CLINIC application channel — address/e-mail/registered e-mail (KEP)]. Your requests will be concluded within 30 days at the latest.
This template is generic; it must be adapted to your Clinic's actual processes (for example, whether you use SMS delivery, and how you keep guardian records).
BLUEHAMS Stock, patient, technical service and collection management for hearing aid centres.

Cloud-based management software that brings patient tracking, inventory, technical service and collections together in one panel for hearing aid centers.

  • Data hosted in Türkiye
  • KVKK-aligned contract framework
  • Encrypted daily backups
Request a Demo
Sign In Sign Up

Product

Modules Features How It Works Pricing FAQ

Account

Sign In Sign Up Request a Demo

Legal

Privacy & Legal Center Privacy Notice Privacy Policy Cookie Policy Terms of Service Data Processing Agreement

Contact

OYOX LLC
1209 Mountain Road PL NE, STE N
Albuquerque, NM 87110, United States
kvkk@bluehams.com LLC registered in New Mexico (USA) · Registration No 0008084103
© 2026 OYOX LLC — BLUEHAMS. All rights reserved. BLUEHAMS is a product of OYOX LLC (New Mexico, USA).
BLUEHAMS