CEVIZ PRIVACY POLICY AND PERSONAL DATA PROCESSING DISCLOSURE
🇹🇷 TürkçeNote: This document is an English translation provided for convenience. In the event of any discrepancy, the Turkish version prevails: Gizlilik Politikası (Türkçe).
1. IDENTITY OF THE DATA CONTROLLER
In the capacity of data controller under the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and the EU General Data Protection Regulation (“GDPR”):
| Trade Name | Ceviz Biyoteknoloji Anonim Şirketi |
| Short Name | “Ceviz” or the “Company” |
| Address | Çalca OSB Mahallesi, 1. Cadde, Tasarım Teknokent A.Ş. No:1 İç Kapı No:3, Merkez/Kütahya, Türkiye |
| Tax Office | Çinili |
| Tax ID No | 2071296229 |
| Field of Activity | Research and experimental development in biotechnology (NACE 721002) |
| info@cevizbiotech.com |
2. PURPOSE AND SCOPE
This Privacy Policy (the “Policy”) has been prepared in order to fulfil our disclosure obligation regarding personal data processed through the Ceviz mobile application (the “Application”), developed by Ceviz and distributed via the App Store and Google Play Store.
The Policy applies within the framework of the KVKK, the GDPR, Law No. 6563 on the Regulation of Electronic Commerce and the relevant secondary legislation.
By downloading the Application, creating an account or using it, you acknowledge that you have read and understood the data processing activities set out in this Policy.
3. DEFINITIONS
| Term | Description |
|---|---|
| User | The dentist, healthcare professional or authorised natural person who creates an account in order to use the Application |
| Doctor | A User holding the “doctor” role; authorised to create and manage cases |
| Admin | An authorised Company employee holding the “admin” role who provides engineering and technical support services within Ceviz |
| Case | The clinical request and related files created by a Doctor and stored under an anonymous system code |
| Anonymous System Code | The identifier automatically generated by the system for each case in the format #CVZ-XXXXXXXX (see Article 6) |
| Personal Data | Any information relating to an identified or identifiable natural person |
| Processing | Any operation such as obtaining, recording, storing, altering, disclosing, transferring, classifying or erasing personal data |
4. CATEGORIES OF PERSONAL DATA PROCESSED
In order to deliver the functionality of the Application, Ceviz processes the following categories of data:
4.1. Account and Identity Data
- First name, last name
- E-mail address
- Password (stored cryptographically hashed by Firebase Authentication; Ceviz cannot access the plain-text form of your password)
- Profile photo (optional)
4.2. Professional Data
- Title (Dr., DDS, Prof. Dr., etc.)
- Profession / field of specialisation
4.3. Case and Related Health Data
- The anonymous case code automatically generated by the system (
#CVZ-XXXXXXXX) — the Doctor cannot change this code or enter their own patient alias - Case description entered by the Doctor (free text)
- Uploaded files: DICOM (.dcm/.dicom), 3D model files (.glb), archives (.zip, .rar), PDF documents (.pdf), images (.jpg, .png)
- The system record indicating whether the uploaded file is anonymised (the
isAnonymizedfield) - The record of the Doctor’s declaration that patient consent has been obtained (the
hasPatientConsentfield) and the date on which the declaration was made (theconsentDeclaredAtfield) - Case status, creation date and feedback
Important: The Application does not request any direct identifying data of patients — such as name, surname, national ID number, date of birth or contact details — and it is the Doctor’s responsibility not to enter such data into the system (see Article 12). The only identifier used for a patient is the anonymous code automatically generated by the system.
4.4. Technical and Device Data
- Device model, operating system version
- Application version
- Crash reports and error logs
- IP address (solely for security and App Check verification purposes)
4.5. Notification Data
- Firebase Cloud Messaging (FCM) push notification token — stored under the
/users/{userId}document in order to send case status updates to your device
4.6. Usage Data
- Sign-in / sign-out times
- In-app navigation statistics (aggregated)
5. PURPOSES AND LEGAL BASES OF PROCESSING
| Data Category | Purpose of Processing | KVKK Legal Basis (Art. 5/6) | GDPR Legal Basis (Art. 6) |
|---|---|---|---|
| Account and Identity (4.1) | Account creation, authentication, provision of the service | Establishment and performance of a contract (Art. 5/2-c) | Performance of a contract (Art. 6/1-b) |
| Professional Data (4.2) | Verification of the professional user base, suitability for the nature of the service | Legitimate interest (Art. 5/2-f) | Legitimate interest (Art. 6/1-f) |
| Case Data (4.3) | Technical fulfilment of the 3D implant and prosthesis design request | Performance of a contract + explicit consent (Art. 5/1) | Performance of a contract (Art. 6/1-b) + explicit consent (Art. 9/2-a) |
| Technical Data (4.4) | Ensuring application stability, troubleshooting, security | Legitimate interest (Art. 5/2-f) | Legitimate interest (Art. 6/1-f) |
| FCM Token (4.5) | Case status notifications | Explicit consent (Art. 5/1) — notification permission is obtained at device level | Explicit consent (Art. 6/1-a) |
| Usage Data (4.6) | Improving service quality | Legitimate interest (Art. 5/2-f) | Legitimate interest (Art. 6/1-f) |
Since files uploaded within a case may contain “special categories of personal data” (health data) within the meaning of Article 6 of the KVKK, the Doctor is obliged to obtain written/electronic explicit consent from their patient. This consent is obtained in a process outside of Ceviz (within the doctor–patient relationship) and the original copy of the signed document is kept in the Doctor’s own archive. The Doctor expressly declares in the “Provide Consent Declaration” step within the Application that such consent has been obtained; this declaration, together with its date, is permanently recorded in Firestore in the hasPatientConsent and consentDeclaredAt fields and cannot be withdrawn. As Ceviz does not communicate directly with the patient and never collects patient identity information, the responsibility and burden of proof that consent was in fact obtained rests with the Doctor (see Article 12.1).
6. PRIVACY BY DESIGN PRINCIPLE AND ANONYMISATION
Ceviz has been developed on the “Privacy by Design” principle. The following technical measures are applied in order to protect patient privacy:
6.1. Anonymous System Code Generation Each time a new case is created, the system automatically generates an anonymous identifier in the format #CVZ-XXXXXXXX. This code:
- Is derived from a cryptographically random value based on the UUID v4 standard
- Is an 8-character one-way identifier
- Has no mathematical relationship whatsoever with the patient’s real identity in Ceviz’s database
- Has a practically zero probability of collision
6.2. Automatic DICOM Anonymisation All DICOM (.dcm) files uploaded by the Doctor are automatically anonymised by the Application before being uploaded to the server. Metadata contained in the header of DICOM files that could reveal the patient’s identity — such as patient name, date of birth, national ID number, hospital information, doctor name and scan date — is cleaned by the DicomSanitizer module. Only the cleaned file is uploaded to Firebase Storage; the original file is not retained on the device for long either, and the temporary file is deleted after anonymisation.
6.3. The Doctor’s Anonymisation Declaration When uploading file types other than DICOM (JPG, PNG, PDF, ZIP, RAR, GLB), the Doctor expressly declares and undertakes within the system that the file does not contain the patient’s direct identity information. A file cannot be uploaded without this declaration.
6.4. Data Minimisation The Application does not request any personal data that is not necessary for the provision of the service. Patient identity information, contact details and insurance information are not collected by the Application.
6.5. Separation of Account and Case Data Doctor account information and case data are held in different collections in Firestore, and layered access is ensured through authorisation rules (Firestore Security Rules and Storage Security Rules). Under no circumstances can one Doctor access another Doctor’s cases. Only authorised Admin users providing engineering services within Ceviz Company may access doctors’ cases for the purpose of providing the service (see Article 10.1).
7. DEVICE PERMISSIONS
In order to perform its functions, the Application requests the following device permissions:
| Permission | Purpose | Mandatory? |
|---|---|---|
| Photo/Media Access (READ_MEDIA_IMAGES) | Uploading a profile photo and selecting medical images/files for a case | Required in order to upload files to a case |
| Notifications (POST_NOTIFICATIONS) | Delivering case status updates (“Your model is ready”, etc.) | Optional; you may decline |
| Internet Access | Data synchronisation with Firebase | Mandatory |
| Network State | Connectivity check and offline warnings | Mandatory |
Our Application does not request CAMERA permission and does not access your device camera. Existing images are uploaded by selecting them from the device gallery.
8. DATA SECURITY MEASURES
Ceviz applies the following administrative and technical measures to ensure the security of personal data:
Technical Measures:
- Encryption in transit: All data traffic is encrypted with the TLS 1.2+ protocol
- Encryption in storage: All data on Firebase Storage and Firestore is encrypted at rest with AES-256
- Automatic DICOM anonymisation: All uploaded DICOM files are stripped of patient metadata before being transferred to the server (see Article 6.2)
- Firebase App Check: All requests made to the Application are verified with Play Integrity (Android) and App Attest (iOS); access to data by fraudulent clients is blocked
- Firestore Security Rules and Storage Security Rules: With layered access control, each user can access only their own data; apart from the Admin role, no user can read another user’s case or file
- Password security: Passwords are hashed by Firebase Authentication using the scrypt algorithm; Ceviz cannot access passwords in plain text
- Error monitoring: Crashlytics collects technical logs stripped of personally identifying information
Administrative Measures:
- Written Confidentiality and Personal Data Protection Undertakings have been signed with Company employees (Admins)
- Data access is organised according to the “need-to-know” principle
- A data breach response procedure has been established
- Employees remain under an indefinite confidentiality obligation even after leaving their positions
9. DATA RETENTION PERIODS
Ceviz retains personal data only for as long as is necessary for the purpose of processing. The general principle is as follows: your data is retained for as long as your account is active; when you delete your account, all of your data is permanently erased.
| Data Type | Retention Period |
|---|---|
| Account and identity data | For as long as the account is active |
| Case data (DICOM, models, images, case records) | For as long as the account is active; automatically deleted when the account is deleted |
| Cases archived by the Doctor | Retained unless deleted by the Doctor, or for as long as the account is active |
| Account deletion | Initiated immediately; all Firestore records, Storage files (raw uploads and processed models) and the Authentication record are deleted |
| Firebase backups | Removed from Firebase’s infrastructure backups within a maximum of 180 days after deletion |
| Crashlytics logs | Automatically deleted after 90 days |
| Data retained due to legal obligations | A maximum of 10 years for reasons such as tax legislation (invoice/contract data only; not patient health data) |
Important: Account deletion is irreversible. After deleting your account, you will no longer have access to your cases, the files you uploaded, or the 3D models produced by the Admin.
10. TRANSFER OF PERSONAL DATA
10.1. Domestic Transfer
Your personal data is transferred to authorised Admin users working within Ceviz for the purpose of providing the service. This transfer takes place because the engineering service is provided by Ceviz’s own team; there is no transfer to a third-party engineer.
10.2. International Transfer
The Application uses Google Firebase services as its infrastructure. For the purposes of KVKK and GDPR compliance, Firebase data is hosted within the borders of the European Union, in the europe-west3 region located in Frankfurt/Germany. The reasons for choosing this region are:
- It falls within the scope of an adequacy decision of the EU Commission
- The data of citizens of the Republic of Türkiye is processed under EU GDPR protection
- It has the status of a country with adequate protection under Article 9 of the KVKK
The service provider Google Ireland Limited acts as a data processor within the framework of GDPR-compliant Standard Contractual Clauses (SCC).
Post-MVP commitment: Ceviz undertakes to move its server infrastructure to Türkiye following the completion of the product’s commercialisation process.
11. THIRD-PARTY SERVICE PROVIDERS
The following Google/Firebase services are used in the capacity of “data processor”:
| Service | Purpose | Data Processed | Location |
|---|---|---|---|
| Firebase Authentication | Account management and authentication | E-mail, hashed password | europe-west3 |
| Cloud Firestore | Structured data (cases, profiles) | The data listed in Article 4 | europe-west3 |
| Firebase Storage | File storage (DICOM, models, images) | Case files | europe-west3 |
| Firebase Cloud Messaging (FCM) | Push notification delivery | FCM token, notification content | Global (Google infrastructure) |
| Firebase App Check | Blocking fraudulent clients | Device integrity token | Global |
| Firebase Crashlytics | Error monitoring | Anonymous technical logs | Global |
| Cloud Functions | Notification triggering and background jobs | Depends on the operation | europe-west3 |
Google’s privacy policy: https://policies.google.com/privacy
Firebase data processing terms: https://firebase.google.com/terms/data-processing-terms
The Application does not use advertising networks, third-party analytics or marketing service providers.
12. RESPONSIBILITIES OF THE USER (DOCTOR)
The Doctor accepts the following obligations when using the Application:
12.1. Patient Consent (Explicit Consent) After creating a case, the Doctor is obliged to obtain the necessary explicit consent from their patient in writing or electronically, in accordance with Article 6 of the KVKK and the relevant healthcare legislation, so that the service can operate fully. In order to make things easier for the Doctor, Ceviz provides a downloadable “Informed Patient Consent Form” template within the Application; however, the Doctor may also use another consent form of their own choosing. Whichever form is used, the original copy of the signed consent document is kept in the Doctor’s own archive and must be presented by the Doctor in the event of a KVKK audit.
The Doctor who has obtained consent formally declares within the system, via the “Provide Consent Declaration” step in the Application, that such consent has been obtained. This declaration is permanently recorded in Firestore together with the timestamp of the moment it was made; once given, the declaration cannot be withdrawn. As Ceviz has no direct contact with the patient and never collects patient identity information, the accuracy of this declaration is the exclusive responsibility of the Doctor.
12.2. File Anonymity Declaration Where the Doctor uploads a file other than DICOM (JPG, PNG, PDF, ZIP, RAR, GLB) when creating a case, the Doctor expressly declares and undertakes, via the confirmation checkbox in the system, that the file does not contain the patient’s direct identity information (name and surname, national ID number, clearly visible facial photograph, etc.). A file cannot be uploaded without this declaration. As DICOM files are automatically anonymised by the system, they do not require a separate declaration (see Article 6.2).
12.3. Identity Confidentiality in Case Descriptions The Doctor is obliged not to enter information that would disclose the patient’s direct identity (name and surname, national ID number, telephone number, address, etc.) in case descriptions or in the names of uploaded files.
12.4. Account Security The Doctor is obliged to keep their account password confidential, not to share it with third parties, and to change their password immediately if unauthorised access to their account is suspected.
12.5. Lawful Use The Doctor is exclusively responsible for the method of obtaining, the content and the lawfulness of the data they upload to the Application.
In the event of a breach of these obligations, the resulting legal liability rests exclusively with the Doctor; Ceviz bears no liability. The Doctor is obliged to indemnify Ceviz for any damages arising from such a breach.
13. CHILDREN’S PERSONAL DATA
The Ceviz Application is intended solely for the use of healthcare professionals over the age of 18. Ceviz does not knowingly collect data from individuals under the age of 18 as account users. Where it is determined that a user under the age of 18 has created an account, the relevant account and data are deleted immediately.
The age of the patient to whom the medical data uploaded to the system by the Doctor belongs may be an exception to this rule; however, since Ceviz never collects patient identity information, the patient’s age or identity is not known to Ceviz. Ensuring the anonymity of patient data and obtaining consent from the patient’s legal representative (where applicable) is the Doctor’s responsibility (see Article 12).
14. DATA SUBJECT RIGHTS (KVKK ART. 11 AND GDPR)
Under Article 11 of the KVKK and the GDPR, you have the following rights as a data subject:
- To learn whether your personal data is being processed
- To request information if your personal data has been processed
- To learn the purpose of processing of your personal data and whether it is used in accordance with that purpose
- To know the third parties, domestically or abroad, to whom your personal data is transferred
- To request the rectification of your personal data where it has been processed incompletely or inaccurately
- To request the erasure or destruction of your personal data within the conditions set out in Article 7 of the KVKK
- To request that the operations carried out under items (5) and (6) be notified to the third parties to whom your personal data has been transferred
- To object to an adverse outcome arising against you as a result of the analysis of your processed data exclusively by automated systems
- To claim compensation for damages where you suffer loss due to the unlawful processing of your personal data
Additionally, under the GDPR:
- Right to data portability — to receive your data in a structured format
- Right to object to processing
- Right to restriction of processing
- Right to lodge a complaint with a supervisory authority — the Personal Data Protection Authority (KVKK) for Türkiye, and the relevant national supervisory authority for the EU
How to Apply
To exercise these rights, you may choose one of the following methods:
- E-mail: info@cevizbiotech.com (subject: “KVKK Data Subject Request”)
- Written application: Çalca OSB Mahallesi, 1. Cadde, Tasarım Teknokent A.Ş. No:1 İç Kapı No:3, Merkez/Kütahya
- In-app: Profile > Edit Profile > Delete My Account
Your application will be answered free of charge within a maximum of 30 days. Where the application is assessed as unfounded, a fee may be charged in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller.
15. DATA BREACH NOTIFICATION
In the event that your personal data is subject to a data breach such as unauthorised access, disclosure, alteration, loss or destruction, Ceviz will:
- Notify the Personal Data Protection Board within 72 hours pursuant to Article 12/5 of the KVKK
- Notify the competent supervisory authority within 72 hours pursuant to Article 33 of the GDPR
- Inform you without undue delay via in-app notification and e-mail where the breach poses a high risk to your rights and freedoms
16. ACCOUNT AND DATA DELETION
You have full control over your data:
16.1. Case Archiving The Doctor may archive individual cases in order to keep the active case list tidy. Archived cases are removed from the Doctor’s active list, but the Doctor may restore them from the archive if desired. Archiving is not a deletion operation; the data continues to be retained until the account is deleted.
16.2. In-App Account Deletion You can delete your account by following the steps Profile > Edit Profile > Delete My Account. When the account deletion process is initiated, the system carries out the following steps immediately and irreversibly:
- All of your raw case files in Firebase Storage (
uploads/{userId}/...) are deleted - All processed 3D model files belonging to you in Firebase Storage (
processed_models/{userId}/...) are deleted - All of your case records in Firestore (active and archived) are deleted
- Your user profile document in Firestore is deleted
- Your Firebase Authentication record is deleted
- You are automatically signed out of the Application
16.3. Request by E-mail If you do not have access to the in-app deletion method, you may initiate the deletion process by sending a request to info@cevizbiotech.com. Your request will be processed within a maximum of 7 days.
16.4. Deletion from Backups Due to Firebase’s infrastructure backups, your deleted data is completely removed from Google’s backup layers within a maximum of 180 days. During this period, the backups can be accessed only by Google for disaster recovery purposes; no party, including Ceviz, can access these backups.
16.5. Irreversibility of the Operation Account deletion is irreversible. The cases, files or 3D models you delete cannot be recovered under any circumstances. We recommend that you download any files you may need to your own device before initiating the operation.
17. COOKIES AND SIMILAR TECHNOLOGIES
Our mobile application does not use “cookies” in the classic sense used on websites. However, the Firebase SDKs store temporary identifiers (tokens) in device memory for session management and App Check. These identifiers are not used for advertising or tracking purposes.
18. ABOUT THE APP STORES
The Ceviz Application is distributed via the Apple App Store and Google Play Store. When you download the Application, the privacy policy and terms of service of the relevant store also apply:
- Apple Privacy Policy: https://www.apple.com/legal/privacy/
- Google Play Privacy Policy: https://policies.google.com/privacy
Data relating to your store account (download history, payment information, etc.) is processed directly by the relevant store; Ceviz has no access to this data.
19. CHANGES TO THE POLICY
Ceviz may update this Policy from time to time. Where significant changes are involved:
- The new version is published within the Application and at https://cevizapp.web.app
- All active users are informed via push notification and/or e-mail
- A 30-day transition period is granted before material changes take effect
It is the User’s responsibility to keep track of the current version of the Policy.
20. GOVERNING LAW AND COMPETENT COURTS
The laws of the Republic of Türkiye apply to the interpretation and application of this Policy. The Courts and Enforcement Offices of Kütahya shall have jurisdiction over any disputes that may arise. Data subjects residing in the EU reserve their right to lodge a complaint with the supervisory authority of the member state in which they are located.
21. CONTACT
For any questions, requests and complaints regarding this Policy or your personal data:
Ceviz Biyoteknoloji A.Ş.
Çalca OSB Mahallesi, 1. Cadde, Tasarım Teknokent A.Ş. No:1 İç Kapı No:3, Merkez/Kütahya, Türkiye
E-mail: info@cevizbiotech.com
This Policy entered into force on April 13, 2026.