CEVIZ PRIVACY POLICY AND PERSONAL DATA PROCESSING DISCLOSURE

Effective Date: April 13, 2026    Last Updated: April 13, 2026    Version: 2.3

🇹🇷 Türkçe

Note: This document is an English translation provided for convenience. In the event of any discrepancy, the Turkish version prevails: Gizlilik Politikası (Türkçe).

1. IDENTITY OF THE DATA CONTROLLER

In the capacity of data controller under the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and the EU General Data Protection Regulation (“GDPR”):

Trade NameCeviz Biyoteknoloji Anonim Şirketi
Short Name“Ceviz” or the “Company”
AddressÇalca OSB Mahallesi, 1. Cadde, Tasarım Teknokent A.Ş. No:1 İç Kapı No:3, Merkez/Kütahya, Türkiye
Tax OfficeÇinili
Tax ID No2071296229
Field of ActivityResearch and experimental development in biotechnology (NACE 721002)
E-mailinfo@cevizbiotech.com

2. PURPOSE AND SCOPE

This Privacy Policy (the “Policy”) has been prepared in order to fulfil our disclosure obligation regarding personal data processed through the Ceviz mobile application (the “Application”), developed by Ceviz and distributed via the App Store and Google Play Store.

The Policy applies within the framework of the KVKK, the GDPR, Law No. 6563 on the Regulation of Electronic Commerce and the relevant secondary legislation.

By downloading the Application, creating an account or using it, you acknowledge that you have read and understood the data processing activities set out in this Policy.


3. DEFINITIONS

TermDescription
UserThe dentist, healthcare professional or authorised natural person who creates an account in order to use the Application
DoctorA User holding the “doctor” role; authorised to create and manage cases
AdminAn authorised Company employee holding the “admin” role who provides engineering and technical support services within Ceviz
CaseThe clinical request and related files created by a Doctor and stored under an anonymous system code
Anonymous System CodeThe identifier automatically generated by the system for each case in the format #CVZ-XXXXXXXX (see Article 6)
Personal DataAny information relating to an identified or identifiable natural person
ProcessingAny operation such as obtaining, recording, storing, altering, disclosing, transferring, classifying or erasing personal data

4. CATEGORIES OF PERSONAL DATA PROCESSED

In order to deliver the functionality of the Application, Ceviz processes the following categories of data:

4.1. Account and Identity Data

4.2. Professional Data

Important: The Application does not request any direct identifying data of patients — such as name, surname, national ID number, date of birth or contact details — and it is the Doctor’s responsibility not to enter such data into the system (see Article 12). The only identifier used for a patient is the anonymous code automatically generated by the system.

4.4. Technical and Device Data

4.5. Notification Data

4.6. Usage Data


Data CategoryPurpose of ProcessingKVKK Legal Basis (Art. 5/6)GDPR Legal Basis (Art. 6)
Account and Identity (4.1)Account creation, authentication, provision of the serviceEstablishment and performance of a contract (Art. 5/2-c)Performance of a contract (Art. 6/1-b)
Professional Data (4.2)Verification of the professional user base, suitability for the nature of the serviceLegitimate interest (Art. 5/2-f)Legitimate interest (Art. 6/1-f)
Case Data (4.3)Technical fulfilment of the 3D implant and prosthesis design requestPerformance of a contract + explicit consent (Art. 5/1)Performance of a contract (Art. 6/1-b) + explicit consent (Art. 9/2-a)
Technical Data (4.4)Ensuring application stability, troubleshooting, securityLegitimate interest (Art. 5/2-f)Legitimate interest (Art. 6/1-f)
FCM Token (4.5)Case status notificationsExplicit consent (Art. 5/1) — notification permission is obtained at device levelExplicit consent (Art. 6/1-a)
Usage Data (4.6)Improving service qualityLegitimate interest (Art. 5/2-f)Legitimate interest (Art. 6/1-f)

Since files uploaded within a case may contain “special categories of personal data” (health data) within the meaning of Article 6 of the KVKK, the Doctor is obliged to obtain written/electronic explicit consent from their patient. This consent is obtained in a process outside of Ceviz (within the doctor–patient relationship) and the original copy of the signed document is kept in the Doctor’s own archive. The Doctor expressly declares in the “Provide Consent Declaration” step within the Application that such consent has been obtained; this declaration, together with its date, is permanently recorded in Firestore in the hasPatientConsent and consentDeclaredAt fields and cannot be withdrawn. As Ceviz does not communicate directly with the patient and never collects patient identity information, the responsibility and burden of proof that consent was in fact obtained rests with the Doctor (see Article 12.1).


6. PRIVACY BY DESIGN PRINCIPLE AND ANONYMISATION

Ceviz has been developed on the “Privacy by Design” principle. The following technical measures are applied in order to protect patient privacy:

6.1. Anonymous System Code Generation Each time a new case is created, the system automatically generates an anonymous identifier in the format #CVZ-XXXXXXXX. This code:

6.2. Automatic DICOM Anonymisation All DICOM (.dcm) files uploaded by the Doctor are automatically anonymised by the Application before being uploaded to the server. Metadata contained in the header of DICOM files that could reveal the patient’s identity — such as patient name, date of birth, national ID number, hospital information, doctor name and scan date — is cleaned by the DicomSanitizer module. Only the cleaned file is uploaded to Firebase Storage; the original file is not retained on the device for long either, and the temporary file is deleted after anonymisation.

6.3. The Doctor’s Anonymisation Declaration When uploading file types other than DICOM (JPG, PNG, PDF, ZIP, RAR, GLB), the Doctor expressly declares and undertakes within the system that the file does not contain the patient’s direct identity information. A file cannot be uploaded without this declaration.

6.4. Data Minimisation The Application does not request any personal data that is not necessary for the provision of the service. Patient identity information, contact details and insurance information are not collected by the Application.

6.5. Separation of Account and Case Data Doctor account information and case data are held in different collections in Firestore, and layered access is ensured through authorisation rules (Firestore Security Rules and Storage Security Rules). Under no circumstances can one Doctor access another Doctor’s cases. Only authorised Admin users providing engineering services within Ceviz Company may access doctors’ cases for the purpose of providing the service (see Article 10.1).


7. DEVICE PERMISSIONS

In order to perform its functions, the Application requests the following device permissions:

PermissionPurposeMandatory?
Photo/Media Access (READ_MEDIA_IMAGES)Uploading a profile photo and selecting medical images/files for a caseRequired in order to upload files to a case
Notifications (POST_NOTIFICATIONS)Delivering case status updates (“Your model is ready”, etc.)Optional; you may decline
Internet AccessData synchronisation with FirebaseMandatory
Network StateConnectivity check and offline warningsMandatory

Our Application does not request CAMERA permission and does not access your device camera. Existing images are uploaded by selecting them from the device gallery.


8. DATA SECURITY MEASURES

Ceviz applies the following administrative and technical measures to ensure the security of personal data:

Technical Measures:

Administrative Measures:


9. DATA RETENTION PERIODS

Ceviz retains personal data only for as long as is necessary for the purpose of processing. The general principle is as follows: your data is retained for as long as your account is active; when you delete your account, all of your data is permanently erased.

Data TypeRetention Period
Account and identity dataFor as long as the account is active
Case data (DICOM, models, images, case records)For as long as the account is active; automatically deleted when the account is deleted
Cases archived by the DoctorRetained unless deleted by the Doctor, or for as long as the account is active
Account deletionInitiated immediately; all Firestore records, Storage files (raw uploads and processed models) and the Authentication record are deleted
Firebase backupsRemoved from Firebase’s infrastructure backups within a maximum of 180 days after deletion
Crashlytics logsAutomatically deleted after 90 days
Data retained due to legal obligationsA maximum of 10 years for reasons such as tax legislation (invoice/contract data only; not patient health data)

Important: Account deletion is irreversible. After deleting your account, you will no longer have access to your cases, the files you uploaded, or the 3D models produced by the Admin.


10. TRANSFER OF PERSONAL DATA

10.1. Domestic Transfer

Your personal data is transferred to authorised Admin users working within Ceviz for the purpose of providing the service. This transfer takes place because the engineering service is provided by Ceviz’s own team; there is no transfer to a third-party engineer.

10.2. International Transfer

The Application uses Google Firebase services as its infrastructure. For the purposes of KVKK and GDPR compliance, Firebase data is hosted within the borders of the European Union, in the europe-west3 region located in Frankfurt/Germany. The reasons for choosing this region are:

The service provider Google Ireland Limited acts as a data processor within the framework of GDPR-compliant Standard Contractual Clauses (SCC).

Post-MVP commitment: Ceviz undertakes to move its server infrastructure to Türkiye following the completion of the product’s commercialisation process.


11. THIRD-PARTY SERVICE PROVIDERS

The following Google/Firebase services are used in the capacity of “data processor”:

ServicePurposeData ProcessedLocation
Firebase AuthenticationAccount management and authenticationE-mail, hashed passwordeurope-west3
Cloud FirestoreStructured data (cases, profiles)The data listed in Article 4europe-west3
Firebase StorageFile storage (DICOM, models, images)Case fileseurope-west3
Firebase Cloud Messaging (FCM)Push notification deliveryFCM token, notification contentGlobal (Google infrastructure)
Firebase App CheckBlocking fraudulent clientsDevice integrity tokenGlobal
Firebase CrashlyticsError monitoringAnonymous technical logsGlobal
Cloud FunctionsNotification triggering and background jobsDepends on the operationeurope-west3

Google’s privacy policy: https://policies.google.com/privacy
Firebase data processing terms: https://firebase.google.com/terms/data-processing-terms

The Application does not use advertising networks, third-party analytics or marketing service providers.


12. RESPONSIBILITIES OF THE USER (DOCTOR)

The Doctor accepts the following obligations when using the Application:

12.1. Patient Consent (Explicit Consent) After creating a case, the Doctor is obliged to obtain the necessary explicit consent from their patient in writing or electronically, in accordance with Article 6 of the KVKK and the relevant healthcare legislation, so that the service can operate fully. In order to make things easier for the Doctor, Ceviz provides a downloadable “Informed Patient Consent Form” template within the Application; however, the Doctor may also use another consent form of their own choosing. Whichever form is used, the original copy of the signed consent document is kept in the Doctor’s own archive and must be presented by the Doctor in the event of a KVKK audit.

The Doctor who has obtained consent formally declares within the system, via the “Provide Consent Declaration” step in the Application, that such consent has been obtained. This declaration is permanently recorded in Firestore together with the timestamp of the moment it was made; once given, the declaration cannot be withdrawn. As Ceviz has no direct contact with the patient and never collects patient identity information, the accuracy of this declaration is the exclusive responsibility of the Doctor.

12.2. File Anonymity Declaration Where the Doctor uploads a file other than DICOM (JPG, PNG, PDF, ZIP, RAR, GLB) when creating a case, the Doctor expressly declares and undertakes, via the confirmation checkbox in the system, that the file does not contain the patient’s direct identity information (name and surname, national ID number, clearly visible facial photograph, etc.). A file cannot be uploaded without this declaration. As DICOM files are automatically anonymised by the system, they do not require a separate declaration (see Article 6.2).

12.3. Identity Confidentiality in Case Descriptions The Doctor is obliged not to enter information that would disclose the patient’s direct identity (name and surname, national ID number, telephone number, address, etc.) in case descriptions or in the names of uploaded files.

12.4. Account Security The Doctor is obliged to keep their account password confidential, not to share it with third parties, and to change their password immediately if unauthorised access to their account is suspected.

12.5. Lawful Use The Doctor is exclusively responsible for the method of obtaining, the content and the lawfulness of the data they upload to the Application.

In the event of a breach of these obligations, the resulting legal liability rests exclusively with the Doctor; Ceviz bears no liability. The Doctor is obliged to indemnify Ceviz for any damages arising from such a breach.


13. CHILDREN’S PERSONAL DATA

The Ceviz Application is intended solely for the use of healthcare professionals over the age of 18. Ceviz does not knowingly collect data from individuals under the age of 18 as account users. Where it is determined that a user under the age of 18 has created an account, the relevant account and data are deleted immediately.

The age of the patient to whom the medical data uploaded to the system by the Doctor belongs may be an exception to this rule; however, since Ceviz never collects patient identity information, the patient’s age or identity is not known to Ceviz. Ensuring the anonymity of patient data and obtaining consent from the patient’s legal representative (where applicable) is the Doctor’s responsibility (see Article 12).


14. DATA SUBJECT RIGHTS (KVKK ART. 11 AND GDPR)

Under Article 11 of the KVKK and the GDPR, you have the following rights as a data subject:

  1. To learn whether your personal data is being processed
  2. To request information if your personal data has been processed
  3. To learn the purpose of processing of your personal data and whether it is used in accordance with that purpose
  4. To know the third parties, domestically or abroad, to whom your personal data is transferred
  5. To request the rectification of your personal data where it has been processed incompletely or inaccurately
  6. To request the erasure or destruction of your personal data within the conditions set out in Article 7 of the KVKK
  7. To request that the operations carried out under items (5) and (6) be notified to the third parties to whom your personal data has been transferred
  8. To object to an adverse outcome arising against you as a result of the analysis of your processed data exclusively by automated systems
  9. To claim compensation for damages where you suffer loss due to the unlawful processing of your personal data

Additionally, under the GDPR:

  1. Right to data portability — to receive your data in a structured format
  2. Right to object to processing
  3. Right to restriction of processing
  4. Right to lodge a complaint with a supervisory authority — the Personal Data Protection Authority (KVKK) for Türkiye, and the relevant national supervisory authority for the EU

How to Apply

To exercise these rights, you may choose one of the following methods:

Your application will be answered free of charge within a maximum of 30 days. Where the application is assessed as unfounded, a fee may be charged in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller.


15. DATA BREACH NOTIFICATION

In the event that your personal data is subject to a data breach such as unauthorised access, disclosure, alteration, loss or destruction, Ceviz will:


16. ACCOUNT AND DATA DELETION

You have full control over your data:

16.1. Case Archiving The Doctor may archive individual cases in order to keep the active case list tidy. Archived cases are removed from the Doctor’s active list, but the Doctor may restore them from the archive if desired. Archiving is not a deletion operation; the data continues to be retained until the account is deleted.

16.2. In-App Account Deletion You can delete your account by following the steps Profile > Edit Profile > Delete My Account. When the account deletion process is initiated, the system carries out the following steps immediately and irreversibly:

  1. All of your raw case files in Firebase Storage (uploads/{userId}/...) are deleted
  2. All processed 3D model files belonging to you in Firebase Storage (processed_models/{userId}/...) are deleted
  3. All of your case records in Firestore (active and archived) are deleted
  4. Your user profile document in Firestore is deleted
  5. Your Firebase Authentication record is deleted
  6. You are automatically signed out of the Application

16.3. Request by E-mail If you do not have access to the in-app deletion method, you may initiate the deletion process by sending a request to info@cevizbiotech.com. Your request will be processed within a maximum of 7 days.

16.4. Deletion from Backups Due to Firebase’s infrastructure backups, your deleted data is completely removed from Google’s backup layers within a maximum of 180 days. During this period, the backups can be accessed only by Google for disaster recovery purposes; no party, including Ceviz, can access these backups.

16.5. Irreversibility of the Operation Account deletion is irreversible. The cases, files or 3D models you delete cannot be recovered under any circumstances. We recommend that you download any files you may need to your own device before initiating the operation.


17. COOKIES AND SIMILAR TECHNOLOGIES

Our mobile application does not use “cookies” in the classic sense used on websites. However, the Firebase SDKs store temporary identifiers (tokens) in device memory for session management and App Check. These identifiers are not used for advertising or tracking purposes.


18. ABOUT THE APP STORES

The Ceviz Application is distributed via the Apple App Store and Google Play Store. When you download the Application, the privacy policy and terms of service of the relevant store also apply:

Data relating to your store account (download history, payment information, etc.) is processed directly by the relevant store; Ceviz has no access to this data.


19. CHANGES TO THE POLICY

Ceviz may update this Policy from time to time. Where significant changes are involved:

It is the User’s responsibility to keep track of the current version of the Policy.


20. GOVERNING LAW AND COMPETENT COURTS

The laws of the Republic of Türkiye apply to the interpretation and application of this Policy. The Courts and Enforcement Offices of Kütahya shall have jurisdiction over any disputes that may arise. Data subjects residing in the EU reserve their right to lodge a complaint with the supervisory authority of the member state in which they are located.


21. CONTACT

For any questions, requests and complaints regarding this Policy or your personal data:

Ceviz Biyoteknoloji A.Ş.
Çalca OSB Mahallesi, 1. Cadde, Tasarım Teknokent A.Ş. No:1 İç Kapı No:3, Merkez/Kütahya, Türkiye
E-mail: info@cevizbiotech.com


This Policy entered into force on April 13, 2026.