Privacy Policy
Last updated: August 2026
1. About this policy
Aurenza provides AI-powered clinic management software to aesthetic health clinics in Turkey. We act as a data processor on behalf of our partner clinics, who are the data controllers. This policy explains how we handle personal data as a processor.
2. Our role
We are a data processor under KVKK (Turkey) and GDPR (EU). Our partner clinics (such as Dr. Gamze Eren) are the data controllers. We process patient data only on documented instructions from the clinic. The clinic is responsible for obtaining patient consent and providing privacy notices.
3. What data we process
On behalf of clinics, we may process:
- Patient names and contact details (phone, email, WhatsApp)
- Medical history and procedure interests
- Photographs
- Appointment data
- Billing information
- Communication records
4. Data sub-processors
We do not sell personal data. We share data only with the following sub-processors, each bound by appropriate data protection obligations and Standard Contractual Clauses:
- Base44 (platform hosting and data storage) — DPA with SCCs at base44.com/dpa
- Vercel (web hosting) — DPA with SCCs at vercel.com/legal/dpa
- Meta / WhatsApp (patient messaging via WhatsApp Business Platform)
- Google (email and workspace tools for getaurenza.com)
- AI providers used for message drafting under clinic control
5. Data retention
We retain personal data according to the following schedule:
- Medical records (processed on behalf of clinics): 10 years from the date of the patient's last treatment, in accordance with Turkish Health Law and medical record retention requirements.
- Inquiry-only data (non-patients who contact a clinic but do not proceed): 2 years from last contact, then securely deleted.
- Financial records: retained for the durations required by Turkish tax legislation and commercial law.
- Clinic account data: retained for as long as the clinic maintains an active account. Upon termination, data is exported and securely deleted within 60 days, unless longer retention is required by law.
Clinics may request deletion of their data at any time by contacting privacy@getaurenza.com.
6. Security
All patient data is stored with encryption and access controls. File storage uses private access (signed URLs). Access is restricted to authorized clinic staff. We do not sell or share personal data with third parties beyond what is necessary to provide our services.
7. Cross-border data transfer
Patient data may be transferred to sub-processors with servers outside Turkey (Meta, Google, Vercel, Base44). All transfers are covered by Standard Contractual Clauses under GDPR Arts. 45–49 and KVKK Arts. 8–9.
8. Your rights
If you are a patient, please contact your clinic directly to exercise your data rights. If you are a partner clinic, contact us at privacy@aurenza.com for data processing requests.
9. Contact
Email: privacy@aurenza.com