GDPR

General Data Protection Regulation Notice

Data Controller and Contact Information
Name: Vaka At Domain: https://vaka.at Email: info@vaka.at Under the General Data Protection Regulation ("GDPR"), we act as the "data controller." We also take the necessary measures and safeguards required by GDPR in our relationships with third parties, including data transfers.
Scope and Purpose
Vaka At is a platform where physicians (doctors) can anonymously share case information. Protecting personal data is a core priority governed by both KVKK (Turkish Data Protection Law) and GDPR. The platform operates as follows: We do not store identifiable personal data (e.g., patient name, phone number) in our databases; only anonymous case notes and physician account details (e.g., name, surname, email) are kept. Patient identifying information (e.g., name, ID number, phone) may only be stored temporarily in the user's browser local storage. This information is never saved to our database. For users (doctors) accessing from within the European Union, we declare that we have taken all technical and organizational measures required under the GDPR for lawful data processing. This GDPR Disclosure Notice is prepared pursuant to EU Regulation 2016/679 ("GDPR") to set out our obligations regarding the processing, transfer, and protection of personal data, as well as to inform data subjects (physicians and, if applicable, other EU-based users) of their rights.
Personal Data Collection and Processing Conditions

Data Collection Methods

User Account Information: Basic details (such as name, surname, and email) provided by doctors upon account registration. Without this data, we cannot provide our services (GDPR Art. 6(1)(b): performance of a contract). Site Usage / Cookies: We may use cookies to improve user experience and operate the platform. (See our Cookies Policy.)

Lawful Bases for Processing

Consent (GDPR Art. 6(1)(a)): We may process data based on explicit user consent, for instance, to send newsletters or conduct potential marketing activities. Contractual Necessity (GDPR Art. 6(1)(b)): We process essential user data (e.g., account setup, case sharing) to perform our services. Legal Obligations (GDPR Art. 6(1)(c)): Where necessary under EU/Member State law, we may process data at the request of regulatory authorities. Legitimate Interests (GDPR Art. 6(1)(f)): We may process minimal data to prevent abuse, ensure site security, or pursue other legitimate interests without overriding data subject rights.

Purposes of Using Personal Data

To manage platform membership and identify our users, To provide support, troubleshoot, and ensure security, To fulfill legal obligations (e.g., responding to requests from regulatory or judicial authorities), To offer customized services (where applicable).

Data Minimization and Retention Periods

Doctor account details (name, email, etc.) are retained during the membership period or until legal obligations (e.g., audits) end. Patient personal data may only be held in local storage in the browser to facilitate creating anonymous cases. These details are not transferred to our central database and should be deleted from local storage once converted to PDF/TXT. Users can request permanent deletion of their account data, subject to legal allowances (GDPR Art. 17).
Data Security
Technical Measures: SSL/TLS encryption, secure server protocols, and regular backups. Prevention of Unauthorized Access: Access to the platform management panel and database is restricted to authorized personnel only (GDPR Art. 32). Data Breach Notification: If a personal data breach occurs, we will notify the supervisory authority and/or affected users within 72 hours, in compliance with GDPR Arts. 33–34.
Third-Party Transfers
Transfers Outside the EU: Although the platform aims to store data anonymously, potential infrastructure/cloud providers might be located within or outside the EU. We do not transfer data abroad unless we ensure adequate safeguards (e.g., Standard Contractual Clauses) under GDPR Arts. 44–49. Requests from Official Authorities: Where legally mandated under EU/Member State law, data may be shared with competent authorities.
Data Subject (Doctor/User) Rights
In accordance with GDPR Arts. 12–22, you have the right to: Access (Arts. 13–15): Obtain information regarding which personal data we process and for what purposes. Rectification (Art. 16): Request correction of inaccurate or incomplete data. Erasure (Art. 17, "Right to be Forgotten"): Request data deletion where permitted by law. Restriction of Processing (Art. 18): Under certain conditions, request that data be retained but not otherwise processed. Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format. Objection (Art. 21): Object to processing in certain scenarios (e.g., direct marketing). Not to be Subject to Automated Decisions (Art. 22): You can refuse decisions based solely on automated processing, including profiling. To exercise these rights, please email info@vaka.at. We will aim to respond within a reasonable time (GDPR Art. 12/3).
Complaints and How to Lodge Them
Supervisory Authority (Art. 77 GDPR): You may lodge a complaint with the national Data Protection Authority (e.g., CNIL in France, BfDI in Germany) in the Member State of your habitual residence or workplace, or where an alleged infringement has occurred. Judicial Remedy (Art. 79 GDPR): If you believe your personal data has been processed contrary to the GDPR, you have the right to bring the matter before the courts in the relevant Member State.
Children's Data
Our platform is intended for use by physicians and is not designed for children (under 16). Should children's data be processed in any way, we will seek explicit parental consent where required by GDPR Art. 8.
Updates and Binding Effect
This GDPR Compliance Notice is dated January 12, 2025, and is subject to revision (GDPR Art. 97). In case of substantial changes, we will notify our users separately.
Contact
For your GDPR rights or any inquiries regarding this Notice, please contact: Email: info@vaka.at Vaka At Date: January 12, 2025 Email: info@vaka.at This text is prepared under Law No. 6698 on the Protection of Personal Data and related legislation. By using our platform, you are deemed to have accepted the terms set forth herein.