Personal Data Protection Law / KVKK Clarification Text
Personal Data Protection Law / KVKK Clarification Text
This Clarification Text explains how personal data may be collected, used, accessed, retained, and protected within DentiBridge.
DentiBridge is an academic dental clinical coordination platform designed to support patient request submission, initial case suitability review, faculty triage, student case requests, supervised case coordination, and academic clinical workflow management.
DentiBridge is not a hospital, an independent dental clinic, or an emergency healthcare service. It does not independently provide diagnosis, treatment planning, medical advice, or clinical decision-making. Clinical evaluation, treatment decisions, and patient care remain under the responsibility of qualified healthcare professionals and the relevant academic or clinical institution.
This page is prepared in line with the general principles of Turkey’s Personal Data Protection Law No. 6698, which states that the purpose of the law is to protect fundamental rights and freedoms, particularly the right to privacy, in relation to the processing of personal data.
1. Purpose and Scope of This Clarification Text
This Clarification Text is intended to inform patients, students, faculty members, and authorized users about the personal data processing activities that may occur within DentiBridge.
Under Article 10 of the Personal Data Protection Law No. 6698, data subjects should be informed about the identity of the data controller, the purpose of processing, to whom and for which purposes personal data may be transferred, the method and legal basis of collection, and the rights referred to in Article 11.
This page applies only to personal data processed through the DentiBridge platform. Personal data collected, stored, or processed directly by a university, dental faculty, university clinic, hospital, or other healthcare institution may also be subject to that institution’s own privacy notices, consent forms, patient documentation rules, and legal obligations.
2. Responsible Contact and Institutional Role
DentiBridge provides a digital environment for academic dental clinical coordination. Depending on how the platform is deployed, the roles of data controller, data processor, and participating academic institution may be determined according to the applicable institutional arrangement, access permissions, and workflow responsibilities.
When DentiBridge is used within or together with an academic institution, the participating institution may be involved in determining clinical review procedures, faculty supervision, access permissions, patient documentation requirements, and institutional workflow rules.
For privacy-related questions, correction requests, deletion requests, or other personal data inquiries, DentiBridge can currently be contacted at:
If a dedicated institutional contact channel is introduced in the future, this page may be updated accordingly.
3. Categories of Personal Data That May Be Processed
DentiBridge may process different categories of personal data depending on the user’s role and the function being used.
3.1 Patient Request Information
When a patient or public user submits a request through DentiBridge, the platform may process information such as:
- name and contact details;
- age or basic background information;
- reason for the request;
- type of dental concern or requested department;
- description of dental pain, complaint, condition, or clinical need;
- medical or dental information voluntarily submitted by the user;
- availability or coordination-related details;
- images, documents, or files uploaded voluntarily by the user.
Dental complaints, intraoral images, radiographic images, medical history, or other health-related information may fall within special categories of personal data. Article 6 of the Personal Data Protection Law No. 6698 identifies data concerning health as a special category of personal data.
3.2 Student Account and Workflow Information
For dental students who are invited to use DentiBridge, the platform may process information such as:
- name;
- email address;
- user role or platform status;
- basic profile information;
- case requests submitted by the student;
- case status information related to the student;
- actions performed within an academic clinical workflow.
3.3 Faculty and Authorized User Information
For faculty members, clinical supervisors, and authorized administrative personnel, DentiBridge may process information such as:
- name and contact details;
- user role and access permissions;
- case review, triage, or supervision actions;
- case status updates;
- workflow actions required for academic clinical coordination.
3.4 Technical and Operational Information
For security, access control, troubleshooting, and platform operation, DentiBridge may process limited technical or operational information, such as:
- account status;
- login-related information;
- user role and permission level;
- workflow actions;
- records required to identify technical issues, unauthorized access attempts, or misuse of the platform.
4. Methods of Collection and Possible Processing Basis
Personal data may be collected electronically through actions taken by users within DentiBridge, including patient request forms, account creation, login, profile completion, file upload, student case requests, case status updates, platform tools, and messages sent to DentiBridge’s contact channel.
The processing of personal data may be based on one or more of the following, depending on the user role, data type, institutional deployment model, and applicable legal requirements:
- a request or action voluntarily submitted by the user;
- explicit consent, where required;
- the need to review and coordinate an academic clinical request;
- the need to manage user accounts, access permissions, and supervised workflows;
- the need to protect platform security and prevent unauthorized access;
- institutional or legal obligations, where applicable.
Where explicit consent is required, KVKK describes explicit consent as consent that is “freely given, specific and informed,” and the KVKK guidance on explicit consent emphasizes that consent should be connected to a specific processing activity and should not be presented in a misleading or bundled manner.
Personal data processing within DentiBridge is intended to follow the general KVKK principles that personal data should be processed for “specified, explicit and legitimate purposes” and should be “relevant, limited and proportionate” to those purposes, as stated in Article 4 of the Personal Data Protection Law No. 6698.
5. Purposes of Processing Personal Data
DentiBridge may process personal data for the following purposes:
- receiving and organizing patient requests;
- conducting an initial suitability review of submitted cases;
- enabling authorized faculty members to perform academic clinical triage;
- assigning or routing requests to a relevant dental field or department;
- coordinating suitable cases with senior dental students under supervision;
- enabling students to request appropriate clinical cases;
- tracking case status and workflow steps;
- supporting faculty supervision and academic clinical management;
- creating and managing user accounts and role-based permissions;
- protecting platform security and preventing unauthorized access;
- responding to privacy, correction, deletion, or clarification requests;
- improving user experience, platform stability, and pilot-stage workflows.
DentiBridge does not use personal data for selling patient information, public disclosure of patient data, third-party marketing, insurance billing, hospital billing, payment collection, CCTV monitoring, call-center recordings, laboratory transfer, or inpatient services.
6. Access to Personal Data and Possible Transfer
Access to personal data within DentiBridge is limited according to user role, permission level, and the purpose of the academic clinical workflow.
Depending on the case type and workflow stage, personal data may be accessible to:
- authorized faculty members for review, triage, supervision, or academic clinical decision support;
- authorized administrative personnel, only where necessary for coordination, operation, or workflow support;
- senior dental students, only when a case is considered suitable for supervised coordination and only to the extent necessary for that case;
- authorized technical personnel or service providers, where necessary for platform operation, security, maintenance, or infrastructure support;
- the participating academic institution, where applicable and in line with the relevant institutional workflow and access rules.
Students do not receive open access to all patient requests or all platform data. Their access is intended to be limited to relevant case information within a supervised workflow.
Personal data may be transferred or made accessible to third parties only where necessary for platform operation, secure hosting or infrastructure support, academic clinical supervision, applicable institutional requirements, or a valid legal request by a competent authority.
Under Article 8 of the Personal Data Protection Law No. 6698, personal data transfer is subject to specific legal conditions. Any access or transfer should be limited to the relevant purpose and the minimum information required for that purpose.
7. Retention, Correction, Deletion, and Anonymization
Personal data is retained only for as long as necessary for the purpose for which it was collected, or as required by applicable academic, clinical, operational, institutional, or legal obligations.
Retention periods may vary depending on:
- the type of data;
- the status of the request;
- the stage of the workflow;
- whether the case is accepted, rejected, pending, or completed;
- the need for academic clinical supervision;
- the need for documentation, security, or user request handling;
- applicable institutional or legal requirements.
When the reasons for processing no longer exist, Article 7 of the Personal Data Protection Law No. 6698 provides that personal data should be “erased, destroyed or anonymized” by the data controller, either ex officio or upon the request of the data subject, subject to the conditions of the law.
Users may request the correction of inaccurate data, completion of incomplete data, deletion, or clarification regarding their personal data. Such requests will be reviewed according to the data type, case status, user role, and applicable academic, clinical, technical, institutional, or legal requirements.
Requests may be sent to:
8. Rights of the Data Subject
Under Article 11 of the Personal Data Protection Law No. 6698, data subjects have the right to submit requests regarding their personal data.
These rights may include the right to:
- learn whether personal data is being processed;
- request information if personal data has been processed;
- learn the purpose of processing and whether the data is used in line with that purpose;
- know the third parties to whom personal data has been transferred, where applicable;
- request correction of incomplete or inaccurate personal data;
- request deletion or destruction of personal data under the conditions set out in the law;
- request that relevant third parties be informed of correction or deletion, where applicable;
- object to a result arising solely from automated analysis, where relevant;
- exercise other rights available under Article 11, where applicable.
Requests related to these rights may be sent to:
To protect personal data, DentiBridge may request information necessary to verify the identity of the person submitting the request. Requests will be reviewed in accordance with applicable procedures and timeframes.
9. Data Security and Authorized Access
DentiBridge is designed to support role-based access and permission controls, so that users access only the information required for their role within the academic clinical workflow.
The platform may include measures such as:
- user account authentication;
- separation between public users, students, faculty members, and authorized administrative personnel;
- role-based permissions;
- restricted access to patient information;
- case status management;
- private handling of uploaded files and related information;
- operational controls for significant workflow actions, where implemented.
KVKK states that the data controller is required to take necessary technical and administrative measures to ensure an appropriate level of security. DentiBridge refers to the official KVKK guidance on data security obligations as a reference point for privacy-conscious handling of personal data.
Users with platform accounts are responsible for keeping their login credentials private, not sharing passwords or access links, and not transferring personal, dental, or clinical information to unauthorized persons.
Sharing an account, attempting to access information not intended for the user, or transferring personal or clinical information to an unauthorized person may harm patient and user privacy and may result in access restrictions, institutional action, or legal consequences in accordance with applicable law and KVKK data security principles.
10. Explicit Consent and Health-Related Information
Where explicit consent is required for processing personal data or health-related information, such consent should be given freely, clearly, and for a specific purpose.
Submitting a patient request through DentiBridge may involve sharing dental or medical information. Such information is submitted for the purpose of initial case suitability review, academic clinical coordination, faculty or authorized review, and management of the relevant workflow.
A user is not required to submit a request through DentiBridge. If the user does not wish the information required for review to be processed through the platform, the user may choose not to submit the request.
Consent to submit a request does not guarantee acceptance for treatment, an appointment, diagnosis, or suitability for an academic clinical workflow. Each case may be reviewed according to academic, clinical, institutional, and operational considerations.
11. Embedded Legal References
The legal references included in this page are drawn from official KVKK sources, including the Personal Data Protection Law No. 6698, the KVKK guidance on explicit consent, the KVKK page on data subject rights, the KVKK guidance on data security obligations, and the KVKK explanation on erasure, destruction, or anonymization of personal data.
These references are provided to help users understand the legal background of this Clarification Text. They do not represent a separate certification, approval, or compliance statement by any authority.
12. Page Updates
This Clarification Text may be updated from time to time to reflect changes in DentiBridge, regulatory requirements, institutional arrangements, or platform workflows.
The most recent version will be published on this page.
Last updated: 2026-06-27