Legal
Data Protection & Security
On HeliaLoop your personal health data is processed and stored under Turkish Personal Data Protection Law No. 6698 (KVKK). Last updated: June 2026.
✅ Data Protection Compliant
🔒 SSL / TLS Encryption
🏥 Special Protection for Health Data
🇪🇺 EU Servers (Supabase EU)
Data Controller
Who processes the data?
Nechh Robotics — HeliaLoop
Contact: nechhlab.global@gmail.com
Subject: Data Protection & Security Requests
HeliaLoop is a SaaS healthcare platform developed and operated by Nechh Robotics.
Data Processed
Which data is collected?
Patient Data
- First name, surname, email, phone
- National ID number (optional, for verification only)
- Date of birth, gender
- Health complaints, when the AI assistant is used
- Appointment and referral history
Doctor / Professional Data
- First name, surname, email, phone
- Diploma and certificate details, during the approval process
- Clinic address and specialty information
- Appointment and referral records
Purpose of Processing
Why is the data processed?
- Patient-doctor matching and appointment management
- AI-assisted healthcare referral service
- Platform security and fraud prevention
- Legal obligations (data protection law and Ministry of Health regulations)
Important: Health data is classified as "special category personal data" under Article 6 of KVKK. Such data is processed only on the basis of explicit consent and/or a legal requirement.
Technical Security
How is your data protected?
Encryption
All data is encrypted with TLS 1.3 in transit and AES-256 at rest.
Infrastructure
HeliaLoop runs on Supabase (PostgreSQL). Servers are located in a European Union data centre (Frankfurt), on GDPR-compliant, SOC 2 Type II certified infrastructure.
Access Control
Row Level Security (RLS) policies mean each user can access only their own data. Doctors can see data only for patients who have given approval.
API Keys
Service keys are held server-side and are never sent to the client (browser or app).
Your Rights
Your Rights Under Data Protection Law
- The right to learn whether your personal data is processed
- The right to request information where it has been processed
- The right to have inaccurate data corrected
- The right to request erasure or destruction of the data
- The right to request notification of third parties to whom the data has been transferred
- The right to object where an automated system produces an outcome against you
To exercise these rights, email nechhlab.global@gmail.com with the subject line "Data Protection Request". Requests are answered within 30 days.
Retention Period
How long is data kept?
- Active account data: For as long as the account is active
- Health records: Up to 3 years after a deletion request, as a legal obligation
- Log records: 90 days
- Payment information: Held in the payment provider's secure vault; no card details are stored on HeliaLoop servers