Legal

Data Protection & Security

On HeliaLoop your personal health data is processed and stored under Turkish Personal Data Protection Law No. 6698 (KVKK). Last updated: June 2026.

✅ Data Protection Compliant 🔒 SSL / TLS Encryption 🏥 Special Protection for Health Data 🇪🇺 EU Servers (Supabase EU)

Data Controller
Who processes the data?

Nechh Robotics — HeliaLoop

Contact: nechhlab.global@gmail.com

Subject: Data Protection & Security Requests

HeliaLoop is a SaaS healthcare platform developed and operated by Nechh Robotics.


Data Processed
Which data is collected?

Patient Data

Doctor / Professional Data


Purpose of Processing
Why is the data processed?
Important: Health data is classified as "special category personal data" under Article 6 of KVKK. Such data is processed only on the basis of explicit consent and/or a legal requirement.

Technical Security
How is your data protected?

Encryption

All data is encrypted with TLS 1.3 in transit and AES-256 at rest.

Infrastructure

HeliaLoop runs on Supabase (PostgreSQL). Servers are located in a European Union data centre (Frankfurt), on GDPR-compliant, SOC 2 Type II certified infrastructure.

Access Control

Row Level Security (RLS) policies mean each user can access only their own data. Doctors can see data only for patients who have given approval.

API Keys

Service keys are held server-side and are never sent to the client (browser or app).


Your Rights
Your Rights Under Data Protection Law

To exercise these rights, email nechhlab.global@gmail.com with the subject line "Data Protection Request". Requests are answered within 30 days.


Retention Period
How long is data kept?