Parties and Entry into Force
| Party | Details |
|---|---|
| Processor | Clonify Labs Mühendislik Sanayi ve Ticaret Anonim Şirketi ("Clonify"), Cyberpark Dikmen GO, Ankara, Türkiye · kvkk@clonifylabs.com |
| Controller | The clinic, hospital or institution (the "Customer") that enters into a service agreement or subscription terms with Clonify (the "Principal Agreement") |
This DPA enters into force upon the Customer's acceptance of the Principal Agreement and forms an integral part of the Principal Agreement. At the Customer's request, a copy of this text signed by the Parties shall be executed. Requests shall be sent to kvkk@clonifylabs.com.
1. Definitions
Terms not defined in this DPA have the meanings given to them in the GDPR and the KVKK. Such terms include personal data, special categories of personal data, processing, controller, processor, data subject and personal data breach.
- GDPR: Regulation (EU) 2016/679 of the European Union (General Data Protection Regulation).
- KVKK: the Turkish Personal Data Protection Law No. 6698 (Kişisel Verilerin Korunması Kanunu) and its secondary legislation.
- Board: the Turkish Personal Data Protection Board (the Board).
- Data Protection Legislation: the GDPR, the KVKK and related legislation applicable to the Parties and to the processing concerned. The UK GDPR and the Swiss Federal Act on Data Protection also fall within this scope.
- Service: the Clonify platform provided under the Principal Agreement. The desktop CAD software, the web-based clinic dashboard, cloud storage, user authorisation, notifications and technical support fall within this scope.
- Customer Personal Data: the personal data processed by Clonify on behalf of the Customer in providing the Service. Details are set out in Annex A.
- Health Data: the special categories of health data, within the meaning of Article 9 GDPR and Article 6 KVKK, contained in Customer Personal Data. 3D anatomical scans, measurements, and design and production parameters fall within this scope.
- Sub-processor: a third party engaged by Clonify to process Customer Personal Data on behalf of the Customer.
- SCCs: the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.
- KVKK Standard Contract: the standard contracts announced by the Board pursuant to Article 9 KVKK and the Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad.
- Personnel: Clonify's employees and contractors working on behalf of Clonify.
2. Scope and Roles
- With respect to Customer Personal Data, the Customer is the controller and Clonify is the processor. Clonify processes such data solely on behalf of the Customer and within the limits of this DPA.
- Where the Customer processes such data on behalf of another controller, Clonify acts as a sub-processor. In that case, the Customer undertakes that it has obtained the necessary authorisations.
- Clonify is an independent controller with respect to its own data, and such data falls outside the scope of this DPA. Such data relates to customer account management, invoicing, website visits and marketing activities, and is subject to the Privacy Policy and the KVKK Privacy Notice.
- The Service does not make diagnoses and does not decide on treatment. Clinical assessment and design approval rest with the Customer's authorised healthcare professionals.
3. Subject Matter and Purpose of Processing
The subject matter, duration, nature and purpose of the processing, the categories of data and the categories of data subjects are set out in Annex A.
Clonify shall not process Customer Personal Data for purposes other than those set out in Annex A. Clonify shall not sell or rent such data or use it for marketing. Unless the Customer gives separate written instructions, Clonify shall not use such data to train artificial intelligence or machine learning models. Clonify shall not profile such data for its own purposes.
4. Obligations of the Controller
- The Customer undertakes that the legal bases required for the processing exist. With respect to health data, this undertaking also covers the conditions set out in Article 6 KVKK and Article 9 GDPR.
- The Customer is obliged to inform data subjects duly. Data subjects are patients, patients' parents or guardians, and the Customer's own staff. The Customer is further obliged, where necessary, to obtain their explicit consent and to keep records of such consent.
- The Customer's instructions must comply with the Data Protection Legislation. The Customer is responsible for the accuracy and lawfulness of the data it uploads to the Service.
- The Customer is responsible for the security of its own user accounts. This responsibility covers keeping authorisations up to date, removing the access of departing staff without delay, the confidentiality of passwords and the security of the devices on which the desktop software is installed.
5. Obligations of the Processor
5.1 Documented instructions. Clonify shall process Customer Personal Data only on the documented instructions of the Customer. Transfers to third countries are also subject to this rule. The documented instructions are the Principal Agreement, this DPA, the Customer's configurations and actions within the Service, and additional written instructions. Where Clonify is of the opinion that an instruction infringes the legislation, it shall inform the Customer without delay and may suspend that instruction until the Parties reach agreement. Where the legislation to which Clonify is subject requires processing, Clonify shall inform the Customer in advance. Cases in which the legislation prohibits such information are an exception to this rule.
5.2 Confidentiality. Clonify shall limit access to the data to Personnel who require it for the Service. Such Personnel are under a written obligation of confidentiality, and this obligation continues after the end of their assignment.
5.3 Security. Clonify shall implement the measures set out in Annex B pursuant to Article 32 GDPR and Article 12 KVKK. The measures may be updated, but no update may reduce the overall level of security.
5.4 Data subject requests. Requests reaching Clonify directly are requests for access, rectification, erasure, restriction, portability and objection, and requests under Article 11 KVKK. Clonify shall forward such requests to the Customer within 5 business days at the latest and shall not respond to their substance without the Customer's written instructions. The Service provides functions for viewing, rectifying, exporting and deleting records. Where these functions are insufficient, Clonify shall provide reasonable technical assistance.
5.5 Other assistance. Clonify shall provide reasonable assistance to the Customer with its obligations under Articles 32–36 GDPR. These obligations are security, breach notification, data protection impact assessment and prior consultation. Clonify shall also provide assistance with requests from the Board and supervisory authorities.
5.6 Return and deletion. During the term of the agreement, the Customer may download its data using the export functions of the Service. After the Principal Agreement ends, the Customer is granted an export period of 30 days. On request, the data shall be returned in machine-readable formats; scan and design files shall be provided in STL, OBJ or PLY format. Within 30 days at the latest from the end of that period, Clonify shall delete or anonymise the data in its live systems and in the systems of its sub-processors. Copies in backups shall be destroyed by being overwritten at the end of the ordinary backup cycle and, until then, shall not be processed other than for restoration. On request, deletion shall be confirmed in writing. Data whose retention is required by legislation shall be retained only for that period and purpose.
5.7 Information and audits. Clonify shall provide, upon written request and within a reasonable time, the information necessary to demonstrate its compliance with this DPA. The Customer may conduct audits itself or through an independent auditor who is bound by confidentiality obligations and is not a competitor of Clonify. Audits shall take place no more than once a year, with at least 30 days' prior written notice, and during business hours. These limits do not apply to audits conducted following a breach or at the request of a supervisory authority. Audits shall not extend to other customers' data or to trade secrets. To the extent that Clonify holds an independent audit report or certification, the Customer shall first review those documents. Audit costs shall be borne by the Customer. However, if an audit reveals a material non-compliance, Clonify shall bear the reasonable costs.
5.8 Records. Clonify shall maintain a record of the processing activities it carries out on behalf of the Customer pursuant to Article 30(2) GDPR.
5.9 Requests from public authorities. Where a public authority requests Customer Personal Data, Clonify shall inform the Customer without delay, except where prohibited by legislation. Clonify shall pursue legal remedies against requests it considers unlawful and shall disclose only the minimum data that is legally required.
6. Technical and Organisational Measures
Clonify shall implement the technical and organisational measures set out in Annex B. Pursuant to Article 12(2) KVKK, where data is processed by Clonify on the Customer's behalf, the Customer is jointly responsible with Clonify for taking the security measures. In the internal relationship between the Parties, responsibility is determined according to each Party's obligations under this DPA.
7. Sub-processors
- General written authorisation: The Customer grants Clonify general written authorisation to engage sub-processors. The sub-processors listed in Annex C are deemed approved.
- Notification: At least 30 days before a new sub-processor is added or an existing one is replaced, the Customer shall be notified by email and the list on this page shall be updated. The notification shall include the sub-processor's name, place of establishment, the processing it will carry out and the country in which the data will be processed.
- Objection: Within 15 days of the notification, the Customer may object in writing on reasoned grounds relating to data protection. The Parties shall seek a solution in good faith. If no solution is found, the Customer may terminate the affected parts of the Service without paying any contractual penalty; the fee for any prepaid and unused period shall be refunded.
- Urgent change: Where security or service continuity requires an urgent change, notification shall be given as soon as possible after the change. In that case, the objection period starts from the date of notification.
- Same obligations: Clonify shall conclude with each sub-processor a written contract containing data protection obligations at essentially the same level as those in this DPA.
- Liability: Clonify is liable to the Customer for its sub-processors' data protection obligations to the same extent as for its own acts.
8. Personal Data Breach Notification
Upon becoming aware of a personal data breach affecting Customer Personal Data, Clonify shall notify the Customer without undue delay. In any event, the notification shall be made within 48 hours at the latest of becoming aware of the breach. This time limit is intended to enable the Customer to use the 72 hours available to it for notifying the supervisory authority under Article 33 GDPR and Board Decision 2019/10. The notification shall be made by email to the Customer's data protection contact address and, where necessary, confirmed by telephone.
The notification shall include the following, to the extent known at that time:
- The nature of the breach and the time of its occurrence and detection
- The categories of data affected and the approximate number of records (including whether Health Data is affected)
- The categories and approximate number of data subjects affected
- The likely consequences of the breach
- The measures taken or proposed to be taken
- The Clonify contact person from whom further information can be obtained
Where not all of the information can be provided at the same time, it shall be provided in phases. The initial notification shall not be delayed on the grounds of incomplete information. Clonify shall cooperate with the Customer in investigating the breach and remedying its effects. Unless the Customer gives written instructions or Clonify has its own legal obligation, Clonify shall not notify data subjects or authorities on the Customer's behalf. The notification does not constitute an acknowledgement of fault by Clonify.
9. International Data Transfers
9.1 Data location. Customer Personal Data is stored on servers managed by Clonify and located in a data centre in the European Union. This covers database records, 3D scan and design files, and backups. When the web application is served, data passes through the infrastructure of the hosting provider listed in Annex C. Clonify Personnel may access the data remotely from Türkiye for support and maintenance purposes.
9.2 EEA, United Kingdom and Switzerland. Where the GDPR applies, the access and processing carried out by Clonify, by reason of its establishment in Türkiye, constitute a transfer to a third country within the meaning of Chapter V GDPR. For these transfers, SCC Module 2 (controller to processor) is incorporated into this DPA by reference. Where the Customer is itself a processor, Module 3 applies. The Customer is the data exporter and Clonify is the data importer. The SCCs apply as follows:
- The docking clause in Clause 7 of the SCCs applies.
- For the purposes of Clause 9(a), general written authorisation and the 30-day notification period in section 7 of this DPA apply.
- The optional wording in Clause 11 does not apply.
- For the purposes of Clause 17, the law of the EU Member State in which the data exporter is established applies. Where that law does not allow for third-party beneficiary rights, Irish law applies.
- For the purposes of Clause 18, the courts of the EU Member State in which the data exporter is established have jurisdiction.
- The information required in the annexes to the SCCs consists of Annex A, Annex B and Annex C to this DPA.
For transfers from the United Kingdom, the ICO's International Data Transfer Addendum (UK Addendum) applies. For transfers from Switzerland, the SCCs apply as adapted to the Swiss Federal Act on Data Protection.
9.3 Türkiye (KVKK). Where the Customer is established in Türkiye, the storage of data on servers in the EU and its transfer to the foreign sub-processors listed in Annex C constitute a transfer abroad within the scope of Article 9 KVKK. For transfers to its sub-processors, Clonify shall sign the appropriate KVKK Standard Contract and notify it to the Turkish Personal Data Protection Authority within five business days of signature. Where a KVKK Standard Contract is required between the Customer and Clonify, the Parties shall sign it as an annex to this DPA. The notification shall be made by whichever Party is obliged to make it under the legislation.
9.4 Transfers to sub-processors. Transfers to sub-processors outside the EU/EEA are based on one of the following mechanisms: an adequacy decision of the European Commission (including certification under the EU-U.S. Data Privacy Framework), SCC Module 3 or other appropriate safeguards provided for by legislation. Clonify assesses the legislation of the countries to which data is transferred and, where necessary, applies supplementary measures such as encryption in transit, access restriction and data minimisation. This assessment shall be shared with the Customer on request.
10. Liability
The Parties' liability arising from this DPA is subject to the liability provisions of the Principal Agreement. These limitations do not limit the rights of data subjects or mandatory liability provisions, and do not apply in cases of wilful misconduct or gross negligence. Pursuant to Article 82 GDPR, a processor is liable for the damage caused by processing only where it has not complied with obligations specifically directed to processors or where it has acted outside of the lawful instructions.
11. Term and Termination
This DPA remains in force for the term of the Principal Agreement. For as long as Clonify continues to process Customer Personal Data, including during the return and deletion process under section 5.6, the relevant provisions continue to apply. The provisions on confidentiality, liability and return and deletion survive the end of the agreement.
12. Order of Precedence
In the event of a conflict relating to the protection of personal data, this DPA prevails over the Principal Agreement. In the event of a conflict between this DPA and the SCCs, the SCCs prevail. In the event of a conflict between this DPA and the KVKK Standard Contract, the KVKK Standard Contract prevails.
13. Governing Law and Jurisdiction
Without prejudice to matters governed by the SCCs, this DPA is governed by the laws of the Republic of Türkiye. The Courts and Enforcement Offices of Ankara have jurisdiction over disputes.
14. Miscellaneous
- Amendment: Where the Data Protection Legislation changes or a competent authority announces new standard clauses, the Parties shall update this DPA in good faith to the extent necessary. Material changes shall be notified to the Customer at least 30 days in advance.
- Notices: Notices to Clonify shall be sent to kvkk@clonifylabs.com, and notices to the Customer shall be sent to the administrator or data protection contact email address registered in the Customer's account.
- Severability: A provision held invalid does not affect the other provisions. The invalid provision shall be replaced by the valid provision closest to its purpose.
- Language: The Turkish text of this DPA prevails. Texts in other languages are for information purposes only.
Annex A — Details of Processing
| Item | Description |
|---|---|
| Subject matter | Provision of the Service under the Principal Agreement |
| Duration | The term of the Principal Agreement and the return and deletion period under section 5.6 |
| Nature | Collection (import of scan files and form entries), recording, storage, organisation, computation (alignment and measurement), design generation, display, transmission on the Customer's instructions (sending files to a production partner, physician sharing link), export, deletion |
| Purposes | Processing of 3D scan data, measurement, and custom orthosis/prosthesis design (CAD) and creation of production files (CAM); keeping patient, appointment, order and report records; cloud storage and synchronisation between the desktop software and the web dashboard; authentication and authorisation; sending notifications enabled by the Customer; technical support and troubleshooting; security and audit logs |
| Frequency | Continuous |
| Place of processing | The data centre in the EU; the countries listed in Annex C; Türkiye, with respect to remote access by Clonify Personnel |
Categories of data subjects:
- The Customer's authorised staff (clinicians, orthotic and prosthetic technicians, administrators)
- The Customer's patients. This category also includes children and infants (for example, infants undergoing cranial helmet therapy).
- Patients' parents, guardians or relatives
- Physicians and healthcare professionals informed by the Customer
| Data category | Data |
|---|---|
| Staff identity and contact details | First name, surname, email, telephone, title, institution name, role and authorisation details |
| Patient identity and contact details | First name, surname, date of birth, sex, patient or parent contact details, identity number (stored as a hash value rather than in plain text) |
| Transaction records | Appointment, order, production status, report and invoice records; consent and notification preferences |
| Technical data | Session information, IP address, access and audit logs, technical diagnostic logs of the desktop software |
| Health data: 3D scans | Head, torso and limb scans; STL, OBJ, PLY, CPX and VTP mesh files |
| Health data: measurements | CVAI, cephalic index, head circumference and volume; residual limb length, circumference and volume; other biomechanical measurements |
| Health data: clinical information | Diagnosis or indication, treatment and follow-up information, clinical notes entered by the Customer |
| Health data: design and production | Custom device design files, production parameters, revision history |
3D scans including the head and face may contain details that could enable the identification of the individual. The Parties regard such data as high-risk.
Annex B — Technical and Organisational Measures
Access control and authorisation:
- Each clinic can access only its own records. This separation is enforced not only at the application layer but also by row-level security policies in the database.
- User roles and permissions within a clinic are managed by the Customer's administrator (role-based access control).
- Sharing with a patient or physician takes place via personal, unguessable links and can be revoked by the Customer.
- Production files cannot be exported without clinician approval.
- Access by Clonify Personnel is limited to persons who need it for their duties (principle of least privilege).
Authentication and encryption:
- User accounts are personal. A minimum password length and a weak-password check are enforced. Passwords are stored in irreversible form (hashed).
- All access to the Service is encrypted over HTTPS (TLS).
- Patient identity numbers are stored as a hash value rather than in plain text.
- Technical diagnostic logs of the desktop software are encrypted on the device before transmission and decrypted only on the authorised server side.
- Push notification (web push) content is transmitted with end-to-end encryption.
- Secret keys and access tokens are not kept in the source code.
Logging, integrity and audit trail:
- Critical record operations (for example, patient registration, order status and consent operations) are written to an audit log. Audit logs are protected against modification and deletion.
- Status transitions in records are controlled at database level. Design files are stored with versioning and previous versions are preserved.
- Server access and security logs are retained for 12 months.
Personnel, organisation and incident management:
- All Personnel with access to Customer Personal Data give a written confidentiality undertaking and are informed about data protection.
- The access of Personnel whose duties have ended is removed without delay.
- A procedure consistent with the time limits in section 8 is applied for the detection, assessment, recording and notification of security incidents. Each breach is recorded together with its cause, its effects and the measures taken.
- The servers are located in access-controlled data centres of the hosting provider listed in Annex C. Physical security is provided by that provider.
Annex C — Authorised Sub-processors
The current list is on this page. Changes are notified in advance in accordance with section 7.
| Sub-processor | Subject matter of processing | Location of processing | Transfer mechanism |
|---|---|---|---|
| Contabo GmbH (Germany) | Server hosting: database, 3D file storage, application and email servers, backups | European Union | Within the EU |
| Vercel Inc. (USA) | Hosting of the website and the web dashboard application and processing of user requests | USA and the provider's global network | EU-U.S. Data Privacy Framework or SCCs; KVKK Standard Contract |
| Google LLC (USA) / Google Ireland Ltd. | Relaying of emails sent from Clonify's mail server | USA and EU | EU-U.S. Data Privacy Framework or SCCs; KVKK Standard Contract |
| Cloudflare, Inc. (USA) | Bot verification on registration and contact forms. Only browser signals and the IP address are processed; form content is not transmitted. | The provider's global network | EU-U.S. Data Privacy Framework or SCCs; KVKK Standard Contract |
Services not regarded as sub-processors:
- Messaging: Where the Customer connects its own WhatsApp account to the Service, messages are transmitted via the Customer's account through the messaging service's infrastructure. The software providing the connection runs on Clonify's server in the EU. The relationship with the messaging service provider belongs to the Customer.
- Browser notification services: Push notifications are transmitted with end-to-end encryption through the service of the user's browser vendor. The service cannot see the content.
- Desktop software: Runs on the Customer's devices. Data stored locally on these devices is under the Customer's control.
For questions: kvkk@clonifylabs.com