1. Our principles
- We collect only the data genuinely needed to deliver the service.
- We do not sell your data to third parties for advertising or profiling.
- We run no behavioural analytics or advertising scripts on the site.
- For patient data, the CLINIC is the controller; we act on the clinic's instructions.
- Clinician approval is mandatory at every critical step; the system makes no medical decision on its own.
2. What we collect
Information you give us directly: the name, clinic, email, phone and message you enter in the demo, waitlist and contact forms, plus the identity and contact details provided when opening a platform account.
Information generated automatically: cookies used to keep you signed in, the language preference cookie, and server access logs held by our infrastructure provider (IP address, timestamp, requested path).
Patient data processed during clinical use: patient records, scan data, measurements and orders entered by clinics inside Clonify Ops. This data remains under the clinic's control.
3. How we use it
- To answer demo requests and schedule meetings
- To create your account, authenticate you and deliver the service
- To send transactional notifications such as appointment reminders
- To secure the service and prevent abuse and fraud
- To improve the product — using aggregated and anonymised data wherever possible
We send marketing messages only on the explicit consent you give when joining the waitlist, and every message includes an unsubscribe option.
4. Security
- All traffic is encrypted over HTTPS; HSTS blocks unencrypted connections.
- Row level security (RLS) is enforced in the database: each clinic sees only its own data.
- Passwords are stored as irreversible hashes; nobody, including our staff, can read your password.
- The application is protected by a content security policy (CSP) and browser security headers.
- Critical operations are written to an audit trail.
- Permissions are role-based and granted on a least-privilege basis.
5. Data residency
Platform data is configured to be hosted in Türkiye. Where a transfer abroad becomes necessary, the conditions of KVKK Art. 9 apply and the transfer is disclosed in the privacy notice.
6. Children's data
Our website is not directed at children and we do not knowingly collect data from them. In paediatric applications such as cranial helmets, a child's health data is processed only inside Clonify Ops, by the relevant clinic and with parental consent; the clinic is the controller for that data.
7. Changes
We may update this policy. On a material change we update the date at the top of the page and notify account holders by email.
For questions: kvkk@clonifylabs.com