Legal

Privacy Policy

This Privacy Policy sets out the principles governing the processing of information obtained through the website and the Clonify Ops platform operated by Clonify Labs. It is to be read together with the KVKK Privacy Notice in respect of legal bases and the rights of the data subject.

Last updated:

1. Governing Principles

  • Personal data is processed only to the extent necessary for the provision of the service.
  • Personal data is not sold to third parties for advertising or profiling purposes.
  • No third-party tracking scripts are used for advertising or profiling; website traffic is measured through the Company's own cookieless measurement infrastructure.
  • In respect of patient data the clinic concerned is the data controller; the Company acts on that clinic's instructions.
  • Clinician approval is mandatory at every critical step; the system does not produce medical decisions on its own.

2. Information Collected

Information provided directly by the data subject: the name, clinic, email address, telephone number and message entered in the demo, waitlist and contact forms, together with the identity and contact details supplied when creating a platform account.

Information generated automatically: cookies serving to maintain the session, language and region preference cookies, and server access logs held by the infrastructure provider (IP address, date and time, requested path). A security check runs on public forms to filter automated submissions; form contents are not sent to that check. Page views are additionally measured as aggregate statistics, without cookies, through the measurement infrastructure operating on the Company's own server.

Patient data processed in the course of clinical use: patient records, scan data, measurement results and order records entered by clinics within Clonify Ops. Such data remains under the control of the clinic concerned.

3. Purposes of Use

  • Handling demo requests and scheduling meetings
  • Creating the platform account, authenticating the user and delivering the service
  • Sending transactional notifications such as appointment reminders
  • Securing the service and preventing abuse and fraud
  • Improving and developing software algorithms, machine learning models, and overall service quality to clinical research standards; data uploaded to the platform for this purpose (on the premise that the clinic has completed all necessary information and consent processes) is stripped of all identifying and contact information (fully anonymised) before being included in R&D and technical testing procedures

Commercial electronic messages are sent solely on the basis of the explicit consent given upon waitlist registration, and every message provides the means to opt out.

4. Data Security Measures

The technical and administrative measures taken to prevent the unlawful processing of, and unlawful access to, personal data include in particular the following:

  • All traffic is encrypted over HTTPS and unencrypted connections are blocked by HSTS.
  • Row level security (RLS) is enforced in the database; each clinic may access only its own data.
  • Passwords are stored as irreversible hashes and cannot be read by any person, including Company personnel.
  • The application is protected by a content security policy (CSP) and browser security headers.
  • Critical operations are recorded in an audit trail.
  • Authorisation is role-based and granted on a least-privilege basis.

No information system can offer an absolute guarantee of security. Any security vulnerability identified in relation to an account must be reported without delay to info@clonifylabs.com.

5. Data Residency and International Transfers

Form records and platform data are held on servers established and managed by the Company, located in a data centre within the European Union. The website is published on the infrastructure of a hosting provider established in the United States, which processes technical request data such as IP addresses in the course of serving pages. The security check on public forms is likewise operated by a provider established in the United States, on the basis of technical browser signals and without access to form contents.

For users located in Türkiye this constitutes storage of personal data abroad. The consent checkboxes in our forms also cover explicit consent to that transfer; for details and the procedure for withdrawal, see the 'Transfer of Personal Data' section of the KVKK Privacy Notice.

6. Visitors Located in the European Economic Area, the United Kingdom and Switzerland (GDPR)

Where the website is accessed from the European Economic Area, the United Kingdom or Switzerland, personal data is processed in accordance with the General Data Protection Regulation (GDPR) and equivalent legislation. The data controller is Clonify Labs and requests are to be addressed to kvkk@clonifylabs.com.

The legal bases for processing under Article 6 GDPR are as follows:

  • Consent (Art. 6(1)(a)) — waitlist registration and commercial electronic messages. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out prior to withdrawal; every message carries an unsubscribe link.
  • Contract (Art. 6(1)(b)) — creation of the account, fulfilment of the demo request and delivery of the service.
  • Legitimate interests (Art. 6(1)(f)) — information security, prevention of abuse and response to enquiries.

Personal data is hosted on the Company's servers within the European Union (see 'Data Residency and International Transfers'). The provider established in the United States which delivers the website, and the provider which operates the form security check, process technical request data under a data processing agreement.

The data subject holds the following rights under the GDPR:

  • Access to the data and a copy thereof (Art. 15)
  • Rectification (Art. 16) and erasure — the 'right to be forgotten' (Art. 17)
  • Restriction of processing (Art. 18) and data portability (Art. 20)
  • Objection to processing based on legitimate interests (Art. 21)
  • Withdrawal of consent where processing rests upon it (Art. 7(3))

A written or electronic application to the Company is sufficient to exercise these rights. The data subject's right to lodge a complaint with the data protection supervisory authority of their country is reserved.

7. Visitors Located in the United States

Personal information is not sold and is not shared for cross-context behavioural advertising; no targeted advertising is displayed on the website. The data collected and the purposes of processing are set out in sections 2 and 3 of this Policy (notice at collection).

Irrespective of whether any particular state legislation (such as the California CCPA/CPRA) applies to the Company's processing, the following rights are extended on request to all visitors located in the United States: access to the data held about them, correction, deletion and a portable copy. Requests are to be addressed to kvkk@clonifylabs.com. No data subject is treated differently for exercising these rights.

As no sale or sharing of personal information takes place, there is no processing in respect of which an opt-out right arises. Global Privacy Control signals do not affect processing that does not occur.

8. Personal Data Relating to Children

The website is not directed at children and personal data is not knowingly collected from them. In paediatric applications such as cranial helmets, a child's health data is processed solely within Clonify Ops, by the clinic concerned and on the basis of parental or guardian consent; the clinic is the data controller in respect of that data.

9. Amendments to this Policy

This Policy may be updated from time to time. In the event of a material amendment, the update date shown at the top of the page is revised and account holders are notified by email.

For questions: kvkk@clonifylabs.com

Sits on the scanner and printer you already have

A clinician approves every step

Built for custom-made device regulation