Legal

Privacy Policy

How we collect, use, and protect your personal data.

Effective: March 2026 Updated: March 2026 Jurisdiction: Turkey (KVKK + GDPR)

Welcome to MedTalks. We are committed to protecting your personal data in accordance with the Law on Protection of Personal Data No. 6698 (KVKK) of Turkey and the General Data Protection Regulation (GDPR).

Your Consent: By using MedTalks you consent to data processing as described here. You may withdraw consent at any time by emailing privacy@medtalks.app.

1. Data Controller

MedTalks
Registered in: Republic of Turkey
Email: info@medtalks.app

2. Data We Collect

A. Information You Provide

  • Full name and email address
  • Phone / WhatsApp number (optional)
  • Institution, company name, job title
  • Country of residence
  • Content provided in forms and applications

B. Platform & Session Data

  • Conversation transcripts from AI practice sessions
  • Session duration, frequency, and agent usage
  • CEFR proficiency scores and assessment results
  • IP address, browser type, and device info
  • Pages visited and feature usage patterns
  • Cookies and similar tracking technologies

3. Why We Collect Your Data

  • Explicit Consent: Marketing, newsletters, and optional cookies.
  • Contract Performance: Delivering sessions, generating reports, processing payments.
  • Legitimate Interests: Platform security, performance improvements, analytics.
  • Legal Obligations: Billing records, compliance with Turkish and international law.

4. Cross-Border Data Transfers

MedTalks operates internationally. Your data may be processed outside Turkey or the EEA under these safeguards:

  • Adequacy Decisions — countries with recognised adequate protection.
  • Standard Contractual Clauses (SCC) — binding agreements for transfers requiring extra safeguards.
  • Explicit Consent — where you have consented to international processing.

5. Data Breach Notification

We protect your data with SSL encryption, strict access controls, and secure servers. In the event of a breach likely to affect your rights, we will notify the KVKK Board and all affected individuals without undue delay as required by law.

6. Automated Decision-Making

MedTalks uses AI agents for medical English practice. We do not use automated profiling that produces legal or similarly significant effects on you. Human review is involved in all critical decisions including partnerships and certification.

7. Data Retention

We keep personal data only as long as needed for business operations, legal compliance, and dispute resolution. After the retention period your data is securely deleted or fully anonymised per KVKK and GDPR requirements.

8. Your Rights Under KVKK & GDPR

You have the right to:

  • Access your personal data and learn how it is processed
  • Correct incomplete or inaccurate data
  • Request deletion ("right to be forgotten")
  • Restrict or object to unlawful processing
  • Receive your data in a portable format
  • Withdraw consent at any time without penalty
  • Claim compensation for damages from unlawful processing

To exercise these rights: privacy@medtalks.app

9. Age Restriction

MedTalks is intended for healthcare professionals and adult learners aged 18 and over. We do not knowingly collect data from minors. If we discover such data has been collected, we will delete it immediately.

10. Policy Updates

We may revise this policy periodically. Significant changes will be communicated by email or site notice. Continued use after updates are published constitutes acceptance of the revised policy.

Frequently Asked Questions

Quick answers to the most common privacy questions.

No. Your conversation transcripts are used solely to generate your personal report and improve our AI. We do not sell, rent, or share your conversation data with third parties.
Email privacy@medtalks.app with your request. We will delete your account and all associated personal data within 30 days in accordance with GDPR and KVKK.
User profiles and reports are stored in Google Firebase (Firestore) with servers in the EU region. Additional AI processing may pass through Google's Gemini infrastructure. All transfers comply with GDPR Standard Contractual Clauses.
We use essential session cookies to keep you logged in. We do not currently use advertising or third-party tracking cookies.
Yes. Under GDPR Article 20 and KVKK Article 11, you have the right to data portability. Email privacy@medtalks.app and we will send you a copy of your data within 30 days.