Privacy Policy

Last updated: July 2026

1. Introduction

Patiento (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website patiento.appand use our platform (collectively, the “Service”).

Patiento is a software-as-a-service platform that helps clinics manage patient communications through messaging channels such as WhatsApp. We process data on behalf of the clinics that use our platform (“Clinics”) and directly from visitors to our website.

2. Data We Collect

2.1 Information You Provide

  • Account information: when a Clinic registers, we collect the clinic name, email address, phone number, and billing details.
  • Patient communications: we process messages, images, and media sent between Clinics and their patients through our platform. This may include health-related data, contact information, and treatment inquiries.
  • Support requests: information you provide when contacting our support team.

2.2 Information Collected Automatically

  • Usage data: IP address, browser type, pages visited, time spent on pages, and other diagnostic data.
  • Cookies and tracking: we use essential cookies for authentication and security. Analytics cookies are used only with your consent.

3. How We Use Your Data

We use the collected data for the following purposes:

  • To provide, maintain, and improve our Service.
  • To process and deliver AI-powered patient communication features.
  • To manage Clinic accounts, billing, and customer support.
  • To send service-related communications, including updates, security alerts, and administrative messages.
  • To detect, prevent, and address technical issues, fraud, or abuse.
  • To comply with legal obligations and enforce our Terms of Service.

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), our legal basis for processing personal data depends on the context:

  • Contractual necessity: processing required to deliver the Service to Clinics.
  • Legitimate interests: improving our Service, preventing fraud, and securing our platform.
  • Consent: where required, we obtain explicit consent before processing.
  • Legal obligation: complying with applicable laws and regulatory requirements.

5. KVKK Compliance (Turkey)

For users in Turkey, we process personal data in accordance with Law No. 6698 on the Protection of Personal Data (“KVKK”). Please also review our KVKK & GDPR for detailed disclosures required under Turkish law.

As a data processor acting on behalf of Clinics (data controllers), we:

  • Process personal data only as instructed by the Clinic.
  • Implement appropriate technical and administrative measures to protect personal data.
  • Notify the Clinic of any data breach without undue delay.
  • Delete, destroy, or anonymize personal data upon the Clinic's request or when the purpose of processing ceases.

6. Data Sharing and Disclosure

We do not sell personal data. We may share data in these circumstances:

  • Service providers: trusted third parties who assist us in operating our platform (cloud hosting, messaging infrastructure, payment processing).
  • Legal requirements: when required by law, court order, or governmental authority.
  • Business transfers: in connection with a merger, acquisition, or sale of assets.

7. International Data Transfers

Your data may be transferred to and processed in countries other than your country of residence. We ensure that appropriate safeguards — such as Standard Contractual Clauses (SCCs) — are in place for any such transfers, in compliance with GDPR and KVKK.

8. Data Retention

We retain personal data only as long as necessary to fulfill the purposes described in this policy, or as required by law. Patient communication data is retained according to each Clinic's instructions and applicable healthcare regulations.

9. Data Security

We implement industry-standard technical and organizational measures to protect personal data, including encryption at rest and in transit, access controls, regular security assessments, and staff training. For further details, see our Information Security Policy.

10. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you.
  • Request correction or deletion of your data.
  • Object to or restrict processing of your data.
  • Request data portability.
  • Withdraw consent at any time (where processing is based on consent).
  • Lodge a complaint with a supervisory authority.

To exercise these rights, please contact us at [email protected].

11. Children's Privacy

Our Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from children.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify Clinics of material changes via email or through the platform. Continued use of the Service after changes constitutes acceptance.

13. Contact Us

If you have questions about this Privacy Policy, please contact us:

Patiento — [email protected]