Privacy Policy
Last updated: 2026-09-04
This Privacy Policy explains how NAVİCORE TEKNOLOJİ VE YAZILIM LİMİTED ŞİRKETİ ("we", "us") processes personal data when you visit https://mdrpilot.com or use the MDRpilot platform ("Service"). It is intended for website visitors, account holders, invited workspace users and business contacts.
We process personal data in accordance with the Turkish Personal Data Protection Law No. 6698 (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR).
1. Data controller
- Controller: NAVİCORE TEKNOLOJİ VE YAZILIM LİMİTED ŞİRKETİ
- Address: Çamtepe Mah. Mahmut Tevfik Atay Blv. Gaziantep Teknopark No: 4 C İç Kapı No: 31 Şahinbey / Gaziantep
- Tax office: Şahinbey
- Website: https://mdrpilot.com
- General contact: support@mdrpilot.com
- Data protection / KVKK requests: privacy@mdrpilot.com
2. Categories of personal data
2.1 Account and identity
Name, work email, password hash, language / preference settings, role and company membership, email verification and password-reset tokens, optional two-factor authentication secrets.
2.2 Company and workspace content
Company profile fields (legal name, address, SRN, notified body references), invited user emails, products and regulatory documentation you enter or upload (technical files, QMS records, risk files, CAPA / complaints, exports), audit logs and support correspondence.
2.3 Commercial and billing data
Subscription plan, purchase / sales requests, invoices and payment status metadata received from our Payment Partner (we do not store full card PAN data on our servers; card data is processed by the Payment Partner).
2.4 Technical and security data
IP address, browser / device type, session identifiers, approximate timestamps of access, error and security logs needed to operate and protect the Service.
2.5 Communication data
Messages you send to support or sales, demo requests and related follow-up.
We do not intentionally collect patient health records or special-category health data as a product feature. Do not upload personal health information unless you have assessed lawful basis, necessity, minimisation and appropriate safeguards.
3. Purposes and legal bases
| Purpose | Examples | Typical basis (GDPR / KVKK) |
|---|---|---|
| Provide the Service | Account, login, document workflows, exports | Contract / steps prior to contract |
| Subscription & billing | Plan limits, renewals, payment confirmation | Contract / legal obligation |
| Support & sales | Tickets, demos, onboarding help | Contract / legitimate interest |
| Security | Fraud prevention, abuse detection, audit trails | Legitimate interest / legal obligation |
| Product reliability | Aggregated diagnostics, incident response | Legitimate interest |
| Legal compliance | Tax, accounting, responding to lawful requests | Legal obligation |
| Communications you request | Verification emails, security alerts | Contract / legitimate interest |
We do not sell personal data and do not use personal data for third-party advertising networks.
4. AI processing
When you enable or use AI features, relevant prompts or document excerpts may be transmitted to configured AI sub-processors (for example OpenAI or Anthropic) solely to generate the output you request. Where contractual options exist, we configure providers not to use Customer Data to train public foundation models.
You remain responsible for ensuring AI processing is allowed under your internal policies, customer contracts and medical-device confidentiality rules before submitting content.
5. Recipients and sub-processors
Personal data may be disclosed to:
- cloud infrastructure and database hosting providers;
- transactional email delivery providers;
- AI inference providers when live AI is used;
- licensed Payment Partners (e.g. iyzico) for checkout and refunds;
- professional advisers (legal, accounting) under confidentiality;
- competent authorities where required by law.
A current sub-processor summary is available on request from privacy@mdrpilot.com.
6. International transfers
Where personal data is transferred outside Türkiye or the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions or other mechanisms recognised under applicable law, together with contractual and technical protections.
7. Retention
- Account data — while the account is active and for a limited period thereafter to close the relationship, resolve disputes and meet legal obligations.
- Workspace / regulatory content — according to subscription status, your deletion requests and backup cycles.
- Billing records — for the periods required by tax and commercial law.
- Security logs — for a limited period needed for investigation and hardening.
You may request account deletion via in-app settings (where available) or by emailing support@mdrpilot.com. Some records may be retained where legally required.
8. Security measures
We apply administrative, technical and organisational measures appropriate to the risk, including HTTPS encryption in transit, access control and role-based permissions, password hashing, session controls, audit logging and least-privilege access for personnel. No method of transmission or storage is perfectly secure; you must protect your credentials and devices.
9. Your rights
Subject to applicable law, you may have the right to:
- learn whether personal data is processed and request access;
- request rectification of inaccurate data;
- request erasure or destruction;
- request restriction of processing;
- object to processing based on legitimate interests;
- request data portability where applicable;
- withdraw consent where processing is consent-based;
- lodge a complaint with the Turkish Personal Data Protection Authority (KVKK) or another competent supervisory authority.
To exercise rights, contact privacy@mdrpilot.com. We may need to verify your identity and will respond within statutory timeframes.
10. Cookies and similar technologies
We use essential cookies / storage for authentication, security and basic preferences (language / theme). We do not use third-party advertising cookies. Disabling essential cookies may prevent login.
11. Children
The Service is designed for business and professional users. It is not directed at individuals under 16 and we do not knowingly collect their data.
12. Automated decision-making
We do not make solely automated decisions that produce legal or similarly significant effects about natural persons within the meaning of KVKK / GDPR profiling rules. AI outputs are tools for your human review.
13. Changes
We may update this Policy. Material changes will be shown by updating the date above and, where appropriate, by in-app or email notice.
14. Contact
Privacy / KVKK: privacy@mdrpilot.com · Support: support@mdrpilot.com · Address: Çamtepe Mah. Mahmut Tevfik Atay Blv. Gaziantep Teknopark No: 4 C İç Kapı No: 31 Şahinbey / Gaziantep
