Terms of Service and Data Processing Agreement
Version 1.0 · Effective 2026-09-23
These terms govern the relationship between a clinic using DentalSeller and its provider, and how personal data processed on the clinic's behalf is protected.
1. Parties and scope
This agreement is between Dental Seller (address: Muratpaşa, Antalya, Türkiye; tax number: 0000000000) (the “Provider”) and the clinic using DentalSeller (the “Clinic”). It is accepted electronically on the Clinic's behalf by one of its authorised administrators.
If the Turkish and English versions of this text conflict, the Turkish version prevails.
2. The service
DentalSeller is web-based software for managing patient pipelines, quotes, visits, tasks, sales-team commission and notifications. Notifications may be sent through Telegram if the Clinic chooses.
3. Data protection roles
For the patient and staff data it enters into the service, the Clinic is the data controller (veri sorumlusu) under Turkey's Law No. 6698 on the Protection of Personal Data (“KVKK”) and, where applicable, the EU/UK General Data Protection Regulation (GDPR / UK GDPR). The Provider is a processor (veri işleyen) that processes this data only on the Clinic's behalf and on its instructions.
The Clinic is responsible for collecting data lawfully, informing data subjects, obtaining explicit consent where required, and registering with VERBİS where applicable.
4. Processing instructions and purposes
By accepting this agreement, the Clinic instructs the Provider to process Clinic data only to: provide and operate the service; give support at the request of the Clinic or its users; maintain, secure, back up, monitor and troubleshoot the service; monitor and improve the service's performance using aggregated or de-identified data only; and comply with legal obligations.
The Provider does not use Clinic data for its own purposes: it does not process it for marketing, sale, profiling or training AI models, and does not sell it to third parties.
5. Support and maintenance access
Authorised Provider personnel may access the Clinic's account and data for the purposes in section 4 without prior notice or separate approval for each access, and may change data where necessary to resolve an issue. Access is limited to what the purpose requires.
Every support session is recorded in an access log: who accessed, when, which areas were viewed and what was changed. Changes made during support appear in the Clinic's history as “DentalSeller support”.
The Clinic may request the access log for its account at any time; the Provider will provide it within a reasonable time (15 days). Access logs are kept for 10 years.
6. Confidentiality
Provider personnel with access to Clinic data are bound by confidentiality obligations that continue after their engagement ends. Access is granted only to authorised individuals and removed promptly when no longer needed.
7. Security measures
Having regard to Article 12 of the KVKK and the Personal Data Protection Board's decision on special categories of personal data, the Provider applies these measures: two-factor authentication for Provider access; encryption in transit (TLS) and at rest by its hosting providers; logical separation of each clinic's data through database-level access rules; least-privilege access; access logging; and regular backups.
The Clinic is responsible for managing its user accounts, using strong passwords and closing the accounts of staff who leave.
8. Sub-processors and data location
The Provider uses these sub-processors to deliver the service: Supabase (database, authentication and file storage; data is stored in the EU data centre in Stockholm, Sweden); Vercel (application hosting; Stockholm, Sweden, EU); Telegram (notifications the Clinic enables).
Transfers of personal data abroad take place under the mechanisms in Article 9 of the KVKK (such as standard contracts) and, where applicable, Chapter V of the GDPR. The Provider will notify Clinic administrators of changes to sub-processors at least 30 days in advance, and the Clinic may object.
9. Personal data breaches
If the Provider becomes aware of a personal data breach affecting Clinic data, it will notify the Clinic without undue delay and, where feasible, within 24 hours, and provide the information the Clinic needs to notify the Personal Data Protection Board and data subjects.
10. Data subject requests and assistance
The Provider will reasonably assist the Clinic in responding to data subject requests (such as access, correction and deletion) and to enquiries from supervisory authorities.
11. End of service and deletion
The Clinic may export its data while the service is active. After the service ends, the Provider will delete Clinic data within 90 days, except where the law requires it to be kept. Access logs are kept for the period in section 5.
12. Changes
The Provider may update these terms. Updates are announced to Clinic administrators in the app, and they will be asked to accept the new version. Each acceptance is recorded with the version, the person accepting and the date.
13. Governing law
This agreement is governed by Turkish law. The courts and enforcement offices of Antalya have jurisdiction over disputes.
14. Contact
For questions about these terms or data protection: osman07arslann@gmail.com.