Asternoos processes health data. This policy explains exactly what we collect, why, who else sees it, how long we keep it, and what rights you have under Turkish law (KVKK) and the GDPR.
In short: we never sell data, we never use patient audio, transcripts, or clinical notes to train AI models, and we do not share identifiable patient data with anyone outside the providers listed on our Subprocessors page.
1. Who we are and who does what
Asternoos operates the platform at asternoos.com and app.asternoos.com. Contact: privacy@asternoos.com.
Two different relationships apply, and this matters for your rights:
- For clinician account data (your name, email, credentials, billing, usage) Asternoos is the data controller. We decide why and how that data is processed.
- For patient data (audio, transcripts, clinical notes, patient records) the physician, clinic, or hospital using Asternoos is the data controller and Asternoos is a data processor acting on their documented instructions. Patients should direct requests about their data to their treating clinician or institution, who we support in responding.
2. What we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password hash, professional title, specialty, institution | You, at registration |
| Clinical audio | Recordings of consultations you capture or upload | You / your device |
| Transcripts & notes | Speech-to-text output and the generated clinical note, including any edits you make | Generated from your audio |
| Patient records | Patient name or identifier, age, sex, complaint, history, medication, and other details you enter or dictate | You |
| Uploaded documents | Lab reports and images you upload for data extraction | You |
| Usage & technical data | Login times, feature usage, IP address, device and browser type, error logs | Automatically |
| Billing data | Name, email, country, tax status, subscription state, invoice history. Card details are handled by Paddle; we never see or store full card numbers. | Paddle |
| Support correspondence | Emails you send us and our replies | You |
Clinical audio, transcripts, notes, patient records, and uploaded documents are special category data concerning health (GDPR Art. 9) and special categories of personal data under KVKK Art. 6. They receive the strictest handling described in this policy.
3. Why we process it, and our legal basis
| Purpose | Legal basis (GDPR) | Legal basis (KVKK) |
|---|---|---|
| Providing the documentation service to clinicians | Art. 6(1)(b) contract | Art. 5(2)(c) necessity for a contract |
| Processing patient health data to generate notes | Art. 9(2)(h) health care, on the controller's instruction | Art. 6 special category, on the controller's instruction and explicit consent obtained by the clinician |
| Billing, tax, and accounting | Art. 6(1)(c) legal obligation | Art. 5(2)(ç) legal obligation |
| Security, abuse prevention, and audit logging | Art. 6(1)(f) legitimate interests | Art. 5(2)(f) legitimate interests |
| Service emails and product notices | Art. 6(1)(b) contract | Art. 5(2)(c) necessity for a contract |
| Marketing analytics and advertising measurement on our public website | Art. 6(1)(a) consent | Art. 5(1) explicit consent |
4. What we do not do
- We do not sell personal data or patient data to anyone.
- We do not use your audio, transcripts, notes, or patient records to train, fine-tune, or improve general-purpose AI models. Our AI providers are used under API terms that exclude customer data from model training.
- We do not share identifiable patient data for advertising, profiling, or any purpose unrelated to producing your documentation.
- We do not copy production patient data into development or test environments.
5. AI providers and how your data flows
Generating a note involves sending data to specialist providers. The flow is:
- During live documentation, microphone audio may be streamed from your browser to OpenAI for real-time speech-to-text (after Asternoos mints a short-lived session).
- Consultation audio is also uploaded over TLS to our storage on Amazon Web Services (encrypted at rest) when the recording is saved.
- Saved audio may be sent to OpenAI for batch transcription when needed.
- The transcript, together with limited patient-chart fields you already store (such as name, bed, and chart notes), is sent to OpenAI to draft the structured clinical note.
- If you upload a lab report or image, the file bytes are sent to Google (Gemini API) to extract structured fields. Asternoos does not keep the raw image file — only the extracted fields and resulting chart updates.
- Consultation transcripts may also be sent to Gemini for structured extraction flows (for example creating a new patient from spoken text).
- The resulting note and patient record are stored in our database on AWS.
- Separately, operational AI telemetry (model, tokens, latency, cost, pseudonymous ids) may be sent to Langfuse in the EU after sanitisation. Clinical content is not included.
A visual walkthrough is on our How we protect data page. Providers process data only to return a result to us under API terms that exclude customer content from model training. The maintained list with locations is on Subprocessors.
6. International transfers
Our infrastructure is hosted in the European Union (AWS, Frankfurt region). Some AI, email, and payment providers may process data in the United States or other countries outside Türkiye and the EEA.
Where data leaves Türkiye or the EEA, we rely on the transfer mechanisms available under KVKK Art. 9 (as amended in 2024, including standard contractual clauses filed with the Turkish Data Protection Authority where applicable) and, for EEA data, the European Commission's Standard Contractual Clauses together with supplementary technical measures such as encryption in transit and at rest.
If you need data residency limited to a specific country, contact privacy@asternoos.com before deploying Asternoos in your institution.
7. How long we keep data
| Data | Retention |
|---|---|
| Raw clinical audio | Deleted from object storage after about 7 days by default (automated purge of expired temporary recordings). Until purge runs, expired audio is already inaccessible in the app. A clinician can explicitly keep a recording, in which case it is retained until deleted. Deleting a patient or closing an account also deletes associated audio objects. |
| Transcripts and clinical notes | Kept while your account is active, because they are your clinical record. Deleted when you delete the patient/consultation or when you close your account. |
| Patient records you create | Kept until you delete them or close your account. |
| Uploaded documents and images | Raw files are not retained. Only extracted fields and chart updates are stored with the patient record until deleted. |
| Account data | While your account is active. You can request deletion via the product (authenticated account deletion) or email privacy@asternoos.com; we complete erasure of Asternoos-held account and clinical data without undue delay and within 30 days. |
| Access and audit logs | Up to 12 months, for security and incident investigation. |
| Billing and invoice records | Retained by Paddle and by us as required by tax law, typically 10 years in Türkiye. |
| Database backups | Rolling database backups retained up to 35 days within our AWS environment. Deleted clinical records age out of backups as those backups rotate. |
8. Security
Summary of the main controls:
- All traffic encrypted in transit with TLS 1.2 or higher.
- Audio and files encrypted at rest in AWS object storage.
- Passwords stored only as bcrypt hashes, never in plain text or recoverable form.
- Authenticated, per-account data isolation so one clinician cannot read another's records.
- Least-privilege production access, restricted to the small number of people who need it.
- Clinical content excluded from analytics and third-party crash reporting.
Our full posture, including what we do not yet support, is documented on the Security page. No system is perfectly secure; if you discover a vulnerability, email security@asternoos.com.
9. Data breaches
If we become aware of a personal data breach affecting your data, we will notify the affected controller (you or your institution) without undue delay and normally within 24 hours of confirmation, with what we know about scope, cause, and remediation, so you can meet your own notification deadlines to the Turkish Data Protection Authority (KVKK Kurumu, currently 72 hours) or your supervisory authority.
10. Cookies and tracking
Essential. We use strictly necessary cookies and browser local storage to keep you signed in, remember your language, and store your cookie choice. These cannot be switched off.
Analytics and advertising. Our public marketing site uses Google Analytics 4 to understand traffic and the Meta Pixel to measure advertising. These load only after you accept them in the cookie banner, and you can change your choice at any time by clearing site data.
These tools receive pseudonymous usage signals such as page address, referrer, approximate location derived from IP, and device type. They never receive audio, transcripts, clinical notes, or patient records.
The signed-in clinical application at app.asternoos.com runs no third-party analytics or advertising trackers at all. Because page addresses there can reference patient records, no Google, Meta, or other external measurement tool is loaded in the app. It uses only the essential cookies and local storage needed to keep you signed in.
Paddle sets cookies necessary to operate checkout and prevent fraud when you make a purchase.
11. Your rights
Under KVKK Art. 11 and GDPR Chapter III you can:
- Learn whether your personal data is processed and request information about it.
- Access a copy of your data and receive it in a portable, machine-readable format.
- Have inaccurate or incomplete data corrected.
- Request erasure or destruction of your data.
- Request that we restrict processing, or object to processing based on legitimate interests.
- Withdraw consent at any time, without affecting processing already carried out.
- Be informed about transfers of your data to third parties, in Türkiye or abroad.
- Object to decisions produced solely by automated analysis, and claim compensation for damage caused by unlawful processing.
To exercise these rights, email privacy@asternoos.com. We respond within 30 days, as required by KVKK, and normally sooner. We may need to verify your identity first.
Patients: if you are a patient whose consultation was documented with Asternoos, please contact your physician or the clinic, who is the data controller. We will assist them in locating, exporting, correcting, or deleting your data.
Complaints: you may complain to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) or, in the EEA, to your local supervisory authority.
12. Children
Asternoos accounts are for licensed healthcare professionals and are not available to anyone under 18. We do not knowingly create accounts for minors. Clinical records processed through the platform may relate to paediatric patients; those are handled by the treating clinician as data controller under the safeguards described above.
13. Changes to this policy
We may update this policy. Material changes will be announced by email or in-app at least 30 days before they take effect, and the "last updated" date above will change. Changes to our subprocessor list are published on the Subprocessors page.
14. Contact
Privacy and data protection: privacy@asternoos.com
Security reports: security@asternoos.com
General support: hello@asternoos.com
Data Processing Agreements for clinics and hospitals: legal@asternoos.com.