Document key: vendor_transfer_registry
Vendor and Data-Transfer Categories
Vendor categories used to provide the service, processing purposes, and selection and oversight principles.
- Version
- 2.0
- Last updated
- July 25, 2026
- Data controller
- EGC YAZILIM SAĞLIK HİZMETLERİ LTD. ŞTİ.
Vendor categories
- Hosting, database, file storage, content delivery, backup, and network-security providers.
- Authentication, SMS, email, push-notification, error-monitoring, support, and security-operations providers.
- Apple App Store and Google Play purchase, receipt-verification, payment, and store-notification infrastructure.
- Technical services supporting live video communication, appointment operations, and communication features requested by users.
- Artificial-intelligence, OCR, document-processing, and similar specialist technical providers used in user-initiated features and enabled automated or queued weekly evaluations.
Selection, minimization, and oversight principles
- A provider must receive only the data and access necessary for a specific service. Limits on role, duration, and subprocessors must be implemented in contractual and technical controls and verified in the actual flow.
- Confidentiality, security, incident notification, deletion or return, audits, and applicable international-transfer terms are assessed in proportion to risk.
- Providers may not use health data for targeted advertising, data sales, or independent marketing profiles.
- Vendor and infrastructure changes are reflected in current privacy documents. No unverified country or data center and no absolute availability or security guarantee is represented.