For professionals using Vitena
Data processing, hosting and subprocessors
If you use Vitena to keep records about your clients or patients, you are the controller of that data and Vitena is your processor. This page covers what is true wherever you practise: where the data physically lives, who else touches it, and what stays under your control. The rules that differ by country — which agreement applies and how health data is treated — are on the page for your regime, linked below.
Who is who
You decide which clients you record, what you write about them and how long you keep it, so you are the controller under Art. 4(7) GDPR. Vitena stores and processes that data on your instructions and for no other purpose, which makes it a processor under Art. 4(8). Vitena does not use your clinical data for its own purposes, does not sell it, and does not use it to train AI models.
There is one part of the platform where the roles differ. Your public profile in the directory, and the details a person enters when booking an appointment with you before they become your client, are processed by Vitena as a controller in its own right — that is the marketplace side of the product. Everything inside your workspace is processor-side.
Which rules apply to you
Pick the regime you practise under. Each page carries the agreement Vitena offers under that law, how special-category health data is handled, and the rules on transfers abroad.
GDPR — European Union and EEA
The Art. 28 data processing agreement, plus your clients' own rights. This is the document called an Auftragsverarbeitungsvertrag (AVV) in Germany, a verwerkersovereenkomst in the Netherlands and a contrato de encargado del tratamiento in Spain — one law, four names.
GDPR and the Art. 28 agreementKVKK — Türkiye
Türkiye is outside the EU and Law no. 6698 is a separate regime with its own rules on special-category data, the duty to inform, explicit consent and transfers abroad.
KVKK and the processor agreementHIPAA (United States): Vitena does not currently serve the US market, does not act as a Business Associate and does not sign BAAs. If you handle Protected Health Information under HIPAA, Vitena is not the right tool for it today. We would rather say so than imply a compliance we do not have.
Where your data is stored
All client records, appointments, notes, forms, consent records and uploaded files are stored in the European Union, in Amazon Web Services' Frankfurt region (eu-central-1). Each practice has its own isolated database schema. Data is encrypted in transit (TLS) and at rest, and backups stay in the same region.
Company seat and data location are two different things
Vitena is operated by Ahmet Çakıl, a business registered in Türkiye (Kartal tepe mh. Kılıçaslan cd. 11/22 Merkez, Karabük 78100, Türkiye). That is who invoices you, and it is what our Terms of Service state. It is not where your data is kept: the servers are in Frankfurt, inside the EU, as described above. Both facts are true at the same time and neither replaces the other. Türkiye is not on the European Commission's adequacy list, so any access from the operator's side is governed by the data processing agreement and the Standard Contractual Clauses, not by an adequacy decision.
Subprocessors
These are the third parties that may process data on Vitena's behalf. The list is kept current; you will be told before a new subprocessor is added, and you may object.
| Subprocessor | What it is used for | Processing location |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting: application servers, database, file storage and content delivery | European Union — Frankfurt (eu-central-1) |
| Amazon SES (AWS) | Transactional email: booking confirmations, reminders, portal links, account notices | European Union — Frankfurt (eu-central-1) |
| Amazon Rekognition (AWS) | Automated moderation of images uploaded to public profiles. Clinical files are not sent | European Union — Frankfurt (eu-central-1) |
| OpenAI, L.L.C. | AI assistant features, only when the professional explicitly starts one (meal-plan draft, note draft, document reading) | United States — Standard Contractual Clauses |
| Groq, Inc. | Fallback provider for the same AI features when the primary provider is unavailable | United States — Standard Contractual Clauses |
| Google Ireland Ltd. | Calendar synchronisation — only for professionals who connect their own Google Calendar | European Union |
About the AI features: they never run on their own. An AI provider only sees content when you deliberately start an AI action — drafting a meal plan, drafting a session note, or reading a document you attached. If you never use those features, no client data reaches an AI provider. Neither provider trains models on the content sent through the API. If you would rather not use AI at all, the whole product works without it.
Staying in control of your data
- Export: you can export your client data yourself, at any time, without asking.
- Deletion: a client's right to erasure can be actioned from your workspace, and a deletion certificate is produced as evidence.
- Access control: Business Admin, Consultant and Assistant roles limit who in your team sees what.
- If you leave: your data is returned or deleted at the end of the contract, at your choice.
- Incidents: you are notified without undue delay if a breach affects your data, with what is known at the time, so you can meet your own 72-hour obligation.
Questions and requests
Data protection questions, agreement requests and subprocessor objections all go to the same address: info@vitena.care. Related reading: security and privacy, the privacy policy, and the terms of service.