Privacy Policy
Last updated: 27 September 2026
ORDEİN YAZILIM VE DANIŞMANLIK LİMİTED ŞİRKETİ (“Ordein”, “we”) explains in this Privacy Policy how we collect, use and protect personal data when you visit our website, create an account or use the Ordein platform, and how you can exercise your rights.
1. Who we are
ORDEİN YAZILIM VE DANIŞMANLIK LİMİTED ŞİRKETİ is the company behind Ordein. Address: Büyükdere Caddesi, Levent Mahallesi, Çayırçimen Sokak, Emlak Kredi Blokları A2 Blok, Apt. No: 3/39 (Ofis No: 8), PK: 34330, Beşiktaş / İstanbul. Email: destek@ordein.com.
For website visitors and for the people who hold Ordein accounts (business owners and their staff), Ordein is the data controller.
For the data a business enters about its own customers — for example patient or client records, appointments and invoices — the business is the data controller and Ordein acts as its data processor. We process that data only on the business’s instructions and only to provide the service.
2. Data we collect
Account data: name, email address, phone number, business details and user role, provided when you sign up or when your business invites you.
Customer data entered by businesses: the records a business keeps about its customers, such as contact details, appointment history, treatment or service notes, photos, consent records and invoices. Depending on the type of business this can include health data, which is special-category personal data.
Technical data: IP address, browser and device information, session records and error logs, used to run and secure the service.
Enquiries: the name, phone number, email address and message you send us through the demo or contact form.
3. How we use data
To provide, maintain and secure the platform, including sign-in, permissions and support.
To answer demo requests and support questions, and to send service emails such as account confirmation and password resets.
To meet legal obligations, such as keeping invoicing records.
We do not sell personal data, and we never use the customer data that businesses enter for our own marketing.
4. Legal bases
We process personal data where it is necessary to perform our contract with you or your business, to meet a legal obligation, for our legitimate interest in running and securing the service (balanced against your rights), or with your consent — for example for optional cookies. You can withdraw consent at any time.
When a business records health data about its customers, the business is responsible for having a valid legal basis for it, such as the explicit consent of its customer or the provision of care.
5. Who processes data for us
Supabase — database, sign-in and file storage, hosted in Germany (EU).
Vercel — application hosting and delivery (United States).
Google — the Gemini AI models that answer AI Assistant questions (the question and the business data needed to answer it are sent to Google for processing); Google Analytics, Search Console and Google Ads, only for businesses that connect their own Google accounts; and the email service that sends our account and password emails.
Intercom — the live chat on our website, loaded only after you accept optional cookies or open the chat yourself.
A PCI-DSS compliant payment provider handles subscription card payments; we never see or store card details.
Each provider processes data only to deliver its service to us, under its data processing terms.
6. International transfers
Our database is in the EU. Some providers, such as Vercel, Google and Intercom, may process data in the United States or other countries. Where personal data leaves the UK or the European Economic Area, we rely on the safeguards in our providers’ data processing terms, such as the European Commission’s Standard Contractual Clauses.
Our team works from Istanbul and may access data where this is needed to provide support.
7. Google user data
Businesses can connect their own Google Analytics, Search Console and Google Ads accounts with their explicit consent, and disconnect them at any time from the Integrations page.
We access aggregated reporting data only: visits, traffic sources and conversions from Google Analytics; search queries, clicks and rankings from Search Console; campaign, keyword and cost performance from Google Ads. We never access your Google password, email or files.
We use this data only to show the business its own website and advertising performance inside Ordein, and to create advertising campaigns that the business reviews and approves. We do not use it for ad targeting, do not combine it across businesses, and do not sell it or share it for marketing.
Google access tokens are stored server-side in a separate database schema that no browser session can reach, and are never sent to the browser. When a business disconnects, the token is deleted immediately and permanently. Summary reporting data is kept for at most 12 months.
Ordein’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Instagram data
If a business connects its Instagram professional account, we access the account’s ID and username and the direct messages sent to it, only to show those messages to the business’s staff and to send their replies. We never use this data for advertising, combine it across businesses or sell it.
Disconnecting Instagram deletes the connection and access token immediately. To delete conversation history, email destek@ordein.com with the Instagram username; we complete deletion within 30 days.
9. How long we keep data
Account data is kept while the account is active. When an account is closed, the business can export its data for a reasonable period; the data is then deleted, except records the law requires us to keep, such as invoices.
Customer data entered by a business stays in Ordein for as long as the business keeps it there, and is deleted when the business deletes it or closes its account.
Demo and contact enquiries are kept only as long as we need them to follow up.
10. Security
Every connection is encrypted with TLS. Each business’s data is separated by row-level security in the database, and staff access is limited by role. Access to our systems is restricted to the people who need it.
If we become aware of a personal data breach, we will inform the affected businesses without undue delay and notify the authorities where required.
11. Your rights
Depending on where you live, you have the right to access your personal data, to have inaccurate data corrected, to have your data erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw consent at any time without affecting earlier processing.
To exercise these rights, email destek@ordein.com; we reply within one month. If you are a customer of a business that uses Ordein, please contact that business first — it controls your data, and we will help it respond.
You also have the right to complain to your local data protection authority.
12. Children
Ordein is a tool for businesses and is not directed at children. A business that records data about minors is responsible for doing so lawfully, including obtaining a parent’s or guardian’s consent where required.
13. Changes and contact
We may update this policy; the date at the top shows the current version, and we will tell account holders about significant changes.
Questions about privacy: destek@ordein.com · ORDEİN YAZILIM VE DANIŞMANLIK LİMİTED ŞİRKETİ, Büyükdere Caddesi, Levent Mahallesi, Çayırçimen Sokak, Emlak Kredi Blokları A2 Blok, Apt. No: 3/39 (Ofis No: 8), PK: 34330, Beşiktaş / İstanbul
