Healthcare data deserves more than a privacy policy.
Native e-Nabız and e-Fatura compliance, full KVKK-aligned data handling, and an audit trail on every action — not a privacy policy and a promise.
0. e-Nabız & Government Compliance
Klinio includes native e-Nabız / HBYS submission, with institution and facility code configuration, a submission queue with status tracking (draft, pending, sent, failed), and a full HTTP audit trail for every government submission. e-Fatura / e-Arşiv connectivity is available the same way — built into the platform settings, not a separate tool you have to reconcile manually.
0.1 KVKK & Legal Framework
Klinio maintains a structured legal and consent framework aligned with KVKK (Turkish Personal Data Protection Law): Terms of Use, Privacy Policy, a KVKK disclosure, a Data Processing Agreement, and explicit, separately tracked consent for cloud backup, AI usage, and media/radiology uploads. Nothing is bundled into a single blanket consent — each capability is opted into on its own.
1. Local-First Architecture
Klinio is local-first by design. Clinic and patient data is stored in a local database on the clinic's own workstation by default. Data only leaves the device when the clinic explicitly enables optional cloud sync or the encrypted cloud backup add-on.
2. Multi-Tenant Clinic Isolation
When cloud sync is enabled, Klinio enforces strict logical separation of all clinic records using database-level Row-Level Security (RLS). This ensures that your clinic's rows cannot be accessed, modified, or viewed by other accounts or organizations.
3. Encryption Standards
- In Transit: Communications between the desktop program, web browsers, and synchronization databases use secure transport protocols.
- At Rest: Cloud storage and database services use provider-managed encryption at rest where cloud features are enabled. Local workstation protection depends on the clinic device and operating-system configuration.
- API Access: Application credentials are not exposed in public website code. Authorization is handled through controlled client and server-side policies.
4. Role-Based Access Controls (RBAC)
Administrators can define permissions on a user-by-user basis. Prevent unauthorized clinic staff from viewing payment reports, exporting doctor commissions, or deleting historical clinical files. Each action is authorized locally before execution.
5. Audit Logs & Verification
Klinio includes an internal audit logging architecture. Major actions—such as patient exports, database backups, file deletions, or credential modifications—are recorded to a local, tamper-evident log history.
6. Safe AI Assistant Processing
Klinio AI drafting queries are processed over secure endpoints. Patient names and clinical identification numbers are sanitized or stripped prior to transmission to drafting models. AI prompts and generated drafts are never used to train third-party public models.
7. Clinical Backups & Data Portability
With local-first operations, clinic owners retain full ownership of their data. You can export the entire SQL state, clinical images, and proposal PDFs at any point. Database backups can be scheduled locally to external drives, or synced to our secure cloud backup add-on.
Klinio provides local-first storage, optional encrypted cloud backup, secure transport, provider-managed encryption at rest, and database access isolation. Clinics remain responsible for configuring their own workstation security and verifying that their setup meets the healthcare compliance requirements applicable in their region.