Türkçe metin üstte, İngilizce metin aşağıdadır.
Son güncelleme: 6 Ekim 2026
Kısaca: Voxy Patoloji, dikte ettiğiniz sesi yazıya ve patoloji raporuna dönüştürür; raporu laboratuvar bilgi sisteminizde (LIS) açık olan vakanın ilgili bölümüne yazar. Bunun için dikte sesinizi, dikte metninizi ve raporlarınızı, hesap bilgilerinizi, LIS vaka sayfasındaki vaka numaralarını ve rapor bölümünün metnini, ayrıca bazı teknik kayıtları işler. Tarama geçmişinizi ve desteklenen LIS sayfaları dışındaki sitelerin içeriğini toplamaz. Verileriniz, kurumunuzla yaptığımız sözleşmeye göre Birleşik Krallık, Amerika Birleşik Devletleri veya Türkiye'de bulunan bulut sağlayıcıları üzerinde çalışan sunucularımızda saklanır. Verileriniz satılmaz ve reklam için kullanılmaz. Hastalarınızın verileri için karar verici kurumunuzdur; biz kurumunuzun talimatıyla çalışırız.
Bu bildirim, Voxy Patoloji Chrome eklentisini ve eklentinin açtığı Voxy panelini kapsar. www.meditechlabs.ai web sitesi için Aydınlatma Metni geçerlidir.
1. Kim sorumlu
Eklentiyi MediTechLabs Yazılım Anonim Şirketi sunar (MERSİS 0614169719700001; Çifte Havuzlar Mah. Eski Londra Asfaltı Cad. Kuluçka Mrk. A1 Blok No:151/1C İç Kapı No: B34 Esenler/İstanbul; kvkk@meditechlabs.ai).
Eklentiyi bir sağlık kuruluşu adına kullanıyorsanız, dikte ettiğiniz ve raporladığınız hasta verileri için sorumlu taraf kurumunuzdur; biz bu verileri kurumunuzla imzaladığımız sözleşme çerçevesinde ve kurumunuzun talimatıyla işleriz. Hesap ve kullanım bilgileriniz için sorumlu taraf biziz.
2. Hangi verileri topluyoruz
Sizin verdiğiniz veriler
- Hesap bilgileri: ad soyad, e-posta adresi, kurum adı ve kullanıcı rolünüz.
- Giriş bilgileri: şifreniz şifreli bağlantıyla sunucuya iletilir, tarayıcıda saklanmaz. Girişten sonra verilen oturum jetonu tarayıcınızda tutulur. Şifre sıfırlama talebinde bulunursanız e-posta adresiniz talebinizle birlikte kaydedilir.
- Dikte sesi: dikte sırasında mikrofonunuzdan alınan ses, yazıya dökülmek üzere sunucularımıza iletilir ve orada saklanır.
- Uyandırma kelimesi ses kesitleri: uyandırma kelimesi açıkken (varsayılan: açık) ve panel görünürken mikrofon, komutu algılamak için tarayıcınızda dinlenir; bu dinleme sırasında ses sunucuya gönderilmez. Komut algılandığında ya da komuta çok benzeyen bir ses duyulduğunda, algılamanın doğruluğunu ölçmek için o ana ait birkaç saniyelik ses kesiti sunucularımıza gönderilir. Uyandırma kelimesini panelin Ayarlar bölümünden kapatabilirsiniz; kapalıyken bu kesitler gönderilmez.
- Dikte metni ve raporlar: dikte ettiğiniz metin, oluşturulan raporlar, seçtiğiniz şablon, kısaltmalarınız, şablonlara verdiğiniz alternatif adlar ve bir rapora koyduğunuz "kötü çıktı" işareti. Bu veriler hasta sağlık bilgisi içerebilir.
LIS sayfasından okunan veriler
Eklenti bu verileri yalnızca desteklenen LIS vaka sayfasında okur.
- Vakanın protokol numarası, rapor numarası ve kayıt numarası.
- LIS'te oturum açmış kullanıcının adı ve numarası (LIS oturum bilgisinden okunur).
- Raporun yazılacağı bölümde o an duran metin. Bu metin, mevcut içeriğin korunması ve raporun ona göre oluşturulması için sunucularımıza gönderilir ve rapor kaydıyla birlikte saklanabilir.
- Vakanın kaset listesi ile ek istem listesi ve kurumunuzun ek istem kataloğu (istem türleri ve taslak metinleri). Ek istem listesi ve katalog, LIS oturumunuzla LIS'in kendi sunucusundan okunur; vakanın ilgili alanlarını doldurmak için tarayıcınızda kullanılır. Hasta verisi içermeyen katalog, güncel tutulmak üzere sunucularımıza kaydedilir. LIS oturum jetonunuz yalnızca LIS'in kendi sunucusuna gönderilir; sunucularımıza gönderilmez.
Kullanım sırasında oluşan kayıtlar
- Elle yapılan değişikliklerin kaydı: rapor bölümlerinde ve paneldeki dikte metninde klavye, yapıştırma, kesme ya da sesle düzeltme yoluyla yaptığınız değişiklikler denetim amacıyla kaydedilir. Kayıt; değişikliğin türünü, yapıldığı bölümü, vaka numarasını ve eklenen ile silinen metni (en çok 500 karakter) içerir.
- Oturum kayıtları: dikte oturumunun başlaması ve bitmesi, rapor oluşturulması, bunların süresi ve ilgili vaka numaraları.
- Ses kalitesi ölçümleri: gürültü düzeyi, ses düzeyi ve segment süreleri gibi sayısal ölçümler ile kullandığınız mikrofonun adı. Bu kayıtlar ses içermez.
- Tanılama kayıtları: eklenti raporu sayfaya yazamadığında arızanın türü, eklenti sürümü, sayfanın yapısına ilişkin sayılar ve sayfanın adresi kaydedilir. Adresteki numaralar gizlenerek yazılır. Bu kayıtlar hasta metni ve rapor içeriği içermez. Tanılama kayıtlarını ve ses kalitesi ölçümlerini eklentinin ayarlarından kapatabilirsiniz.
- Sunucu kayıtları: IP adresiniz, tarayıcı bilginiz ve istek zamanı.
- Tercihler: panelin konumu ve boyutu, rapor çıktı tercihleri, yazı boyutu, tema ve eklenti ayarları.
Toplamadıklarımız
Tarama geçmişiniz, desteklenen LIS sayfaları dışındaki sitelerin içeriği, konumunuz ve ödeme bilgileriniz toplanmaz.
3. Verileri nasıl kullanıyoruz
Verilerinizi yalnızca şu amaçlarla kullanırız:
- dikte ettiğiniz sesi yazıya dökmek;
- patoloji raporunu oluşturmak, vakanın ilgili bölümüne yazmak ve saklamak;
- hesabınızı doğrulamak ve oturumunuzu sürdürmek;
- rapora yapılan değişikliklerin sonradan denetlenebilmesini sağlamak;
- hizmeti güvenli ve çalışır tutmak, hataları gidermek;
- konuşma tanımanın, uyandırma kelimesinin ve rapor üretiminin doğruluğunu ölçmek ve iyileştirmek.
Hasta verilerini kurumunuzun belirlediği amaç ve şartlarla, kurumunuzun talimatıyla işleriz.
Ses kayıtlarınız, dikte metinleriniz ve raporlarınız model eğitiminde varsayılan olarak kullanılmaz. Böyle bir kullanım ancak kurumunuzla ayrıca anlaşılır ve gerekli hukuki şartlar sağlanırsa yapılır.
Verileriniz reklam için kullanılmaz, kişiselleştirilmiş reklam için aktarılmaz ve satılmaz. Kredi değerliliği belirleme ya da borç verme amacıyla kullanılmaz.
4. Verileri nerede ve ne kadar süre saklıyoruz
Tarayıcınızda
Oturum jetonunuz ve panel tercihleriniz tarayıcınızda saklanır; çıkış yaptığınızda oturum jetonunuz silinir. Oturumunuz beklenmedik biçimde kapanırsa ya da sayfa yenilenirse, o vakaya ait bitmemiş dikte metni kaybolmaması için tarayıcınızda taslak olarak saklanır ve aynı kullanıcı aynı vakaya döndüğünde geri yüklenir. Kendi isteğinizle çıkış yaptığınızda taslak saklanmaz. Eklentinin yerleşim ve çıktı ayarları ile giriş yapan kullanıcının numarası ve rolü, tarayıcının eklenti depolama alanında (chrome.storage.local) tutulur.
Sunucularımızda
Veriler tarayıcınız ile sunucularımız arasında şifreli bağlantıyla (HTTPS ve WSS) iletilir. Sunucularımız, kurumunuzla yaptığımız sözleşmeye göre Birleşik Krallık, Amerika Birleşik Devletleri veya Türkiye'de bulunan bulut sağlayıcıları üzerinde çalışır; Türkiye dışındaki bir konum seçildiğinde verileriniz Türkiye dışında işlenir ve saklanır. Her ülkede yerel bulut firmalarıyla çalışırız: Türkiye'deki canlı (production) kurulumlar DT Cloud (DT İletişim Hizmetleri A.Ş.; İstanbul ve Ankara veri merkezleri), Birleşik Krallık'taki kurulumlar GIGAGPU, ABD'deki kurulumlar Microsoft Azure altyapısında çalışır. Demo ortamlarımız Microsoft Azure'un ABD'deki sunucularında çalışır. Veriler diskte, sağlayıcının depolama şifrelemesiyle (AES-256) şifrelenmiş olarak saklanır. Veritabanı ve dosyalar her gün yedeklenir; yedekler sözleşmede belirlenen bulut altyapısında tutulur.
Saklama süreleri
- Hesap bilgileri: hesabınız açık olduğu sürece.
- Raporlar, dikte metinleri, dikte sesleri, uyandırma kelimesi ses kesitleri ve değişiklik kayıtları: kurumunuzla yaptığımız sözleşme yürürlükte olduğu sürece.
- Oturum, ölçüm ve tanılama kayıtları: kurumunuzla yaptığımız sözleşme yürürlükte olduğu sürece.
- Sunucu ve izleme kayıtları: sınırlı süre ve boyutta tutulur; süre ya da alan dolunca en eski kayıtlar silinir.
- Yedekler: 30 gün.
Hesabınız kapatıldığında, kurumunuzla sözleşmemiz sona erdiğinde ya da siz veya kurumunuz silinmesini istediğinde verileri sileriz. Silinen veriler yedeklerden en geç 30 gün içinde çıkar. Yasanın daha uzun saklamayı zorunlu kıldığı kayıtlar bu sürenin dışındadır.
5. Verileri kimlerle paylaşıyoruz
Verilerinizi satmayız ve reklam için kimseye vermeyiz. Hizmeti sunmak için gerektiği ölçüde yalnızca şu taraflarla paylaşırız:
- Bulut altyapı sağlayıcılarımız (kurumunuzla yaptığımız sözleşmeye göre Birleşik Krallık, Amerika Birleşik Devletleri veya Türkiye'de bulunan bulut sağlayıcıları): sunucularımızın ve veritabanımızın barındırılması, hizmetin izlenmesi ve günlük yedekleme. 2. bölümde sayılan veriler bu altyapıda işlenir ve saklanır.
- Kurumunuz: rapor, sizin işleminizle kurumunuzun LIS'indeki vakaya yazılır. Hesabınız kurumunuz adına açıldığı için kurumunuz, kendi kullanıcılarına ait kayıtları sözleşme çerçevesinde bizden isteyebilir.
- Yetkili kamu kurumları: yalnızca yasal bir yükümlülük gerektirdiğinde.
Bu sağlayıcılar verileri bizim adımıza ve yalnızca hizmeti sunabilmemiz için işler. Bunların dışında yalnızca kötü amaçlı yazılım, dolandırıcılık, kötüye kullanım ve güvenlik ihlallerine karşı korunmak için gerektiğinde paylaşım yaparız. Şirket birleşmesi, devralma veya varlık satışında kullanıcı verilerinin devri, önceden vereceğiniz açık onaya bağlıdır; bu onay hasta verileri için gereken şartların yerine geçmez.
Çalışanlarımız verilerinizi yalnızca belirli bir veriye erişim için açık onay verdiğinizde, güvenlik için gerektiğinde, yasal bir yükümlülük için ya da toplulaştırılıp anonim hale getirilmiş verilerle yürütülen iç işlerde okuyabilir. Hasta verilerine erişim için ayrıca kurumunuzun yetkisi ve hukuki şartlar aranır. Erişim, görevi gerektiren yetkili çalışanlarla sınırlıdır.
6. Tarayıcı izinleri
Eklenti kurulurken hiçbir web sitesine erişim izni istemez. Panel yalnızca siz eklenti simgesine tıkladığınızda, tıkladığınız sekmede açılır. Eklentinin ayarlarında "LIS açılınca paneli otomatik getir" seçeneğini açarsanız tarayıcı yalnızca kurumunuzun LIS adresi için sizden izin ister; bu izni aynı yerden geri alabilirsiniz. Mikrofon izni panel ilk açıldığında tarayıcı tarafından sorulur.
7. Haklarınız
Verilerinizin işlenip işlenmediğini öğrenebilir, bilgi isteyebilir, düzeltilmesini veya silinmesini isteyebilir ve işlemeye itiraz edebilirsiniz. Başvurunuzu kvkk@meditechlabs.ai adresine ya da İlgili Kişi Başvuru Formu ile iletin; en geç 30 gün içinde yanıtlarız. Hasta verilerine ilişkin talepleri, sorumlu taraf olan kurumunuza yönlendiririz. Hesabınızın ve verilerinizin silinmesini aynı adresten isteyebilirsiniz.
8. Chrome Web Mağazası Sınırlı Kullanım beyanı
Voxy Patoloji'nin kullanıcı verilerini kullanımı, Sınırlı Kullanım gereksinimleri dahil olmak üzere Chrome Web Mağazası Kullanıcı Verileri Politikası'na uygundur.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
9. Değişiklikler
Bu bildirimi güncellediğimizde bu sayfada yayımlar ve "Son güncelleme" tarihini yenileriz.
Hukuki dayanaklar (KVKK)
| İşlem | Dayanak |
|---|---|
| Hasta verileri | Kurumunuzun veri sorumlusu olarak belirlediği ve şartlarını sağladığı m.6 kapsamındaki sebep; biz m.3 anlamında veri işleyeniz |
| Hesap ve kullanım verileri | m.5/2-c sözleşmenin ifası; m.5/2-f meşru menfaat |
| Model eğitimi | Yalnızca ayrıca belirlenen geçerli dayanakla; varsayılan olarak yapılmaz |
| Haklarınız | m.11, m.13 |
Voxy Patoloji Chrome Extension — Privacy Notice (English)
Last updated: 6 October 2026
In short: Voxy Patoloji turns your dictation into text and into a pathology report, and writes the report into the matching section of the case that is open in your laboratory information system (LIS). To do this it processes your dictation audio, your dictated text and reports, your account details, the case numbers and the report section text shown on the LIS case page, and some technical records. It does not collect your browsing history or the content of any site other than the supported LIS pages. Your data is stored on our servers running on cloud providers located in the United Kingdom, the United States or Türkiye, depending on the contract with your institution. Your data is not sold and is not used for advertising. Your institution decides how its patients' data is handled; we act on your institution's instructions.
This notice covers the Voxy Patoloji Chrome extension and the Voxy panel it opens. The website www.meditechlabs.ai is covered by its own privacy notice.
1. Who is responsible
The extension is provided by MediTechLabs Yazılım Anonim Şirketi (MERSİS 0614169719700001; Çifte Havuzlar Mah. Eski Londra Asfaltı Cad. Kuluçka Mrk. A1 Blok No:151/1C İç Kapı No: B34 Esenler/İstanbul, Türkiye; kvkk@meditechlabs.ai).
If you use the extension on behalf of a healthcare institution, your institution is the data controller for the patient data you dictate and report; we process that data under our agreement with your institution and on its instructions. We are the controller for your account and usage information.
2. Data collection — what we collect
Data you provide
- Account details: name, e-mail address, institution name and your user role.
- Sign-in details: your password is sent to the server over an encrypted connection and is not stored in the browser. The session token issued after sign-in is kept in your browser. If you request a password reset, your e-mail address is recorded with the request.
- Dictation audio: the audio captured from your microphone while you dictate is sent to our servers to be transcribed, and is stored there.
- Wake-word audio clips: while the wake word is on (default: on) and the panel is visible, the microphone is listened to in your browser to detect the command; no audio is sent to the server during this listening. When the command is detected, or a sound very close to it is heard, a clip of a few seconds from that moment is sent to our servers to measure detection accuracy. You can turn the wake word off in the panel's Settings; no clips are sent while it is off.
- Dictated text and reports: the text you dictate, the reports generated, the template you choose, your abbreviations, the alternative names you give to templates, and the "bad output" flag you may put on a report. This data may contain patient health information.
Data read from the LIS page
The extension reads this data only on the supported LIS case page.
- The protocol number, report number and record number of the case.
- The name and number of the user signed in to the LIS (read from the LIS session information).
- The text currently in the report section the report will be written to. This text is sent to our servers so that existing content is preserved and the report is generated accordingly, and it may be stored with the report record.
- The cassette list and the additional-request list of the case, and your institution's additional-request catalogue (request types and draft texts). The additional-request list and the catalogue are read from the LIS's own server with your LIS session and are used in your browser to fill the related fields of the case. The catalogue, which contains no patient data, is saved on our servers to keep it up to date. Your LIS session token is sent only to the LIS's own server; it is not sent to our servers.
Records created during use
- Record of manual changes: changes you make to the report sections and to the dictated text in the panel by keyboard, paste, cut or voice correction are recorded for audit purposes. The record contains the type of change, the section, the case number, and the inserted and deleted text (up to 500 characters).
- Session records: the start and end of a dictation session, report generation, their duration and the related case numbers.
- Audio quality measurements: numeric measurements such as noise level, audio level and segment durations, and the name of the microphone you use. These records contain no audio.
- Diagnostic records: when the extension cannot write the report into the page, the type of failure, the extension version, counts describing the page structure and the page address are recorded. Numbers in the address are masked. These records contain no patient text or report content. You can turn off diagnostic records and audio quality measurements in the extension's settings.
- Server logs: your IP address, browser information and the time of the request.
- Preferences: panel position and size, report output preferences, font size, theme and extension settings.
What we do not collect
We do not collect your browsing history, the content of sites other than the supported LIS pages, your location or your payment information.
3. Data use — how we use and handle data
We use your data only to:
- transcribe the audio you dictate;
- generate the pathology report, write it into the matching section of the case and store it;
- verify your account and keep you signed in;
- make changes to a report auditable afterwards;
- keep the service secure and running, and fix errors;
- measure and improve the accuracy of speech recognition, wake-word detection and report generation.
We process patient data for the purposes and under the conditions set by your institution, on your institution's instructions.
Your audio recordings, dictated text and reports are not used for model training by default. Such use takes place only if it is separately agreed with your institution and the applicable legal conditions are met.
Your data is not used for advertising, is not transferred for personalised advertising and is not sold. It is not used to determine creditworthiness or for lending purposes.
4. Data storage — where and for how long
In your browser
Your session token and panel preferences are stored in your browser; the session token is deleted when you sign out. If your session ends unexpectedly or the page is reloaded, the unfinished dictated text for that case is kept in your browser as a draft so that it is not lost, and is restored when the same user returns to the same case. No draft is kept when you sign out yourself. The extension's layout and output settings and the signed-in user's number and role are kept in the browser's extension storage (chrome.storage.local).
On our servers
Data is transmitted between your browser and our servers over an encrypted connection (HTTPS and WSS). Our servers run on cloud providers located in the United Kingdom, the United States or Türkiye, depending on the contract with your institution; when a location outside Türkiye is chosen, your data is processed and stored outside Türkiye. We work with local cloud companies in each country: production deployments in Türkiye run on DT Cloud (DT İletişim Hizmetleri A.Ş.; data centres in İstanbul and Ankara), deployments in the United Kingdom on GIGAGPU, and deployments in the United States on Microsoft Azure. Our demo environments run on Microsoft Azure servers in the United States. Data is stored on disk encrypted with the provider's storage encryption (AES-256). The database and files are backed up daily; backups are kept on the cloud infrastructure specified in the contract.
Retention periods
- Account details: for as long as your account is open.
- Reports, dictated text, dictation audio, wake-word audio clips and records of changes: for as long as our agreement with your institution is in force.
- Session, measurement and diagnostic records: for as long as our agreement with your institution is in force.
- Server and monitoring logs: kept for a limited time and size; the oldest entries are deleted when the time or the space runs out.
- Backups: 30 days.
We delete the data when your account is closed, when our agreement with your institution ends, or when you or your institution ask for deletion. Deleted data leaves the backups within 30 days at the latest. Records that the law requires us to keep longer are excepted.
5. Data sharing — who we share data with
We do not sell your data and do not give it to anyone for advertising. We share it only with the following parties, and only to the extent needed to provide the service:
- Our cloud infrastructure providers (cloud providers located in the United Kingdom, the United States or Türkiye, depending on the contract with your institution): hosting of our servers and database, service monitoring and daily backups. The data listed in section 2 is processed and stored on this infrastructure.
- Your institution: the report is written, by your action, into the case in your institution's LIS. Because your account is opened on behalf of your institution, your institution may request the records of its own users from us under our agreement.
- Competent public authorities: only where a legal obligation requires it.
These providers process the data on our behalf and only so that we can provide the service. Beyond these, we share data only where needed to protect against malware, fraud, abuse and security breaches. A transfer of user data as part of a merger, acquisition or sale of assets is subject to your prior explicit consent; that consent does not replace the conditions required for patient data.
Our employees may read your data only when you have given explicit consent for specific data, when it is necessary for security purposes, to comply with a legal obligation, or for internal operations carried out with aggregated and anonymised data. Access to patient data additionally requires your institution's authorisation and the applicable legal conditions. Access is limited to authorised employees whose duties require it.
6. Browser permissions
The extension asks for no website access at installation. The panel opens only in the tab where you click the extension icon. If you switch on "LIS açılınca paneli otomatik getir" (open the panel automatically on the LIS) in the extension's settings, the browser asks for your permission for your institution's LIS address only; you can withdraw that permission in the same place. Microphone permission is requested by the browser when the panel is first opened.
7. Your rights
You can learn whether your data is processed, request information, ask for correction or deletion, and object to processing. Send your request to kvkk@meditechlabs.ai or use the data subject application form; we reply within 30 days at the latest. We forward requests concerning patient data to your institution, which is the controller. You can ask for your account and data to be deleted at the same address.
8. Chrome Web Store Limited Use disclosure
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
9. Changes
When we update this notice, we publish it on this page and renew the "Last updated" date.