HemşireM

HemşireM Personal Data Processing Notice

Effective Date: July 26, 2026

This notice has been prepared under Article 10 of KVKK (Turkey's Personal Data Protection Law No. 6698) and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Disclosure Obligation, in order to inform you about the personal data processed when you use the "HemşireM" mobile application (the "App").

HemşireM is a shift/schedule planning app for nurses working in Turkey. It is intended for adult healthcare professionals; it is not intended for anyone under 18.


1. Identity of the Data Controller

Your personal data is processed, within the scope and for the purposes described below, by the indie developer Yakup Habanoğlu acting as the data controller.

You can submit all of your KVKK-related requests via the email address above.


2. Categories of Personal Data Processed

The App embraces the principle of data minimization and processes only the minimum data the function requires. The data processed is as follows:

Data CategoryData ProcessedWhere It Is Stored
Identity / ContactThe email address obtained from the identity provider (Google/Apple) during sign-inFirebase Authentication (cloud)
Transaction SecurityFirebase user ID (UID)Firebase Authentication (cloud) + device
Published schedule dataIf the charge nurse publishes a schedule: unit name, month/year, 6-digit join code, team list (each person's name, position, and whether they are the charge nurse), and shift details (date, type, time)Cloud Firestore (cloud)
Pro access statusIf a promotional code is redeemed: the code used, platform information (Android/iOS) and, if applicable, the expiry date of the accessCloud Firestore (cloud)
Local app dataStaff, shifts, claims (matching), manual calendar, settings, swap historyOn your device only (Hive + shared_preferences)

Your real name is not shown in any community — the App has no "community" feature. Identity information is used solely to match you with your own shifts.

Important — About team data: The names and positions of team members in the "published schedule data" are, in most cases, team data entered by the charge nurse (the person using the App) — meaning this may be the personal data not of you, but of other people on your team. This point is addressed separately in Section 9 below.

Data Not Processed / Not Collected

As part of the App's strong privacy approach, the following data is never collected and never sent to the cloud:


3. Purposes of Processing Personal Data

Your personal data is processed for the following purposes:


4. Legal Grounds for Processing Personal Data (KVKK Art. 5)

Your personal data is processed based on the following legal grounds set out in Article 5 of KVKK:

- Being directly related to the establishment or performance of a contract (Art. 5/2-c):
The email address and UID are necessary to establish and perform the usage relationship between us (the provision of the App service), to let you sign in, and to enable your shifts to be matched.

- The legitimate interest of the data controller (Art. 5/2-f):
Running the App's core functions securely, preventing misuse, and protecting service integrity rely on this legal ground, provided that the fundamental rights and freedoms of the data subject are not harmed.

- Explicit consent (Art. 5/1):
The charge nurse's choice to publish a schedule (writing the team list and shift details to Cloud Firestore and sharing them with signed-in users) is an optional action; this action takes place at the will (explicit consent) of the user who publishes it. Unless a schedule is published, this data is not sent to the cloud.

Note: Because health/special-category personal data is never uploaded to the cloud under any circumstances, no special-category data processing under KVKK Art. 6 is involved.

5. Parties to Whom Personal Data Is Transferred and Transfers Abroad (KVKK Art. 8–9)

Your personal data is processed only through the following data processor service providers, in order to make the service technically available. Apart from this, it is not sold to any third party and is not shared for marketing purposes.

- Google (Firebase Authentication + Cloud Firestore):
Authentication (email, UID) and the storage of published schedule data take place on Google's infrastructure.
- Apple ("Sign in with Apple"):
When sign in with Apple is chosen, authentication is performed via Apple's infrastructure.

Transfer Abroad: Because the servers of Google and Apple may be located in countries outside Turkey and the EU, the processing of the above data may amount to a transfer of data abroad. This transfer is carried out within the framework of KVKK Art. 9 and based on the legal grounds set out in Section 4 above.

Access to a published schedule: When a schedule is published, under the Firestore security rules it can be read only by users who have signed in to the App; permission to write/update/delete belongs only to the owner who published the schedule (ownerUid).

Purchases: Subscriptions for charge-nurse tools are purchased through Google Play or the App Store. Your payment details are processed directly by the relevant store; this information is not transmitted to the data controller and is not visible to us. The app only learns from the store whether a subscription is active; this information is not written to the cloud.


6. Retention Periods for Personal Data

Account and Data Deletion

Using the in-app option Settings > "Delete account":

are permanently deleted. The local data on your device, on the other hand, is deleted when you uninstall the App.


7. Rights of the Data Subject (KVKK Art. 11)

Under Article 11 of KVKK, by applying to the data controller you have the following rights:

a) To learn whether your personal data is being processed,
b) To request information if it has been processed,
c) To learn the purpose of the processing and whether the data is used in line with that purpose,
ç) To know the third parties, in Turkey or abroad, to whom the data is transferred,
d) To request correction if it has been processed incompletely or incorrectly,
e) To request its deletion or destruction within the conditions set out in KVKK and the relevant legislation,
f) To request that the operations carried out under items (d) and (e) be notified to the third parties to whom the data was transferred,
g) To object to any result that arises against you due to the analysis of the processed data solely by automated systems,
ğ) To request that the damage be remedied if you suffer harm due to unlawful processing.

How to Apply

You can submit your requests regarding the rights above, together with information verifying your identity, to the email address d.jacopmd@gmail.com. Under KVKK Art. 13, your applications are concluded free of charge as soon as possible and within 30 (thirty) days at the latest, depending on the nature of the request; if the process additionally entails a cost, the fee in the tariff set by the Board may be charged.


8. Data Security

A significant portion of the data is stored only on your device and is not sent to any server. Data written to the cloud is protected by Google's security infrastructure and by Firestore security rules (only the owner can write, only signed-in users can read). Special-category/health data, on the other hand, is never transferred to the cloud.


9. Note on the Charge Nurse Uploading Team Data

When a schedule is published, the names and positions of the team members included in the schedule are usually entered by the charge nurse who manages the schedule. In this case:

This point is brought to the attention of charge nurses who use the publishing feature.

Recommendation — entering real names is not mandatory: The app allows you to add team members using initials, nicknames or labels such as "Nurse 1". Where your institution's rules permit, we recommend this approach; in that case no identifiable personal data is transferred to the cloud and the obligations above are significantly reduced.


*This notice took effect on July 26, 2026. Updates may be announced through the App and/or via the contact channel above.*