HemşireM Personal Data Processing Notice
Effective Date: July 26, 2026
This notice has been prepared under Article 10 of KVKK (Turkey's Personal Data Protection Law No. 6698) and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Disclosure Obligation, in order to inform you about the personal data processed when you use the "HemşireM" mobile application (the "App").
HemşireM is a shift/schedule planning app for nurses working in Turkey. It is intended for adult healthcare professionals; it is not intended for anyone under 18.
1. Identity of the Data Controller
Your personal data is processed, within the scope and for the purposes described below, by the indie developer Yakup Habanoğlu acting as the data controller.
- Data Controller: Yakup Habanoğlu (individual developer)
- Contact (email): d.jacopmd@gmail.com
- App: HemşireM (Android and iOS)
You can submit all of your KVKK-related requests via the email address above.
2. Categories of Personal Data Processed
The App embraces the principle of data minimization and processes only the minimum data the function requires. The data processed is as follows:
| Data Category | Data Processed | Where It Is Stored |
|---|---|---|
| Identity / Contact | The email address obtained from the identity provider (Google/Apple) during sign-in | Firebase Authentication (cloud) |
| Transaction Security | Firebase user ID (UID) | Firebase Authentication (cloud) + device |
| Published schedule data | If the charge nurse publishes a schedule: unit name, month/year, 6-digit join code, team list (each person's name, position, and whether they are the charge nurse), and shift details (date, type, time) | Cloud Firestore (cloud) |
| Pro access status | If a promotional code is redeemed: the code used, platform information (Android/iOS) and, if applicable, the expiry date of the access | Cloud Firestore (cloud) |
| Local app data | Staff, shifts, claims (matching), manual calendar, settings, swap history | On your device only (Hive + shared_preferences) |
Your real name is not shown in any community — the App has no "community" feature. Identity information is used solely to match you with your own shifts.
Important — About team data: The names and positions of team members in the "published schedule data" are, in most cases, team data entered by the charge nurse (the person using the App) — meaning this may be the personal data not of you, but of other people on your team. This point is addressed separately in Section 9 below.
Data Not Processed / Not Collected
As part of the App's strong privacy approach, the following data is never collected and never sent to the cloud:
- Health and special-category personal data never leaves the device for the cloud. Information such as exemptions, pregnancy, experience/seniority, and personal notes is not uploaded to the cloud.
- There is no analytics.
- There is no crash reporting (Crashlytics).
- There are no ads and no third-party ad SDKs.
- There is no tracking.
- No location data is collected.
- There is no access to contacts/address book.
- There are no push/remote notifications (FCM) — all notifications run only on the device (locally).
3. Purposes of Processing Personal Data
Your personal data is processed for the following purposes:
- Providing secure sign-in and authentication to the App (sign in with Google / Apple),
- Matching the user with their own shifts under the correct account,
- If the charge nurse chooses to do so, publishing the shift schedule so that team members can access the schedule using a 6-digit join code,
- Carrying out the App's core functions (viewing the schedule, tracking shifts, swaps),
- Upon your request, deleting your account and your data in the cloud,
- Displaying news content from the Sağlık Aktüel and Anadolu Agency RSS feeds (no user data is sent during this; news is fetched read-only over HTTP, and tapping a news item opens an external browser).
4. Legal Grounds for Processing Personal Data (KVKK Art. 5)
Your personal data is processed based on the following legal grounds set out in Article 5 of KVKK:
- Being directly related to the establishment or performance of a contract (Art. 5/2-c):
The email address and UID are necessary to establish and perform the usage relationship between us (the provision of the App service), to let you sign in, and to enable your shifts to be matched.
- The legitimate interest of the data controller (Art. 5/2-f):
Running the App's core functions securely, preventing misuse, and protecting service integrity rely on this legal ground, provided that the fundamental rights and freedoms of the data subject are not harmed.
- Explicit consent (Art. 5/1):
The charge nurse's choice to publish a schedule (writing the team list and shift details to Cloud Firestore and sharing them with signed-in users) is an optional action; this action takes place at the will (explicit consent) of the user who publishes it. Unless a schedule is published, this data is not sent to the cloud.
Note: Because health/special-category personal data is never uploaded to the cloud under any circumstances, no special-category data processing under KVKK Art. 6 is involved.
5. Parties to Whom Personal Data Is Transferred and Transfers Abroad (KVKK Art. 8–9)
Your personal data is processed only through the following data processor service providers, in order to make the service technically available. Apart from this, it is not sold to any third party and is not shared for marketing purposes.
- Google (Firebase Authentication + Cloud Firestore):
Authentication (email, UID) and the storage of published schedule data take place on Google's infrastructure.
- Apple ("Sign in with Apple"):
When sign in with Apple is chosen, authentication is performed via Apple's infrastructure.
Transfer Abroad: Because the servers of Google and Apple may be located in countries outside Turkey and the EU, the processing of the above data may amount to a transfer of data abroad. This transfer is carried out within the framework of KVKK Art. 9 and based on the legal grounds set out in Section 4 above.
Access to a published schedule: When a schedule is published, under the Firestore security rules it can be read only by users who have signed in to the App; permission to write/update/delete belongs only to the owner who published the schedule (ownerUid).
Purchases: Subscriptions for charge-nurse tools are purchased through Google Play or the App Store. Your payment details are processed directly by the relevant store; this information is not transmitted to the data controller and is not visible to us. The app only learns from the store whether a subscription is active; this information is not written to the cloud.
6. Retention Periods for Personal Data
- Email and UID (Firebase Auth): Retained for as long as your account is active. When you delete your account, they are permanently deleted.
- Published schedules and join codes (Cloud Firestore): Retained until you delete them, or permanently deleted when you delete your account.
- Local data on the device (Hive / shared_preferences): Stays on your device; it is not sent to any server. It is deleted when you remove the App from your device.
Account and Data Deletion
Using the in-app option Settings > "Delete account":
- Your published schedules in the cloud,
- The join codes you created,
- Your Firebase Authentication account
are permanently deleted. The local data on your device, on the other hand, is deleted when you uninstall the App.
7. Rights of the Data Subject (KVKK Art. 11)
Under Article 11 of KVKK, by applying to the data controller you have the following rights:
a) To learn whether your personal data is being processed,
b) To request information if it has been processed,
c) To learn the purpose of the processing and whether the data is used in line with that purpose,
ç) To know the third parties, in Turkey or abroad, to whom the data is transferred,
d) To request correction if it has been processed incompletely or incorrectly,
e) To request its deletion or destruction within the conditions set out in KVKK and the relevant legislation,
f) To request that the operations carried out under items (d) and (e) be notified to the third parties to whom the data was transferred,
g) To object to any result that arises against you due to the analysis of the processed data solely by automated systems,
ğ) To request that the damage be remedied if you suffer harm due to unlawful processing.
How to Apply
You can submit your requests regarding the rights above, together with information verifying your identity, to the email address d.jacopmd@gmail.com. Under KVKK Art. 13, your applications are concluded free of charge as soon as possible and within 30 (thirty) days at the latest, depending on the nature of the request; if the process additionally entails a cost, the fee in the tariff set by the Board may be charged.
8. Data Security
A significant portion of the data is stored only on your device and is not sent to any server. Data written to the cloud is protected by Google's security infrastructure and by Firestore security rules (only the owner can write, only signed-in users can read). Special-category/health data, on the other hand, is never transferred to the cloud.
9. Note on the Charge Nurse Uploading Team Data
When a schedule is published, the names and positions of the team members included in the schedule are usually entered by the charge nurse who manages the schedule. In this case:
- With respect to that team data, the charge nurse who enters this data by their own determined purposes and means may, under KVKK, be in the position of a data controller or data processor.
- It is recommended that this person assess their own KVKK obligations, including informing the team members and, where necessary, providing a legal ground (for example, explicit consent).
- With respect to entering this team data into the system, the developer (Yakup Habanoğlu) merely provides the technical infrastructure that hosts the data; responsibility for the content of the data and the purpose of its entry may also rest with the user who enters it.
This point is brought to the attention of charge nurses who use the publishing feature.
Recommendation — entering real names is not mandatory: The app allows you to add team members using initials, nicknames or labels such as "Nurse 1". Where your institution's rules permit, we recommend this approach; in that case no identifiable personal data is transferred to the cloud and the obligations above are significantly reduced.
*This notice took effect on July 26, 2026. Updates may be announced through the App and/or via the contact channel above.*