Skip to content

Legal

Privacy Policy

This policy explains how personal data is handled both when you visit the website at www.mooncrm.com.tr and when you use the MoonCRM platform. It sets out what we collect, why we collect it, who we share it with, how we protect it and what rights you have, in plain language.

Updated:

1. Scope and who we are

MoonCRM is medical tourism CRM software built by Moon Workshop. For the purposes of this policy the data controller is [Full registered company name], the company operating the MoonCRM brand, referred to below as “Moon Workshop”.

The policy covers both visitors to the website and the customers and users of the MoonCRM platform. The difference between those two scopes is explained in the next section.

You can reach us at the details below.

  • Registered office: Güzeloba Mah. Çağlayangil Cad. Hatice Güleser İş Merkezi No:39 İç Kapı No:104 Muratpaşa/Antalya, Türkiye
  • Other offices: Göztepe Mah. İnönü Cad. No:496 Kat:8 Daire:22 Konak/İzmir — AOSB 3. Kısım 40. Cad. No:4 İç Kapı No:214 Döşemealtı/Antalya
  • Email: [email protected]
  • Phone: +90 535 455 32 10
  • Website: https://www.mooncrm.com.tr
  • Trade registry number: [Trade registry number]
  • MERSIS number: [MERSIS number]
  • Tax office and number: [Tax office and number]
  • VERBIS registration number: [VERBIS registration number]
  • Registered electronic mail (KEP) address: [KEP address]

2. The three scopes of this policy

Our processing falls into three distinct groups. Use the distinction below to find the part that applies to you.

A — Website visitors
Contact form submissions, demo requests and the technical logs generated automatically on the server. Moon Workshop is the controller for this data.
B — MoonCRM platform users
Account details created under a subscription, platform usage data, device information and data received from third-party integrations you have explicitly authorised. Moon Workshop is the controller for this data as well.
C — Patient and lead data entered into the platform
The lead and patient records a clinic, hospital or agency enters into the system. The customer business is the controller for that data; Moon Workshop acts solely as a processor.

3. What we collect from website visitors

We collect data in three categories. The first two exist only when you choose to fill in a form.

Contact form data
Your name, the company you work for, your email address, your phone number and the content of your message.
Demo request data
In addition to the above, details you send so we can assess the request: team size, the modules you are interested in and your preferred time for a call.
Technical log data
Records generated automatically on the server, such as IP address, browser and operating system, request time and the page requested.

4. What we collect from platform users

For users who hold a MoonCRM account we process the categories below. They are needed to open the account, deliver the service and keep it secure.

Account and identity data
Your name, email address, phone number, job title, the organisation you belong to, your role, and records relating to two-factor authentication setup.
Usage data
Screens viewed, features used, time spent in the platform and actions taken. The change log records which user changed which field and when, together with the previous and new value.
Device and connection data
Details of the device used to reach the service, including IP address, browser type and version, operating system and session information.
Third-party integration data
Messages and form submissions received from platforms such as WhatsApp, Facebook, Instagram and TikTok, strictly on the basis of your explicit authorisation.

5. Patient data our customers enter into the platform

Clinics, hospitals and agencies that use MoonCRM enter records about their own patients and leads. For that data the customer business is the controller: it decides what is collected, for what purpose and for how long it is kept.

Moon Workshop hosts and processes that data solely on the customer’s instructions. We do not use it for our own purposes, we do not sell it to third parties and we do not go beyond the instructions given.

The terms of that relationship are set out separately in the subscription agreement and its data processing terms. If you have a request about your own patient record, contact the clinic or agency treating you first; if the request reaches us directly we will refer it to that business.

  • Decides the scope, purpose and retention period of the data: the customer business
  • Hosting, technical maintenance and support: Moon Workshop, acting as processor
  • Handles access, rectification and erasure requests: the customer business
  • Support staff access: on request only, limited to what is necessary and logged
  • When a subscription ends: data is returned to the business or destroyed as agreed in the contract

6. No special-category data is collected on the website

The website has no field that asks you for health information, identity documents, test results or medical imagery, and we ask that you do not send such material through the contact form.

If your enquiry genuinely requires sharing that kind of information, we agree an appropriate and secure channel with you during the call.

Health data held inside the platform belongs to scope C above rather than to this section, and remains the responsibility of the customer business.

7. How we use the information

MoonCRM is not accounting or payment software. The platform holds no price, amount, collection or currency data, so we do not process information of that kind.

  • Providing the service: running lead management, appointment and operations planning, communication and reporting
  • Improving the experience: analysing usage trends to plan performance and feature work
  • Running third-party integrations: operating the WhatsApp, Facebook, Instagram and TikTok connections you authorise
  • Security: detecting and preventing fraud, unauthorised access and other misuse
  • Legal compliance: meeting statutory and contractual record-keeping and disclosure obligations
  • Customer support: answering questions, resolving incidents and providing technical assistance
  • Sales and marketing communication: sending product news and promotional material where you have asked for it

8. Lawful bases

Where processing rests on consent you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before it.

  • Responding to your enquiry, arranging a demo and sharing subscription terms — steps taken at your request prior to entering into a contract
  • Opening your account, delivering the service and providing support under a subscription — performance of a contract
  • Running our sales and support processes and keeping a record of our correspondence — legitimate interests
  • Keeping the site and the platform secure and detecting misuse or attack attempts — legitimate interests
  • Meeting statutory record-keeping and disclosure obligations — legal obligation
  • Connecting third-party integrations and sending marketing material — consent

9. Third-party integrations and authorisation

Integrations in the platform only run once you explicitly authorise them. You can remove an authorisation from the settings screen at any time; once removed, no further data is received through that channel.

  • WhatsApp: connecting line sessions and showing inbound and outbound messages in the platform
  • Facebook and Instagram: importing lead records from Lead Ads forms
  • TikTok: importing lead records from Lead Ads forms
  • Email and SMS providers: delivering templated notifications and bulk sends
  • AI voice assistant provider: writing the call summary, analysis and recording link back to the patient record
The platform’s own policy applies
Each platform you connect has its own privacy policy and terms. What is transferred through an integration is limited to the permissions you grant on that platform.
Notification records
The type, channel, status and any error detail of notifications sent through integrations are logged so that delivery can be audited.

10. Data sharing

We do not sell or rent your personal data, and we do not pass it to third parties for their own marketing. Sharing is limited to the parties needed to run the service, and to what those parties actually need.

  • Hosting and server infrastructure providers
  • Business email, SMS and messaging providers
  • Providers that handle subscription invoicing and payment processing
  • Vendors that assist with software maintenance and technical support
  • Professional advisers such as accountants, auditors and lawyers, where required
  • Competent public authorities where required by law, regulation or a court order
  • Third-party integrations authorised by the user during service configuration

11. International transfers

Some of the hosting, email and messaging services we rely on may be provided by companies whose servers sit outside Türkiye.

Where that happens, the transfer is made under the cross-border transfer rules of Law No. 6698 and, where the GDPR applies, under Chapter V of that regulation. Appropriate safeguards include instruments such as Standard Contractual Clauses (SCCs) and written undertakings.

If you would like details of the current hosting location and the providers involved, write to [email protected].

12. Security

We apply technical and organisational measures that complement one another.

  • Encryption technologies applied to data in transit and at rest
  • Role-based access control, with access limited to what a role requires
  • Two-factor authentication and manageable personal access tokens
  • Regular security audits and remediation of the weaknesses they surface
  • System logging and monitoring for unusual access
  • Regular automated backups kept apart from the live system
  • Incident response plans and breach notification procedures
  • Confidentiality obligations for every employee who can reach the data
No claim of absolute security
No technical measure provides absolute security. What we can commit to is reviewing our organisational and technical measures regularly to keep the risk at a reasonable level.

13. How long we keep information

We retain data only for as long as it is needed to provide the service or to meet a legal obligation.

  • Enquiries and demo requests that do not proceed: up to 24 months after the request is closed
  • Platform account details: for the term of the subscription and, afterwards, for the statutory limitation periods that apply
  • Usage and change logs: for as long as the audit trail requires, up to 2 years
  • Technical log data: a maximum of 2 years, taking applicable legislation into account
  • Records of consent to commercial electronic messages: 3 years after consent is withdrawn
  • Patient records our customers enter into the platform: for the period the customer business sets, under the subscription agreement
When the period ends
Once the relevant period ends, or upon request, data that is no longer needed is securely deleted, destroyed or irreversibly anonymised.

14. Your rights

Depending on which framework applies to you, you hold the rights set out in Article 11 of Law No. 6698 and, where relevant, Articles 15 to 22 of the GDPR.

Send a request to [email protected] or in writing to the registered office above and we will answer within thirty days at the latest; the formal requirements under Turkish law, and the route to the supervisory authority, are set out on our Data Protection Notice page.

  • Access: confirmation of whether we process your data, and a copy of it
  • Information: learning the purpose of the processing and whether it is used accordingly
  • Rectification: correction of inaccurate or incomplete data
  • Erasure: deletion of your data where the conditions for it are met
  • Restriction: limiting how we use your data while a matter is resolved
  • Portability: receiving data you provided in a structured, machine-readable format
  • Objection and withdrawal: objecting to processing based on legitimate interests, withdrawing consent and opting out of marketing messages
  • Transfer information: learning which third parties, in Türkiye or abroad, have received your data
  • Automated decisions: not being subject to a decision based solely on automated processing that produces an adverse effect
  • Compensation: redress for damage arising from unlawful processing

15. Cookies

The site may use cookies required for it to function, along with a small amount of browser storage for interface preferences. What is stored, why, and how you can manage it is explained on our Cookie Policy page.

16. Changes and contact

We may revise this policy when legislation or our own processes change. The current version is always published on this page, and the date at the top changes accordingly.

Significant changes are also announced by email or through a prominent notice in the platform. We encourage you to review the policy from time to time.

For questions or requests, reach us through the channels below.

  • MoonCRM — Moon Workshop
  • Email: [email protected]
  • Phone: +90 535 455 32 10
  • Address: Güzeloba Mah. Çağlayangil Cad. Hatice Güleser İş Merkezi No:39 İç Kapı No:104 Muratpaşa/Antalya, Türkiye
Disclaimer
This text is provided for information only and does not constitute legal advice. For a definitive assessment of your own situation, please consult your legal adviser.