Security & data protection
Patient data is sensitive data, and the system is built accordingly
Medical tourism businesses handle special-category personal data: identity documents, diagnoses, lab results and before-and-after imagery. This page sets out the technical measures MoonCRM provides to support that responsibility.
Five pillars
Security is not one feature but a set of decisions that reinforce each other. In MoonCRM those decisions fall under five headings.
Access control
Permissions attach to roles, not to individuals. Consultants see their own portfolio and the operations team sees travel and accommodation. Which patient statuses a role can see is defined separately, the multi-organisation structure keeps branch and brand data apart, and user accounts are protected with two-factor authentication.
Auditability
Every change is stored with the user, the field, the old value, the new value and a timestamp. Each automated notification is logged too, with its channel, status and the request and response behind it. Audit entries cannot be edited from within the application. When a concern about an employee arises, or a data subject request lands, this trail is what you read.
Data integrity and backups
Data is backed up automatically at regular intervals, with backups kept separately from the live system. Deletions are recorded, so a patient record removed by mistake never disappears anonymously. The silent data loss a spreadsheet allows is structurally impossible here.
Transmission and storage
Access runs over encrypted connections, so traffic between browser and server is not carried in the clear. Uploaded lab results, X-rays and images are held behind permission checks rather than as openly reachable links.
People and process
Most technical measures fail without process behind them. New joiners are given a role, leavers have access revoked and their portfolio handed over, and conversation history and files stay with the company. Strong passwords and no shared accounts remain a discipline the business itself has to hold.
Where the responsibility sits
Stating the split clearly is the best way to avoid arguments later. These five points separate your obligations from MoonCRM’s role.
- Controller and processor
- For your patients’ data you are the data controller: you decide what is collected, why it is processed and how long it is kept. MoonCRM hosts and processes that data on your instructions as a processor and does not use it for its own purposes.
- Privacy notice and consent
- Writing the notice that tells patients what you collect and why — and running a consent process where one is required — is yours to design. On the MoonCRM side, consent fields can be added to forms, and communication permission and preferences are stored on the record and applied when campaigns are sent.
- Retention and deletion
- Personal data must not be kept longer than the purpose requires, and setting those retention periods is the business’s responsibility. MoonCRM makes it possible to delete records and files, log those deletions, and list and manage the affected records in bulk.
- Cross-border transfers
- For businesses taking patients from Europe, GDPR also comes into play and where data is hosted starts to matter. Hosting location, backup arrangement and which sub-processors are involved are all set out in writing at contract stage.
- Data subject requests
- A patient may ask to access, correct or delete their data, and answering that request falls to you as controller. Because MoonCRM keeps every record, file and message for a person on one card, assembling a complete response is straightforward.
What this looks like in practice
The day-to-day equivalents of the principles above.
- Role-based permissions with per-user access restrictions
- Status visibility by role: which patient statuses each role can see
- Two-factor authentication with QR setup, verification and recovery codes
- Field-level change log capturing old value, new value, user and time
- Automated notifications logged with channel, status, request and response
- Personal access token management, issued and revoked per user
- Encrypted connections and managed session handling
- Regular automated backups and access revocation when staff leave
This page is provided for information only and does not constitute legal advice. The scope of your obligations under KVKK and GDPR depends on your own processes, and we recommend working with your legal adviser on any final assessment.
Frequently asked questions
Our team knows medical tourism operations inside out. Let’s review your process together in a 15-minute call.
All questions Where is our data stored?
Hosting location and backup arrangements are confirmed in writing during onboarding. For businesses accepting patients from Europe and assessing GDPR scope, this is discussed specifically at contract stage.
Can my consultants see every patient?
Entirely up to the permission rules you set. You can restrict consultants to their own portfolio, define which statuses each role sees, and manage module access permission by permission.
What happens to patient data when an employee leaves?
The account is deactivated, access is cut immediately and the portfolio is transferred to another consultant. WhatsApp threads, files and change history stay with the company — which is the fundamental difference from data living on a personal phone.
Can a record deleted by mistake be recovered?
Deletions are logged, so who removed what and when is visible. Recovery from backups is assessed on request; scope and time window depend on the backup plan agreed during setup.
Does MoonCRM make us compliant?
No software makes an organisation compliant on its own. MoonCRM provides a large share of the technical measures compliance requires; privacy notices, retention periods, data inventories and process decisions remain the controller’s responsibility.
Let’s design your permission structure together
We define who should see which data during onboarding, with you. Write to the team directly with any questions.