Medonay relies on a small number of infrastructure providers to deliver the service. This page lists all of them, what they do, and where the data sits.
It is written for two audiences: the compliance and information security teams evaluating the service, and individuals who want to know where their personal data goes. For general information on how personal data is processed see the Privacy Notice; for browser-side technologies see the Cookie Policy.
Separating the roles
Medonay processes data in three distinct capacities, and the lists below should be read against that split:
- For patient data, Medonay is a processor. Policyholder data is processed on behalf of and under the instructions of the insurer, foundation, fund or hospital using the service. That organisation is the controller.
- For panel user data, Medonay is a controller. Staff account details, session records and activity logs are Medonay's own responsibility.
- For website visitor data, Medonay is a controller.
The first table below covers sub-processors with access to patient data. The second covers services that run only on the public marketing site and never touch patient data.
1. Sub-processors used to deliver the service
| Sub-processor | Service | Data processed | Data location |
|---|---|---|---|
| Google Cloud Platform | Application runtime (Cloud Run), database (Cloud SQL), build and deployment (Cloud Build, Container Registry), system logs and monitoring (Cloud Logging, Cloud Monitoring) | All data within the scope of the service: policyholder records, provisioning requests and decisions, panel user accounts, audit records | Belgium (europe-west1 region) |
| Vercel Inc. | Serving the management panel and the marketing site; the proxy layer between the browser and the API | The content of authenticated panel requests, in transit. Not stored persistently; access logs are generated at the provider | The provider's global edge network |
| Cloudflare, Inc. | DNS resolution, TLS termination, firewall and rate limiting in front of api.medonay.com | The content of API requests, in transit only. Not stored persistently; access logs are generated at the provider | The provider's global edge network |
| Resend (Resend, Inc.) | Sending transactional email: password reset, email verification, new-device verification code, hospital invitation, administrator notices | The recipient's email address and name, and the message body. No access to policyholder or patient data | United States |
Notes
Google Cloud Platform. The application server and the database run only in the europe-west1 (Belgium) region. Backups are kept in the same region and are not replicated elsewhere. The contracting Google legal entity is named in the annex to the data processing agreement.
Vercel Inc. Requests made from the management panel pass through a proxy layer between the browser and the Medonay API. That layer does not store data, but the data does traverse this provider's infrastructure in transit, which is why it is listed explicitly here.
Cloudflare, Inc. api.medonay.com is published through this provider's network; the TLS connection terminates there and the request reaches the application decrypted. The provider does not store the data, but every request to the service traverses its infrastructure in transit — the same reason as Vercel, and it is listed the same way.
Resend (Resend, Inc.). Account and security emails are sent through this provider. What is sent is the recipient's name, email address and the message itself; it contains no policy, provisioning or health data, and the provider has no access to such data.
Machine-to-machine calls made by hospital information systems to the /v1/provision/* endpoints do not pass through the Vercel layer; they go to api.medonay.com, reaching the application on Google Cloud through the Cloudflare network listed above.
2. Services used only on the marketing site
| Service | What it does | Access to patient data | Consent |
|---|---|---|---|
| TalkOmni | Chat assistant on the marketing site | None | Explicit consent only |
TalkOmni is a separate product operated by the same legal entity as Medonay (Genez LLC) and runs on the same cloud provider, in the same region (Belgium). It is not an independent third party.
The assistant runs only on public marketing pages. It is not present in the management panel, and therefore never has access to policyholder data, provisioning records or panel sessions. Its script is not loaded at all unless consent is given in the cookie banner.
3. What is not used
Stated explicitly because it is asked often. None of the following is in use:
- Advertising networks, tracking pixels, profiling or retargeting technology
- Third-party user behaviour analytics
- Error tracking or session replay services
- AI model providers. Provisioning decisions are made by a fully rule-based, deterministic engine; no language model or external service takes part in the decision
- Payment service providers. No card data is processed in the system
Email sending is active and is listed as Resend in the first table above. What is sent is limited to account and security email; it contains no policy, provisioning or health data.
4. Cross-border transfer
Because the data sits in Belgium, from a Turkish perspective this constitutes a cross-border transfer.
Work to put the required legal mechanism in place (standard contractual clauses notified to the Turkish Data Protection Authority under Article 9 of Law No. 6698) is in progress. This page will be updated, with a new version number and effective date, once that work is complete.
The data processing agreement signed with corporate customers separately sets out the legal basis for the transfer, the technical and organisational measures in place, and the path to be followed should hosting in Turkey be requested. A technical plan for migrating the data to a Turkish region is held ready.
5. Change notification
Corporate customers receive written notice at least thirty days before a new sub-processor is added or an existing one is changed. The customer may object with reasons within that period; where the objection cannot be resolved, the customer retains the right to terminate without penalty.
The version number and effective date on this page are updated with every change. Previous versions are on record and shared on request.
6. Contact
Questions about this page and requests for sub-processor change notifications: kvkk@medonay.com.tr