Privacy Policy
This policy explains the processing of personal data through the public website, registration, subscription and PanaShift service.
Last updated: 2026-08-06Data categories
We may process identity and contact data, institution and billing data, account and authorization data, service usage and audit records, device/log data, support correspondence and transaction references.
PanaShift is not intended for patient medical records. Customers must not enter patient health data unless a separately agreed and legally compliant feature expressly requires it.
Purposes and legal grounds
Data is processed to create and secure accounts, provide subscriptions, perform contracts, issue invoices, provide support, prevent abuse, keep legally required records, improve service reliability and comply with legal obligations. Processing relies on the legal grounds applicable to each activity, including contract performance, legal obligation, establishment or protection of rights and legitimate interests; consent is requested where legally required.
Recipients
Data may be shared only as necessary with hosting/infrastructure vendors, support and security providers, accountants or e-invoice providers, competent authorities and the payment provider iyzico. Vendors receive only the data necessary for their role and are subject to appropriate safeguards.
Card data
Card number, expiry date and CVV are not requested by PanaShift pages and are not stored in the PanaShift database. When payment is enabled, these details are entered in the secure iyzico-hosted checkout form. PanaShift retains only necessary transaction references and payment status.
Customer staff data
For staff-scheduling data uploaded by an institutional customer, the institution generally determines the purposes and means of processing and PanaShift acts according to the service agreement and documented instructions. The customer is responsible for providing required notices and establishing a legal basis for its staff data.
Retention and security
Data is retained only for the period required by the service relationship, legal obligations, limitation periods and legitimate security needs, then deleted, anonymized or securely archived. Access controls, logging, encryption in transit, backups and least-privilege practices are used in proportion to risk.
Your rights
You may contact the data controller to ask whether your data is processed, request information, correction or deletion where applicable, learn the purpose and recipients, object to certain results and seek compensation where the law provides. Requests may be sent through the contact channels below after identity verification.
International transfers and updates
If a service provider outside Türkiye is used, transfers will be performed only under a lawful transfer mechanism and appropriate safeguards. Material policy changes will be published on this page with an updated date.