Vena
Vena

Version 1.0

Privacy Policy

What personal data Vena collects, why we process it, who we share it with, and the rights you have over it.

Effective: 23 September 2026

  1. 1. Data Controller and Contact
  2. 2. Data We Collect
  3. 3. Google Sign-In and Google User Data
  4. 4. Purposes and Legal Bases
  5. 5. How We Share Data
  6. 6. Retention
  7. 7. Security
  8. 8. Cookies and Local Storage
  9. 9. Your Rights and Account Deletion
  10. 10. Children's Data
  11. 11. Changes to This Policy

1. Data Controller and Contact

Vena Sağlık Teknolojileri Ltd. Şti. ("Vena", "we") acts as the data controller under Turkish Personal Data Protection Law No. 6698 ("KVKK") and, where applicable, the GDPR. Vena is a health-technology platform that matches blood donors, hospitals and urgent blood needs.

For any request about this policy, your data or your rights: info@vena.health

2. Data We Collect

We collect only what the platform needs to work. What is collected depends on which features you use.

2.1 Account and identity data

  • Full name
  • Email address
  • Phone number
  • Profile photo (uploaded by you, or the picture from your Google account)
  • Password (stored only as a hash by our authentication provider, Supabase; Vena never sees it in plain text)
  • Early-access activation code and the community it links you to

2.2 Health and donor data (special category)

  • Blood type
  • Date of birth and weight (used to compute donation eligibility)
  • Last donation date, donation history and cooldown period
  • Donation eligibility status
  • Laboratory reports you choose to upload and the analyte values extracted from them

Health data is special-category data under KVKK art. 6 and GDPR art. 9. It is processed solely on the explicit consent you give at registration, which you may withdraw at any time.

2.3 Location data

  • City and district, as entered by you at registration
  • Device location (latitude/longitude) — only if you explicitly grant the browser location permission
  • Location permission status and the source of the location (GPS, manual entry or fallback)

Location is used to show urgent blood requests and donation points near you. You can revoke the permission in your browser at any time; distance-based matching is then disabled.

2.4 Usage and transaction data

  • In-app activity such as notifications, badges, level and contribution points
  • Protection-circle and friendship connections
  • Your responses to urgent requests and appointment records
  • Messages you send to the Vena AI assistant
  • Session and security records (sign-in time, authentication cookies)

3. Google Sign-In and Google User Data

You may choose to sign in to Vena with your Google account. When you do, we request only these scopes: openid, email, profile.

The data we receive from Google is limited to:

  • Your Google account email address — to create and identify your account
  • Your name — to display on your profile and in in-app greetings
  • The link to your profile photo — to display as your profile picture

We start the Google flow with access_type=online, so Google issues no refresh token and no Google access token is ever stored on our servers. We have no access to Gmail, Drive, Calendar, Contacts or any other Google service, and we read no data from them.

Vena's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we never sell or market it to third parties.

You can revoke Vena's access at any time at myaccount.google.com/permissions (Google Account → Security → Third-party apps). Revoking access does not delete your Vena account — see section 9 for account deletion.

4. Purposes and Legal Bases

  • Creating your account and authenticating you — performance of a contract
  • Matching you with urgent blood needs by blood type, eligibility and location — explicit consent (health data) and legitimate interest
  • Computing your donation eligibility and cooldown — explicit consent
  • Sending urgent-request, appointment and platform notifications — performance of a contract and legitimate interest
  • Reading laboratory reports you upload and showing you a summary — explicit consent
  • Keeping the platform secure and preventing abuse — legitimate interest
  • Meeting our legal obligations — compliance with a legal obligation

We do not subject you to automated decision-making that produces legal effects concerning you. Matching results are suggestions; the decision to donate is always yours.

5. How We Share Data

We do not sell personal data. It is shared only in the following cases, and only to the minimum extent needed:

5.1 Healthcare institutions

When you choose to respond to an urgent request, your blood type, name, contact details and general location are shared with that hospital. Hospitals cannot see your identity unless you respond to a request.

5.2 Service providers (processors)

  • Supabase — database, authentication and file storage
  • Vercel — application hosting and delivery
  • Google LLC — authentication, only when you use Google Sign-In
  • Anthropic — only to answer the messages you send to the Vena AI assistant; those messages are not used to train models
  • Mapbox — serving map tiles

These providers process data only on our instructions and for contractually defined purposes. Some of them host data outside Türkiye, so your data may be transferred abroad under KVKK art. 9 on the basis of the explicit consent given at registration and the data-processing agreements we hold with them.

5.3 Legal authorities

We may share data with competent public authorities where a court order or a statutory obligation requires it.

6. Retention

  • Account and profile data: while your account is open
  • Donation and eligibility records: while your account is open and for any period required by law
  • Laboratory reports and extracted values: until you delete them or close your account
  • Vena AI chat history: while your account is open
  • Session and security records: up to 12 months

When you delete your account, your data is permanently deleted or irreversibly anonymised within 30 days. Records we are legally required to keep are retained only for the length of that obligation.

7. Security

  • All traffic is encrypted with HTTPS/TLS
  • Row-level security is enforced in the database: a user can reach only their own records
  • Passwords are stored hashed, never in plain text
  • Admin access is separately authorised and audit-logged

No system is completely secure. In the event of a breach we will notify you and the Turkish Data Protection Authority within the period the law prescribes.

8. Cookies and Local Storage

  • Session cookies — strictly necessary to keep you signed in (set by our authentication provider)
  • Local storage (localStorage/sessionStorage) — for your language and theme preference and for notices shown once per session

We use no advertising or third-party tracking cookies, and we do not profile you.

9. Your Rights and Account Deletion

You have the right to learn whether your personal data is processed, to request information about it, to learn the purpose of processing and whether it is used accordingly, to know the third parties to whom it is transferred at home or abroad, to request correction, erasure or destruction of incomplete or inaccurate data, to request that such action be notified to the third parties concerned, to object to a result derived solely from automated analysis, and to claim compensation for damage caused by unlawful processing.

You can correct most of your profile data yourself on the Profile page in the app. To delete your account and all associated data, email info@vena.health with the subject "account deletion"; the request is completed within 30 days and confirmed to you in writing.

Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out beforehand. If you withdraw consent for health data, matching features become unavailable.

If you are not satisfied with our response, you may lodge a complaint with the Turkish Data Protection Authority (www.kvkk.gov.tr) or your local supervisory authority.

10. Children's Data

Vena is not directed at anyone under 18, and the platform enforces an 18-year minimum for donor registration. If we learn that we hold data belonging to someone under 18, we delete the account and the data without delay.

11. Changes to This Policy

We may update this policy. When a material change is made we update the effective date and show a notice in the app. Continuing to use the platform after a change means you accept the updated policy.

Terms of ServiceBack to the app