Compliance is a layer of the operation.
Vigilance, adverse-event reporting, marketing review and data protection aren't bolted on after launch. They run inside the same operation that holds the licence, imports the device and sells it. This page sets out who carries which obligation, and how each one works in practice.
Why compliance sits inside the operation
Compliance retrofitted after market entry tends to live in a binder. The obligations get listed, yet nobody in the field owns them, and the first real test is an incident. When that happens in your distribution channel, the damage attaches to the manufacturer's name; that exposure is what you are actually handing over when you appoint a distributor.
We built the layer the other way round. The licence sits in our name and the channel that sells the device is ours to run, so the distributor-level obligations attach to us directly: field vigilance, the adverse-event reporting flow, marketing review and the data-processor role move in the same rhythm as import, stock and collections. For a manufacturer, that means one counterparty in Türkiye and a compliance file that stays current because the operation depends on it.
Operating layers of compliance
Vigilance & adverse events
We carry medical-device vigilance obligations and the adverse-event reporting flow under authorised-distributor responsibility.
When a signal comes in from the field, the sequence is fixed: we log the case, assess it, file with the competent authority where a report is required, and close the loop in coordination with the manufacturer. Authorised centres know exactly who to call; the record, the follow-up and the correspondence sit with us.
Marketing compliance (Red/Amber/Green)
Every outbound piece passes a three-tier lens:
- Red
- non-compliant, not published (e.g. superlative clinical claims, patient testimonials, before/after imagery, price statements). There is no rework path at this tier; the piece is dropped.
- Amber
- needs evidence/qualifier, not released until fixed. The piece waits until the source is attached or the wording is qualified.
- Green
- sourced and compliant. Only this tier reaches publication.
Turkish advertising rules (12.11.2025), including the brand-name restriction on clinic-facing content, are coded into this lens.
Quality system and certification
Quality-management certification is a standard line in any manufacturer's assessment of a distribution partner. We know that, which is why we won't present ourselves as further along than we are.
We do not hold ISO 13485 today, and we carry no standard on this site that we cannot evidence. ISO 13485 certification is a defined work item on our quality-system roadmap. Once the certificate is issued it will be published in this section with its date and number; until then this passage stays as it is.
Regulatory status
- FDA
- PMA Class III full approval· 23.02.2026
- CE
- CE 0123 (TÜV SÜD) — Article 120 transition regime
- Türkiye
- TİTCK precautionary decisions lifted as of 19.02.2025
- Registration
- TİTCK / ÜTS registration
Regulatory status may change; consult official TİTCK and FDA records for the current position.
Data protection — role split
Data-controller responsibility splits by the data flow. The roles differ across two distinct surfaces:
For Allurion Program patient/clinical data
Data Controller = Allurion Inc. · Türkiye Representative = Kavlak · Alzey = Data Processor.
For Alzey’s own corporate forms (partnership / contact)
Data Controller = Alzey Danışmanlık ve Ticaret Ltd. Şti.
For the full notice covering corporate-form data, see our Data Protection Notice (KVKK).