PRIVACY NOTICE
As the data controller, Dr. Birgul Tümay (the "Clinic") prioritizes the confidentiality and security of personal data in accordance with the Personal Data Protection Law No. 6698 ("Law") and relevant regulations. In alignment with the principles of transparency and accountability, we are committed to informing you about the processing of your personal data.
THE TYPES OF DATA WE COLLECT
The types of personal data generally processed by our Clinic, which may vary depending on the specific process, can be summarized as follows:
Categories of Personal Data | Examples of Personal Data |
---|---|
Client Service Data | Appointment and request details, complaint information, consent declarations, payment, and billing information, and other details obtained within the scope of healthcare service financing etc. |
Health Data | Diagnosis details, hereditary disease/medical history, medications used, smoking habits, treatment details, examination and test results, doctor's analysis and comments, x-ray results, prescription details, and any health information obtained during or as a result of medical diagnosis, treatment, and care services etc. |
Visual and Audio Records | Visual records such as photographs obtained before and during treatment |
Device Data | IP information, log records, and similar transaction security information obtained during your visit to our website. |
Physical Secuirty Data | CCTV |
Contact Data | Telephone number, address, email address. |
Identity Data | For example, your name, surname, ID Number , tax identification number, gender, and other identity-related details. |
PURPOSES AND LEGAL BASES FOR PROCESSING PERSONAL DATA
Categories of Personal Data | Processing Purposes of Personal Data | Legal Basis |
---|---|---|
Identity Data, Contact Data, Client Service Data | To receive patient requests and applications; To manage appointment processes and inform patients | Based on the legal ground that processing of personal data of the parties of a contract is necessary, provided that it is directly related to the establishment or performance of the contract |
Identity Data, Contact Data, Client Service Data, Health Data, Visual and Audio Records | To manage patient registration; To provide preventive medicine; To conduct medical diagnoses, treatments, and care services; To carry out examinations and treatments; To perform post-operative checks and follow-ups; To handle potential complication management | Based on the legal ground that processing of personal data of the parties of a contract is necessary, provided that it is directly related to the establishment or performance of the contract, Based on the legal ground that protection of public health, operation of preventive medicine, medical diagnosis, treatment and nursing services, planning and management of health-care services as well as their financing. |
Identity Data, Contact Data, Client Service Data, Health Data | To track payments and billing processes for provided health services; To provide necessary information in line with requests and inspections of regulatory and supervisory institutions and official authorities | Based on the legal ground that processing of personal data is necessary for compliance with a legal obligation to which the data controller is subject to, Based on the legal ground that the processing is expressly provided for by the laws, Based on the legal ground that protection of public health, operation of preventive medicine, medical diagnosis, treatment and nursing services, planning and management of health-care services as well as their financing. |
Identity Data, Health Data | To share requested information with the Ministry of Health and other public institutions and organizations; To maintain health data and financial records required by relevant regulations, Necessary for compliance with legal obligations | Based on the legal ground that processing of personal data is necessary for compliance with a legal obligation to which the data controller is subject to, Based on the legal ground that the processing is expressly provided for by the laws |
Device Data (IP Address, Log Records, etc.) | To ensure the security and effectiveness of systems used by the Clinic; To provide information to authorized institutions and organizations; To ensure compliance with regulations | Based on the legal ground that the processing is expressly provided for by the laws, Based on the legal ground that processing of data is necessary for the legitimate interests pursued by the data controller |
Physical Security Data | To ensure physical space security | Based on the legal ground that processing of data is necessary for the legitimate interests pursued by the data controller |
COLLECTING PERSONAL DATA
Your personal data is collected through information and documents provided by you directly or by your relatives via telephone, email, and other communication channels, as well as through information and document requests received from special and official institutions and organizations, and administrative and judicial authorities, both automatically and non-automatically.
RECIPIENT PARTIES AND PURPOSES FOR TRANSFERRING PERSONAL DATA
Your personal data may be transferred to the following third parties and for the purposes stated below within the scope of the personal data processing conditions and purposes specified in Articles 8 and 9 of the Law:
Recipient Parties | Purposes for Transferring |
---|---|
Legally authorized public institutions and organizations | To comply with information storage, reporting, informing, tax, and other obligations stipulated by legal regulations |
Regulatory and supervisory institutions, courts, prosecutors' offices | If necessary, to track and manage legal matters in case of a legal dispute, to provide information to authorized persons, institutions, and organizations, to ensure compliance with regulations |
Another hospital, community dental service or other health professional caring for you, dental labs | To share necessary information for conducting treatment and care services |
Suppliers whom we receive product and service support such as IT, finance, payment services | To obtain product and service support in areas requiring expertise |
Ministry of Health, Provincial Health Directorates, other units affiliated with the Ministry of Health, and patient information management systems | To fulfill legal obligations arising from laws and other health regulations |
YOUR RIGHTS AS A DATA SUBJECT
Data subjects are entitled to the below-listed rights under Article 11 of the Law:
-
Learn whether data relating to him/her are being processed;
-
Request further information if personal data relating to him have been processed;
-
Learn the purpose of the processing of personal data and whether data are being processed in compliance with such purpose;
-
Learn the third-party recipients to whom the data are disclosed within the country or abroad,
-
Request rectification of the processed personal data which is incomplete or inaccurate and request such process to be notified to third persons to whom personal data is transferred.
-
Request erasure or destruction of data in the event that the data is no longer necessary in relation to the purpose for which the personal data was collected, despite being processed in line with the Law no. 6698 and other applicable laws and request such process to be notified to third persons to whom personal data is transferred.
-
Object to negative consequences about him/her that are concluded as a result of analysis of the processed personal data by solely automatic means,
-
Demand compensation for the damages he/she has suffered as a result of an unlawful processing operation.
For requests and notifications related to the Law, you can submit your applications with documents identifying your identity, either in person with a wet signature at the address "Güzelbahçe Sk. 6/1 Nişantaşı, Istanbul" or through a notary, or by sending an email using the registered email address in our system to birgul@birgultumay.com.