Loading

Op.Dr.Sultan Buğday
Op.Dr.Sultan Buğday
Op.Dr.Sultan Buğday
  • +90 232 343 20 94
  • info@sultanbugday.com.tr

KVKK

PROCESSING OF PERSONAL DATA LIGHTING TEXT
“Lighting Text”


In accordance with the provisions of the Personal Data Protection Law No. 6698 (“KVKK”) and the provisions of the European Union General Data Protection Regulation (GDPR), Mansuroğlu, EGE Sun Plaza, 295./2 Sk. No: 1/F, 35535 Bayraklı/İzmir, Gynecology and Obstetrics Specialist Dr. As Sultan Buğday and the Practice/Clinic it operates (will be briefly referred to as Physician/ Practice/ Clinic/ Employer below), in the capacity of Data Controller, within the framework of your personal information explained below; We inform you about our mutual rights and obligations within the scope of the aforementioned legal regulation, which can be recorded, stored, updated, disclosed to third parties, transferred, classified and processed in the ways listed in the KVKK and GDPR when permitted by the legislation.

We will save and process your personal information, which is necessary for establishing a physician-patient relationship within the scope of legal legislation, and to provide you with health services (diagnosis, treatment, care services, etc.) in line with patient benefit and public health, -Private Hospitals Law, Private Hospitals Regulation, Health To record the identity, address, telephone, medical history and all other necessary information in order to determine the patient's information so that we can provide health services to you as our Clinic within the scope of the Implementation Communiqué, the Patient Rights Regulation and other legislation; We are obliged to arrange all records and documents to be included in the medical patient file that will be the basis for the transaction in electronic or paper environment, If you use your private health insurance, it is requested by the competent authorities, especially your insurance company but not limited to these institutions, by the persons appointed by the competent authorities or within the scope of the e-pulse and similar systems established, or the notification and/or reporting uploaded to us. We declare that within the scope of our obligation, your personal data will be shared with the relevant authorities and persons.

PURPOSE OF PROCESSING PERSONAL DATA, METHODS OF COLLECTION AND LEGAL REASONS

To use your personal data in the services we can offer you, establishing and performing the physician-patient relationship and fulfilling the contractual provisions; recording the identity, address, tax number and other necessary information, including personal health data, to identify the information of the operator/operator; to organize all records and documents that will be the basis for the transaction in electronic (internet/mobile etc.) or paper media; to comply with the information retention, reporting and information obligations stipulated by the legislation, authorized institutions and other authorities; In order to increase the quality of service with service activities, to offer the requested / other products / services, and your personal data of special nature are processed due to communication, informing and similar processes within the contractual relationship.

Your blood type, laboratory and imaging results, tests, allergies, chronic diseases, venereal diseases, infectious diseases, data on previous surgeries/operations, heart rate information, medications you constantly use, information on Covid-19 disease, medical treatments, prescriptions your information, your harmful habits, your body analysis and death information, and your other health data and other personal data necessary for the treatment and applications to be applied to you; To be able to create a patient file, to carry out preventive medicine, examination, medical diagnosis, treatment and care services, to carry out your checks after medical diagnosis and treatment processes, to manage complications that may occur, to communicate with you one-on-one, to manage appointment processes, to perform patient satisfaction and demand management, To be able to fulfill contractual obligations, to keep the information about your health data, which must be kept in accordance with the relevant legislation, within the specified periods, to receive consultation services from other relevant specialist physicians when necessary in order to carry out your treatment correctly, to fulfill legal obligations in accordance with the legislation within the scope of health tourism, To be able to plan the transfer, accommodation, interpreter services of the clients, to announce the innovations regarding the medical treatment and practices, 3rd K. It is processed in order to be able to inform the business, to plan and manage health services and financing, to ensure workplace safety, to fulfill the responsibilities arising from the legal relationship established between the doctor and the patient, to fulfill financial and administrative obligations, to provide technical and commercial security and to fulfill public obligations.

Your Personal Data and Sensitive Personal Data mentioned above will be processed in line with the above-mentioned purposes and legislation in order to carry out the examination, preventive medicine, medical diagnosis, treatment and medical applications to be applied to you and to fulfill your obligations regarding your treatment. If you do not provide the relevant personal data, the legal obligations imposed on the Physician and the examination who will serve in your medical treatment will not be fulfilled properly and your treatment and/or recovery processes will not be carried out successfully.

Other scopes in which your personal data can be processed are: HR operations, In-office operations, Activities with legal, technical and administrative consequences, Strategy, planning and business partners/suppliers, customer management, customer satisfaction, Planning and execution of corporate communication activities, events, In-office training Planning and execution of programs, Examination Workplace Safety, Protection of Worker and Occupational Health and Safety, performance of services, Execution of Technical Service Services, Realization of collection transactions, Customers; Providing various advantages through product-service promotion, information, personalized advertising, campaigns and other benefits, sending all kinds of service and commercial electronic messages, survey applications, statistical analysis, Improving service quality Making studies and providing better service, Issuing invoices in return for our services, Procuring services from external sources, Providing services to customers on issues that are not in their area of ​​expertise, and providing the benefits of specialized institutions to customers in order to receive technology services, Benefiting from the requirements of practice activities. Identity confirmation, Answering questions and complaints Responding, Taking necessary technical and administrative measures within the scope of data security, Ensuring financial agreement with relevant business partners and other third parties regarding the products and services, Obtaining necessary information in line with the requests and inspections of regulatory and supervisory institutions and official authorities, Data that must be kept as per the relevant legislation. Preserving the related information, Ensuring the control of the consistency of the information, Measuring the customer satisfaction, In terms of employees; Creation of personal file, determination of whether it is capable of fulfilling the requirements of the job continuously, making private health insurance, creating a health file, taking occupational safety precautions, making travel plans. For employee candidates: Managing and planning the process of evaluating suitability for vacant positions. Publishing the visual and audio data of the Practice and Employees and their stands obtained in competitions, organizations, fairs, studies and other events for the purpose of developing and sharing the business, Fulfilling legal obligations, Execution/follow-up of the practice financial reporting and risk management transactions, Law Execution/follow-up of works, Creation and follow-up of patient records. Planning and execution of machinery and equipment use of employees. Planning and execution of the use of medical services in accordance with the law, Planning and execution of the practice, fair, activity, social projects, product and corporate promotion,

The aforementioned purposes are for informational purposes, and any further additions that may be added by us will be announced with updates so that the Clinic can carry out its future operational activities.

Your Personal Data, depending on the health service provided;

Through your health reports, laboratory and imaging results, analyzes, health reports and statements you have given regarding your health data, which you have submitted for medical evaluation regarding the treatment to be applied to you,

By filling in the "Patient Information and Consent Form" regarding the treatment to be administered by the physician and the practice,

Through the contact form you fill in on the corporate website of the Physician Practice,

By e-mails you will send to the institutional e-mail address of the Physician and the Practice,

By means of photo/video records recorded before, after and/or during the medical procedure applied to you in the Physician's Office,

.At your request and when necessary; In order for the physician and the practice to make your online diagnosis and controls via remote access, you can choose the remote connection application service providers (whatsapp/zoom.us/facetime/skype/messanger/google/instagram/) by accepting their Privacy Policy and International Transfer Policy. via your written/audio/visual (photo and/or video recording) messages you send to the Physician and his/her practice using facebook etc. and your online audio/video calls that you have set up through these applications,

By accepting their Privacy Policy and International Transfer Policy, sending a direct message to the profile accounts of the Physician and his practice on social media accounts (instagram, youtube, facebook, twitter, linkedin, etc.) of which you are currently a user and whose servers are located abroad, and/or by commenting on their posts,

By accepting their own Privacy Policies and International Transfer Principles, the “contact us” included in the promotions and advertisements of the Physician and the Clinic via social media accounts (instagram, youtube, facebook, twitter, linkedin, google, etc.) that you are currently a user of and whose servers are located abroad. through the information you transfer by allowing it to be processed automatically through panels such as "contact me" or "get information",

is processed.

5/2 of KVKK. Exceptions that make it possible to process personal data in accordance with the law are regulated in the article. In this respect, apart from express consent, the practice may also process personal data in the presence of one of the other conditions (exceptions) listed below. The basis of the personal data processing activity can be only one of the conditions stated below, or more than one of these conditions can be the basis of the same personal data processing activity.

These are: Explicitly Established in Laws, Obligation to process the personal data of the person who is unable to express his consent due to actual impossibility or whose consent cannot be validated, to protect the life or bodily integrity of himself or another person, Being Directly Related to the Establishment or Execution of the Contract, Fulfilling the Legal Obligation of the Clinic. These are the cases where Data Processing is Obligatory for the Establishment or Protection of a Right, Data Processing is Obligatory for the Legitimate Interest of the Practice, provided that it does not harm the fundamental rights and freedoms of the data owner.

In addition, cases where your data can be processed without seeking express consent in accordance with article 9/2/h, article 6/1/b, article 6/1/f GDPR:

In order to carry out examination, medical diagnosis, treatment and care services, your Health Data, which is considered as Special Quality Personal Data, will be processed by the Clinic, which is under the obligation to keep confidential as per the Law, without your explicit consent.

Your Personal Data will be processed by the Clinic, without your explicit consent, in order to be able to carry out your controls after the medical diagnosis and treatment processes, to communicate with you one-to-one, and to manage the appointment processes.

In order to carry out patient satisfaction and demand management, your Personal Data will be processed by the Clinic without your explicit consent.

Pursuant to legal obligations pursuant to article 6/1/c of ​​GDPR, your Personal Data will be processed without your explicit consent in the following cases;

Creating a patient file.

Preservation of information about your health data, which must be kept in accordance with the relevant legislation.

Issuing invoices by controlling your wage payments.

Execution of tax payments.

Fulfillment of obligations pursuant to Ministry of Health Legislation.

Fulfillment of obligations pursuant to Health Tourism Legislation.

Ensuring your data security.

Fulfillment of legal obligations before the Judicial Authorities.

Fulfillment of administrative obligations before Administrative Institutions and Organizations.

PERSONS/ENTERPRISES THAT PERSONAL DATA MAY BE TRANSFERRED:

Persons permitted by the provisions of the legal legislation are public institutions and organizations and private public institutions and organizations, polyclinics and medical laboratories with contracted physicians and clinics, and relevant persons, institutions and organizations in case of consultation. Special quality personal data, on the other hand, may be transferred to places in the country and abroad, where services are provided to carry out activities subject to the purposes specified in the legislation to which we are subject and which are secured by confidentiality agreements, to carry out insurance and finance activities and to fulfill insurance and financial services. Personal and special personal data; It is stored in a secure environment that is not open to public use and is never shared with third parties unless authorized or under a legal obligation.

Your Personal Data and Private Personal Data collected in accordance with the conditions and purposes within the scope of Personal Data Processing Conditions specified in Articles 5 and 6 of the KVKK numbered 6698; In accordance with Articles 8 and 9 of the KVKK, the physician and his practice carry out and develop examination, preventive medicine, medical diagnosis, treatment and care services, obtaining consultation services from other specialist physicians when necessary, fulfilling administrative obligations regarding health tourism legislation, health tourism Planning the transfer, accommodation and interpreter services of the patients coming within the framework of the project, communicating with the patients, managing the control appointment processes, planning and managing the health services and financing, fulfilling the responsibilities arising from the legal relationship established between the doctor and the patient, fulfilling the financial, legal and administrative obligations, for the purposes of ensuring technical and commercial security and fulfilling public obligations, promoting the medical services offered; To the extent that it is sufficient for the realization of the purpose, it will be able to transfer it to third persons and institutions by signing the necessary confidentiality agreements and providing all necessary administrative and technical security measures in accordance with the legislation.

In this context, your Personal Data processed by the Physician and his Practice;

To other specialist physicians for consultation,

To Insured Employees,

to its suppliers,

Financial Advisor, Tax and Financial Advisors and Auditors

Legal Advisor

Database (Server) Providers

“Clinical Management Software” Service Provider

Web Consultant

interpreters

Data Protection Officer

IT Consultant

Tourism Agencies

Union of Pharmacists, General Directorate of Population, General Directorate of Eminyet and other law enforcement agencies and institutions such as unions and institutions.

Public Institutions and Organizations authorized within the framework of laws,

It will be transferred to the Judicial Authorities.

 

STORAGE OF PERSONAL DATA

The collection method of personal data; your personal data may be collected verbally, in writing or electronically through all digital channels such as questions, messages, telephone calls sent to our website.

The personal data we obtain are securely stored in physical or electronic environment for an appropriate period of time in order for the Physician and his practice to be able to carry out their activities. Within the scope of these activities, the physician and his practice act in accordance with the obligations stipulated in all relevant legislation, especially the KVKK, regarding the protection of personal data.

In the event that the purposes for processing personal data expire, with the exception of cases where personal data is allowed or required to be stored for a longer period of time in accordance with the relevant legislation, the data will be deleted by the Physician and his/her Office ex officio or upon the request of the data owner and with different techniques that can be used and upon the request of the data owners. will be anonymized. In case of deletion of personal data by means of such methods, these data will be destroyed in a way that cannot be used again and cannot be recovered.

In cases where the data controller has a legitimate interest, personal data may be stored, provided that the law allows it, despite the expiration of the purpose of processing and the periods specified in the relevant laws, provided that it does not harm the fundamental rights and freedoms of the data subjects. After the expiry of the aforementioned statute of limitations, personal data will be deleted, destroyed or anonymized according to the above-mentioned procedure.

MEASURES TAKEN FOR DATA SECURITY

The practice takes all necessary technical and administrative measures to ensure the appropriate level of security required for the protection of personal data. 12 (1) of the KVKK. The measures envisaged in the article are as follows: To prevent the unlawful processing of personal data, To prevent unlawful access to personal data, To ensure the preservation of personal data.

PROCESSING IMAGE RECORDINGS

In order to ensure the general and service safety of the facilities and businesses by the building and practice where the practice is located, images of visitors, employees and other relevant persons are taken in accordance with the basic principles stipulated in the KVKK.

 

 

PROCESSING OF PERSONAL DATA OF BUSINESS PARTNERS

Within the scope of the activities established with business partners such as practice, medical laboratory, product purchase/sale supplier, the personal data of the employees of the business partners, if it is necessary for the performance of the work or to ensure the functioning of the service activity for the purposes specified in the law, It can work for the purpose of fulfilling the legal and commercial security of mutual work.

APPLICATION PROCEDURE AND RIGHTS

Your rights in accordance with Article 11 of KVKK; By applying to us, your personal data; a) learning whether it has been processed, b) requesting information if it has been processed, c) learning the purpose of the processing and whether it is used in accordance with its purpose, ç) knowing the third parties to whom it has been transferred, d) requesting correction if it has been processed incompletely/wrongly, e) To request deletion / destruction within the framework of the conditions stipulated in Article 7 of the KVKK, f) to request the notification of the transactions made in accordance with subparagraphs (d) and (e) above, to the third parties to which it has been transferred, g) to have a result against you due to the analysis exclusively by automated systems. We inform you that you have the right to object to the removal of the damage, ğ) in case you suffer damage due to unlawful processing, to demand the compensation of the damage from our practice.

Your requests in your application will be concluded free of charge within thirty days at the latest, depending on the nature of the request. However, if the transaction requires a separate cost for the practice, the fee determined in the Communiqué on Application Procedures and Principles to the Data Controller by the Personal Data Protection Board may be charged. The relevant request can be made with the methods and information specified in the "Communiqué on the Procedures and Principles of Application to the Data Controller" published in the Official Gazette dated March 10, 2018 and numbered 30356. Exceptions to the Right of Application Pursuant to Article 28 of the KVK Law, they will not be able to assert.

• Processing of personal data for purposes such as research, planning and statistics by anonymizing with official statistics

• Processing of personal data for art, history, literature or scientific purposes or within the scope of freedom of expression, provided that it does not violate national defense, national security, public security, public order, economic security, privacy of private life or personal rights or does not constitute a crime.

• Processing of personal data within the scope of preventive, protective and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public security, public order and economic security.

. Processing of personal data by judicial authorities or execution authorities in relation to investigation, prosecution, trial or execution proceedings

Pursuant to article 28/2 of the KVK Law; In accordance with the purpose and basic principles of the law and proportionally, Article 10, which regulates the obligation of disclosure of the data controller, Article 11, which regulates the rights of the data subject, except for the right to demand the compensation of the damage, and Article 16, which regulates the obligation to register in the Data Controllers Registry, shall not be applied in the following cases:

• The processing of personal data is necessary for the prevention of crime or for criminal investigation.

• Processing of personal data made public by the personal data owner himself

• Personal data processing is necessary for the execution of inspection or regulation duties and for disciplinary investigation and prosecution by authorized and authorized public institutions and organizations and professional organizations in the nature of public institution, based on the authority given by the law.

• The processing of personal data is necessary for the protection of the economic and financial interests of the state with regard to budget, tax and financial matters.

RIGHTS OF DATA OWNERS ACCORDING TO GDPR

As the Data Owner, your Personal Data is also protected in accordance with the GDPR. In cases where GDPR is under jurisdiction (European Union citizens or residents of European Union countries), the rights of Data Subjects are as follows;

Right of Access (GDPR Article 15): The data owner has the right to confirm whether the personal data relating to him is processed or not, by applying to the Clinic, and to learn the details in Article 15 of GDPR in case personal data is processed.

Right to Rectification (GDPR Article 16): The Data Owner has the right to have his/her personal data, which is under the responsibility of the Clinic, corrected at any time by applying.

Right to Deletion (GDPR article 17): The Data Owner has the right to request the deletion of his personal data held in the custody of the Clinic. If the issues specified in article 17 of GDPR occur, your personal data will be deleted by the Clinic without delay.

Right to Restriction of Processing (Article 18 GDPR):

If the Data Owners object to the up-to-dateness of their Personal Data, they have the right to request the restriction of the use of the data as the Data Owner, until the accuracy of the Personal Data is confirmed by the Clinic.

In cases where the Data Owner requests the deletion of his Personal Data due to the illegality of the Personal Data processing activity, he has the right to request the restriction of the use of the data until the request is fulfilled.

The Data Owner has the right to request that the use of his data be restricted in cases where his personal data is no longer needed for the purposes of the Clinic's processing.

 

 

 

 

 

In cases where the Data Subjects object to the processing in accordance with Article 21/1 of the GDPR, they have the right to request the restriction of the use of their data until it is verified whether the Clinic's legitimate reasons for data processing outweigh the Data Owner's legitimate reasons.

Right to Data Transfer (GDPR article 20): The Data Owner has the right to request the transfer of his Personal Data held in the custody of the Clinic to another controller, if technically possible. However, this right may be exercised when data processing is based on consent or when required by the contract.

Right to object (GDP ARTICLE 21)

The data owner has the right to object to the processing of Personal Data within the scope of Article 6/1 /e and (f) clauses of the GDP, based on the grounds related to special drmuy.

We would like to inform you that we continue our activities with the awareness that personal data security is at the forefront in all our products and services we offer to you.

 

CONSENT and APPROVAL

When you accept this Clarification Text by reading, you are fully and completely informed about the data processing process carried out by the Physician and Clinic, you learn about your rights under the KVKK and GDPR, and you are free to have your Personal Data and Private Personal Data PROCESSED by the Physician and their Practice within the scope of this Clarification Text. and you are deemed to accept, declare and undertake that you give your consent with your free will.