www.heradent.com.tr
LAW NO. 6698 ON THE PROTECTION OF PERSONAL DATA (KVKK)
INFORMATION AND DISCLOSURE TEXT
As https://heradent.com.tr; we pay utmost attention to the processing and protection of your personal data. In accordance with the Law on the Protection of Personal Data, Basic Law on Health Services, Regulation on Personal Health Data, Regulation on Private Health Institutions Providing Oral and Dental Health Services, Private Hospitals Regulation, Patient Rights Regulation and relevant legislation, as the data controller; all necessary technical and administrative measures are taken to prevent unlawful processing of personal data, to prevent unlawful access to personal data, and to ensure the preservation of personal data.
Pursuant to Article 10 of the Law on the Protection of Personal Data; we inform you through policies and this disclosure text created to include our patients, patient companions, patient relatives, visitors, hospital managers and our employees, employee candidates, suppliers, service providers and their managers and employees, business/solution partners, company partners, employee candidates, interns, public institutions and organizations with which we are in contact, and employees of private law legal entities and related third parties. This disclosure text has been prepared by https://heradent.com.tr as the data controller within the scope of Article 10 of the Law on the Protection of Personal Data (“Law”), Article 5/8 of the Regulation on Personal Health Data and the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform.
1-Data Controller
“https://heradent.com.tr”; processes your personal data as the “Data Controller” as defined in Article 3 of Law No. 6698 on the Protection of Personal Data.
2-For What Purpose Personal Data Will Be Processed
Your personal data collected in accordance with the Law on the Protection of Personal Data, Basic Law on Health Services, Regulation on Personal Health Data, Regulation on Private Health Institutions Providing Oral and Dental Health Services, Private Hospitals Regulation, Patient Rights Regulation and relevant legislation, is processed in accordance with the principles stipulated in the law, wholly or partially, automatically or by non-automatic means, provided that it is part of any data recording system, by obtaining, recording, storing, modifying, reorganizing.
Your personal data is processed within the scope of company activities in accordance with Articles 4, 5, 6 of the Law and relevant legislation for the following purposes:
- Protection of public health, preventive medicine, carrying out medical diagnosis, treatment and care services, ensuring the planning and management of financing of health services,
- Sharing information we obtain regarding health services with the Ministry of Health, Social Security Institution and other relevant public institutions and organizations, responding to the requests of institutions, making necessary notifications to relevant public institutions and organizations, fulfilling legal obligations, in accordance with the relevant legislation to which we are subject,
- Ensuring the preservation of data that must be stored in accordance with legislation within the scope of the health services we provide,
- Verifying your identity, verifying your legal connection with contracted institutions within the scope of health services provided, ensuring invoicing and financial reconciliation, making notifications arising from legislation to relevant institutions and organizations such as judicial cases,
- Making appointments, creating appointments, making necessary notifications, ensuring patient, patient relative, visitor satisfaction, monitoring request and complaint processes, conducting examinations and evaluations required by the health services provided within the scope of our health services,
- Developing company services, maintaining corporate development activities, maintaining advertising and marketing activities, maintaining the company’s finance and accounting, administrative, legal, technical business processes, fulfilling risk management and quality improvement processes,
- Planning and executing human resources processes, fulfilling job application processes, creating personnel files for employees, fulfilling financial obligations, determining company salary policy,
- Establishing and ensuring the performance of contracts made or to be made between our company and patients, suppliers, service providers, employees and consultants, relevant institutions and organizations, third parties with whom we have a legal relationship,
- Burden of proof as evidence in legal disputes between the company and third parties,
- Ensuring communication between our company and relevant persons and organizations, providing necessary contact through our website, online applications, live support services, social media accounts, maintaining the necessary processes for you to fill out relevant electronic and physical forms, ensuring the transaction security of relevant persons,
- Providing necessary information to regulatory and supervisory official institutions, private law legal entities,
- Ensuring the supply of medical drugs, materials or devices, invoicing related to services provided, making payment transactions;
- Monitoring the safety of our patients, visitors, employees and relevant third parties through closed circuit camera recording system, ensuring legal, technical and commercial business security, preventing behaviors of third parties that may constitute crimes, ensuring the physical security of company buildings and annexes and their surroundings,
- Performance evaluation, ensuring work attendance and control, ensuring control of entry and exit of company buildings and annexes through personnel attendance control system within the scope of the employment contract made with employees and company interest,
For the purposes written above, within the limits of company activities, your personal data written below is processed.
- Your Identity Information (T.R. identity / foreign identity number, your name and surname, place and date of birth, mother and father names, marital status, gender, passport, foreign identity document, identity information on driver’s license, identity information on your population identity document or other population identity information on the identity sharing system, patient number, patient protocol number for patients)
- Your Contact information (Your telephone numbers, contact address, email address, residence, business address)
- Personnel Information (Personal information on contracts filled out for employees, interns, education, diploma information, certificate information, social security registration number information, general health insurance, private health insurance information, SGK employment entry, exit declaration, family status declaration with written identity information, dependents, spouse, child kinship information, family members’ population registry information, bailment document obtained according to the nature of the work, work certificate, resignation, termination, severance and notice indemnity payroll, salary payroll information, disciplinary investigation information, service record, resume information, leave information, occupation information, reference information, bank account information, IBAN number information, survey information, personal information obtained within the scope of occupational health and safety, military service information, personnel attendance control system, personal information obtained through personnel cards for the purpose of ensuring entry and exit transactions to relevant units, information contained in the job application form,)
- Financial Information (Invoicing and payment information, bank account number, IBAN number, credit card information, private insurance information within the scope of financial payment, policy information, General Health Insurance information, financial information obtained within the scope of notifications to be made to SGK and Ministry of Health, salary payroll, expense advance information, tax identification number, tax office information, invoices, dispatch notes, signature circulars, personal information on delivery and receipt documents, information contained in contract annexes made with third parties)
- Legal Transaction Information (Legal contact and services provided with relevant persons, personal information in correspondences with courts, prosecutor’s offices, mediators, arbitration boards, judicial authorities, information in lawsuit and enforcement files within the scope of legal disputes, identity, contact, location information processed into the system for legal notifications that must be made to police departments for identity verification purposes for patients and companions, personal information in minutes and forms kept in cases of torts, legal disputes and other situations that occur during the visits of patients, patient relatives, visitors to our hospital, personal information in forms filled out, recorded, reported through communication, website, call center within the scope of the “White Code Application” established by the Ministry of Health for healthcare workers, information contained in correspondences, procedures performed, documents issued within the scope of deceased examination, autopsy procedures, forensic medicine)
- Professional experience information (Education status information, school, diploma information, working life, reference information, internship, seminar, hardware, software used, computer knowledge, foreign language knowledge, former workplace, institution information, courses attended, in-service training information, certificates, driver’s license information, other information in reported forms, specialization, title, duty information),
- Visual and Audio Recordings (Your photographs on health reports, documents prepared within the scope of company activities, your voice recordings in conversations with call centers during appointment creation, communication with the company and monitoring of request complaint processes, job application forms, your photograph information on electronic and physical forms, documents and official identity documents filled out and printed, your photographs, your images in videos/camera recordings shared on the company website, our social media accounts or in print and visual media, third party social media channels for the purpose of public health protection, medical diagnosis, treatment and care services, promotion, information)
- Physical Space Security Information (Your camera recording information that receives image and sound recordings, security exit book information, information in forms kept, vehicle license plate information),
- Within the scope of company activities, in accordance with the employment contract and the legitimate interests of the company, for promotional, advertising and informational purposes, on the company website, social media accounts, mobile applications, promotional brochures, professional experience, promotion, information, resume and photograph information of employees,
- For the purpose of protecting public health, preventive medicine, carrying out medical diagnosis, treatment and care services, planning and management of health services and their financing, images and personal data belonging to patients in photographs and videos shared in written and visual media, on the website, on our social media accounts by persons or authorized institutions and organizations under the obligation of confidentiality, with the explicit consent of the person concerned,
- Request and Complaint Information (Information collected from relevant persons through electronic and physical environments and records, information regarding the evaluation and management process of requests and complaints coming through the internet and social media, online channels, call center)
- Information on Criminal Convictions and Security Measures (Criminal record, conviction information, judicial status information),
- Health Information (Examination, all kinds of laboratory, imaging and test results, patient diagnosis, diagnosis, treatment, prescription, medication information, doctor analysis and comments, patient history (anamnesis) information, examination information, diagnosis and prescription information, health reports and all health information received within the scope of health services, health status information written in the job application form, health reports for employees, health tests, blood type information, personal health and physical disability status information, health board reports, your personal data regarding diagnosis and treatment procedures are processed within the scope of activities for protecting public health, preventive medicine, carrying out medical diagnosis, treatment and care services for patients)
In accordance with Law No. 6698 KVKK, your personal data shared with our clinic is processed by our clinic wholly or partially, automatically or by non-automatic means, provided that it is part of any data recording system, by obtaining, recording, storing, modifying, reorganizing, as the subject of all kinds of operations performed on your personal data. Personal data processed within the scope of company activities are processed in accordance with the relevant legislation for the purposes listed below.
With its purposes, your personal data is processed in accordance with the conditions and purposes determined in accordance with Articles 4, 5 and 6 of the Law. Your personal data will not be used for any purpose other than the activities of our clinic.
3-To Whom and For What Purpose Processed Personal Data May Be Transferred
Your personal data processed by our company is transferred to the real and legal persons written below for the purposes written below in accordance with the relevant legislation to which our company is subject and Articles 8, 9 of the Personal Data Protection Law:
- To the Ministry of Health, its affiliated sub-units, family medicine centers, Social Security Institution, General Directorate of Security and its affiliated organizations, other law enforcement agencies, General Directorate of Population and Citizenship Affairs, Turkish Pharmacists’ Association, Revenue Administration, Tax Offices and all relevant public institutions and organizations, public professional organizations for the purpose of fulfilling legal obligations stipulated in relevant legislation,
- University hospitals, public hospitals, private hospitals, medical faculties, laboratories, medical centers and third parties providing health services, other health institutions with which we cooperate for the purpose of carrying out medical diagnosis, examination, treatment and referral procedures,
- To persons and organizations providing health services, private insurance companies within the scope of occupational health and safety measures for the purpose of carrying out occupational health and safety processes of relevant persons,
- Based on your explicit consent, your photographs, your images in videos/camera recordings obtained for the purpose of protecting public health, medical diagnosis, treatment and care services, promotion, information to written and visual media organs, relevant press institutions and organizations, third party websites, social media channels,
- To banks, financial institutions, public and private law legal entities, public officials for the purpose of carrying out the financial transactions of relevant persons,
- In matters related to public safety and in legal disputes, upon request and for the purpose of the request in accordance with legislation, to prosecutor’s offices, courts, mediators, execution offices and relevant legal institutions and organizations,
- To software, hardware, information and technology companies located domestically and abroad for the purpose of installing computer operating systems and computer programs used within our company, ensuring the security of electronic data, performing maintenance and repair of programs,
- To carry out company activities, to fulfill mutual obligations; “https://heradent.com.tr”, to company partners, group companies, our business/solution partners, our service providers, our suppliers,
- Together with the groups of relevant persons listed above, to our company’s employees, legal, financial and tax advisors, regulatory and supervisory institutions, auditors and official authorities, relevant ministries, authorized public institutions and organizations, persons, institutions and organizations permitted by payment service legislation provisions,
- For special categories of personal data, when necessary in accordance with legal regulations, with explicit consent obtained when required, for the purpose of protecting public health, preventive medicine, carrying out medical diagnosis, treatment and care services, planning and management of health services and their financing, your personal data is transferred without seeking the explicit consent of the person concerned, in accordance with legislation and limited to the purpose of transfer.
4-Transfer of Data Abroad:
In accordance with the principles stipulated in Article 4/2 of the Personal Data Protection Law, regarding processed personal data belonging to relevant persons, by obtaining explicit consent texts or in cases stipulated in Articles 5/2, 6/3 of the Law, without seeking explicit consent, in accordance with the rules in Article 9 of the Law, after foreign countries with adequate protection to be determined by the Personal Data Protection Board (“Board”) are announced, only to persons and organizations residing in these countries, for countries where adequate protection is determined and announced to be absent, provided that the data controllers in Turkey and the relevant foreign country have committed in writing to adequate protection and necessary permissions are obtained from the Personal Data Protection Board for the relevant transfer, it may be transferred within the limits of company activities. Within the framework of the limits stipulated by the legislation, taking all necessary measures, within the scope of your legal relationship with our company and your activity, in accordance with legislation and for the protection of public health, preventive medicine, carrying out medical diagnosis, treatment and care services, planning and management of financing of health services, limited to the purpose of transfer, through applications used, software programs, website, mobile applications, online services, live support services, social media accounts, your personal information such as identity, contact, transaction security, customer/service transaction information, financial information, visual and audio data, health information, sexual life information, genetic data, protocol number, patient number belonging to relevant persons may be transferred abroad.
5-Method and Legal Reasons for Collecting Personal Data:
Your personal data; for the services we provide, in line with the personal data processing purposes specified above; by using software and hardware programs offered in electronic environments, by using call center, live support services, our mobile applications, our social media accounts, electronic mail channels, by filling out forms on the website, creating membership, using online services, receiving patient applications, performing registration procedures, preparing printed forms, carrying out medical diagnosis, treatment and health services within the scope of health services, creating personnel files, preparing contracts, performance, accounting, finance, financial, legal transaction information processing, your personal data is processed and collected wholly or partially automatically or by non-automatic means provided that it is part of any data recording system. Your personal data and special categories of personal data; are processed based on the explicit consent of the relevant person in accordance with the legal regulations to which our company is subject. In addition, your personal data is processed based on the legal reasons written below without seeking explicit consent. Accordingly; your personal data,
- Due to being expressly stipulated in laws,
- When it is necessary to protect the life or physical integrity of the person who is unable to express his/her consent due to actual impossibility or whose consent is not legally valid, or of another person.
- Provided that it is directly related to the establishment or performance of contracts between our company and real and legal persons, it is necessary to process personal data belonging to the parties to the contract,
- The personal data has been made public by the relevant person himself/herself,
- Data processing is mandatory for the establishment, exercise or protection of a right,
- For the reasons that data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the relevant person,
In accordance with Articles 5 and 6 of the Personal Data Protection Law, Article 5/1-h of the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform, it is processed, collected and transferred limited to the specified purposes. Your personal data is preserved and stored for the period written in the relevant legislation within the scope of company activities.
6-Rights of Personal Data Owner Pursuant to KVKK No. 6698 (Right to Apply)
You can submit your requests within the scope of Article 11 of Law No. 6698 on the Protection of Personal Data, which “regulates the rights of the relevant person”, according to the Communiqué on the Procedures and Principles of Application to the Data Controller(3), as the data controller to “https://heradent.com.tr” “Headquarters, Seba Suites, Cendere Cad. No:16/1D Kâğıthane/Istanbul” address, by filling out the APPLICATION FORM included in the attachment by the relevant person who is the Personal Data Owner, you can deliver a signed copy of the form in person to the company address with documents identifying you, by sending an email to info@heradent.com.tr using Secure Electronic Signature, mobile signature or the Email address you have notified us and registered in our clinic system, with your personal application, with the application you will make through a Notary or with the methods determined by the KVKK Institution.
In accordance with Article 11 of the Law; everyone has the right to apply to the data controller regarding themselves;
- To learn whether personal data is processed,
- To request information about it if personal data has been processed,
- To learn the purpose of processing personal data and whether they are used in accordance with their purpose,
- To know the third parties to whom personal data is transferred domestically or abroad,
- To request correction if personal data is incomplete or incorrectly processed,
- To request deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the KVKK,
- In case of correction, deletion, destruction of personal data, to request that these transactions be notified to third parties to whom personal data has been transferred,
- To object to the emergence of a result against the person by analyzing the processed data exclusively through automatic systems,
- In case of damage due to unlawful processing of personal data, to request compensation for the damage.
In accordance with Article 13/1 of KVK Law No. 6698, you must submit your applications to our Company in writing or by the methods written above determined by the KVKK Institution in order to exercise your rights specified above. Our Company will finalize your requests in the application according to the nature of the request, as soon as possible and within thirty days at the latest, free of charge. However, if the transaction requires an additional cost, the fee in the tariff determined by the Board will be requested. In this context, if a written response is given to the application of the relevant person, no fee will be charged up to ten pages, and a processing fee of 1 TL will be charged for each page exceeding ten pages. If the response to the application is given on an electronic recording medium such as CD, flash drive, the fee that may be requested by our company will not exceed the cost amount required by the recording medium.