1. Data controller
This notice is issued by [Company Legal Name] as data controller under the EU General Data Protection Regulation ("GDPR") and Turkish Personal Data Protection Law No. 6698 ("KVKK").
- Legal name: [Company Legal Name]
- Address: [Full address]
- Trade / tax registration number: [Number]
- Email: [email protected]
2. Personal data we process
When you complete the contact form on our website or otherwise get in touch, we process the following:
- Identity data: first name, last name
- Contact data: phone number, email address, country
- Health data: medical history, reports, images and diagnostic information you share with us in connection with your treatment enquiry
- Technical data: IP address, browser and device information, site usage logs
- Travel data: passport details, flight and accommodation preferences (only where you ask us to arrange them)
Health data is a special category of personal data under GDPR Art. 9 and KVKK Art. 6, and is processed only with your explicit consent.
3. Purposes of processing
- Assessing your treatment enquiry and proposing suitable clinics and doctors
- Carrying out pre-assessment, pricing and quotation processes
- Arranging travel, accommodation, transfer and interpreter services
- Providing post-treatment follow-up and consultancy support
- Meeting our legal obligations and establishing or defending legal claims
4. Legal bases
We process your personal data on the basis of the performance of a contract (GDPR Art. 6(1)(b)), compliance with a legal obligation (Art. 6(1)(c)) and our legitimate interests (Art. 6(1)(f)).
Your health data is processed solely on the basis of your explicit consent (GDPR Art. 9(2)(a)). You may withdraw your consent at any time; withdrawal does not affect the lawfulness of processing carried out before it.
5. Sharing and international transfers
Given the nature of our service, your data is shared, strictly to the extent necessary, with:
- Partner hospitals, clinics and physicians
- Travel agencies, airlines, hotels and transfer providers
- Interpreting service providers
- Public authorities legally entitled to request information
- Our hosting, email and CRM infrastructure providers
Where data is transferred outside your country, we rely on your explicit consent or put appropriate safeguards in place, such as standard contractual clauses, in line with GDPR Chapter V.
6. Retention
We keep your personal data for as long as necessary for the purposes described above and until the statutory limitation periods expire. Once that period ends, the data is deleted, destroyed or anonymised.
7. Cookies
We use strictly necessary cookies to maintain your session and remember your language preference. Any analytics or marketing cookies are set only with your consent, and you can block them at any time through your browser settings.
8. Your rights
Under GDPR Art. 15-22 and KVKK Art. 11 you have the right to:
- Be informed whether your data is processed and obtain access to it
- Have inaccurate or incomplete data corrected
- Request erasure of your data
- Request restriction of processing and object to processing
- Receive your data in a portable format
- Object to decisions based solely on automated processing
- Claim compensation for damage caused by unlawful processing
9. Security
We apply administrative and technical safeguards — access control, encryption, secure transport (HTTPS) and regular audits — to protect your data against unauthorised access, loss and disclosure.
10. Contacting us
To exercise your rights, write to [email protected] or to the registered address of [Company Legal Name]. We respond within 30 days at the latest. If you are not satisfied with our response, you may lodge a complaint with your local supervisory authority or, in Türkiye, with the Personal Data Protection Authority.
11. Changes
We may update this policy. The current version is always published on this page and the date at the top is updated accordingly.