Contact live support now for all your inquiries0541 356 67 39

Policy on the Processing and Protection of Personal Data

  • Home
  • /Policy on the Processing and Protection of Personal Data
  1. Introduction

As EKONSEY ÖZEL SAĞLIK HİZMETLERİ SAĞLIK YATIRIM VE DANIŞMANLIK LİMİTED ŞİRKETİ (“Company”), we adopt the principles regarding the protection and processing of Personal Data within the scope of the legislation to ensure compliance with the Personal Data Protection Law No. 6698 (hereinafter referred to as the “LPPD Law”) and take all necessary administrative and technical measures. In this context, we present this Policy on the Processing and Protection of Personal Data (“Policy”) to the information of Personal Data Subjects in order to both fulfill the disclosure obligation regulated in Article 10 of the Law and to report all administrative and technical measures we have taken for the processing and protection of Personal Data. Any changes to be made within the scope of this Policy and the effective date of the changes will be shared on our website with the domain name www.ekonsey.com.

Your personal data is processed in accordance with the LPPD Law, secondary legislation deriving its legal basis from it, the decisions of the Personal Data Protection Board (hereinafter referred to as the “PDP Board”), and other relevant legislative provisions. The framework regarding the collection, storage, transfer, or any processing of your personal data by business partners who are in a contractual relationship as a data controller, have a confidentiality obligation, and process data on our behalf is explained below with this text.

  1. Purpose of the Policy

The main purpose of this Policy is to provide explanations on systems for the processing and protection of Personal Data in accordance with the relevant legislation, and in this context, to inform Personal Data Subjects whose Personal Data are processed by our Company, including but not limited to our Shareholders; Officials; Personnel; Personnel Candidates; Customers; Potential Customers; Consumers; Visitors; Real Person Business Partners; Real Person Business Partner Candidates; Shareholders, Officials, Personnel of Business Partners or Business Partner Candidates, and Third Parties. In this way, it is aimed that Personal Data Subjects protect all their rights arising from the legislation regarding Personal Data and are aware of these rights.

  1. Definitions

Concepts within the scope of this Policy are used in accordance with the following definitions:

Open data: Anonymized data made accessible to everyone over the internet for free or in a way that does not exceed the cost of preparation, on which there are no intellectual property rights, and which can be freely used for any purpose, is machine-readable, and thus can work together with other data and systems,

Open health data: Health data that has been converted into open data,

Explicit consent: Consent regarding a specific subject, based on information, and expressed with free willAnonymization: Rendering personal data impossible to associate with an identified or identifiable natural person in any way, even by matching it with other data,

Relevant person: The natural person whose personal data is processed,

Personal data: Any information relating to an identified or identifiable natural person,

Special categories of personal data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data,

Personal health data: All kinds of information regarding the physical and mental health of an identified or identifiable natural person and information regarding the health service provided to the person,

Destruction of personal data: Deletion, destruction, or anonymization of personal data,

Processing of personal data: Any operation performed on data such as obtaining, recording, storing, preserving, changing, rearranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of personal data by fully or partially automated means or by non-automated means provided that they are part of any data recording system,

Deletion of personal data: The process of making personal data inaccessible and unusable for relevant users in any way,

Destruction of personal data: The process of making personal data inaccessible, irrecoverable, and unusable by anyone in any way,

Data processor: The natural or legal person who processes personal data on behalf of the data controller, based on the authority given by them,

Data recording system: The recording system where personal data are structured and processed according to specific criteria,

Data controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system,

Law: Personal Data Protection Law No. 6698,

PDP Board: Refers to the Personal Data Protection Board.

 

  1. Processing of Personal Data

Personal data can only be processed in accordance with the procedures and principles provided for in the Personal Data Protection Law and other laws. In the processing of personal data; it is mandatory to comply with the principles of being in compliance with the law and rules of integrity, being accurate and up-to-date when necessary, being processed for specific, explicit, and legitimate purposes, being relevant, limited, and proportionate to the purpose for which they are processed, and being preserved for the period provided for in the relevant legislation or required for the purpose for which they are processed.

4.1. Conditions for Processing Personal Data

Personal data cannot be processed without the explicit consent of the relevant person. In the presence of one of the following conditions, it is possible to process personal data without seeking the explicit consent of the relevant person:

  • Being explicitly provided for in the laws: The obligation to include the name of the relevant natural person on the invoice in accordance with the Tax Procedure Law, etc.
  • Being mandatory for the protection of the life or physical integrity of the person or someone else when the person is unable to express their consent due to actual impossibility or whose consent is not legally valid: The necessity of urgent medical intervention for the Data Subject, etc.
  • Being necessary to process the personal data of the parties to a contract, provided that it is directly related to the establishment or performance of a contract: Obtaining address information for product shipment in accordance with a concluded contract, etc.
  • Being mandatory for the data controller to fulfill its legal obligation: Carrying out activities and audits in information systems to prevent unauthorized access to Personal Data, etc.
  • Being made public by the relevant person themselves: The personal data subject sharing their Personal Data from a social media account open to access, etc.
  • Being mandatory for the establishment, exercise, or protection of a right: Reporting the personnel file information of the Company Personnel to the Social Security Institution, etc.
  • Being mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the relevant person: Processing the Personal Data of the Personnel during the arrangement of the organizational structure of the Company, etc.

 

4.2. Conditions for Processing Special Categories of Personal Data

Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data are special categories of personal data. Processing of special categories of personal data without the explicit consent of the relevant person is prohibited. Personal data other than health and sexual life may be processed without the explicit consent of the relevant person in cases provided for in the laws. Personal health data may be processed without the explicit consent of the relevant person by persons under a duty of confidentiality or authorized institutions and organizations for the purpose of protecting public health, execution of preventive medicine, medical diagnosis, treatment and care services, and planning and management of health services and financing.

4.3. Conditions for Transferring Personal Data and Special Categories of Personal Data

By ensuring that all necessary technical and administrative measures are taken to ensure the appropriate level of security in accordance with the LPPD Law and relevant health legislation, we may transfer your personal data in line with the purposes stated and contained in legal regulations to: institutions or organizations permitted by the Basic Law on Health Services No. 3359, the Decree-Law on the Organization and Duties of the Ministry of Health and its Affiliated Institutions No. 663, the Regulation on the Processing and Ensuring the Privacy of Personal Health Data, and other relevant legislative provisions; private insurance companies; our direct/indirect domestic/foreign shareholders, subsidiaries, and/or affiliates; our group companies; auditors; consultants; business partners; domestic/foreign organizations and other third parties from whom we receive services contractually to carry out our activities, with whom we cooperate.

  1. Conditions and Purposes for Processing Personal Data

Personal data we collect within the scope of the services you receive are processed by our Company for the following purposes:

  • Fulfillment of legal and contractual obligations to be performed by our Company,
  • Fulfilling our legal obligations in the Basic Law on Health Services No. 3359, Decree-Law No. 663, Regulation on the Processing and Ensuring the Privacy of Personal Health Data, and other relevant regulations,
  • Protection of public health, execution of preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and financing,
  • Identification and verification of your identity for your security,
  • Questioning your entitlement with contracted institutions, ensuring financial reconciliation regarding health services, sharing information requested by institutions,
  • Execution of the billing process,
  • Sharing acquired information with the Ministry of Health and other public institutions and organizations and responding to their requests in accordance with the legislation,
  • Contacting Personal Data Subjects who convey their requests and complaints to our Company and ensuring the follow-up and management of requests and complaints,
  • Analyzing your use of health services to improve our services,
  • Ensuring compliance with internal policy and principles,
  • Preserving information regarding your health data that must be stored pursuant to the relevant legislation,
  • Carrying out necessary IT activities to ensure the security of data held by our Company, and in this context, receiving technical support services from outside,
  • Creating personnel file information of the Personnel in line with the employment contract concluded between the Personnel and our Company, keeping this information up to date, preserving it, and storing it for the duration of the statute of limitations provided for by the legal legislation,
  • Paying the salary earned by the Personnel for their duty and documenting and controlling the payment, tracking advance payments and expenses incurred,
  • Setup and backup of e-mail accounts allocated to the Personnel by our Company for use within the scope of our Company's activities, creation of necessary user accounts and passwords for the Personnel's access to digital environments and software, making authorization limitations, and providing technical support for these within or outside the Company;
  • Carrying out promotion and information activities, contacting you for informational purposes regarding our services,
  • Without being limited to these, for the purposes of carrying out and developing medical diagnosis, treatment and care services, planning and management of health services and financing, increasing and researching patient satisfaction, and related reasons. However, your personal data will not be used for any commercial purpose in any way other than the activities listed above and cases required by the relevant legislation.

Your Personal Data obtained and processed pursuant to the relevant legislation may be stored both in the digital environment and in the physical environment by being transferred to physical archives and/or IT systems.

  1. Method and Legal Basis of Collecting Personal Data, Deletion, Destruction, and Anonymization, and Preservation Period

6.1. Deletion, Destruction, or Anonymization of Personal Data

Although it has been processed in accordance with the Personal Data Protection Law and other relevant law provisions, personal data are deleted, destroyed, or anonymized re’sen or upon the request of the relevant person by the data controller in the event that the reasons requiring their processing disappear.

Deletion of personal data is the process of making personal data inaccessible and unusable in any way for the relevant users (everyone except those responsible for technically storing, protecting, and backing up data at the data controller or data processor).

Destruction of personal data is the process of making personal data inaccessible, irrecoverable, and unusable by anyone in any way.

Anonymization of personal data means that even if these data are matched with other data, they cannot be associated with an identifiable natural person in any way.

Everyone has the right to apply to the data controller and request the deletion or destruction of personal data related to themselves within the framework of the conditions provided for in the seventh article of the LPPD Law.

6.2. Preservation Period of Personal Data

In the event that the reasons requiring the processing of personal health data uploaded to the portal and/or the system disappear, personal health data are anonymized or deleted by the data controller upon the request of the relevant person. All operations performed regarding the deletion, destruction, and anonymization of personal data are recorded, and the said records are stored for at least 3 (three) years, excluding other legal obligations. Data requested for deletion are archived without disrupting data integrity in order to make it possible to establish, use, or protect a right or to provide the data to judicial authorities in case of need. Access to archived data is prevented for purposes other than these. Data transferred to the data system can be deleted from the database of our website with the domain name www.ekonsey.com 10 (ten) years after the date of transfer. Provisions in other laws regarding the deletion, destruction, or anonymization of personal data are reserved.

In the destruction of personal data, the provisions of Article 7 of the Law and the Regulation on the Deletion, Destruction, or Anonymization of Personal Data prepared by the Authority and published in the Official Gazette dated 28/10/2017 and numbered 30224 are complied with.

  1. Protection of Personal Data and Special Categories of Personal Data

Our Company, in accordance with Article 12 of the Law, takes the necessary technical and administrative measures provided for in the relevant legislation and to be notified by the Personal Data Protection Board to prevent unlawful processing of Personal Data, to prevent unlawful access to Personal Data, and to ensure the preservation of Personal Data, and in this context, performs or has the necessary audits performed. In this direction, our Company takes reasonable technical and administrative measures, considering technological possibilities and application costs, to ensure that Personal Data are processed lawfully, stored in secure environments, prevent unauthorized access risks and all other types of unlawful access, prevent accidental data loss, prevent intentional damage to Personal Data, and prevent their deletion.

However, a part of Personal Data listed limitedly in the Law is attributed a separate importance due to the risk of causing victimization and/or discrimination of persons when processed unlawfully. These Personal Data are listed one by one both in Article 6 of the Law and in Article 3 of this Policy. Maximum sensitivity is shown by our Company for the protection of Special Categories of Personal Data. In this context, the technical and administrative measures taken by our Company for the protection of Personal Data are also applied with maximum care for Special Categories of Personal Data, and the necessary audits are provided within the Company.

The measures and audits applied by our Company in this context are listed below:

  • Preparation of corporate policies on Personal Data security, Personal Data Processing, storage, and destruction;
  • Auditing the Personal Data processing activities of our Company with technical systems established, and eliminating confidentiality and security deficiencies and errors resulting from the audits;
  • Taking security measures within the scope of established systems, providing necessary internal controls; making periodic reporting regarding technical measures taken;
  • Informing and training the Personnel processing Personal Data within our Company about the relevant legislation and the lawful processing of Personal Data;
  • Determining application rules by creating awareness specifically for the relevant business units to ensure the legal compliance requirements determined on a business unit basis, and organizing internal policies and trainings to ensure the audit and sustainability of these matters;
  • Making access and authorizations in accordance with legal compliance requirements determined on a business unit basis and limiting access authorizations accordingly;
  • Creating records and awareness of the Personnel regarding the obligation not to process, disclose, or use Personal Data, except for the exceptions brought by our Company's instructions and legislation, with contracts and documents governing the legal relationship between our Company and the Personnel;
  • Ensuring access to Personal Data held in the digital environment in our Company only by predetermined persons due to their duties, providing digital access with person-specific accounts and keeping it limited to the user person with the encryption method, providing its audit, creating an authorization matrix for Personnel, and removing the authorizations of Personnel who have a change of duty or leave the job;
  • Storing Personal Data held physically in our Company in locked and closed cabinets, in closed files, and giving access authorization only to authorized, specific persons;
  • Storing personal data with network security and application security, and using a closed system network and key method in personal data transfers via network;
  • Taking security measures within the scope of IT system procurement, development, and maintenance;
  • Ensuring that the access authorizations of employees in information technology units to Personal Data are kept under control;
  • Using up-to-date anti-virus systems, firewalls, intrusion detection and prevention systems, and applying penetration tests;
  • Providing the technical infrastructure that will prevent or observe the leakage of Personal Data outside the Company and creating relevant matrices, and applying data masking measures when necessary;
  • Applying the confidential document format for physically transferred personal data;
  • Taking necessary security measures regarding entries and exits to physical environments containing personal data, ensuring security against external risks (fire, flood, etc.), and identifying existing risks and threats;
  • If special categories of personal data are to be sent via e-mail, they must be sent encrypted and by using KEP (registered electronic mail) or a corporate mail account, using secure encryption/cryptographic keys for special categories of personal data and being managed by different units; transferring special categories of personal data transferred via portable memory, CD, DVD in encrypted form;
  • Installing and operating software and hardware including IT system protection programs and firewalls;
  • Adding provisions to contracts concluded with persons to whom Personal Data are lawfully transferred, including Business Partners and third parties from whom our Company receives services from outside due to technical requirements regarding the storage of Personal Data, stating that the persons to whom Personal Data are transferred will take the necessary security measures for the protection of Personal Data and ensure compliance with these measures in their own organizations;
  • Keeping log records without user intervention;
  • Establishing technical security systems for storage areas using lawful backup programs.

Our Company, in accordance with Article 12 of the Law, will ensure that in case the processed Personal Data are obtained by others through unlawful means, this situation is reported to the relevant Personal Data Subject and the Personal Data Protection Board as soon as possible. If deemed necessary by the Personal Data Protection Board, this situation may also be announced on the website of the Personal Data Protection Board or by another method.

  1. Disclosure Obligation of the Data Controller

Our Company, in accordance with Article 10 of the Law, discloses information to Personal Data Subjects during the acquisition of Personal Data. In this context, it provides disclosure regarding the title of our Company and the identity of its representative, if any, the purpose for which Personal Data will be processed, to whom and for what purposes the processed Personal Data can be transferred, the method and legal basis of collecting Personal Data, and the rights possessed by the Personal Data Subject.

  1. Obligations Regarding Data Security

The data controller must take all necessary technical and administrative measures to provide the appropriate level of security in order to

  • prevent unlawful processing of personal data,
  • prevent unlawful access to personal data,
  • ensure the preservation of personal data.

The data controller must perform or have performed the necessary audits in its own institution or organization in order to ensure the implementation of the provisions of this Law.

Data controllers and persons who process data cannot disclose the personal data they have learned to others in violation of the provisions of this Law and cannot use them for purposes other than processing. This obligation continues after they leave office.

In the event that the processed personal data are obtained by others through unlawful means, the data controller reports this situation to the relevant person and the Board as soon as possible.

  1. Rights of the Personal Data Subject, Exercise and Evaluation of Rights

10.1. Rights of the Personal Data Subject/Relevant Person

Everyone has the right to apply to the data controller and:

  • Learn whether personal data is processed or not,
  • If personal data has been processed, request information regarding this,
  • Learn the purpose of processing personal data and whether they are used in accordance with their purpose,
  • Know the third parties to whom personal data are transferred domestically or abroad,
  • Request correction of personal data if it is processed incompletely or incorrectly,
  • Request the deletion or destruction of personal data within the framework of the conditions provided for in the Personal Data Protection Law,
  • Request notification of the operations carried out pursuant to the previous two paragraphs (correction, deletion, or destruction) to third parties to whom personal data have been transferred,
  • Object to the occurrence of a result against the person themselves by analyzing the processed data exclusively through automated systems,
  • Request compensation for the damages in case of loss due to unlawful processing of personal data.

10.2. Cases Where the Personal Data Subject Cannot Assert Their Rights

In accordance with Article 28 of the Law, since the following cases are excluded from the scope of the Law, Personal Data Subjects cannot assert their rights listed in article 10.1 of this Policy in these cases:

  • Processing of Personal Data by natural persons within the scope of activities related to themselves or their family members living in the same dwelling, provided that they are not given to third parties and obligations regarding data security are complied with,
  • Processing of Personal Data for purposes such as research, planning, and statistics by making them anonymous with official statistics,
  • Processing of Personal Data for artistic, historical, literary, or scientific purposes or within the scope of freedom of expression, provided that they do not violate national defense, national security, public security, public order, economic security, privacy of private life, or personal rights and do not constitute a crime,
  • Processing of Personal Data within the scope of preventive, protective, and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public security, public order, or economic security,
  • Processing of Personal Data by judicial authorities or execution authorities in relation to investigation, prosecution, trial, or execution proceedings.

Again, pursuant to Article 28, paragraph 2 of the Law; in the following cases, Personal Data Subjects cannot assert their rights listed in article 10.1 of this Policy, except for the right to request compensation for damages:

  • Processing of Personal Data is necessary for the prevention of a crime or for a criminal investigation;
  • Processing of Personal Data made public by the Personal Data Subject themselves;
  • Processing of Personal Data is necessary for the execution of auditing or regulatory duties and for disciplinary investigation or prosecution by authorized and empowered public institutions and organizations and professional organizations in the nature of public institutions, based on the authority given by the law;
  • Processing of Personal Data is necessary for the protection of the economic and financial interests of the State regarding budget, tax, and financial matters.

10.3. Exercise of Rights by the Personal Data Subject/Relevant Person

Information requests made by Personal Data Subjects in line with their right to have information about Personal Data concerning them and the right to "request information" among the rights mentioned above, pursuant to Article 20 of the Constitution, are met by our Company in accordance with the legislation.

Our Company carries out the necessary channels, internal functioning, administrative, and technical regulations in accordance with Article 13 of the Law in order to provide the necessary information to Personal Data Subjects. In this direction, if Personal Data Subjects convey their requests regarding their rights specified in article 10.1 of this Policy to our Company, the Company shall notify the acceptance of the request or the reasoned rejection response free of charge within 30 (thirty) days at the latest, depending on the nature of the request. However, if the transaction requires an additional cost, our Company may charge the fee in the tariff determined by the Personal Data Protection Board. Personal Data Subjects may convey their requests to our Company via the “Application Form” in the ANNEX.

In order for third parties to make an application request on behalf of Personal Data Subjects, there must be a special power of attorney issued by a notary public by the Data Subject in the name of the person who will make the application. In cases where the application is rejected, the answer given is found insufficient, or the application is not answered within 30 (thirty) days from the date of application pursuant to Article 14 of the Law; the Personal Data Subject may file a complaint with the Personal Data Protection Board within 30 (thirty) days from the date they learn our Company's response and in any case within 60 (sixty) days from the date of application.

Our Company accepts the request or rejects it by explaining the reason and notifies its response to the relevant person in writing and/or electronically. If the request in the application is accepted, it is fulfilled by our Company. If the application is due to our Company's fault, the collected fee is refunded to the relevant person, provided that it is in accordance with the articles in the Membership Agreement.

Applications to be made by Personal Data Subjects will be carried out by one of the following methods, together with documents that will identify the Personal Data Subject:

  • Submitting a copy of the filled form with a wet signature in person, via notary public, or by registered mail with return receipt to the address: Levent Mah. Hacı Adil Cad. Zerrin Sok. No:2/2 Beşiktaş İSTANBUL,
  • Sending the form via registered electronic mail to the address [info@ekonsey.com] signed with a secure electronic signature regulated under the Electronic Signature Law No. 5070,
  • Following a method prescribed/to be prescribed by the Personal Data Protection Board.

 

  1. Management Structure of Our Company Pursuant to the Policy on the Processing and Protection of Personal Data

A Personal Data Committee has been established within our Company to manage this Policy and other policies related and associated with this Policy, upon the decision of the senior management of the Company. The duties of the Personal Data Committee are:

  • To create, update, and put into effect basic policies regarding the protection and processing of Personal Data,
  • To take actions regarding the implementation and auditing of policies for the protection and processing of Personal Data, and to ensure coordination by making internal assignments related to this,
  • To follow developments regarding the protection and processing of Personal Data and ensuring compliance with relevant legislation, and to ensure that necessary actions are taken within this framework,
  • To increase awareness within our Company and before the institutions our Company cooperates with regarding the protection and processing of Personal Data,
  • To evaluate the applications of Personal Data Subjects and to resolve them in accordance with the law,
  • To identify the risks that may occur in our Company's Personal Data processing activities and to ensure that necessary measures are taken,
  • To manage relations with the Personal Data Protection Board and the Authority.

 

 

  1. Update, Compliance, and Changes

Our Company reserves the right to make changes to this Policy and other policies related and associated with this Policy in line with the changes made in the Law, pursuant to the decisions of the Personal Data Protection Board, or in line with the developments in the sector or in the field of informatics.

Changes made to this Policy are immediately reflected in the text and explanations regarding the changes are explained at the end of the Policy.