Processing and Protection of Personal Data Policy

I. INTRODUCTION

A. Purpose and Scope

This policy defines the principles for the protection and processing of personal data by gastricsleeveturkey.net. The aim is to ensure transparency regarding personal data processing and to guarantee compliance with data protection laws.

This Policy aims to explain the personal data processing practices of gastricsleeveturkey.net and the systems in place to protect such data. It ensures the proper handling of personal data by informing relevant individuals, such as patients, employees, prospective clients, partners, and visitors.

The goals of this policy are to:

  • Establish standards for managing personal data in alignment with legal obligations and organizational objectives.
  • Implement control mechanisms that manage the risk of data processing.
  • Ensure compliance with international standards and legal frameworks like the General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law (KVKK).
  • Protect the fundamental rights and freedoms of individuals.

This policy applies to both physical and electronic data processing systems utilized for personal and sensitive data, as long as the data is part of a structured data recording system.

B. DEFINITIONS

TermDefinition
Explicit ConsentConsent given for a specific purpose, based on adequate information and expressed freely.
Personal DataAny information related to an identified or identifiable individual.
Sensitive Personal DataSpecial categories of data such as health, sexual orientation, political opinions, religion, race, etc.
Data ControllerA natural or legal person who determines the purposes and means of processing personal data.
Data ProcessorA person or entity processing personal data on behalf of the data controller.
Data SubjectThe individual whose personal data is being processed.
GDPRGeneral Data Protection Regulation of the European Union.
KVKKLaw No. 6698 on the Protection of Personal Data (Turkey).
ProcessingAny operation performed on personal data, such as collection, storage, modification, and deletion.
Personal Data Protection BoardA regulatory body responsible for ensuring the compliance with personal data protection regulations.

II. GENERAL PRINCIPLES AND CONDITIONS REGARDING THE PROCESSING OF PERSONAL DATA

gastricsleeveturkey.net processes personal data in accordance with the principles outlined in Article 20 of the Constitution of the Republic of Turkey, Articles 4 and 5 of the KVKK, and Article 5 of the GDPR. The processing will be:

  1. Lawful and Fair: Data will be processed according to the law, ensuring the rights and freedoms of individuals are respected.
  2. Purpose Limitation: Personal data will only be collected for clear, legitimate, and defined purposes.
  3. Data Minimization: Data collected will be limited to what is necessary for the intended purpose.
  4. Accuracy: Reasonable steps will be taken to ensure that personal data is accurate and up-to-date.
  5. Storage Limitation: Data will not be kept longer than necessary.
  6. Security: Data will be protected against unauthorized access, disclosure, or destruction.

III. CATEGORIES OF PERSONAL DATA PROCESSED BY GASTRICSLEEVETURKEY.NET

Personal data processed by gastricsleeveturkey.net may include:

  1. Identification Information
    • National ID, passport, driver’s license, residence permit, etc.
  2. Contact Information
    • Email, phone number, and physical address.
  3. Medical Information
    • Health conditions, medical history, medical treatments, etc.
  4. Financial Information
    • Payment information, transaction records, invoices.
  5. Legal Transaction Information
    • Data related to compliance with laws and regulations.
  6. Security Information
    • Video surveillance, access logs, and other security-related data.
  7. Marketing and Communication Information
    • Preferences, interests, and behavioral data related to marketing campaigns.

IV. TRANSFER OF PERSONAL DATA

gastricsleeveturkey.net may transfer personal data to third parties when necessary, for the delivery of services, legal obligations, or other purposes consistent with the legal framework. Data may be shared with:

  • Business partners, contractors, and suppliers.
  • Public authorities for compliance with regulations.
  • Healthcare professionals and medical institutions when necessary for treatment purposes.

Personal data will only be transferred with the explicit consent of the data subject or as required by applicable law.

A. Legal Basis for Data Transfer

Personal data may be transferred without explicit consent in the following situations:

  1. Legal Obligation
    • When required by law or regulation.
  2. Vital Interests
    • To protect the life or physical integrity of the individual or others.
  3. Contractual Necessity
    • For fulfilling contracts with the data subject.
  4. Legitimate Interests
    • To serve legitimate interests that do not override the data subject’s rights.
  5. Public Disclosure by the Data Subject
    • If the data subject has made the data public.

B. Transfer of Sensitive Data

Sensitive personal data, including health data, is processed with additional protection. Such data may be transferred to third parties only under the following conditions:

  1. Explicit Consent
    • The data subject’s explicit consent is required, especially for health data.
  2. Legal Obligations
    • Sensitive data may be processed and transferred to authorized entities as required by law for public health, medical treatment, or health services.

In cases of international transfers, appropriate safeguards must be in place to ensure the protection of sensitive data, as defined by the relevant regulations (KVKK, GDPR). Data may only be transferred to countries with adequate data protection laws or with proper legal safeguards in place.

V. RIGHTS OF THE DATA SUBJECT

Data subjects have the following rights:

  • Access
    • Request access to their personal data.
  • Rectification
    • Request correction or completion of inaccurate data.
  • Erasure
    • Request deletion of personal data under certain conditions.
  • Restriction of Processing
    • Request the restriction of data processing in certain situations.
  • Data Portability
    • Request the transfer of data to another data controller.
  • Object
    • Object to the processing of personal data based on legitimate interests.

To exercise these rights, data subjects can contact gastricsleeveturkey.net via the provided communication channels.

VI. UPDATES

This policy may be updated from time to time. Any updates will be communicated through the website, and the latest version of the policy will always be available on gastricsleeveturkey.net.

Get 30% Discount Today! ⏰🎉