Clarification Text – Person Receiving Product or Service

KAŞKALOĞLU EYE HOSPITAL WITHIN THE SCOPE OF LAW NO. 6698 ON THE PROTECTION OF PERSONAL DATA PATIENT/SERVICE RECIPIENT DISCLOSURE TEXT

Purpose and Scope of the Clarification Text

As LASER MYOPIA PRIVATE TREATMENT CENTER LIMITED COMPANY (“Kaşkaloğlu Eye Hospital”), we take measures to protect your personal data within the scope of the Personal Data Protection Law No. 6698 (“KVKK” or “Law”). We process your Personal Data within the scope of KVKK and relevant legislation and in our capacity as “data controller” for the reasons and methods described below.

LASER MYOPIA SPECIAL TREATMENT CENTER LIMITED COMPANY Clarification Text on the Processing of Personal Data has been prepared in accordance with the article titled “Data Controller’s Obligation to Inform” in Article 10 of the KVKK: the identity of the data controller, the method and legal reason for collecting your personal data, the purpose for which this data will be processed, to whom and for what purpose it can be transferred, the data processing period and what your rights are listed in Article 11 of the KVKK. The explanations made for your “Personal Data” in the clarification text also cover your “Sensitive Personal Data”.

Method and Legal Reason for Collecting Your Personal Data

Your personal data may be collected verbally, in writing or electronically by automatic or non-automatic methods, through the company’s affiliated units, website, social media channels, call center, mobile applications, software used to carry out activities within the company, camera shooting and verbally, in writing or electronically. Your personal data may be processed by creating and updating as long as your relationship with the Company continues and may be kept in both digital and physical environment.

Your personal data may be processed in line with the purposes set out under the heading “Your Personal Data Processed and the Purposes of Processing” and in accordance with Article 5, paragraph 1 of Article 5 of Law No. 6698 and in accordance with the explicit consent requirement within the scope of paragraph 1 of Article 5 or specified in accordance with paragraph 2 of Article 5;

  1. a) Explicitly stipulated in the law,
  2. b) It is mandatory for the protection of the life or physical integrity of the person who is unable to disclose his/her consent due to actual impossibility or whose consent is not legally valid,

c)Provided that it is directly related to the conclusion or performance of a contract, it is necessary to process personal data of the parties to the contract

ç) It is mandatory for the data controller to fulfill its legal obligation,

  1. e) Data processing is mandatory for the establishment, exercise or protection of a right,
  2. f) Data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject,

processed within the scope of personal data processing conditions.

Your personal data of special nature processed as “association, foundation, union membership” other than health and sexual life will be processed in order to be used in case you want to benefit from special agreements and discounts for associations, foundations and unions with which our company has an agreement in line with the title “Your Processed Personal Data and Processing Purposes” in the clarification text, in order to ensure the explicit consent requirement within the scope of paragraph 2 of Article 6 of Law No. 6698 or in cases stipulated by law in accordance with paragraph 3 of Article 6.

Your personal data of special nature relating to your health information will be collected for the purposes set out under the heading “Your Personal Data Processed and Purposes of Processing” and in accordance with Article 6, paragraph 3 of Article 6 of Law No. 6698, only by authorized persons under the obligation of confidentiality for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and financing.

Your Processed Personal Data

Your Personal Data is processed securely in accordance with the Law on the Protection of Personal Data in accordance with legal obligations or in order to provide a more appropriate service in company business and transactions.

In this context, the data in the table are collected as personal data;

Identity: This is the data group containing information about the identity of the person (e.g. Name, Surname, Date of Birth / Place of Birth, Turkish ID Number, Gender, SSI Registration Number, Nationality, Marital Status)

Contact: A group of data that can be used to reach the person (e.g. Telephone Number, Residential Address, E-Mail Address)

Physical Space Security: This data category refers to data types such as employee entry and exit registration information, camera recordings. (Ex. Camera Image Records)

Transaction Security: This category of data refers to data types such as IP address information, website login and exit information, password and password information. (e.g. Log Records, IP Addresses, Cookie Information)

Finance: It is the data group containing the financial information of the person (e.g. Bank Account Number, IBAN Information)

Visual and Auditory Records: It is the data group containing visual and auditory data of the person (e.g. Photograph, Voice Recording, Camera Recording)

Customer Transaction: It contains the customer transaction information of the person. (e.g. Invoice Information, Invoice Number)

Legal Process: It contains information about the person’s judicial processes. (e.g. information in the case file, debt information)

Purposes of Processing Your Personal Data;

  • To be able to carry out the necessary work by our relevant business units so that real and / or legal third parties, institutions and organizations (employees, visitors, patients, suppliers, business partners, etc.) who have a relationship with the Company can benefit from the products and services of our Company and / or the centers and units of our Company,
  • Ensuring the security of life and property and legal and commercial security of real and/or legal third party institutions and organizations in the centers and units where the company’s business is carried out or affiliated to the company,
  • Storage of camera images, ensuring discipline, security and inspections in case you are physically present in the centers and units where the company’s business is carried out or affiliated to the company,
  • Carrying out the appointment activities on our website and confirming the identity information of those who make transactions through our website,
  • If an appointment is made, we can inform our patients about the appointment, provide information and remind them of the appointment,
  • Planning and managing the internal functioning of our hospital and daily operations and ensuring the supply of medication,
  • Turkish Commercial Code No. 6102, Turkish Code of Obligations No. 6098, Consumer Protection Law No. 6502, Personal Data Protection Law No. 6698, Tax Procedure Law No. 213, Social Security and General Health Insurance Law No. 5510, Health Services Basic Law No. 3359, Regulation on the Development and Evaluation of Quality in Health No. 29399, To fulfill the legal and regulatory requirements arising / may arise from the Regulation on Private Hospitals, the Regulation on the Processing and Protection of Privacy of Personal Health Data, the Regulation on Archive Services and all relevant laws and secondary regulations and to take the necessary measures within this scope,
  • Carrying out auditing and/or regulatory duties to be carried out by the authorized and authorized public institutions and organizations and professional organizations in the nature of public institutions,
  • Fulfillment of information and document requests by judicial bodies and/or administrative authorities,
  • To carry out listing, reporting, verification analysis studies on the usage patterns of the products and services offered in our company and all centers and units affiliated to the company, to produce statistical and scientific information in this regard, to improve our products and services accordingly, to increase satisfaction with our products and services and to make customizations regarding the user in this context,
  • To be able to conduct market research, promotion and necessary information regarding our products and services, to evaluate complaints and suggestions and to contact you directly through the communication channels shared with the Company,
  • Planning and management of the financing and invoicing of all services provided,
  • Preventive Medicine, Medical Diagnosis, Examination, Treatment and Care Services, Protection of Public Health
  • Planning and Management of Health Services and Financing
  • Conducting Necessary Tests and Audits and Execution of Related Processes
  • Procurement of Medicines and Related Materials
  • Planning Patient Relationship Management Processes
  • Providing Information to Authorized Public, Institutions and Organizations in accordance with the Legislation
  • Informing about the provision of services such as appointment reminders, changes, etc.
  • Measuring Patient Satisfaction
  • Execution of Patient Exit Processes and Procedures
  • Conducting Activities to Improve the Satisfaction of Patient Relatives, Companions, Visitors, etc.
  • Patient Assessment
  • Fulfillment of risk management and quality improvement activities,
  • Fulfillment of rights and obligations such as offers, promotions, exemptions, etc. offered by contracted private insurance companies and/or other institutions within the framework of agreements,
  • Taking all necessary technical and administrative measures for systems and applications within the scope of data security,
  • Protection of public order and health,
  • Conducting and managing health services such as medical diagnosis, treatment and care, and supply of medical supplies

purposes.

Your Personal Data of Special Nature Processed

Health Information: This is the data group containing the health information of the person (e.g. Blood Type, Medical History, Check-Up Result, Consultation Report, Surgery Information, Treatment Method Applied, Type of Disease, Medications Used, Eye Retina Shots, Medical Values, Test Results).

Biometric Data: Data group containing biometric/genetic data of the person (e.g. Palmprint, Retinal Scan).

In addition to the information above, if you want to benefit from activities or discounts in accordance with the agreement between the contracted associations, unions and non-governmental organizations and our hospital;

Union Membership Information: This is the data group containing the union information of the person (e.g. Union Membership Information)

Association Membership Information: This is the data group containing information about the association that the person is a member of and related to (e.g. Member Association Information).

Foundation Membership Information: This is the data group containing information about the foundation of which the person is a member and related to.

Purposes of Processing Your Special Categories of Personal Data;

  • Preventive Medicine, Medical Diagnosis, Examination, Treatment and Care Services, Protection of Public Health
  • Planning and Management of Health Services and Financing
  • Conducting Necessary Tests and Audits and Execution of Related Processes
  • Procurement of Medicines and Related Materials
  • Planning Patient Relationship Management Processes
  • Providing Information to Authorized Public, Institutions and Organizations in accordance with the Legislation
  • Informing about the provision of services such as appointment reminders, changes, etc.
  • Measuring Patient Satisfaction
  • Execution of Patient Exit Processes and Procedures
  • Patient Assessment
  • Fulfillment of rights and obligations such as offers, promotions, exemptions, etc. offered by contracted private insurance companies and/or other institutions within the framework of agreements,
  • Protection of public order and health,
  • Conducting and managing health services such as medical diagnosis, treatment and care, supply of medical supplies

purposes.

To Whom and For What Purpose Your Processed Personal Data Can Be Transferred

By ensuring that all necessary technical and administrative measures are taken to ensure the appropriate level of security in accordance with the KVKK and the relevant health legislation, in line with the above-mentioned purposes;

  • To legally authorized public institutions and organizations in line with the requests of the relevant public institutions and organizations and limited to the purposes of the request,
  • Private insurance companies and banks in order to ensure the fulfillment and continuity of financial services,
  • Lawyers or law partnerships for the follow-up of legal affairs,
  • Our business partners from whom we contractually receive and/or provide services to carry out our activities and with whom we cooperate

It may be transferred within the framework of the personal data processing conditions specified in Articles 8 and 9 of the KVK Law.

Data Processing Period and Storage Period

Your personal data, limited to the purposes specified in this Clarification Text; It will be processed by complying with the data processing and statute of limitations periods in all relevant laws and other legal legislation to which our company and our company’s affiliated centers and units are subject. In case of changes in the laws regarding data processing periods, the new periods determined will be taken as basis.

As a requirement of the principle of purpose limitation, your personal data is processed limited to the time required for the fulfillment of the purposes described in this Clarification Text and in any case in accordance with the practices of the company and the customs of its commercial life, and after the expiration of the periods, it is deleted, destroyed or anonymized.

Exercise of Rights by the Relevant Person:

As a data subject, you may use your rights under Article 11 of the Law regulating the rights of the data subject by submitting your requests in writing to the address “Mimar Sinan Mahallesi 1400 Sokak No: 10/Z1 Konak İzmiraccording to the “Communiqué on the Procedures and Principles of Application to the Data Controller” or electronically to the e-mail address info@kaskaloglu.com provided that your e-mail is registered in the company systems or by applying to our company’s lasermiyopiozel@hs03.kep.tr kep address by registered e-mail. More comprehensive regulation on this subject, more detailed information on data groups is provided in Kaşkaloğlu Eye Hospital Personal Data Application and Response Procedure and Kaşkaloğlu Eye Hospital Personal Data Protection and Processing Policy . You can access the relevant procedure from our corporate website or in line with the request you will make to the relevant personnel.

Data Controller

Title LASER MYOPIA SPECIAL TREATMENT CENTER LIMITED COMPANY

Address : MİMAR SİNAN MAHALLESI 1400 SOKAK NO: 10/Z1 KONAK İZMİR