General Data Protection
INFORMATION FORM WITH REGARD TO OBTAINING AND PROCESSING OF PERSONAL DATA
Acıbadem Sağlık Hizmetleri ve Ticaret A.Ş. (“Acıbadem”) and Acıbadem’s controlling shareholders, parent companies and affiliates (hereinafter to be collectively referred to as “Acıbadem Group”) may, acting as “Data Supervisor” under the Law on Protection of Personal Data no. 6698 (the “Law”), The General Data Protection Regulation 2016/679 (“GDPR”) and other pertinent laws and regulations, process your personal data within the following frame and in strict compliance with the Basic Healthcare Services Law no. 3359, the Governmental Decree-Law on Organization and Duties of the Ministry of Health and its Affiliated Companies no. 663, the Private Hospitals Regulation, and other regulations of the Ministry of Health, and other applicable laws and provisions.
- Obtaining and Processing of Personal Data, and Purposes of Processing:
Your personal data is collected and obtained verbally, in writing, or in visual or electronic media, through call center, internet site, verbally, in writing or similar other channels for conduct of such services as protection of public health, preventive medicine, medical diagnosis, treatment and maintenance services offered by Acıbadem Group, or for planning and management of healthcare services and financing, and in accordance with the fields of business of Acıbadem Group Companies. Your general personal data and special personal data, especially your healthcare data, may be processed by the Group to a limited extent for all and any purposes, including, but not limited to, the following purposes:
- Your identity data and information: Your first name, surname, T.R. Identity Number, passport number or temporary T.R. Identity Number, birth date and place, marital status, gender, social security or patient protocol number, as well as other identity data that may be helpful in identification of you by us; and
- Your communication information: Your address, telephone number, electronic mail address and other communication data, and your verbal interview or call records kept by the customer services or patient services departments as per the call center standards, as well as your personal data collected when you communicate with us by electronic mail, letter or other communication means; and
- Your accounting information: Your bank account number, IBAN number, credit card data, invoicing data and similar other financial data and information; and
- Your private health insurance data and Social Security Agency data and information as needed for financing and planning of healthcare services; and
- Your camera recordings and images taken and kept for security and audit purposes if and when you visit our hospitals or medical centers; and
- Your car plate license number if you use the car parking area; and
- Your healthcare information: Your personal data about your health and sexual life acquired and collected during provision or as a result of medical diagnosis, treatment and care services, including, but not limited to, your laboratory analysis results, test results, medical examination data, appointment data and information, check-up data, and prescription data and information; and
- Your healthcare information and other personal data sent or inserted by you in the following websites;
- If and when you file a job application to Acıbadem or to any one of Acıbadem Group Companies, your personal data and information, also including your curriculum vitae, submitted by you, and if you are an employee or a related employee of Acıbadem Group, your employment contract and all kinds of your personal data about your predisposition to job.
All kinds of your personal data obtained by Acıbadem Group (including, but not limited to, your special personal data) may be processed for the following purposes:
- For confirmation of your identity, and
- For protection of public health, preventive medicine, medical diagnosis, treatment and maintenance services, and for planning and management of healthcare services and financing, and
- Sharing of requested information with the Ministry of Health and other relevant public entities and administrations pursuant to the applicable laws and regulations, and
- Planning and management of internal operations and daily operations of our Hospitals and Medical Centers, and
- Measurement, enhancement and study of patient satisfaction by Hospital Management, Patient Rights and Patient Experience departments, and
- Procurement of drugs, and
- If you get an appointment, keeping you informed about the appointment, and
- Performance of risk management and quality improvement activities, and
- Performance of analyses for further development of healthcare services, and
- Financing of your healthcare services by Patient Services, Financial Affairs and Marketing departments, and payment of your medical examination, diagnosis and treatment costs, and sharing of requested information with private health insurance firms as a part of your eligibility inquiry, and
- Conduct of researches and studies, and
- Compliance with legal and regulatory requirements and conditions, and
- Sharing of requested information with private health insurance firms in the course of financing of healthcare services, and
- Conduct of risk management and quality development activities by Quality, Patient Experience and Information Systems departments, and
- Issuance of invoices by Patient Services, Financial Affairs and respective departments in consideration of our services, and confirmation of your relations with the contracted institutions and firms, and
- Participation in campaigns and disclosure of campaign information, and designing and transmission of special contents, and discrete and abstract benefits in web and mobile channels, by Media and Communication, and Call Center departments.
Your personal data obtained and processed pursuant to the applicable laws and regulations may be transferred to physical archives and/or information systems of Acıbadem or Acıbadem Group and may be kept and stored both in digital and in physical platforms.
- Transfer of Personal Data
Your personal data may be shared by Acıbadem and Acıbadem Group with companies included in Acıbadem Group or with private insurance companies, Ministry of Health and its sub-units, Social Security Agency, Security General Directorate and other security forces, General Directorate of Population and Census, Turkish Pharmacists’ Association, courts and all kinds of other juridical authorities, central etc. with your consent and to be limited by your consent Acıbadem may share your personal data with third parties, your authorized representatives and agents, and third parties offering consulting and advice services to us, including, but not limited to, lawyers, tax and financial consultants and auditors, and our business partners and other third parties acting in cooperation with us for further development or performance of healthcare services for the purposes cited above, also including regulatory and supervisory bodies and authorities, and official authorities, for the purposes of processing listed above, in accordance with the Law, GDPR and other applicable laws and regulations.
- Methods and Legal Causes of Obtaining of Personal Data
Your personal data are collected and processed in all kinds of verbal, written, visual or electronic media, for the purposes listed hereinabove, and for performance of all kinds of works included in the fields of business of Acıbadem within the legal framework, and accordingly, for full and proper performance of all kinds of contractual and legal duties and obligations of Acıbadem. Legal causes of collection and acquisition of your personal data are the pertinent provisions of:
- Law on Protection of Personal Data no. 6698,and
- The General Data Protection Regulation 2016/679 (“GDPR”) and Basic Healthcare Services Law no. 3359, and
- Governmental Decree-Law on Organization and Duties of the Ministry of Health and its Affiliated Companies no. 663, and
- Private Hospitals Regulation, and
- Regulation on Processing and Protection of Privacy of Personal Healthcare Information, and
- Other regulations of the Ministry of Health, and other applicable laws and provisions.
Furthermore, as stipulated in 3rd paragraph of article 6 of the Law, personal data relating to health may also be processed by persons under secrecy obligations or by authorized official entities and organizations, without being liable to receive prior explicit consent of the relevant purpose, only for protection of public health, preventive medicine, medical diagnosis, treatment and maintenance services, and for planning and management of healthcare services and financing.
- Your Rights Regarding Protection of Personal Data
Pursuant to the Law and GDPR and other relevant applicable laws and regulations, you are entitled:
- To learn whether your personal data are processed or not, and
- If your personal data are processed, to request information relating thereto, and
- To have access to and request personal healthcare data and information, and
- To learn the purpose of processing of personal data and whether they are used for the intended purposes or not, and
- To learn third parties resident at home or abroad and to whom your personal data are transferred, and
- If your personal data are processed incompletely or wrongly, to request correction or completion of them, and
- To request deletion or destruction of your personal data, and
- To request that the third parties to whom your personal data have previously been transferred are informed about correction or completion of your personal data in case of incomplete or wrong processing, and/or about deletion or destruction of your personal data, and
- To raise objections to any conclusions which may arise against your interests upon analysis of your processed personal data solely by means of automatic systems.
If at any time you use any one or more of your aforesaid rights, the relevant information will be transmitted to you clearly and in an understandable manner, in writing or in electronic media, by using the communication data and information provided by you.
- Data Security
Acıbadem protects your personal data in full and strict compliance with all technical and administrative security controls required to be taken in accordance with information security standards and procedures. Said security actions and measures are taken and provided at a level appropriate for the probable risks by also taking into consideration the technological possibilities.
- Complaints and Communications
Your personal data are protected within the frame of the available technical and administrative possibilities, and the required security actions and measures are taken and provided at a level appropriate for the probable risks by also taking into consideration the technological possibilities.
By filling in the “Application Form Pursuant to the Law on Protection of Personal Data and/or GDPR” given herein, you may transmit and submit your legal requests:
- (i) by sending to the address of Fahrettin Kerim Gökay Cad. No: 49 Altunizade, Istanbul, Turkey by cargo courier service, together with a petition bearing your wet signature, and in an envelope addressed to the attention of “Corporate Secretariat” department marked with “Information Request Under the Law on Protection of Personal Data” or “Information Request Under the GDPR” phrase, or
- (ii) by sending via a Notary Public, or
- (iii) by sending to firstname.lastname@example.org address with secure electronic means or mobile signature, through your registered electronic mail address or your electronic e-mail address registered in our system, and/or
- (iv) by signing a dossier in “word or pdf.” Format addressed to Acıbadem with your secure e-signature and transmit the same to email@example.com address by writing “Information Request Under the Law on Protection of Personal Data” or “Information Request Under the GDPR” phrase in the subject line of your e-mail.
You are hereby kindly requested to transmit your legal requests under the Law and/or GDPR by filling in the “Application Form Pursuant to the Law on Protection of Personal Data and/or GDPR” given herein and sending it to us by the communication means set forth in the form.