This English translation is provided for convenience. In the event of any discrepancy, the Turkish version prevails.
“Dear visitor; one of the core principles of Dr. Ömer Fatih ŞAHİN is to work with respect for individual rights and freedoms. The lawful processing of personal data and the safeguarding of information security are among our priorities. You may learn more by reading the Privacy and Personal Data Protection Policy below and by contacting us at any time.”
1. Purpose and Scope
This Privacy and Personal Data Protection Policy (the “Policy”) sets out, on behalf of Dr. Ömer Fatih Şahin — who holds the status of data controller under Turkish Law No. 6698 on the Protection of Personal Data (the “Law”, “KVKK”) — the methods by which personal data is obtained and the legal grounds for doing so; the categories of data subjects and personal data; the purposes of processing; to whom and for what purposes personal data is transferred, including transfers abroad; the technical and administrative measures taken to protect personal data; the retention periods; and the rights of data subjects.
This Policy was last updated on 6 August 2026, taking into account the amendments made to Articles 6 and 9 of the Law by Law No. 7499 and the IT infrastructure actually used by our practice.
2. Methods of Obtaining Personal Data and Legal Grounds
Your personal data is obtained by Dr. Ömer Fatih Şahin in accordance with the general principles of Article 4 of the Law and the principle of data minimisation;
- Verbally (face-to-face communication, telephone and WhatsApp calls),
- In writing (forms and other documents completed by you, e-mails you send, notifications from judicial authorities),
- Visually (CCTV recordings at the practice), or
- Electronically (use of the website, the website contact form, cookies)
in each case in fulfilment of the duty to inform, and — where required — with your explicit consent.
Personal data is processed on the legal grounds set out in Article 5 of the Law: the explicit consent of the data subject; processing being expressly provided for by law; factual impossibility; processing being directly related to the conclusion or performance of a contract; processing being necessary for the data controller to comply with a legal obligation; the data having been made public by the data subject; processing being necessary for the establishment, exercise or protection of a right; and processing being necessary for the legitimate interests of the data controller, provided it does not harm the fundamental rights and freedoms of the data subject.
Special categories of personal data are processed only where one of the conditions listed in Article 6 of the Law, as amended by Law No. 7499, is met. Your health data is processed primarily by, or under the supervision of, physicians and healthcare staff who are under a duty of confidentiality, for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning, management and financing of healthcare services; in all other cases it is processed only with your explicit consent.
3. Data Subjects and Categories of Personal Data
Dr. Ömer Fatih Şahin processes the personal data of the following groups, in the categories indicated:
- Patients / clients: identity, contact, finance, legal transaction, health data, visual and audio recordings
- Job applicants, employees, former employees, interns: identity, contact, finance, employment and personnel records, professional experience, legal transaction, special categories (health, criminal convictions), fringe benefits, family members and relatives, visual and audio recordings
- Relatives of employees: identity, contact, finance, personnel and professional records
- Business partners, suppliers and their employees / authorised signatories: identity, contact, legal transaction
- References: identity, contact, professional experience
- Visitors: identity, physical premises security (CCTV recordings)
- Website visitors: transaction security data (IP address, browser and device information, access logs), the name, e-mail address and message content you submit via the contact form, and — only subject to your explicit consent — data processed through cookies
4. Purposes of Processing
Personal data is processed by Dr. Ömer Fatih Şahin for the following purposes:
- Protection of public health, preventive medicine, medical diagnosis, treatment and care services, and the planning, management and financing of healthcare services
- Conducting activities in compliance with legislation, handling legal affairs, providing information to authorised persons and institutions, storage and archiving activities
- Receiving and managing appointment requests, handling requests and complaints, communication activities, promotional activities, patient relations processes
- Providing the website securely, lawfully and without interruption; information security processes and access management; risk management
- Emergency management, physical premises security, protection of movable assets and resources
- Human resources processes: recruitment and placement, fulfilment of obligations arising from employment contracts and legislation, remuneration and benefits, occupational health and safety, training and performance processes
- Contract processes, procurement of goods and services, finance and accounting
- Creating and tracking visitor records
5. Transfers of Personal Data
Your personal data is transferred to third parties only for the purposes stated above and in accordance with Articles 8 and 9 of the Law. In all transfer processes the necessary technical and administrative measures are taken, and the need-to-know and data-minimisation principles are observed.
5.1. Domestic Transfers
- Patient / client data: where necessary for your treatment and with your explicit consent, to contracted laboratory service providers; to financial advisers and banks for financial and accounting processes; to e-invoicing and courier providers; to tax offices and Ministry of Finance representatives for tax obligations; to lawyers, auditors and advisers in the context of legal obligations; and to regulatory and supervisory authorities, courts, enforcement offices and other public institutions legally authorised to request personal data.
- Employee, former employee and intern data: to the Social Security Institution (SGK) and/or İŞKUR for employment notifications; to the SGK and the Ministry of Health in audits; to tax offices for mandatory declarations; to banks for salary payments; to service providers for automatic private pension transactions; to occupational health and safety firms, hospitals and healthcare institutions; to insurance companies; and to authorised public institutions in the context of legal obligations.
- Employee relatives’ data: to authorised public institutions in the context of minimum living allowance notifications.
- Business partner, supplier and signatory data: to public institutions and notaries for statutory notifications; to Ministry of Finance representatives during tax audits; to banks where payment obligations exist.
- Visitor data: to public institutions legally authorised to request such information; the names and appointment times of visitors to the building management of the premises for physical security purposes; and, upon request, access logs and CCTV recordings to official authorities such as prosecutors’ offices and courts.
5.2. Transfers Abroad
Our corporate e-mail is hosted on servers located in Turkey; when you e-mail us, or when contact-form content reaches us, this data is stored domestically. The operation of our website, however, relies on service providers whose servers are located outside Turkey. The personal data indicated below is therefore transferred to the following categories of recipients, in accordance with the conditions of Article 9 of the Law as amended by Law No. 7499:
- Cloudflare, Inc. (USA; global server network): when you visit our website, your transaction security data (IP address, browser and device information, access logs) is processed through the Cloudflare infrastructure that hosts, accelerates and protects the site.
- Web3Forms (form relay service located abroad): the information you submit through the contact form (name, e-mail address, message content) passes through this service, which processes the form content solely for the purpose of delivering it to us by e-mail.
- Google Ireland Ltd. / Google LLC (EU and USA): only if you give explicit consent via our cookie banner, measurement data about the use of our site is processed through Google Tag Manager and connected measurement services. If you do not consent, this transfer does not take place; see the Cookie Policy for details.
If you include information about your health in a message sent via the contact form, that information will also pass through the relay service located abroad described above while the form is being delivered. If you prefer not to share health details online, we recommend contacting us by telephone or discussing them during your consultation.
Transfers abroad are carried out in accordance with the safeguards provided for in Article 9 of the Law, the principle of data minimisation and the principle of purpose limitation, taking into account that the relevant services can only be provided in this way; agreements containing data-protection provisions are concluded with the relevant service providers. Patient files and medical records are not kept on our website.
6. Technical and Administrative Measures Taken to Protect Personal Data
Dr. Ömer Fatih Şahin takes the technical and administrative measures required under Article 12 of the Law to ensure the confidentiality, integrity and security of personal data:
- Data minimisation: our website is published as a static site and contains no membership system, user accounts or online patient registration; no patient files or medical records are kept on the site. Only contact-form data and transaction security data are processed through the site.
- Encryption: all connections to the website are encrypted with TLS (HTTPS) and HSTS is enforced. Corporate e-mail is accessed over encrypted connections, and the mailboxes are hosted on servers located in Turkey.
- Infrastructure security: the site is served through the Cloudflare infrastructure, which includes firewalls and attack-prevention systems; security headers (including a content security policy) are applied.
- Access control: access to the site content and to the domain and e-mail administration panels is restricted to authorised persons and protected with strong authentication. Access rights are updated immediately upon any change of role.
- Consent management: measurement and marketing cookies are not activated unless explicit consent is given (they are off by default).
- Physical security: personal data on paper is kept in locked cabinets and accessed only by authorised persons. CCTV recordings at the practice are retained for a limited period.
- Awareness: persons with access to personal data receive regular reminders and briefings on information security and personal data protection.
- Breach notification: if, despite all measures taken, personal data is unlawfully obtained by third parties, the situation is reported as soon as possible to the Turkish Personal Data Protection Board and to the data subjects concerned, and the necessary measures are taken to minimise the consequences.
7. Retention Periods and Disposal
Dr. Ömer Fatih Şahin retains personal data for the periods prescribed by the applicable legislation or required by the purpose of processing:
- Patient / client data: 10 years from the end of the legal relationship (laboratory and blood-transfusion data: 30 years in physical form, under the applicable regulations)
- Business partner / supplier data: 10 years from the end of the legal relationship
- CVs and personnel details received with job applications: 2 years from the application date
- Employee data: personnel records for the period required by legislation; other data for 10 years from the end of the legal relationship
- Employees’ special-category data: health data 15 years; criminal-conviction data 10 years from the end of the legal relationship
- CCTV recordings at the practice: 1 week
- Website access logs: 2 years, under Law No. 5651 and secondary legislation
- Contact-form and e-mail correspondence: where a legal relationship is established, the same period as patient records; otherwise no longer than 2 years after the request is concluded
- Accounting and financial records: 10 years
At the end of these periods, personal data is deleted, destroyed or anonymised in accordance with the Regulation on the Deletion, Destruction or Anonymisation of Personal Data. The periodic disposal interval is set at 6 months.
8. Rights of Data Subjects and How to Exercise Them
Under Article 11 of the Law, data subjects have the right to:
- Learn whether their personal data is processed,
- Request information about such processing,
- Learn the purpose of processing and whether the data is used in line with that purpose,
- Know the third parties to whom personal data is transferred, in Turkey or abroad,
- Request rectification of incomplete or inaccurate data,
- Request deletion or destruction of personal data under the conditions of Article 7 of the Law,
- Request that rectification, deletion and destruction be notified to the third parties to whom the data has been transferred,
- Object to a result arising to their detriment from analysis of processed data exclusively by automated systems,
- Claim compensation for damage suffered due to unlawful processing.
You may submit requests concerning these rights, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller, with a petition containing information establishing your identity and the subject of your request:
- In person at Harbiye Mahallesi, Abdi İpekçi Cad. No: 39, Hayal Apartmanı, Kat: 4 Daire: 5, 34367 Şişli / İstanbul,
- By notary or registered post to the same address,
- With a secure electronic signature or mobile signature, or from the e-mail address you previously notified to us and registered in our system, to [email protected].
Your application will be concluded free of charge as soon as possible and within 30 (thirty) days at the latest, depending on its nature; where the process involves an additional cost, the fee set by the Personal Data Protection Board may be charged.
9. Changes to This Policy
This Policy may be revised in line with changes in legislation or updates to our data-processing activities. The current version is always published on this page; the date of the most recent update is stated in Section 1.
