This English translation is provided for convenience. In the event of any discrepancy, the Turkish version prevails.
“Dear visitor; one of the core principles of Dr. Ömer Fatih ŞAHİN is to work with respect for individual rights and freedoms. Ensuring that personal data — which holds great importance today — is processed lawfully, and safeguarding information security, are also among the priorities of our policies. In this respect, you may learn more by reading the Privacy and Personal Data Protection Policy below and by contacting us at any time.”
1. Purpose and Scope
This Privacy and Personal Data Protection Policy (the “Policy”) sets out, in detail, on behalf of Dr. Ömer Fatih Şahin — who holds the status of data controller under Law No. 6698 on the Protection of Personal Data (the “Law”, “KVKK”) — the methods by which personal data is obtained and the legal grounds on which such data is obtained; the categories of data subjects and personal data covered by the personal data processing activity; the purposes for which Dr. Ömer Fatih ŞAHİN processes personal data; to whom and for what purposes such data is transferred; the technical and administrative measures taken to ensure the security of personal data; the retention periods of personal data; and the rights of the data subject and how those rights may be exercised.
2. Methods of Obtaining Personal Data and Legal Grounds
Your personal data is obtained by Dr. Ömer Fatih ŞAHİN, in adherence to the general principles set out in Article 4 of the Law and with regard to data minimisation;
- Verbally (for example, face-to-face communication, telephone conversations, etc.),
- In writing (for example, forms and other documents prepared or completed by you, e-mails sent, notifications from judicial authorities, etc.),
- Visually (for example, camera recordings), or
- Electronically (for example, use of the website, etc.)
in every case with the obligation to inform being fulfilled, and, in addition, where necessary, with the explicit consent of the data subject being obtained.
Personal data is processed by Dr. Ömer Fatih Şahin on the following legal grounds: the explicit consent of the data subject; it being expressly provided for by law; it being mandatory for the protection of the life or physical integrity of the data subject or of another person, where the data subject is physically incapable of giving consent or whose consent is not legally valid; it being directly related to the establishment or performance of a contract; it being mandatory for the data controller to fulfil its legal obligations; the data having been made public by the data subject themselves; it being mandatory for the establishment, exercise or protection of a right; and it being mandatory for the legitimate interests of the data controller, provided this does not harm the fundamental rights and freedoms of the data subject.
Within the scope of its activities, Dr. Ömer Fatih Şahin does not, as a rule, process special categories of personal data unless the explicit consent of the data owner has been obtained. Special categories of personal data other than those relating to health and sexual life may only be processed without the explicit consent of the data subject where expressly provided for by law. Personal data relating to health and sexual life, however, may be processed by persons bound by an obligation of confidentiality (our physicians and other healthcare personnel), without seeking the explicit consent of the data subject, solely for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of healthcare services and their financing; in all other circumstances, such data may only be processed with the explicit consent of the data subject.
3. Categories of Data Subjects and Personal Data
Within the scope of its activities, Dr. Ömer Fatih Şahin processes the personal data of the following groups of persons, falling within the categories specified below:
Patient/Customer: Identity, Contact, Financial, Legal Transaction, Health, Genetic or Sexual Life Data, Visual and Audio Records, Other. Job Applicant, Employee, Former Employee, Intern: Identity, Contact, Financial, Employment Information, Personnel and Professional Information, Legal Transaction, Special Category Personal Data (Health and Criminal Conviction), Fringe Benefits and Interests, Family Members and Relatives’ Information, Visual and Audio Records, Other. Employee’s Relative: Identity, Contact, Financial, Personnel and Professional Information. Business Partner: Identity, Contact, Legal Transaction. Supplier and Customer Company Employee: Identity, Contact. Supplier and Customer Company Authorised Signatory: Identity, Contact, Legal Transaction. Reference: Identity, Contact, Personnel (and/or Professional Experience). Visitor: Identity, Transaction Security, Physical Space Security. Website Visitor: Transaction Security.
4. Purposes of Processing Personal Data
Personal data is used by Dr. Ömer Fatih Şahin for the following purposes:
▪ Carrying out activities in compliance with legislation, follow-up and execution of legal affairs, providing information to authorised persons, institutions and organisations, carrying out storage and archiving activities
▪ Protecting public health, preventive medicine, carrying out medical diagnosis, treatment and care services, planning and managing healthcare services and their financing
▪ Following up requests/complaints, carrying out communication activities, carrying out promotional activities, carrying out customer relationship management processes
▪ Managing access authorisations, carrying out risk management processes, carrying out information security processes, ensuring the security of data controller operations
▪ Carrying out emergency management processes, ensuring physical space security, ensuring the security of movable property and resources
▪ Carrying out assignment processes, carrying out audit/ethics activities, carrying out internal audit/investigation/intelligence activities, carrying out activities for ensuring business continuity
▪ Carrying out management activities, carrying out strategic planning activities, carrying out contract processes
▪ Organisation and event management, carrying out social responsibility and civil society activities
▪ Carrying out training activities, carrying out/supervising business activities, carrying out job applicant/intern/student selection and placement processes, carrying out employee satisfaction and loyalty processes, fulfilling obligations arising from employment contracts and legislation for employees, carrying out fringe benefits and interests processes for employees, planning human resources processes, carrying out occupational health/safety activities, carrying out performance evaluation processes, work and residence permit procedures for foreign personnel, carrying out wage policy, carrying out talent/career development activities
▪ Receiving and evaluating suggestions for improving business processes, carrying out goods/service procurement processes, carrying out goods/service production and operation processes
▪ Carrying out finance and accounting affairs, carrying out supply chain management processes, carrying out logistics activities
▪ Creating and following up visitor records
5. Transfer of Personal Data and Purposes of Transfer
Within the scope of the activities carried out by Dr. Ömer Fatih Şahin, your personal data must be shared with third parties other than Dr. Ömer Fatih Şahin, for the purposes stated above and limited to the fulfilment of those purposes. In all such transfer processes, Dr. Ömer Fatih Şahin acts in accordance with Articles 8 and 9 of the Law, implements the necessary technical and administrative measures, observes the principles of need-to-know and need-to-use, and adheres to the principle of data minimisation. In addition, personal data transferred is also legally protected through additional protocols signed with the third parties to whom the transfer is made.
Within this scope, personal data transfers are carried out as set out in the table below:
Data Subject / Purpose of Transfer and Recipient
Customer
- With our contracted firms providing laboratory services, with your explicit consent, for the purpose of carrying out your tests where necessary for your treatment; with relevant business partners, consultants and service providers, banks, and our financial advisors, for the management of financial and accounting processes and the detection, assessment and prevention of fraud and risks,
- With our e-invoice business partner, for the electronic delivery of the e-invoice to the customer; with cargo and courier companies, for the delivery of physical contracts or invoices,
- With tax offices, for the fulfilment of tax obligations; with representatives of the Ministry of Finance, during tax audits, for invoices and collection receipts,
- With our business partners and service providers that provide, operate or supply our information technology infrastructure,
- With our business partners providing financial advisory/accounting services, with lawfully authorised public institutions and private persons or organisations, and with third parties,
- With lawyers, auditors, forensic IT experts, cyber security consultants, tax consultants, and other third parties and business partners from whom we receive advisory and services, for the fulfilment of legal obligations,
- With regulatory and supervisory authorities and other official institutions such as courts and enforcement offices,
- In all processes, with other public institutions or organisations authorised to request your personal data,
Employee, Former Employee, Intern
- With the Social Security Institution (SGK) and/or the Turkish Employment Agency (İŞKUR), within the scope of our legal obligations regarding entry and exit notifications,
- With the Social Security Institution and the Ministry of Health, in the event of an audit,
- With the Ministry of Family, Labour and Social Services, where necessary,
- With the tax office, for the filing of mandatory tax returns arising from law, and with other public institutions or organisations authorised to request your personal data, including but not limited to the above,
- With banks, for the payment of employee salaries, regarding financial information,
- With service providers, for the fulfilment of automatic individual pension transactions,
- With our business partners and service providers that provide, operate or supply our information technology infrastructure, and with our business partners and service providers offering services in quality control, complaint management and risk analysis,
- With our business partners providing independent audit, financial advisory/accounting services, with lawfully authorised public institutions and private persons or organisations and third parties, with lawyers, auditors, forensic IT experts, cyber security consultants, tax consultants and other third parties from whom we receive advisory and services for the fulfilment of legal obligations, and with regulatory and supervisory authorities and other official institutions such as courts and enforcement offices,
- With occupational health and safety companies, hospitals and healthcare institutions, for emergency medical intervention and the fulfilment of occupational health and safety obligations,
- With travel agencies and hotels located in Turkey and abroad, for the arrangement of transportation and accommodation in connection with the planning and execution of events, organisations and business travel,
- With infrastructure providers, for the storage of physical and electronic employee data,
- With security companies, for camera recordings and similar data, to ensure the security of the premises,
- With service providers, for training and performance evaluation purposes,
- With relevant service providers, for the provision of fringe benefits such as discounted transportation cards, meal cards and clothing to employees,
- With cargo companies where delivery is required; with customers to whom services are provided, for the purpose of ensuring the necessary communication and coordination within the scope of on-site technical support, installation and similar advisory services,
- With business partners, forensic IT experts and consultants operating in this field, for the provision of information security and the fulfilment of legal and technical obligations,
- With parties named as references by the employee,
- With private insurance companies and relevant service providers in this field, for the preparation of incapacity reports, periodic health screenings, and insurance transactions such as private health insurance and personal accident insurance,
Employee’s Relative
- With authorised public institutions, within the scope of minimum living allowance (AGİ) notifications,
Business Partner, Supplier and Customer Company’s Authorised Signatory
- With relevant public institutions and notaries, for the fulfilment of legal notifications required to be made by the accounting department,
- With representatives of the Ministry of Finance, during tax audits, for invoices and collection receipts,
- With other authorised public institutions and organisations, for the fulfilment of our legal obligations,
- With banks, where a payment obligation arises from the existing relationship, for that purpose,
Visitor, Website Visitor
- With public institutions and organisations legally authorised to request such information, within the scope of legal obligations (such as, but not limited to, combating crime, threats to state and public security, and other circumstances in which Dr. Ömer Fatih Şahin has a legal or administrative obligation to notify or provide information),
- With the site management of the building in which our practice is located, for the purpose of ensuring physical space security, regarding visitors’ names and appointment times,
- With official institutions such as the public prosecutor’s office and courts, where requested (for example, log records and camera recordings)
6. Technical and Administrative Measures Taken to Ensure the Security of Personal Data
Dr. Ömer Fatih Şahin exercises the necessary diligence and takes the necessary technical and administrative measures to ensure the confidentiality, integrity and security of your personal data. In this context, the following measures are taken to prevent the unlawful processing of personal data, unauthorised access to personal data, and the disclosure, alteration or destruction of data.
Anti-Virus: All computers and servers within our information technology infrastructure have anti-virus software installed that is updated periodically.
Firewall: The Data Centre hosting our servers is protected by a periodically updated firewall. Next-generation firewalls monitor the internet connections of all personnel and provide protection against viruses and similar threats during this monitoring.
User Identification and Authorisation Matrix: The authorisations of Dr. Ömer Fatih Şahin’s employees within our systems are limited only to the extent required by their job descriptions, and in the event of any change in authorisation or duties, access rights are immediately terminated or amended in line with the new role.
Information Security Threat and Incident Management: Any breaches or identified risks occurring on our servers and firewalls are immediately reported to the person responsible for information technology. This person responds promptly to any security threat and ensures the security of personal data.
Penetration Testing: Penetration testing is periodically carried out manually on the servers and computers within our system by a contracted external firm. Any vulnerabilities identified as a result of this testing are closed, and verification testing is carried out to confirm that the relevant vulnerabilities have been resolved.
Employee Training and Awareness-Raising: In order to raise the awareness of Dr. Ömer Fatih Şahin’s employees against various information security breaches and to minimise the impact of the human factor in information breach incidents, employees are regularly reminded of and trained on information security matters. Users are given further reminders and warnings where necessary.
Clean Desk Policy: In accordance with our internal rules, employees are required to comply with a clean desk policy.
Physical Security: We ensure that personal data in paper form is kept in locked cabinets and is accessible only to authorised persons.
Cookies: Personal data processed through cookies belonging to third parties from whom services are received is deleted from the third parties’ systems once the relevant relationship ends.
Breach Notification: Notwithstanding that Dr. Ömer Fatih Şahin takes the necessary technical and administrative information security measures, in the event that personal data is damaged or falls into the hands of unauthorised third parties as a result of attacks on the online platforms or systems operated by Dr. Ömer Fatih Şahin, Dr. Ömer Fatih Şahin will immediately notify you and the Personal Data Protection Board of the situation and take the necessary measures to minimise the consequences of the breach.
7. Retention Periods and Destruction Conditions for Personal Data
Dr. Ömer Fatih Şahin retains the personal data it processes, in compliance with the Law, for the periods stipulated by the relevant legislation or required by the purpose of processing. These periods are set out in the table below:
Personal Data / Retention Period
- Personal Data relating to Customers: 10 years from the end of the legal relationship; (Laboratory and blood transfusion data belonging to customers, however, is retained in physical form for 30 years pursuant to the Medical Laboratories Regulation and the Blood and Blood Products Regulation, and indefinitely in electronic form.)
- Personal Data relating to Business Solution Partners/Suppliers: 10 years from the end of the legal relationship
- CVs and Personnel Information Collected during Job Applications: 2 years from the date of the job application
- Personal Data belonging to Personnel (Identity, Contact, Personnel Information, Legal Transaction Data, Professional Experience, Visual and Audio Records, Physical Space Security): Personnel information for the duration of the employee’s life, other data for 10 years from the end of the legal relationship, camera recordings for 6 months
- Special Category Personal Data belonging to Personnel (Criminal Conviction and Health Data): Health data for 15 years; criminal conviction data for 10 years from the end of the legal relationship
- Personal Data relating to Visitors (Camera Recordings): 1 week
- Personal Data relating to Online Visitors: 2 years
- All Records relating to Accounting and Financial Transactions: 10 years
Dr. Ömer Fatih Şahin retains the personal data it collects and processes through physical, electronic, website, e-mail and other channels within the scope of its business processes, pursuant to Articles 7 and 17 of the Law and Article 138 of the Turkish Criminal Code, for the periods stipulated by the relevant laws or secondary legislation and/or required by the purpose of processing. Upon the expiry of these periods, such data is deleted, destroyed or anonymised in accordance with the provisions of the Regulation on the Deletion, Destruction or Anonymisation of Personal Data and the Guide on the Deletion, Destruction or Anonymisation of Personal Data. Dr. Ömer Fatih Şahin has determined a periodic destruction period of 6 months.
For Dr. Ömer Fatih Şahin, deletion of personal data means rendering the personal data inaccessible and unusable in any way whatsoever by the relevant users; destruction of personal data means rendering the personal data inaccessible, unrecoverable and unusable in any way whatsoever by anyone. Anonymisation of personal data means rendering such data incapable, under any circumstances, of being associated with an identified or identifiable natural person, even when matched with other data.
In its Personal Data Retention and Destruction Policy, prepared pursuant to the Regulation on the Deletion, Destruction or Anonymisation of Personal Data, Dr. Ömer Fatih Şahin explains in detail the methods of deletion, destruction and anonymisation and the technical and administrative measures it has taken in this regard.
8. Rights of Data Subjects and the Exercise of These Rights
Pursuant to Article 11 of the Law, data subjects have the following rights:
▪ To learn whether their personal data is being processed,
▪ To request information regarding such processing, if their personal data has been processed,
▪ To learn the purpose of processing of their personal data and whether the data is used in accordance with its intended purpose,
▪ To know the third parties, domestic or abroad, to whom their personal data is transferred,
▪ To request the correction of their personal data in the event it has been processed incompletely or incorrectly,
▪ To request the deletion or destruction of their personal data,
▪ To request that the correction, deletion or destruction of their personal data be notified to third parties to whom the personal data has been transferred,
▪ To object to the emergence of a result against themselves through the analysis of processed data exclusively by automated systems,
▪ To request compensation for damages in the event of loss due to the unlawful processing of their personal data.
In order to exercise your rights over your personal data, you may complete the “Application Form” accessible at https://www.omerfatihsahin.com.tr/kvkk and;
▪ Deliver it in person to the address: Harbiye Mahallesi, Abdi İpekçi Cad, No:39, Hayal Apartmanı, Kat:4 Daire:5 34367 Şişli / İstanbul,
▪ Send it, wet-signed, to the address specified above through a notary,
▪ Submit it to [email protected] via secure electronic or mobile signature, through a registered electronic mail (KEP) address, or via your e-mail address registered in our system.
