AESTHETIC & WELLNESS

Privacy and Personal Data Protection Policy

This English translation is provided for convenience. In the event of any discrepancy, the Turkish version prevails.

“Dear visitor; one of the core principles of Dr. Ömer Fatih ŞAHİN is to work with respect for individual rights and freedoms. Ensuring that personal data — which holds great importance today — is processed lawfully, and safeguarding information security, are also among the priorities of our policies. In this respect, you may learn more by reading the Privacy and Personal Data Protection Policy below and by contacting us at any time.”

1. Purpose and Scope

This Privacy and Personal Data Protection Policy (the “Policy”) sets out, in detail, on behalf of Dr. Ömer Fatih Şahin — who holds the status of data controller under Law No. 6698 on the Protection of Personal Data (the “Law”, “KVKK”) — the methods by which personal data is obtained and the legal grounds on which such data is obtained; the categories of data subjects and personal data covered by the personal data processing activity; the purposes for which Dr. Ömer Fatih ŞAHİN processes personal data; to whom and for what purposes such data is transferred; the technical and administrative measures taken to ensure the security of personal data; the retention periods of personal data; and the rights of the data subject and how those rights may be exercised.

Your personal data is obtained by Dr. Ömer Fatih ŞAHİN, in adherence to the general principles set out in Article 4 of the Law and with regard to data minimisation;

in every case with the obligation to inform being fulfilled, and, in addition, where necessary, with the explicit consent of the data subject being obtained.

Personal data is processed by Dr. Ömer Fatih Şahin on the following legal grounds: the explicit consent of the data subject; it being expressly provided for by law; it being mandatory for the protection of the life or physical integrity of the data subject or of another person, where the data subject is physically incapable of giving consent or whose consent is not legally valid; it being directly related to the establishment or performance of a contract; it being mandatory for the data controller to fulfil its legal obligations; the data having been made public by the data subject themselves; it being mandatory for the establishment, exercise or protection of a right; and it being mandatory for the legitimate interests of the data controller, provided this does not harm the fundamental rights and freedoms of the data subject.

Within the scope of its activities, Dr. Ömer Fatih Şahin does not, as a rule, process special categories of personal data unless the explicit consent of the data owner has been obtained. Special categories of personal data other than those relating to health and sexual life may only be processed without the explicit consent of the data subject where expressly provided for by law. Personal data relating to health and sexual life, however, may be processed by persons bound by an obligation of confidentiality (our physicians and other healthcare personnel), without seeking the explicit consent of the data subject, solely for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of healthcare services and their financing; in all other circumstances, such data may only be processed with the explicit consent of the data subject.

3. Categories of Data Subjects and Personal Data

Within the scope of its activities, Dr. Ömer Fatih Şahin processes the personal data of the following groups of persons, falling within the categories specified below:

Patient/Customer: Identity, Contact, Financial, Legal Transaction, Health, Genetic or Sexual Life Data, Visual and Audio Records, Other. Job Applicant, Employee, Former Employee, Intern: Identity, Contact, Financial, Employment Information, Personnel and Professional Information, Legal Transaction, Special Category Personal Data (Health and Criminal Conviction), Fringe Benefits and Interests, Family Members and Relatives’ Information, Visual and Audio Records, Other. Employee’s Relative: Identity, Contact, Financial, Personnel and Professional Information. Business Partner: Identity, Contact, Legal Transaction. Supplier and Customer Company Employee: Identity, Contact. Supplier and Customer Company Authorised Signatory: Identity, Contact, Legal Transaction. Reference: Identity, Contact, Personnel (and/or Professional Experience). Visitor: Identity, Transaction Security, Physical Space Security. Website Visitor: Transaction Security.

4. Purposes of Processing Personal Data

Personal data is used by Dr. Ömer Fatih Şahin for the following purposes:

▪ Carrying out activities in compliance with legislation, follow-up and execution of legal affairs, providing information to authorised persons, institutions and organisations, carrying out storage and archiving activities

▪ Protecting public health, preventive medicine, carrying out medical diagnosis, treatment and care services, planning and managing healthcare services and their financing

▪ Following up requests/complaints, carrying out communication activities, carrying out promotional activities, carrying out customer relationship management processes

▪ Managing access authorisations, carrying out risk management processes, carrying out information security processes, ensuring the security of data controller operations

▪ Carrying out emergency management processes, ensuring physical space security, ensuring the security of movable property and resources

▪ Carrying out assignment processes, carrying out audit/ethics activities, carrying out internal audit/investigation/intelligence activities, carrying out activities for ensuring business continuity

▪ Carrying out management activities, carrying out strategic planning activities, carrying out contract processes

▪ Organisation and event management, carrying out social responsibility and civil society activities

▪ Carrying out training activities, carrying out/supervising business activities, carrying out job applicant/intern/student selection and placement processes, carrying out employee satisfaction and loyalty processes, fulfilling obligations arising from employment contracts and legislation for employees, carrying out fringe benefits and interests processes for employees, planning human resources processes, carrying out occupational health/safety activities, carrying out performance evaluation processes, work and residence permit procedures for foreign personnel, carrying out wage policy, carrying out talent/career development activities

▪ Receiving and evaluating suggestions for improving business processes, carrying out goods/service procurement processes, carrying out goods/service production and operation processes

▪ Carrying out finance and accounting affairs, carrying out supply chain management processes, carrying out logistics activities

▪ Creating and following up visitor records

5. Transfer of Personal Data and Purposes of Transfer

Within the scope of the activities carried out by Dr. Ömer Fatih Şahin, your personal data must be shared with third parties other than Dr. Ömer Fatih Şahin, for the purposes stated above and limited to the fulfilment of those purposes. In all such transfer processes, Dr. Ömer Fatih Şahin acts in accordance with Articles 8 and 9 of the Law, implements the necessary technical and administrative measures, observes the principles of need-to-know and need-to-use, and adheres to the principle of data minimisation. In addition, personal data transferred is also legally protected through additional protocols signed with the third parties to whom the transfer is made.

Within this scope, personal data transfers are carried out as set out in the table below:

Data Subject / Purpose of Transfer and Recipient

Customer

Employee, Former Employee, Intern

Employee’s Relative

Business Partner, Supplier and Customer Company’s Authorised Signatory

Visitor, Website Visitor

6. Technical and Administrative Measures Taken to Ensure the Security of Personal Data

Dr. Ömer Fatih Şahin exercises the necessary diligence and takes the necessary technical and administrative measures to ensure the confidentiality, integrity and security of your personal data. In this context, the following measures are taken to prevent the unlawful processing of personal data, unauthorised access to personal data, and the disclosure, alteration or destruction of data.

Anti-Virus: All computers and servers within our information technology infrastructure have anti-virus software installed that is updated periodically.

Firewall: The Data Centre hosting our servers is protected by a periodically updated firewall. Next-generation firewalls monitor the internet connections of all personnel and provide protection against viruses and similar threats during this monitoring.

User Identification and Authorisation Matrix: The authorisations of Dr. Ömer Fatih Şahin’s employees within our systems are limited only to the extent required by their job descriptions, and in the event of any change in authorisation or duties, access rights are immediately terminated or amended in line with the new role.

Information Security Threat and Incident Management: Any breaches or identified risks occurring on our servers and firewalls are immediately reported to the person responsible for information technology. This person responds promptly to any security threat and ensures the security of personal data.

Penetration Testing: Penetration testing is periodically carried out manually on the servers and computers within our system by a contracted external firm. Any vulnerabilities identified as a result of this testing are closed, and verification testing is carried out to confirm that the relevant vulnerabilities have been resolved.

Employee Training and Awareness-Raising: In order to raise the awareness of Dr. Ömer Fatih Şahin’s employees against various information security breaches and to minimise the impact of the human factor in information breach incidents, employees are regularly reminded of and trained on information security matters. Users are given further reminders and warnings where necessary.

Clean Desk Policy: In accordance with our internal rules, employees are required to comply with a clean desk policy.

Physical Security: We ensure that personal data in paper form is kept in locked cabinets and is accessible only to authorised persons.

Cookies: Personal data processed through cookies belonging to third parties from whom services are received is deleted from the third parties’ systems once the relevant relationship ends.

Breach Notification: Notwithstanding that Dr. Ömer Fatih Şahin takes the necessary technical and administrative information security measures, in the event that personal data is damaged or falls into the hands of unauthorised third parties as a result of attacks on the online platforms or systems operated by Dr. Ömer Fatih Şahin, Dr. Ömer Fatih Şahin will immediately notify you and the Personal Data Protection Board of the situation and take the necessary measures to minimise the consequences of the breach.

7. Retention Periods and Destruction Conditions for Personal Data

Dr. Ömer Fatih Şahin retains the personal data it processes, in compliance with the Law, for the periods stipulated by the relevant legislation or required by the purpose of processing. These periods are set out in the table below:

Personal Data / Retention Period

Dr. Ömer Fatih Şahin retains the personal data it collects and processes through physical, electronic, website, e-mail and other channels within the scope of its business processes, pursuant to Articles 7 and 17 of the Law and Article 138 of the Turkish Criminal Code, for the periods stipulated by the relevant laws or secondary legislation and/or required by the purpose of processing. Upon the expiry of these periods, such data is deleted, destroyed or anonymised in accordance with the provisions of the Regulation on the Deletion, Destruction or Anonymisation of Personal Data and the Guide on the Deletion, Destruction or Anonymisation of Personal Data. Dr. Ömer Fatih Şahin has determined a periodic destruction period of 6 months.

For Dr. Ömer Fatih Şahin, deletion of personal data means rendering the personal data inaccessible and unusable in any way whatsoever by the relevant users; destruction of personal data means rendering the personal data inaccessible, unrecoverable and unusable in any way whatsoever by anyone. Anonymisation of personal data means rendering such data incapable, under any circumstances, of being associated with an identified or identifiable natural person, even when matched with other data.

In its Personal Data Retention and Destruction Policy, prepared pursuant to the Regulation on the Deletion, Destruction or Anonymisation of Personal Data, Dr. Ömer Fatih Şahin explains in detail the methods of deletion, destruction and anonymisation and the technical and administrative measures it has taken in this regard.

8. Rights of Data Subjects and the Exercise of These Rights

Pursuant to Article 11 of the Law, data subjects have the following rights:

▪ To learn whether their personal data is being processed,

▪ To request information regarding such processing, if their personal data has been processed,

▪ To learn the purpose of processing of their personal data and whether the data is used in accordance with its intended purpose,

▪ To know the third parties, domestic or abroad, to whom their personal data is transferred,

▪ To request the correction of their personal data in the event it has been processed incompletely or incorrectly,

▪ To request the deletion or destruction of their personal data,

▪ To request that the correction, deletion or destruction of their personal data be notified to third parties to whom the personal data has been transferred,

▪ To object to the emergence of a result against themselves through the analysis of processed data exclusively by automated systems,

▪ To request compensation for damages in the event of loss due to the unlawful processing of their personal data.

In order to exercise your rights over your personal data, you may complete the “Application Form” accessible at https://www.omerfatihsahin.com.tr/kvkk and;

▪ Deliver it in person to the address: Harbiye Mahallesi, Abdi İpekçi Cad, No:39, Hayal Apartmanı, Kat:4 Daire:5 34367 Şişli / İstanbul,

▪ Send it, wet-signed, to the address specified above through a notary,

▪ Submit it to [email protected] via secure electronic or mobile signature, through a registered electronic mail (KEP) address, or via your e-mail address registered in our system.