General Data Protection Regulation

Last Updated: [07.09.2024]

At Cevre Hospital, we take your privacy seriously. This policy outlines how we collect, use, store, and protect your personal data in compliance with the General Data Protection Regulation (GDPR).

1. Data Controller

The Data Controller responsible for the processing of your personal data is:

2. Personal Data We Collect

We may collect the following types of personal data:

  • Identity Data: Name, surname, date of birth, passport number, etc.
  • Contact Data: Email address, phone number, home address, etc.
  • Health Data: Medical history, treatments, prescriptions, etc.
  • Financial Data: Payment details, credit card information, etc.
  • Technical Data: IP address, browser type, time zone settings, and other technology on devices used to access the website.

3. How We Collect Your Data

We collect your data when you:

  • Fill out contact or appointment forms.
  • Sign up for newsletters or other communications.
  • Communicate with us via email, phone, or other means.
  • Visit our website, through cookies or tracking technologies.

4. Purpose of Data Processing

We collect and process your personal data for the following purposes:

  • To provide medical consultations, treatments, and related services.
  • To arrange medical travel, accommodation, and transfer services.
  • To handle payment transactions and invoicing.
  • To comply with legal obligations, such as reporting requirements.
  • For marketing purposes, including newsletters and promotional offers (with your consent).
  • To improve our website and services through analytics and customer feedback.

5. Legal Basis for Data Processing

We process your data based on the following legal grounds:

  • Consent: For marketing communications and medical data, we obtain explicit consent.
  • Contract: Processing is necessary to fulfill our contractual obligations to provide health tourism services.
  • Legal Obligations: For compliance with Turkish healthcare regulations and GDPR.
  • Legitimate Interest: For fraud prevention, website security, and improving our services.

6. Sharing of Data

Your personal data may be shared with:

  • Medical professionals and healthcare providers involved in your treatment.
  • Travel agencies, accommodation providers, and transportation companies.
  • Government authorities, where required by law.
  • Third-party service providers (e.g., IT, payment processing) for operational purposes.

We ensure that all third parties are GDPR-compliant and handle your data securely.

7. International Data Transfers

If your data is transferred outside of the European Economic Area (EEA), we ensure that appropriate safeguards are in place, such as:

  • Standard contractual clauses (SCCs).
  • Binding corporate rules.
  • Adequate levels of protection under international agreements.

8. Data Retention

We will retain your personal data for as long as necessary to fulfill the purposes outlined in this policy. Medical records will be retained as required by Turkish healthcare regulations. Other personal data will be retained until it is no longer needed for the purpose for which it was collected or until you request its deletion.

9. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You can ask us to correct any inaccurate or incomplete data.
  • Right to Erasure: You can request the deletion of your personal data, subject to legal and regulatory requirements.
  • Right to Restrict Processing: You can request the restriction of your personal data processing.
  • Right to Data Portability: You can request to receive your personal data in a machine-readable format.
  • Right to Object: You can object to the processing of your data for certain purposes, such as direct marketing.
  • Right to Withdraw Consent: You can withdraw your consent to data processing at any time.

To exercise any of these rights, please contact us at [Insert Contact Information].

10. Security Measures

We take appropriate technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction. These measures include:

  • Secure server hosting.
  • Encryption of sensitive data.
  • Regular security audits and staff training.

11. Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience on our website. You can control your cookie preferences through your browser settings.

For more information, please refer to our Cookie Policy.

12. Changes to This Policy

We may update this privacy policy periodically. We will notify you of any changes by updating the “Last Updated” date at the top of this policy.

13. Contact Us

If you have any questions or concerns regarding this privacy policy or your personal data, please contact us at:

Last update: 22 Oct 2024

ATTENTION!
The content of the page is for informational purposes only, please consult your doctor for diagnosis and treatment.
X
By visiting our website, you agree to our Cookie Policy.