This text has been prepared for the purpose of clarification regarding the processing of personal data by the data controller within the scope of the Personal Data Protection Law No. 6698.

Our purpose is to ensure that your personal data are legally collected, stored, shared with public institutions and organizations stipulated by the law, and to take the highest level of security measures possible to protect your confidentiality.

Pursuant to Article 10 of the Personal Data Protection Law No. 6698 and in line with your satisfaction, our aim is to inform you in the most transparent way about the collection of your personal data, the purposes of processing them, with whom these are shared, legal reasons and your rights.

Data Controller

Pursuant to Personal Data Protection Law No. 6698, your personal data will be collected and may be processed by EBR SAĞLIK HİZMETLERİ TİC.LTD.ŞTİ. as data controlled within the scope described below.



a) Methods and Legal Reasons for Obtaining Personal Data

Your personal data is collected electronically or physically. Your personal data collected for the legal reasons specified in the Law may be processed and shared within the framework of the personal data processing conditions specified in Articles 5 and 6 of the Law.

Personal data may be collected by the data controller from our customers, employees, potential customer candidates, employee candidates, business partners and suppliers, etc. in categories such as identity details, contact details, customer information, customer transaction information, transaction security information, legal transaction and compliance information and marketing and sales information.

b) Purposes of Processing Personal Data

The personal data we collect within the scope of the services we provide to you are processes for various purposes and information stated below:

Your personal data is processed in order to fulfill our legal obligations set forth in Health Services Fundamental Law no. 3359, Decree Law no. 663 on Organization and Duties of the Ministry of Health and Affiliated Organizations, Regulation on Processing of Personal Health Data and Ensuring Privacy and other relevant regulations, to protect public health, to conduct protective medicine, medical diagnosis, treatment and maintenance services, to plan and manage healthcare services and financing, to plan and execute the activities required to customize the products and services offered by the data controller according to the likes, usage habits and needs of the relevant persons within the framework of the personal data processing conditions set out in articles 5 and 6 of the Law and to recommend and promote these to the relevant persons, to allow the relevant work departments to carry out works and conduct relevant business processes in order to ensure that relevant persons benefit from the products and services offered and that the commercial activities are conducted to carry out the relevant business processes, to plan and execute commercial and/or business strategies and to ensure the legal, technical and commercial-business safety of the relevant persons with a business relation.

In case the subjects are defined separately:

  • To determine and verify your identity in order to prevent your Personal Data from being acquired by others,
  • To perform public health protection, preventive medicine, medical diagnosis, treatment and care services, to plan and manage health services and financing,
  • To supply medicines and/or medical equipment and/or devices specific to you,
  • To be able to inform you about an appointment, provide information and/or remind you of an appointment
  • To perform risk management and quality improvement activities,
  • To fulfill legal and regulatory requirements,
  • To share and respond to the information obtained with the Ministry of Health and other public institutions and organizations in accordance with the legislation,
  • To question your entitlement with the institutions/organizations that are contracted with the hospital or to provide financial reconciliation with these institutions regarding the health services offered to you,
  • To share information and authentication requested by contracted institutions/organizations, especially private insurance companies, within the scope of financing health services,
  • To issue invoices for the services we provide,
  • To take all necessary technical and administrative measures within the scope of data security of hospital systems and applications,
  • To analyze your use of health services and store your health data, to respond to your questions or complaints about our services in order to develop and improve the health services we provide to you,
  • To provide the necessary information in accordance with the demands and audits of regulatory and supervisory agencies and official authorities,
  • To store information about your health-related data that should be kept in accordance with the relevant legislation,
  • To comply with internal policies and principles,
  • To measure and improve your patient satisfaction after receiving health services,
  • To conduct special promotional and information activities for you and to ensure your benefit, to contact with you for providing information about our services,
  • To execute and develop medical diagnosis, treatment and maintenance services, to plan and manage health services and financing, to increase and investigate patient satisfaction and relevant causes without limitation to the abovementioned.

Your Personal Data obtained and processed in accordance with the relevant legislation can be transferred to EBR SAĞLIK HİZMETLERİ TİC.LTD.ŞTİ. information systems and stored under protection both in digital and physical information.

c) Parties to whom Personal Data may be Shared and Purposes of Sharing

Your personal data may be shared with the Company’s business partners and suppliers, legally authorized institutions and organizations, legally authorized natural and legal persons within the scope of the personal data processing conditions and purposes set out in articles 8 and 9 of the Law in order to plan and execute the activities required to customize the products and services offered by the data controller according to the likes, usage habits and needs of the relevant persons and to recommend and promote these to the relevant persons, to allow the relevant work departments to carry out works and conduct relevant business processes in order to ensure that relevant persons benefit from the products and services offered and that the commercial activities are conducted to carry out the relevant business processes, to plan and execute commercial and/or business strategies and to ensure the legal, technical and commercial-business safety of the relevant persons with a business relation with the Company.

d) Rights of Data Owners and Exercise of These Rights

As personal data owners, in the event you submit your requests regarding your rights specified below to the Company by the methods specified under the title of Exercise of Rights by Data Owners, your requests will be evaluated and concluded by our Company as soon as possible and in any case within 30 (thirty) days.

In accordance with Article 11 of the Law, you have the following rights as personal data owner:

  • To learn whether your personal data have been processed or not,
  • To request information regarding the personal data if they are processed,
  • To learn the purpose of your data processing and whether this data is used for intended purposes,
  • To know the third parties to whom your personal data are transferred in country or abroad,
  • To request correction of personal data if it is incomplete or improperly processed, and to request notification of third parties to whom personal data of processed about the procedure performed within this scope,
  • To request deletion or destruction of personal data in case the reasons necessitating their processing cease to exist, despite personal data has been processed in accordance with Law and relevant other law provisions, and to request notification of the operations made within this context to third parties to whom your personal data has been transferred,
  • To object to the emergence of a result to the detriment of the person himself/herself by analyzing your processed data exclusively via automated systems,
  • To request compensation if you suffer damage due to unlawful processing of your personal data.
  • 2nd clause of article 28 of the Law lists the conditions where the data owners do not have the right to claim, and within this scope, the aforementioned rights shall not be exercised for the data if;
  • Processing of personal data is necessary for the prevention of crime or criminal investigation,
  • Processing personal data publicized by the person concerned,
  • Processing of personal data is necessary for the execution of supervisory or regulatory duties and disciplinary investigation or prosecution by the public institutions and organizations and professional organizations in the nature of public institutions, which are authorized by law,
  • Processing of personal data is necessary for protection of economic and financial benefits of the State regarding budget, tax and financial issues.
  • Since the data will be outside the scope of the Law in the following cases pursuant to paragraph 1 of Article 28 of the Law, the requests of the data owners will not be processed in terms of this data:
  • Processing the personal data for the purposes of investigation, planning and statistics by anonymizing with official statistics.
  • Processing the personal data by judicial or enforcement authorities in relation to the investigation, proceedings, litigation or execution procedures.

Exercise of Rights by Data Owners

In order to use the abovementioned rights,
the data owners can make an application by one of the following methods with the documents to authenticate the identity of the relevant data owner:

A petition shall be filled and its originally signed copy shall be sent to the address EBR SAĞLIK HİZMETLERİ TİC.LTD.ŞTİ. MERKEZ MH HASAT SK KAMARA 52/1 ŞİŞLİ – ISTANBUL TÜRKİYE by hand, via notary or by registered letter with return receipt,

The form shall be signed by secure electronic signature set out within the scope of Electronic Signature Law no. 5070 and sent to the address ebru.coskun.3@hs01.kep.tr by registered electronic mail,

  • Following a method envisaged by the Personal Data Protection Board.
  • The Company shall respond to the data owners who wish to exercise the said rights within the limits stipulated in the Law within a maximum of thirty (30) days as stipulated in the Law. In order for third parties to request an application in the name of personal data owners, a special power of attorney, issued by a notary public in the name of the person applying for the data owner and granted by the same, shall be submitted.
  • Although data owner applications are processed free of charge as a rule, fees can be charged based on the fee tariff stipulated by the Personal Data Protection Board.
  • The Company may request information from the relevant person in order to determine whether the applicant is the owner of personal data, and may ask questions to the personal data owner in order to clarify the issues specified in the application.

Legal Reasons Requiring Storage

Personal data processed within the framework of the commercial activities shall be stored for the period stipulated in the relevant legislation. Within this scope, personal data shall be stored for the durations prescribed within the framework of;

· Personal Data Protection Law No. 6698,

· Turkish Code of Obligations no. 6098,

· Public Servants Law no. 657,

· Social Security and General Health Insurance Law no. 5510,

· Regulating Broadcasting in the Internet and Fighting Against Crimes Committed through Internet Broadcasting Law no. 5651,

· Public Financial Management Law no. 5018,

· Occupational Health and Safety Law No. 6331,

· Right to Information Law no. 4982,

· Exercising the Right to Petition Law no. 3071,

· Labor Law no. 4857,

· Regulation on Health and Safety Measures to be Taken in Workplace Buildings and Annexes,

· Other secondary regulations in force pursuant to these laws.

Reasons Requiring Destruction

Personal data shall be deleted, destructed or ex officio deleted, destructed or anonymized by the Institution upon the request of the relevant person in following cases:

· Amendment or abolition of the relevant legislation provisions that form the basis of processing

· Absence of the purpose that requires processing or storage,

· In cases where the processing of personal data takes place only in accordance with the explicit consent condition, withdrawal of the relevant person’s consent,

· The Authority accepting the application made by the relevant person regarding the deletion and destruction of personal data within the framework of their rights pursuant to article 11 of the Law,

· In the event that the request made by the relevant person for deletion, destruction or anonymization of the personal data is rejected, the response is found insufficient or no response is given within the duration prescribed in the law, the relevant person submitting a complaint to the Board and the Board approving this request,

· In the event that the minimum duration required to store the personal data is expired and there are no conditions to justify further storage of personal data.