Personal Data Protection and Processing Policy
CONTENTS
1. INTRODUCTION
2. PURPOSE
3. SCOPE
4. DEFINITIONS
5. PROSECUTION OF THE POLICY AND RELEVANT LEGISLATION
6. PERSONAL DATA PROCESSING PRINCIPLES
7. CLARIFICATION TEXT FOR THE PROCESSING OF PERSONAL DATA
8. CLARIFICATION TEXT FOR THE PROCESSING OF SENSITIVE PERSONAL DATA
9. ENSURING THE SECURITY OF PERSONAL DATA
10. TRANSFER OF PERSONAL DATA
11. TRANSMISSION OF PERSONAL DATA
12. TERMS OF DELETING, DESTRUCTION AND ANONYMIZATION OF PERSONAL DATA
13. CLARIFYING AND INFORMING THE PERSONAL DATA OWNER
14. RIGHTS OF THE DATA OWNER; REQUESTING INFORMATION, COMMUNICATION CHANNELS AND DATA OWNERS 'REQUESTS
15. BUILDING, BUILDING ENTRANCES AND PERSONAL DATA PROCESSING ACTIVITIES IN THE BUILDING FOUNDATION AND INTERNET SITE VISITORS
16. EFFECTIVENESS
1. INTRODUCTION
Private Gebze Doğa Hospital Health Services Incorporated Company (Briefly referred to as "Private Center Prime Hospital" and / or "Hospital".) Within the framework of superior service quality determined by our Hospital, respect for the rights of individuals, transparency and honesty, in line with the new regulations stipulated by The Law On The Protection Of Personal Data (Briefly referred to as "Law"), the internal functioning of our hospital; Law, Secondary Regulations (Regulation, Circular, Declaration etc.) It is among our priorities that the Personal Data Protection Board Decisions-Regulations and its regulation within the scope of the relevant legislation. Our Hospital pays attention to the security of personal data, and attaches great importance to patient privacy and to the protection of all personal data of our patients in the best possible way and with care. Besides our patients, companions, visitors and employees of institutions and organizations we cooperate with; This policy has been regulated and put into effect in order to protect and process personal data within the framework of the "Law on the Protection of Personal Data No.6698", "Regulation on the Processing of Personal Health Data and Ensuring Privacy" and the basic principles of the relevant legislation.
2. PURPOSE
The main purpose of this Policy is to make statements about the personal data processing activities carried out by Private Central Health Group in accordance with the legislation and about the protection of personal data, within this framework , our patients, companions, visitors, employees and institution officials, employees, officials of the institutions we cooperate with, to ensure transparency by informing the persons whose personal data are processed by our Hospital, especially third parties. Although personal data processed by Private Central Health Group may vary depending on the health services provided, they are stored by physical and / or digital methods. Our patient representatives, physicians, healthcare professionals, etc. Special quality personal data and general quality personal data, primarily health data collected orally, in writing or digitally through our employees, subcontractors and employees and companies engaged in all kinds of commercial activities, our call center, our Hospital's website, online services and similar means , is processed for the following purposes and within the scope of other needs that may arise in the future, including but not limited to:
- Conducting medical diagnosis, treatment and care services,
- Protection of public health,
- Planning and management of preventive medicine health services and financing,
- Informing our patients about the appointment
- Planning and managing our Hospital's internal procedures,
- Making analysis in order to improve the performance of health services in accordance with the legislation,
- To train and develop our employees, to protect the personal processes and legal rights of our employees, to monitor and prevent abuse and unauthorized transactions,
- Carrying out risk management and quality improvement activities,
- Performing research
- Perform the task of legal and regulatory requirements,
- Billing for our services,
- Confirming your identity,
- Notice of newborn,
- Conforming your relationship with organizations contracted with our Hospital,
- Sharing all kinds of information requested by private insurance companies within the scope of financing health services,
- Responding to all your questions and complaints regarding our health services,
- H) Taking all necessary technical and administrative measures within the scope of data security of the systems and applications in our Hospital,
- Analyzing your use of health services and storing your health data in order to improve and improve the health services we offer you,
- Preserving the information about your health data that should be kept in accordance with the relevant legislation,
- Ensuring a financial agreement with the institutions we have contracted with, banks and all institutions (public and private) for which health expenditures are collected, regarding the health services provided to you,
- Sharing the requested information with the Ministry of Health and relevant public institutions and organizations in accordance with the relevant legislation,
- Measuring patient satisfaction, increasing patient satisfaction,
- Fulfilling the contracts and legal obligations of our Hospital as required,
Personal data is stored and processed in any verbal, written or digital environment in order to fulfill the purposes stated above.
3. SCOPE
This Policy; includes the personal data defined below, processed in physical and / or digital environment of our patients, attendants, visitors, institution officials, employees, persons, institutions and organizations with whom we cooperate and have all kinds of legal relations, employees, officials and third parties.
PERSONAL DATA CATEGORIZATION:
Identification Details
All information about the identity of the person in documents such as driver's license, identity card, passport, lawyer identity, marriage certificate.
Communication Details
Information for contacting the data owner such as phone number, address, residence, e-mail
Location Data
Data that is clear to belong to an identified or identifiable real person and is included in the data recording system to determine the location of the data subject.
Family Members and Relative Information
Data that is clear to belong to an identified or identifiable real person and is included in the data recording system to determine the location of the data subject.
Physical Place
Personal data regarding records and documents such as camera records, fingerprint records taken during the entrance to the physical place, during the stay in the physical place
Information About The Process Security:
Your personal data processed to ensure our technical, administrative, legal and commercial security while conducting our activities.
Financial Information
Personal data processed in relation to information, documents and records showing all kinds of financial results created according to the type of legal relationship our hospital has established with the personal data owner.
Employee Candidate Information
Personal data processed about individuals who have applied to be an employee of our Hospital or who have been evaluated as employee candidates in line with the human resources needs of our Hospital or who are in a working relationship with our Hospital in accordance with commercial practices and honesty rules.
Personnel Information
Information about Payroll Information, disciplinary proceeding , statement of employment-exit document records, asset declaration information, background information, performance evaluation reports.
Performance ve Career Development Information
Information such as Performance Evaluation interviews, results, reports, tests
Fringe Benefits
Fringe Benefits Based Information
Legal Transaction
Personal data processed within the scope of the determination, follow-up of our legal receivables and rights and the execution of our debts and compliance with our legal obligations and Hospital policies
Professional Experience
Personal data regarding the content of the Employment Contract, employment start information / date, termination information / date,
Sensitive Personal Data
Individuals' race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, costume and dress, association, foundation or union membership, health, sexual life, criminal conviction and data of security measures, and biometric and genetic datas are called sensitive personal data
Marketing Information
Data to be used in marketing activities by the Hospital, clearly belonging to an identified or identifiable real person and included in the data recording system
Incident Management Information
Personal data processed in order to take necessary legal, technical and administrative measures against events that develop in order to protect the commercial rights and interests of our Hospital and the rights and interests of the people receiving service.
Audio Visual Data
Visual and audio records that are clearly owned by an identified or identifiable real person and are included in the data recording system and associated with the personal data owner.
According to the groups of personal data owners, the scope of application of this policy may be the entire policy (such as our patients); There may be only some provisions (For example, only our employees, suppliers, etc.).
Personal data can also be processed when the call center or website is used to benefit from the online services of our Hospital, in the intranet, training, participating in the events organized by the Hospital or visiting the websites.
4. DEFINITIONS
Express Assent: Consent on a specific subject, based on information and expressed with free will.
Anonymization: It is the change of personal data in a way that loses the quality of personal data and this situation cannot be recovered. For example, by masking, aggregation, data destruction, etc. techniques, making personal data unrelated to a real person It is possible to anonymize personal data for various purposes only in accordance with the request and / or consent of the person concerned in a way that does not violate the scope of the Law on the Protection of Personal Data. Necessary precautions will be taken within our Hospital to prevent the anonymized personal data from making the person identifiable by various methods.
Employees, Shareholders and Authorities of Institutions We Cooperate with: It refers to the real people working in the institutions with which our Hospital has all kinds of business relations (such as business partners, suppliers, but not limited to these), including the shareholders and officials of these institutions.
Recording of Personal Data: It refers to all kinds of operations performed on data such as obtaining, recording, storing, preserving, changing, reorganizing,blocking, disclosing, transferring, taking over, making available, classifying or using personal data through fully or partially automatic means or non-automatic means provided that they are part of any data recording system.
Relevant Person: Refers to the real person whose personal data is processed. The processing and protection of personal data and personal data of our Hospital's real and / or legal entity business partners, shareholders, managers or employees, guests, employees will be handled by our Hospital within the scope of the Law on the Protection of Personal Data and Policy.
Personal Data: It refers to all kinds of information regarding an identified or identifiable real person. All information that makes the person identifiable is organized as personal data, and information such as TR Identity Number, Name Surname, e-mail address, phone number, residence address, date of birth, bank account number can be given as examples of personal data.
In our Hospital, these data have been classified and the data inventory has been arranged in terms of how, by whom, for what purpose and for how long each category of data will be processed.
Patient: It refers to the person who applies to our Hospital for examination and treatment and receives outpatient or inpatient treatment.
Sensitive Personal Data: Individuals' race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, costume and dress, association, foundation or union membership, health, sexual life, criminal conviction and data of security measures, and biometric and genetic data are called sensitive personal date.
Third Person: It refers to third party natural persons who are associated with these persons in order to ensure the security of commercial transactions between our Hospital and the parties mentioned above or to protect the rights of the aforementioned persons and to obtain benefits. (For example, company employees or officials, Companion etc.)
Data Entered by: It refers to the real and legal person who processes personal data on behalf of the data controller based on the authority given by her/him. For example, the IT firm that keeps the data of our Hospital.
Data Controller: It refers to the person who determines the purposes and means of processing personal data and manages the place where the data is kept systematically (data recording system).
Within the scope of the Law on the Protection of Personal Data, our Hospital will have the title of data controller and will be registered in the data information system. A team of 11 people (Personal Data Supervisor Team) has been established in our hospital to carry out the operations to be carried out as a data controller during registration, and this team will be responsible for the follow-up and coordination of all work and transactions within the scope of the Law on the Protection of Personal Data and Data Protection Board regulations. In cases that require a decision to be taken, the in-hospital Personal Data Supervisor team will present its decision as a recommendation to the management after taking the opinion of the Legal Consultancy Department, and the decision taken following the approval of the management will be implemented.
Visitor: Refers to real persons who have entered the physical areas owned by our Hospital for various purposes or visited our websites.
5. PROSECUTION OF THE POLICY AND RELEVANT LEGISLATION
The processing and protection of personal data are carried out within the framework of the relevant legal regulations in force. Private Central Health Group Personal Data Protection Policy has been prepared in accordance with current regulations.
The policy has been created by integrating the Private Center Prime Hospital practices within the framework of the rules laid down by the relevant legislation. It carries out the necessary preparations by adhering to the effective periods stipulated in the Law on the Protection of Personal Data. Under the scope heading above, when the personal data specified in Article 3 are required, the Health Services Fundamental Law No.3359, Decree Law No.663 on the Organization and Duties of the Ministry of Health and its Affiliates, Private Hospitals Regulation, Regulation of the Processing of Personal Health Data and Protection of Privacy and Ministry of Health regulations, etc. can be processed within the framework of the provisions of the legislation, and transferred to the physical archives and information systems of our hospitals and / or suppliers. As a result, personal data will be protected in both digital and physical environments in accordance with the legal periods defined in institution procedures.
6. PERSONAL DATA PROCESSING PRINCIPLES
General Principles of Processing Personal Data: The Hospital accepts that personal data within the scope of this policy will be processed in accordance with the following principles in Article 4 of the Law on the Protection of Personal Data:
Compliance with Law and Good Faith Rules: As a prudent merchant in the capacity of data controller, the hospital accepts that it will carry out personal data processing activities in accordance with the provisions of all legislation that will come into force, especially the Constitution and the Law on the Protection of Personal Data , and in accordance with the honesty rule stipulated in Article 2 of the Turkish Civil Code.
Accuracy and Currency The Hospital takes all necessary measures to ensure the accuracy and currency of personal data to the extent permitted by the technique in the processing of personal data. The requests to be notified by the relevant person to the Hospital in the capacity of data controller, in case the Hospital deems necessary, administrative and technical mechanisms established by the Hospital will be operated in order to correct and control the accuracy of erroneous or outdated personal data.
To process for specific, clear and legitimate purposes: Personal data are processed in accordance with the law, limited to the services offered or to be provided by the Hospital in accordance with the requirements of the relevant legislation provisions, and the purpose of processing personal data is clearly and precisely determined before the data is processed.
Processing in relation to the purpose, limited and measured: Personal data are processed by the Hospital in connection with and limited to the purposes of processing and to the extent necessary for the realization of this purpose. In this scope, it is essential to avoid processing personal data that are not related to the purpose of processing the data and are not needed.
To process within the period stipulated by the legislation provisions or required by the purpose of processing: Personal data are kept in line with the periods stipulated by the relevant legislation provisions and / or for the period required by the purpose of processing the data. Personal data are deleted, destroyed or anonymized by the Hospital at the end of the period stipulated by the legislation provisions or at the end of the period required by the purpose of processing. Necessary administrative and technical measures will be taken to prevent data from being stored at the end of the required period.
7. CLARIFICATION TEXT FOR THE PROCESSING OF PERSONAL DATA
Protection of personal data is a Constitutional right. In accordance with the third paragraph of anecdote 20 of the Constitution, personal data can only be processed in cases stipulated by the law or with the express consent of the person. Our hospital processes personal data in this direction and in accordance with the Constitution, only in cases stipulated by the law or with the express consent of the person.
Although the legal bases for the processing of personal data by our hospital differ, we act in accordance with the general principles specified in the 4th article of the Law on the Protection of Personal Data numbered 6698 in all kinds of personal data processing activities.
The express consent of the personal data owner is only one of the legal bases that allow the processing of personal data in accordance with the law. Apart from express consent, personal data can also be processed in the presence of one of the other conditions listed below. The basis of the personal data processing activity can be only one of the conditions stated below, and more than one of these conditions can also be the basis of the same personal data processing activity. The following conditions are applied in case the processed data is sensitive personal data.
Obtaining the Express Consent of the Personal Data Owner: The main rule in the processing of personal data is the express consent of the person concerned to the processing of her/his data. The hospital will carry out data processing activities for the transactions covered by the consent, in line with the explicit consent of the relevant person upon informing the person about the purpose to be processed in a clear manner that will not leave any hesitation, as stipulated by the Law on the Protection of Personal Data.
Clearly Stipulated in Laws: In cases where it is necessary to process personal data in accordance with the provisions of the legislation, even without the express consent of the relevant persons as per the Law on the Protection of Personal Data , data processing activities will be deemed legal, provided that other necessary criteria are met.
Failure to Obtain Express Consent of the Relevant Person Due to Actual Impossibility: In accordance with the Law on the Protection of Personal Data , it is possible to process personal data in cases where it is not possible for the person concerned to disclose his / her consent de facto or if his / her consent is not legally valid, if it is necessary to process personal data for the protection of the person's life or body integrity. The hospital will process personal data in the foreseen cases in accordance with this regulation.
Being Directly Related to the Establishment or Performance of the Contract: Provided that it is directly related to the establishment and execution of the contract, the personal data of the parties to the contract will be processed by the Hospital.
Perform Institution's Legal Obligations: Personal data will be processed by the Hospital in accordance with the limits of the said obligation in order for the Hospital, which has the title of Data Supervisor in accordance with the Law, to fulfill its obligations arising from the provisions of the legislation.
Making Personal Data Public by Personal Data Owner: In the event that the person concerned makes her/his personal data public, personal data in point will be processed by the Hospital in proportion to the purposes of making it public.
When Data Processing Is Mandatory For The Establishment, Exercise Or Protection Of Any Right: Personal data will be processed by the Hospital to the extent necessary for the establishment, use or protection of a right.
When Data Processing is Mandatory for the Legitimate Interest of Our Hospital: Personal data may be processed in line with the legitimate interests of the Hospital, which has the title of Data Supervisor, provided that the fundamental rights and freedoms of the relevant person are not harmed. However, the statement of legitimate interests of the Hospital cannot in any way contradict the principles determined by the Law on the Protection of Personal Data , the purpose of processing personal data, and cannot interfere with the essence of the right guaranteed by the Constitution.
8. CLARIFICATION TEXT FOR THE PROCESSING OF SENSITIVE PERSONAL DATA
Our hospital acts in accordance with the regulations stipulated in the Law on the Protection of Personal Data in the processing of personal data determined as "sensitive" with the Law on the Protection of Personal Data .
In the article 6 of the the Law on the Protection of Personal Data , some personal data that have the risk of causing the victimization or discrimination of individuals when processed illegally are defined as "sensitive". These datas are Individuals' race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, costume and dress, association, foundation or union membership, health, sexual life, criminal conviction and data of security measures, and biometric and genetic datas.
By our hospital in accordance with the Law on the Protection of Personal Data; Special quality personal data are processed in the following situations, provided that adequate measures are taken by the Personal Data Protection Board:
- If the personal data owner has explicit consent or,
- If the personal data owner has no explicit consent; Special quality personal data other than the health and sexual life of the personal data owner, in cases stipulated by the law,
Sensitive personal data regarding the health and sexual life of the personal data owner, only for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, planning and managing health services and financing, is processed by persons or authorized institutions and organizations under the obligation to keep confidentiality.
9. ENSURING THE SECURITY OF PERSONAL DATA
Our hospital takes the necessary technical and administrative measures to ensure a high level of security in order to prevent unlawful processing of the personal data it processes and to ensure the preservation of the data, and in this context, it carries out or has it done.
The actions and measures taken by our hospital to ensure "data security" in accordance with Article 12 of the Law on the Protection of Personal Data are as follows:
- Our hospital takes technical and administrative measures according to technological possibilities and application costs in order to ensure that personal data are processed legally.
- Employees are informed that they cannot disclose the personal data they have learned to anyone in violation of the provisions of the the Law on the Protection of Personal Data and cannot use it for purposes other than processing, and this obligation will continue after they leave the job and in this direction, necessary commitments are taken from them.
- Our hospital takes technical and administrative measures to prevent imprudent or unauthorized disclosure, access, transfer of personal data or any other illegal access.
- Our hospital also raises awareness on the basis of data processing institutions such as business partners and suppliers, to whom personal data are transferred, to prevent illegal processing of personal data, to prevent illegal access to data, and to ensure legal storage of data.
- The obligations that our hospital has to comply with while processing personal data as the data controller and the obligation to comply with the legal, administrative and technical measures developed in this regard are contracts made to the data processing institutions with which our hospital is associated with various titles, such as suppliers and business partners, in accordance with the nature of their data processing activities.
- Our Hospital carries out the necessary inspections within it or has it done. These audit results are reported to the relevant department within the scope of the internal functioning of the Hospital and necessary actions are carried out to improve the measures taken.
- Our hospital carries out the system that ensures that personal data processed in accordance with Article 12 of the Law on the Protection of Personal Data are obtained by others illegally, and this situation is reported to the relevant personal data owner and the Personal Data Protection Board as soon as possible.
10. TRANSFER OF PERSONAL DATA
Our hospital can transfer personal data and sensitive personal data of the personal data owner to third parties (third party companies, institutions, group companies, third real persons) by taking the necessary security measures in line with the legal personal data processing purposes. Our hospital acts in accordance with the regulations stipulated in the 8th article of the Law on the Protection of Personal Data in this direction.
Your personal data, within the scope of the Law and other legislation and for the purposes stated above, can be shared with; Medical Centers, Universities, Ministry of Health, affiliated sub-units and Family Medicine centers, private insurance companies (health, retirement and life insurance, etc.) Social Security institution, General Directorate of Police and other law enforcement agencies, National Headquarters, Turkey Pharmacists Association, courts and to stay connected with this registration with all public institutions and organizations, in the country we are in cooperation for medical diagnosis or laboratory located outside the country, medicine third persons, regulator and supervisor, including the healthcare centers and third parties who provide healthcare services, the healthcare institution to which the patient is referred or to whom the patient applied, your authorized representatives, the institution you are affiliated with and / or work with, lawyers, tax consultants and auditors institutions and authorities, domestic systems at or abroad may be shared with our suppliers, support service providers and business partners whose services we benefit from or cooperate with.(for more detailed information, you can apply in writing to our hospital).
11. TRANSMISSION OF PERSONAL DATA
Private Central Health Group can transfer the personal data and sensitive personal data of the personal data owner to the contracted private and public institutions of the foreign countries, foreign health and insurance institutions, service providers that need to be shared for medical necessity by taking necessary security measures in line with personal data processing purposes. Personal data by our hospital; Personal Data Protection Board by adequate protection where it has been declared to foreign countries ( "Foreign Countries with Adequate Protection ") or in case of the absence of adequate protection of an adequate protection of responsible data in Turkey and in the relevant foreign country where a written commitment and Personal Data Protection Board are transferred to foreign countries ("Foreign Country with Adequate Protection of Data Controller"). In this direction, our hospital acts in accordance with the regulations stipulated in article 9 of the Law on the Protection of Personal Data.
12. TERMS OF DELETING, DESTRUCTION AND ANONYMIZATION OF PERSONAL DATA
Although it has been processed in accordance with the provisions of the relevant law as regulated in Article 138 of the Turkish Penal Code and Article 7 of the Law on the Protection of Personal Data, in case the reasons for processing disappear, the personal data will be deleted and made anonymous or destroyed in accordance with the relevant procedures of our Hospital or upon the request of the personal data owner.
In this context, our hospital trains and assigns relevant business units and increases their awareness in order to fulfill its obligation.
While obtaining the names and surnames of the persons who come to our hospital's buildings, or through texts posted by the Institution or made available to the guests in other ways, the personal data owners are enlightened within this scope.
Providing security by our hospital and for the purposes specified in this Policy; Internet access can be provided by our hospital to our visitors who request during their stay in our buildings and foundations. In this case, the log records regarding internet access are recorded in accordance with the Law No. 5651 and the governing provisions of the legislation regulated according to this Law; These records are only processed if requested by the authorized public institutions and organizations or to fulfill our legal obligation in the audit processes to be carried out within the Agency.
Only a limited number of Hospital staff have access to the log records obtained within this framework. Hospital staff, who have access to the aforementioned records, access these records only for use in the demand from the authorized public institutions and organizations or in audit processes and share them with legally authorized persons. A limited number of people who have access to the records declare that they will protect the confidentiality of the data they access with a confidentiality undertaking.
On the websites owned by our hospital; to ensure that visiters who visit these sites perform their visits on the sites in a suitable manner for visiting purposes; It records the internet movements within the site by technical means in order to show them customized content and to perform online promotion activities.
13. CLARIFYING AND INFORMING THE PERSONAL DATA OWNER
Personal data owners are enlightened by our hospital during the acquisition of personal data in accordance with Article 10 of the Law on the Protection of Personal Data. In this context, during the acquisition of personal data by our Hospital to personal data owners, the identity of our hospital, the purpose for which personal data will be processed, to whom and for what purpose the processed personal data can be transferred, the method of personal data collection and the legal reason, and the personal data owner is informed about the rights that he/she has under Article 11 of the the Law on the Protection of Personal Data.
It is stated in Article 20 of the Constitution that everyone has the right to receive information about their personal data. In this regard, in Article 11 of the Law on the Protection of Personal Data , "the right to request information" is included among the rights of the personal data owner. In this context, our hospital provides the necessary information in case the personal data owner requests information in accordance with Article 20 of the Constitution and Article 11 of the Law on the Protection of Personal Data.
Our hospital informs the personal data owners and those concerned about the corporate policy in the protection of personal data with various publicly available documents, and provides accountability and transparency within this framework. In addition, the relevant persons of our hospital; It also informs people about their activities and the articles in the law in different ways, especially when they apply for "express consent".
14. RIGHTS OF THE DATA OWNER; REQUESTING INFORMATION, COMMUNICATION CHANNELS AND DATA OWNERS 'REQUESTS
Our Hospital carries out the necessary channels, internal operation, administrative and technical regulations in accordance with Article 13 of the Law on the Protection of Personal Data in order to evaluate the rights of personal data owners and to provide the necessary information to personal data owners.
If personal data owners submit their requests regarding their rights listed below to our Hospital in person with an application and a specially authorized power of attorney, our hospital concludes the request as soon as possible and free of charge within thirty days at the latest, depending on the nature of the request. Provided that personal data owners are related to them;
- Learn whether your personal data is processed,
- Request information if personal data has been processed,
- Know about the purpose of processing personal data and whether they are used in accordance with their purpose,
- Know about the third parties to whom personal data is transferred at home or abroad,
- Request correction of personal data in case of incomplete or incorrect processing,
- To request the deletion or destruction of personal data,
- Requesting that these transactions be notified to third parties to whom personal data have been transferred, In case of correction, deletion or destruction of personal data,
- Object to the occurrence of any consequence against yourself due to analysis of the processed data exclusively through automated systems,
- Demand indemnification of loss if they suffer loss due to their personal data being processed in breach of the law.
Pursuant to paragraph 1 of Article 13 of the Law on the Protection of Personal Data , the request for the exercise of the above-mentioned rights must be sent to our hospital (data officer) in "written" form.
In order to use the rights specified within the framework of the Law on the Protection of Personal Data , the request, along with the necessary information identifying the rights and explanations about the rights to be used, and the application of the request to our hospital by specifying which right is related to the use of the article 11 of the Law on the Protection of Personal Data, will ensure that the application for the request is answered faster and more effective.
15. BUILDING, BUILDING ENTRANCES AND PERSONAL DATA PROCESSING ACTIVITIES IN THE BUILDING FOUNDATION AND INTERNET SITE VISITORS
Our hospital acts in accordance with the regulations in the Law on the Protection of Personal Data in the monitoring activities with cameras for security purposes.
Personal data processing is carried out in the buildings and foundations of our hospital to monitor the entrance and exit of patients, personnel, visitors, and supplier company employees with security cameras.
Personal data processing is carried out by our Hospital by using security cameras and recording guest entrance and exits.
In this context, our hospital acts in accordance with the Constitution, the Law on the Protection of Personal Data and other relevant legislation.
Image records of our visitors and sound recordings are taken where necessary by means of camera monitoring system at the building, foundation entrances and inside the foundation of our hospital.
Our hospital, within the scope of surveillance activity with security cameras; It aims to increase the quality of the service provided, to ensure its reliability, to ensure the safety of the institution, patients and employees, and to protect the interests of the patients regarding the healthcare and other services they receive.
The camera surveillance activity carried out by our hospital is carried out in accordance with the Law on Private Security Services and the relevant legislation.
Only authorized company employees and / or supplier company employees have access to digitally recorded and maintained records. The live camera images can be watched by security guards from outside. Camera recordings are kept for 2 months.
Necessary technical and administrative measures are taken by our Hospital to ensure the security of personal data obtained as a result of camera surveillance in accordance with Article 12 of the Law on the Protection of Personal Data.
16. EFFECTIVENESS
Private Gebze Doğa Sağlık Hizmetleri Anonim Şirketi Policy on Protection and Processing of Personal Data enters into force on 17.08.2020. In case the whole or certain articles of the policy are renewed, the effective date of the Policy is the date on which that article is revised for the renewed article.
