Skip to main content

Smirni Health Services Tourism Consultancy Trade Limited Company

Policy on the Protection and Processing of Personal Data

SECTION 1

1.1. INTRODUCTION

The protection of personal data is among the fundamental corporate priorities of Smirni Health Services Tourism Consultancy Trade Limited Company, and maximum attention, care and sensitivity are shown to ensure that data processing activities are carried out in accordance with the legislation in force, the decisions of the Personal Data Protection Board, relevant secondary regulations and binding legal obligations.

Within the scope of this Policy on the Protection and Processing of Personal Data, the fundamental principles and rules adopted in personal data processing activities carried out by Smirni Health Services Tourism Consultancy Trade Limited Company, as well as the corporate approach regarding the processing of personal data in a lawful, fair, transparent, proportionate manner and in a way that ensures data security, are set forth. In this way, it is aimed to inform the relevant persons, record data processing activities, systematize data governance, support personal data security with technical and administrative control mechanisms, and protect personal data in a manner that does not harm fundamental rights and freedoms.

With awareness of this responsibility, personal data belonging to employees, employee candidates, foreign national patients residing abroad, patient relatives, persons receiving services within the scope of health tourism, potential patients, suppliers, supplier officials and employees, business partners, visitors, website users, persons who apply through call and communication channels, and all relevant persons contacted within the scope of health tourism, patient referral, international patient coordination, travel planning, accommodation organization, transfer processes, consultancy activities, accounting, finance, human resources, administrative affairs, physical premises security and information technology processes are processed in accordance with the provisions of this Policy and the legislation in force.

In the processes of protecting and processing personal data, the principles of compliance with the law and good faith, being accurate and, where necessary, up to date, processing for specific, explicit and legitimate purposes, being relevant, limited and proportionate to the purposes for which they are processed, and being retained for the period stipulated in the relevant legislation or required for the purpose for which they are processed are taken as basis. In addition, the principles of transparency, accountability, data minimization, retention period management, risk-based control approach and sustainability of data security are accepted as an integral part of the corporate management approach.

The field of activity of Smirni Health Services Tourism Consultancy Trade Limited Company İNŞ. SAN. TİC. LTD. ŞTİ. includes health tourism services, patient referral and coordination processes, travel and accommodation organization, transfer planning, consultancy activities, customer relations management, sales and operational activities, supplier and business partnership relations, accounting, finance, human resources and administrative processes, and data processing activities are shaped within the framework of this activity structure. Therefore, the personal data processed are not limited only to administrative processes; they may also be processed within the scope of planning health tourism services, receiving patient requests, coordinating appointment and operation processes, carrying out reservation procedures, establishing coordination with domestic and international service providers, establishing and performing contracts, fulfilling payment and collection transactions, managing procurement and service relations, ensuring physical premises security, protecting information systems and fulfilling obligations arising from legislation.

The protection of personal data is considered not only as a legislative obligation, but also as a fundamental governance matter in terms of protecting corporate reputation, ensuring commercial trust, maintaining the sustainability of service relations, establishing auditable data governance and securing the fundamental rights and freedoms of relevant persons, and all processes are structured in line with this understanding.

1.2. PURPOSE

Smirni Health Services Tourism Consultancy Trade Limited Company undertakes, in line with this Policy, to act in accordance with the Constitution of the Republic of Turkey, the Personal Data Protection Law No. 6698, relevant regulations, communiqués, decisions of the Personal Data Protection Board and other legislative provisions, and to protect the rights of relevant persons.

Within this scope, a written personal data protection system that is implemented and continuously improved has been established, and data governance is carried out within a corporate structure. This structure includes tracking data processing activities on an inventory basis, matching data categories with processing purposes, determining legal grounds, planning data retention and destruction processes, keeping data transfer relationships under control, managing relevant person application processes, and systematically implementing technical and administrative measures regarding data security.

With this Policy, the fundamental principles regarding the protection and processing of personal data are regulated within the scope of health tourism and consultancy activities, patient relations, travel and accommodation organization, transfer and coordination services, finance and accounting transactions, human resources practices, contract management, information security, physical premises security, audit and internal control activities and administrative processes.

The purpose of the Policy has been determined as follows:

  • to ensure that activities are carried out in accordance with the law,
  • to establish corporate data management standards,
  • to establish personal data security and control mechanisms,
  • to make risk management effective,
  • to ensure full compliance with the Personal Data Protection Law No. 6698 and relevant legislation,
  • to protect the fundamental rights and freedoms of relevant persons,
  • to standardize and record data processing activities,
  • to institutionalize a personal data protection culture,
  • to reduce the risks of data breaches and to establish effective response processes in the event of a breach,
  • to secure data processing and data transfer processes carried out with third parties,
  • to manage retention and destruction processes in accordance with the legislation,
  • to structurally secure domestic and international data transfer processes in accordance with current legislation.

1.3. SCOPE

This Policy covers all activities carried out within Smirni Health Services Tourism Consultancy Trade Limited Company and the personal data processing processes carried out in connection with these activities.

The provisions of the Policy cover the entire organizational structure of the company, its departments, processes, physical and electronic archives, information systems, software, databases, user devices, e-mail infrastructure, accounting and commercial records, camera systems, visitor registration systems, human resources files, contracts, offers, reservations, patient and customer records, travel and accommodation planning records, patient coordination files, financial records, supplier relations, website and digital application channels, and all elements involved in data processing processes.

This Policy covers managers, employees, employee candidates, patients, patient relatives, customers, potential customers, suppliers, supplier employees and officials, business partners, visitors, website visitors and all real persons who have any legal, commercial or actual relationship with the company.

Any transaction contrary to the Personal Data Protection Law No. 6698 or this Policy shall be evaluated within the framework of the relevant legislation, contractual provisions, internal regulations and disciplinary mechanisms. In this context, acts of employees or third-party service providers that undermine data security are considered to be capable of giving rise to administrative, legal, financial and, where necessary, criminal consequences.

Third parties with whom data is shared by the company are also obliged to act in accordance with data security obligations, and necessary contractual, administrative and technical measures are taken accordingly. In relations carried out with persons and organizations acting as data processors, it is essential that personal data be processed only within the framework of the instructions of the data controller, confidentiality obligations be complied with, an appropriate level of security be ensured, data transfer limits be observed and sub-processor relationships be kept under control.

The implementation and updating of the Policy are carried out by the company management, and all employees are responsible for daily implementation. Each employee is responsible, limited to their area of duty, for carrying out personal data processing processes in compliance with the legislation, protecting data security, and reporting suspicious or risk-generating situations without delay.

1.4. TARGET

The company’s target is to increase corporate awareness regarding the protection of personal data, expand the culture of data security, operate technical and administrative control mechanisms effectively, make the rights of relevant persons accessible and effectively usable, and establish compliance with legislation in a sustainable structure.

In this respect, this Policy serves as a fundamental corporate guide aimed at standardizing, controlling, monitoring, measuring, reporting and continuously improving data processing activities. The target is not only to fulfill existing legal obligations, but also to keep the personal data protection system dynamically up to date in the face of changing technological conditions, digitalization processes, online application and reservation structures, international patient flow, domestic and international service networks and cybersecurity threats.

In line with this target, it is aimed to keep data processing inventories up to date, conduct employee training regularly, fulfill the obligation to inform in accordance with the procedure, design explicit consent processes in accordance with the law, audit data retention and destruction processes, establish data transfer relationships on a legal basis, keep data breach management operational, and carry out information security processes in an integrated manner with the personal data protection approach.

SECTION 2

2.1. DEFINITIONS AND ABBREVIATIONS

Term / Abbreviation Definition
Explicit Consent Refers to consent that relates to a specific subject, is based on information and is declared with free will.
Recipient Group Refers to the category of real or legal persons to whom personal data are transferred by the data controller.
Anonymization Refers to rendering personal data incapable of being associated with an identified or identifiable real person, even if matched with other data.
Relevant Person Refers to the real person whose personal data are processed.
Destruction Refers to the deletion, destruction or anonymization of personal data.
Recording Medium Refers to any medium containing personal data processed wholly or partially by automatic means or by non-automatic means provided that it is part of any data recording system.
Personal Data Refers to any information relating to an identified or identifiable real person.
Personal Data Protection Board Refers to the Board operating under the Personal Data Protection Law No. 6698.
Personal Data Protection Authority Refers to the Authority operating under the Personal Data Protection Law No. 6698.
Special Category Personal Data Refers to personal data subject to special protection under the Personal Data Protection Law No. 6698.
Data Processor Refers to the real or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller.
Data Controller Refers to the legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.
Data Controllers Registry Information System Refers to the registration system through which data controllers fulfill their registry registration and notification obligations.
Registered Electronic Mail Refers to the system that enables electronic messages producing legal consequences to be sent and received securely.
Smirni Health Services Tourism Consultancy Trade Limited Company Refers to the company that processes personal data in the capacity of data controller.

2.2. CLASSIFICATION OF PROCESSED PERSONAL DATA

Category Description
Identity Name, surname, Turkish Republic identity number, date of birth, place of birth, passport information, identity document information, signature information
Contact Telephone number, e-mail address, full address, registered contact information
Customer Transaction Application records, reservation information, travel plan information, flight and accommodation information, offer records, contract information, request and complaint records, coordination and operation records
Patient and Service Transaction Requests received within the scope of health tourism, referral records, appointment and coordination information, healthcare institution matching information, service history records
Finance Invoice information, payment information, bank account information, current account data, collection and payment records
Professional Experience Resume information, diploma information, certificate information, reference information, professional qualification data
Personnel Payroll information, leave information, employment start and termination records, performance evaluation records, fringe benefit information
Physical Premises Security Camera records, visitor entry and exit records, security control information
Transaction Security Internet access records, system log records, user activity records, internet protocol address information
Visual and Audio Records Photograph records, camera footage, audio recordings where necessary
Legal Transaction Information relating to lawsuits, enforcement proceedings, notices, official institution correspondence and dispute processes
Special Category Personal Data Health information, medical photographs and images of the treatment area, disability status information, data relating to criminal convictions and security measures, and other data deemed special category data under the legislation

The company classifies data categories based on the field of activity, type of business relationship, data subject person group, processing purpose, retention period and legal ground, thereby ensuring the control, traceability and auditability of data processing activities. In determining data categories, it is essential not to process data that are not required for the business and to act in accordance with the principle of proportionality.

2.3. MEDIA WHERE PERSONAL DATA ARE STORED

Electronic media:
Servers, desktop and laptop computers, mobile devices, e-mail systems, patient and customer registration systems, reservation and operation tracking systems, accounting and finance programs, call and communication recording infrastructures, databases, security camera systems, portable memories, network devices, backup units, cloud systems, corporate software, website and other information technology infrastructures.

Physical media:
Contracts, application forms, reservation documents, patient and customer transaction documents, personnel files, visitor logbooks, printed documents, archive cabinets, folders, accounting documents, payrolls, signature sheets, human resources documents, operation documents and other physical files.

The media where personal data are stored are classified according to data security levels, and access, preservation, transportation, archiving and destruction rules for these media are separately determined. The risk level for each electronic and physical medium is evaluated separately, and additional control mechanisms are applied particularly for special category personal data and data constituting trade secrets.

2.4. PURPOSES OF PROCESSING PERSONAL DATA

Personal data are processed for the following purposes:

  • carrying out health tourism, patient referral and consultancy processes,
  • carrying out application, offer, reservation and contract processes,
  • managing patient, customer and potential customer relations,
  • planning and carrying out travel, accommodation, transportation, transfer and organization services,
  • ensuring coordination with domestic and international healthcare institutions,
  • planning and managing procurement, purchasing and business partnership processes,
  • carrying out operation, coordination and service delivery processes,
  • fulfilling finance and accounting transactions,
  • carrying out human resources and personnel management processes,
  • fulfilling occupational health and safety processes,
  • fulfilling legal obligations,
  • ensuring information security and physical premises security,
  • carrying out audit, reporting, internal control and risk management activities,
  • providing information to authorized institutions and organizations,
  • planning, monitoring and improving business activities,
  • carrying out corporate communication processes,
  • ensuring the sustainability of commercial activities,
  • carrying out job application and recruitment processes,
  • managing employee satisfaction, performance and fringe benefit processes.

When determining data processing purposes, the company evaluates whether each data category is genuinely necessary, avoids data processing activities outside the intended purpose, and informs relevant persons regarding data processing purposes in accordance with the procedure.

SECTION 3

3.1. CONDITIONS FOR PROCESSING PERSONAL DATA

Personal data are processed in accordance with the data processing conditions regulated under Articles 5 and 6 of the Personal Data Protection Law No. 6698. Within this scope, personal data are processed based on the following legal grounds:

  • it is expressly provided for by law,
  • it is mandatory for the protection of the life or bodily integrity of the person or another person who is unable to express consent due to actual impossibility or whose consent is not legally valid,
  • it is necessary to process personal data belonging to the parties of a contract, provided that it is directly related to the establishment or performance of a contract,
  • it is mandatory for the data controller to fulfill its legal obligation,
  • the relevant person has made the data public themselves,
  • data processing is mandatory for the establishment, exercise or protection of a right,
  • data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the relevant person,
  • the explicit consent of the relevant person is obtained.

Special category personal data are processed within the framework of the conditions stipulated by law and by taking sufficient technical and administrative measures. In the processing of special category personal data, the principles of necessity, proportionality, limited access and enhanced security are also observed.

The company determines the legal grounds separately for each data category in personal data processing activities and carries out data processing activities within this framework. Data processing activities for which no processing condition exists or for which the condition later ceases to exist are immediately reviewed; where necessary, the relevant data processing process is terminated, and the data are deleted, destroyed or anonymized.

In data processing activities based on explicit consent, it is ensured that the consent relates to a specific subject, is based on information and is given with free will. It is also taken into consideration that explicit consent is exceptional in cases where there is no other lawful data processing condition.

3.2. TRANSFER OF PERSONAL DATA

Personal data processed by the company may be transferred to the following parties in accordance with the provisions of the relevant legislation and limited to the purposes of data processing:

  • authorized public institutions and organizations,
  • courts, enforcement offices and official authorities,
  • law enforcement agencies and regulatory or supervisory authorities,
  • banks and financial institutions,
  • parties providing financial consultancy and accounting services,
  • suppliers and service provider companies,
  • business partners and solution partners,
  • information technology service providers,
  • persons and organizations from whom legal, audit and consultancy services are received,
  • healthcare institutions, doctors, intermediary healthcare service providers and other parties from whom services are received within the scope of health tourism,
  • airline companies, accommodation facilities, transfer and transportation service providers, car rental companies and service providers involved in organization processes,
  • organizations providing archiving, support services and similar processes.

In the transfer of personal data, the company acts in accordance with the conditions regulated under Articles 8 and 9 of the law, and the necessary contractual, administrative and technical security measures are established with the third parties to whom data are transferred. In international data transfers, adequacy decisions, appropriate safeguards, standard contracts or other transfer mechanisms accepted by the Board are taken into account within the framework of current legislation.

In transfer processes, sharing only the necessary amount of data, clearly determining the purpose of the data transfer, evaluating the data security capacity of the receiving party and keeping transfer records in a provable manner where necessary are among the fundamental principles.

3.3. RETENTION AND DESTRUCTION OF PERSONAL DATA

The company retains personal data only for the period required by the purposes for which they are processed and within the framework of the retention periods stipulated in the relevant legislation. Pursuant to the law and relevant regulation, when the reasons for processing cease to exist, personal data must be deleted, destroyed or anonymized.

Where no explicit retention period is stipulated in the legislation, personal data are retained for reasonable periods determined in line with company practices, commercial customs, evidentiary obligations, limitation periods and legal requirements in connection with the purpose for which they are processed.

When the retention period expires or the data processing conditions cease to exist, personal data are destroyed by using the appropriate method among deletion, destruction or anonymization.

Destruction processes are carried out within the scope of the Personal Data Retention and Destruction Policy established by the company, and periodic destruction processes are carried out regularly.

The company evaluates the nature of the data, the medium in which they are stored, access risk, processing purpose, legal obligations and possible disputes together in retention and destruction processes. Secure destruction methods are used for the destruction of physical documents, while irreversible technical methods are used for the destruction of data stored in electronic media. Stricter security measures are also applied in the destruction processes of special category personal data.

SECTION 4

4.1. TECHNICAL AND ADMINISTRATIVE MEASURES

The company takes the necessary technical and administrative measures to prevent the unlawful processing of and access to personal data, to ensure the preservation of personal data and to provide an appropriate level of security.

The main technical measures applied within this scope are as follows:

  • establishing authorization matrices and access control systems,
  • implementing user-based authorization and authentication mechanisms,
  • keeping, monitoring and, where necessary, auditing log records,
  • using firewalls, malware protection and endpoint security systems,
  • establishing and testing data backup and disaster recovery plans,
  • ensuring network security and system security controls,
  • applying up-to-date software and system patches,
  • ensuring access controls for physical archive and server areas,
  • applying encryption methods where deemed necessary in databases and portable media,
  • conducting regular security controls on camera systems, user devices and information technology infrastructures,
  • implementing preventive controls against unauthorized data copying, data leakage and transfer risks to external environments,
  • storing backups in secure environments and keeping access records,
  • using secure connection and authentication mechanisms in remote access processes.

Within the scope of administrative measures:

  • regular personal data protection and information security training is provided to employees,
  • confidentiality agreements and undertakings are signed,
  • data processing inventories are created and updated,
  • internal audit and control mechanisms are operated,
  • data security provisions are added to contracts made with third parties,
  • access authorizations are reviewed and terminated in cases of duty changes or termination of employment,
  • retention and access rules are determined for physical documents, personnel files, visitor records, patient files, reservation files and similar recording media,
  • additional control mechanisms are applied regarding the processing of special category personal data,
  • information notices, explicit consent texts and application processes are kept up to date,
  • data breach and security incident notification mechanisms are announced to employees,
  • authorities and responsibilities are clarified within the framework of job descriptions,
  • data security criteria are taken into consideration in the selection of suppliers and service providers.

The company considers the technical and administrative measures taken not as a static structure, but as a dynamic area of compliance that must be continuously reviewed in line with developing technology, changing risks, transformation in business processes and legislative updates.

4.2. DATA BREACH MANAGEMENT

The company operates the necessary response processes in the event that personal data are unlawfully obtained, disclosed, lost, altered or exposed to unauthorized access.

Within this scope:

  • when a data breach is detected, the relevant units and authorized responsible persons are immediately informed,
  • necessary technical and administrative measures are taken to minimize the effects of the breach,
  • the scope of the breach, affected data categories, relevant person groups and possible consequences are evaluated,
  • where necessary, notification is made to the Personal Data Protection Board within the period and in the manner prescribed by the legislation,
  • where necessary, relevant persons are informed through appropriate methods,
  • corrective and preventive activities aimed at preventing recurrence of the breach are planned and implemented,
  • post-incident evaluation is conducted and existing control mechanisms are reviewed.

Data breach processes are carried out within the scope of the Data Breach Response Policy established by the company.

The company may consider a data breach not only as an event that has caused actual damage, but also as any vulnerability, error, unauthorized access, exceeding of authority or control deficiency that may occur and endanger personal data security. Therefore, early detection, rapid reporting, incident classification, assignment of responsibility and preparation of an improvement plan are essential in data breach management.

SECTION 5

5.1. RIGHTS OF THE RELEVANT PERSON

Relevant persons have the following rights within the scope of Article 11 of the Personal Data Protection Law No. 6698: to learn whether their personal data are processed, to request information if their personal data have been processed, to learn the purpose of processing and whether they are used in accordance with such purpose, to know the third parties to whom the data are transferred domestically or abroad, to request correction if the data are processed incompletely or inaccurately, to request deletion or destruction of the data, to request that these transactions be notified to third parties to whom the data have been transferred, to object to the occurrence of a result against them through analysis exclusively by automated systems, and to request compensation for damage.

The company takes as basis the evaluation of applications of relevant persons within an effective, accessible and auditable system, and concludes requests by taking into account not only their formal aspects but also their substantive aspects. In application processes, identity verification, clarification of the scope of the application, obtaining opinions from relevant units and observing legal periods are among the fundamental principles.

5.2. APPLICATION METHOD

Relevant persons may submit their requests regarding the rights specified above through the application methods determined by the company.

Applications may be submitted:

  • in writing,
  • through a notary public,
  • through the e-mail address registered in the company’s system,
  • through other methods permitted by the legislation.

The contact details through which applications may be submitted are as follows:

Title: Smirni Health Services Tourism Consultancy Trade Limited Company

Address: Kartaltepe Mah. Saydam Sk. No:13/A Küçükçekmece / Istanbul

E-Mail: consultancy@qualitylifehealthtravel.info

Telephone: +90 538 971 49 33

Website: qualitylifehealth.com

Applications are concluded within the periods stipulated in the legislation, and if the request requires an additional cost, the fee tariff determined by the Personal Data Protection Board may be applied. The company prepares its response to the application in a clear, understandable, reasoned and auditable manner.

During the evaluation of applications, it is also assessed whether the applicant is genuinely the relevant person, which data processing activity the request relates to, whether fulfilling the request would violate the rights and freedoms of other persons, and whether it conflicts with the company’s legal obligations.

SECTION 6

6.1. ENTRY INTO FORCE AND UPDATE

This Policy enters into force on the date it is approved by the senior management of the company.

The Policy is periodically reviewed in line with legislative amendments, decisions of the Personal Data Protection Board, technological developments, changes in the company’s organizational structure, updates in data processing processes and risk assessments, and is updated where deemed necessary.

The company is obliged to announce the current version of the Policy to its employees and relevant parties.

In update processes, needs arising in practice, internal audit findings, data breach experiences, transitions to new systems, changes in third-party relationships and good practices in the field of data protection are taken into account. Amendments made to the Policy are also reflected, where deemed necessary, in relevant procedures, instructions, contract annexes and information notices.

The company takes as basis that this Policy should not remain merely a written regulation, but should become an effective management tool that lives in practice, is known and internalized by personnel, and is integrated into business processes.

WhatsApp
##Çerez Tercihleri