MSA DENTAL HEALTH LTD. CO.
PERSONAL DATA PROTECTION POLICY
Our company, MSA Ağız ve Diş Sağlığı Hizmetleri LTD. ŞTİ., hereinafter referred to as “Our Company,” “we,” or “our company,” has prepared this document to ensure compliance with the Personal Data Protection Law No. 6698 (KVKK) and related regulations regarding the protection and security of personal data. This document will be referred to as the “Policy” or “This Policy” in the rest of the text. As the data controller, our company is aware of the importance of maintaining the confidentiality and security of personal data collected in accordance with KVKK and other related legislation. The aim is to meet the requirements for compliance with Law No. 6698 and related legislation, and to establish a data protection and processing policy that meets international standards.
In this Policy, as a data controller, our company will process personal data in compliance with the law, the rules of fairness, and the principles of necessity and proportionality, in accordance with the purposes for which the data is collected, and will store the data for no longer than necessary for the stated purposes. Our company will follow personal data processing procedures in a manner that is consistent with the Turkish Constitution, KVKK, and related legislation. These data will be processed in accordance with the procedures outlined in this Policy, which comply with KVKK and other relevant legislation.
This Policy applies to all personal data of real persons defined as “data subjects” in KVKK and related legislation, which is processed through automated means or as part of a manual data filing system. The channels through which personal data reaches our company, as well as the method of collection, legal reasons for collection, purposes of processing, and the recipients of the data are detailed in the relevant Clarification Texts and Explicit Consent Forms provided to the data subjects.
The definitions provided in Article 3 of the Personal Data Protection Law (KVKK) are as follows.
Anonymization | : | The process of transforming personal data in such a way that it can no longer be associated with a specific or identifiable individual, even when combined with other data. |
Explicit Consent | : | The statement of consent made by the individual whose personal data will be processed, after being informed about the processing, before the processing operation is carried out. |
Clarification Text | : | An explanation made to the data subject about the purpose for which personal data will be stored, the duration of storage, the methods of collection, how it will be preserved, and whether it will be shared with third parties. This explanation is required to ensure transparency and compliance with the Personal Data Protection Law (KVKK) and is typically included in the Clarification Text (Aydınlatma Metni). The goal is to provide the data subject with all necessary information to make an informed decision regarding the processing of their personal data. |
Presidency | : | Presidency of the Personal Data Protection Authority |
Inventory | : | An inventory created by data controllers, which details the personal data processing activities they carry out based on their business processes. This inventory associates the activities with the purposes of personal data processing, data categories, the recipient group to which data is transferred, and the group of data subjects. It also provides details about the maximum duration for which personal data is retained, data that may be transferred to foreign countries, and the security measures taken to protect the data. This inventory serves as a comprehensive record that outlines the processing operations, ensuring compliance with data protection regulations and providing transparency regarding how personal data is handled, stored, and transferred. |
Data Subject | : | The natural person whose personal data is being processed. |
Destruction | : | The deletion, destruction, or anonymization of personal data. |
Processing | : | In Article 3 of the KVKK (Personal Data Protection Law), the term “processing” refers to the operations of recording, storing, preserving, altering, reorganizing, disclosing, transferring, acquiring, making available, and classifying personal data. |
Law / KVKK | : | Personal Data Protection Law (KVKK) |
Personal Data | : | Any information related to an identified or identifiable natural person. For example, name-surname, TCKN (Turkish National ID), email, address, date of birth, bank account number, etc. Therefore, information related to legal entities is not processed under the scope of the Personal Data Protection Law (KVKK). |
Processing of Personal Data | : | The processing of personal data refers to any operation performed on personal data, whether by automated means or non-automated means as part of a data recording system, including collection, recording, storage, maintenance, alteration, rearrangement, disclosure, transmission, reception, making available, classification, or restriction of use. |
The Board | : | The Personal Data Protection Board |
The Institution | : | Personal Data Protection Authority |
Special Categories of Sensitive Personal Data | Data related to race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, clothing, membership in associations, foundations, or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data are classified as special categories of sensitive personal data under the Personal Data Protection Law (KVKK) in Turkey. | |
VERBİS | : | The information system created and managed by the Presidency, which data controllers will use for applying to the Registry and for other related processes, accessible via the internet. |
Data Processor | : | A real or legal person who processes personal data on behalf of the data controller, based on the authorization given by the data controller. |
Data Controller | : | A real or legal person who determines the purposes and means of processing personal data, and is responsible for the establishment and management of the data recording system. |
The Data Controllers’ Registry | : | The Data Controllers’ Registry maintained by the Presidency |
Data Controller Contact Person | : | The natural person notified by the data controller during the registration to the Registry, who will communicate with the Authority regarding the obligations of legal entities located in Turkey and the representatives of legal entity data controllers located outside of Turkey, within the scope of the Law and secondary regulations to be issued based on this Law. |
Deletion | : | Deletion of personal data: The process of removing personal data so that it becomes completely inaccessible and cannot be reused by any means for the relevant users. |
Destruction | : | Destruction of personal data refers to the process of making personal data completely inaccessible, irretrievable, and unusable by anyone in any way. |
The table below contains the individuals whose personal data is obtained and processed by our company. The scope and application area of this Policy are limited to the individuals listed in this table. Requests from individuals outside of these definitions will also be processed by our company in accordance with the KVKK (Personal Data Protection Law) and related regulations.
Employee | : | A person working with an employment contract at our company. |
A person receiving healthcare services. | : | Persons receiving services from our company. |
Clinic Owner/Doctor | : | The person who is the owner of the company and provides treatment services in their capacity as a doctor. |
Occupational Physician | : | A real person providing occupational physician services in accordance with legal obligations. |
Consultant, Supplier and Business Partner Representative, Shareholder, Employee | : | Individuals who are shareholders, employees, and representatives of organizations with which our company has business relationships, receives services, or collaborates, and/or individual suppliers. |
Guardian/Representative | : | An individual who is authorized to represent another person due to custody, guardianship, or power of attorney. |
Visitor | : | Real persons who have physically visited the address specified in the contract for purposes related to the company’s operations, services, or activities. |
Caller | : | A person who contacts the company via its switchboard or telephone system. |
5. FUNDAMENTAL PRINCIPLES IN PERSONAL DATA PROCESSING
Our company complies with the general principles and conditions set out in the legislation regarding the protection and processing of personal data and ensures that personal data is processed in accordance with the Constitution and the Law on the Protection of Personal Data (KVKK). To ensure compliance, the following principles are followed in the company’s practices, and these principles are adhered to with high awareness by our employees in the medical office.
5.1. General Principles for Personal Data Processing
Our company adheres to the procedures and principles specified in Article 4(2) of the Law on the Protection of Personal Data and other related laws, as listed below:
5.1.1. Compliance with the Law and the Principle of Good Faith
Our company ensures that personal data is processed in accordance with legal requirements and in good faith.
5.1.2. Ensuring Data Accuracy and Keeping It Updated When Necessary
We ensure that the data is accurate and, if necessary, updated.
5.1.3. Processing Personal Data for Specific, Explicit, and Legitimate Purposes
Personal data is processed for specified, explicit, and legitimate purposes.
5.1.4. Purpose Limitation, Minimization, and Proportionality
Personal data is processed in a manner that is relevant, adequate, and not excessive in relation to the purposes for which it is collected.
5.1.5. Retention of Personal Data for the Duration Necessary for Legal Obligations or Purposes
Personal data will be retained for the period stipulated in the relevant legislation or for as long as necessary for the purpose for which it was processed.
5.2. The Rule of Prohibition of Personal Data Processing
Our company is aware that personal data will not be processed without the explicit consent of the data subject, and this can only be regulated by the relevant law. The company aims to process personal data in accordance with the conditions specified in Article 5(2) of the Law on the Protection of Personal Data. These conditions are as follows:
a. Explicit Consent of the Data Subject
b. Clear Stipulation in Laws
c. Inability to Obtain the Data Subject’s Consent Due to Impossibility
d. Direct Relation to the Establishment or Fulfillment of a Contract
e. Fulfillment of Legal Obligations
f. Public Disclosure of the Personal Data by the Data Subject
g. Data Processing is Necessary for the Establishment or Protection of a Right
h. Data Processing is Necessary for Legitimate Interests
6. PERSONAL DATA COLLECTION CHANNELS
Our company collects personal data of relevant persons as outlined in Article 4 of this Policy, using both automated and non-automated methods, either verbally, in writing, or electronically. The personal data collected, including medical diagnosis, examination, treatment, and care services required to carry out these services, is listed in detail below.
7. CATEGORIES OF PERSONAL DATA COLLECTED
The categories of personal data collected from the relevant persons mentioned in this Policy are listed in our company’s Personal Data Inventory, considering examples from VERBIS. If there are any changes in the personal data collected from relevant persons, the Inventory and VERBIS record will be updated.
Some of the personal data categories and types collected are shown in the table below.
Personal Data Categories | : | Related Data Types (Examples from VERBİS) |
Identity Data | : | Full Name, Parent’s Names, Date of Birth, Place of Birth, Marital Status, National ID Serial Number, Turkish ID Number, Signature, Passport Number or Temporary Turkish ID Number (if not a Turkish Citizen) |
Contact Information | : | Address, Email Address, Phone Number |
Employment Data | : | Payroll Information, Employment Start Date, Rank-Position-Job Description, Salary Information, Bank IBAN Account Number |
Physical Location Security Data | : | Employee and Visitor Entry and Exit Records, Camera Footage |
Professional Experience Data | : | Occupation Information, Diploma Information, Courses Attended, Professional Development Training Information, Certificates |
Health Data | : | Health Reports, Blood Type Information, Personal Health Information, Body Temperature, Laboratory and Imaging Results, Test Results, Examination Data, Prescription Information, Health and Infectious Disease Data. |
Customer Transaction Data | : | Payment records, invoice information. |
Transaction Security Data | : | Username and Password Information |
Visual and Audio Records | : | Photo, closed-circuit television system video and audio recordings taken during the examination visit. |
8. DISCLOSURE OBLIGATION
In accordance with Article 10 of the Turkish Personal Data Protection Law (KVKK), the information that must be provided to data subjects under the disclosure obligation is outlined below:
•The identity of the data controller and, if applicable, its representative,
•The purposes for which personal data will be processed,
•To whom and for what purposes the processed personal data may be transferred,
•The method of collecting personal data and its legal basis,
•The rights of the data subject as listed in Article 11 of the KVKK.
To fulfill the disclosure obligation, our company has prepared disclosure texts that will be provided to data subjects, in line with the above-mentioned KVKK provision, based on the processes and data being processed. After the disclosure texts are shared with data subjects, explicit consent is obtained for data processing activities and categories that require the consent of the data subject for the company to carry out its business activities.
In accordance with Article 28(1) of the KVKK, there are certain exceptions where the disclosure obligation does not apply. These are the cases where the disclosure obligation does not exist:
•Personal data processed by individuals for activities solely related to themselves or their family members living in the same household, provided that they are not shared with third parties and data security obligations are adhered to,
•Personal data processed for statistical purposes by anonymizing them for research, planning, or statistical purposes,
•Personal data processed for scientific, artistic, historical, or literary purposes, or for freedom of expression, without violating national defense, national security, public safety, public order, economic security, privacy, or personal rights,
•Personal data processed by public institutions and organizations that are authorized by law for preventive, protective, and intelligence activities related to national defense, national security, public safety, public order, or economic security,
•Personal data processed by judicial authorities or enforcement authorities in connection with investigation, prosecution, trial, or enforcement actions.
Furthermore, Article 28(2) of the KVKK lists additional exceptions under which the disclosure obligation does not apply:
•Personal data processing necessary for preventing crime or for a criminal investigation,
•Personal data processed by the data subject themselves in public,
•Personal data processed by public institutions and organizations authorized by law, for audit or regulatory tasks, or for disciplinary investigations or prosecutions,
•Personal data processing necessary for the protection of the State’s economic and financial interests in relation to budgeting, taxation, and financial matters.
9. SPECIAL CATEGORIES OF PERSONAL DATA POLICY
In accordance with the Personal Data Protection Board’s decision dated 31/01/2018 and numbered 2018/10, regarding the processing of special categories of personal data, our company ensures the protection of such data by implementing adequate security measures.
According to Article 6 of the KVKK, special categories of personal data include:
•Data about an individual’s race, ethnic origin, political opinions, philosophical beliefs, religion, sect, or other beliefs, clothing, membership in associations, foundations, or unions, health, sexual life, criminal convictions, and security measures, as well as biometric and genetic data.
•Processing special categories of personal data without the explicit consent of the individual is prohibited.
•Personal data mentioned in the first paragraph (excluding health and sexual life) may be processed without explicit consent in cases where required by law. Health and sexual life-related data can only be processed without explicit consent by persons or authorized institutions with confidentiality obligations, for public health protection, preventive medicine, medical diagnosis, treatment, and care services, or for planning and managing health services and financing.
•In processing special categories of personal data, additional sufficient measures must be taken, as specified by the Personal Data Protection Authority.
10. RIGHTS OF THE PERSONAL DATA SUBJECT
Under Article 11 of the Personal Data Protection Law (KVKK), everyone has the right to apply to our company, as the data controller, regarding the following matters:
(1) Everyone has the right to request the following from the data controller regarding their own personal data:
a) Learn whether personal data is being processed,
b) If personal data has been processed, request information about it,
c) Learn the purpose of processing personal data and whether it is being used in accordance with its purpose,
ç) Learn the third parties to whom personal data has been transferred, both domestically and abroad,
d) Request the correction of personal data if it is incomplete or incorrect,
e) Request the deletion or destruction of personal data in accordance with the conditions set out in Article 7 of the KVKK,
f) Request the notification of corrections, deletions, or destructions made under (d) and (e) to third parties to whom personal data has been transferred,
g) Object to the result of processing personal data solely through automated systems that lead to a negative outcome for the individual,
ğ) Request compensation for damages caused by unlawful processing of personal data.
11. METHOD FOR EXERCISING THE RIGHTS OF THE PERSONAL DATA SUBJECT
In accordance with Article 13 of the KVKK and the Regulation on the Procedures and Principles for Application to the Data Controller published in the Official Gazette on 10.03.2018, applications to exercise these rights should be submitted in writing or through other methods determined by the Personal Data Protection Board (Board).
The data subject may communicate their requests and rights as outlined in Article 11 of the KVKK to our company. In this regard, the data subject can apply in writing to use all rights under Article 11 of the KVKK, through the following methods:
•In person, with a signed statement,
•By post with an attached signature declaration,
•Through notary,
•By secure electronic signature,
•By sending a signed application via secure electronic signature to the KEP address provided below,
•By sending it from the e-mail address previously notified by the data subject to the data controller.
The application must include the following:
•Name, surname, and signature if the application is written,
•For Turkish citizens, the Turkish Identification Number; for foreigners, nationality, passport number, or identification number if available,
•Residential or workplace address for notification purposes,
•If available, email address, phone number, and fax number for notification,
•Subject of the request,
•Information and documents related to the subject.
Under Article 13 of the KVKK, the following process applies:
•The data subject submits their request in writing or via other methods determined by the Board.
•The data controller will respond to the application within thirty days, free of charge, depending on the nature of the request. However, if the process incurs additional costs, the fee set by the Board may be charged.
•The data controller accepts or rejects the request, providing a written or electronic explanation of the reasoning. If the request is accepted, the necessary actions will be taken.
Applications must be made by the individual themselves. If made on behalf of someone else, it must be accompanied by a power of attorney if the request involves the right to request information under KVKK. If there is any doubt about the identity of the applicant, the company may request verification details from the applicant.
12. CONTACT INFORMATION
Title: Msa Ağız ve Diş Sağlığı Hizmetleri LTD. ŞTİ
Address: İçerenköy Mahallesi, Küçükbakkalköy Yolu Caddesi, No: 56-58 A, 34752, Ataşehir, İSTANBUL
Email address: info@msadentalclinic.com
13. MEASURES TAKEN TO PROTECT PERSONAL DATA
In accordance with Article 12 of the KVKK, our company takes necessary administrative and technical measures to prevent unlawful processing and access of personal data and to ensure its secure storage. Appropriate measures are implemented based on the nature of the data, and sensitive personal data is protected with stricter security measures.
14. STORAGE OF PERSONAL DATA
The personal data obtained by our company is securely stored, either physically or electronically, for the time necessary to conduct the company’s activities. In this context, our company complies with all legal obligations related to personal data protection, including the KVKK and other relevant legislation.
If there is no specified retention period in the relevant legislation, personal data is stored for a period determined according to the following criteria and is deleted, destroyed, or anonymized at the end of this period. After this period, personal data will be deleted, destroyed, or anonymized.
In cases where the retention of personal data for a longer period is allowed or required, personal data will be retained until the expiration of the statute of limitations as outlined in the Turkish Code of Obligations (10 years). Employee data will be retained for 15 years following the end of the employment contract, in accordance with the Labor Law and Occupational Safety regulations. After the expiration of these timeframes, the data will be deleted or destroyed according to the procedures outlined in the Storage and Destruction Policy.
15. TRANSFER OF PERSONAL DATA WITHIN TURKEY
Our company adheres strictly to the requirements of the KVKK when transferring personal data to third parties, in accordance with the relevant laws.
In this regard, personal data will not be transferred to third parties without the explicit consent of the data subject, except under the conditions specified in Article 5 of the KVKK, such as:
•If explicitly required by law,
•If necessary for the protection of life or bodily integrity in cases where the data subject is unable to give consent,
•If necessary for the establishment or performance of a contract,
•If necessary for fulfilling the legal obligations of the data controller,
•If the data subject has made the data public,
•If necessary for the establishment, exercise, or protection of a legal right,
•If processing personal data is necessary for the legitimate interests of the data controller, without harming the fundamental rights and freedoms of the data subject.
16. TRANSFER OF PERSONAL DATA ABROAD
In accordance with Article 9 of the KVKK, the explicit consent of the data subject is required for the transfer of personal data abroad. However, personal data can be transferred to a foreign country without the data subject’s explicit consent if the country ensures adequate protection and meets the conditions outlined in the law.
If the country to which data is being transferred is not on the list of countries with adequate protection, our company and the data controller in the foreign country will provide written guarantees regarding the sufficient protection of personal data.
17. EFFECTIVE DATE AND APPLICATION
Our company’s policies regarding the processing and protection of personal data will be regulated in accordance with the KVKK and other relevant legislation. Any updates to the policy will become effective on the date of publication. The most current version of the policy will be published on our website at https://www.msadentalclinic.com/.
If there is any inconsistency between the KVKK and this policy, the provisions of the KVKK and related laws will prevail, and the policy will be updated as necessary to ensure compliance.