INFORMATION ON THE PROCESSING OF PERSONAL DATA
As Hisar Sağlık Hizmetleri A.Ş. (“Hisar Hospital Intercontinental”), we prioritize the security of your personal data. With this awareness, we show great sensitivity to the preservation of all kinds of personal data belonging to you, processed in the best possible way and with care. With the awareness of this responsibility, we process your personal data as the Data Controller within the framework of the Law No. 6698 on the Protection of Personal Data (“Law”) and relevant legislation as specified below.
Collection, Processing, and Purposes of Personal Data
In order to provide you with high standards of service, we obtain your personal data verbally, in writing, visually, or electronically through Call Center, internet, mobile applications, physical locations, and similar channels, depending on the nature of the service provided. In this context, the main general and special qualified personal data, especially personal health data necessary for the execution of all medical diagnoses, examinations, treatments, and care services, are listed below;
- Your identity data such as your name, surname, Turkish ID number, passport number if you are not a Turkish citizen or your temporary Turkish ID number, place and date of birth, marital status, gender information, and a copy of your Turkish ID Card or Driver’s License you presented,
- Your contact data such as your address, phone number, and email address,
- Your financial data such as your bank account number and IBAN number,
- Your medical diagnosis, treatment, and care service data obtained during the execution of these services, such as laboratory and imaging results you provided for tracking your file, test results, examination data, and prescription information,
- Your responses and comments shared for evaluating our services,
- Your closed-circuit camera system image and sound recording taken during your visit to our hospitals,
- Your voice call recordings kept if you contacted our Call Center,
- Your data related to private health insurance and Social Security Institution data for financing and planning of health services,
- Your vehicle plate data if you benefit from parking and valet services,
- Browsing information, IP address, browser information, and medical documents, surveys, form information, and location data you provided voluntarily during the use of our website and mobile application.
The personal data listed above and your special qualified personal data may be processed for the following purposes:
- Protection of public health, preventive medicine, execution of medical diagnosis, treatment, and care services,
- Sharing requested information with the Ministry of Health and other public institutions and organizations in accordance with relevant legislation,
- Fulfillment of legal and regulatory requirements,
- Financing your health services, covering your examination, diagnosis, and treatment expenses by Patient Services, Financial Affairs, Marketing departments, sharing requested information with private insurance companies within the scope of eligibility inquiry,
- Informing you about your appointment and other matters related to the medical service process via our Call Center, SMS, or Digital Channels,
- Verification of your identity by Patient Services, Health Professionals, and Call Center departments,
- Planning and managing the internal operations of the institution by Hospital Management,
- Analysis for the purpose of improving health services by Quality, Patient Rights, Information Systems departments,
- Training our employees by Human Resources and Quality departments,
- Monitoring and preventing abuse and unauthorized transactions by Audit and Information Systems departments,
- Carrying out risk management and quality improvement activities by Quality, Patient Rights, Information Systems departments,
- Billing for our services by Patient Services, Financial Affairs, Marketing departments,
- Verification of your relationship with institutions contracted with our hospital by Patient Services, Financial Affairs, Marketing departments,
- Responding to any questions and complaints regarding our health services by Hospital Management, Patient Rights, Call Center departments,
- Taking all necessary technical and administrative measures regarding data security of our hospital systems and applications by Hospital Management, Information Systems departments,
- Providing information about participation in campaigns and campaign information by Marketing, Media and Communication, Call Center departments, designing and communicating special content, tangible and intangible benefits on web and mobile channels,
- Measuring, increasing, and researching patient satisfaction by Hospital Management, Patient Experience departments,
- Carrying out educational activities by educational institutions in cooperation with the institution.
- Conducting scientific studies and research for the development of treatment services to be carried out by the institution and/or cooperating institution with physicians (provided that it is anonymized)
The “Personal and Special Qualified Data” mentioned above may be preserved with great care and in compliance with legal provisions in physical and electronic archives of Hisar Hospital Intercontinental and external service providers.
Transfer of Personal Data
Your personal data may be shared with the following parties within the framework of the Law No. 3359 on Basic Health Services, the Decree Law No. 663 on the Organization and Duties of the Ministry of Health and its Affiliated Institutions, the Law No. 6698 on the Protection of Personal Data, the Regulation on Private Hospitals, the Regulation on the Processing of Personal Health Data and the Protection of Privacy, and the regulations of the Ministry of Health and other legislative provisions and for the purposes explained above;
- The Ministry of Health, its affiliated subunits, and family medicine centers,
- Private insurance companies (health, retirement, life insurance, etc.),
- Social Security Institution,
- General Directorate of Security and other law enforcement agencies,
- General Directorate of Population,
- Turkish Pharmacists Association,
- Judicial authorities,
- Laboratories, medical centers, ambulances, medical devices, and health service institutions we cooperate with for medical diagnosis and treatment, both domestically and internationally,
- The health institution to which the patient is referred or the health institution the patient applies to,
- Your legal representatives whom you have authorized,
- Consultants we work with, including lawyers, tax advisors, and auditors,
- Regulatory and supervisory authorities and official authorities,
- Your employer,
- Our suppliers, support service providers, archive service providers, and business partners with whom we cooperate or benefit from their services (for more detailed information, you can inquire by writing to our hospital.)
Method and Legal Reason for Collecting Personal Data
Your personal data is collected and processed in order to carry out all kinds of work included in the legal framework of the above-mentioned purposes and the activities of Hisar Hospital Intercontinental, and to fulfill the contractual and legal obligations of Hisar Hospital Intercontinental fully and properly. The legal reason for the collection of your personal data is;
- Law No. 6698 on the Protection of Personal Data,
- Law No. 3359 on Basic Health Services,
- Decree Law No. 663 on the Organization and Duties of the Ministry of Health and its Affiliated Institutions,
- Regulation on Private Hospitals,
- Regulation on the Processing of Personal Health Data and the Protection of Privacy,
- Regulations of the Ministry of Health and other legislative provisions.
Additionally, as stated in the 3rd paragraph of Article 6 of the Law, personal data related to health and sexual life can only be processed without seeking the explicit consent of the data subject by persons or authorized institutions and organizations under the obligation of confidentiality for the purposes of protecting public health, preventive medicine, execution of medical diagnosis, treatment and care services, and planning and management of health services and financing.
Your Rights Regarding the Protection of Personal Data
According to the Law and relevant legislation;
- You have the right to learn whether your personal data is processed,
- If your personal data is processed, you have the right to request information regarding it,
- You have the right to access your personal health data and request this data,
- You have the right to learn the purpose of processing your personal data and whether it is used in accordance with its purpose,
- You have the right to know the third parties to whom your personal data has been transferred, domestically or abroad,
- You have the right to request the correction of your personal data if it is incomplete or incorrectly processed,
- You have the right to request the deletion or destruction of your personal data,
- You have the right to request that the transactions for the correction of your personal data or the deletion or destruction of your personal data be notified to the third parties to whom your personal data has been transferred,
- You have the right to object to the emergence of a result against you by analyzing your processed data exclusively through automated systems,
- You have the right to request compensation for damages in case you suffer damage due to the unlawful processing of your personal data.
Data Security and Right to Apply
Your personal data is meticulously protected within the limits of technical and administrative possibilities, and necessary security measures are provided at an appropriate level considering possible risks and technological possibilities.