CLARIFICATION TEXT OF THE LAW ON PROTECTION OF PERSONAL DATA

Your personal data shall only be processed within the framework explained below and in accordance with the regulations of the Ministry of Health and Private Hospitals Directive and other relevant legislation by ÖZEL RUMELİ HASTANESİ SAĞLIK HİZMETLERİ LİMİTED ŞİRKETİ (hereinafter referred to as “PRIVATE RUMELİ HOSPİTAL”) in capacity of Data Controller within scope of Law on Protection of Personal Data (the “Law”) numbered 6698 and relevant legislation.

Your personal data shall only be processed within the framework explained below and in accordance with the regulations of the Ministry of Health and Private Hospitals Directive and other relevant legislation by ÖZEL RUMELİ HASTANESİ SAĞLIK HİZMETLERİ LİMİTED ŞİRKETİ (hereinafter referred to as “PRIVATE RUMELİ HOSPİTAL”) in capacity of Data Controller within scope of Law on Protection of Personal Data (the “Law”) numbered 6698 and relevant legislation.

  1. Obtaining Personal Data

Your personal data is obtained in verbal, written, visual or electronic ways, online via SSI system, shared records in case you benefit from private health insurance, from records of other healthcare institutions in case you have been referred from other institutions, from e-mails that you have sent, from call center records, web site, and similar verbal and written resources by Private Rumeli Hospital for the purpose of protecting public health, preventive medicine, records related to the applications you make to our health institutions, conducting medical diagnosis, treatment and care services, planning and managing health services and financing..

Your credentials: Your name, surname, citizenship number, passport number or temporary citizenship number, birthplace and date, marital status, gender, insurance and/or patient protocol number and other identification data that may identify you,

Your Contact Details: Your address, telephone number, e-mail address and other contact data, patient number and protocol number,

Your personal data collected by customer representatives or patient services in accordance with call center standards and your personal data obtained when you contact us by e-mail, letter or other means,

Your accounting information: Your financial data such as your bank account number, IBAN number, credit card information on the slip, billing and invoicing information,

Your data on private health insurance and Social Security Institution data for financing and planning of health services,

Your Health Information: All kinds of personal data information of yours obtained in during or in consequence of performance of medical diagnosis, treatment and healthcare  activities, including but not limited to medical reports, diagnosis data, biometrics and genetic data, laboratory results, test results, examination data, appointment data, prescription data.

Your health data including but not limited to laboratory and imaging results, test results, examination data, check-up data, prescription data from external institutions that you submitted to your patient file.

Your feedbacks such as questionnaires filled out by the patients, letters of thanks and complaints, results of satisfaction etc,

Your images and sound recordings obtained from camera recordings that are constantly recorded in common areas of our hospital in accordance with the legislation,

Your personal data obtained when you attend the trainings, seminars or organizations organized by Private Rumeli Hospital,

Your health data and other personal data that you send or enter on all websites of Private Rumeli Hospital,

We hereby declare that we will record and process your personal data including your resume submitted for this purpose in case you apply for a job at the Private Rumeli Hospital, and your personal data related with your labor contract in case you are an employee or associated employee of Private Rumeli Hospital in accordance with the terms and conditions stipulated in Law of Protection of Personal Data.

2. Processing of Personal Data, Processing Tools

Any personal data obtained by Private Rumeli Hospital (including but not limited to special personal data) may be processed for the following purposes:

3. Transfer of Personal Data

Subject to the conditions set out in the Law on Protection of Personal Data and for the purpose of public health and preventive medicine services.

Your personal data, within the scope of the law and other legislation and for the above purposes, may be shared by Private Rumeli Hospital with Private insurance companies, Ministry of Health and related units, Provincial Health Directorate, District Health Directorate, Public Health Centers and other units affiliated to the Ministry of Health, Social Security Institution, General Directorate of Security and other law enforcement agencies, General Directorate of Civil Registry, Turkey Pharmacists Association, the courts and all kinds of judicial authorities, central and other third parties, your representative you have authorized, lawyers, tax and financial advisors third parties we receive counseling, including regulatory and our business partners and other collaborators, if required by the supervisory bodies, official authorities or within the scope of the e-pulse and similar systems established, or within the scope of our obligation of notification and / or reporting imposed on us, for the purposes stated above, or in case of dispute when necessary,

4. The Method and Legal Grounds of Collecting Personal Data

Depending on the nature of the service provided, your personal data is collected from the call center, switchboard, internet, mobile applications, physical locations and similar channels, verbally, visually, in writing or electronically, within the scope of the above-mentioned purposes.

Your personal data is collected and processed in any verbal, written or electronic environment, within the framework of the legal regulations regarding the above-mentioned purposes and the purpose of providing health services within the specified legal framework and within this scope, in order Private Rumeli Hospital to fulfill its contractual and legal obligations.

In addition, the legal grounds for the processing of your personal data mentioned above: Your personal data may be processed for the purposes of fulfilling obligations arising from secondary legislations such as Private Hospitals Law numbered 2219, Basic Healthcare Services Law numbered 3359, governmental decree concerned with Organization and duties of the Ministry of Health and Associated Organizations, Directives of Private Hospitals, Communique of Healthcare Practices, protection of public health, carrying out of preventive medicine, medical diagnosis, treatment and care services, planning and management of financing of health services, in accordance with Directives of Processing and safeguarding of personal health data, regulations of the Ministry of health and other legislation, and can be kept in both digital and physical environment by being transferred to the physical archives and/or information systems of  Private Rumeli Hospital.

5. Your Rights Concerned with Protection of Your Personal Data

We would like to inform you that, by applying to our Health Institution within the scope of Article 11 of the Personal Data Law as a personal data subject, you have right to know whether your personal data is processed in accordance with the legislation regarding your processed personal data, to request information in case your personal data has been processed; to access to and requesting your personal health data; to learn the purpose of processing of your personal data and whether it is used in accordance with its purpose; to know the third parties to whom your personal data has been transferred domestically or abroad; to request notification of your demand to correction or destruction of your personal data to third parties to whom your personal data has been transferred in case your personal data is incomplete or incorrectly processed; to object to the occurrence of an unfavorable  result against the person as a consequence of analyzing the processed data exclusively through automated systems, and to request the remedy for  the damage in the event that the personal data is damaged due to unlawful processing.

In case you exercise your right to learn whether personal data has been processed, your right to request information if your personal data has been processed; your right to access and request personal health data, to learn about the purpose of processing your personal data, and whether it is used in accordance with this purpose, or your right to know the third parties to whom your personal data is transferred in land or abroad, the relevant information will be communicated to you in clear and understandable manner in writing or electronically via the contact details provided by you.

6. Security Measures Taken Regarding Your Personal Data

Our Healthcare Institution, which performs data processing activities such as obtaining, saving, storing, preserving, modifying, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing your personal data as a data controller is responsible for proving security measures at a reasonable level and takes this measures at the utmost level for purposes;

a) To prevent your personal data from being processed unlawfully,

a) To prevent your personal data from being accessed unlawfully,

c) and to provide security for personal data. In addition, additional security measures, which are not limited to the following, are taken by the Personal Data Protection Board in the processing of special personal data.

Our employees are trained on information security, patient privacy, personal data protection, corporate policies and procedures are in force about personal data security, they are destroyed when the purpose of processing personal data is eliminated, our systems containing personal data are routinely audited, contracts are made with data processors, current software are used, we have a security network organized against cyber-attacks, access to systems containing personal data is limited, antivirus and anti-spam programs are used, information networks related to security problems are constantly monitored, tests are carried out to identify system weaknesses, there is a corporate reporting system about problems, in case systems are misused, the evidence is collected and reported to the Personal Data Protection Authority, and a criminal complaint is made to the Prosecutor’s Office. Protection measures against natural disasters have been taken and these environments are kept locked and the entrances/exits are under control.

7. Complaint and Communication

In case you desire to exercise your rights or you have requests within the scope of the above articles, you can fill in the Personal Data Access and Information Request Form on our website and sign the file with a secure e-signature and send it to info@rumelihospital.com.tr or send a hard copy petition with wet signature by courier to Patient Affairs Unit at Tevfik Bey Mah. Mektep Sok. No:11 Sefaköy / Küçükçekmece İSTANBUL.

Click here for Access / Information request form