Personal data protection
Patient Personal Data Notice
Information about the processing of patient personal and health data under Turkish Personal Data Protection Law No. 6698.
1. Data controller
Your personal data is processed by Ersa Dental Ağız ve Diş Sağlığı Polikliniği Sağlık Hizmetleri Limited Şirketi, operating at Pınartepe Mah. Avrupa Cad. No:73/1H, Interior Door No:22, Büyükçekmece, Istanbul, Türkiye. The notice covers data recorded in the DentSoft system while the clinic provides patient services.
2. Definitions and principles
Personal data means information relating to an identified or identifiable person. Processing includes collecting, recording, storing, changing, transferring, making available, classifying or restricting use. Data is processed lawfully, fairly, accurately, for specified and legitimate purposes, in a relevant and proportionate manner, and retained only for the period required by law or purpose.
3. Processed data categories
| Identity | Name, Turkish identity number where applicable, nationality, date of birth and gender. |
|---|---|
| Contact | Phone, email and address. |
| Professional | Occupation. |
| Patient transaction | Patient type, referral, doctor, contracted institution, health-tourism information, invoice, appointments, services, notifications and last visit. |
| Financial | Balance, treatment amount, payments and payment method. |
| Health | Conditions, medication, operations, blood group, treatment, X-rays, reports, prescriptions, dental condition and previous treatment. |
| Other | Parent or guardian details, oral-care habits and other information supplied for care administration. |
4. Collection methods
Information may be obtained verbally, through written forms, during the provision of care or through electronic communication, in accordance with applicable processing conditions.
5. Purposes and legal grounds
Data may be used to provide and administer care, communicate, schedule appointments, conduct clinical and business operations, meet legal and accounting duties, manage contracts, invoices, archives, suppliers, continuity, patient relations and post-service support. Legal grounds may include performance of a contract, compliance with legal obligations, legitimate interests that do not override fundamental rights and, for health data where required, explicit consent.
6. Data transfers
Using need-to-know, data-minimisation and appropriate safeguards, data may be shared with domestic service providers, with overseas service providers where explicit consent is required, and with authorised public bodies where legally necessary.
7. Your rights and applications
You may ask whether your data is processed, request information, learn the purpose and recipients, request correction, deletion or destruction where conditions are met, request notification of those actions to recipients, object to solely automated adverse results and claim compensation for unlawful processing. Submit a clear, identity-verifiable request in writing to the clinic address or from your registered email to [email protected]. Requests are answered within the statutory period; an official tariff may apply where processing creates an additional cost.
8. Explicit consent for health data
Where explicit consent is the applicable legal ground, consent covers processing and transfer of the health information described in this notice for clinical operations, continuity, legal compliance and the provision of services. Consent must be informed, specific and freely given.