Antalya · Gynecologic Oncology · Advanced Surgery

PRIVACY AND PERSONAL DATA PROTECTION POLICY

Last updated: 3 August 2026

1. Purpose and Scope of the Policy

This Privacy and Personal Data Protection Policy has been prepared to explain how the personal data of individuals who visit www.evrimerdemoglu.com, submit contact or appointment requests, or provide information through the website is collected, used, stored and protected, and with whom such data may be shared.

Your personal data is processed in accordance with the Turkish Personal Data Protection Law No. 6698 and other applicable legislation. Personal data processing activities are carried out:

  • Lawfully and fairly,
  • For specified, explicit and legitimate purposes,
  • In a manner relevant, limited and proportionate to the purposes of processing,
  • Accurately and, where necessary, up to date,
  • For no longer than required by applicable legislation or the relevant processing purpose.

Reading this Policy or confirming that you have been informed does not, by itself, constitute explicit consent. Where explicit consent is legally required, it will be requested separately and clearly.

2. Data Controller

For the purposes of the Turkish Personal Data Protection Law No. 6698, the data controller is:

Data Controller: Prof. Dr. Evrim Erdemoğlu / [Official professional or commercial title]
Address: [Full business or official notification address]
Telephone: [Telephone number]
Email: [Contact email address]
Data protection application email: [KVKK application email address]
Registered electronic mail address: [KEP address, if applicable]
Website: www.evrimerdemoglu.com

Where healthcare services are provided through a healthcare institution or legal entity, the data controller details must be updated according to the official information of the relevant institution or entity.

3. Categories of Personal Data That May Be Processed

Depending on how you use the website and the scope of your communication with us, the following categories of personal data may be processed:

Identity Information

First name, surname, age, date of birth and other information required to identify or verify an individual.

Contact Information

Telephone number, email address, country, city, preferred method of communication and preferred language.

Appointment and Enquiry Information

Requested appointment date, subject of the enquiry, content of the request, preferred consultation method, communication history and appointment history.

Health Information

Health complaints, symptoms, medical conditions, diagnoses, previous treatments, surgical history, medications, medical examinations, reports, images and other health-related information voluntarily provided by the user.

Health information is considered a special category of personal data. It is processed only where necessary and where the processing conditions specified under applicable legislation are satisfied.

Website Usage and Information Security Data

IP address, access date and time, browser and device information, operating system, website traffic records, error logs, access records and security logs.

Marketing and Communication Preferences

Preferences regarding commercial electronic communications, information and promotional communications, marketing permissions and cookie settings.

Visual and Audio Data

Photographs, videos, voice recordings or visual and audio content submitted by the user during online consultations, remote communications or other interactions.

Where a video or audio recording is to be made, the user will be separately informed in advance.

4. Methods of Collecting Personal Data

Personal data may be collected electronically or physically through:

  • Contact and appointment forms on the website,
  • Telephone calls,
  • Email correspondence,
  • SMS and messaging applications,
  • WhatsApp and similar communication channels,
  • Face-to-face or online consultations,
  • Cookies and similar technologies,
  • Website server and security logs,
  • Documents, reports, photographs and files submitted by users,
  • Appointment, CRM or patient communication systems,
  • Authorised individuals or healthcare institutions designated by the user.

Users are advised not to send detailed health reports, identity documents or special categories of personal data that are not necessary through the general contact form.

Where such documents are required, an appropriate secure communication channel may be provided separately.

5. Purposes of Processing Personal Data

Personal data may be processed for the following purposes:

  • Receiving and responding to contact and appointment requests,
  • Contacting users regarding their enquiries,
  • Providing preliminary information and guidance,
  • Planning examinations, consultations and treatment processes,
  • Planning and managing medical assessment, diagnosis, treatment and care services,
  • Managing requests from patients located in Türkiye or abroad,
  • Communicating with users in their preferred language,
  • Improving service quality and user experience,
  • Ensuring website and system security,
  • Preventing unauthorised access, fraud and misuse,
  • Detecting and resolving technical errors,
  • Complying with legal obligations,
  • Responding to lawful requests from authorised institutions and authorities,
  • Establishing, exercising or protecting legal rights,
  • Sending informational or promotional communications where the user has separately consented,
  • Conducting statistical and performance analysis based on the user’s cookie preferences.

An application submitted through the website does not constitute a definitive medical diagnosis or treatment.

In a medical emergency, the website forms must not be used. Users should contact the 112 Emergency Call Centre or the nearest healthcare institution.

6. Legal Grounds for Processing Personal Data

Depending on the relevant processing activity, personal data may be processed on one or more of the following legal grounds:

  • Processing is expressly provided for by law,
  • Processing is necessary for the establishment or performance of a contract,
  • Processing is necessary for the data controller to comply with a legal obligation,
  • Processing is necessary for the establishment, exercise or protection of a legal right,
  • Processing is necessary for the legitimate interests of the data controller, provided that the fundamental rights and freedoms of the data subject are not adversely affected,
  • The conditions prescribed by applicable healthcare legislation are satisfied,
  • The data subject has given freely provided, specific and informed explicit consent where consent is legally required.

Where another valid legal basis exists, explicit consent will not be requested unnecessarily.

7. Special Categories of Personal Data and Health Information

Health information is a special category of personal data and is subject to enhanced protection.

Health information may be processed only where necessary for:

  • Assessing your enquiry,
  • Planning or providing healthcare services,
  • Medical diagnosis, treatment and care,
  • Managing healthcare services,
  • Complying with legal obligations relating to healthcare,
  • Establishing, exercising or protecting legal rights.

Health information is processed only where the conditions prescribed under applicable legislation are satisfied.

Appropriate technical and organisational measures are implemented to protect health information, including:

  • Restricting access authorisations,
  • Protecting records against unauthorised access,
  • Using secure transmission methods,
  • Maintaining confidentiality obligations,
  • Monitoring access and security records.

8. Transfer of Personal Data

Where necessary for the stated purposes and legally permitted, personal data may be transferred to:

  • Authorised employees and healthcare professionals,
  • Healthcare institutions where examination or treatment is provided,
  • Laboratories, medical imaging centres and other healthcare service providers,
  • Information technology, hosting, server, maintenance and cybersecurity providers,
  • Email, SMS, call centre and messaging service providers,
  • Appointment and patient communication system providers,
  • Accountants, legal advisers and consultants,
  • Auditors and insurance providers,
  • Authorised public authorities, courts and administrative bodies,
  • Persons acting upon the user’s express request or authorisation.

Personal data is shared with service providers only to the extent necessary for the relevant service. Service providers are not authorised to use the data for their own independent purposes unless another valid legal basis applies.

9. International Transfer of Personal Data

Where hosting, cloud storage, email, analytics, cybersecurity, appointment, video consultation or messaging services use servers located outside Türkiye, personal data may be transferred internationally.

International transfers are carried out only where the requirements and appropriate safeguards under Article 9 of the Turkish Personal Data Protection Law No. 6698 and the applicable secondary legislation are satisfied.

Where international transfer must be based on explicit consent, the user’s consent will be requested separately from this Policy and any privacy notice.

10. Cookies and Similar Technologies

The website may use cookies and similar technologies to ensure proper and secure operation and to improve the user experience.

The following cookie categories may be used:

Strictly Necessary Cookies

These cookies are required for website functionality, security, form operations and saving user preferences.

Functional Cookies

These cookies allow language, region and display preferences to be remembered.

Performance and Analytics Cookies

These cookies help measure visitor numbers, page usage, traffic sources, website performance and technical issues.

Advertising and Marketing Cookies

These cookies may be used to measure advertising performance and, where the user has given consent, to provide relevant advertising or conduct remarketing activities.

Non-essential cookies are not activated before the user has given permission where consent is legally required.

Users can manage their cookie preferences through the Cookie Settings or Cookie Preferences panel.

The names, providers, purposes and retention periods of cookies used on the website are described separately in the Cookie Policy or cookie preference panel.

11. Third-Party Services and External Links

The website may contain services, content or links provided by third parties, including:

  • Mapping services,
  • Video platforms,
  • Social media networks,
  • Messaging services,
  • Analytics platforms,
  • Appointment systems.

When users access third-party websites or applications, the privacy and cookie policies of the relevant third party apply.

The data controller is not responsible for the independent personal data processing activities of third-party providers.

12. Retention Periods

Personal data is retained for:

  • The period required for the relevant processing purpose,
  • The retention periods prescribed under healthcare, tax, commercial, consumer and other applicable legislation,
  • The period required to comply with legal obligations,
  • Applicable limitation periods relating to possible legal disputes.

When the applicable retention period expires and no other valid legal basis exists, personal data is deleted, destroyed or anonymised in accordance with applicable legislation.

13. Personal Data Security

Appropriate technical and organisational measures are implemented to prevent personal data from being:

  • Processed unlawfully,
  • Accessed without authorisation,
  • Disclosed without authorisation,
  • Altered unlawfully,
  • Lost, damaged or destroyed.

Depending on the nature of the processing activity, these measures may include:

  • Access and authorisation controls,
  • Strong passwords and authentication mechanisms,
  • Up-to-date security software,
  • Encrypted and secure connections,
  • Firewalls and malware protection,
  • Logging and monitoring of system access,
  • Regular backups,
  • Confidentiality obligations for employees and service providers,
  • Data protection clauses in service agreements,
  • Data breach detection and response procedures.

No method of transmission over the internet is completely risk-free. Nevertheless, reasonable and current security safeguards are implemented to protect personal data.

14. Rights of the Data Subject

Under Article 11 of the Turkish Personal Data Protection Law No. 6698, data subjects have the right to apply to the data controller and:

  • Learn whether their personal data is being processed,
  • Request information where their personal data has been processed,
  • Learn the purpose of processing and whether the data is used in accordance with that purpose,
  • Learn the third parties to whom their personal data has been transferred,
  • Request correction of incomplete or inaccurate personal data,
  • Request deletion or destruction where the legal requirements are satisfied,
  • Request notification of correction, deletion or destruction to third parties to whom the data has been transferred,
  • Object to a result arising against them through analysis conducted exclusively by automated systems,
  • Claim compensation where they suffer damage due to unlawful processing.

15. Application Procedure

Requests relating to personal data may be submitted to the data controller through one of the following methods:

  • By personally delivering or sending a signed written application to [full postal address],
  • Through a notary public,
  • Using a secure electronic signature or mobile signature,
  • Through the registered electronic mail address [KEP address],
  • By sending an email from an address previously registered in our systems and through which identity can be verified to [data protection application email address].

The application should include:

  • First name and surname,
  • Contact details,
  • The subject and details of the request,
  • Information or documents necessary to verify identity.

Applications will be processed within the periods specified under applicable legislation.

Where the processing of the application requires an additional cost, the fees permitted under applicable legislation may be charged.

16. Personal Data Relating to Children

The website is not directly intended for children.

Applications concerning individuals under the age of 18 should preferably be submitted by a parent, guardian or legal representative.

Where a child’s health or identity information is provided, proof of parental responsibility, guardianship or legal authority may be requested.

17. Updates to the Policy

This Policy may be updated where:

  • Applicable legislation changes,
  • Decisions or guidance issued by the Turkish Personal Data Protection Authority are updated,
  • The systems and services used on the website change,
  • Personal data processing activities are modified.

The updated Policy becomes effective on the date it is published on www.evrimerdemoglu.com.

18. Contact

For questions concerning this Policy or the processing of your personal data, you may contact us using the following details:

Data Controller: [Official title]
Address: [Full address]
Telephone: [Telephone number]
Email: [Email address]
Data protection application email: [KVKK application email address]
Website: www.evrimerdemoglu.com