Personal Data Retention and Destruction Policy
The policy document setting out, in accordance with Law no. 6698 and the related Regulation, in which environments and for how long personal data is retained, and how it is destroyed.
The data controller, Neda Deniz Uluslararası Sağlık Turizmi Hizmetleri Limited Şirketi, retains and destroys your personal data in accordance with the general principles and provisions set out in this Personal Data Retention and Destruction Policy, which has been prepared in compliance with the Constitution, Personal Data Protection Law no. 6698, the Regulation on the Deletion, Destruction or Anonymisation of Personal Data and other relevant legislation.
The purpose of this Policy is to set out the general principles governing the retention and destruction of the data of natural persons that is subject to the company's personal data processing activities under the Personal Data Protection Law, and to fulfil the obligations established by the legislation.
Definitions
- Explicit consent: Consent relating to a specific matter, based on information and expressed by free will.
- Recipient group: The category of natural or legal person to whom personal data is transferred by the data controller.
- Anonymisation: Rendering personal data incapable of being associated with an identified or identifiable natural person in any way, even by matching it with other data.
- Relevant user: Persons who process personal data within the data controller's organisation, or in accordance with the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.
- Destruction: The deletion, destruction or anonymisation of personal data.
- Personal data: Any information relating to an identified or identifiable natural person (e.g. name and surname, Turkish ID number, e-mail address, address, date of birth, credit card number, bank account number).
- Data subject: The natural person whose personal data is processed.
- Processing of personal data: Any operation performed on data, such as obtaining, recording, storing, retaining, altering, reorganising, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, by wholly or partly automated means or by non-automated means provided that it forms part of a data recording system.
- Special categories of personal data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, denomination or other beliefs, appearance and dress, membership of an association, foundation or trade union, health, sexual life, criminal convictions and security measures, together with biometric and genetic data.
- Periodic destruction: The deletion, destruction or anonymisation carried out of the company's own motion at the recurring intervals set out in this Policy, where all of the conditions for processing personal data contained in the Personal Data Protection Law cease to exist.
The recording environments governed by the Policy
The Policy covers all personal data that is subject to data processing activities under the Personal Data Protection Law. The documents referred to in the Policy also cover both physical and digital copies.
Personal data processed by wholly or partly automated means, or by non-automated means provided that it forms part of a data recording system, is retained in the following environments: company computers, e-mail accounts, desktop computers, employees' devices (e.g. mobile telephones), backup storage, paper files, folders, the visitors' book, CDs, DVDs, USB drives, external hard drives, printers and photocopiers.
The reasons requiring retention and destruction
The following principles form the basis of our personal data processing activities:
- Compliance with the law and with the rule of good faith.
- Ensuring that personal data is accurate and, where necessary, up to date.
- Processing for specific, explicit and legitimate purposes.
- Being relevant, limited and proportionate to the purposes for which it is processed.
- Retention for the period stipulated in the relevant legislation or required for the purpose of processing.
Our company retains and uses personal data for personal data processing purposes and on the basis of the conditions for processing set out in Articles 5 and 6 of the Personal Data Protection Law below, and where all of those conditions cease to exist, destroys the personal data of its own motion or upon the request of the data subject:
- The explicit consent of the data subject: The first of the conditions for processing personal data is the explicit consent of the data subject.
- Expressly provided for by law: Where it is expressly provided for by law, the data subject's personal data may be lawfully processed without their explicit consent being obtained.
- Inability to obtain explicit consent due to actual impossibility: The data subject's personal data may be processed where it is necessary to process it in order to protect the life or physical integrity of the person themselves or of another person, where that person is unable to express their consent due to actual impossibility or whose consent cannot be given legal validity.
- Directly related to the conclusion or performance of a contract: Personal data may be processed where it is necessary to process the personal data of the parties to a contract, provided that it is directly related to the conclusion or performance of that contract.
- Legal obligation: Where processing is necessary for our company to fulfil its legal obligations, the data subject's data may be processed.
- Personal data made public: Where the data subject has themselves made their personal data public, that personal data may be processed to the extent that it has been made public.
- Necessity for the establishment or protection of a right: Where processing is necessary for the establishment, exercise or protection of a right, the data subject's personal data may be processed.
- Necessity for the legitimate interests of the company: Where processing is necessary for the legitimate interests of our company, provided that it does not harm the fundamental rights and freedoms of the data subject, the data subject's personal data may be processed.
The deletion, destruction or anonymisation of personal data
Personal data is deleted, destroyed or anonymised by the company upon the request of the data subject or of its own motion where: the provisions of the relevant legislation forming the basis of its processing are amended or repealed; the purpose requiring its processing or retention ceases to exist; the data subject withdraws their explicit consent in cases where personal data is processed solely on the basis of explicit consent; or the maximum period requiring the retention of the personal data has elapsed and there is no condition justifying its retention for a longer period.
Unless a decision to the contrary is taken by the Personal Data Protection Board, our company selects the appropriate method of deleting, destroying or anonymising personal data of its own motion, according to technological means and the cost of implementation. Where the data subject so requests, the reasoning for the chosen method is explained. The necessary technical and administrative measures are taken in each of these operations.
The technical and administrative measures taken
In accordance with Article 12 of the Personal Data Protection Law and the provisions of the Regulation, the general principles set out above, this Policy and the decisions of the Personal Data Protection Board, our company takes the following measures according to technological means and the cost of implementation:
- The necessary software and hardware have been identified. Strong passwords are used on computers and e-mail accounts.
- What needs to be protected in terms of safeguarding customer information has been communicated to our staff through training, and their responsibilities have been set down in writing in their employment contracts (confidentiality agreements). This obligation continues after the individuals concerned have left their post.
- The necessary infrastructure has been established for backing up all data.
- The employees who may access the data on the computers have been identified.
- Customer files and information are provided only to the individuals concerned, to relatives for whom they have given written consent, to the relevant public institutions and organisations within the framework of the legislation, and to the competent judicial authorities in legal proceedings.
- The obligation to inform the individuals concerned is fulfilled before personal data processing begins.
- A personal data processing inventory has been prepared.
Retention and destruction periods
Our company retains personal data only for the period stated in the legislation with which it is obliged to comply, or required for the purpose for which it is processed, and destroys it at the end of that period.
| Process | Retention period | Destruction period |
|---|---|---|
| The preparation of contracts | 10 years from the end of the contract | At the first periodic destruction following the end of the retention period |
| Carrying out human resources processes | 10 years from the end of the activity | At the first periodic destruction following the end of the retention period |
| Carrying out hardware and software access processes | 5 years | At the first periodic destruction following the end of the retention period |
| Records of visitors and meeting participants | 5 years | At the first periodic destruction following the end of the retention period |
| Records of personal health data | For the period stated in the applicable legislation | At the first periodic destruction following the end of the retention period |
| Identity data | For the period stated in the applicable legislation | At the first periodic destruction following the end of the retention period |
| Camera footage | At least 2 months, as required by the Private Hospitals Regulation | At the first periodic destruction following the end of the retention period |
Destruction upon application
Where the data subject applies to our company requesting the destruction of their personal data:
- If all of the conditions for processing have ceased to exist: the request is concluded within thirty days at the latest and the data subject is informed. If the personal data subject to the request has been transferred to third parties, this is notified to the third party and the necessary steps are ensured to be taken by that third party.
- If not all of the conditions for processing have ceased to exist: the request may be refused with reasons given, in accordance with the third paragraph of Article 13 of the Personal Data Protection Law; the refusal is notified to the data subject in writing or electronically within thirty days at the latest.
Periodic destruction periods
Personal data is destroyed at the first periodic destruction following the date on which the obligation to destroy it arises. Accordingly, where the obligation to destroy arises, data is subject to destruction at six-monthly intervals.
This Policy is deemed to have entered into force upon its publication on the website.
Contact
Data controller: Neda Deniz Uluslararası Sağlık Turizmi Hizmetleri Limited Şirketi
Address: ATA2, Atatürk, Ataşehir Blv. B2 Blok No: 6 Suite No: 35, 34758 Ataşehir / Istanbul
E-mail: info@nedadeniz.com