Alsancak, Izmir FEBO and FICO International Ophthalmology Qualifications +90 547 917 11 37

KVKK Data Subject Application Form and Policies

Data Controller: Assoc. Prof. Dr. Berkay Akmaz Entity Name: Assoc. Prof. Dr. Berkay Akmaz Private Practice Website: https://drberkayakmaz.com Publication and Update Date: August 22, 2026 SECTION 1. KVKK DATA SUBJECT APPLICATION FORM 1. Purpose of the Application This form is designed for data subjects to submit their requests regarding their rights under Article 11 of […]

Data Controller: Assoc. Prof. Dr. Berkay Akmaz

Entity Name: Assoc. Prof. Dr. Berkay Akmaz Private Practice

Website: https://drberkayakmaz.com

Publication and Update Date: August 22, 2026

SECTION 1. KVKK DATA SUBJECT APPLICATION FORM

1. Purpose of the Application

This form is designed for data subjects to submit their requests regarding their rights under Article 11 of the Personal Data Protection Law No. 6698 ("KVKK") to the data controller, Assoc. Prof. Dr. Berkay Akmaz.

The use of this form is optional. Applications containing the mandatory information specified in the KVKK and the Communiqué on the Procedures and Principles of Application to the Data Controller may also be submitted separately through the methods described below.

2. Data Controller and Application Channels

Data Controller: Assoc. Prof. Dr. Berkay Akmaz

Entity Name: Assoc. Prof. Dr. Berkay Akmaz Private Practice

Written Application Address: Kültür Mahallesi, Talatpaşa Bulvarı No:4/A, Alsancak, Konak/İzmir

Email: [email protected]

Inquiry Phone: +90 547 917 11 37

Applications can be made using one of the following methods:

  • Delivering the signed application in person to the above address, or sending it via post or notary.

  • Sending the application prepared using a secure electronic signature or mobile signature to the above email address.

  • Applying to the above email address using an email address previously reported to the practice and recorded in the practice's records.

  • Applying through a dedicated application system available on the website that provides identity verification and secure data transmission, if available.

It is recommended to write "KVKK Data Subject Application" on the postal envelope or in the email subject field to expedite the evaluation process. The phone line can be used for informational purposes. Phone calls alone do not replace written application methods.

3. Applicant Identity and Contact Information

Information Field Information to be Filled by Applicant
First and Last Name [First and Last Name]
T.C. ID Number (for Turkish citizens) [T.C. ID Number]
Nationality (for foreign nationals) [Nationality]
Passport or ID Number (for foreign nationals) [Passport or ID Number]
Residential or Workplace Address for Notification [Full Address]
Email Address, if any [Email Address]
Phone Number, if any [Phone Number]
Fax Number, if any [Fax Number]
Relationship with the Practice [Patient / Patient relative / Guardian / Custodian / Visitor / Website user / Other]
Capacity of Representation (if applying on behalf of another) [Proxy / Guardian / Custodian / Other legal representative]
Preferred Response Method [Email / Post / In-person delivery]

The application must contain the first name, last name, identity information appropriate for the relevant citizenship status, address for notification, and the subject of the request. Written applications must also be signed. Documents proving representation authority may be requested if applying on behalf of someone else. Identity copies, medical reports, and other documents that are not necessary for evaluating the application should not be sent. If document submission is mandatory, irrelevant information may be redacted appropriately.

4. Rights Exercised

The applicable request(s) below may be checked:

  • I want to learn whether my personal data is processed.

  • If my personal data has been processed, I request information regarding this.

  • I want to learn the purpose of processing my personal data and whether it is used in accordance with its purpose.

  • I want to know the third parties to whom my personal data is transferred domestically or abroad.

  • I request the correction of my incomplete or incorrectly processed personal data.

  • I request the deletion or destruction of my personal data if the conditions specified in Article 7 of the KVKK are met.

  • I request that the third parties to whom my personal data has been transferred be notified of correction, deletion, or destruction operations.

  • I object to any outcome against me resulting exclusively from the analysis of my personal data through automated systems.

  • I request compensation for damages incurred due to the unlawful processing of my personal data.

Subject of Request and Explanation:

[Clearly state your request, which information or record it relates to, and the relevant date range if applicable. Do not share medical details not necessary for evaluating the application.]

Attachments, if any:

[Specify only documents necessary to evaluate the request or verify representation authority.]

5. Applicant's Declaration

I have been informed that the information provided in this application will be processed for the purposes of verifying my identity, evaluating my application, finalizing my request, and responding to me.

Information Field to be Filled by Applicant
First and Last Name [First and Last Name]
Application Date [DD/MM/YYYY]
Signature (for written applications) [Signature]

6. Clarification Regarding Application Data

Identity, contact, representation, and request data processed through this form are processed for the purposes of verifying that the application belongs to the data subject, reviewing the request, responding within the statutory period, fulfilling legal obligations, and proving the application process when necessary.

Personal data relating to the application is processed based on the legal grounds of fulfilling a legal obligation under Article 5/2(c) of the KVKK and establishing, exercising, or protecting a right under Article 5/2(e), depending on the nature of the processing activity. If evaluating health data is mandatory for examining the application, only the necessary data is processed within the scope of establishing, exercising, or protecting a right regulated in Article 6/3(d) of the KVKK and subject to confidentiality obligations.

Application information may be transferred to authorized employees, legal advisors, authorized administrative or judicial authorities, and service providers ensuring secure transmission of the application, to the extent necessary. This form is not an explicit consent text. Submitting an application does not mean granting explicit consent for advertising, marketing, non-essential cookies, or any other data processing activity.

If an electronic application mechanism is used on the website, the T.C. ID number, health information, and application attachments will not be transferred to advertising, analytics, or retargeting tools. Application fields are protected by secure connections, access authorization, and appropriate technical measures.

7. Evaluation of Application

Applications are finalized as soon as possible according to the nature of the request, and in any case within 30 days at the latest from the date the request reaches the data controller. As a rule, applications are free of charge. If the transaction requires an additional cost, a fee may only be charged according to the tariff set by the Personal Data Protection Board in force.

Additional identity verification or clarification regarding the application may be requested, provided it is necessary and proportionate to finalize the request securely. In case of rejection, the reasons for rejection are communicated to the data subject.

If the application is rejected, the response provided is deemed insufficient, or no response is given within the due time, the data subject may file a complaint with the Personal Data Protection Board within 30 days from learning of the answer, and in any case within 60 days from the application date.

SECTION 2. PERSONAL DATA RETENTION AND DISPOSAL POLICY

1. Purpose, Scope, and Legal Basis

This Policy regulates the lawful retention of personal data processed by Assoc. Prof. Dr. Berkay Akmaz Private Practice for the necessary period, and its deletion, destruction, or anonymization when the grounds for retention cease to exist.

The Policy covers data belonging to patients, potential patients, patient relatives, companions, legal representatives, visitors, website users, applicants, employees, and real persons related to service providers.

The Policy has been prepared based on the KVKK, Regulation on the Deletion, Destruction, or Anonymization of Personal Data, Regulation on Personal Health Data, health legislation, tax legislation, labor and social security legislation, and other applicable regulations. Statutory retention periods in legislation apply primarily for each record type.

2. Definitions

  • Personal data: Any information relating to an identified or identifiable natural person.

  • Special categories of personal data: Personal data subject to special protection under Article 6 of the KVKK, including health data.

  • Recording medium: Any physical or electronic medium where personal data is processed, stored, or backed up.

  • Deletion: Making data inaccessible and non-reusable for relevant users.

  • Destruction: Making data inaccessible, unrecoverable, and non-reusable by anyone.

  • Anonymization: Rendering data impossible to link to an identified or identifiable natural person under any circumstances, even if matched with other data. Using pseudonyms or masking alone does not constitute anonymization.

  • Periodic disposal: The process of deleting, destroying, or anonymizing personal data whose retention conditions no longer exist, at predetermined, repeating intervals.

3. Data Controller and Recording Media

The data controller within the scope of this Policy is Assoc. Prof. Dr. Berkay Akmaz. Application and contact details are available in Section 1 of this page.

Depending on the processing activity performed, personal data may reside in the following media:

  • Printed patient files, examination records, consents, receipts, correspondence, and locked archives.

  • Practice computers, authorized mobile devices, patient and appointment applications, and electronic record systems.

  • Website hosting infrastructure, contact and application forms, technical security logs, and cookie management systems.

  • Email, phone, SMS, and messaging applications (if used).

  • Security camera systems in common areas.

  • Local or online backup media, and authorized public and health information systems only when necessary.

If a service infrastructure providing access abroad is used, transfer conditions under Article 9 of the KVKK are evaluated separately. Listing a recording medium in this Policy does not mean that the relevant service is used for all data categories.

4. Legal and Operational Reasons Requiring Retention

Personal data is retained only for specific, explicit, and legitimate purposes and for as long as necessary. Reasons for retention are:

  • Conducting appointment, examination, eye health evaluation, diagnosis, treatment, follow-up, and patient care processes.

  • Fulfilling obligations regarding files, consents, reports, prescriptions, notifications, and records related to health services.

  • Fulfilling tax, accounting, payment, labor, social security, and other legal obligations.

  • Evaluating requests, complaints from data subjects, and official authority applications.

  • Ensuring the security of the practice, visitors, and information systems.

  • Resolving disputes and establishing, exercising, or protecting legal rights.

  • Managing consent and withdrawal requests if processing is based on explicit consent.

Health data is processed by persons under confidentiality obligations, particularly under Article 6/3(f) of the KVKK, for conducting medical diagnosis, treatment, and care services. Depending on the concrete activity, other legal grounds such as explicit provision by law, establishment, exercise, or protection of a right, or separate explicit consent where necessary, are evaluated separately.

5. Reasons Requiring Disposal

Personal data will be deleted, destroyed, or anonymized in the following cases, without prejudice to applicable retention obligations and legal rights:

  • The legislative provisions serving as the basis for processing or retention become obsolete.

  • The purpose of processing is fulfilled, ceases to exist, or the data is no longer necessary.

  • Expiration of the statutory or maximum retention period specified in this Policy.

  • Withdrawal of consent (where processing relies solely on explicit consent) and absence of any other legal grounds.

  • Approval of the data subject's application for deletion or destruction.

  • Binding decision of disposal issued by the Personal Data Protection Board, a court, or an authorized body.

Requests to delete medical records are evaluated considering record obligations in health legislation, patient safety, ongoing treatment needs, and applicable legal periods. If the legal reason requiring retention persists, the record is not deleted immediately. The data subject is informed with justification, and data is kept accessible solely for the required purpose.

6. Retention and Disposal Periods

The following periods represent basic rules applied per record type. If a mandatory statutory period is set by legislation, that period applies. Operational periods of 30 days, 6 months, and 1 year expressed numerically represent the Practice's own maximum retention preference. These periods should not be interpreted as statutory retention periods applicable to all health institutions.

Data or Record Group Retention Period Disposal Time and Method
Patient files, anamnesis, eye examination, tests, diagnosis, treatment, medical consent, and health records For the mandatory duration in health legislation applicable to the record type and period necessary to protect legal rights. Concrete duration is set in the data processing inventory per record. Secure deletion, physical destruction, or anonymization (if conditions are met) at the first periodic disposal after all retention reasons cease.
Patient appointments and communication linked to patient file For the period applicable to the relevant patient record if health service was provided. Deletion at the first periodic disposal when retention grounds with or independent of patient record cease.
Website contact and appointment requests not resulting in health services Maximum six months from request resolution. Unnecessary health details in applications are pruned or deleted upon evaluation completion and at latest within 30 days. Deletion when period expires. If a patient relationship is established, necessary records move to patient file, unnecessary copies removed.
Email, SMS, and messaging correspondence Records related to patient file for duration of health record. Routine non-service correspondence max 6 months post-resolution. Secure deletion from mailbox, app, and archive. If necessary, minimal content transferred to patient file.
Accounting documents, payment info, receipts, and financial records Mandatory duration under tax, accounting, and relevant financial legislation. Deletion or physical destruction at first periodic disposal upon expiration of legal periods and retention reasons.
Employee and service provider records Duration under labor, social security, OHS, contract, and related legislation. Deletion or physical destruction at first periodic disposal upon expiration of legal periods.
Common area security camera footage As a rule, max 30 days. In case of security event, official request, or dispute, relevant event records kept separately as needed. Automatic overwriting, secure deletion, or physical destruction of recording medium.
Website access and security logs Duration necessary for info security, max 1 year as a rule. Mandatory statutory period governs if different. Secure deletion or anonymization preventing identity re-linkage at period end.
Cookie records and preference info Duration necessary for cookie function and lifespan specified in cookie panel. Valid preference required for non-essential cookies. Deletion or disabling upon period expiry or valid preference withdrawal.
KVKK applications, complaints, and responses Duration necessary to finalize application, legal remedies, burden of proof, and applicable statute of limitations. Secure deletion or physical destruction at first periodic disposal upon termination of retention grounds.
Explicit consent, withdrawal, and contact preference records Duration consent remains valid and necessary to prove processing lawfulness. Minimal proof record kept post-withdrawal. Deletion at first periodic disposal when proof and legal retention needs expire.
Legal disputes, official requests, and investigation files For duration of dispute, investigation, legal obligation, and applicable statute of limitations. Deletion or physical destruction at first periodic disposal when retention/evidence needs cease.
Records in backups deleted from active systems Until next secure backup cycle, max 6 months as a rule. Secure deletion, cryptographic erasure, or physical destruction of backup during backup cycle. Deleted records not restored to active systems.
Deletion, destruction, and anonymization process logs At least 3 years from transaction date. Longer mandatory legal period applies if required. Secure deletion or physical destruction when mandatory period and proof need end.

Disposal may be temporarily suspended for data that must be retained due to a lawsuit, investigation, audit, security incident, or binding official request. In such cases, data scope is minimized, access is restricted, and retention necessity is re-evaluated during each periodic disposal.

7. Technical and Administrative Security Measures

Appropriate measures proportionate to the activity nature are taken to ensure safe retention and prevent unlawful access:

  • Patient files and paper records are stored in closed areas accessible only to authorized personnel, in locked cabinets where possible.

  • Access privileges on electronic systems are restricted by job description. Strong passwords, multi-factor authentication where applicable, and access logs are used.

  • Website forms operate over secure connections. Identity and health data are not exposed to advertising or analytics tools.

  • Operating systems and software are kept up to date. Security software, backup, and data transfer security measures are implemented.

  • Health data is accessible only to physicians, authorized health personnel under confidentiality obligation, and staff whose duties strictly require it.

  • Camera recording is prohibited in examination rooms, restrooms, and privacy-sensitive areas. Security cameras are restricted to common areas and do not record audio.

  • Employees and service providers are trained/informed on confidentiality, data security, retention periods, and disposal obligations.

  • Service providers (hosting, software, accounting, backups, etc.) access is restricted by written instructions, confidentiality, and security obligations.

  • In case of suspected data breach, access is restricted, incident investigated, and notifications made under relevant regulations.

8. Deletion, Destruction, and Anonymization Methods

  • Electronic data: Application and database entries deleted, access rights revoked, relevant files securely deleted, cryptographic erasure or overwriting applied as needed. Service provider copies requested for deletion. Backups cleared during standard disposal cycles.

  • Printed records: Shredded via paper shredders to unreadable pieces or securely disposed of via authorized service provider bound by confidentiality. Medical documents never left in open trash.

  • Physical recording media: Disks, USB drives, camera recorders, etc., destroyed via secure overwriting, technical deletion, or unrecoverable physical destruction.

  • Anonymization: Identity details removed; aggregation, generalization, or data reduction applied where necessary. Data is not deemed anonymous if linking to an individual remains possible via other data.

Disposal operations are logged with data category, date, method used, responsible person, and result. Log does not contain details of deleted medical data. Kept for at least 3 years.

9. Roles and Responsibilities

Role or Service Group Responsibility
Assoc. Prof. Dr. Berkay Akmaz, Data Controller Approves Policy, determines retention purposes/durations, evaluates applications, oversees compliance of disposal.
Authorized Practice Employees Creates records within job scope, forwards applications to data controller, protects physical/electronic records, reports expired data.
IT and Hosting Service Providers Executes system security, access management, backup, and electronic deletion under authority and written instructions.
Financial Advisor and Legal Counsel Advises data controller on legal retention of financial records and protection of ongoing disputes within their domains.

10. Periodic Disposal and Data Subject Requests

Periodic disposal takes place every year in January and July. The interval between two periodic disposals cannot exceed six months. Personal data whose processing conditions have ceased are deleted, destroyed, or anonymized at the latest during the first periodic disposal period following the obligation. Records with shorter automatic deletion periods are destroyed within their own timeframe.

If all processing conditions cease, data subject requests for deletion/destruction are finalized within 30 days at latest. If data was transferred to third parties, proper notifications are made. If valid legal grounds persist, request may be rejected with explanation.

11. Entry into Force, Review, and Amendments

This Policy enters into force on August 22, 2026. Re-evaluated upon legislation changes, new processing activities, system updates, or retention period revisions. Current text published at https://drberkayakmaz.com.

EYE HEALTH IN VIDEOS

Hear it from your doctor.

Videos about eye health, examination procedures, and frequently asked questions.

All videos
Laser Eye Surgery

How are laser eye treatment methods evaluated?

Assoc. Prof. Dr. Berkay Akmaz
Göz yüzeyi

Göz kuruluğu hakkında doğru bilinen yanlışlar

Assoc. Prof. Dr. Berkay Akmaz
Görme kusurları

Miyopi ve uzağı görememe nasıl değerlendirilir?

Assoc. Prof. Dr. Berkay Akmaz
Göz sağlığı

Göz tembelliği neden değerlendirilmelidir?

Assoc. Prof. Dr. Berkay Akmaz
Retina

Gözde uçuşan cisimler ne zaman incelenir?

Assoc. Prof. Dr. Berkay Akmaz
Lens seçenekleri

Göz içi mercek uygunluğu nasıl belirlenir?

Assoc. Prof. Dr. Berkay Akmaz
Göz kapağı

Göz kapağı çevresindeki şikayetler nasıl ele alınır?

Assoc. Prof. Dr. Berkay Akmaz
Çocuk Göz Sağlığı

Çocuklarda Miyopi Artışı ve Çözüm Yöntemleri

Assoc. Prof. Dr. Berkay Akmaz
Laser Eye Surgery

Lazer Ameliyatından Sonra Gözlük Veya Kontak Lens Kullanmam Gerekir Mi?

Assoc. Prof. Dr. Berkay Akmaz

Partner Institutions

Our clinic has agreements with the following institutions and private insurance providers.