Alsancak, Izmir FEBO and FICO International Ophthalmology Qualifications +90 547 917 11 37

Privacy Notice

This text is not a consent form. Where the processing of personal data is required based on explicit consent, explicit consent is obtained separately from the information process and is limited to the specific processing activity. The failure to provide explicit consent, or its subsequent withdrawal, does not affect the provision of healthcare services that are not dependent on explicit consent.

1. Purpose and scope

Importance is attached to the confidentiality of personal data and health data within the scope of the eye health services provided by Assoc. Prof. Dr. Berkay Akmaz. This Privacy Notice has been prepared pursuant to Article 10 of the Law No. 6698 on the Protection of Personal Data (the "Law"), the Communiqué on the Procedures and Principles to Be Followed in Fulfilment of the Obligation to Inform, the Regulation on Personal Health Data and the relevant healthcare legislation.
This Notice covers patients, potential patients, patients' relatives, companions, parents, court-appointed guardians and other legal representatives, visitors, website users and persons who contact the Private Practice.
This Notice is not an explicit consent form. Where personal data must be processed on the basis of explicit consent, separate explicit consent limited to the specific processing activity is obtained independently of the information process. Refusal to give explicit consent or its subsequent withdrawal does not affect the provision of healthcare services that do not depend on explicit consent.

2. Identity and contact details of the data controller

The data controller under the Law is the natural person specified below:

  • Data controller: Assoc. Prof. Dr. Berkay Akmaz
  • Practice name: Assoc. Prof. Dr. Berkay Akmaz Private Practice
  • Address: Kültür Mahallesi, Talatpaşa Bulvarı No:4/A, Alsancak, Konak/Izmir
  • Telephone: +90 547 917 11 37
  • Email: [email protected]
  • Website: https://drberkayakmaz.com

In this Notice, the term "Private Practice" refers to the data controller, Assoc. Prof. Dr. Berkay Akmaz, and the activities of the private practice carried out under his supervision.

3. Categories of personal data processed

Depending on the data subject's relationship with the Private Practice and the relevant procedure, all or part of the following data categories may be processed:

  • Identity data: First name, surname, Republic of Türkiye identity number, foreign identity or passport details, date of birth, sex, patient and protocol numbers and other information required to verify identity.
  • Contact data: Telephone number, email address, residential or notification address and preferred communication channel.
  • Patient procedure data: Records relating to appointments, applications, admission, examinations, consultations, procedures, operations, prescriptions, reports, referrals, follow-ups, consent and patient files.
  • Health data: Medical history, complaint, anamnesis, examination findings, eye measurements, test and imaging results, diagnosis, treatment, operation, medicines and medical devices used, allergies, physician's opinion, reports and other information required for the healthcare service.
  • Financial data: Fees, payments, refunds, self-employment receipts, invoices, banking, insurance and payment transaction information. Card security data processed by a bank or payment service provider is not stored by the Private Practice.
  • Legal transaction and compliance data: Requests, complaints, applications, consent and refusal records, contract and dispute files, correspondence with authorised institutions and records concerning fulfilment of legal obligations.
  • Physical premises security data: Camera footage without audio recorded for security purposes in the common areas of the Private Practice.
  • Transaction security and digital usage data: IP address, date and time, access and system logs, device and browser information, security records and cookie preferences.
  • Request and communication data: Explanations entered in contact or appointment forms, emails or messaging channels and records of correspondence. Telephone calls are not audio-recorded unless this is separately and explicitly stated.
  • Visual and audio data: Medical images and photographs, videos or audio recordings processed only where legally permitted and after the required separate explicit consent has been obtained.
  • Marketing and consent data: Commercial electronic communication preferences, records of explicit consent and withdrawal and selections relating to non-essential cookies.

Special categories of personal data are not requested unless required by the nature of the healthcare service. Detailed health information that is not necessary for making an appointment or personal data belonging to third parties should not be entered into the free-text fields on the website.

4. Methods and sources used to collect personal data

Personal data is collected:

  • During application to the Private Practice and the patient admission, examination, testing, treatment, operation and follow-up processes,
  • Through printed or electronic forms, patient files, consent documents, prescriptions, reports and financial documents,
  • By telephone, SMS, email, website, online appointment and contact forms and the messaging channels preferred by the data subject,
  • Through medical devices, measurement systems, laboratories, imaging centres, hospitals and other authorised healthcare providers involved in the provision of healthcare services,
  • From Ministry of Health systems, authorised public institutions, insurance organisations, banks and payment service providers, to the extent permitted by law,
  • Through security cameras in the common areas of the Private Practice and technical records in the website and information systems

directly from the data subject or from legally authorised third parties, in physical or electronic environments, by fully or partly automated means or by non-automated means provided that they form part of a data filing system.
A person making an appointment or sharing information on behalf of another person must provide only the information that they are authorised to share and that is necessary for the procedure. Where personal data is not obtained directly from the data subject, the Private Practice additionally informs the data subject within the period and by the method prescribed by the legislation, to the extent applicable.

5. Purposes and legal grounds for processing personal data

Personal data is processed in accordance with the general principles set out in Article 4 of the Law, for specified, explicit and legitimate purposes, and in a manner that is relevant, limited and proportionate to those purposes.

Processing activity and purpose Main data categories Legal ground
Receiving an appointment request, verifying identity and contact details, creating a patient record, sending appointment reminders and providing information about the service Identity, contact, patient procedure, request and communication Necessary for the establishment or performance of a contract under Article 5(2)(c) of the Law, necessary for compliance with a legal obligation under Article 5(2)(ç), and legitimate interest under Article 5(2)(f) for mandatory and proportionate operations. Where health data is involved, additionally Article 6(3)(f)
Protecting public health, planning and providing preventive medicine, medical diagnosis, treatment, operation, care and follow-up services, maintaining medical records and managing consultation and referral processes Identity, contact, patient procedure, health, visual Processing by persons under an obligation of confidentiality being necessary under Article 6(3)(f) of the Law for the protection of public health, preventive medicine, medical diagnosis, treatment and care services and the planning, management and financing of healthcare services. For processing prescribed by the relevant healthcare legislation, Articles 5(2)(a), 5(2)(ç) and 6(3)(b)
Making the necessary records and notifications in the systems of the Ministry of Health and other authorised institutions, maintaining statutory records and responding to audit requests Identity, contact, patient procedure, health, financial, legal transaction Articles 5(2)(a), 5(2)(ç), 6(3)(b) of the Law and, for health data, Article 6(3)(f)
Carrying out pricing, payment, refund, self-employment receipt or invoice issuance, accounting, tax, insurance and financial processes Identity, contact, patient procedure, financial Articles 5(2)(c) and 5(2)(ç) of the Law. Article 6(3)(f) for health data connected with the financing of healthcare services
Ensuring patient safety, service quality and continuity, carrying out medicine and medical supply processes and assessing requests and complaints Identity, contact, patient procedure, health, request and communication Articles 5(2)(c), 5(2)(ç) and 5(2)(f) of the Law. Article 6(3)(f) for health data
Fulfilling legal obligations, establishing, exercising or protecting a right, conducting legal and administrative processes and responding to requests from authorised authorities Identity, contact, patient procedure, health, financial, legal transaction Articles 5(2)(ç) and 5(2)(e) of the Law. Article 6(3)(d) and other conditions under Article 6(3) applicable to the specific case for special categories of personal data
Ensuring the security of the Private Practice, patients, employees and visitors and preventing unauthorised access and unlawful acts Physical premises security, transaction security, identity The legitimate interest of the data controller under Article 5(2)(f) of the Law, provided that the fundamental rights and freedoms of the data subject are not harmed, and Article 5(2)(e) where necessary
Operating the website, ensuring cybersecurity, preventing errors and misuse and responding to contact and appointment forms Transaction security, contact, request and communication Article 5(2)(f) of the Law for essential technical operations and Article 5(2)(c) for the requested service or appointment. Where health data is shared in a form, Article 6(3)(f), limited to the healthcare service
Using non-essential analytical, functional or advertising cookies and sending commercial electronic communications Transaction security, digital usage, contact, marketing and consent Separate explicit consent under Article 5(1) of the Law where required and the relevant legislation, including the Law No. 6563 on the Regulation of Electronic Commerce. Health data is not used for advertising targeting
Using a patient's testimonial, photograph, video or treatment-related image in promotion and information activities Identity, health, visual and audio, consent Only to the extent permitted by the legislation governing promotion and information in the healthcare sector, and on the basis of separate, specific and freely given explicit consent under Article 5(1) and, where required, Article 6(3)(a) of the Law

For a processing activity based on explicit consent, the data subject may withdraw consent at any time with effect for the future. Withdrawal of explicit consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

6. Transfer of personal data within Türkiye

Pursuant to Article 8 of the Law, personal data may be transferred to the following recipient groups where the transfer is necessary and proportionate and an appropriate processing condition under Article 5 or 6 of the Law is present:

  • The Ministry of Health, provincial and district health directorates and other authorised public institutions: For the purpose of fulfilling statutory registration, notification, audit and public health obligations.
  • Hospitals, laboratories, imaging centres, consulting physicians and other authorised healthcare providers: For the purpose of ensuring diagnosis, treatment, operation, consultation, referral and continuity of healthcare services.
  • The Social Security Institution, private insurance companies and contracted organisations: For the purpose of financing healthcare services and conducting authorisation, eligibility verification and payment processes, to the extent required by the data subject's service relationship.
  • Banks and authorised payment service providers: For the purpose of carrying out payments, refunds and financial transactions.
  • Accountants, lawyers, auditors and other professional advisers: For the purpose of conducting accounting, tax, audit, legal obligation and rights-protection processes, within the framework of their obligations of confidentiality.
  • Information technology, software, hosting, backup, archiving, cybersecurity, appointment, call, SMS, email, courier and similar service providers: For the purpose of ensuring that the Private Practice's processes are carried out securely and without interruption, in their capacity as data processors and limited to written instructions.
  • Courts, public prosecutors' offices, law enforcement units and other authorised judicial or administrative authorities: For the purpose of responding to duly issued and legally binding requests and protecting legal rights.
  • Interpreters and authorised health tourism service providers: Where communication in a foreign language or management of an international patient process is required at the request of the data subject.

The confidentiality of health data is observed in transfers, the data to be transferred is limited to the minimum necessary for the purpose, and the relevant recipients are expected to implement appropriate confidentiality and security measures.

7. Transfer of personal data abroad

Where the website, email, cloud, backup, online communication, instant messaging, video, map, analytics or social media services are used through infrastructure belonging to service providers located abroad or providing access from abroad, the IP address, device and browser information, cookie or identifier information, contact data and content shared by the user through the relevant channel may be transferred abroad.
International transfers are carried out in accordance with the tiered system prescribed by Article 9 of the Law. Accordingly, a transfer first requires the existence of one of the processing conditions under Article 5 or 6 of the Law and an adequacy decision concerning the destination country, sector or international organisation. Where there is no adequacy decision, a standard contract or one of the other appropriate safeguards listed in the Law is provided. Where none of these is available, the transfer is made only if one of the occasional exceptions exhaustively listed in the Law applies to the specific case.
Where it is legally possible to rely on explicit consent as one of the occasional circumstances prescribed by Article 9 of the Law, separate explicit consent is obtained after information has been provided about the possible risks. Non-essential cookies and third-party embedded content are not activated without obtaining the user's preference to the extent that consent is legally required. After external links belonging to social media or messaging platforms are opened by the user, the data processing activities carried out by the relevant platform are also subject to that platform's own privacy notices and privacy rules.

8. Retention and disposal of personal data

Personal data is retained for the period required for the purpose of processing, the retention periods prescribed by the relevant healthcare, tax, accounting and other legislation and the periods for legal claims and limitation. Where no specific statutory period exists, the purpose of processing and the principle of data minimisation are taken as the basis.
When the retention period expires and there is no other legal ground requiring the data to be processed, personal data is erased, destroyed or anonymised in accordance with the Regulation on the Erasure, Destruction or Anonymisation of Personal Data and the retention and disposal rules of the Private Practice. Data contained in backups is made inaccessible within secure backup and disposal cycles and is disposed of when its retention period expires.

9. Security of personal data

Taking particular account of the sensitive nature of health data, the Private Practice implements appropriate administrative and technical measures in line with Article 12 of the Law and the adequate measures determined by the Board. Within this scope, measures appropriate to the processing risk are taken, including restriction of access authorisations, confidentiality obligations, recording and logging, secure backups, use of up-to-date software, encryption or equivalent protection methods, service provider controls, physical archive security and staff awareness.

10. Rights of the data subject under Article 11 of the Law

Data subjects have the right to apply to the data controller in relation to themselves and:

  1. Learn whether personal data is being processed,
  2. Request information if personal data has been processed,
  3. Learn the purpose of processing personal data and whether it is being used in accordance with that purpose,
  4. Know the third parties to whom personal data is transferred within Türkiye or abroad,
  5. Request correction where personal data has been processed incompletely or inaccurately,
  6. Request the erasure or destruction of personal data within the framework of the conditions set out in Article 7 of the Law,
  7. Request that correction, erasure or destruction operations be notified to third parties to whom the personal data has been transferred,
  8. Object to the occurrence of a result against the person through analysis of the processed data exclusively by automated systems,
  9. Request compensation for damage suffered as a result of the unlawful processing of personal data.

Requests for the erasure or modification of health records are concluded by considering together the integrity of medical records, retention and notification obligations under the relevant healthcare legislation and Articles 5, 6 and 7 of the Law. Data subject to an ongoing statutory retention obligation may not be erased immediately upon request. In such a case, the reason why the request cannot be fulfilled is explained to the data subject, and the data is not used for any purpose other than the continuing legal ground.

11. Application to the data controller

Applications concerning the rights under Article 11 of the Law may be submitted by one of the following methods in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller:

  • Delivering the written and signed application, together with information enabling identity verification, by hand or through a notary public to Kültür Mahallesi, Talatpaşa Bulvarı No:4/A, Alsancak, Konak/Izmir,
  • Sending an application signed with a secure electronic signature or mobile signature to [email protected],
  • Sending the application to [email protected] using an email address previously notified to the Private Practice by the data subject and registered in the Private Practice's system,
  • Using the KVKK Data Subject Application Form on the website and submitting it through one of the valid application methods explained in the form.

The application must include the first name and surname, a signature if the application is in writing, the necessary identity and contact details, the subject of the request and any information and documents relating to the request. Personal data or health documents beyond what is required for identity verification should not be sent. The Private Practice may request additional information to conclude the application and may verify that the applicant is the data subject or an authorised representative.
Applications are concluded as soon as possible according to the nature of the request and no later than thirty days, as a rule free of charge. Where the process requires an additional cost, a fee under the tariff determined by the Board may be charged.

12. Updating this Notice

This Privacy Notice may be updated in the event of changes to the legislation, Board decisions, the activities of the Private Practice or personal data processing operations. The current Notice is published on the website. Changes that significantly affect the rights and freedoms of data subjects are additionally announced through appropriate communication channels.

EYE HEALTH IN VIDEOS

Hear it from your doctor.

Videos about eye health, examination procedures, and frequently asked questions.

All videos
Laser Eye Surgery

How are laser eye treatment methods evaluated?

Assoc. Prof. Dr. Berkay Akmaz
Göz yüzeyi

Göz kuruluğu hakkında doğru bilinen yanlışlar

Assoc. Prof. Dr. Berkay Akmaz
Görme kusurları

Miyopi ve uzağı görememe nasıl değerlendirilir?

Assoc. Prof. Dr. Berkay Akmaz
Göz sağlığı

Göz tembelliği neden değerlendirilmelidir?

Assoc. Prof. Dr. Berkay Akmaz
Retina

Gözde uçuşan cisimler ne zaman incelenir?

Assoc. Prof. Dr. Berkay Akmaz
Lens seçenekleri

Göz içi mercek uygunluğu nasıl belirlenir?

Assoc. Prof. Dr. Berkay Akmaz
Göz kapağı

Göz kapağı çevresindeki şikayetler nasıl ele alınır?

Assoc. Prof. Dr. Berkay Akmaz
Çocuk Göz Sağlığı

Çocuklarda Miyopi Artışı ve Çözüm Yöntemleri

Assoc. Prof. Dr. Berkay Akmaz
Laser Eye Surgery

Lazer Ameliyatından Sonra Gözlük Veya Kontak Lens Kullanmam Gerekir Mi?

Assoc. Prof. Dr. Berkay Akmaz

Partner Institutions

Our clinic has agreements with the following institutions and private insurance providers.