PDPL
Patient Information Notice
This Information Notice has been prepared by Assoc. Prof. Dr. Ata Can in accordance with Article 10 of the Law on the Protection of Personal Data No. 6698 (the “Law”), titled “Obligation of the Data Controller to Inform”, in order to provide information to patients and/or their legal representatives regarding: the identity of the data controller, the method and legal basis for collecting personal data, the purposes of processing such data, the recipients to whom data may be transferred and the purposes of transfer, the data retention period, and the rights specified in Article 11 of the Law. The explanations provided herein regarding “Your Personal Data” also include “Your Special Categories of Personal Data.”
Data Controller
Title: Assoc. Prof. Dr. Ata Can
Address: İnönü, Nizamiye Cd. No:9 D:No:1, 34373 Şişli/İstanbul
Phone: +90 536 576 66 66
E-mail: atababay@yahoo.com
Website: https://dratacan.com
Categories of Processed Personal Data
Identity Data: Name, surname, Turkish ID number, passport number or temporary ID number (if non-citizen), place and date of birth, marital status, gender, signature
Contact Data: Address, phone number, e-mail address, etc.
Financial Data: Bank account and card details, debt and invoice information
Customer Transaction Data: Patient file payment details, requests, treatment records, etc.
Visual and Audio Records: Laboratory and imaging results obtained during treatment, photos used for patient tracking automation system
Health Data: Laboratory and imaging results, test results, examination data, prescription information, private health insurance details, Social Security Institution data, prosthetic/device information, blood type, medical history, responses and feedback you provide, treatment and care data, sexual health data (when necessary for medical services)
Transaction Security Data: IP address information, website login/logout details
Private Health Insurance Data
Purposes of Processing Personal Data
Your personal data are processed in line with the principles of the Law (lawfulness, fairness, accuracy, up-to-dateness, explicit and legitimate purposes, necessity, proportionality, and limited retention). Processing purposes include:
Patient evaluation, provision of healthcare services, protection of public health, preventive medicine, medical diagnosis, treatment, and care
Preparation and supply of medicines, dental materials, and medical devices
Procurement of services from dental prosthetics laboratories and other suppliers, collaboration with imaging and diagnostic centers
Appointment scheduling, follow-up, communication, patient request and complaint management
Execution of financial/accounting processes, fulfillment of tax obligations, issuing invoices for provided healthcare services
Archiving and storage of healthcare data in accordance with regulations
Following and executing legal proceedings
Sharing of information with the Ministry of Health and other authorities when legally required
Compliance with relevant legal requirements
Verification of relations with contracted institutions, financing of healthcare services, cost coverage by social security/insurance institutions
With explicit consent: sharing with associations, unions, or foundations with which you are affiliated for financing of healthcare services
Patient identity verification, planning and managing clinic operations
Conducting information security, auditing, and ethical compliance processes
Managing requests/complaints and patient relations
Improving healthcare services through analysis, training of staff, monitoring abuse and unauthorized actions, risk management, quality assurance
Ensuring data security, informing patients about campaigns, measuring and enhancing patient satisfaction
Transfer of Personal Data
Your personal data may be transferred, limited to the purposes above, to:
Ministry of Health, affiliated institutions, family health centers, and other legally authorized public bodies
Legal advisors, lawyers, accountants, tax consultants, auditors, and third-party consultants
With explicit consent: to designated relatives or third parties upon your request
Insurance companies, contracted healthcare providers, and IT service providers for archiving purposes
No data shall be transferred abroad without your explicit consent.
Collection Method, Legal Basis, and Retention Period
Personal data are collected:
Via forms, reports, prescriptions, treatment records, and communication forms available on the website,
Through clinic software, camera recordings, and oral, written, or electronic means.
Legal bases for processing include:
Explicitly required by law (Law No. 1219, Regulations on Private Oral and Dental Health Clinics, Medical Deontology Regulations, Turkish Dental Association Code of Ethics, Patient Rights Regulation),
Necessity for the performance of the healthcare contract,
Compliance with the legal obligations of the data controller,
Establishment, exercise, or protection of patient rights.
Retention: Your personal data are processed only for the purposes described above, within the time limits set by applicable legislation. Once mandatory retention periods expire, your data will be deleted. Should legal changes occur, updated retention periods will apply.
Rights of the Data Subject (Patient)
Under Article 11 of the Law, you have the right to:
Learn whether personal data are processed,
Request information if processed,
Learn the purpose of processing and whether it is used accordingly,
Know the third parties to whom data are transferred domestically/abroad,
Request correction of incomplete/incorrect data,
Request deletion or destruction of personal data when conditions are met,
Request notification of corrections/deletions to third parties,
Object to results arising against you from automated processing,
Request compensation if unlawfully processed data cause you damage.
Exercising Your Rights
You may exercise your rights by completing the Data Subject Application Form available at:
Our clinic address (stated above),
Our website https://dratacan.com.
The completed and signed form must be submitted:
By hand,
By post or notary,
Or electronically, via your registered e-mail address previously provided to us.
Applications will be answered free of charge within 30 (thirty) days at the latest. However, if the requested transaction incurs additional costs, a fee may be charged in accordance with the tariff set by the Personal Data Protection Board.
Read and Understood
Patient’s Name & Surname: ……………………
Signature: ……………………
Date: ……………………
