Corporate
Privacy Policy
How Biruni University Hospital collects, uses, shares and protects your personal data, and your rights under Law No. 6698 and, where applicable, the GDPR.
Biruni University Hospital is committed to protecting your personal data and respecting your privacy. This Privacy Policy describes what personal data we collect, how we use it, who we share it with, how long we keep it, and your rights regarding it, in accordance with Law No. 6698 on the Protection of Personal Data and, where applicable, the EU General Data Protection Regulation, referred to below as the GDPR.
Data we collect
We may collect identification information such as your name, date of birth and national ID number, contact information such as your address, phone number and email, health and medical data such as diagnoses, treatment history and test results, financial information such as payment and insurance details, and website usage data such as your IP address, browser type and the pages you visit.
Most of this data is collected directly from you, whether in person, by phone, or through forms on this website. Some data, such as website usage data, is collected automatically as you browse the site. In some cases we may also receive data from a referring physician or from your insurer where relevant to your care.
How we use your data
Your personal data is used to provide healthcare services, to process appointments, prescriptions and billing, to communicate with you about your treatment, to fulfil legal obligations, and to improve our services through anonymised analysis. We do not sell or rent your personal data to third parties.
Legal basis for processing
Under the Law, health data is a special category of personal data and is generally processed either with your explicit consent, or, where permitted, by health professionals under a duty of confidentiality for purposes such as diagnosis, treatment and the planning and management of health services. Other categories of data, such as contact and financial information, are typically processed because it is necessary to deliver the service you have requested, to meet a legal obligation, or, for anonymised analysis, on the basis of our legitimate interest once the data no longer identifies you.
Who we share your data with
We do not sell or rent your personal data. Depending on the service involved, your data may be shared with parties such as laboratories or other healthcare providers involved in your diagnosis or treatment, your health insurer for billing and claims purposes, regulatory and public health authorities where required by law, and service providers, such as IT and hosting providers, who process data on our behalf under confidentiality obligations.
How long we keep it
Your rights
Under Article 11 of the Law, you have the right to:
- learn whether your personal data have been processed,
- request information about how your data has been processed, if it has been,
- learn the purpose of processing and whether your data has been used in line with that purpose,
- know the third parties, in Turkey or abroad, to whom your data has been transferred,
- request correction of incomplete or inaccurate data,
- request erasure or destruction of your data, under the conditions set out in the Law,
- request that any correction or erasure be notified to third parties your data was shared with,
- object to a decision made about you based solely on automated analysis of your data, and
- claim compensation if you are harmed by unlawful processing of your data.
Where the GDPR applies to you, you may also have additional rights, including the right to restrict processing, the right to data portability, and a broader right to object to processing.
This section summarises what the Law provides. It is not legal advice, and if a specific situation is not covered here, please contact us directly.