კონტაქტის ფორმა - ინფორმაციული ტექსტი
At Vimfay International Health Services (the “Company”), we attach importance to the security of your personal data. This Privacy Notice concerns the processing of personal data you submit through the contact/enquiry form on our website, and is provided under KVKK Art. 10 and GDPR Art. 13.
1. Our Personal Data Processing PrinciplesYour personal data is processed in the light of the following principles:
- Lawfulness and fairness.
- Accuracy and, where necessary, being kept up to date.
- Processing for specified, explicit and legitimate purposes.
- Being relevant, limited and proportionate to the purposes.
- Retention only for the period prescribed by law or necessary for the purposes.
Article 10 of the KVKK (and Articles 13-14 of the GDPR) require controllers to inform data subjects whose personal data is processed. Accordingly, the Company, as controller, informs data subjects about:
- the identity of the controller,
- the purposes for which personal data is processed,
- to whom and for what purpose the data may be transferred,
- the method and legal basis of collection,
- the rights of the data subject under KVKK Art. 11 and GDPR Art. 15-22
This information is provided by means of this Privacy Notice.
3. Data ControllerUnder KVKK Art. 3(1)(ı), the controller is “the natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system” (see also GDPR Art. 4(7)). The Company acts as controller and your personal data may be processed within the scope explained below.
Controller | Details |
|---|---|
Legal name | VIMFAY ULUSLARARASI SAĞLIK HİZMETLERİ TURİZM SANAYİ VE TİCARET A.Ş. |
Address | Beştepe Mah. Dumlupınar Blv. No: 6/1, Interior Unit No: 22, Yenimahalle / Ankara, Türkiye (Armada Business Centre, Floor 14) |
Phone | +90 312 963 1400 |
info@vimfay.com · kvkk@vimfay.com | |
Registered e-mail (KEP) | — |
Data Protection Officer | [Name] · dpo@vimfay.com |
EU Representative (Art. 27) | [EU-based representative] · eu-rep@vimfay.com |
IDENTITY AND CONTACT DATA
PERSONAL DATA PROCESSED | PROCESSING PURPOSES |
|---|---|
Name, surname, e-mail address, phone number, country/nationality | Handling your request, contacting you and providing information |
REQUEST CONTENT
PERSONAL DATA PROCESSED | PROCESSING PURPOSES |
|---|---|
Information you provide in the message text and any attachments | Assessment and conclusion of requests, questions and complaints; planning of service processes |
TRANSACTION SECURITY DATA
PERSONAL DATA PROCESSED | PROCESSING PURPOSES |
|---|---|
IP address, form submission date and time, session information | Ensuring information security, preventing misuse and fulfilling evidentiary obligations |
Your personal data may be processed on the following legal bases, within the conditions set out in KVKK Art. 5-6 and GDPR Art. 6 and 9:
Legal Basis | Processing Purposes | Data Categories |
|---|---|---|
Necessary for the performance of a contract or pre-contractual steps (KVKK 5/2-c; GDPR 6(1)(b)) | Handling your request and initiating the service process | Identity and Contact, Request Content |
Legitimate interests (KVKK 5/2-f; GDPR 6(1)(f)) | Improving communication quality, security and prevention of misuse | Transaction Security |
Legal obligation (KVKK 5/2-ç; GDPR 6(1)(c)) | Statutory retention and evidentiary obligations | All categories |
Explicit consent (KVKK 6; GDPR 9(2)(a)) | Processing of health information if you include it in the free-text field | Request Content (health data) |
Warning: Please do not share detailed health information in the free-text field of the contact form. If you enter health information there, it will constitute special-category personal data and will be processed solely to respond to your request, on the basis of your explicit consent. For requests requiring medical assessment, we will direct you to our secure communication channels.
7. To Whom and For What Purpose Personal Data May Be TransferredTransfers are carried out in accordance with KVKK Art. 8-9 and GDPR Chapter V; all technical and organisational measures are taken to ensure data security during and after the transfer.
- Data is shared with the relevant departments of the Company according to the nature of your request.
- Where your request requires medical assessment, data may be shared with a contracted physician or hospital on the basis of your explicit consent.
- Data may be hosted with IT service providers whose servers are located in Türkiye or abroad, for the operation of our website and e-mail infrastructure.
- Data may be shared with persons and institutions authorised by law upon a court decision or the request of competent authorities.
International transfers rely on an adequacy decision where available; otherwise on the appropriate safeguards listed in KVKK Art. 9 (standard contract, undertaking, binding corporate rules) or on your explicit consent. Where a standard contract is signed, it is notified to the Turkish Authority within 5 business days. For data subjects in the EU, transfers rely on GDPR Chapter V safeguards (Standard Contractual Clauses and a transfer impact assessment).
8. Method of CollectionYour personal data is collected electronically, by wholly or partly automated means, when you complete the contact/enquiry form on our website. After your request is concluded, data is retained for up to 2 years; this period may be extended in case of a legal dispute.
9. Rights of the Data SubjectAs a data subject, you have the following rights:
- To learn whether your personal data is processed,
- To request information if your personal data has been processed,
- To learn the purpose of processing and whether the data is used in accordance with that purpose,
- To know the third parties, in Türkiye or abroad, to whom the data is transferred,
- To request rectification where the data is incomplete or inaccurate,
- To request erasure or destruction where the reasons for processing no longer exist (KVKK Art. 7; GDPR Art. 17),
- To request notification of rectification/erasure to third parties to whom the data has been transferred,
- To object to a result arising against you from analysis carried out solely by automated systems (KVKK Art. 11; GDPR Art. 22),
- To request compensation for damage arising from unlawful processing,
- In addition, if you are in the European Union: rights to restriction of processing (Art. 18), data portability (Art. 20), objection (Art. 21), withdrawal of consent at any time (Art. 7) and to lodge a complaint with a supervisory authority (Art. 77).
The Company takes all necessary technical and organisational measures to protect the personal data it collects and processes and to prevent unauthorised access. These include role- and attribute-based access control (RBAC/ABAC), multi-factor authentication, AES-256 encryption, TLS 1.3 secure transmission, access and transaction logging with regular review, backups, penetration testing, staff confidentiality undertakings and regular awareness training. For special-category data, additional measures are applied in line with the Turkish Authority's decision dated 31.01.2018, including separate encryption, separate access logging and restricted authorisation.
11. Right to Apply and Obtain InformationYou may submit your requests in writing or by other methods determined by the Turkish Data Protection Authority. In particular:
- by sending an e-mail to kvkk@vimfay.com,
- by sending a secure e-signed message from your registered e-mail (KEP) address,
- by submitting a signed written petition in person,
- by submitting a petition through a notary public with identity verification
The Company will conclude such requests free of charge as soon as possible and within thirty (30) days at the latest (KVKK Art. 13/2). For data subjects in the EU, requests are answered without undue delay and within one month (GDPR Art. 12).