English
Contact Us

Personal Data Retention and Disposal Policy

Dental services provided by MSc. Dt. Aykut Koşun are delivered through AK 212 Bayrampaşa Diş Sağlığı Hizmetleri Sanayi ve Ticaret Limited Şirketi.

This Personal Data Retention and Disposal Policy sets out the procedures and principles relating to the retention and disposal of personal data processed by AK 212 Bayrampaşa Diş Sağlığı Hizmetleri Sanayi ve Ticaret Limited Şirketi in its capacity as data controller under applicable legislation.

1. Introduction

1.1 Purpose

This Personal Data Retention and Disposal Policy (“Policy”) has been prepared within the framework of applicable legislation. AK 212 Bayrampaşa Diş Sağlığı Hizmetleri Sanayi ve Ticaret Limited Şirketi (hereinafter referred to as the “Company”) implements this Policy in accordance with the fundamental principles adopted at national level regarding the disposal of personal data.

The Policy sets out the framework and principles governing disposal activities required under applicable legislation.

The third paragraph of Article 7 of the Personal Data Protection Law (“Law”) provides that the procedures and principles relating to the deletion, destruction or anonymisation of personal data shall be regulated by regulation.

Pursuant to this provision and Article 22(1)(e) of the Law, the Regulation on the Deletion, Destruction or Anonymisation of Personal Data (“Regulation”) was prepared by the Personal Data Protection Board (“Board”) and published in the Official Gazette No. 30224 dated 28 October 2017.

In accordance with the regulation referred to above, the purpose of this Policy is to establish, in accordance with the Regulation, the procedures and principles governing the deletion, destruction or anonymisation of personal data processed by the Company in the course of its activities.

1.2 Scope

This Policy covers personal data relating to Company employees, job applicants, visitors, third parties with whom the Company co-operates and third-party personnel working at the Company.

This Policy applies to all recording environments in which personal data owned or managed by the Company is processed and to all activities involving the processing of personal data.

1.3 Abbreviations and Definitions

Term Definition
Recipient Group The category of natural or legal persons to whom personal data is transferred by the data controller.
Explicit Consent Consent relating to a specific matter, based on information and given freely.
Anonymisation Rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching it with other data.
Electronic Environment Environments in which personal data can be created, read, modified and recorded using electronic devices.
Non-Electronic Environment All written, printed, visual and similar environments other than electronic environments.
Data Subject The natural person whose personal data is processed.
Disposal The deletion, destruction or anonymisation of personal data.
Law Personal Data Protection Law No. 6698.
Personal Data Any information relating to an identified or identifiable natural person.
Board Personal Data Protection Board.
Authority Personal Data Protection Authority.
Data Processor A natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the data controller.
Data Controller A natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.
Regulation The Regulation on the Deletion, Destruction or Anonymisation of Personal Data, published in the Official Gazette No. 30224 dated 28 October 2017.

2. Responsibilities and Allocation of Duties

All departments and employees of the Company actively support the responsible departments in implementing the technical and administrative measures adopted under this Policy.

This includes employee training and awareness, continuous monitoring, preventing unlawful access to and processing of personal data, and ensuring the appropriate protection of personal data in all environments in which it is processed.

Title Department Responsibilities
Information Technology Officer Information Technology Ensuring that processes comply with retention periods, managing the periodic disposal process and carrying out the necessary audits and controls.
Accounting Department Manager Accounting Monitoring retention periods and overseeing obligations relating to the retention of books and records arising from commercial and tax legislation.
Human Resources Manager Human Resources Monitoring retention periods for personnel data, carrying out periodic disposal processes and managing relevant applications and requests.

3. Recording Environments

Personal data is stored lawfully and securely by the Company in the electronic and non-electronic environments specified below.

Electronic Environments Non-Electronic Environments
Servers, domain, backup, email, database, web and file-sharing systems Paper
Office software and information security devices Manual data recording systems
Mobile devices Written, printed and visual media
Optical discs and removable storage devices Files and folders
Desktop and laptop computers Other physical recording environments

4. Explanations Regarding Retention and Disposal

The Company retains personal data processed within the scope of its activities in accordance with the KVKK and applicable legislation and disposes of such data where required.

4.1 Explanations Regarding Retention

Personal data is retained for the period prescribed by applicable legislation or for as long as necessary for the purposes for which it is processed, provided that the data remains relevant, limited and proportionate to those purposes.

4.1.1 Legal Grounds Requiring Retention

The Company retains personal data processed within the scope of its activities for the periods prescribed by applicable legislation.

  • Tax Procedure Law No. 213
  • Basic Law on Health Services No. 3359
  • Labour Law No. 4857
  • Social Insurance and General Health Insurance Law No. 5510
  • Turkish Code of Obligations No. 6098
  • Turkish Commercial Code No. 6102
  • Occupational Health and Safety Law No. 6331
  • Personal Data Protection Law No. 6698
  • Regulation on Private Healthcare Institutions Providing Oral and Dental Health Services
  • Patient Rights Regulation
  • Other applicable legislation and secondary regulations currently in force

4.1.2 Processing Purposes Requiring Retention

  • Managing information security processes
  • Ensuring that activities are conducted in compliance with applicable legislation
  • Managing finance and accounting processes
  • Ensuring the security of physical premises
  • Managing communication activities
  • Managing human resources processes
  • Managing occupational health and safety activities
  • Managing the procurement of goods and services
  • Managing contractual processes
  • Monitoring requests and complaints
  • Providing medical diagnosis, treatment and care services
  • Providing information to authorised persons, institutions and organisations
  • Managing administrative and operational activities

4.2 Grounds Requiring Disposal

Personal data is deleted, destroyed or anonymised by the Company either ex officio or upon the request of the data subject in the following circumstances.

  • Amendment or repeal of the legislative provisions forming the basis for processing
  • The purpose requiring the processing or retention of personal data ceases to exist
  • Where processing is based solely on explicit consent, the data subject withdraws their explicit consent
  • A request by the data subject for deletion or destruction is accepted
  • The maximum period requiring the retention of personal data expires

5. Technical and Administrative Measures

The Company takes the necessary technical and administrative measures to ensure that personal data is retained securely, to prevent unlawful processing and access, and to ensure its lawful disposal.

5.1 Technical Measures

  • Network and application security is maintained.
  • Security measures are implemented within information technology systems.
  • The security of personal data stored in cloud environments is maintained.
  • Firewalls are used.
  • Personal data is backed up securely.
  • User account and authorisation controls are implemented.
  • Encryption methods are used where necessary.
  • Measures are implemented to prevent data loss.

5.2 Administrative Measures

  • Access permissions are revoked for employees who change roles or leave the Company.
  • Confidentiality undertakings are implemented.
  • Security measures are implemented for physical environments containing personal data.
  • Physical recording environments are protected against fire, flooding and similar external risks.
  • Care is taken to keep the personal data processed to the minimum extent reasonably necessary.

6. Personal Data Disposal Methods

At the end of the period prescribed by applicable legislation or the retention period required for the purposes of processing, personal data is deleted, destroyed or anonymised in accordance with applicable legislation.

6.1 Deletion of Personal Data

Data Recording Environment Description
Physical environment Redaction methods or secure storage methods that prevent access by relevant users are applied.
Servers User access permissions relating to data for which the retention period has expired are revoked and the relevant data is deleted.
Databases Access to the relevant data is prevented by adjusting user roles and permissions.
Portable devices User access to files and data is prevented.

6.2 Destruction of Personal Data

Data Recording Environment Description
Physical environment Personal data held on paper is destroyed by shredding it in a manner that prevents its recovery.
Electronic environment Secure physical or software-based destruction methods appropriate to the recording medium are used to ensure that the data cannot be recovered.

6.3 Anonymisation of Personal Data

Anonymisation of personal data means rendering such data incapable of being associated with an identified or identifiable natural person, even where it is matched with other data.

7. Retention and Disposal Periods

The Company determines the retention periods applicable to personal data processed within the scope of its activities in accordance with applicable legislation, the Personal Data Processing Inventory and VERBİS records.

Process Retention Period Disposal Period
Human resources employee processes 15 years from the employee's departure During the first six-month periodic disposal period following the expiry of the retention period
Job applicant processes 1 year from the date of application During the first six-month periodic disposal period following the expiry of the retention period
Contractual relationships 10 years from termination of the contract During the first six-month periodic disposal period following the expiry of the retention period
CCTV recordings 30 days from the date of recording Automatically at the end of the retention period
Accounting and finance processes 10 years from the date of recording During the first six-month periodic disposal period following the expiry of the retention period
Patient record processes 20 years from creation During the first six-month periodic disposal period following the expiry of the retention period

8. Periodic Disposal Period

Pursuant to Article 11 of the Regulation, the Company has determined the periodic disposal period as six months. Accordingly, the Company carries out periodic disposal operations in June and December each year.

9. Publication and Retention of the Policy

The Policy is published in printed and electronic form and may be made available to the public through the website. A signed copy is retained in the relevant Company records.

10. Updates to the Policy

The Policy is updated where necessary or where changes occur in personal data processing activities or applicable legislation.

11. Entry into Force of the Policy

This Policy enters into force on the date of its publication. Previous versions of the Policy that are no longer in force are retained in accordance with the Company's relevant record-keeping and retention procedures.

Data Controller

Contact Details

AK 212 Bayrampaşa Diş Sağlığı Hizmetleri Sanayi ve Ticaret Limited Şirketi

  • Email: info@aykutkosun.com
  • Phone: +90 542 142 7817
  • Address: Yenidoğan, Abdi İpekçi Cd. No:55, 34030 Bayrampaşa, İstanbul, Türkiye

Get in Touch

Contact our team via phone or WhatsApp to learn more about our treatments.

Make an enquiry... 1