ALAR ORAL AND DENTAL HEALTH SERVICES INDUSTRY AND TRADE LIMITED COMPANY

PERSONAL DATA PROCESSING AND PROTECTION POLICY


IDENTITY OF THE DATA CONTROLLER

According to Article 3, Paragraph 1, Subparagraph (ı) of the Law on the Protection of Personal Data (“LPPD”), the data controller is defined as ‘real or legal persons who determine the purposes and means of processing personal data and are responsible for the establishment and management of the data recording system.’

 

 

Alar Oral and Dental Health Services Industry and Trade Limited Company is the “Data Controller” pursuant to the LPPD and is responsible for determining the purposes and means of processing personal data, as well as the establishment and management of the data recording system.

  • Name of Data Controller: Alar Oral and Dental Health Services Industry and Trade Limited Company

  • Address of Data Controller: Ayazağa Mah. Kemerburgaz Cad. No: 10E/6 Sarıyer Istanbul

  • Tax Identification Number: 0481317044

  • E-mail: info@alardent.com

  • Telephone: 0212 741 31 41


DEFINITIONS AND ABBREVIATIONS

  • Personal Data: Any information relating to an identified or identifiable real person.

  • Data Controller: The person who determines the purposes, methods, and principles of processing personal data.

  • Data Subject: Real persons whose personal data is processed.

  • Processing of Personal Data: Any operation performed on data such as obtaining, recording, storing, preserving, altering, reorganizing, disclosing, transferring, taking over, making available, classifying, or preventing the use of personal data by fully or partially automated means or non-automated means provided that they are part of any data recording system.

  • Anonymization of Personal Data: Rendering personal data impossible to associate with an identified or identifiable real person, even when matched with other data.

  • Erasure of Personal Data: Rendering personal data inaccessible and unusable for Relevant Users in any way.

  • Destruction of Personal Data: The process of making personal data inaccessible, unrecoverable, and unusable by anyone in any way.

  • Website: alardent.com

  • LPPD (“The Law”): The Law on the Protection of Personal Data No. 6698 dated March 24, 2016, published in the Official Gazette dated April 7, 2016, and numbered 29677.

  • Constitution: The Constitution of the Republic of Turkey No. 2709 dated November 7, 1982, published in the Official Gazette dated November 9, 1982, and numbered 17863.

  • Board (“The Board”): Personal Data Protection Board.

  • PPD Authority (“The Authority”): Personal Data Protection Authority.

  • Company: Alar Oral and Dental Health Services Industry and Trade Limited Company.

  • Data Policy: Personal Data Protection and Privacy Policy of our Company.

  • Turkish Penal Code (“TPC”): The Turkish Penal Code No. 5237 dated September 26, 2004, published in the Official Gazette dated October 12, 2004, and numbered 25611.


METHOD OF COLLECTING PROCESSED PERSONAL DATA

We collect your personal data through e-mails you send, phone calls you make, your physical presence at the Company, filling out the Patient Registration Form, visiting the Website, and information and documents you physically transmit to us, through automated, semi-automated, and non-automated means provided they are part of any data system, based on the legal grounds stated below.


PROCESSED PERSONAL DATA, PURPOSES OF PROCESSING, AND LEGAL GROUNDS

Your personal data listed in the table below is processed within the scope of the Law, in accordance with the following principles:

  • Compliance with the law and rules of honesty,

  • Being accurate and up-to-date when necessary,

  • Processing for specific, explicit, and legitimate purposes,

  • Being relevant, limited, and proportionate to the purposes for which they are processed,

  • Retention for the period prescribed by relevant legislation or required for the purpose for which they are processed.

Data CategoryPersonal DataPurpose of ProcessingData SubjectLegal Ground
IdentityName, Surname, TR Identity Number, Gender, Date of Birth, Passport Number, Photo, etc.Execution of activities in accordance with legislation; Communication activities; Evaluating and responding to inquiries, requests, suggestions, complaints, and applications; Providing health services; Managing appointment processes; Determining emergency contacts.Patient, Relative of Patient, Shareholder/Partner, Supplier Employee, Supplier Authority, Parent/Guardian/RepresentativeNecessary for the establishment/performance of a contract; Made public by the data subject; Necessary for the data controller to fulfill its legal obligation.
CommunicationAddress, E-mail, Phone NumberExecution of activities in accordance with legislation; Follow-up of legal affairs; Communication activities; Tracking requests/complaints; Providing information to authorized persons/institutions; Managing patient appointments and health services.Candidate Employee, Employee, Other-Patient, Other-Patient Relative, Shareholder/Partner, Supplier Employee/Authority, Parent/Guardian/RepresentativeNecessary for the establishment/performance of a contract; Necessary for the legal obligation of the data controller; Made public by the data subject.
MarketingWebsite records, Cookie records, Occupational informationAnnouncement of new/existing products, services, and campaigns; Execution of sales and marketing activities; Market research; Creating statistics and analyzing usage; Customizing products and services.Website Visitors, Patients, Patient RelativesNecessary for the legitimate interests of the data controller, provided it does not harm the fundamental rights and freedoms of the data subject; Explicit consent.
Health InformationHealth Report, Blood Type, Medication used, Test ResultsProviding health services in accordance with medical science; Diagnosis and treatment processes; Prescription of medication; Maintaining personnel files for employees.Patients, EmployeesExplicitly stipulated in laws; Explicit consent; Necessary for contract performance; Necessary for legal obligation.
Sexual Life InformationPregnancy status, use of medication related to sexual diseases, use of birth control pillsIn necessary cases to provide health services (Diagnosis/treatment of oral lesions, medication prescription requirements, etc.).PatientsExplicit consent; Necessary for the establishment, exercise, or protection of a right.
Covid-19 Health InfoHES Code, Vaccination Info, Covid Test ResultProtecting the health of persons in the Company; Complying with state Covid-19 measures; Legitimate interest of the Company.Patients, Employees, Relatives, Candidates, VisitorsNecessary for legitimate interests of the data controller; Explicit consent.
Financial DataBank account, IBAN, Credit card info, financial result documentsReceiving payments from patients/relevant parties; Making payments under contracts; Payment of employee wages and benefits.Patient, Parent/Guardian, Shareholder, Employee, SupplierNecessary for the establishment/performance of a contract; Necessary for the establishment, exercise, or protection of a right.
Physical Space SecurityCamera recordsManagement of emergency processes; Ensuring physical space security.Patient, Visitors, Relatives, Employees, Candidates, ShareholdersNecessary for legitimate interests of the data controller.
Employment/ PersonnelPayroll info, disciplinary investigation, employment entry documents, asset declaration, CV, performance reports.Selection/placement of candidates; Fulfilling obligations arising from labor contracts/legislation; Planning HR processes; Occupational health and safety.Employees, Candidates, ShareholdersExplicitly stipulated in laws; Necessary for legitimate interests of the data controller.
Professional ExperienceDiploma info, courses attended, in-service training, certificates, transcripts.Candidate selection processes; Fulfilling labor contract obligations; Improving business processes.Employees, Candidates, ShareholdersNecessary for legitimate interests of the data controller.

TRANSFER OF PERSONAL DATA

The Company is under a confidentiality obligation and protects your personal data, ensuring its privacy. It does not share data with third parties/institutions unless legally required.

  • Authorized Institutions: Data may be shared limited to the purpose (e.g., notifying infectious diseases).

  • Service Providers: Identity, communication, and financial data may be sent to financial advisors, lawyers, and the Ministry of Finance to fulfill tax and legal obligations.

  • Insurance/Social Security: Data may be shared with private insurance companies or the Social Security Institution upon explicit request and for the purpose of service provision.

  • Consultation: In accordance with the Ethical Rules of the Turkish Dental Association, medical data may be shared for consultation purposes with your consent.

  • Data is transferred within the conditions specified in Articles 8 and 9 of the LPPD.


PROTECTION OF PERSONAL DATA / SECURITY

Our company takes technical and administrative measures according to technological possibilities and application costs.

i. Technical Measures:

  • Processing activities are audited by technical systems.

  • Network and application security measures and data loss prevention software are used.

ii. Administrative Measures:

  • Employees receive periodic training on data protection and awareness.

  • Business units are analyzed to minimize data processing.

  • Data security provisions are added to all contracts signed by the Company.

  • Internal discipline and Data Policy procedures ensure continuity and compliance.


PREVENTION OF UNLAWFUL ACCESS

i. Technical Measures:

  • Periodic updates of technical measures.

  • Access and authorization solutions are adopted; physical archives have defined authorities.

  • Access rights are limited; authorities of employees who change roles or leave are revoked.

  • User account management and authorization control systems are applied.

  • Virus protection systems and firewalls are installed.

  • Regular security scans are performed to detect and close vulnerabilities.

ii. Administrative Measures:

  • Employees are informed about technical measures to prevent unlawful access.

  • Confidentiality undertakings are obtained from employees regarding the continued obligation after termination.

  • Contracts with third parties include provisions requiring them to take necessary security measures.


STORAGE AND DESTRUCTION PERIODS

Storage and destruction periods are determined as follows:

  1. Legal Periods: If the legislation stipulates a period, it is followed.

  2. No Stipulated Period: Data is classified (Personal/Special Category). Special category data that no longer needs to be kept is destroyed.

  3. Principle Check: If there is no legitimate purpose for storage, data is deleted, destroyed, or anonymized.

  4. Exception Check: Reasonable storage periods are determined based on exceptions in Articles 5 and 6 of the Law.

Methods:

  • Physical Destruction: Physical destruction of data in paper or microfiche format.

  • Overwriting: Writing random data (0s and 1s) at least seven times over magnetic/optical media using special software.

  • Anonymization: Rendering data impossible to associate with a person even via matching or reverse engineering.

Storage and Destruction Table:

Data CategoryStorage PeriodDestruction Period
IdentityEmployee/Partners/Relatives: 10 yrs; Candidates: 6 months; Patient: 20 yrsFollowing the first periodic destruction after storage ends.
CommunicationEmployee/Partners/Relatives/Patient: 10 yrs; Candidates: 6 monthsFollowing the first periodic destruction.
PersonnelEmployee/Authority: 10 yrs; Candidates: 6 monthsFollowing the first periodic destruction.
MarketingMaximum 2 YearsImmediately.
Physical Security15 DaysFollowing the first periodic destruction.
Finance10 YearsFollowing the first periodic destruction.
HealthEmployees: 10 yrs (after termination); Covid Test/HES: Immediately; Patient: 20 yrsFollowing the first periodic destruction.
Sexual LifePatient: 20 yearsFollowing the first periodic destruction.

AUDIT OF MEASURES

The Company conducts technical audits every 2 years through consulting lawyers and IT consultants in accordance with Article 12 of the Law.

MEASURES IN CASE OF DISCLOSURE

If any employee witnesses unlawful obtaining, processing, or transfer of data, they must immediately report it to the data controller.

  • Unit managers inform Human Resources of any suspicion.

  • If the breach has legal consequences, legal advisors are informed.

  • The Disciplinary Committee takes action against violators.

  • In case of unlawful acquisition by third parties, the Company will notify the data subject and the Board as soon as possible.


RIGHTS OF THE DATA SUBJECT

By applying to the Data Controller, you have the right to:

  1. Learn whether your personal data is processed,

  2. Request information if your personal data has been processed,

  3. Learn the purpose of the processing and whether it is used appropriately,

  4. Know the third parties to whom data is transferred (domestic/abroad),

  5. Request rectification of incomplete or inaccurate data,

  6. Request erasure or destruction of data under Article 7 of LPPD,

  7. Request notification of the operations in (5) and (6) to third parties,

  8. Object to a result against you via automated systems analysis,

  9. Request compensation for damages due to unlawful processing.

Contact for Requests:

  • E-mail: info@alardent.com

  • Address: Ayazağa Mah. Kemerburgaz Cad. No: 10E/6 Sarıyer Istanbul (via registered mail or physical petition).

    Requests will be finalized within 30 days. No fee is charged unless a tariff is specified by the Board.