Privacy Policy

Privacy Policy

VTC SAĞLIK HİZMETLERİ SANAYİ VE TİCARET A.Ş. (VITRIN CLINIC)

CLARIFICATION TEXT ON THE PROTECTION AND PROCESSING OF PERSONAL DATA

VTC Sağlık Hizmetleri Sanayi ve Ticaret Anonim Şirketi ("Vitrin Clinic", "we" or the "Company") treats the privacy and security of personal data as a core part of patient care. This applies to the data of our patients, prospective patients, website visitors and business partners. As the Data Controller under Personal Data Protection Law No. 6698 ("KVKK" or the "Law"), we process, record and store your personal data as explained below, in line with the Law and the principle of good faith. We share it with third parties only where the law allows.

This notice covers every personal-data processing activity carried out at our clinic in Başakşehir, Istanbul, on our website (www.vitrinclinic.com and its language versions), through our patient-coordination team, and on every other channel we use to communicate with you. Because we treat patients from Türkiye and from many other countries, we also follow internationally recognised data-protection principles: transparency, data minimisation, purpose limitation, confidentiality, security, accountability and respect for your rights.


1. Categories of Personal Data We Process

Given the nature of our dental-care and health-tourism services, we process the following categories of data. Some you give us directly; others are collected automatically or semi-automatically while we provide our services.

Data Category

What It Includes

Identity Information

Name and surname, T.R. Identity Number, date and place of birth, gender and patient file number. For international patients: passport number and nationality.

Contact Information

Mobile and landline numbers, e-mail address, home address, country and city, and emergency-contact details (name and phone number).

Special Categories of Personal Data (Health Data)

Dental and medical history (anamnesis), panoramic and periapical X-rays, CBCT scans, intraoral and extraoral photographs, digital smile-design and intraoral-scan records, treatment plans, prescriptions, laboratory results, chronic conditions, allergies, medications in use, and pregnancy status.

Visual and Audio Records

CCTV footage recorded for the security of our clinic (with audio at specially marked points only), call recordings where applicable, and before-and-after photos and videos of your smile.

Financial Data

Bank account details (IBAN), masked card details on POS receipts, invoice details, payment plans and, where relevant, insurance information.

Marketing and Transaction-Security Data

Website cookie records (IP address, browser information and browsing activity), campaign preferences, survey responses, and messages submitted through our consultation and contact forms.

Travel and Logistics Data

Flight details (date, time and booking reference), hotel reservation details, pick-up location for transfers, and the passport details needed for invitation letters.


2. Why We Process Your Personal Data

We process your data only for the specific purposes below. We follow the principles in Articles 4, 5 and 6 of the KVKK and collect no more than each purpose requires.

A. Diagnosis, Treatment and Care

We process your health and identity data so that we can:

  • examine your teeth and mouth and reach a diagnosis

  • prepare your treatment plan

  • carry out surgical, restorative and cosmetic dental procedures

  • have your crowns, veneers, implant restorations and other prostheses made and fitted

  • supply the medicines and materials your treatment needs

  • manage your aftercare and follow-up

Final diagnoses, treatment decisions and clinical recommendations are always made by licensed dentists as part of a proper clinical process. This is our core activity under Basic Law on Health Services No. 3359 and Decree-Law No. 663.

B. Free Consultations and Remote Communication

You may contact us through our website forms, free online consultation, WhatsApp, phone, e-mail, SMS or social media. When you do, we process your identity and contact details and anything you choose to share, such as photos or X-rays. We use this information to answer your questions, give a preliminary assessment, explain your treatment options, plan your appointment and prepare for your clinical evaluation.

Information exchanged this way helps prepare your care, but it is not a final diagnosis. Remote communication does not replace an in-person examination where one is needed, and every definitive clinical decision is made by a licensed dentist following the proper clinical process.

C. Health Tourism and Travel Logistics

For patients travelling to us from other cities or countries, we process identity, contact and travel data to:

  • arrange airport, hotel and clinic transfers

  • book accommodation

  • support visa applications, including issuing invitation letters

  • provide interpreting and patient-coordination services

D. Legal and Administrative Obligations

We process your data to meet our legal obligations, including:

  • making the notifications required by the T.R. Ministry of Health, the Provincial Health Directorate, the Social Security Institution (SGK) and other public authorities (for example, e-Nabız)

  • issuing invoices, paying taxes and completing financial reconciliations

  • keeping patient files for the periods the law requires

E. Patient Relations and Service Quality

We process your data to send appointment reminders by SMS, phone, WhatsApp and e-mail, to run patient-satisfaction surveys, to review your requests and complaints, and to keep our patient-coordination service at a high standard.

F. Promotion and Marketing (Only With Your Explicit Consent)

With your separate explicit consent, we may use your data to:

  • send you personalised treatment suggestions

  • tell you about new services and campaigns

  • share your success story, including before-and-after images and testimonials, on our website and social-media channels

We use health data for marketing, publish before-and-after visuals or testimonials, or send commercial messages only after you have given separate, freely given explicit consent for each. You can withdraw that consent at any time.


3. How We Collect Your Data and Our Legal Grounds

We collect your personal data verbally, in writing, visually or electronically through these channels:

  • our clinic

  • our website (vitrinclinic.com and its language versions)

  • our patient-coordination team and call centre

  • e-mail, SMS and WhatsApp

  • social-media platforms (including Facebook, Instagram, TikTok, X, LinkedIn and YouTube)

  • our authorised business partners

When these channels are used for remote contact, we collect information for the purposes described in Section 2(B): answering your questions before treatment, planning your appointment and preparing for your clinical evaluation.

We process your data on the following legal grounds:

  • Expressly provided for by law: Ministry of Health legislation, the Tax Procedure Law, the Turkish Commercial Code and related regulations.

  • Performance of a contract: Delivering the treatment and services agreed between you and Vitrin Clinic.

  • Physical impossibility of obtaining consent: Protecting the life or physical integrity of a patient who cannot give consent, for example because they are unconscious.

  • Compliance with a legal obligation: Meeting our legal duties to notify authorities, retain records and keep data secure.

  • Establishment, exercise or protection of a right: Where processing is needed in a legal dispute.

  • Medical diagnosis and treatment (KVKK Art. 6/3): Processing of health data by dentists and healthcare staff who are bound by professional confidentiality, in order to provide treatment and care.

  • Legitimate interests of the data controller: Managing appointments, keeping our clinic physically secure (including CCTV) and improving our processes, provided this does not harm your fundamental rights and freedoms.

  • Explicit consent: Obtained separately for specific activities such as marketing, sharing treatment visuals and testimonials, and transferring data abroad.


4. Who We Share Your Data With

To achieve the purposes above, we may share your personal data with the following recipients under Article 8 (domestic transfers) and Article 9 (transfers abroad) of the KVKK. In every case we share only the data the recipient needs for that purpose.

  • Public institutions and authorities: The T.R. Ministry of Health, the Provincial Health Directorate, law-enforcement authorities, courts and enforcement offices, tax offices and the SGK, where the law requires it.

  • Medical partners: Dental laboratories that make prostheses, imaging and diagnostic centres, and consulting specialists.

  • Service providers: IT infrastructure, database and server providers, financial advisers, lawyers and translation offices.

  • Tourism and logistics partners: Contracted hotels and transfer companies. They receive only the identity and location details needed to arrange your stay and transport.

  • Recipients abroad: Your own insurer, where applicable, and the servers of global technology providers we use (such as Google, Meta and WhatsApp), which may be located outside Türkiye. We transfer data abroad only in line with Article 9 of the Law, on one of these bases:

    1. your explicit consent

    2. transfer to a country the Personal Data Protection Board has declared adequate

    3. appropriate safeguards, such as Standard Contracts signed and notified to the Board

  • Mobile messaging privacy: We will not share, sell or disclose your mobile number or your text-messaging opt-in to any third party, affiliate or partner for their marketing or promotional purposes. We do not share your SMS consent with third parties. We use your mobile number only to send the messages you have asked for or agreed to receive.


5. Data Security, Patient Privacy and Confidentiality

Vitrin Clinic is committed to protecting your personal data, and your health data above all, against loss, theft, unauthorised access, alteration and disclosure. We do this through administrative, physical and technical safeguards, which we review regularly against legal requirements and recognised healthcare privacy and information-security standards.

Confidentiality and Authorised Access

Only staff who need patient records to do their jobs can access them. Access rights depend on each person's role and are reviewed regularly. Everyone who works with us must keep patient information confidential, both while they work with us and after they leave.

Accurate and Complete Medical Records

We take reasonable steps to keep your personal and medical information accurate, complete and up to date, so that your care is continuous, high-quality and safe. Records are protected against unauthorised alteration, deletion or disclosure.

Access Monitoring and Audit Logs

Each user must sign in with their own credentials to access electronic patient records. System access and activity may be logged and monitored to confirm we are complying with the law, our internal policies and our information-security rules.

Physical, Administrative and Technical Safeguards

Our safeguards depend on the system and how sensitive the data is. They may include:

  • controlled physical access to our premises and records

  • secure information systems and secure transmission

  • encryption where appropriate

  • role-based access

  • regular backups

  • antivirus protection and firewalls

  • periodic security reviews

Staff Confidentiality and Training

All employees, consultants, contractors and third-party staff who may access personal data must follow our confidentiality obligations and receive appropriate training in privacy and data protection. Before we entrust personal data to a supplier or processor, we check them carefully and bind them to data-protection obligations by contract.

Your Privacy at Every Stage of Care

We protect your privacy at every stage: registration, consultation, examination, diagnosis, treatment, communication and record-keeping. We use or share patient information only where the law allows, with your consent where required, or to meet a legal obligation. We make every effort to respect your dignity and confidentiality throughout your care.

Handling Data Breaches

We have procedures to detect, assess, manage and respond to personal-data breaches. If a breach happens, we take corrective action promptly. Where the law requires, we notify the Personal Data Protection Board within 72 hours and inform the people affected.

Continuous Improvement

We review our privacy and information-security practices regularly to stay compliant with the law, international standards and our own policies. We make improvements based on risk assessments, audits, incident reports and new technology.


6. How Long We Keep Your Data

We keep your personal data for the periods required by the relevant legislation, including:

  • Patient medical records: 20 years from the end of treatment.

  • Records of deceased patients: 30 years.

  • Forensic case records: For the applicable statutory limitation period (at least 20 years).

  • CCTV recordings: Approximately [X] months, depending on the capacity of the recording system.

  • Accounting and commercial records: 10 years.

  • Consultation enquiries that do not lead to treatment: [X] years from your last contact with us.

When a retention period ends, we delete, destroy or anonymise the data in our regular reviews, in line with the Vitrin Clinic Personal Data Retention and Destruction Policy.


7. Your Rights as a Data Subject (KVKK Article 11)

As a data subject, you have the right to ask Vitrin Clinic to:

  • tell you whether we process your personal data

  • give you information about that processing

  • tell you why we process your data and whether we use it for that purpose

  • tell you which third parties, in Türkiye or abroad, we have shared your data with

  • correct your data if it is incomplete or inaccurate

  • delete or destroy your data under the conditions in Article 7 of the KVKK

  • tell the third parties who received your data about any correction, deletion or destruction

  • reconsider a result that is against your interests and came solely from automated analysis of your data (you have the right to object to it)

  • compensate you for any damage caused by unlawful processing of your data


8. How to Exercise Your Rights

To make a request, fill in the Application Form to the Data Controller and send it to us through one of these channels:

  • In writing: In person (with a document proving your identity) or through a notary public to İkitelli OSB Mah., Süleyman Demirel Bulvarı, Demirciler Sanayi Sitesi No: 4/1, İç Kapı No: 2, Başakşehir / İstanbul. Please write "Request for Information under the Personal Data Protection Law" on the envelope.

  • By registered electronic mail (KEP): To [email protected], signed with a secure electronic signature.

  • By e-mail: To [email protected], from the e-mail address registered in our system. Please use the subject line "Request for Information under the Personal Data Protection Law".

We may ask for more information to confirm your identity before we act on your request.

We will respond as quickly as possible and within thirty (30) days at the latest, depending on the nature of your request. Responses are free of charge. However, if your request requires an additional cost, we may charge the fee set by the Personal Data Protection Board under Article 13 of the Law.

Data Controller: VTC Sağlık Hizmetleri Sanayi ve Ticaret A.Ş. Address: İkitelli OSB Mah., Süleyman Demirel Bulvarı, Demirciler Sanayi Sitesi No: 4/1, İç Kapı No: 2, Başakşehir / İstanbul E-mail: [email protected] KEP: [email protected] Phone: +90 545 103 6000


VITRIN CLINIC COOKIE POLICY

Effective Date: [DD Month 2026]

1. Introduction and Purpose

Vitrin Clinic (VTC Sağlık Hizmetleri Sanayi ve Ticaret A.Ş.) uses cookies, pixels, local storage and similar tracking technologies on www.vitrinclinic.com. We use them to improve your experience, measure how the site performs and show you content that suits your interests. This policy explains what these technologies are, how we use them and how you can manage your preferences.

2. What Is a Cookie?

A cookie is a small data file that your browser saves on your device (computer, tablet or phone) when you visit a website. It lets the website and your device exchange information. Cookies help the site remember you, for example your language choice or session, and work more efficiently.

3. Types of Cookies We Use

The cookies on our website fall into four categories.

A. Strictly Necessary Cookies

These cookies keep the website working and secure and let you use its basic features, such as moving between pages, opening the consultation form and saving your privacy choices. They are not used for marketing and do not need your consent. If you block them in your browser settings, parts of the site may stop working.

Examples: session ID, security tokens, record of your cookie consent.

B. Analytics and Performance Cookies

These cookies show us how visitors use our website: where traffic comes from and which pages are most popular. We use this information to improve the site's performance and your experience. The data is aggregated and anonymous and does not identify you directly.

Services used: Google Analytics 4 [add or remove tools to match the site].

What they measure: number of visitors, bounce rate and time spent on each page.

C. Functional Cookies

These cookies remember the choices you make, such as your language or region, so the site can offer more personalised features.

Examples: language preference, live-chat or WhatsApp widget settings.

D. Targeting and Advertising Cookies

These cookies help us show you relevant adverts on other websites and social-media platforms (such as Facebook, Instagram, TikTok and Google), based on how you use our site. Vitrin Clinic or our advertising partners may place them. They are switched on only if you give your explicit consent by clicking "Accept". If you do not, you will see general adverts instead of ones tailored to you.

Services used: Meta (Facebook) Pixel, Google Ads, TikTok Pixel [add or remove tools to match the site].

4. Specific Cookies Used on Our Website

[To verify]: Replace this table with the cookies actually set on vitrinclinic.com. You can find them with a cookie scan or in your browser's developer tools.

Cookie Name

Provider

Category

Duration

Purpose

_ga

Google Analytics

Analytics

2 years

Gives each visitor a unique ID so we can calculate visit statistics.

ga[ID]

Google Analytics

Analytics

2 years

Keeps track of your session on the site.

_fbp

Meta (Facebook)

Marketing

3 months

Measures ad conversions and supports retargeting.

gclau

Google Ads

Marketing

3 months

Measures conversions from Google Ads.

_ttp

TikTok

Marketing

13 months

Measures the performance of TikTok ads.

[consent cookie]

Vitrin Clinic

Strictly necessary

1 year

Remembers whether you accepted or declined cookies.

NEXT_LOCALE

Vitrin Clinic

Functional

Session

Remembers your preferred language.

5. Managing Your Cookie Preferences

When you first visit our website, a cookie banner asks for your preferences:

  • Accept All: allows every cookie category.

  • Manage Preferences: lets you switch analytics and marketing cookies on or off separately.

  • Decline: allows only strictly necessary cookies and blocks the rest.

You can change your choice at any time using the "Cookie Settings" link at the bottom of our website. You can also delete or block cookies in your browser:

  • Google Chrome: Settings > Privacy and security > Third-party cookies

  • Mozilla Firefox: Settings > Privacy & Security

  • Safari: Settings > Privacy

  • Microsoft Edge: Settings > Cookies and site permissions

6. Contact

If you have questions about this Cookie Policy or your personal data, please read the Clarification Text above or e-mail us at [email protected].