WE ARE OPEN WEEKDAYS BETWEEN 9:00 AM AND 6:00 PM.

Özel Tansan Polikliniği

  • HOME PAGE
  • ABOUT US
  • OUR TEAM
    • DOCTORS
    • NURSES
    • LABORATORY TECHNICIANS
    • PUBLIC RELATIONS
    • SUPPORT STAFF
  • OUR SERVICES
    • CANCER DIAGNOSIS AND TREATMENT
    • LABORATORY SERVICES
    • NURSING SERVICES
    • PUBLIC RELATIONS
  • BLOG
  • TANSAN IN THE PRESS
  • EVENTS & DEVELOPMENTS
  • VIDEOS
  • COMMUNICATION
  • BOOK AN APPOINTMENT
+90 212 225 27 56
  • Home
  • PERSONAL DATA STORAGE AND DESTRUCTION POLICY

PERSONAL DATA STORAGE AND DESTRUCTION POLICY

PERSONAL DATA STORAGE AND DESTRUCTION POLICY

TANSAN PRIVATE HEALTH SERVICES AND TRADE LTD.

(TANSAN PRIVATE POLYCLINIC)

PERSONAL DATA STORAGE AND DESTRUCTION POLICY

ENTRANCE

  1. Purpose and Scope

Personal Data Storage and Destruction Policy (POLICY) This policy has been prepared to determine the procedures and principles to be applied regarding the storage and destruction of personal data obtained by Tansan Private Health Services and Trade Ltd. Co. (COMPANY) in accordance with the Law No. 6698 on the Protection of Personal Data and related legislation.

In accordance with the fundamental principles determined by the Company, the processing of personal data of employees, patients, patient relatives, guardians/parents/representatives, shareholders/partners, service providers, supplier officials/supplier employees, visitors, and all other third parties whose personal data is held within the Company's polyclinic for any reason, is carried out in accordance with the Turkish Constitution, international conventions, Law No. 6698 on the Protection of Personal Data, and relevant legislation, within the framework of this Personal Data Storage and Destruction Policy.

The processes and procedures related to the storage and destruction of personal data are carried out in accordance with the Policy prepared by the Company for this purpose.

  1. Abbreviations and Definitions

Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.

Data Processor: A natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the data controller.

Contact person: The natural person whose personal data is being processed.

Company : Tansan Private Healthcare Services and Trade Ltd. Co.

Worker : Company (polyclinic) staff.

Buyer Group: The category of natural or legal person to whom personal data is transferred by the data controller.

Service Provider: A natural or legal person who provides services to the company within the framework of a specific contract.

Personal Data: Anything relating to an identified or identifiable natural person

various information

Special Category Personal

Data:  Data relating to a person's race, ethnic origin, political views, philosophical beliefs, religion, sect or other beliefs, appearance and clothing, membership in associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.

Personal Data

Processing: Personal data processing includes any operation performed on data, such as obtaining, recording, storing, keeping, modifying, reorganizing, disclosing, transferring, acquiring, making available, classifying, or preventing the use of personal data, whether wholly or partly automated or non-automated, provided that it is part of a data recording system.

Personal Data Processing

Inventory: Data controllers create an inventory detailing their personal data processing activities based on their business processes, associating these activities with the purposes of personal data processing, data category, recipient group to whom the data is transferred, and data subject group. This inventory also specifies the maximum period for which the personal data is processed for the intended purposes, the personal data intended for transfer to foreign countries, and the measures taken regarding data security.

Electronic Environment: Environments where personal data can be created, read, modified, and written using electronic devices.

Non-electronic

Environment : All written, printed, visual, and other media outside of electronic media.

Recording Medium: Any medium containing personal data processed wholly or partly automatically, or by non-automatic means as part of a data recording system.

Destruction: Deletion, destruction, or anonymization of personal data.

Elimination: It is the process of making personal data inaccessible, irretrievable, and unusable by anyone in any way.

Delete: This is the process of making personal data completely inaccessible and unusable for the relevant users.

Periodic Destruction: If all the conditions for processing personal data stipulated in the law cease to exist, the personal data will be deleted, destroyed, or anonymized automatically at recurring intervals as specified in the data retention and destruction policy.

Anonymous Hale

Bringing: Personal data must be rendered in such a way that it cannot be linked to an identified or identifiable natural person, even when combined with other data.

Policy: Personal Data Processing, Storage and Destruction Policy

Law:  Law No. 6698 on the Protection of Personal Data.

Regulation: Regulation on the Deletion, Destruction or Anonymization of Personal Data, published in the Official Gazette dated 28.10.2017 and numbered 30224.

Board: Personal Data Protection Board

Verbis: Data Controllers Registry Information System

 RECORDING MEDIA

Personal data is securely stored by the Company in the following environments:.

  1. Electronic Environments

– Email, web.

- Information security devices (antivirus, firewall, etc.),

– Office programs,

– Personal computers (desktop and laptop),

– Mobile devices (phone, tablet),

– Surver,

– Video Recording Devices,

– Removable storage devices (USB, memory card, etc.),

– Printer, scanner, photocopier.

  1. Non-Electronic Environments

– Paper, Folders,

– Manual data recording systems (patient files, forms, protocols, inspection and audit logbook, work documents, personnel files, and other registers required to be kept in accordance with the Regulation on Private Health Institutions Providing Outpatient Diagnosis and Treatment),

– Archives, Unit Cabinets.

 INSTRUCTIONS REGARDING STORAGE AND DISPOSAL

Personal data of employees, patients, patient relatives, companions, guardians, parents, representatives, shareholders/partners, service providers, supplier officials, supplier employees, visitors, and any other individuals whose data is held by the Company for any reason, are stored and destroyed by the Data Controller in accordance with the Law. Detailed explanations regarding storage and destruction are provided below.

  1. Storage Information

Article 3 of the law defines the concept of processing personal data, Article 4 states that processed personal data must be relevant, limited and proportionate to the purpose for which it is processed, and must be retained for the period stipulated in the relevant legislation or for the period necessary for the purpose for which it is processed, and Articles 5 and 6 list the conditions for processing personal data.

Accordingly, personal data related to the company's (polyclinic's) activities are stored by the data controller for the period stipulated in the relevant legislation or for the period appropriate to our processing purposes.

  1. Legal Reasons Requiring Concealment

Personal data processed within the scope of the company's activities is retained for the period required by the service provided and stipulated in the relevant legislation. In this context, personal data includes:;

Law No. 6698 on the Protection of Personal Data,

Law No. 1219 on the Manner of Practice of Medicine and Related Professions

Turkish Code of Obligations No. 6098,

Turkish Penal Code No. 5237,

Turkish Commercial Code No. 6102,

Law No. 6502 on Consumer Protection,

Social Security and General Health Insurance Law No. 5510,

Law No. 3359 on Basic Health Services,

Occupational Health and Safety Law No. 6361,

Labor Law No. 4857,

Criminal Records Act No. 5352,

Regulation on Private Healthcare Institutions Providing Outpatient Diagnosis and Treatment,

Occupational Health and Safety Services Regulation,

Patient Rights Regulation,

Rules of Medical Professional Ethics,

Other relevant laws and other secondary regulations in force pursuant to these laws.

They are stored for the retention periods stipulated within the framework.

  1. Processing Purposes Requiring Storage

Personal data processed within the scope of polyclinic activities is stored for the following purposes:.

– Managing communication and human resources processes,

– Ensuring safety during operations,

– To be able to perform tasks and transactions due to contracts and protocols.

– To manage emergency processes,

– The burden of proof in future legal disputes,

-To ensure that legal obligations are fulfilled as required or mandated by legal regulations.

  1. Reasons Requiring Destruction

Personal data;

– Amendment or repeal of the relevant legal provisions forming the basis for its processing,

-The purpose requiring urinating or storing it has ceased to exist,

– In cases where the processing of personal data is carried out solely based on explicit consent, the data subject may withdraw their explicit consent.,

-The Company's acceptance of the data subject's application for the deletion and destruction of their personal data, within the scope of their rights under Article 11 of the Law,

-If the company rejects an application from the data subject requesting the deletion, destruction, or anonymization of their personal data, finds the response insufficient, or fails to respond within the time limit stipulated by law; the individual may file a complaint with the Board, and if this request is deemed appropriate by the Board,

– If the maximum retention period for personal data has expired and there are no circumstances justifying the retention of personal data for a longer period, the data will be deleted, destroyed, or anonymized by the Company upon the request of the data subject, or automatically deleted, destroyed, or anonymized.

TECHNICAL AND ADMINISTRATIVE MEASURES

In order to ensure the secure storage of personal data, prevent its unlawful processing and access, and to ensure the lawful destruction of personal data, the company shall take technical and administrative measures within the framework of adequate measures determined and announced by the Board for special categories of personal data, as required by Article 12 and Article 6, paragraph 4 of the Law.

  1. Technical Measures

As part of the technical measures;

  1. Within the scope of the systems established for monitoring personal data security, necessary internal controls are carried out, and appropriate technical measures and precautions are taken to ensure personal data security.
  2. The technical infrastructure to prevent or monitor data leaks is ensured, and necessary software, including network security, application security, and anti-virus systems, is kept up-to-date.
  3. Access to electronic and non-electronic storage areas containing personal data is recorded to monitor inappropriate access or access attempts, and necessary measures are taken to ensure that deleted personal data is inaccessible and unusable for the relevant users.
  4. A separate policy has been established for the security of sensitive personal data. In addition, employees involved in sensitive personal data processing processes receive training on sensitive personal data security, and confidentiality agreements are made.
  5. The company takes necessary measures to ensure the physical security of the information systems equipment, software, and the environments where all personal data, including sensitive personal data, is stored and/or accessed (restricting access by unauthorized persons, etc.). (fire extinguishing system, air conditioning system, etc.).
  6. Administrative Measures

As part of administrative measures;

– We employ knowledgeable and experienced personnel in the processing of personal data, preventing unlawful processing, preventing unlawful access to personal data, and ensuring its preservation. Our personnel also receive training on the Personal Data Protection Law, the Labor Law, and other relevant legislation.

-Confidentiality agreements are signed with employees and service providers regarding the activities carried out, and employees receive information security training. Furthermore, periodic and random internal audits are conducted/commissioned, and the nature and extent of potential damage to the relevant party in the event of a security breach are taken into consideration.

-Necessary measures are taken to prevent personal data from being obtained by others through unlawful means, and if the relevant personal data is obtained illegally, this is reported to the data subject and the Board as soon as possible.

-The obligation to inform data subjects before commencing personal data processing is fulfilled.

– It has prepared an inventory of personal data processing.

PERSONAL DATA DESTRUCTION TECHNIQUES

At the end of the retention period stipulated in the relevant legislation or the retention period necessary for the purpose for which they were processed, personal data shall be destroyed by the DATA CONTROLLER ex officio or upon the request of the data subject, in accordance with the provisions of the relevant legislation and using the techniques specified below.

  1. Deletion of Personal Data

Personal data is deleted using one or more of the following methods:

Personal data stored electronically that has reached the expiration of its required retention period will be rendered inaccessible and unusable for all employees (relevant users) except the Data Controller.

Personal data held in physical form, for which the required retention period has expired, shall be rendered inaccessible and unusable to anyone other than the Data Controller. Furthermore, the data shall be obscured by drawing over, painting over, or erasing to make it unreadable.

  1. Destruction of Personal Data

Personal data is destroyed by one or more of the following methods:

* Personal data in paper format for which the retention period has expired will be physically destroyed in a way that makes it impossible to recover (either by shredding the paper in a paper shredder or by hand, tearing it into unreadable small pieces).

*Access rights for users to office files located in the central directory are revoked.
* Rows or columns containing personal information in databases are deleted using the 'Delete' command.

* If necessary, it can be securely deleted with the help of a professional.

* Personal data stored on optical and magnetic media that has reached the end of its required retention period will be physically destroyed by melting, burning, or pulverizing.

  1. Anonymization of Personal Data

Anonymization of personal data is the process of rendering personal data in such a way that, even when matched with other data, it cannot in any way be linked to an identified or identifiable natural person.

Personal data belonging to the data subject is anonymized by removing one or more direct identifiers that could be used to identify the data subject, by combining personal data belonging to many individuals and transforming it into statistical data by removing distinguishing information, or by mixing or distorting the direct or indirect identifiers in the personal data with other values, thereby severing their connection with the data subject and causing them to lose their identifying characteristics.

STORAGE AND DISPOSAL PERIODS

The Data Controller shall, within the scope of its activities, process personal data as follows:;

Retention periods for all personal data related to activities carried out depending on the processes, on a data-by-data basis.

– In the Personal Data Processing Inventory,

– Retention periods based on data categories are determined upon registration with VERBİS.,

– Retention periods for each process are detailed in the Personal Data Retention and Destruction Policy.

The data controller will make updates to these retention periods as needed. For personal data whose retention periods have expired, the data controller will automatically delete, destroy, or anonymize the data.

Table of storage and destruction times by process:

PERIOD STORAGE TIME DESTRUCTION PERIOD
Human Resources Processes and Fulfillment of Employer Obligations Data entry records are kept for 10 years from the termination of the employment contract, or until the conclusion of any ongoing legal proceedings. (Article 86/1 of Law No. 5510) During the first periodic destruction period following the expiration of the storage period
Fulfillment of Occupational Health and Safety Obligations Data entry records are kept for 15 years from the termination of the employment contract, or until the conclusion of any ongoing legal proceedings. (Article 7 of the Occupational Health and Safety Services Regulation) During the first periodic destruction period following the expiration of the storage period
Healthcare Delivery In accordance with relevant legal regulations and the requirements of healthcare services, it is kept for a period of 20 years. If a legal process is ongoing, it is kept until the process is concluded. (Articles 146, 147, and 478 of the Turkish Code of Obligations No. 6098, Articles 66-72 of the Turkish Penal Code No. 5237, and Article 27 of the Regulation on Private Healthcare Institutions Providing Outpatient Diagnosis and Treatment) During the first periodic destruction period following the expiration of the storage period
Obtaining Services from Third Parties The contract is kept for 10 years from the termination of the contract, or until the conclusion of any ongoing legal proceedings. (Article 146 of the Turkish Code of Obligations No. 6098) During the first periodic destruction period following the expiration of the storage period
Camera Recordings 15 days During the first periodic destruction period following the expiration of the storage period

If a longer period is stipulated in the law or other regulations, or if a longer period is provided for statutes of limitations, forfeiture periods, retention periods, etc., in the legislation, the periods in the legislation provisions shall be considered as the maximum retention period.

PERIODIC DESTRUCTION PERIOD

In accordance with Article 11/2 of the regulation, the Data Controller has determined the periodic destruction period as 6 months. Accordingly, periodic destruction is carried out in the company every year in June and December.

RESPONSIBILITIES AND DUTIES

The Data Controller is responsible for the preparation, development, implementation, publication and updating of the Policy in relevant media, ensuring that employees act in accordance with the Policy, and providing the technical solutions needed for the implementation of the Policy.

The company (polyclinic) employees comply with technical and administrative measures taken within the scope of the Policy to ensure data security in all environments where personal data is processed, in order to properly implement these measures, to provide training and increase awareness among employees, to prevent the unlawful processing of personal data, to prevent unlawful access to personal data, and to ensure the lawful storage of personal data.

These individuals, whose responsibilities are clearly defined, are accountable for transactions and actions occurring within their jurisdiction under the Turkish Commercial Code, the Code of Obligations, the Labor Code, and the Turkish Penal Code.

The titles, departments, and job descriptions of those involved in the processes of storing and destroying personal data are as follows:.

Data Controller Company Manager They are responsible for ensuring that employees act in accordance with the policy.
Data Processor  Preliminary Accounting They are responsible for the preparation, development, implementation, publication in relevant media, and updating of the policy.
Service Provider  Outsourcing It is responsible for providing the technical solutions needed for the implementation of the policy.
Doctor, Nurse, Staff Other Units They are responsible for the implementation of the Policy in accordance with their duties.

PUBLICATION AND CONFIDENTIALITY OF POLICY

The policy is drawn up in printed form with a wet signature and kept in the relevant files within the company. If the company (polyclinic) has a website, the policy is also made publicly available on the website.

POLICY UPDATE PERIOD

The policy is reviewed as needed, and the necessary sections are updated.

ENTRY INTO FORCE AND ABOLITION OF THE POLICY

The policy shall be deemed to have entered into force upon completion of the VERBİS registration by the Data Controller.

If a decision is made to revoke the Policy, the old copies bearing wet signatures will be cancelled (by stamping or writing "canceled") and signed by the Data Controller and kept in the relevant files at the Company (polyclinic) for at least 5 years.

DATA CONTROLLER

NAME SURNAME

SIGNATURE

Call

Latest News & Announcements

  • Tansan Oncology Celebrates its 30th Anniversary with Pride.

    As Tansan Oncology, we are a passenger in the field of healthcare...
  • Following the Path of Scientific Progress: Participation of Our Clinical Team in the Turkish Medical Oncology Congress 2026

    Closely following the latest developments in the field of oncology...
  • Doctor of the Year in Türkiye

    At the University of Boston, only...
  • Müjdat Gezen wrote: Süalp Tansan | Cumhuriyet

    Click here to go to the link. Kandemir (Kond...
  • We need to stop fighting death.

    Click to go to the link. He turned his pocket...

TANSAN ONCOLOGY

We aim to be a modern clinic that is considered a benchmark in terms of patient and employee satisfaction, utilizing internationally standardized knowledge and technology in all areas of oncology to raise national cancer awareness.

E-NEWSLETTER

Please subscribe if you would like to receive updates from us.

  • Personal Data Protection Law (KVKK) Information Text
  • PERSONAL DATA STORAGE AND DESTRUCTION POLICY
  • POLICY ON THE PROTECTION AND PROCESSING OF SPECIAL CATEGORY PERSONAL DATA
  • DECLARATION OF EXPLICIT CONSENT UNDER THE PERSONAL DATA PROTECTION LAW (KVKK)
  • SATISFACTION SURVEY

Tansan Oncology © 03.07.2026 All rights reserved.
These articles are written for patient information purposes.

Design Implementation Arda Catalkaya
TOP
EN
TR
By continuing to use our website, our privacy policy By doing so, you agree to the use of cookies.