GDPR Policy
Last updated January 2026. This is the operative text, unchanged. If anything here is unclear, write to hello@swedishclinicturkey.com and a person answers.
01. Introduction
Sweden Özel Sağlık Hizmetleri ve Danışmanlık Anonim Şirketi ("we", "our", "us") is committed to protecting your personal data and respecting your privacy. This GDPR Policy explains how we collect, use, store, and protect your personal information in accordance with the General Data Protection Regulation (GDPR, EU 2016/679).
Sweden Özel Sağlık Hizmetleri ve Danışmanlık Anonim Şirketi
19 Mayıs Mah. Dr. Hüsnü İsmet Öztürk Sk., Şişli Plaza No: 1 C
34360 Şişli, Istanbul, Turkey
02. Scope & applicability
This GDPR Policy applies to all individuals in the European Economic Area whose personal data we process — whether you are an existing patient, prospective patient, website visitor, or contact form respondent. The policy applies regardless of the channel (website, WhatsApp, phone, email, in-person).
03. Personal data we collect
We may collect and process the following categories of personal data:
- Identification data: full name, country of residence, date of birth (if relevant to treatment)
- Contact data: email address, phone number, WhatsApp number
- Medical data (special category): medical history, treatment-related details, photos, X-rays voluntarily provided by you
- Technical data: IP address, browser type, device information, referrer URL
- Usage data: pages visited, time on site, cookie identifiers, analytics events
04. How we use your personal data
Your personal data may be used for the following purposes:
- To respond to your inquiries and consultation requests
- To provide medical information and treatment offers
- To arrange communication with our medical team and partner clinics
- To improve our website and services
- To comply with legal and regulatory obligations
We do not sell or rent your personal data to third parties.
05. Legal basis for processing
We process your personal data based on:
- Article 6(1)(a) — Consent: your explicit, freely given, informed consent
- Article 6(1)(b) — Contract: performance of a contract or pre-contractual steps
- Article 6(1)(c) — Legal obligation: compliance with applicable laws and regulations
- Article 6(1)(f) — Legitimate interests: service improvement and communication, where these do not override your fundamental rights
- Article 9(2)(a) — Explicit consent for special category data: required for processing medical data
06. Data sharing and third parties
Your data may be shared only with:
- Authorized medical professionals and partner clinics involved in your treatment
- Technical service providers (hosting, CRM, analytics, communication platforms)
- Public authorities when required by law or court order
All third parties are contractually obligated to comply with GDPR requirements through Data Processing Agreements (DPAs).
07. Data retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy or to comply with legal requirements:
- Inquiry / consultation data: up to 36 months from your last interaction
- Patient records: as required by Turkish medical regulations (typically 15–20 years)
- Marketing communications: until you withdraw consent
- Website analytics: up to 26 months (Google Analytics default)
08. Data security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, misuse, or disclosure — including encryption in transit (TLS), access controls, secure storage of medical files, staff training on data protection, and regular security audits.
09. Your rights under GDPR
You have the following rights under GDPR:
- Right of access: obtain confirmation that we process your data and request a copy
- Right to rectification: request correction of inaccurate or incomplete data
- Right to erasure ("right to be forgotten"): request deletion of your data where applicable
- Right to restrict processing: limit how we use your data
- Right to data portability: receive your data in a machine-readable format
- Right to object: object to processing based on legitimate interests or direct marketing
- Right to withdraw consent at any time
- Right to lodge a complaint with a supervisory authority in the EU
To exercise your rights, please contact us using the details below — we respond within 30 days.
11. International data transfers
If your data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place in accordance with GDPR — typically via Standard Contractual Clauses (SCCs) approved by the European Commission, or transfers to countries deemed adequate by the EU.
12. Contact information
For questions regarding this GDPR Policy, your personal data, or to exercise your rights:
Data Protection Contact
Sweden Özel Sağlık Hizmetleri ve Danışmanlık A.Ş.
Şişli Plaza No: 1 C, Şişli 34360, Istanbul, Türkiye
Email: hello@swedishclinicturkey.com
Phone: +90 540 255 50 55
13. Updates to this policy
We reserve the right to update this GDPR Policy at any time. Any changes will be published on this page with an updated revision date. Material changes affecting how we process your personal data will be communicated to you via email.
This document was last updated in January 2026. By using this website or our services, you acknowledge that you have read and understood this policy.
