PRIVACY POLICY AND GDPR PRIVACY NOTICE
Last Updated: 10 July 2026
This Privacy Policy explains how personal data is processed when individuals visit www.aperahealthgroup.com, complete a contact or preliminary medical evaluation form, or contact Apera Health Group via WhatsApp, telephone, or email.
Apera Health Group operates in Türkiye and provides medical tourism services to individuals located in Europe. Accordingly, certain data processing activities may be subject to the General Data Protection Regulation (GDPR) of the European Union. The principles governing the GDPR’s extraterritorial application have also been clarified by the European Data Protection Board (EDPB).
1. Data Controller and Contact Information
Your personal data may be processed by the following entity:
- Data Controller: Apera Health Group
- Address: Uphill Towers, A76, Ataşehir, Istanbul, Türkiye
- Telephone: +90 850 241 70 78
- E-mail: [email protected]
- Website: www.aperahealthgroup.com
Throughout this Policy, Apera Health Group will hereinafter be referred to as “Apera.”
2. Scope of this Policy
This Policy applies to personal data collected through the following channels:
- Website
- Contact forms
- Preliminary medical evaluation forms
- Medical file and report upload areas
- WhatsApp communications
- Email correspondence
- Telephone calls
- Online or face-to-face meetings
- Information collected during patient coordination
- Post-treatment follow-up communications
No medical treatment, products, or healthcare services are sold through the website, and no online payments are accepted.
3. Categories of Personal Data That May Be Processed
3.1 Identity Information
The following identity information may be processed:
- Full name
- Age
- Date of birth
- Gender
- Nationality
- Passport or identity document information, where required
- Patient or application reference number
Passport and identity information is collected only where necessary for travel arrangements, hospital registration, or patient admission procedures.
3.2 Contact Information
The following contact information may be processed:
- Telephone number
- Email address
- WhatsApp number
- Country and city of residence
- Preferred language of communication
- Communication preferences
3.3 Health Information
For the purpose of evaluating an application, the following health-related information may be collected:
- Current complaints or symptoms
- Diagnosis and medical conditions
- Previous surgeries
- Current medications
- Allergies
- Height, weight, and Body Mass Index (BMI)
- Laboratory test results
- Medical reports and discharge summaries
- X-rays, MRI scans, CT scans, and other medical imaging
- Pathology reports
- Surgical reports
- Treatment and rehabilitation history
- Photographs or video recordings
- Pregnancy information
- Information regarding infectious diseases
- Any other health information necessary for medical evaluation
Health information is classified as special category personal data under the GDPR and is therefore processed with a higher level of protection.
Users are expected to submit only the information necessary for processing their application and conducting the preliminary medical evaluation.
3.4 Travel and Coordination Information
The following information may be processed for travel and organizational purposes:
- Arrival and departure dates for Türkiye
- Flight details
- Airport information
- Accommodation preferences
- Information regarding accompanying persons
- Transfer schedules
- Interpretation requirements
- Mobility or accessibility requirements
3.5 Service and Payment Information
No payments are accepted through the website, and no payment card information is collected online.
After the patient arrives in Türkiye and makes payment by cash or through a physical POS terminal, the following limited information may be processed:
- Payment amount
- Payment date
- Transaction details
- Invoice or receipt information
- Records indicating whether the payment was successful or unsuccessful
Apera does not store:
- Card security codes (CVV/CVC);
- Online banking passwords;
- Banking PIN codes;
- Full payment card numbers.
3.6 Website and Technical Information
During the use of the website, the following technical information may be processed:
- IP address
- Device and browser type
- Operating system
- Date and time of the visit
- Pages viewed
- Traffic source
- Language and country preferences
- Cookie preferences
- Approximate country or regional location
- Interactions with forms and contact buttons
- Advertising campaign and UTM parameters
- Security and error logs
Analytics and advertising cookies that are not strictly necessary shall only be activated after obtaining the required user consent.
3.7 Communication Records
The following communication records may be processed:
- WhatsApp conversations
- Email correspondence
- Notes from telephone conversations
- Patient coordinator notes
- Requests and complaint records
- Post-treatment follow-up communications
Telephone or video calls are not recorded unless the user has been informed in advance and any required consent has been obtained.
4. Purposes of Processing Personal Data
Personal data may be processed for the following purposes:
- Responding to applications and inquiries;
- Verifying the patient’s identity and contact information;
- Facilitating a preliminary medical evaluation;
- Forwarding medical documents to the relevant physician or healthcare institution;
- Identifying suitable physicians and hospitals;
- Assessing eligibility for treatment;
- Scheduling physician and hospital appointments;
- Preparing treatment and travel plans;
- Providing estimated information regarding the scope of services and costs;
- Arranging accommodation and medical hotel services;
- Organizing airport and local transportation;
- Providing medical interpretation services;
- Coordinating rehabilitation and dietitian support;
- Providing post-treatment follow-up and communication;
- Evaluating patient requests and complaints;
- Improving service quality and security;
- Maintaining accounting and payment records;
- Complying with legal obligations;
- Protecting legal rights;
- Securing information systems and the website;
- Sending promotional or informational communications where explicit consent has been provided.
Personal data shall not be processed in a manner incompatible with the purposes for which it was collected.
5. Legal Bases for Processing Personal Data
Personal data may be processed on one or more of the following legal bases.
5.1 Processing at the User’s Request
Where requested by the individual, personal data may be processed for the purpose of:
- Evaluating the application;
- Preparing physician and hospital options;
- Creating a service plan;
- Providing an estimated quotation.
5.2 Explicit Consent
Where no other valid legal basis exists, explicit consent may be obtained for the processing of health data and its disclosure to the relevant physicians or healthcare institutions.
Consent for processing health data must be kept separate from:
- Acceptance of the Privacy Policy;
- Acceptance of the Terms of Service;
- Marketing consent.
5.3 Legal Obligations
Personal data may be processed where necessary for:
- Accounting and financial records;
- Payment processing;
- Medical tourism requirements;
- Patient safety;
- Requests from competent public authorities;
- Management of legal disputes.
5.4 Legitimate Interests
Provided that the user’s fundamental rights and freedoms are not disproportionately affected, personal data may be processed for:
- Website and system security;
- Preventing fraud and misuse;
- Managing applications and complaints;
- Measuring service quality;
- Protecting legal rights;
- Resolving system and operational errors.
5.5 Vital Interests
Where an individual is incapable of providing consent in a genuine medical emergency, information necessary to protect the individual’s life or physical integrity may be disclosed to healthcare institutions.
6. Processing of Health Data
Health data is processed solely for the following purposes:
- Preliminary medical evaluation;
- Identifying the appropriate physician and hospital;
- Assessing eligibility for treatment;
- Preparing a safe treatment and travel plan;
- Coordinating the treatment process;
- Post-treatment follow-up;
- Ensuring patient safety.
Health data:
- Is not sold to advertising companies;
- Is not added to non-medical marketing databases;
- Is not published on social media without authorization;
- Is not used to create advertising profiles based on an individual’s health condition without consent;
- Is not transmitted to advertising platforms in the form of medical form content.
If a patient’s photograph, video, testimonial, or treatment story is to be used for advertising or promotional purposes, separate, explicit, and specific consent must first be obtained. Receiving medical treatment shall not be conditional upon granting promotional consent.
7. Parties with Whom Personal Data May Be Shared
Personal data may be shared only to the extent necessary with the following categories of recipients.
7.1 Healthcare Service Providers
- Specialist physicians;
- Hospitals;
- Clinics;
- Laboratories;
- Medical imaging centers;
- Rehabilitation centers;
- Physiotherapists;
- Dietitians;
- Nurses;
- Other authorized healthcare professionals.
7.2 Operational Service Providers
- Accommodation and medical hotel providers;
- Transfer companies;
- Medical interpreters;
- Patient coordinators;
- Travel and operations teams.
These parties receive only the information necessary to provide their respective services. For example, a transfer company will not receive a detailed medical report.
7.3 Technical Service Providers
- Website hosting providers;
- Email service providers;
- CRM and patient management systems;
- Cloud storage providers;
- Cybersecurity service providers;
- Technical support providers;
- Cookie and analytics service providers.
7.4 Financial and Legal Service Providers
- Banks and physical POS payment providers;
- Accounting and financial advisory firms;
- Legal advisors;
- Competent public authorities;
- Courts and administrative authorities.
No recipient is provided with the patient’s complete medical file. Data sharing is limited to the information necessary for the relevant service.
8. Independent Role of Physicians and Hospitals
Apera may manage the patient’s application and coordinate the medical tourism process. Once the patient’s information has been shared with the relevant physician or hospital, those individuals or institutions may act as independent data controllers with respect to:
- Medical diagnosis;
- Treatment decisions;
- Patient records;
- Surgical procedures;
- Medical documentation;
- Clinical follow-up.
The relevant hospital or physician may also provide their own Privacy Policy and Patient Information Notice.
9. Processing of Data in Türkiye
Apera operates in Türkiye. Accordingly, personal data provided by individuals located in Europe may be processed:
- By Apera’s teams in Türkiye;
- By physicians and hospitals located in Türkiye;
- Through systems operated or accessed in Türkiye.
Such processing may constitute an international transfer of personal data outside the European Union.
Where applicable, such transfers may rely on:
- The individual’s explicit consent;
- The necessity of the transfer for the performance of services requested by the individual;
- Data protection agreements concluded with service providers;
- Appropriate technical and organizational security measures;
- Standard Contractual Clauses (SCCs), where required.
The European Commission recognizes Standard Contractual Clauses (SCCs) as one of the appropriate safeguards for transfers of personal data between the European Union and third countries.
10. Personal Data Retention Periods
Personal data will be retained only for as long as necessary to fulfill the purposes for which it was collected.
The general retention periods applied by Apera may include:
- Applications that do not result in treatment: 2 years from the date of the last communication;
- Contact and preliminary evaluation records: 3 years from the date of the last activity;
- Medical reports and application documents: 3 years from the date of the last activity or communication;
- Patient coordination records for individuals receiving services: 10 years following completion of the services;
- Payment, accounting, and invoicing records: 10 years from the transaction date;
- Contracts and quotations: 10 years following completion of the services;
- Complaint and dispute records: 10 years following closure of the relevant case;
- Marketing communication consents: Until consent is withdrawn or 2 years after the last interaction, whichever occurs first;
- Cookie preferences: Up to 2 years;
- Website security and access logs: Up to 1 year;
- Records relating to deletion requests or withdrawal of consent: 3 years after the request has been fulfilled.
Where a legal dispute, official investigation, or legal obligation is ongoing, the relevant data may be retained for a longer period where necessary.
Upon expiry of the applicable retention period, personal data will be:
- Deleted;
- Anonymized; or
- Securely destroyed.
11. Data Security
Apera implements reasonable technical and organizational measures to protect personal data.
Such measures may include:
- Role-based access controls;
- Strong password policies;
- Multi-factor authentication;
- Encrypted internet connections;
- Secure servers and backup systems;
- Staff confidentiality obligations;
- Access logging;
- Malware protection;
- Regular access control reviews;
- Data protection training;
- Data processing agreements with technical service providers;
- Personal data breach response procedures.
No method of transmitting information over the Internet is completely secure. Users are therefore encouraged to use secure devices, up-to-date software, and trusted internet connections.
12. WhatsApp, Email, and Other Communication Channels
When patients communicate with Apera via WhatsApp, email, or telephone, the data processing practices of those communication platforms may also apply.
Users are expected to:
- Avoid sending medical documents through publicly accessible links;
- Avoid sharing unnecessary health information;
- Avoid using unsecured shared devices when communicating;
- Maintain the security of their WhatsApp and email accounts.
Health documents received through WhatsApp may, where necessary, be incorporated into the patient’s medical file, with access restricted to authorized personnel only.
13. Başkası adına yapılan başvurular
Başka bir kişi adına başvuru yapan kullanıcı, ilgili kişinin verilerini paylaşmaya yetkili olduğunu kabul eder.
Apera gerekli görürse:
- veri sahibinden doğrudan teyit,
- temsil yetkisi,
- ebeveynlik veya vasilik belgesi isteyebilir.
14. Reşit olmayan kişilerin verileri
Reşit olmayan bir kişinin başvurusu ebeveyni, vasisi veya hukuken yetkili temsilcisi tarafından yapılmalıdır.
Reşit olmayan kişiye ait sağlık verilerini gönderen kişi, bu bilgileri paylaşma yetkisine sahip olduğunu kabul eder.
Gerekli hâllerde temsil veya velayet belgesi istenebilir.
15. Otomatik karar verme
Apera, yalnızca otomatik sistemler tarafından verilen ve kişi üzerinde önemli sonuç doğuran tıbbi kararlar vermeyi amaçlamaz.
Form bilgileri;
- başvuruyu ilgili bölüme yönlendirmek,
- ülke ve dil seçmek,
- tedavi alanını sınıflandırmak amacıyla otomatik olarak kullanılabilir.
Ancak tıbbi uygunluk, teşhis ve tedavi kararları ilgili doktor veya sağlık kuruluşu tarafından verilir.
16. Pazarlama ve iletişim izni
Hizmet, kampanya veya bilgilendirme mesajları yalnızca gerekli izin bulunduğunda gönderilir.
Kullanıcı bu izni istediği zaman:
- WhatsApp üzerinden bildirimde bulunarak,
- e-postayla talep göndererek,
- e-posta içindeki çıkış seçeneğini kullanarak geri çekebilir.
Pazarlama izninin geri çekilmesi, tedavi sürecinin yürütülmesi için gerekli iletişimi durdurmaz.
Hasta başvurusu, sağlık verisi rızası ve pazarlama izni ayrı işlemler olarak değerlendirilir.
17. Çerezler ve analiz araçları
Sitede aşağıdaki çerez türleri kullanılabilir:
- Kesinlikle gerekli çerezler
- İşlevsellik çerezleri
- Analitik çerezler
- Reklam ve pazarlama çerezleri
Zorunlu olmayan çerezler, kullanıcı onay vermeden çalıştırılmamalıdır.
Google Analytics, Google Ads, Meta Pixel veya benzeri araçlar kullanılıyorsa kullanıcının sağlık formuna yazdığı bilgiler bu sistemlere gönderilmemelidir.
Ayrıntılar Çerez Politikası içinde açıklanır.
18. Kullanıcı hakları
Uygulanabilir veri koruma kuralları kapsamında kullanıcılar aşağıdaki haklara sahip olabilir:
- Kişisel verilerinin işlenip işlenmediğini öğrenme
- Verilerine erişme
- Eksik veya yanlış verileri düzelttirme
- Uygun şartlarda verilerin silinmesini isteme
- İşlemenin sınırlandırılmasını isteme
- Belirli işlemlere itiraz etme
- Uygun şartlarda veri taşınabilirliği talep etme
- Verdiği açık rızayı geri çekme
- Otomatik işlemler hakkında bilgi alma
- Yetkili veri koruma makamına şikâyette bulunma
Rızanın geri çekilmesi, geri çekilmeden önce yapılan işlemlerin hukuka uygunluğunu etkilemez.
Aşağıdaki durumlarda silme veya benzeri talepler tamamen karşılanamayabilir:
- Yasal saklama yükümlülüğü
- Tıbbi kayıt zorunluluğu
- Devam eden tedavi veya hasta güvenliği
- Hukuki taleplerin oluşturulması veya savunulması
- Yetkili makam talebi
- Başka kişilerin haklarının korunması
19. Hakların kullanılması
Kullanıcılar veri koruma taleplerini aşağıdaki iletişim kanallarından iletebilir:
Apera Health Group
Uphill Towers, A76, Ataşehir, İstanbul, Türkiye
Telefon: +90 850 241 70 78
E-posta: [email protected]
Başvuruda aşağıdaki bilgilerin bulunması önerilir:
- Ad ve soyad
- Başvuruda kullanılan telefon veya e-posta
- Talebin açık açıklaması
- Varsa hasta veya başvuru numarası
Apera, talepte bulunan kişinin gerçekten veri sahibi olduğunu doğrulamak amacıyla makul ölçüde ek bilgi isteyebilir.
Kimlik doğrulama için gereğinden fazla belge talep edilmez.
20. Veri ihlalleri
Kişisel verilerin:
- kaybolması,
- yetkisiz kişilere açıklanması,
- yanlış kişiye gönderilmesi,
- yetkisiz erişime uğraması,
- değiştirilmesi veya
- kullanılamaz hale gelmesi durumunda olay değerlendirilir.
Uygulanabilir mevzuat gerektiriyorsa ilgili kişilere ve yetkili makamlara gerekli bildirimler yapılır.
21. Üçüncü taraf bağlantıları
Sitede aşağıdaki platformlara bağlantı verilebilir:
- YouTube
- Google Maps
- Doktor ve hastane siteleri
- Yorum ve değerlendirme platformları
Bu platformların veri işleme faaliyetleri kendi gizlilik politikalarına tabidir.
Apera, üçüncü taraf sitelerin veri güvenliği veya gizlilik uygulamalarından sorumlu değildir.
22. Politika değişiklikleri
Bu Gizlilik Politikası;
- hizmetlerin değişmesi,
- yeni doktor veya sağlık kuruluşlarıyla çalışılması,
- kullanılan teknolojilerin değişmesi,
- yeni ülkelere hizmet verilmesi,
- mevzuat değişiklikleri nedeniyle güncellenebilir.
Güncel politika, internet sitesinde yayımlandığı tarihten itibaren geçerli olur.
Önemli değişiklikler gerektiğinde internet sitesi veya iletişim kanalları üzerinden duyurulabilir.
23. Dil
Bu metin aşağıdaki dillerde yayımlanabilir:
- İngilizce
- Romence
- Almanca
- Hırvatça
- İspanyolca
Çeviriler arasında farklılık olması hâlinde, yasal olarak izin verilen ölçüde İngilizce metin esas alınır.
Kullanıcının kendi ülkesindeki zorunlu veri koruma hakları saklıdır.
24. İletişim
Bu politika veya kişisel verileriniz hakkında sorularınız için:
Apera Health Group
Uphill Towers, A76, Ataşehir, İstanbul, Türkiye
Telefon: +90 850 241 70 78
E-posta: [email protected]
