PROF. DR. HASAN GÖÇER CLINIC
PERSONAL DATA RETENTION AND DISPOSAL POLICY
INTRODUCTION – Purpose of the Policy
In accordance with Article 20 of the Constitution, the Law on the Protection of Personal Data No. 6698 (“the Law”), and the provisions of the applicable regulations and circulars, the processing of personal data collected by Prof. Dr. Hasan Göçer, the protection of data subjects’ fundamental rights and freedoms, and the establishment of principles regarding the protection, retention, and, where necessary, destruction of personal data constitute the purpose of this Policy.
MATTERS RELATING TO THE PROTECTION OF PERSONAL DATA
2.1. Ensuring the Security of Personal Data
Pursuant to Article 12 of Law No. 6698, the data controller; is obligated to take all necessary administrative and technical measures to ensure an appropriate level of security in order to prevent the unlawful processing of personal data, prevent unlawful access to such data, and ensure its proper safeguarding. Prof. Dr. Hasan Göçer implements all necessary measures within this scope.
2.2. Protection of Special Category Personal Data
Sensitive personal data, such as the health data of data subjects, may be processed without the data subject’s explicit consent by persons or authorized institutions and organizations subject to a duty of confidentiality, for the purposes of protecting public health, preventive medicine, and the provision of medical diagnosis, treatment, and care services.
STORAGE AND DISPOSAL OF PERSONAL DATA
Your personal data held by Prof. Dr. Hasan Göçer is retained only for as long as necessary for the data processing activity; and if the obligation to delete, destroy, or anonymize personal data arises, such data will be deleted, destroyed, or anonymized within the first periodic destruction period following the date on which this obligation arises.
Personal Data Retention Periods:
| Personal Data Category | Retention Period |
| Health Data (examinations, laboratory results, prescriptions, patient records, etc.) | 30 years from the termination of the activity |
| Records Related to Accounting and Financial Transactions | 10 years |
| Cookies and Log Records | 6 months – up to 2 years |
| Traffic Information Regarding Online Visitors | 2 Years |
| Personal Data Regarding Suppliers | 10 years after the legal relationship ends |
| Contracts | 10 years from the termination of the contract |
| Human Resources Processes | 10 years from the end of the activity |
| CCTV Camera Recordings | 90 Days |
| Job Applications (Rejected) | 1 Year |
| Internet Network Traffic Data (IP, connection duration, etc.) | 2 Years |
| Personnel File Data Under the Labor Code | 10 years from the termination of the employment relationship |
ADMINISTRATIVE AND TECHNICAL MEASURES
Administrative Measures:
- Preparation of the Personal Data Processing Inventory
- Corporate Policies (Access, Information Security, Use, Retention, and Destruction)
- Confidentiality Agreements
- Internal Periodic Audits and Risk Analyses
- Training and Awareness Activities for Employees
- Notification to the Data Controller Registry Information System (VERBİS)
Technical Measures:
- Authorization Matrix and Access Controls
- Network Security and Encryption
- Up-to-Date Antivirus Systems
- Firewalls
- Data Loss Prevention Software
- Backup Systems
Data Controller: Prof. Dr. Hasan Göçer
Address: Hakkı Yeten St. No. 11/13, Şişli / Istanbul
Phone: +90 532 604 02 44
Email: [email protected]
Website: https://hasangocer.com.tr
