Privacy Policy, KVKK Information Notice, Cookie Policy, Consent Texts and Application Form
- Last updated: 24 September 2025
- Scope: This package concerns the processing of personal data of website visitors, prospective patients/patients, contact-form users, and recipients of commercial communications.
1) PRIVACY POLICY (WEBSITE)
1.1. Data Controller
Company Name: Hoi Sağlık Hizmetleri Turizm İnşaat Sanayi ve Ticaret A.Ş
Address: Ataköy 2–5–6. Kısım Mah. Rauf Orbay Cad. No:4 Yalı Ataköy C Blok Daire: 36
MERSİS/Company No.: 0463093931200001
Email: info@hairofistanbul.com
KEP: hoiturizm@hs01.kep.tr
Phone: +90 530 688 42 47
At Hair of Istanbul, we value your privacy. This Privacy Policy explains what personal data we collect when you use our website, for which purposes and legal bases we process it, with whom we may share it, how long we retain it, and your rights.
1.2. Categories of Data Collected
- Identity: name, surname, year/date of birth, country.
- Contact: email, phone, address, WhatsApp number.
- Transaction Security: IP address, session details, logs, device/browser information.
- Marketing/Profile: preferences and interests via cookies/pixels.
- Health Data: hair-loss status, procedure suitability, images (only with explicit consent).
- Visual/Audio: photos, videos, call recordings.
1.3. Purposes of Processing and Legal Bases
| Purpose | Example Activities | KVKK Legal Basis |
|---|---|---|
| Inquiry and appointment management | Contact forms, WhatsApp correspondence | Art. 5/2-c, 5/2-f |
| Treatment/health services | Pre-assessment, diagnosis, treatment | Art. 6/3 |
| Customer relations and satisfaction | Feedback, support requests | Art. 5/2-f |
| Compliance with legal obligations | Invoicing, reporting to authorities | Art. 5/2-ç |
| Security and fraud prevention | Log records, access control | Art. 5/2-f |
| Marketing/analytics/retargeting | Cookies, pixels, campaign reports | Art. 5/1 (explicit consent) |
| Sharing visuals (before/after) | Website and social media publication | Arts. 5/1, 6/2 (explicit consent) |
Note: Health data is not processed for marketing purposes; it can only be used with explicit consent and anonymisation.
1.4. Methods of Collection
- Website forms, email, phone, WhatsApp, live chat.
- Cookies, pixels, analytics tools.
- Documents provided during clinic application (physical/electronic).
1.5. Data Disclosures/Transfers
- Service providers: hosting, CRM, call center, marketing, analytics, security.
- Group companies: HOI Holding and affiliates.
- Authorities: when required by law.
- International transfers: pursuant to Art. 9 KVKK, to adequately protected countries or by explicit consent.
1.6. Retention Periods
- Contracts and financial records: up to 10 years.
- Medical records: per health legislation.
- Marketing data: until consent withdrawal.
- Logs: reasonable retention for security.
After the retention period, data is deleted, destroyed, or anonymised.
1.7. Your Rights (KVKK Art. 11)
- To learn if your data is processed
- To request information
- To learn third parties receiving data
- To request correction/deletion
- To object to automated decisions
- To claim compensation for damages
See Section 5 – Data Subject Application Form.
1.8. Third-Party Links
Our website may contain external links. We are not responsible for their privacy practices.
1.9. Security
Your data is protected by technical and administrative measures such as encryption, access control, and employee training.
2) KVKK INFORMATION NOTICE (WEBSITE VISITOR, PROSPECTIVE PATIENT/PATIENT)
This notice is provided by Hoi Sağlık Hizmetleri Turizm İnşaat Sanayi ve Ticaret A.Ş under Law No. 6698 on Personal Data Protection.
2.1. Data Processed and Purposes
- Identity/Contact: managing inquiries and communications.
- Health Data: diagnosis, treatment, and care.
- Finance: invoicing and payments.
- Visual/Audio: only with explicit consent.
- Marketing/Analytics: only with explicit consent.
2.2. Legal Bases
- KVKK Arts. 5/2-c, ç, e, f: contract, legal obligation, legitimate interest.
- Art. 6/3: health data processed by authorized professionals.
- Explicit consent: marketing, profiling, data transfer, visual use.
2.3. Transfers
- Domestic: authorities, hospitals, laboratories, logistics, translators.
- International: to adequately protected countries or by explicit consent.
2.4. Method of Collection
Collected via electronic (website, email, CRM) or physical channels.
2.5. Retention
In line with applicable law or until the processing purpose ceases.
2.6. Rights and Applications
See Section 5.
3) COOKIE POLICY
3.1. What Are Cookies?
Cookies are small text files stored on your device to enhance your browsing experience.
3.2. Types of Cookies
- Strictly Necessary: essential for functionality.
- Functional: remember preferences.
- Analytics: measure traffic and performance (consent-based).
- Marketing: retargeting and advertising (consent-based).
3.3. Third-Party Tools
We use Google Analytics/Ads, Meta pixels, and WhatsApp widgets, which may involve international transfers.
3.4. Cookie Management
You can manage cookies via your browser or Cookie Settings panel.
4) CONSENT TEXTS
4.1. Commercial Communication Consent
“I consent to receive commercial messages from Hoi Sağlık Hizmetleri Turizm İnşaat Sanayi ve Ticaret A.Ş via SMS, email, and calls.”
4.2. Marketing/Analytics Cookie Consent
“I consent to the use of non-essential cookies and to data transfer for advertising purposes.”
4.3. International Data Transfer Consent
“I consent to my personal data being processed on servers abroad.”
4.4. Visual Sharing Consent
“I consent to the publication of my before/after photos on Hair of Istanbul’s website and social media.”
5) DATA SUBJECT APPLICATION FORM (KVKK Art. 13)
Application Channels
- Email: info@hairofistanbul.com
- Post: Ataköy 2–5–6. Kısım Mah. Rauf Orbay Cad. No:4 Yalı Ataköy C Blok Daire: 36
- Signed petition or secure e-signature
Response time: within 30 days. Fees may apply as per the Authority’s tariff.
6) FREQUENTLY ASKED QUESTIONS
How can I withdraw cookie consent? You can update it anytime via the Cookie Settings link in the footer.
Do I have to communicate via WhatsApp? No. Email and phone are available alternatives.
Why are my visuals requested? For pre-assessment or, with explicit consent, case-sharing.
What happens if I withdraw consent? Marketing stops; legally required data is retained.
7) MANAGEMENT AND CHANGES
Any changes will be updated and published on our website.
WARNING / LEGAL NOTICE
These texts are templates prepared for general compliance. Review with your legal counsel for sector-specific adjustments.
en
TR
SK
ITA
FR
DE
ES
BG