HeartInCare Health Professional Explicit Consent Text

The Law on Protection of Personal Data No. 6698 (KVKK) came into force by being published in the Official Gazette dated 07.04.2016. In summary, the Law defines personal data, the processing and protection thereof, sets out the general conditions for processing and protecting personal data, and determines the sanctions to be applied in case of non-compliance with the processing and protection rules.

As INVICTUS (hereinafter referred to as the "COMPANY"), we attach importance to the protection of the personal data of our valued business partner doctors, application developers, and the people we cooperate with. This explicit consent text has been prepared in accordance with the principles determined in the INVICTUS PERSONAL DATA PROTECTION AND PROCESSING POLICY.

According to KVKK No. 6698, "Personal Data" means any information relating to an identified or identifiable natural person. By signing this explicit consent text, you accept the collection and processing of your personal data. The COMPANY may process personal data without the explicit consent of the data subject (business partner doctors, our application developers) in exceptional cases specified in the KVKK.

Our company may collect and process the identity, contact, financial, legal transaction, and physical space security information of its customers, business partners, or suppliers within the scope of KVKK.

DATA CATEGORIES AND PROCESSING PURPOSES

DATA TYPEDATA INFORMATIONPURPOSE OF DATA PROCESSING
IDENTITY INFORMATIONName - Surname, T.R. Identity No., Date of Birth, Place of Birth, Photo, any information on the Old Identity Card or New Identity Card, documents such as driver's license, passport etc. submitted as a substitute for identity card, and name-surname information of family members or relatives for receiving test-analysis results by the customer.Execution of Activities in Compliance with Legislation, Execution of Finance and Accounting Affairs, Ensuring Physical Space Security, Follow-up and Execution of Legal Affairs, Execution of Communication Activities, Execution / Audit of Business Activities, Execution of Business Continuity Activities, Execution of Goods / Services Purchasing Processes, Execution of Storage and Archive Activities, Execution of Contract Processes, Informing Authorized Persons, Institutions and Organizations, Execution of Management Activities
CONTACT INFORMATIONAddress, phone, e-mail information.Execution of Emergency Management Processes, Execution of Information Security Processes, Execution of Activities in Compliance with Legislation, Execution / Audit of Business Activities, Execution of Processes, Execution of Storage and Archive Activities, Execution of Contract Processes, Informing Authorized Persons, Institutions and Organizations, Execution of Management Activities, Execution of Communication Activities
LEGAL TRANSACTION INFORMATIONInformation in correspondence with judicial authorities, lawsuit file information, foreclosure warrants etc.Fulfillment of Obligations Arising from Employment Contract and Legislation for Employees, Execution of Activities in Compliance with Legislation, Execution of Finance and Accounting Affairs, Follow-up and Execution of Legal Affairs, Execution of Storage and Archive Activities
FINANCIAL INFORMATIONBank account no, IBAN no, credit card information, invoicing and invoice information, interest amount and rate to be paid, debt balance, credit balance, promissory notes, check information, demand-order information etc.Execution of Activities in Compliance with Legislation, Execution of Finance and Accounting Affairs, Follow-up and Execution of Legal Affairs, Execution of Goods / Services Purchasing Processes, Execution of Contract Processes, Informing Authorized Persons, Institutions and Organizations
PHYSICAL SPACE SECURITY INFORMATIONCCTV recordings taken if our suppliers or business partners are visitors in our company.Ensuring Physical Space Security, Execution of Storage and Archive Activities, Ensuring Security of Movable Property and Resources, Informing Authorized Persons, Institutions and Organizations

NOTE: INVICTUS DATA INVENTORY and PERSONAL DATA PROTECTION POLICY IS AN ATTACHMENT TO THIS DECLARATION.

LEGAL GROUNDS FOR PROCESSING AND TRANSFER

A group of your personal data mentioned above is processed limited to the purposes mentioned above. Your personal data; in accordance with Article 5 of the KVKK;

"It is expressly provided for by the laws, it is necessary to process the personal data of the parties to the contract, provided that it is directly related to the establishment or performance of a contract, it is mandatory for the data controller to fulfill its legal obligation, and provided that it does not harm the fundamental rights and freedoms of the data subject, data processing is mandatory for the legitimate interests of the data controller"

based on legal grounds, may be collected and processed in the form of processing information transferred to our company during the performance of a contract, processing information transmitted during the performance of the contract, the continuation of the commercial relationship, or via e-mail channels and other applications through written/oral/electronic/digital methods.

Your personal data may be transferred in accordance with the provisions of KVKK and relevant legal legislation to legally authorized public institutions and organizations, legally authorized private law legal entities, our business partners, shareholders, company officials, employees, and software and financial consultancy firms with which our company works on a contractual basis.

Transfer Abroad

In addition, although personal data can be transferred to foreign countries declared to have adequate protection by the Board or to countries where the commitment and permission conditions are met in case of lack of adequate protection, your data is stored by the main service provider Huawei through servers located in Germany, and the transfer of your data abroad is in question only at the point of data storage. You should also examine the existing foreign data storage text in detail regarding this.

RETENTION AND DELETION

The COMPANY retains personal data in accordance with the purpose specified in this explicit consent text and by taking necessary security measures in accordance with the obligations brought by legal regulations and personal data processing purposes. Although it has been processed in accordance with the provisions of KVKK and other relevant laws, in case the reasons requiring processing cease to exist (if the processing purpose has ended; relevant legislation and retention periods determined by the Company have expired; excluding purposes such as constituting evidence in possible legal disputes or asserting the relevant right depending on personal data or establishing a defense), personal data is deleted, destroyed or anonymized by the COMPANY ex officio or upon the request of the data subject.

RIGHTS OF THE DATA SUBJECT (KVKK Art. 11)

As a personal data owner, you have the following rights in accordance with Article 11 of the KVKK:

  1. To learn whether personal data is processed,
  2. To request information if personal data has been processed,
  3. To learn the purpose of processing personal data and whether they are used in accordance with their purpose,
  4. To know the third parties to whom personal data is transferred domestically or abroad,
  5. To request correction of personal data in case of incomplete or incorrect processing,
  6. To request deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of KVKK,
  7. To request notification of the transactions made pursuant to subparagraphs (d) and (e) to third parties to whom personal data has been transferred,
  8. To object to the occurrence of a result against the person himself by analyzing the processed data exclusively through automated systems,
  9. To request compensation for the damage in case of loss due to unlawful processing of personal data.

APPLICATION TO THE DATA CONTROLLER

You must submit your requests regarding your rights listed above by filling out the application form at https://www.heartincare.com or via a written document to the COMPANY's open address found on the https://www.heartincare.com website via post, or by sending it to one of the [email protected] e-mail addresses. The COMPANY, as the data controller, concludes the requests in the application free of charge as soon as possible and within thirty days at the latest depending on the nature of the request. However, if the transaction requires an additional cost, the fee in the tariff determined by the Board may be charged.

* This document is for informational purposes.