The Law on Protection of Personal Data No. 6698 (KVKK) came into force by being published in the Official Gazette dated 07.04.2016. In summary, the Law defines personal data, the processing and protection thereof, sets out the general conditions for processing and protecting personal data, and determines the sanctions to be applied in case of non-compliance with the processing and protection rules.
As İnvictus Turizm Kongre ve Organizasyon Hizmetleri Ltd. Şti. (hereinafter referred to as the COMPANY), we attach importance to the protection of the personal data of our valued customers, business partners, suppliers, and persons we cooperate with. This explicit consent text has been prepared in accordance with the principles determined in the INVICTUS PERSONAL DATA PROTECTION AND PROCESSING POLICY.
According to KVKK No. 6698, “Personal Data” means any information relating to an identified or identifiable natural person. By signing this explicit consent text, you accept the collection and processing of your personal data. The COMPANY may process personal data without the explicit consent of the data subject (customer) in exceptional cases specified in the KVKK.
Our company may collect and process the identity, contact, customer transaction, physical space security, health, and genetic data information of its customers within the scope of KVKK.
| DATA TYPE | DATA INFORMATION | PURPOSE OF DATA PROCESSING |
|---|---|---|
| IDENTITY INFORMATION | Name - Surname, T.R. Identity No., Date of Birth, Place of Birth, Photo, any information on the Old Identity Card or New Identity Card, information contained in documents such as driver's license, passport which are identity distinguishing cards submitted as a substitute for identity card, and name-surname information of family members or relatives for the customer to receive test/analysis results. | Emergency Management, Information Security, Access Authorizations, Compliance with Legislation, Finance and Accounting, Physical Space Security, Legal Affairs, Communication Activities, Business Activities / Audit, Occupational Health / Safety Activities, Business Continuity, Goods / Services Purchasing Processes, Customer Relations Management, Storage and Archiving, Contract Processes, Request / Complaint Tracking, Informing Authorized Persons, Institutions and Organizations, Management Activities. |
| CONTACT INFORMATION | Address, phone, e-mail information and contact information of family members or relatives for the customer to receive test/analysis results. | Emergency Management, Information Security, Compliance with Legislation, Business Activities / Audit, Customer Relations Management, Storage and Archiving, Contract Processes, Request / Complaint Tracking, Informing Authorized Persons, Institutions and Organizations, Management Activities, Communication Activities. |
| CUSTOMER TRANSACTION INFO | Bank account no, IBAN no, credit card information, invoicing and invoice information etc. | Compliance with Legislation, Finance and Accounting, Legal Affairs, Goods / Services Purchasing Processes, Contract Processes, Informing Authorized Persons, Institutions and Organizations. |
| PHYSICAL SPACE SECURITY | CCTV recordings of customers and visitors. | Audit / Ethics Activities, Access Authorizations, Physical Space Security, Storage and Archiving, Movable Property and Resource Security, Informing Authorized Persons, Institutions and Organizations. |
| HEALTH INFORMATION | Body-mass index collected through wearable technological products, heart rate and rhythm, body temperature, blood pressure, respiratory rate, oxygen and stress level, blood sugar amount, sleep pattern, examination data to be obtained after doctor control, genetic disease information from parents, all kinds of health data necessary for the execution of the work including but not limited to biometric and genetic data, legally mandatory health documents, disability status certificate, health reports, occupational disease records if any, employment examination form, blood type information in driver's license and old identity document, declaration document regarding any significant past illness or surgery. | Transmitting user health data, which is the main activity of the company, to the doctor chosen by the user, Compliance with Legislation, Business Activities / Audit, Business Continuity, Storage and Archiving, Contract Processes. |
| GENETIC INFORMATION | … | Compliance with Legislation, Business Activities / Audit, Business Continuity, Storage and Archiving, Contract Processes, Informing Authorized Persons, Institutions and Organizations, Transmitting user health data, which is the main activity of the company, to the doctor chosen by the user. |
A group of your personal data mentioned above is processed limited to the purposes mentioned above. Your personal data; in accordance with Article 5 of the KVKK; based on the legal grounds of “it is expressly provided for by the laws, it is necessary to process the personal data of the parties to the contract, provided that it is directly related to the establishment or performance of a contract, it is mandatory for the data controller to fulfill its legal obligation, and provided that it does not harm the fundamental rights and freedoms of the data subject, data processing is mandatory for the legitimate interests of the data controller”, may be collected and processed in the form of processing information transferred to our company during the performance of a contract, processing information transmitted during the performance of the contract, the continuation of the commercial relationship, or via e-mail channels and other applications through written/oral/electronic/digital methods.
Your personal data may be transferred in accordance with the provisions of KVKK and relevant legal legislation to legally authorized public institutions and organizations, legally authorized private law legal entities, our business partners, shareholders, company officials, contracted health institutions, and our employees in case of your request.
Your body-mass index collected through wearable technological products belonging to you, heart rate and rhythm, body temperature, blood pressure, respiratory rate, oxygen and stress level, blood sugar amount, sleep pattern, examination data to be obtained after doctor control, genetic disease information from parents, test, diagnosis and follow-up data, examination results may be shared with doctors integrated into the application.
Also, apart from those listed above, upon your written or oral request, it may be transferred to third parties you specify, provided that the third party presents identity.
In addition, although personal data can be transferred to foreign countries declared to have adequate protection by the Board or to foreign countries where the data controllers in Turkey and the relevant foreign country undertake adequate protection in writing and the Board's permission acts in case of lack of adequate protection, your data is stored by the main service provider Huawei through servers located in Germany, and transfer of your data abroad is in question only at the point of data storage. You should also examine the existing foreign data storage text regarding this in detail.
The COMPANY retains personal data in accordance with the purpose specified in this explicit consent text and by taking necessary security measures in accordance with the obligations brought by legal regulations and personal data processing purposes. Although it has been processed in accordance with the provisions of KVKK and other relevant laws, in case the reasons requiring processing cease to exist (if the processing purpose has ended; relevant legislation and COMPANY's determined retention periods have expired; except for the purpose of constituting evidence in possible legal disputes or claiming the relevant right related to personal data or establishing a defense), personal data is deleted, destroyed or anonymized by the COMPANY ex officio or upon the request of the data subject.
As a personal data owner pursuant to Article 11 of KVKK, you have the rights to; (a) Learn whether personal data is processed, (b) Request information if personal data has been processed, (c) Learn the purpose of processing personal data and whether they are used in accordance with their purpose, (d) Know the third parties to whom personal data is transferred domestically or abroad, (e) Request correction of personal data in case of incomplete or incorrect processing, (f) Request deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of KVKK, (g) Request notification of the transactions made pursuant to subparagraphs (d) and (e) to third parties to whom personal data has been transferred, (h) Object to the occurrence of a result against the person himself by analyzing the processed data exclusively through automated systems, (i) Request compensation for the damage in case of loss due to unlawful processing of personal data.
You must submit your requests regarding your rights listed above to our company by filling out the application form at https://www.heartincare.com or by sending a written document to the COMPANY at the open address on the https://www.heartincare.com website via post or to one of the “[email protected]” e-mail addresses. The COMPANY, as the data controller, concludes the requests in the application free of charge as soon as possible and within thirty days at the latest depending on the nature of the request. However, if the transaction requires an additional cost, the fee in the tariff determined by the Board may be charged.
* This document is for informational purposes.