Koru Health Group

Privacy Policy

How Koru Health Group collects, uses, protects and shares personal data of international patients and website visitors, and the rights you have.

Privacy Policy

Last updated: September 2026

Koru Health Group ("Koru", "we", "us" or "our") operates the website koruhospital.com (the "Website") to provide information about our hospital, medical departments, physicians and international patient services, and to allow prospective patients to contact us or request an appointment or a remote pre-assessment.

We are committed to protecting the privacy and security of the personal data of every person who visits our Website or communicates with us. This Privacy Policy explains what personal data we collect, why and on what legal basis we process it, with whom we share it, how long we keep it, how it is transferred internationally, and what rights you have.

Because we welcome patients from many countries, this Policy is designed to comply with both:

  • the Turkish Law on the Protection of Personal Data No. 6698 ("KVKK") and its secondary regulations, including the Regulation on the Transfer of Personal Data Abroad; and
  • the EU General Data Protection Regulation (EU) 2016/679 ("GDPR"), which applies to us under Article 3(2) GDPR to the extent we offer our services to individuals located in the European Union / European Economic Area ("EU/EEA") or monitor their behaviour through this Website.

Please read this Policy carefully. This Policy is an information notice, not a contract: your use of the Website does not constitute acceptance of this Policy, and we do not treat continued browsing as agreement to any processing that requires consent. Where the law requires your consent — for example for the processing of health data you submit through our forms, or for non-essential cookies — we ask for that consent separately and expressly (through a dedicated consent statement on the relevant form, or through the cookie banner), and you may refuse or withdraw it at any time. This Policy does not replace, and should be read together with, our Cookie Policy, Terms of Use and Medical Disclaimer.

1. Data Controller and Contact Details

The data controller responsible for the processing of personal data described in this Policy is:

  • Data controller: Koru Health Group [FULL REGISTERED TRADE NAME TO BE COMPLETED BY HOSPITAL]
  • Registered address: Kizilirmak Mah. 1450. Sokak No:13, Cukurambar, Cankaya/Ankara, Türkiye
  • MERSIS number: [MERSIS NUMBER TO BE COMPLETED BY HOSPITAL]
  • E-mail: [email protected] (central contact address of Koru Health Group)
  • Website: koruhospital.com

2. Data Protection Officer (DPO)

As an organisation processing health data on a large scale, we have appointed a Data Protection Officer within the meaning of Article 37 GDPR. You may contact our DPO with any question about this Policy or the processing of your personal data:

  • Data Protection Officer: [NAME TO BE COMPLETED BY HOSPITAL]
  • E-mail: [DPO E-MAIL TO BE COMPLETED BY HOSPITAL — e.g. [email protected]]

3. EU Representative (Article 27 GDPR)

As we are established outside the EU/EEA and process personal data of individuals located in the EU/EEA, we have designated a representative in the European Union in accordance with Article 27 GDPR. EU/EEA residents and supervisory authorities may address the representative in addition to, or instead of, contacting us directly:

  • EU Representative: [NAME AND ADDRESS OF APPOINTED EU REPRESENTATIVE TO BE COMPLETED BY HOSPITAL]
  • E-mail: [TO BE COMPLETED BY HOSPITAL]

4. Personal Data We Collect

We only collect personal data that is adequate, relevant and limited to what is necessary for the purposes described in this Policy. Depending on how you interact with the Website, we may process the following categories of data:

4.1 Data you provide to us directly

  • Identity and contact data: name, surname, date of birth, nationality, country of residence, telephone number, e-mail address, preferred language.
  • Enquiry and appointment data: the department, physician or treatment you are interested in, preferred dates, travel-related preferences, and the free-text content of your message.
  • Health data (special category data): any information about your medical condition, symptoms, diagnosis, medical history, current medication, test results, imaging or medical reports that you choose to share with us through our contact/appointment forms, by e-mail, or through messaging channels you initiate, for the purpose of receiving a preliminary assessment or planning your treatment.

Please share only the health information that is necessary for your enquiry. Information submitted through Website forms or e-mail does not form part of an official medical record until you are registered as a patient of our hospital, and online communication channels should never be used for medical emergencies.

4.2 Data we collect automatically

  • Technical and usage data: IP address, approximate location derived from IP, device and browser type, operating system, referring pages, pages visited, date and time of visits, and interactions with the Website.
  • Cookie and tracking data: data collected through cookies and similar technologies, including third-party analytics and advertising tools (Google Analytics, Yandex Metrika, Meta Pixel), only where legally permitted and, for non-essential cookies, only with your prior consent given through our cookie banner. Details, including how to withdraw consent at any time, are set out in our Cookie Policy.

4.3 Data we receive from third parties (Article 14 GDPR)

In some cases we receive your personal data from sources other than you, for example:

  • an international patient facilitator, medical travel agency or assistance company acting on your behalf;
  • a referring physician or hospital in your home country;
  • your insurance company or embassy, where they are involved in arranging your treatment;
  • a family member or companion who contacts us on your behalf (we ask them to do so only with your knowledge).

Where we obtain your data in this way, we will provide you with the information required by Article 14 GDPR at the latest at first contact with you, and this Policy applies to that data as well.

5. Purposes of Processing and Legal Bases

We process your personal data for the following purposes, each based on the legal grounds indicated below (Article 6 GDPR and, for health data, additionally Article 9 GDPR; corresponding grounds under Articles 5 and 6 KVKK apply in parallel):

Purpose Data categories Legal basis (GDPR)
Responding to your enquiries, providing information about our services, and managing appointment or consultation requests Identity, contact and enquiry data Art. 6(1)(b) — steps taken at your request prior to entering into a contract; Art. 6(1)(f) — our legitimate interest in responding to enquiries addressed to us
Conducting a preliminary medical assessment, obtaining a physician's opinion on suitability for treatment, and preparing a treatment plan and cost estimate Identity, contact, enquiry and health data Art. 6(1)(b) together with Art. 9(2)(a) — your explicit consent, and where a care relationship is established, Art. 9(2)(h) — provision of health care, medical diagnosis and treatment by or under the responsibility of professionals subject to the obligation of professional secrecy
Providing medical services once you become a patient (registration, diagnosis, treatment, follow-up, invoicing) Identity, contact, health, insurance and billing data Art. 6(1)(b), Art. 6(1)(c) — legal obligations under Turkish health legislation, and Art. 9(2)(h); a separate patient information and consent process applies at the hospital
Coordinating travel, accommodation, interpreting and companion services for international patients Identity, contact and necessary enquiry data Art. 6(1)(b); health data is shared with interpreters and coordinators only to the extent necessary and under confidentiality obligations, based on Art. 9(2)(a)/(h)
Sending you marketing communications, newsletters or service updates Identity and contact data Art. 6(1)(a) — your consent only. Marketing consent is requested separately from any consent relating to your medical enquiry, is never a condition of receiving care, and can be withdrawn at any time (see Section 10)
Website analytics, performance measurement and — where enabled — advertising measurement (Google Analytics, Yandex Metrika, Meta Pixel) Technical, usage and cookie data Art. 6(1)(a) — your consent given via the cookie banner; strictly necessary cookies rely on Art. 6(1)(f). We do not intentionally associate analytics or advertising data with your health information
Ensuring the security of the Website and our IT systems, and preventing fraud and abuse Technical and usage data Art. 6(1)(f) — our legitimate interest in network and information security
Establishing, exercising or defending legal claims and complying with legal obligations (tax, health, accreditation, official requests) All relevant categories Art. 6(1)(c), Art. 6(1)(f) and Art. 9(2)(f)

Where we rely on legitimate interests (Article 6(1)(f)), we have assessed that our interests are not overridden by your rights and freedoms; you may object to such processing as described in Section 10. Providing identity and contact data in our forms is necessary for us to respond to you — if you do not provide it, we will not be able to process your enquiry. Providing health data at the enquiry stage is voluntary; however, without it our physicians may be unable to give a meaningful preliminary assessment.

6. Special Category (Health) Data — Explicit Consent and Additional Safeguards

Health data is a special category of personal data under Article 9 GDPR and Article 6 KVKK. The principal legal basis for processing health data you submit through this Website is your explicit consent (Article 9(2)(a) GDPR; Article 6(2) KVKK), supplemented — once a care relationship is established — by Article 9(2)(h) GDPR (provision of health care by professionals bound by professional secrecy).

How your explicit consent is given: before you can submit a form that may contain health information, you are presented with a short consent statement and a separate, unticked checkbox (or an equivalent affirmative step). Only by actively confirming that statement do you give your explicit consent to the processing of the health data you choose to share, and to its transfer to Türkiye as described in Section 8. Sending health information to us by e-mail or through a messaging channel you initiate is likewise treated as processing based on your explicit, affirmative act of sharing that information for the purpose of a preliminary assessment; if you have doubts, please use the Website forms, which document your consent.

How to withdraw your consent: you may withdraw your explicit consent at any time, free of charge and with effect for the future, by writing to [email protected] or to the DPO (Section 2), or by using any withdrawal mechanism indicated on the relevant form. Upon withdrawal we will stop the consent-based processing and delete or anonymise the related health data, unless a statutory retention obligation (for example mandatory medical record-keeping for registered patients) requires us to keep it. Withdrawal does not affect the lawfulness of processing carried out before it.

We also apply the following enhanced protections to health data:

  • We process health data submitted through the Website only for preliminary assessment, treatment planning and the provision of health care — never for marketing or advertising purposes.
  • Health data is accessible only to authorised medical staff, international patient coordinators and interpreters bound by statutory and contractual confidentiality obligations.
  • All Website forms are transmitted over encrypted (SSL/TLS) connections.
  • We do not use analytics or advertising pixels on pages in a way that is intended to collect health information, and we configure such tools to operate only after your cookie consent.

7. Recipients of Personal Data

We share personal data only where necessary, on a need-to-know basis, and with appropriate contractual and technical safeguards. Depending on the purpose, recipients or categories of recipients may include:

  • Within Koru Health Group: our physicians, clinical departments, international patient services team and administrative staff.
  • Health service partners: external laboratories, imaging centres and consulted specialists involved in your assessment or treatment.
  • Interpreters and patient coordinators assisting your communication with our medical team.
  • Insurance companies and assistance providers, where you ask us to work with them or they arrange your treatment.
  • Medical travel facilitators or referring physicians, where they are involved in your care with your knowledge.
  • Service providers (processors): IT hosting, website maintenance, e-mail and communication platforms, appointment/CRM systems and translation services, acting on our documented instructions under data processing agreements (Article 28 GDPR).
  • Analytics and advertising providers: Google (Google Analytics), Yandex (Yandex Metrika) and Meta (Meta Pixel), in respect of cookie data processed with your consent, as described in our Cookie Policy. These providers may act as independent or joint controllers for certain processing.
  • Public authorities and courts, where disclosure is required by applicable law (for example Turkish Ministry of Health reporting obligations) or by a binding official request.

We do not sell personal data, and we do not share health data with third parties for their own marketing purposes.

8. International Data Transfers

Because we are located in Türkiye and serve patients worldwide, your personal data will be transferred across borders. We explain both directions of transfer below.

8.1 Transfers from the EU/EEA to Türkiye

Türkiye is a "third country" for GDPR purposes and is not covered by an adequacy decision of the European Commission. This means that when you, as a person located in the EU/EEA, submit personal data (including health data) through this Website, that data is transferred to Türkiye under the safeguards and derogations of Chapter V GDPR:

  • Where we receive personal data from EU/EEA-based partners (e.g. referring physicians, insurers, facilitators) on a structural basis, the transfer is governed by the European Commission's Standard Contractual Clauses (SCCs, Article 46(2)(c) GDPR), supplemented where necessary by additional technical and organisational measures. You may request a copy of the relevant clauses (redacted of commercial terms) via the contact details in Section 1.
  • Where you send us your own data directly to request a preliminary assessment or treatment, the transfer is additionally supported by the derogations of Article 49(1)(a) GDPR (your explicit consent to the transfer, after being informed of the possible risks of a transfer to a country without an adequacy decision) and Article 49(1)(b)/(c) GDPR (the transfer is necessary for pre-contractual steps taken at your request or for the performance of a contract concluded in your interest).

For the avoidance of doubt, transfers from the EU/EEA to Türkiye are governed exclusively by Chapter V GDPR as described above — that is, by Article 46 safeguards (such as SCCs) where applicable and/or the Article 49(1) derogations, in particular your explicit consent under Article 49(1)(a). The Turkish Regulation on the Transfer of Personal Data Abroad governs the opposite direction — transfers out of Türkiye (see Section 8.2) — and is not a legal mechanism for this inbound transfer.

Please be aware that data protection law in Türkiye differs from EU law in certain respects. Regardless of where your data is processed, we apply the protections described in this Policy, and Turkish law itself imposes strict confidentiality and data protection duties on health institutions under the KVKK and health legislation.

8.2 Transfers from Türkiye to other countries

Where we transfer personal data from Türkiye to recipients abroad (for example to your insurer, referring physician or facilitator in your home country, or to service providers operating outside Türkiye), we comply with Articles 9 et seq. KVKK and the Regulation on the Transfer of Personal Data Abroad (in force since Türkiye's July 2024 KVKK amendments). Such transfers are carried out on the basis of appropriate safeguards — primarily the standard contractual clauses published by the Turkish Personal Data Protection Authority ("KVKK Kurumu"), used without modification and notified to the Authority within the statutory period — or, where applicable, on another lawful ground recognised by the Regulation.

8.3 Analytics and advertising tools

Cookie data processed by Google, Yandex and Meta may be transferred to and processed in countries outside the EU/EEA and Türkiye (including the United States and the Russian Federation) in accordance with those providers' own transfer mechanisms. These tools run only with your consent, which you may refuse or withdraw at any time via our cookie settings; refusing them does not affect your ability to use the Website or contact us.

9. Retention Periods

We keep personal data only for as long as necessary for the purposes described above, and thereafter for as long as required by applicable law. Our main retention criteria are:

  • Enquiry and appointment request data (no patient relationship established): retained for up to 2 years from our last contact with you, unless a longer retention is required for the establishment, exercise or defence of legal claims, after which it is deleted or anonymised.
  • Medical records of registered patients: retained in accordance with mandatory Turkish health legislation, which requires health institutions to keep patient records for extended statutory periods (in principle 20 years under the applicable regulations on medical record-keeping; certain records longer where specific legislation so requires).
  • Invoicing, accounting and tax records: retained for the periods required by Turkish commercial and tax law (generally 5 to 10 years).
  • Marketing consent records and communications: retained until you withdraw consent, plus the period needed to demonstrate compliance.
  • Cookie data: retained for the lifetimes stated in our Cookie Policy.
  • Server and security logs: retained for the periods required by Turkish Law No. 5651 and our security procedures.

When retention periods expire, data is securely deleted, destroyed or irreversibly anonymised in accordance with our retention and destruction policy.

10. Your Rights

Subject to the conditions and exceptions set out in applicable law, you have the following rights in relation to your personal data:

  • Right of access (Art. 15 GDPR / Art. 11 KVKK): to obtain confirmation of whether we process your data and to receive a copy of it, together with the information listed in this Policy.
  • Right to rectification (Art. 16 GDPR): to have inaccurate data corrected and incomplete data completed.
  • Right to erasure (Art. 17 GDPR): to have your data deleted where there is no longer a legal ground for processing. Please note that statutory medical record retention obligations may prevent the deletion of patient records before the legal retention period expires.
  • Right to restriction of processing (Art. 18 GDPR): to require us to limit processing in the circumstances defined by law.
  • Right to data portability (Art. 20 GDPR): to receive the data you provided to us in a structured, commonly used, machine-readable format and to have it transmitted to another controller, where processing is based on consent or contract and carried out by automated means.
  • Right to object (Art. 21 GDPR): to object, on grounds relating to your particular situation, to processing based on legitimate interests, and to object at any time to processing for direct marketing purposes, in which case we will stop such processing.
  • Right to withdraw consent (Art. 7(3) GDPR): where processing is based on your consent or explicit consent, you may withdraw it at any time, free of charge, with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
  • Right not to be subject to solely automated decisions (Art. 22 GDPR): see Section 11 below.
  • Rights under KVKK Article 11, including the right to know whether your data is processed, to request information about the processing, to learn the third parties to whom it is transferred, and to claim compensation for damage caused by unlawful processing.

To exercise any of these rights, please contact us at [email protected] or through the DPO contact details in Section 2, stating your request clearly. We may need to verify your identity before acting on a request — this protects your data from disclosure to unauthorised persons. We will respond without undue delay and in any event within the statutory time limits (one month under the GDPR, extendable in complex cases; thirty days under the KVKK). Exercising your rights is free of charge, except where requests are manifestly unfounded or excessive.

Right to lodge a complaint

If you believe that our processing of your personal data infringes data protection law, you have the right to lodge a complaint with a supervisory authority:

  • if you are in the EU/EEA, with the data protection supervisory authority of the Member State of your habitual residence, place of work or the place of the alleged infringement (Art. 77 GDPR); and/or
  • with the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu — kvkk.gov.tr) under the KVKK, after first submitting your request to us as required by Turkish law.

We would, however, appreciate the opportunity to address your concerns directly first.

11. No Automated Decision-Making or Profiling

We do not use your personal data to make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR). All medical assessments, treatment suitability evaluations and appointment decisions are made by qualified human professionals. Analytics tools used on the Website produce aggregated statistics and, where you have consented, advertising measurement; they are not used to make automated decisions about individual patients.

12. Children's Data

The Website and its forms are directed at adults. We do not knowingly collect personal data directly from children under 16 through this Website. Enquiries concerning the medical treatment of a minor must be submitted by a parent or legal guardian, who is responsible for the accuracy of the information provided and for consenting on the child's behalf where the law allows. Where a child's health data is processed for treatment purposes, additional safeguards under Turkish health legislation and, where applicable, the GDPR apply. If you believe a child has provided us personal data without appropriate parental consent, please contact us so that we can delete it.

13. Data Security

We implement appropriate technical and organisational measures (Article 32 GDPR; Article 12 KVKK) designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction, including:

  • SSL/TLS encryption of all data transmitted through the Website;
  • access controls, role-based authorisation and logging on systems holding personal data;
  • confidentiality undertakings from staff and contractual security obligations for processors;
  • network security, monitoring and regular review of our security measures;
  • staff training on data protection and medical confidentiality.

No method of transmission over the internet is completely secure. While we work hard to protect your data, we cannot guarantee absolute security of information transmitted to the Website at your own initiative; please use the secure channels we provide and avoid sending more sensitive information than necessary. In the event of a personal data breach likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, you, in accordance with Articles 33–34 GDPR and Article 12 KVKK.

Nothing in this Policy (including the statements in this Section and in Section 15) excludes or limits any liability that cannot be excluded or limited under applicable law — in particular liability for death or personal injury caused by negligence, or liability arising from intent or gross negligence — and nothing in it affects the mandatory statutory rights you hold under applicable consumer protection, patient rights or data protection law.

14. Important Notes on Online Communication

  • This Website does not provide emergency services. If you have a medical emergency, call your local emergency number immediately (112 in Türkiye and the EU).
  • Information you send via Website forms or e-mail before registration is used for preliminary assessment only and does not constitute an official medical record or establish a physician–patient relationship; please see our Terms of Use and Medical Disclaimer.
  • If you contact us through third-party platforms (e.g. messaging or social media applications), the data you share is also subject to those platforms' own privacy policies, over which we have no control. For sensitive health information, we recommend using the secure channels indicated on our Website.

15. Third-Party Websites

The Website may contain links to external websites operated by third parties. This Policy applies only to koruhospital.com. We are not responsible for the privacy practices or content of third-party websites, and we encourage you to review their privacy policies before providing them any personal data.

16. KVKK Registration and Local Compliance

As a health institution processing personal data in Türkiye, Koru Health Group maintains its registration with the Turkish Data Controllers' Registry (VERBİS) and processes personal data in accordance with the KVKK, the Regulation on Personal Health Data, the Patient Rights Regulation and other applicable Turkish legislation. Separate KVKK clarification (aydınlatma) texts and explicit consent forms are provided in the course of hospital registration and treatment.

17. Changes to This Privacy Policy

We may update this Policy from time to time to reflect changes in our services, legal requirements or data processing practices. The current version will always be published on this page with its "Last updated" date. Where a change materially affects how we process your data — in particular your health data — we will take reasonable steps to bring it to your attention. We encourage you to review this page periodically.

18. Contact

For any questions, requests or complaints regarding this Privacy Policy or our processing of your personal data, please contact:

  • Koru Health Group — Kizilirmak Mah. 1450. Sokak No:13, Cukurambar, Cankaya/Ankara, Türkiye
  • E-mail: [email protected] (central contact address of Koru Health Group)
  • Data Protection Officer: [DPO CONTACT TO BE COMPLETED BY HOSPITAL]
  • EU Representative: [TO BE COMPLETED BY HOSPITAL]

This document is a general information text prepared for publication on koruhospital.com. It has been drafted with reference to the GDPR and the KVKK; final legal review and completion of the bracketed fields by the hospital's legal counsel is required before publication.