Summary: We collect information you provide (e.g., name, phone, email, enquiry details) to respond to your request and manage appointments. We may also use cookies and analytics to operate and improve the Website. You can contact us to exercise your privacy rights.
1) Who we are (Data Controller)
Data Controller: Dr. Nilüfer YÜKSEL
Address: Şirinyalı Mahallesi İsmet Gökşen Caddesi Savaş Apartmanı, No:65 Kat:2, 07160 Muratpaşa/Antalya, Turkey
Email: info@niluferyuksel.com
Phone: +90 553 069 4488
“We”, “us”, and “our” refer to the Data Controller above.
2) Scope
This Privacy Policy applies to:
- Visitors to niluferyuksel.com (the “Website”)
- People who contact us via contact forms, email, phone, WhatsApp or other messaging channels
- People who request or book appointments or consultations
- People who interact with our ads or marketing campaigns (e.g., via Google Ads)
If you are already a patient, additional privacy notices may apply at the clinic (e.g., medical record notices).
3) Personal data we collect
A. Information you provide to us
- Identity & contact data: name, email address, phone number, country/city, preferred contact method.
- Appointment/consultation data: requested service, preferred dates/times, and notes you submit.
- Communications: messages sent via forms, email, WhatsApp, phone call summaries, and follow-up messages.
- Optional documents: information you choose to share to support your enquiry (only if requested and you choose to provide it).
B. Information we collect automatically
- Device & usage data: IP address, browser type, device identifiers, operating system, pages viewed, clicks, referring pages, and timestamps.
- Approximate location: derived from IP address (e.g., country/city-level).
- Cookie data: see Section 7.
C. Information from third parties
- Advertising platforms: we may receive aggregated ad performance data (e.g., clicks, impressions) from platforms such as Google Ads.
- Analytics providers: we may receive usage analytics (often aggregated) to understand Website performance.
Important: Please avoid submitting highly sensitive medical information via website forms unless specifically requested. If you need urgent medical help, contact local emergency services.
4) How we use your data
We use personal data for the following purposes:
- Responding to enquiries: to reply to your messages and provide information about services.
- Appointments & administration: to schedule, confirm, change, or cancel appointments and to manage related communications.
- Service suitability & pre-consultation: to understand your enquiry and determine what information is needed for a consultation.
- Website operation: to maintain, troubleshoot, and improve the Website’s performance and security.
- Analytics: to understand how visitors use our Website and improve user experience.
- Marketing & measurement (where permitted): to measure the effectiveness of advertising and improve campaigns. Where required by law, we will ask for your consent before using cookies/technologies for analytics and advertising.
- Legal and regulatory: to comply with applicable laws, respond to lawful requests, and protect our rights.
5) Legal bases (UK GDPR / GDPR)
If UK GDPR / GDPR applies, we process your personal data under one or more of the following legal bases:
- Consent: where you have given consent (e.g., certain cookies/trackers; optional marketing where required).
- Contract / steps before contract: where processing is necessary to take steps at your request (e.g., handling an appointment request).
- Legitimate interests: where processing is necessary for our legitimate interests (e.g., keeping our website secure, basic analytics, responding to enquiries), balanced against your rights.
- Legal obligation: where processing is required to comply with law.
You may withdraw consent at any time (where consent is the legal basis). Withdrawal does not affect processing already carried out.
6) Health data / special category data
Depending on what you choose to share, your enquiry may include health information (which may be treated as “special category data” under UK GDPR / GDPR).
How we handle it
- We request that you keep website form submissions limited to the information needed to handle your enquiry.
- We restrict access to enquiry data to authorized staff and service providers who need it to respond to you.
- We use reasonable administrative, technical, and organizational measures to protect it (see Section 11).
Condition for processing special category data (if applicable)
Where special category data is processed, we rely on a suitable condition such as:
- Explicit consent (where required and obtained), and/or
- Healthcare / medical purposes where applicable under relevant laws and professional obligations.
We do not use health data to build advertising profiles or target ads based on sensitive health conditions.
9) International transfers
We are based in Turkey. If you access this Website from the UK/EEA or another country, your data may be transferred to and processed in Turkey and other countries where our service providers operate.
Where UK GDPR / GDPR applies and international transfers occur, we aim to use appropriate safeguards such as:
- transfers to countries recognized as providing adequate protection (where applicable), and/or
- contractual safeguards (e.g., standard contractual clauses) with service providers, and/or
- other lawful mechanisms permitted by applicable data protection laws.
10) Data retention
We keep your personal data only as long as necessary for the purposes described in this Policy, including:
- Enquiry data: typically retained for up to 24 months after the last contact, unless you become a patient or law requires longer retention.
- Appointment and clinical records: retained according to medical, legal, and regulatory requirements applicable to our practice.
- Analytics data: retained according to the settings of our analytics tools and our internal retention policies.
Retention periods may vary depending on legal obligations, dispute resolution needs, and clinical record requirements.
11) Security
We use reasonable security measures designed to protect personal data, such as:
- access controls and confidentiality obligations
- secure hosting and encrypted connections (HTTPS)
- limited access to enquiry information
- procedures to handle suspected data incidents
No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we work to protect your data.
12) Your rights
Depending on your location and applicable law (including UK GDPR / GDPR), you may have rights such as:
- Access: request a copy of your personal data.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data (subject to legal/medical record obligations).
- Restriction: request limited processing in certain cases.
- Objection: object to processing based on legitimate interests in certain cases.
- Data portability: receive certain data in a portable format (where applicable).
- Withdraw consent: where processing is based on consent.
How to exercise your rights
Please contact us using the details in Section 15. We may request information to verify your identity.
Complaints
If you are in the UK, you can lodge a complaint with the Information Commissioner’s Office (ICO). If you are in the EEA, you can complain to your local supervisory authority.
We would appreciate the opportunity to address your concerns first—please contact us before filing a complaint.
Turkey (KVKK)
Under Turkish data protection law (KVKK), you may also have rights to learn whether your personal data is processed, request information, request correction/deletion under conditions, and learn third parties to whom data is transferred, among others, subject to applicable rules.
13) Children’s privacy
This Website and our services are not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided personal data, please contact us so we can take appropriate action.
14) Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page. Your continued use of the Website after changes means you accept the updated Policy.
15) Contact
If you have questions or requests regarding privacy, contact:
Dr. Nilüfer YÜKSEL
Email: info@niluferyuksel.com
Phone: +90 553 069 4488
Address: Şirinyalı Mahallesi İsmet Gökşen Caddesi Savaş Apartmanı, No:65 Kat:2, 07160 Muratpaşa/Antalya, Turkey