1. Who We Are
This website, drozlemoymak.com, is operated by Op. Dr. Özlem Oymak, a licenced ENT specialist practising at a private clinic in Bursa, Türkiye. For all data-related enquiries, Dr. Oymak is the data controller. You may contact her directly at info@drozlemoymak.com or via WhatsApp at +90 532 363 30 92.
2. What Data We Collect
We collect personal data only when you voluntarily provide it through the consultation request form, WhatsApp, or direct email. The categories of data we may hold are:
| Category | Examples | Purpose |
|---|---|---|
| Identity data | First name, surname, date of birth | To identify you and prepare a personalised treatment assessment |
| Contact data | Email address, phone/WhatsApp number, country of residence | To respond to your enquiry and maintain aftercare communication |
| Health data | Medical history, photographs, previous surgery records | To conduct a safe and informed surgical consultation |
| Usage data | IP address, browser type, pages visited | Website analytics and security (collected automatically via cookies) |
Health data is classified as Special Category data under GDPR Article 9. We process it solely on the basis of your explicit consent and for the provision of healthcare services.
3. Legal Basis for Processing
We rely on the following legal bases under UK GDPR / EU GDPR:
- Consent — for health data and marketing communications (you may withdraw consent at any time).
- Contract performance — where processing is necessary to deliver the services you have requested.
- Legitimate interests — for website security and fraud prevention.
- Legal obligation — where we are required to retain records under Turkish medical law.
4. How We Use Your Data
Your data is used exclusively to:
- Respond to your initial consultation enquiry.
- Conduct and document your surgical consultation.
- Plan and perform any agreed surgical procedure.
- Deliver the twelve-month post-operative aftercare programme.
- Comply with Turkish medical record retention requirements (minimum ten years for surgical records).
We do not use your data for automated profiling, targeted advertising, or sale to third parties.
5. Data Sharing
We share your personal data only where strictly necessary:
- Hospital partners — JCI-affiliated hospitals in Bursa receive the clinical data required to admit and treat you.
- Anaesthesia and clinical staff — involved directly in your care.
- Legal obligation — if required by Turkish law, a court order, or a regulatory authority.
We do not transfer your data to marketing agencies, data brokers, or any third party outside the direct care team.
6. International Data Transfers
Because our practice is based in Türkiye, communication between you (in the UK or EU) and our clinic involves an international data transfer. Türkiye is not currently recognised by the UK ICO or the European Commission as providing an equivalent level of data protection. We mitigate this by:
- Limiting data transferred to the minimum necessary for your consultation.
- Using end-to-end encrypted channels (WhatsApp Business, encrypted email) wherever possible.
- Obtaining your explicit, informed consent to this transfer before processing any health data.
7. Data Retention
Surgical medical records are retained for a minimum of ten years in accordance with Turkish Ministry of Health regulations. Enquiry and consultation records for patients who did not proceed to surgery are retained for two years, after which they are securely deleted. You may request earlier deletion of non-mandatory records at any time (see Section 9).
8. Cookies
This website uses cookies. Please read our Cookies Policy for full details. You can manage your cookie preferences at any time via the cookie settings banner.
9. Your Rights
Under UK GDPR and EU GDPR, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — request deletion of data we are not legally required to retain.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Object — object to processing based on legitimate interests.
- Withdraw consent — at any time, without affecting the lawfulness of prior processing.
To exercise any right, contact Dr. Oymak directly at info@drozlemoymak.com. We will respond within 30 days. If you are unsatisfied with our response, UK patients may escalate to the Information Commissioner's Office (ICO); EU patients may contact their national data protection authority.
10. Security
We take reasonable technical and organisational measures to protect your data, including TLS encryption on all web traffic, restricted access to patient records, and secure deletion of data no longer required. No transmission over the internet is completely secure; we cannot guarantee absolute security.
11. Changes to This Policy
We may update this policy from time to time. The date at the top of this page reflects the most recent revision. Continued use of the website following a material change constitutes acceptance of the updated policy.
12. Contact
Op. Dr. Özlem Oymak
Bursa, Türkiye
Email: info@drozlemoymak.com
WhatsApp: +90 532 363 30 92