Privacy Policy

Your privacy is important to us. This policy explains how Regal Clinic collects, uses, and protects your personal information.

Last Updated: December 2024

1. Information We Collect

1.1 Personal Information

We collect personal information that you voluntarily provide to us, including:

  • Contact Information: Name, email address, phone number, postal address
  • Demographic Information: Age, gender, country of residence
  • Medical Information: Hair loss history, previous treatments, medical conditions, photos
  • Financial Information: Payment details, insurance information (processed securely through third-party providers)
  • Communication Records: Correspondence, consultation notes, feedback

1.2 Automatically Collected Information

When you visit our website, we automatically collect:

  • Technical Data: IP address, browser type, device information, operating system
  • Usage Data: Pages visited, time spent on site, click patterns, referral sources
  • Cookies and Similar Technologies: As described in our Cookie Policy

1.3 Third-Party Information

We may receive information about you from:

  • Healthcare providers and medical professionals
  • Insurance companies
  • Marketing partners (with your consent)
  • Public databases and social media platforms

2. How We Use Your Information

2.1 Medical Services

  • Providing hair transplant consultations and procedures
  • Developing personalized treatment plans
  • Monitoring treatment progress and outcomes
  • Providing post-procedure care and support
  • Maintaining medical records as required by law

2.2 Communication

  • Responding to your inquiries and requests
  • Sending appointment reminders and confirmations
  • Providing treatment updates and aftercare instructions
  • Sending educational content about hair restoration (with consent)

2.3 Business Operations

  • Processing payments and managing billing
  • Improving our services and website functionality
  • Conducting research and analytics (anonymized data)
  • Complying with legal and regulatory requirements
  • Preventing fraud and ensuring security

2.4 Marketing (With Consent)

  • Sending promotional materials and special offers
  • Conducting customer satisfaction surveys
  • Sharing before/after photos and testimonials (with explicit consent)

3. Information Sharing and Disclosure

3.1 We Do Not Sell Your Information

We never sell, rent, or trade your personal information to third parties for marketing purposes.

3.2 Authorized Sharing

We may share your information in the following circumstances:

  • Medical Professionals: With your healthcare team and specialists involved in your care
  • Service Providers: With trusted third parties who assist in our operations (payment processors, IT services, etc.)
  • Legal Requirements: When required by law, court order, or regulatory authority
  • Business Transfers: In connection with mergers, acquisitions, or asset sales
  • Emergency Situations: To protect your health and safety or that of others
  • With Your Consent: When you explicitly authorize us to share your information

3.3 International Patients

For international patients, we may share information with:

  • Travel agencies and accommodation providers
  • Local healthcare providers in your home country
  • Insurance companies for coverage verification

4. Data Security

4.1 Security Measures

We implement comprehensive security measures to protect your information:

  • Encryption: All data is encrypted in transit and at rest using industry-standard protocols
  • Access Controls: Strict access controls limit who can view your information
  • Regular Audits: We conduct regular security audits and assessments
  • Staff Training: All staff receive privacy and security training
  • Secure Infrastructure: Our systems use secure, monitored servers

4.2 Medical Data Protection

Medical information receives additional protection:

  • Separate, encrypted medical record systems
  • Role-based access controls for medical staff
  • Audit trails for all medical record access
  • Compliance with medical data protection standards

4.3 Incident Response

In the unlikely event of a data breach, we will:

  • Immediately investigate and contain the incident
  • Notify affected individuals within 72 hours (as required by GDPR)
  • Report to relevant authorities as required by law
  • Implement additional security measures to prevent recurrence

5. Your Rights Under GDPR

As a data subject, you have the following rights:

5.1 Right of Access

You can request a copy of all personal information we hold about you, including:

  • What information we have collected
  • How we use your information
  • Who we share it with
  • How long we keep it

5.2 Right to Rectification

You can request correction of inaccurate or incomplete information.

5.3 Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal information, subject to legal and medical record retention requirements.

5.4 Right to Restrict Processing

You can request that we limit how we use your information in certain circumstances.

5.5 Right to Data Portability

You can request a copy of your information in a structured, machine-readable format.

5.6 Right to Object

You can object to processing of your information for marketing purposes or based on legitimate interests.

5.7 Right to Withdraw Consent

Where processing is based on consent, you can withdraw it at any time.

5.8 How to Exercise Your Rights

To exercise any of these rights, contact us at:

  • Email: [email protected]
  • Phone: +90 534 233 37 17
  • Post: Regal Clinic, Nişantaşı Mahallesi, Teşvikiye Caddesi No: 123, Şişli, Istanbul 34365, Turkey

6. Cookies and Tracking Technologies

6.1 What Are Cookies

Cookies are small text files stored on your device when you visit our website. They help us provide a better user experience and understand how our site is used.

6.2 Types of Cookies We Use

  • Essential Cookies: Necessary for website functionality
  • Analytics Cookies: Help us understand website usage (Google Analytics)
  • Marketing Cookies: Used for targeted advertising (with consent)
  • Preference Cookies: Remember your settings and preferences

6.3 Managing Cookies

You can control cookies through your browser settings. However, disabling certain cookies may affect website functionality.

6.4 Third-Party Services

We use third-party services that may set their own cookies:

  • Google Analytics for website analytics
  • Facebook Pixel for marketing (with consent)
  • Payment processors for secure transactions

7. Data Retention

7.1 Medical Records

Medical records are retained as required by Turkish medical law and international standards:

  • Adult patients: Minimum 20 years from last treatment
  • Minor patients: Until age 25 or 20 years from last treatment
  • May be retained longer for legal or medical reasons

7.2 Other Personal Information

  • Marketing Data: Until consent is withdrawn or 3 years of inactivity
  • Website Analytics: 26 months (Google Analytics default)
  • Communication Records: 7 years for business purposes
  • Financial Records: 10 years for tax and legal compliance

7.3 Secure Disposal

When data is no longer needed, we securely delete or anonymize it using certified data destruction methods.

8. International Data Transfers

8.1 Cross-Border Transfers

As an international clinic, we may transfer your information across borders for:

  • Providing medical services to international patients
  • Sharing information with your home country healthcare providers
  • Using international service providers (with adequate safeguards)

8.2 Adequate Protection

We ensure adequate protection through:

  • Standard Contractual Clauses (SCCs) for EU transfers
  • Adequacy decisions by relevant authorities
  • Binding Corporate Rules where applicable
  • Explicit consent for specific transfers

9. Children's Privacy

9.1 Age Requirements

Our services are generally not intended for individuals under 18. However, we may provide services to minors with:

  • Parental or guardian consent
  • Appropriate legal authorization
  • Special consideration for medical necessity

9.2 Special Protections

When treating minors, we implement additional protections:

  • Enhanced consent procedures
  • Parental involvement in decision-making
  • Special data retention policies
  • Additional security measures

10. Changes to This Privacy Policy

10.1 Updates

We may update this privacy policy from time to time to reflect:

  • Changes in our practices
  • New legal requirements
  • Technology improvements
  • Business developments

10.2 Notification

We will notify you of significant changes by:

  • Posting the updated policy on our website
  • Sending email notifications to active patients
  • Displaying prominent notices on our website
  • Updating the "Last Updated" date

10.3 Your Continued Use

Continued use of our services after policy changes constitutes acceptance of the updated terms.

11. Contact Us

11.1 Data Protection Officer

For privacy-related questions or concerns, contact our Data Protection Officer:

Email: [email protected]

Phone: +90 534 233 37 17

Address:
Regal Clinic
Nişantaşı Mahallesi
Teşvikiye Caddesi No: 123
Şişli, Istanbul 34365
Turkey

11.2 Response Time

We will respond to your privacy inquiries within 30 days as required by GDPR.

11.3 Supervisory Authority

You have the right to lodge a complaint with your local data protection supervisory authority if you believe we have not handled your personal information appropriately.