This policy explains how personal and health data are processed under Turkish KVKK and, where applicable, the EU GDPR.
We process information to answer enquiries, present files to authorised healthcare providers, coordinate travel and accommodation, perform agreements and comply with legal duties.
Health data, medical photographs, scans, laboratory results and reports are sensitive data and are processed only where a lawful basis and, when required, explicit consent exist.
We do not sell personal data. Access is limited to authorised staff and selected providers who need the information for the agreed service.
Controller roles
The Turkish company operating Kayseri Care Travel controls its own administrative processing. Each treating healthcare provider independently controls the medical record it creates.
Data categories
Identity, contact, passport, visa, payment, communication, language, travel and health information, photographs, imaging, reports, quotations and consent records.
Purposes and legal bases
Intake, identification, assessment, communication, planning, quotation, translation, travel, invoicing, security and legal administration, based on contract, legal duty, legitimate interests and explicit consent where required.
Recipients and transfer
Data may be shared with authorised hospitals, doctors, laboratories, translators, hotels, transfer providers, IT services and authorities. International transfers use appropriate consent and safeguards.
Retention and rights
Data are retained only as long as necessary or legally required. Depending on applicable law, you may request access, correction, restriction, objection, portability or deletion.
Security and contact
We use access controls, encrypted connections, backups and organisational measures. Requests may be sent to info@kaysericaretravel.nl with adequate identification.
