Rightful Beauty

PERSONAL DATA PROCESSING POLICY
Dear Customers, Suppliers, Employees, Employee Candidates, Business Partners, Potential Customers, Visitors. As Hera Partners Sağlık Hizmetleri ve Ticaret Limited Şirketi (“Company”), we attach great importance to the protection of your personal data. In this context, we would like to inform you about your personal data and data processing in the capacity of “data controller” pursuant to the Law on Protection of Personal Data No. 6698 (“KVKK”).
1. WHAT IS YOUR PROCESSED PERSONAL DATA?
a. In terms of our customers and potential customers;
– Your identity information (name, surname),
– Your contact information (phone number, e-mail address),
– Your health record if you give consent
– Your nationality,
– Your travel data,
– Service Information (sales information, sales date, sales time, payment method, in case of payment by credit card, your information is transferred to the relevant payment institution without recording.),
– If you want it to be included in the invoice (T.R. ID number, tax number, private company information),
– Information contained in the signatory circular,
– Personal data processed for the resolution of your requests and complaints.
– If you give permission for electronic commercial messages, your contact information for marketing purposes,
– Personal data arising during your use of the product during the service,
– Information contained in customer forms,
– If you fill out the customer satisfaction surveys, the data on this survey,
– Data you have shared with our company in organizations such as fairs and congresses,
– If you contact us through our social media accounts, the data you have shared here,
b. In terms of Supplier, Business Partners Employees and Authorities;
– Your identity information (name, surname, TR ID number),
– Your contact information (phone number, e-mail address),
– Product or Service Sales Information (sales information, sales date, sales time, payment method, in case of payment by credit card, your information is transferred to the relevant payment institution without recording),
– If you want it to be included in the invoice (TR ID number, tax number, individual company information),
– Information contained in the signatory circular,
– Information on contracts,
– Information on the negotiable instruments,
– Information on the letters of guarantee,
c. Our Employee Candidates
– Your identity information (name, surname, date of birth, TR ID number, place of birth),
– Your contact information (address, e-mail address, phone number),
– Your gender information,
– Your education and professional information,
– Your information on references,
– Information on your general resume that you have submitted in the application,
– Your license status,
– Your visual data,
– Your military status,
d. For our employees
– Your identity Information (name, surname, date of birth, TR ID number, address),
– Your contact information (address, e-mail address, phone number),
– Your marital status,
– Your license status,
– Your medical report,
– Your photo,
– Your CV,
– Your military status,
– Your criminal record,
– Your performance status,
– Your trainings received,
– Your information that is required by law to be processed,
– Your data processed within the scope of the company regulations and the law processed within the scope of the management right at work,
– Your bank account information,
– Your data on whether there is any lawsuit against you,
– Your workplace registration,
– Your data received within the scope of taking camera recordings in the workplace,
– Your data processed within the scope of the employer’s management right during your work,
– Tracking and monitoring of the electronic devices you use.
– If you have spouses and children, their identity data (name, surname, date of birth, TR ID number, address),
e. In terms of our visitors;
– Identity information (name, surname, signature)
– Your visual data
– Physical space security
f. In terms of our participants in our projects;
– Identity information (name, surname)
– Your visual data

2. PURPOSE OF PROCESSING YOUR PERSONAL DATA
Your personal data may be processed for the following purposes in accordance with the legislation on the protection of personal data;
General Purposes:
• If you contact us, your identity and contact information in order to resolve your problems and complaints and to contact you when necessary,
• Your identity, communication, invoice, financial, shopping information in order to fulfill our obligations arising from the legislation, to fulfill our other legal obligations, especially security of information, with authorized and responsible public institutions and organizations,
• Your identity, communication, invoice, financial and service information for the purpose of exercising all kinds of lawsuits, right of reply and right of objection against official institutions and organizations such as courts, enforcement offices, arbitral tribunals in disputes arising from the contract,
• In order to manage the national and international certification and liability processes that our company is subject to,
In Terms of Labour Relations:
• Establishing the labor contract with employees and fulfilling the necessity, proving the business relationship,
• In order to keep the personal file,
• In order to make travel insurances and aircraft and hotel reservations, opening salary accounts, making compulsory BES payments and social security premium payments,
• In order to establish a business relationship,
• With the aim of making your performance measurements within the scope of the company and increasing efficiency,
• In order to provide trainings due to reasons arising from occupational health and safety (OHS) and general health legislation and to provide information to organizations related to the reasons arising from the legislation,
• Your medical record based on your open consent for reasons for the law,
• In order to transfer abroad on the basis of your explicit consent due to the use of systems from abroad,
• In order to market the visual and auditory data of our employees in order to market the corporate identity of our company,
• In order to manage the travel processes of employees,
• Determination of employees’ working hours and daily working hours, control of overtime continuation, control of the payroll records,
• In order to benefit from employee incentives,
Via Website and Social Media Tools
• Through the “Contact Us” section on the website and related applications such as whatsapp web,
• By contacting us via direct message or similar features through our social media accounts,
• In accordance with the “Cookies Policy” through the cookies on our website,
In Terms of the Service Provided
• Your identity, contact and shopping information in order to record your information in order to carry out post-sales operational processes,
• Providing the best service for you through your medical record, which has been given based on your explicit consent, due to the fact that we provide health tourism services,
• In order not to encounter any problems in terms of legal obligations in the Republic of Turkey by obtaining your travel data,
• To distinguish the records we create in our system regarding you from the records of other customers,
• If you request an invoice, your identity and billing information in order to issue an invoice,
• If you want to make your payment by credit card, your credit card information (transferred to the payment institution without saving the credit card information) so that the payment can be received.
• Your identity and billing information in order to fulfill our storage obligations arising from the legislation,
• Your identity and contact information within the scope of efforts to increase product sales in fairs and various channels in order to improve sales processes,
• Your identity data, requests and digital traces for the purpose of providing your entries regarding the products, keeping transaction security and related records, developing products and services and solving problems,
• Within the scope of the services we provide, within the scope of the management of the products and consultancy, as well as the transactions carried out to ensure the security of the personal data of your customers that you transfer,
• Your data processed for the services provided within the scope of the management of your requests and complaints, keeping the records of the requests you make on behalf of the Company or personally, and resolving these requests,
• If you give your explicit consent, for the purpose of sending electronic commercial messages to your personal data and marketing within this scope,
• With the call center records obtained while providing information for the management of our processes,
In Terms of Our Product or Service Purchases
• Your identity, contact information, in order to record the information of the relevant persons in order to carry out the operational processes after the purchase,
• Your identity and contact information in order to distinguish the records we create in our system regarding you from the records of other customers.
• Your identity and billing information in order to fulfill our storage obligations arising from the legislation,
In Terms of Your Visits
• Visual records of visitors at our company headquarters to ensure physical space security,
3. METHOD OF COLLECTING YOUR PERSONAL DATA AND LEGAL REASON
Your personal data by the company,
With the establishment of employment contracts after recruitment and employment, with visual devices and physical forms in physical locations, service sales contracts within the scope of product sales, demand forms for product sales, signature statements, power of attorney, valuable papers, invoices, e-invoices, customer satisfaction surveys, data transmitted through our social media accounts, demo forms on our website and similar forms added.
As a company, we are processing your personal data;
In terms of Services and Sales Processes
Pursuant to Article 5 of the Law,
• It operates on the basis of “requirement of data processing for the establishment and performance of the contract”, “fulfillment of legal obligation”, “legal reason for data processing and transfer to be mandatory for the establishment, exercise or protection of rights”, “provided that the company does not harm the fundamental personal rights and freedoms”, and “reasons where data processing is necessary for its legitimate interests”.
• If you give your explicit consent, it is processed for the purpose of sending commercial electronic messages.
With the Website and Social Media Tools
• In some exceptional cases, due to the necessity of data processing for the legitimate interest of the company, provided that it does not harm the fundamental personal rights and freedoms.
For General Purposes
• Your personal data is processed based on “fulfillment of legal obligations”, “clearly written in laws” and “reasons where data processing is mandatory for the legitimate interest of the data controller”.
In terms of Employee-Employer Relationship
• Based on the reasons that data processing is necessary for the establishment and performance of the contract, “fulfillment of the legal obligation”, “it is clearly written in the laws” and “the data processing is mandatory for the legitimate interest of the data controller, together with these, the rights of the company within the scope of the management of judicial processes. While it is processed in order to protect it;
• In case the employees give explicit consent, personal data is processed in terms of health data and social media sharing.
In Physical Spaces
• Regarding recording with security cameras, it is processed on the basis of legal reasons that “data processing is mandatory for the legitimate interests of the data controller”.
4. TRANSFERRING YOUR PERSONAL DATA
As a company, we are sharing your personal data with;
a. With its business partners and service providers,
Information technologies or consultancy that require expertise etc. with business partners and service providers (with companies that provide database, consultancy, etc. services) in the country for purposes such as receiving services, receiving product and service support in personal data, collection processes, or abroad by fulfilling the conditions of transfer abroad in Article 9 of the Law.
b. b. In order to provide information, and documents and to fulfill our other related obligations towards state institutions and organizations and judicial authorities; To these institutions, organizations, and authorities, the information requested from us in order to use our legal rights such as lawsuits and reply rights,
c. If you make your payment by credit card, the relevant bank, electronic payment institution etc., without registering your credit card information by the company. third parties providing the service,
d. With our suppliers with whom we are business partners for the purpose of fulfilling our services, or with our suppliers from whom we purchase products or services, even if we are not business partners,
e. With the business partners, with whom we work within the scope of receiving training and compliance with the legislation; with legal persons such as lawyers, financial advisors, occupational safety specialists, etc., with whom we work to fulfill the obligations arising from the Law,
f. With event (fair, conference, etc.) companies when necessary due to business needs and to the extent required by the business,
g. With the health institutions we do business with, depending on your explicit consent, including your medical record for business needs,
h. With the accommodation facilities, tourism agencies, auxiliary suppliers necessary for travel, with which we work in order to organize the travel programs of our customers,
I. With our customers abroad, by fulfilling the conditions for transferring the data of our employees abroad, in Article 9 of the Law, in order to establish communications with customers abroad where the business is conducted, to conclude contracts, and to execute and perform the contract,
j. In order to benefit from employee incentives, with relevant institutions and organizations,
k. With the institutions and organizations that the company has contracted with for the purpose of performing health screening of,
5. YOUR RIGHTS
Pursuant to Article 11 of the Law, you have these rights by applying to the company through the methods set out in the “Contact” section of this policy:
a. Learning whether your personal data is processed or not,
b. If your personal data has been processed, requesting information about it,
c. Learning the purpose of processing personal data and whether they are used in accordance with its purpose,
d. Knowing the third parties to whom your personal data is transferred, within the country or abroad,
e. Requesting correction of your personal data if it is incomplete or incorrectly processed,
f. Requesting the deletion or destruction of your personal data within the framework of the conditions stipulated in the PDPL legislation
g. Requesting notification of third parties to whom your personal data has been transferred,
h. Objecting to the emergence of a result against you by analyzing the processed data exclusively through automated systems,
i. If you suffer damage due to illicit processing of personal data, requesting the removal of this damage
6. CONTACT
As the data controller, applications you sent to the e-mail address from your registered e-mail on the system, to the company which is responsible for the application procedure is being held safe and hidden, at the address of Hera Partners Sağlık Hizmetleri ve Ticaret Limited Şirketi or to the address of the company specified below. (We would like to remind you that in cases where the relevant request must be made in a certain procedure by law, the said procedure must be followed.)
Address : Kuştepe Mahallesi, Leylak 1 Sokak, Nursanlar İş Merkezi, Kat 6, Daire 2 Mecidiyeköy, Şişli / İstanbul /Türkiye

0090 (0) 850 885 58 80