GDPR Privacy Notice
Privacy Notice Under EU General Data Protection Regulation
Data Controller
This GDPR Privacy Notice is issued by the data controller whose information is provided below:
Title
Assoc. Prof. Dr. Özgür AKŞAN
Profession
Neurosurgeon (Brain and Spine Surgery Specialist)
info@drozguraksan.com
Data Protection Contact
privacy@drozguraksan.com
Phone
+90 532 414 35 35
Website
www.drozguraksan.com
Address
Mimar Sinan Mahallesi Ziya Gökalp Bulvarı Mimarin Medikal No:28 Flat:1 Konak / Izmir / Turkey
Personal Data We Process
- •Identification Data: Name, surname, date of birth
- •Contact Data: Email, phone number, address
- ⚠️Health Data: MRI/CT images, medical reports, symptoms, diagnoses
- •Technical Data: IP address, device type, browser information
- •Communication Records: Emails, messages, uploaded files
Health data is considered Special Category Data under Article 9 GDPR.
Purposes of Processing
- ✓Providing medical second opinion services
- ✓Communication between patient and physician
- ✓Appointment and consultation management
- ✓Evaluation of medical documents
- ✓Legal and regulatory compliance
- ✓System security and technical administration
Legal Basis
Article 6 GDPR
- • Consent (Art. 6(1)(a))
- • Performance of a contract (Art. 6(1)(b))
- • Legal obligation (Art. 6(1)(c))
- • Legitimate interest (Art. 6(1)(f))
Article 9 GDPR
- • Medical diagnosis and healthcare (Art. 9(2)(h))
- • Explicit consent (Art. 9(2)(a))
Data Sharing
Personal data may be shared with:
- •Healthcare providers and hospitals
- •Legal authorities where required by law
- •Technical service providers (hosting, email, cloud systems)
Data is shared only to the extent necessary.
International Transfers
Your data may be transferred outside the EU/EEA to Turkey and other countries.
Transfers are safeguarded by:
- • Explicit consent
- • Standard Contractual Clauses (SCCs)
- • Adequacy decisions where applicable
Data Retention
| Data Type | Retention Period |
|---|---|
| Health Records | Patient lifetime + 30 years |
| Communication Data | 10 years |
| Technical Logs | 2 years |
| Financial Data | 7 years |
Your GDPR Rights
Under GDPR you have the right to:
Access Your Data
Art. 15
Rectify Your Data
Art. 16
Erase Your Data
Art. 17
Restrict Processing
Art. 18
Data Portability
Art. 20
Object to Processing
Art. 21
Lodge a Complaint
Art. 77
Data Breach
In case of a personal data breach:
- •Supervisory authority will be notified within 72 hours
- •Data subjects will be informed without undue delay if high risk exists
Supervisory Authority
As the Data Controller is established in Turkey, the relevant supervisory authority depends on your country of residence.
EU data subjects may contact their local Data Protection Authority.
Contact
Data Protection Contact
privacy@drozguraksan.com
General Contact
info@drozguraksan.com
Phone
+90 532 414 35 35
Effective Date
This GDPR Privacy Notice entered into force on January 26, 2026.