Last updated: 2 September 2026 · Version: 3.0

This Privacy Policy explains who we are, what personal data we collect when you visit welldemir.com or contact us, why we process it, who we share it with, how long we keep it and what rights you have. It applies to the website, our contact and consultation forms, our WhatsApp and e-mail correspondence, and our social media pages.

Because we serve patients in the European Union and in Türkiye, this policy is written to satisfy both the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Turkish Personal Data Protection Law No. 6698 (“KVKK”). Where the two differ, we apply the stricter standard.

1. Who is responsible for your data

The data controller (GDPR Art. 4/7) and the data supervisor (KVKK “veri sorumlusu”) is:

  • Demir Health Turizm Anonim Şirketi, trading as WellDemir
  • Esentepe Mah. Büyükdere Cad. Özsezen İş Merkezi No: 124, Inner Door No: 9, Şişli / İstanbul, Türkiye
  • Istanbul Trade Registry No: 410907-5 · MERSIS No: 0279124343300001
  • E-mail: privacy@welldemir.com · General enquiries: hello@welldemir.com
  • Telephone / WhatsApp: +44 7488 811362

We are a health tourism intermediary and a licensed travel agency. We are not a healthcare provider. Hospitals, clinics and physicians who treat you are separate, independent controllers of the health data they process about you, and they have their own privacy notices.

2. The personal data we collect

CategoryExamplesSource
Identity dataFirst name, surname, date of birth, nationality, passport or ID details where a booking requires themFrom you
Contact dataE-mail address, telephone or WhatsApp number, country of residence, postal addressFrom you
Health data (special category)Your treatment interest, medical history, medication, height and weight, photographs of the treatment area, reports and test results you send usFrom you, or from the clinic with your consent
Travel and booking dataTravel dates, flight details, accommodation and transfer preferences, companion details you give usFrom you
Financial dataInvoice details, payment confirmations, refund records. We do not store full card numbers; card payments are processed by the clinic or by a payment institutionFrom you and from the payment provider
Correspondence dataForm submissions, e-mails, WhatsApp and social media messages, call notes, the digital signature you draw on our consent formFrom you
Technical dataIP address, browser and device type, operating system, language, referring URL, pages viewed, time on pageAutomatically, via cookies and server logs. See our Cookie Policy

Health data is a special category of personal data under GDPR Art. 9 and “özel nitelikli kişisel veri” under KVKK Art. 6. We ask for it only when it is needed to obtain a treatment plan or a quotation for you, we ask for the minimum necessary, and we process it only with your explicit consent.

3. Why we process your data and on what legal basis

PurposeData usedLegal basis (GDPR)Legal basis (KVKK)
Answering your enquiry and giving you a non-binding quotationIdentity, contact, correspondenceArt. 6(1)(b) steps prior to a contractArt. 5/2-c contract-related processing
Obtaining a treatment opinion, plan or price from a partner clinicHealth, identity, contactArt. 6(1)(b) and Art. 9(2)(a) explicit consentArt. 5/2-c and Art. 6/2 explicit consent
Organising your travel: appointments, transfer, accommodation, interpreterIdentity, contact, travelArt. 6(1)(b) performance of a contractArt. 5/2-c
Invoicing, accounting, tax and trade law record keepingIdentity, financialArt. 6(1)(c) legal obligationArt. 5/2-ç legal obligation
Handling complaints, insurance claims and legal claimsAll relevant categoriesArt. 6(1)(f) legitimate interest, Art. 9(2)(f) legal claimsArt. 5/2-e and Art. 6/3
Sending you offers, campaigns and newsletters by e-mail, SMS or WhatsAppIdentity, contactArt. 6(1)(a) consentArt. 5/1 explicit consent, plus İYS registration under Law No. 6563
Measuring advertising performance and showing you relevant adsTechnical, online identifiersArt. 6(1)(a) consent given through our cookie bannerArt. 5/1 explicit consent
Keeping the website secure, preventing abuse, producing anonymous statisticsTechnical, server logsArt. 6(1)(f) legitimate interest in a secure serviceArt. 5/2-f meşru menfaat

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

4. Who we share your data with

We share only what is necessary, and only with:

  • Partner hospitals, clinics and physicians you have asked us to approach. They act as independent controllers of your medical record.
  • Travel and hospitality suppliers: hotels, transfer companies, airlines and interpreters, limited to the details needed for the booking.
  • Insurers and assistance providers where you have taken out a treatment or travel insurance product.
  • IT and communication providers acting as our processors: our hosting provider Hetzner Online GmbH (servers in Germany), our e-mail provider, our CRM and our website maintenance agency. Each is bound by a data processing agreement.
  • Meta Platforms Ireland Ltd. for advertising measurement, and WhatsApp Ireland Ltd. when you choose to write to us on WhatsApp. Advertising cookies and pixels are only activated after you consent.
  • Professional advisers: accountants, auditors and lawyers, under a duty of confidentiality.
  • Public authorities and courts, where we are legally obliged to disclose.

We never sell your personal data, and we never share health data for advertising purposes.

5. International transfers

Our website is hosted in Germany. However, our team, our partner clinics and our suppliers are located in Türkiye, so your data is transferred to and accessed from Türkiye.

Türkiye is not covered by a European Commission adequacy decision. We therefore rely on the following safeguards for transfers out of the European Economic Area:

  • the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) with our Turkish suppliers and partner clinics, supported by a transfer impact assessment; and
  • where a specific treatment cannot be arranged without sending your medical file abroad, your explicit consent to that particular transfer under GDPR Art. 49(1)(a), after we have told you about the risks.

For transfers out of Türkiye we apply KVKK Art. 9 as amended, using standard contracts notified to the Turkish Data Protection Authority or, where applicable, your explicit consent.

You can obtain a copy of the safeguards in place by writing to privacy@welldemir.com.

6. How long we keep your data

DataRetention periodReason
Enquiries that do not lead to a booking12 months from the last contactTo answer follow-up questions, then deleted
Health data sent for a quotation, where no treatment follows6 months, or immediately on requestData minimisation
Contract, booking and coordination records10 years from the end of the contractTurkish Commercial Code Art. 82 and Tax Procedure Law
Invoices and accounting records10 yearsStatutory bookkeeping obligation
Marketing consents and the record of themUntil withdrawal, then 3 years for evidenceProof of consent under Law No. 6563 and GDPR Art. 7(1)
Server and security logs12 monthsSecurity and abuse prevention
Cookie consent record12 monthsProof of consent

When a period ends we delete the data or irreversibly anonymise it. Where a legal claim is pending, we keep the relevant file until the claim is finally resolved.

7. Your rights

Under GDPR Art. 15 to 22 and KVKK Art. 11 you may ask us to:

  • confirm whether we process your data and give you a copy of it;
  • correct data that is inaccurate or incomplete;
  • delete your data, where there is no overriding legal reason to keep it;
  • restrict processing while a dispute about accuracy or lawfulness is resolved;
  • receive the data you gave us in a machine-readable format and have it sent to another controller;
  • object to processing based on our legitimate interests, and to direct marketing at any time, without giving a reason;
  • withdraw a consent you have given;
  • be told which third parties your data was disclosed to, and have any correction or deletion notified to them.

You are not subject to any decision with legal effect that is based solely on automated processing, and we do not carry out profiling that produces such effects.

How to exercise your rights. Write to privacy@welldemir.com or to our postal address above. We answer within one month under the GDPR and within 30 days under the KVKK. The request is free of charge. We may ask for proof of identity so that we do not disclose your data to someone else.

Complaints. If you are not satisfied with our answer you may complain to a supervisory authority:

  • in Türkiye, the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, kvkk.gov.tr);
  • in Germany, the data protection authority of your federal state (a list is published at bfdi.bund.de);
  • in the Netherlands, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl);
  • elsewhere in the EU, the supervisory authority of your country of residence or workplace.

8. Cookies and tracking

We use strictly necessary cookies to make the site work, and functional, statistical and marketing cookies only after you have given consent through our cookie banner. You can change or withdraw your choice at any time. Everything we set, including its purpose and lifetime, is listed in our Cookie Policy.

9. How we protect your data

  • TLS encryption on every page of the website and on our forms;
  • encrypted storage and access control on our servers, hosted in an ISO 27001 certified data centre in Germany;
  • role-based access: only staff who need a file to do their job can open it;
  • confidentiality undertakings for all staff and written processing agreements with every supplier;
  • regular backups, patching and log review, and a documented procedure for reporting a personal data breach to the competent authority within 72 hours and to you where the breach is likely to result in a high risk to your rights.

10. Children

Our services are aimed at adults. We do not knowingly collect data from anyone under 18. Where a treatment involves a minor, we deal with the parent or legal guardian and process the minor’s data only on their instructions. If you believe a child has given us data, write to privacy@welldemir.com and we will delete it.

11. Is providing your data mandatory

You are not obliged to give us any data. However, without your contact details we cannot answer you, and without the relevant medical information a clinic cannot prepare a treatment plan or a price. If you prefer not to send medical details by e-mail, tell us and we will arrange a secure alternative.

12. Changes to this policy

We review this policy at least once a year and whenever our services or the law change. The current version is always published on this page with its date and version number. If a change materially affects you, we will tell you by e-mail or by a notice on the website before it takes effect.

13. Contact

Demir Health Turizm A.Ş. (WellDemir)
Esentepe Mah. Büyükdere Cad. Özsezen İş Merkezi No: 124, Inner Door No: 9, Şişli / İstanbul, Türkiye
Data protection contact: privacy@welldemir.com
General enquiries: hello@welldemir.com