Last updated: 2 September 2026 · Version: 3.0
This Privacy Policy explains who we are, what personal data we collect when you visit welldemir.com or contact us, why we process it, who we share it with, how long we keep it and what rights you have. It applies to the website, our contact and consultation forms, our WhatsApp and e-mail correspondence, and our social media pages.
Because we serve patients in the European Union and in Türkiye, this policy is written to satisfy both the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Turkish Personal Data Protection Law No. 6698 (“KVKK”). Where the two differ, we apply the stricter standard.
1. Who is responsible for your data
The data controller (GDPR Art. 4/7) and the data supervisor (KVKK “veri sorumlusu”) is:
- Demir Health Turizm Anonim Şirketi, trading as WellDemir
- Esentepe Mah. Büyükdere Cad. Özsezen İş Merkezi No: 124, Inner Door No: 9, Şişli / İstanbul, Türkiye
- Istanbul Trade Registry No: 410907-5 · MERSIS No: 0279124343300001
- E-mail: privacy@welldemir.com · General enquiries: hello@welldemir.com
- Telephone / WhatsApp: +44 7488 811362
We are a health tourism intermediary and a licensed travel agency. We are not a healthcare provider. Hospitals, clinics and physicians who treat you are separate, independent controllers of the health data they process about you, and they have their own privacy notices.
2. The personal data we collect
| Category | Examples | Source |
|---|---|---|
| Identity data | First name, surname, date of birth, nationality, passport or ID details where a booking requires them | From you |
| Contact data | E-mail address, telephone or WhatsApp number, country of residence, postal address | From you |
| Health data (special category) | Your treatment interest, medical history, medication, height and weight, photographs of the treatment area, reports and test results you send us | From you, or from the clinic with your consent |
| Travel and booking data | Travel dates, flight details, accommodation and transfer preferences, companion details you give us | From you |
| Financial data | Invoice details, payment confirmations, refund records. We do not store full card numbers; card payments are processed by the clinic or by a payment institution | From you and from the payment provider |
| Correspondence data | Form submissions, e-mails, WhatsApp and social media messages, call notes, the digital signature you draw on our consent form | From you |
| Technical data | IP address, browser and device type, operating system, language, referring URL, pages viewed, time on page | Automatically, via cookies and server logs. See our Cookie Policy |
Health data is a special category of personal data under GDPR Art. 9 and “özel nitelikli kişisel veri” under KVKK Art. 6. We ask for it only when it is needed to obtain a treatment plan or a quotation for you, we ask for the minimum necessary, and we process it only with your explicit consent.
3. Why we process your data and on what legal basis
| Purpose | Data used | Legal basis (GDPR) | Legal basis (KVKK) |
|---|---|---|---|
| Answering your enquiry and giving you a non-binding quotation | Identity, contact, correspondence | Art. 6(1)(b) steps prior to a contract | Art. 5/2-c contract-related processing |
| Obtaining a treatment opinion, plan or price from a partner clinic | Health, identity, contact | Art. 6(1)(b) and Art. 9(2)(a) explicit consent | Art. 5/2-c and Art. 6/2 explicit consent |
| Organising your travel: appointments, transfer, accommodation, interpreter | Identity, contact, travel | Art. 6(1)(b) performance of a contract | Art. 5/2-c |
| Invoicing, accounting, tax and trade law record keeping | Identity, financial | Art. 6(1)(c) legal obligation | Art. 5/2-ç legal obligation |
| Handling complaints, insurance claims and legal claims | All relevant categories | Art. 6(1)(f) legitimate interest, Art. 9(2)(f) legal claims | Art. 5/2-e and Art. 6/3 |
| Sending you offers, campaigns and newsletters by e-mail, SMS or WhatsApp | Identity, contact | Art. 6(1)(a) consent | Art. 5/1 explicit consent, plus İYS registration under Law No. 6563 |
| Measuring advertising performance and showing you relevant ads | Technical, online identifiers | Art. 6(1)(a) consent given through our cookie banner | Art. 5/1 explicit consent |
| Keeping the website secure, preventing abuse, producing anonymous statistics | Technical, server logs | Art. 6(1)(f) legitimate interest in a secure service | Art. 5/2-f meşru menfaat |
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
4. Who we share your data with
We share only what is necessary, and only with:
- Partner hospitals, clinics and physicians you have asked us to approach. They act as independent controllers of your medical record.
- Travel and hospitality suppliers: hotels, transfer companies, airlines and interpreters, limited to the details needed for the booking.
- Insurers and assistance providers where you have taken out a treatment or travel insurance product.
- IT and communication providers acting as our processors: our hosting provider Hetzner Online GmbH (servers in Germany), our e-mail provider, our CRM and our website maintenance agency. Each is bound by a data processing agreement.
- Meta Platforms Ireland Ltd. for advertising measurement, and WhatsApp Ireland Ltd. when you choose to write to us on WhatsApp. Advertising cookies and pixels are only activated after you consent.
- Professional advisers: accountants, auditors and lawyers, under a duty of confidentiality.
- Public authorities and courts, where we are legally obliged to disclose.
We never sell your personal data, and we never share health data for advertising purposes.
5. International transfers
Our website is hosted in Germany. However, our team, our partner clinics and our suppliers are located in Türkiye, so your data is transferred to and accessed from Türkiye.
Türkiye is not covered by a European Commission adequacy decision. We therefore rely on the following safeguards for transfers out of the European Economic Area:
- the European Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) with our Turkish suppliers and partner clinics, supported by a transfer impact assessment; and
- where a specific treatment cannot be arranged without sending your medical file abroad, your explicit consent to that particular transfer under GDPR Art. 49(1)(a), after we have told you about the risks.
For transfers out of Türkiye we apply KVKK Art. 9 as amended, using standard contracts notified to the Turkish Data Protection Authority or, where applicable, your explicit consent.
You can obtain a copy of the safeguards in place by writing to privacy@welldemir.com.
6. How long we keep your data
| Data | Retention period | Reason |
|---|---|---|
| Enquiries that do not lead to a booking | 12 months from the last contact | To answer follow-up questions, then deleted |
| Health data sent for a quotation, where no treatment follows | 6 months, or immediately on request | Data minimisation |
| Contract, booking and coordination records | 10 years from the end of the contract | Turkish Commercial Code Art. 82 and Tax Procedure Law |
| Invoices and accounting records | 10 years | Statutory bookkeeping obligation |
| Marketing consents and the record of them | Until withdrawal, then 3 years for evidence | Proof of consent under Law No. 6563 and GDPR Art. 7(1) |
| Server and security logs | 12 months | Security and abuse prevention |
| Cookie consent record | 12 months | Proof of consent |
When a period ends we delete the data or irreversibly anonymise it. Where a legal claim is pending, we keep the relevant file until the claim is finally resolved.
7. Your rights
Under GDPR Art. 15 to 22 and KVKK Art. 11 you may ask us to:
- confirm whether we process your data and give you a copy of it;
- correct data that is inaccurate or incomplete;
- delete your data, where there is no overriding legal reason to keep it;
- restrict processing while a dispute about accuracy or lawfulness is resolved;
- receive the data you gave us in a machine-readable format and have it sent to another controller;
- object to processing based on our legitimate interests, and to direct marketing at any time, without giving a reason;
- withdraw a consent you have given;
- be told which third parties your data was disclosed to, and have any correction or deletion notified to them.
You are not subject to any decision with legal effect that is based solely on automated processing, and we do not carry out profiling that produces such effects.
How to exercise your rights. Write to privacy@welldemir.com or to our postal address above. We answer within one month under the GDPR and within 30 days under the KVKK. The request is free of charge. We may ask for proof of identity so that we do not disclose your data to someone else.
Complaints. If you are not satisfied with our answer you may complain to a supervisory authority:
- in Türkiye, the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu, kvkk.gov.tr);
- in Germany, the data protection authority of your federal state (a list is published at bfdi.bund.de);
- in the Netherlands, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl);
- elsewhere in the EU, the supervisory authority of your country of residence or workplace.
8. Cookies and tracking
We use strictly necessary cookies to make the site work, and functional, statistical and marketing cookies only after you have given consent through our cookie banner. You can change or withdraw your choice at any time. Everything we set, including its purpose and lifetime, is listed in our Cookie Policy.
9. How we protect your data
- TLS encryption on every page of the website and on our forms;
- encrypted storage and access control on our servers, hosted in an ISO 27001 certified data centre in Germany;
- role-based access: only staff who need a file to do their job can open it;
- confidentiality undertakings for all staff and written processing agreements with every supplier;
- regular backups, patching and log review, and a documented procedure for reporting a personal data breach to the competent authority within 72 hours and to you where the breach is likely to result in a high risk to your rights.
10. Children
Our services are aimed at adults. We do not knowingly collect data from anyone under 18. Where a treatment involves a minor, we deal with the parent or legal guardian and process the minor’s data only on their instructions. If you believe a child has given us data, write to privacy@welldemir.com and we will delete it.
11. Is providing your data mandatory
You are not obliged to give us any data. However, without your contact details we cannot answer you, and without the relevant medical information a clinic cannot prepare a treatment plan or a price. If you prefer not to send medical details by e-mail, tell us and we will arrange a secure alternative.
12. Changes to this policy
We review this policy at least once a year and whenever our services or the law change. The current version is always published on this page with its date and version number. If a change materially affects you, we will tell you by e-mail or by a notice on the website before it takes effect.
13. Contact
Demir Health Turizm A.Ş. (WellDemir)
Esentepe Mah. Büyükdere Cad. Özsezen İş Merkezi No: 124, Inner Door No: 9, Şişli / İstanbul, Türkiye
Data protection contact: privacy@welldemir.com
General enquiries: hello@welldemir.com


