Privacy Policy

  • Home
  • Privacy Policy

Who we are

Betadent Privacy Policy

This policy explains what personal data Betadent collects, why we collect it, who we share it with, how long we keep it and what you can ask us to do about it. It covers this website and the dental care we provide at our clinic in Antalya, Türkiye.

The controller of your personal data is Betadent Ağız ve Diş Sağlığı Polikliniği — Est. Öz. Sağ. Hizm. Med. Tur. Tic. Ltd. Şti. (“Betadent”, “we”, “us”), Kızıltoprak Mah., 919. Sokak No:23/A, 07300 Muratpaşa / Antalya, Türkiye.

For anything about your data, write to betadentantalya@gmail.com or info@betadenttr.com, or contact the clinic at the address above.

Many of our patients live in the United Kingdom, the European Union, Norway, Switzerland or another country outside Türkiye. We therefore apply both Turkish data protection law (Law No. 6698, KVKK) and, where it applies to you, the UK GDPR and the EU GDPR. Where the two differ, we apply whichever gives you the stronger protection.

Two things worth knowing before you read on

  • Your treatment happens in Türkiye. Your clinical records are created and kept here, under Turkish health legislation. If you are in the UK or the EU, that means your data leaves your country — section 7 explains the legal basis for that in plain terms.
  • We do not sell your data, ever. We do not share patient data with data brokers, lead sellers or advertising networks, and we do not use your medical information for advertising.

What we collect

The Data We Hold About You

We ask for the minimum needed to treat you safely and to meet our legal obligations. Not every item below applies to every patient — what we ask for depends on your age, your medical history and the treatment planned.

If you contact us or use this website

  • Your name, e-mail address and phone number, and anything else you choose to write in an appointment form, a WhatsApp message or an e-mail.
  • The treatment you are asking about, and any photographs or X-rays you send us so we can give you an indicative plan.
  • Technical data your browser sends: IP address, device and browser type, the pages you view and the site you arrived from. See section 8 on cookies — most of this is only collected if you allow it.

If you become a patient

  • Identity data: name, date and place of birth, gender, national ID or passport number, address.
  • Contact data: phone, e-mail, and the messaging channel you prefer.
  • Your patient protocol number and appointment history.
  • Health data: medical and dental history, examination findings, X-rays and other imaging, laboratory and test results, treatment plans, prescriptions, and clinical notes.
  • Clinical photographs and video of the treated area, where these are needed for planning, laboratory work or your records.
  • Payment and invoicing data, and private insurance or social security details where relevant.
  • CCTV footage of the entrance and common areas of the clinic, kept for security.

Health data, biometric data and similar categories are “special category” data under the GDPR and “special quality” data under the KVKK. We treat them accordingly: they are held under professional confidentiality and are only accessible to the clinical and administrative staff who need them for your care.

Why we may use it

Purposes and Legal Bases

Under the GDPR every use of your data needs a legal basis, and health data needs a second one. This table sets out ours. The equivalent Turkish provisions are Articles 5 and 6 of the KVKK.

What we do with itLegal basis (UK/EU GDPR)
Answer your enquiry and give you an indicative treatment plan and priceSteps taken at your request before entering a contract — Art. 6(1)(b). Where you send us X-rays or clinical photos, your explicit consent — Art. 9(2)(a).
Provide dental treatment, keep clinical records, plan and follow up your carePerformance of our contract with you — Art. 6(1)(b); and for health data, provision of health care by a professional bound by a duty of confidentiality — Art. 9(2)(h).
Book, confirm, change and remind you about appointmentsPerformance of our contract — Art. 6(1)(b).
Invoice you, take payment, keep accounting recordsLegal obligation — Art. 6(1)(c); performance of contract — Art. 6(1)(b).
Meet Turkish health, tax and health-tourism reporting requirements, and respond to authorities and courtsLegal obligation — Art. 6(1)(c); and for health data, public health and health care management — Art. 9(2)(h)/(i).
Keep the clinic secure (CCTV) and keep our systems safeOur legitimate interest in the safety of patients, staff and premises — Art. 6(1)(f).
Handle a complaint, defend or bring a legal claimLegitimate interests — Art. 6(1)(f); for health data, establishment or defence of legal claims — Art. 9(2)(f).
Measure how the website is used and how well our advertising worksYour consent, given through the cookie banner — Art. 6(1)(a). You can withdraw it at any time from the cookie settings link in the footer.
Send you information about our services after treatmentYour consent — Art. 6(1)(a). Every message has an unsubscribe option.
Publish before-and-after photographs or a testimonialYour separate, written, explicit consent — Art. 9(2)(a). We never publish a patient image without it, and you can withdraw that consent later.

Where we rely on legitimate interests, we have weighed our interest against your rights and concluded it does not override them. You can ask us for that assessment.

Who sees it

Sharing and Recipients

We share as little as possible, and only with people who need it to do a specific job for you.

  • Our clinical and administrative team, on a need-to-know basis.
  • Dental laboratories that make your crowns, bridges or aligners — they receive the scans, shade information and models needed for the work, not your full record.
  • Imaging and laboratory providers where a test is sent outside the clinic.
  • Payment providers and banks, for the transaction only. We do not store your full card number; card payments are handled by the payment provider.
  • Our accountants, auditors and lawyers, where they need it for a specific matter.
  • Insurers and assistance companies, only where you ask us to invoice them or to support a claim you are making.
  • IT and communications suppliers who host this website, our e-mail and our patient records — under contract, and only so the service works.
  • The Turkish Ministry of Health, other public authorities and the courts, where the law requires it.

We do not sell personal data, we do not share it with data brokers, and we do not pass patient lists to advertising platforms.

How long we keep it

Retention

RecordKept for
Patient clinical records, imaging, treatment plans and consents10 years and 6 months from the end of treatment — the general limitation period under Article 146 of the Turkish Code of Obligations, plus a margin for service of notices.
Invoices and accounting recordsAs required by Turkish tax and commercial law.
Enquiries that do not become treatmentUp to 24 months, then deleted.
CCTV footageA short rolling period, then overwritten, unless it is needed for an incident.
Website analytics dataUp to 14 months in Google Analytics, if you consented.
Marketing consent recordsFor as long as you are subscribed, plus 3 years as proof of consent.

At the end of the period, paper records are destroyed physically and electronic records are deleted. Some clinical records may be kept longer where a legal claim is open or the law requires it.

Your rights

What You Can Ask Us To Do

These rights apply to you under the UK and EU GDPR, and equivalent rights exist under Article 11 of the Turkish KVKK.

  • Access — ask whether we hold data about you and get a copy of it.
  • Rectification — have anything inaccurate or incomplete corrected.
  • Erasure — ask us to delete data. Clinical records usually cannot be deleted before the retention period ends, because the law requires us to keep them; we will tell you if that is the case and why.
  • Restriction — ask us to stop using data while a dispute about it is resolved.
  • Objection — object to processing based on our legitimate interests, and object to direct marketing at any time, with no reason needed.
  • Portability — receive the data you gave us in a machine-readable format, or have it sent to another provider.
  • Withdraw consent — where we rely on your consent (cookies, marketing, publishing your photographs), you can withdraw it at any time. That does not affect anything done before.
  • Human review — we do not make decisions about your treatment by automated means; if you believe an automated process has affected you, you can ask for it to be reviewed by a person.
  • Compensation — under the KVKK, to claim damages if you suffer loss from unlawful processing.

How to exercise them

Write to betadentantalya@gmail.com from an address we already hold for you, or send a signed written request with proof of identity to the clinic at Kızıltoprak Mah., 919. Sokak No:23/A, 07300 Muratpaşa / Antalya, Türkiye. We ask for proof of identity so that we do not hand your medical records to someone else.

We respond within 30 days and free of charge. Under the KVKK a fee set by the Turkish Personal Data Protection Board may apply where a request requires additional cost; under the GDPR we may charge a reasonable fee only if a request is manifestly unfounded or excessive.

If you are not satisfied

  • United Kingdom — the Information Commissioner’s Office (ICO), ico.org.uk.
  • European Union / EEA — the data protection authority of the country where you live or work.
  • Türkiye — the Personal Data Protection Authority (KVKK), kvkk.gov.tr.

We would rather hear from you first, and we will always try to put things right.

International transfers

Your Data Leaves Your Country — Here Is Why

Betadent is established in Türkiye and your treatment takes place here, so your clinical records are created, stored and processed in Türkiye.

Türkiye is not covered by a UK or EU “adequacy decision”. Under Article 49 of the UK and EU GDPR, we rely on the following for the transfer:

  • Article 49(1)(b) — the transfer is necessary to perform the contract between you and us. You cannot be treated in Antalya without your records being held in Antalya.
  • Article 49(1)(a) — where you send us clinical information before there is a contract, your explicit consent, given after being told about the risk. Sending us your X-rays for an opinion is that consent in practice, and we say so on the form.
  • Article 49(1)(f) — where it is necessary to protect your vital interests and you cannot give consent, for example in an emergency.

Some of our suppliers — website hosting, e-mail, analytics — process data in the EU, the United Kingdom or the United States. Where those suppliers are outside Türkiye or your own country, transfers are covered by the supplier’s Standard Contractual Clauses or, for the United States, the EU–US and UK–US Data Privacy Framework.

You can ask us which suppliers hold what, and we will tell you.

Cookies

Cookies and Similar Technologies

A cookie is a small file a website stores in your browser. Some are needed for the site to work; the rest we only use if you say yes. When you first arrive you are asked to choose, and nothing beyond the strictly necessary category is loaded until you do.

CategoryWhat it doesSet only with consent?
Strictly necessaryRemembers the language you chose (betadentLang) and your cookie choice (betadentConsent). Both are stored in your browser’s local storage, not sent to us. Without these the site cannot remember basic settings.No — these are exempt, and there is no way to switch them off while using the site.
AnalyticsGoogle Analytics 4 (property G-H6D4DM0DXD, cookies _ga and _ga_*), loaded through Google Tag Manager (container GTM-5SS95LLB). Tells us how many people visit, which pages they read and where they leave. We use it in aggregate; we do not try to identify you from it.Yes.
AdvertisingTags from Google (Google Ads) and Meta (Facebook and Instagram), served through the same Tag Manager container. They measure whether an advert led to an enquiry and allow us to show our adverts to people who visited the site. No health data is ever sent to these platforms.Yes.
Embedded contentThe map on our contact page is a Google Maps embed. Loading it means Google receives your IP address. Video or social embeds, where present, work the same way.Yes, where the embed is not needed for the page to function.

Retention: Google Analytics cookies last up to two years and the data is kept for up to 14 months. Advertising cookies typically last up to 13 months in the EU and UK.

Changing your mind

Select Cookie settings in the footer of any page to reopen the banner and change your choice. Rejecting analytics and advertising does not limit anything on the site.

We use Google Consent Mode. When you reject, Google’s tags stay in a restricted state: they set no cookies and send no identifiers. You can also block or delete cookies in your browser settings, and send a Global Privacy Control signal, which we honour.

The rest

Security, Children and Changes

How we protect your data

  • Access to patient records is limited to staff who need it, under individual accounts.
  • The website is served only over HTTPS.
  • Clinical staff are bound by professional confidentiality, and all staff sign confidentiality undertakings.
  • We take the technical and organisational measures required by the KVKK and the GDPR, and we review them as our systems change.
  • If a breach is likely to result in a high risk to you, we will tell you, and we will notify the competent authority within 72 hours where the GDPR requires it.

Children

We treat children. Where a patient is under 18, we take the information from a parent or legal guardian, and consent for treatment and for any photography is given by them. We do not knowingly collect data from a child through this website.

Changes to this policy

We update this page when what we do changes. The date below is the last substantive change. If a change materially affects you — a new purpose, a new recipient — we will say so clearly rather than quietly editing the page.

Last updated: 10 September 2026.

Contact

Betadent Ağız ve Diş Sağlığı Polikliniği — Est. Öz. Sağ. Hizm. Med. Tur. Tic. Ltd. Şti. (“Betadent”, “we”, “us”)
Kızıltoprak Mah., 919. Sokak No:23/A, 07300 Muratpaşa / Antalya, Türkiye
Data protection: betadentantalya@gmail.com
General enquiries: info@betadenttr.com
Phone: +90 242 505 85 85 · WhatsApp: +44 7874 273299

Turkish-speaking patients: the Turkish clarification notice under Law No. 6698 is at KVKK Aydınlatma Metni. Where the two texts differ on a point of Turkish law, the Turkish text governs.

BETADENT

+44 7874 273299