Patient coordinators online now · replies within 15 minutesCoordinators online now · replies in 15 min
EN (language: English)
  • ENEnglish
  • TRTürkçeSoon
  • ITItalianoSoon
  • ESEspañolSoon
  • FRFrançaisSoon
Legal

Privacy Policy

What we collect, why we hold it, how long we keep it and what you can make us do

If you contact us about treatment you will send us photographs of your body, your medical history and your medication list. That is sensitive information and this page sets out exactly what happens to it — written to be read rather than to satisfy a regulator.

  • Health data under explicit consent
  • Deleted on request, with named exceptions
  • No data sold, ever

Who we are and what this covers

Valentmedica, Istanbul, is the data controller for information you give us. This policy covers this website, our messaging channels and your treatment file.

We are a medical travel company rather than a clinic, which matters for privacy: some of your information is held by us, some by the hospital treating you, and the two are governed differently. This page is explicit about which is which.

Who controls what
InformationControllerGoverned by
Your enquiry, photographs and medical historyValentmedicaThis policy
Your quote, itinerary and correspondenceValentmedicaThis policy
Your hospital record, operation note, imagingThe treating hospitalTurkish health records law and the hospital’s own policy
Payment card detailsOur payment providerThe provider’s policy — we never see or store full card numbers
Flight and hotel bookingsThe airline or hotelTheir own policies

The law we work under

Turkish data protection law (KVKK, Law No. 6698) applies to us as a Turkish company. Where you are in the UK, EU or EEA, the UK GDPR or EU GDPR also applies to our processing of your data, and we apply the stricter of the two standards rather than arguing about jurisdiction.

What we collect and why

Four categories, each with a stated purpose and lawful basis. Nothing is collected "just in case".

Information you give us directly

  • Name, email address, telephone number and country of residence — so we can reply to you and know which health system and travel rules apply.
  • Photographs of the treatment area, where you choose to send them. For a hair transplant that is your scalp; for body surgery it is the area concerned.
  • Medical history: conditions, previous operations, allergies, current medication, smoking status, height and weight.
  • What you want to achieve, in your own words, which is the part clinicians actually read first.

Information collected automatically

  • Standard server logs: IP address, browser, pages requested, timestamps. Kept for security and retained for 90 days.
  • Analytics, only if you consent to it. Our cookie policy lists every cookie by name and purpose.
  • Nothing in the self-assessment tools on this site — the calculators, the Norwood scale, the implant and BMI tools — is sent anywhere. They run entirely in your browser and the numbers never reach us.

Information from others

  • Your treating surgeon or dentist in Istanbul, who sends us your operation note and discharge summary so we can run your aftercare.
  • Your own doctor at home, where you have asked us to liaise with them.
  • A referring clinician, with your consent.

Lawful bases

Why each category is lawful to process
PurposeLawful basis
Replying to your enquiry and preparing a quoteSteps taken at your request before entering a contract
Clinical assessment of photographs and medical historyExplicit consent (GDPR Art. 9(2)(a) / KVKK Art. 6)
Arranging treatment, transfer and accommodationPerformance of a contract
Aftercare contact for twelve monthsPerformance of a contract, and explicit consent for the clinical part
Security logging and fraud preventionLegitimate interests
Analytics and marketingConsent, which you may withdraw at any time

Health data, and photographs in particular

Health data is treated as a separate category with stricter handling, because that is what it deserves.

How your photographs are handled

  • They are visible to the coordinator handling your case and to the clinician assessing it. Not to the wider team.
  • They are stored on access-controlled systems and are not kept on anyone’s personal phone.
  • They are never used in marketing, on this website, on social media or in any presentation without separate, specific, written consent that names the use.
  • Consent to treatment is not consent to publication, and we will never make one conditional on the other.
  • If you gave consent to publication and later change your mind, tell us and we will remove the images from everything we control.

Why there are no patient photographs on this website

Advertising rules for cosmetic procedures restrict before-and-after imagery in several of the countries our patients live in, and Turkish health advertising regulation restricts it here. We take the stricter view: result photographs are shown to you privately during consultation, under the consent of the patients who appear in them, rather than published to anyone who lands on a page. Our before and after pages explain how to see them.

If you message us on WhatsApp

Many patients send photographs by WhatsApp because it is convenient. The messages are end-to-end encrypted in transit, but they also sit on your own device and on ours, and Meta processes metadata under its own policy. If you would rather not use it, say so and we will send you a secure upload link instead. We will never pressure you onto a channel you are uncomfortable with.

Who we share it with, and where it goes

A finite list. If a recipient is not on it, your data is not going there.

  • The hospital or clinic treating you, and the named surgeon or dentist. They receive what they need to assess and treat you safely.
  • The anaesthetist and the laboratory handling your pre-operative bloods.
  • Your hotel and transfer driver — name, arrival time and flight number only, never anything clinical.
  • Your own doctor at home, where you ask us to send records.
  • Our payment provider, which handles card details without passing them to us.
  • Professional advisers and auditors, bound by confidentiality, where legally required.
  • A public authority, where Turkish law compels disclosure. We would tell you unless legally prevented from doing so.

International transfers

Your data is processed in Turkey, which is where we and the treating hospitals are. Turkey is not currently covered by a UK or EU adequacy decision, so transfers from the UK or EEA rely on your explicit consent to the transfer, or on standard contractual clauses with our processors. We state this plainly because the alternative — burying it — is what most sites in this sector do.

What we never do

  • Sell personal data to anyone, in any form, including anonymised bulk sale.
  • Share your contact details with other clinics, agencies or "patient matching" services.
  • Buy patient contact lists, or contact anyone who has not asked to hear from us.
  • Pass your enquiry to a third-party call centre.

How long we keep it, and how it is protected

Retention periods, stated as numbers rather than as "no longer than necessary".

Retention schedule
DataKept forWhy
An enquiry that did not proceed12 months, then deletedPeople often come back after thinking about it
Photographs from an enquiry that did not proceed6 months, or immediately on requestNo reason to hold them longer
Treatment file for a patient we treated10 yearsTurkish medical records requirement, and your own interest if a question arises later
Financial records and invoices10 yearsTurkish tax and commercial law
Aftercare correspondence10 years, with the treatment fileIt is part of the clinical record
Server and security logs90 daysSecurity investigation
Marketing consent recordsUntil withdrawn, plus 3 yearsTo prove we had consent when we contacted you

Security measures

  • Encryption in transit (TLS) across the website and our messaging channels, and at rest for stored files.
  • Access restricted by role. A transfer coordinator cannot open your medical history, and does not need to.
  • Two-factor authentication on every staff account with access to patient data.
  • Confidentiality obligations in every staff and partner contract, surviving the end of the contract.
  • Logging of access to patient records, so unusual access can be identified.
  • No patient data on personal devices, personal email accounts or consumer cloud storage.

Your rights, and how to use them

These exist whether or not you are a patient, and exercising them costs nothing.

  • Access. Ask for a copy of everything we hold about you. We respond within 30 days, free of charge.
  • Rectification. Have anything inaccurate corrected. For clinical records the correction is appended rather than overwritten, which is how medical records work everywhere.
  • Erasure. Ask us to delete your data. We will, except for records a treating hospital is legally required to retain — and we will tell you specifically what those are rather than refusing in general terms.
  • Restriction. Ask us to stop processing while a dispute about accuracy or lawfulness is resolved.
  • Portability. Receive your data in a structured, machine-readable format, or have it sent directly to another provider.
  • Objection. Object to processing based on legitimate interests, including any profiling.
  • Withdraw consent. At any time, for marketing or for the processing of health data. Withdrawal does not affect what was lawful before it.
  • Complain. To us first, if you are willing, and to a supervisory authority whether or not you are.

How to make a request

  1. Write to us using the details on our contact page, saying which right you are exercising.
  2. We will verify your identity, because handing someone else’s medical photographs to an impostor would be a far worse failure than a delay.
  3. We respond within 30 days. If a request is genuinely complex we may extend by two months, and we will tell you why within the first 30 days.
  4. If you are not satisfied, you may complain to the Turkish Personal Data Protection Authority (KVKK), or to the ICO in the UK or your national supervisory authority in the EEA.

Automated decisions

We make none. The calculators and self-assessment tools on this site produce estimates in your browser; they do not decide anything, they do not report to us, and no one is accepted or declined by software. Every clinical decision is made by a named clinician who can explain it.

Privacy: frequently asked questions

No — not without separate, specific written consent that names the use, and consent to treatment is never conditional on it. There are no patient photographs anywhere on this site, by design.

Yes, and we will, except for records a treating hospital is legally required to retain for ten years under Turkish medical records law. We will tell you exactly what those are rather than refusing in general terms.

No. Not to advertisers, not to other clinics, not to lead brokers, not in anonymised bulk. We also do not buy patient lists, which is why you will never get an unsolicited message from us.

Messages are end-to-end encrypted in transit, but they sit on your device and ours, and Meta processes the metadata under its own policy. If you would rather not use it, ask and we will send a secure upload link instead.

The coordinator handling your case and the clinician assessing it. Access is restricted by role and logged, so a transfer coordinator cannot open your medical history and does not need to.

In Turkey, on access-controlled systems, encrypted in transit and at rest. Turkey has no UK or EU adequacy decision, so transfers from the UK or EEA rely on your explicit consent or on standard contractual clauses.

Twelve months for the enquiry, six months for any photographs — or immediately, if you ask us to delete them sooner.

No. Every tool on the site runs entirely in your browser. The numbers you enter never leave your device and never reach us.

Yes, free of charge, within 30 days. We will verify your identity first, because handing someone else’s medical photographs to an impostor would be a far worse failure than a short delay.

Only if you ask us to. Where you do, we send the operation note, discharge summary and whatever else your doctor needs, clinician to clinician.

We notify the regulator within 72 hours, and if the breach is likely to put you at high risk we tell you directly, in plain language, describing what was actually exposed.

Us first, if you are willing. Otherwise the Turkish Personal Data Protection Authority (KVKK), the ICO in the UK, or your national supervisory authority in the EEA — and you do not need to come to us first.

Free consultationEmily replies within 15 minutes
What would you like to treat?

No obligation · a specialist reviews your case, not a salesperson

Where can we send your plan?
Thank you.

Emily will message you on WhatsApp shortly, usually within 15 minutes during opening hours, to arrange your free assessment.

Message us now