This page explains how to exercise the rights granted by article 11 of Law no. 6698. The procedure follows the Communiqué on the Procedures and Principles of Application to the Data Controller.
First: who should you apply to
Choosing the right addressee matters, otherwise your request may go unanswered.
When to apply to Medonay
- You filled in the demo request form on
medonay.comormedonay.com.tr - You sign in to the Medonay panel as an employee of a hospital or an insurer
- You have corresponded with us by email
In these cases Medonay is the data controller and you should apply to us directly.
When to apply to your hospital or insurer
- You are a patient with a request about your provisioning transaction
For patient data in the provisioning process, the data controller is the hospital that treated you or the insurer that holds your policy; Medonay only processes that data on their instructions. Requests for access, rectification and erasure must therefore go to that institution.
If you contact us anyway we will not leave your request unanswered: we forward it to the relevant institution and notify you that we have done so.
What your application must contain
Under the Communiqué, your application must state:
- Your name, surname and, if the application is in writing, your signature
- Your Turkish national ID number if you are a Turkish citizen; your nationality, passport number or identity number if you are a foreign national
- Your residential or business address for service of notice
- Your email address, telephone and fax number, if any, for notification
- The subject of your request
Attaching the information and documents relevant to your request speeds the process up.
Note: Do not send more documents than are needed to verify your identity. Share sensitive documents such as medical reports or policy copies only if your request is directly about them.
Application channels
| Channel | Address |
|---|---|
| kvkk@medonay.com.tr | |
| Registered email (KEP) | Provided on request |
| Written application | Send a wet-signed petition by post; write to us for the address |
For applications by email, using the address you previously gave us and that is on file in our systems makes identity verification easier.
Response time and fees
Your application is concluded within thirty days at the latest from the date it reaches us. The response is sent through the channel you indicated in your application.
Your application is free of charge unless answering it involves a cost. Where a cost is involved, the fee set out in the tariff determined by the Personal Data Protection Board may be charged.
If your application is refused
If your application is refused, if you find our response inadequate, or if no response is given within the period, you may file a complaint with the Personal Data Protection Board within thirty days of learning of the response and in any case within sixty days of the application date.
What we can do quickly
For transparency, the two cases differ:
Patient data. If you have a record here because you went to a hospital or made a claim with an insurer, we have a ready process keyed to your identity document for both export and erasure, and such requests are concluded well within the thirty-day period. The request has to reach us through the controller (the hospital or the insurer); we act as a processor on their instruction.
Panel account. If you are a member of staff with a panel account, requests about your account are handled manually: there is no self-service export screen, and closing an account does not by itself erase the data behind it. When a request reaches us we establish what is held and where, erase what can be erased, and tell you the outcome in writing — within the statutory period, though not as quickly as for patient data.
In both cases audit records fall outside erasure requests because they are subject to a legal retention obligation; there you are told in writing which record is retained and why.