Privacy
What this website collects, what you send us, and what happens to it. For the website the short answer is: nothing you have not agreed to.
Last updated 2026-08-24
Who is responsible
The clinic trades as LIN Europe Clinic and sees guests at Zeytinlik, Kennedy Cad. No: 24, Bakırköy, İstanbul. The company behind it, and the data controller for everything described here, is ALIN ESTETIK VE SAGLIK HIZMETLERI LIMITED SIRKETI.
For anything in this notice, write to info@lineuropeclinic.com. A person reads that address; it is not a ticketing system.
What this website collects
Two things, and only one of them is your decision. The first is the ordinary access log any web server keeps, described in the next paragraph. The second is measurement — Google Analytics 4, Google Tag Manager and the Meta Pixel inside it — which loads with every storage signal denied and writes nothing to your browser until you accept the bar at the foot of the page. Refuse and it stays denied, and you can read every page of this site with nothing recorded about you but that log.
The server that sends you these pages keeps ordinary access logs — the requesting IP address, the page asked for, the time, and the browser’s own user-agent string. That is how a web server works and how an attack on it is noticed. The logs are kept for a short operational period and are not used to build a profile of anybody, nor combined with anything else.
What you send us
The site offers three ways to reach the clinic — WhatsApp, telephone and email — and each is a conversation you start. What we then hold is whatever you chose to tell us: your name, the way to reply to you, and what you are considering.
That often includes health information — a photograph, a medication, something in your history. Under both Turkish and European law that is a special category of data, and it is handled accordingly: it is used to advise you and to plan your treatment, it is seen by the coordinator and the clinical team involved in your care and by the hospital treating you, and it is not sent anywhere else. It is never used for marketing, and it is never published — the photographs and films on this site are all there because the person in them agreed to it separately and in writing.
WhatsApp is worth naming separately: it belongs to Meta, and a message you send through it passes through Meta’s systems on its way to us under Meta’s own terms, not ours. If that matters to you, email or the telephone reach the same desk.
What makes that lawful is worth naming rather than leaving to inference. For your name and the way to reply to you: the steps taken at your request before any agreement — Article 6(1)(b) of the GDPR, and the corresponding ground in Article 5 of KVKK. For anything touching your health: your explicit consent, which Article 9(2)(a) of the GDPR and Article 6 of KVKK both require and which sending it to us is taken to be. Consent given that way can be withdrawn the same way, in one sentence, at the address above.
Who else is involved
Only where it is unavoidable, and only these:
- The company hosting this website, which necessarily processes the access logs described above on our behalf.
- Google and Meta, from the moment you accept measurement and not before. Google Analytics 4 and Tag Manager are Google’s, the Pixel is Meta’s, and each processes what it collects under its own policy — every storage signal denied to both until you say otherwise.
- YouTube, but only from the moment you press play on one of the guest films. Until then nothing is requested from it, and the player we use is the no-cookie one. Once it loads, YouTube’s privacy policy governs what it does.
- The hospital and the clinical team treating you, where you become a patient. This is care, not a transfer of data for anybody’s convenience.
- Nobody else. Your data is not sold, not rented, and not passed to advertisers — there are no advertisers, because there is no advertising on this site.
The border your data crosses
Everything described here happens in İstanbul: the server that sends you these pages, the desk that answers your message, the hospital where an operation takes place. Türkiye sits outside the European Economic Area and the European Commission has issued no adequacy decision for it — so if you are writing from the EU or the UK, your enquiry is a transfer of personal data to a country whose regime the Commission has not declared equivalent to its own.
That transfer happens because you asked for it, and it has no other basis. Under the GDPR it rests on Article 49(1)(b) — steps taken at your request before a contract — and, for the health information a consultation involves, on the explicit consent of Article 49(1)(a), which is what sending it is taken to be. Nothing crosses the border until you write, and nothing further crosses it once you stop.
How long any of it is kept
Server logs, for a short operational period measured in weeks. Then they are gone, and nothing is derived from them before they go.
An enquiry that never becomes a treatment is kept while the conversation is alive and for as long afterwards as it might plausibly resume — and deleted whenever you ask, which is faster than any period we could write down here.
A patient record is the exception, and it is worth being plain about it. Once you are treated, Turkish health legislation fixes how long the file must be kept and the treating hospital keeps it for that period. That is an obligation rather than a preference, and it is the one case where asking for deletion will not empty the file — every other right below still applies to it.
Your rights
Under KVKK (Law 6698) in Türkiye and the GDPR where it applies to you, you can ask us what we hold about you, ask for it to be corrected, ask for it to be deleted, ask us to stop processing it, and object to how we are processing it. Where we rely on your consent — publishing a photograph, for instance — you can withdraw that consent, and the photograph comes down.
Write to info@lineuropeclinic.com and say what you want. We answer within thirty days, which is the period KVKK sets. If you are not satisfied you can complain to the Turkish Personal Data Protection Authority (KVKK Kurumu), or to your own supervisory authority if you are in the EU.
Changes
If this website starts doing something it does not do today — an embedded booking form, analytics, anything that sets a cookie — this page changes before that goes live, not after, and the date at the top changes with it.
