Legal
Privacy Policy
Last updated: August 2026
1. Who we are
Istanbul Medical Tourism ('we', 'us') operates istanbulmedtourism.com — a platform that connects international patients with accredited medical clinics in Istanbul, Turkey. This policy explains what data we collect and how we use it.
2. Data we collect
We collect only what you choose to share with us:
- Contact details you submit through quote forms — name, email, phone, country
- Treatment preferences and any health information you voluntarily include in messages
- Newsletter subscriptions (email address only)
- Basic technical data — IP address, browser type, pages visited (anonymised analytics)
3. Why we use it
- To match you with clinics and respond to your quote request
- To send you the medical guides you subscribed to
- To improve our website and understand which treatments are most requested
- To comply with legal obligations
4. Health data — sensitive information
Any medical information you share in a quote request is treated as highly confidential. It is shared only with the clinics you are matched with, and only for the purpose of preparing your quotation. We never sell or rent health data.
5. Who we share data with
- The accredited clinics you are matched with (for quote preparation)
- Service providers who host our website and database (bound by data-processing agreements)
- Authorities, only where legally required
6. Data retention
Quote requests are kept for 24 months after your last contact, after which they are permanently deleted. Newsletter subscriptions persist until you unsubscribe (one click in any email).
7. Your rights
Under GDPR and comparable regulations you may request:
- Access to the personal data we hold about you
- Correction of inaccurate data
- Deletion of your data ('right to be forgotten')
- Restriction or objection to processing
- Data portability
8. Cookies
We use a minimal set of cookies: a locale preference cookie, a currency preference cookie and (if enabled) analytics cookies. We do not use third-party advertising cookies.
9. Security
Data is transmitted over TLS-encrypted connections, stored in a restricted-access database, and never exposed publicly. Admin access is protected by strong authentication.
10. Contact
Privacy questions: [email protected]. We respond within 30 days.