GÜRAY REAL ESTATE DEVELOPMENT CONSTRUCTION INC. and its GROUP OF COMPANIES and SUBSIDIARIES
PERSONAL DATA PROTECTION AND PROCESSING POLICY
The protection of personal data is among the most important priorities of Güray Real Estate Development Construction Inc. (“the Company”) and its group of companies and subsidiaries. The most important part of this is the protection and processing of personal data of our job applicants, company shareholders, company officials, visitors, employees, shareholders and officials of institutions with which we cooperate, and third parties, which is governed by this Policy.
According to the Constitution of the Republic of Turkey, everyone has the right to request the protection of personal data concerning themselves. Regarding the protection of personal data, a right guaranteed by the Constitution, the company is governed by this Policy; The company takes the necessary care to protect the personal data of job applicants, company shareholders, company officials, visitors, employees, shareholders and officials of institutions with which it cooperates, and third parties, and makes this a company policy.
In this context, the necessary administrative and technical measures are taken by the company to protect personal data processed within the framework of legal regulations.
The fundamental principles adopted by the company in the processing of personal data in this Policy are as follows;
- Processing personal data in accordance with the law and principles of fairness,
- Keeping personal data accurate and up-to-date when necessary,
- Processing personal data for specific, explicit and legitimate purposes,
- Processing personal data in a manner that is relevant, limited and proportionate to the purpose for which it is processed,
- Retaining personal data for the period stipulated in the relevant legislation or necessary for the purpose for which it is processed,
- Informing and educating personal data owners,
- Establishing the necessary system for personal data owners to exercise their rights,
- Taking necessary measures in the preservation of personal data,
- Acting in accordance with the relevant legislation and the regulations of the Personal Data Protection Board when transferring personal data to third parties in line with the requirements of the processing purpose,
- Showing the necessary sensitivity to the processing and protection of special categories of personal data.
ARTICLE 1: POLICY PURPOSE
The primary purpose of this policy is to ensure transparency and trust by informing individuals whose personal data is processed by our company, including our customers, employees, job applicants, company shareholders, company officials, visitors, employees, shareholders and officials of institutions with which we cooperate, and third parties, about the personal data processing activities carried out by the company in a lawful manner.
ARTICLE 2: CONTENT AND DEFINITIONS
This Policy relates to all personal data of our employees, job applicants, company shareholders, company officials, visitors, employees, shareholders and officials of institutions with which we cooperate, and third parties, processed automatically or non-automatically as part of any data recording system.
The scope of application of this Policy to the groups of personal data owners in the categories mentioned above may be the entire Policy or only a part of it.
The definitions of the concepts included in this policy document are as follows:
Recipient group: The category of natural or legal persons to whom personal data is transferred by the data controller.
Explicit Consent: Consent given freely and based on informed knowledge regarding a specific matter.
Anonymization: Making personal data impossible to link to an identified or identifiable natural person, even when combined with other data.
Employee: Company personnel.
Electronic Environment: Environments where personal data can be created, read, modified, and written using electronic devices.
Non-Electronic Environment: All written, printed, visual, etc. media outside of electronic environments. Other environments
Service provider: A natural or legal person providing services to the institution within the framework of a specific contract.
Data subject: The natural person whose personal data is processed.
Relevant user: Within the data controller organization or data controller organization, excluding the person or unit responsible for the technical storage, protection and backup of the data.Persons who process personal data in accordance with the authority and instructions received from their supervisor:
Destruction: Deletion, destruction, or anonymization of personal data.
Law: Law No. 6698 on the Protection of Personal Data.
Data Recording Medium: Any medium containing personal data processed wholly or partially automatically, or by non-automatic means as part of any data recording system.
Personal Data: Any information relating to an identified or identifiable natural person.
Personal Data Processing Inventory: Data personal data processing activities carried out by those responsible in accordance with their business processes; An inventory created by data protection agencies detailing the purposes and legal basis for processing personal data, the data category, the recipient group to whom the data is transferred, and the data subject group, along with the maximum retention period necessary for the purposes for which the personal data is processed, the personal data intended for transfer to foreign countries, and the measures taken regarding data security.
**Processing of Personal Data:** Any operation performed on personal data, such as obtaining, recording, storing, keeping, modifying, rearranging, disclosing, transferring, acquiring, making available, classifying, or preventing the use of data, whether wholly or partly automated or non-automated, provided that it is part of a data recording system.
**Board:** Personal Data Protection Board
**Special Category Personal Data:** Data relating to a person’s race, ethnic origin, political opinion, philosophical belief, religion, etc. Data relating to religious or other beliefs, appearance and clothing, membership in associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
Periodic Destruction: The deletion, destruction or anonymization process that will be carried out automatically at recurring intervals as stated in the personal data storage and destruction policy when all the conditions for processing personal data stipulated in the law cease to exist.
Policy: Personal Data Storage and Destruction Policy
Company: GÜRAY REAL ESTATE DEVELOPMENT CONSTRUCTION INC.
Data Processor: A natural or legal person who processes personal data on behalf of the data controller, based on the authority given by the data controller.
Data Recording System: A recording system in which personal data is processed by structuring it according to specific criteria.
Data Controller: A natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.
Data Controllers Registry Information System: An information system created and managed by the Presidency, accessible via the internet, which data controllers will use for applications to the Registry and other related transactions concerning the Registry. System
VERBIS: Data Controllers Registry Information System
Regulation: Regulation on the Deletion, Destruction or Anonymization of Personal Data published in the Official Gazette dated October 28, 2017
ARTICLE 3: APPLICATION OF THE POLICY AND RELATED LEGISLATION
The relevant legal regulations in force regarding the processing and protection of personal data shall primarily apply. In case of any inconsistency between the current legislation and the Policy, our Company accepts that the current legislation shall apply.
The Policy is formed by concretizing and regulating the rules set forth by the relevant legislation within the scope of the Company’s practices.
ARTICLE 4: EFFECTIVE DATE OF THE POLICY
This Policy, prepared by our company, enters into force on the day it is published on our website. The effective date will be updated if there are any changes or updates to the Policy.
The Policy is published on our company’s website and made available to relevant individuals upon request from personal data owners.
ARTICLE 5: MATTERS RELATING TO THE PROTECTION OF PERSONAL DATA
In accordance with Article 12 of the KVKK (Law on Protection of Personal Data), our company aims to prevent the unlawful processing of personal data it processes, and to protect the data…The company takes all necessary administrative, technical, and legal measures to ensure appropriate security to prevent unlawful access to personal data and to ensure its preservation, and provides all necessary audits within this scope.
ARTICLE 6: ENSURING THE SECURITY OF PERSONAL DATA
6.1 Technical and Administrative Measures Taken to Ensure the Lawful Processing of Personal Data
Our company takes technical and administrative measures to ensure the lawful processing of personal data, in accordance with technological capabilities and implementation costs.
- Technical Measures Taken to Ensure the Lawful Processing of Personal Data
The main technical measures taken by our company to ensure the lawful processing of personal data are listed below:
- Personal data processing activities carried out within our company are monitored by established technical systems.
- The technical measures taken are periodically reported to the relevant parties as required by the internal audit mechanism.
- Personnel knowledgeable in technical matters are employed.
- Administrative Measures Taken to Ensure the Lawful Processing of Personal Data
The main administrative measures taken by our company to ensure the lawful processing of personal data are listed below:
- Employees are informed and trained on the law of personal data protection and the lawful processing of personal data.
- All activities carried out by our company are analyzed in detail for each business unit, and as a result of this analysis, personal data processing activities are determined in relation to the commercial activities carried out by the relevant business units.
- The personal data processing activities carried out by our company’s business units are; The requirements to be fulfilled to ensure compliance with the personal data processing conditions required by Law No. 6698 are determined for each business unit and the specific activities it carries out.
Awareness is created and implementation rules are determined for each business unit to ensure that the determined legal compliance requirements are met; Administrative measures necessary to ensure the monitoring of these issues and the continuity of implementation are put into practice through internal company policies and training. - Clauses are included in the contracts and documents governing the legal relationship between our company and employees, obligating them not to process, disclose, or use personal data, except for company instructions and exceptions provided by law. Employee awareness is raised in this regard, and audits are conducted.
6.2 Technical and Administrative Measures Taken to Prevent Unlawful Access to Personal Data
Our company takes technical and administrative measures, according to the nature of the data to be protected, technological capabilities, and implementation costs, to prevent the careless or unauthorized disclosure, access, transfer, or any other form of unlawful access to personal data.
- Technical Measures Taken to Prevent Unlawful Access to Personal Data
The main technical measures taken by our company to prevent unlawful access to personal data are listed below:
- Technical measures are taken in line with developments in technology, and these measures are periodically updated and renewed.
- Access and authorization technical solutions are implemented in accordance with the legal compliance requirements determined on a business unit basis.
- The technical measures taken are periodically reported to the relevant parties as required by the internal audit mechanism, and issues posing risks are re-evaluated and the necessary technological solutions are produced.
- Software and hardware including virus protection systems and firewalls are installed.
- Personnel knowledgeable in technical matters are employed.
-
- Administrative Measures Taken to Prevent Unlawful Access to Personal Data
Measures
The main administrative measures taken by our company to prevent unlawful access to personal data are listed below:
- Employees are trained on the technical measures to be taken to prevent unlawful access to personal data.
- Access and authorization processes for personal data are designed and implemented within the Company in accordance with legal compliance requirements on a business unit basis.
- Employees are informed that they cannot disclose the personal data they have learned to others in violation of the provisions of the Personal Data Protection Law and cannot use it for purposes other than the processing purpose, and that this obligation will continue even after they leave their positions, and the necessary commitments are obtained from them in this regard.
- Provisions are added to the contracts concluded with the persons to whom personal data is lawfully transferred by our company, stating that the persons to whom personal data is transferred will take the necessary security measures for the protection of personal data and ensure compliance with these measures in their own organizations.
6.3 Storage of Personal Data in Secure Environments
Our company takes the necessary technical and administrative measures, according to technological possibilities and implementation costs, to store personal data in secure environments and to prevent its destruction, loss, or alteration for unlawful purposes.
- Technical Measures Taken for the Secure Storage of Personal Data
The main technical measures taken by our company to store personal data in secure environments are listed below:
- Systems in line with technological developments are used for the secure storage of personal data.
- Expert personnel are employed in technical matters.
- Technical security systems are established for storage areas, the technical measures taken are periodically reported to the relevant parties as required by the internal audit mechanism, and issues posing risks are re-evaluated and the necessary technological solutions are produced.
- Backup programs are used in accordance with the law to ensure the secure storage of personal data.
- Administrative Measures Taken for the Secure Storage of Personal Data
The main administrative measures taken by our company to ensure the secure storage of personal data are listed below:
- Employees are trained to ensure the secure storage of personal data.
- In cases where our company obtains an external service for the storage of personal data due to technical requirements, the contracts concluded with the relevant companies to which personal data is lawfully transferred include provisions stating that the persons to whom personal data is transferred will take the necessary security measures for the protection of personal data and ensure compliance with these measures in their own organizations.
6.4 Auditing of Measures Taken Regarding the Protection of Personal Data
Our company conducts or has conducted the necessary audits within its own organization in accordance with Article 12 of the KVKK (Personal Data Protection Law). The results of this audit are reported to the relevant unit within the company’s internal operations, and necessary activities are carried out to improve the measures taken.
6.5 Measures to be Taken in Case of Unauthorized Disclosure of Personal Data
In accordance with Article 12 of the Personal Data Protection Law (KVKK), our company will ensure that if personal data processed is obtained by others through unlawful means, this situation is reported to the relevant personal data owner and the Personal Data Protection Board as soon as possible.
If deemed necessary by the Personal Data Protection Board, this situation may be announced on the KVKK’s website or by another method.
ARTICLE 7: PROTECTION OF THE RIGHTS OF THE DATA SUBJECT; CREATING CHANNELS FOR DATA SUBJECTS TO COMMUNICATING THESE RIGHTS TO OUR COMPANY AND EVALUATING DATA SUBJECTS’ REQUESTS
Our company implements the necessary channels, internal procedures, administrative and technical arrangements in accordance with Article 13 of the Personal Data Protection Law (KVKK) for evaluating the rights of personal data subjects and providing them with the necessary information.
If personal data subjects submit their requests regarding the rights listed below to our company in writing, our company will process the request free of charge as soon as possible and within thirty days at the latest, depending on the nature of the request. However, if the process requires additional costs, our company will charge the fee determined by the Personal Data Protection Board. Personal data subjects;
- To learn whether personal data is being processed,
- To request information regarding the processing of personal data if it has been processed,
- To learn the purpose of the processing of personal data and whether it is being used in accordance with its purpose,
- To know the third parties to whom personal data has been transferred, domestically or abroad,
- To request the correction of personal data if it has been processed incompletely or incorrectly, and to request that the action taken in this regard be notified to the third parties to whom the personal data has been transferred,
- To request the deletion or destruction of personal data if the reasons requiring its processing have ceased to exist, even if it has been processed in accordance with the Personal Data Protection Law and other relevant laws, and to request that the action taken in this regard be notified to the third parties to whom the personal data has been transferred,
- To request that a result detrimental to the individual arises as a result of the analysis of processed data exclusively through automated systems,
- The right to object,
- The right to demand compensation for damages incurred as a result of the unlawful processing of personal data.
More detailed information regarding the rights of data subjects is included in this Policy.
ARTICLE 8: PROTECTION OF SPECIAL CATEGORY PERSONAL DATA
The Personal Data Protection Law (KVKK) assigns special importance to certain personal data due to the risk of causing harm or discrimination to individuals if processed unlawfully.
These data include: race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership in associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
Our company acts with sensitivity in the protection of special category personal data, which are defined as “special category” by the KVKK and processed lawfully. In this context, the technical and administrative measures taken by our Company to protect personal data are carefully applied with regard to special categories of personal data, and the necessary audits are provided within the company.
Detailed information regarding the processing of special categories of personal data is included in this Policy.
ARTICLE 9: INCREASING AWARENESS AND CONTROL OF BUSINESS UNITS REGARDING THE PROTECTION AND PROCESSING OF PERSONAL DATA
Our Company ensures that necessary training is provided to business units to increase awareness regarding the prevention of unlawful processing of personal data, unlawful access to data, and the preservation of data.
Systems are established to raise awareness among existing employees and newly hired employees of the company’s business units regarding the protection of personal data, and professional personnel are consulted when needed.
ARTICLE 10: INCREASING AWARENESS AND MONITORING THE PROTECTION AND PROCESSING OF PERSONAL DATA AMONG BUSINESS PARTNERS AND SUPPLIERS
Our company ensures the organization of trainings and seminars for business partners to increase awareness regarding the prevention of unlawful processing of personal data, the prevention of unlawful access to data, and the preservation of data.
The trainings conducted for the company’s business partners are repeated periodically, and necessary systems are established to raise awareness among existing employees and newly hired employees of the business units regarding the protection of personal data. Professionals are consulted when necessary.
The results of the trainings conducted to increase awareness among the company’s business partners regarding the protection and processing of personal data are reported to the company. In this regard, our company evaluates participation in these trainings, seminars, and information sessions and conducts or commissions the necessary audits. Our company updates and renews its training programs in parallel with the updating of relevant legislation.
ARTICLE 11: MATTERS RELATING TO THE PROCESSING OF PERSONAL DATA
In accordance with Article 20 of the Constitution and Article 4 of the Personal Data Protection Law, our company processes personal data in a manner that is lawful and fair; accurate and, when necessary, up-to-date; pursuing specific, clear, and legitimate purposes; and relevant, limited, and proportionate to the purpose. Our company retains personal data for the period stipulated by law or required by the purpose of personal data processing.
In accordance with Articles 20 of the Constitution and 5 of the Personal Data Protection Law, our company processes personal data based on one or more of the conditions in Article 5 of the Personal Data Protection Law regarding the processing of personal data.
Our company, in accordance with Article 20 of the Constitution and Article 10 of the Personal Data Protection Law, informs personal data owners and provides the necessary information upon request from personal data owners.
Our company acts in accordance with the regulations stipulated in Article 6 of the Personal Data Protection Law regarding the processing of special categories of personal data.
Our company acts in accordance with the regulations stipulated in the law and established by the Personal Data Protection Board regarding the transfer of personal data, in accordance with Articles 8 and 9 of the Personal Data Protection Law.
ARTICLE 12: PROCESSING OF PERSONAL DATA IN ACCORDANCE WITH THE PRINCIPLES PROVIDED FOR IN THE LEGISLATION
12.1 Processing in Accordance with the Law and the Rule of Honesty
Our company acts in accordance with the principles established by legal regulations and the general rule of trust and honesty in the processing of personal data. In this context, our Company takes into account the proportionality requirements in the processing of personal data and does not use personal data for purposes other than those required by the purpose.is.
12.2 Ensuring the Accuracy and Timeliness of Personal Data
Our company ensures the accuracy and timeliness of the personal data it processes, taking into account the fundamental rights of personal data owners and its own legitimate interests. It takes the necessary measures in this regard.
12.3 Processing for Specific, Clear and Legitimate Purposes
Our company clearly and precisely defines the legitimate and lawful purpose of personal data processing. Our company processes personal data only to the extent necessary and relevant to the services it provides.
12.4 Being Relevant, Limited and Proportional to the Purpose for Which They Are Processed
Our company processes personal data in a manner suitable for achieving the defined purposes and avoids processing personal data that is not related to or needed for the achievement of the purpose. For example, personal data processing activities aimed at meeting potential future needs are not carried out.
12.5 Retention for the Period Stipulated in Relevant Legislation or Necessary for the Purpose for Which They Are Processed
Our company retains personal data only for the period stipulated in the relevant legislation or necessary for the purpose for which they are processed. In this context, our company first determines whether a retention period for personal data is stipulated in the relevant legislation; if a period is specified, it acts in accordance with that period; if no period is specified, it retains personal data for the period necessary for the purpose for which they are processed. Upon the expiration of the period or the cessation of the reasons requiring processing, personal data is deleted, destroyed, or anonymized by our company. Personal data is not retained by our company for the possibility of future use. Detailed information on this matter is included in this Policy.
ARTICLE 13: PROCESSING PERSONAL DATA BASED ON ONE OR MORE OF THE PERSONAL DATA PROCESSING CONDITIONS SPECIFIED IN ARTICLE 5 OF THE KVKK (Law on Protection of Personal Data)
The protection of personal data is a constitutional right. Fundamental rights and freedoms may only be restricted by law, without prejudice to their essence, and only for the reasons specified in the relevant articles of the Constitution. According to the third paragraph of Article 20 of the Constitution, personal data may only be processed in cases stipulated by law or with the explicit consent of the individual. In line with this and in accordance with the Constitution, our company processes personal data only in cases stipulated by law or with the explicit consent of the individual. Detailed information on this subject is included in this Policy.
ARTICLE 14: INFORMING AND NOTIFYING THE DATA SUBJECT
In accordance with Article 10 of the Personal Data Protection Law (KVKK), our company informs data subjects during the collection of personal data. In this context, we provide information regarding the identity of the Holding company and its representative (if any), the purpose for which personal data will be processed, to whom and for what purpose the processed personal data may be transferred, the method and legal basis for collecting personal data, and the rights of the data subject. Detailed information on this subject is included in this Policy.
Article 20 of the Constitution states that everyone has the right to be informed about personal data concerning them. In line with this, Article 11 of the KVKK includes the right to “request information” among the rights of the data subject. In accordance with Articles 20 of the Constitution and 11 of the KVKK, our company provides the necessary information when the data subject requests it. Detailed information on this subject is included in this Policy.
ARTICLE 15: PROCESSING OF SPECIAL CATEGORY PERSONAL DATA
Our company meticulously complies with the regulations stipulated in the Personal Data Protection Law (KVKK) when processing personal data defined as “special category” under the KVKK.
Article 6 of the KVKK defines certain personal data as “special category” if processed unlawfully, as these data carry the risk of causing harm or discrimination to individuals. These data include: race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership in associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
In accordance with the KVKK, our company processes: Special categories of personal data are processed in the following cases, provided that adequate measures are taken as determined by the Personal Data Protection Board:
- If the personal data owner has given explicit consent or
- If the personal data owner has not given explicit consent;
- Special categories of personal data other than the personal data owner’s health and sexual life are processed in cases foreseen by law,
- Special categories of personal data relating to the personal data owner’s health and sexual life are processed.Special categories of personal data are processed only by persons or authorized institutions and organizations under an obligation of confidentiality, for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and managing health services and their financing.ARTICLE 16: TRANSFER OF PERSONAL DATA
Our company may transfer the personal data and special categories of personal data of the data subject to third parties (third-party companies, business partners, third-party individuals) in accordance with the lawful purposes of personal data processing, by taking the necessary security measures. Our company acts in accordance with the regulations stipulated in Article 8 of the Personal Data Protection Law. Detailed information on this subject is included in this Policy.
16.1 Transfer of Personal Data
Our company may transfer personal data to third parties based on one or more of the following conditions specified in Article 5 of the Law, in line with legitimate and lawful personal data processing purposes:
- If the personal data owner has given explicit consent;
- If there is an explicit provision in the laws regarding the transfer of personal data;
- If it is necessary for the protection of the life or physical integrity of the personal data owner or another person, and the personal data owner is unable to express their consent due to factual impossibility or if their consent is not legally valid;
- If the transfer of personal data belonging to the parties of a contract is necessary, provided that it is directly related to the establishment or performance of the contract;
- If the transfer of personal data is necessary for our company to fulfill its legal obligations;
- If the personal data has been made public by the personal data owner;
- If the transfer of personal data is necessary for the establishment, exercise or protection of a right,
- If the transfer of personal data is necessary for the legitimate interests of our Company, provided that it does not harm the fundamental rights and freedoms of the personal data owner.
16.2 Transfer of Special Categories of Personal Data
Our Company may transfer the special categories of personal data of the personal data owner to third parties in the following cases, in line with legitimate and lawful personal data processing purposes, by exercising due diligence, taking necessary security measures and adequate precautions foreseen by the Personal Data Protection Board.
- If the personal data owner has given explicit consent or
- If the personal data owner has not given explicit consent;
- Special categories of personal data other than the personal data owner’s health and sexual life (such as race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership in associations, foundations or trade unions, data relating to criminal convictions and security measures, as well as biometric and genetic data) may be processed in cases stipulated by law,
- Special categories of personal data relating to the personal data owner’s health and sexual life may only be processed by persons or authorized institutions and organizations under an obligation of confidentiality for the purpose of protecting public health, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and their financing.
ARTICLE 17:PERSONAL DATA TRANSFER ABROAD
Our company may transfer the personal data and sensitive personal data of the data subject to third parties in accordance with the lawful purposes of personal data processing, by taking the necessary security measures. Personal data is transferred by our company to foreign countries declared by the Personal Data Protection Board as having adequate protection (“Foreign Country with Adequate Protection”) or, in cases where adequate protection is not available, to foreign countries where the data controllers in Turkey and the relevant foreign country have provided a written guarantee of adequate protection and have the permission of the Personal Data Protection Board (“Foreign Country with a Data Controller Guaranteeing Adequate Protection”). Our company acts in accordance with the regulations stipulated in Article 9 of the Personal Data Protection Law. Detailed information on this subject is included in this Policy.
17.1Transfer of Personal Data Abroad
Our company may transfer personal data to foreign countries where the Data Controller Provides or Undertakes to Provide Adequate Protection, in accordance with legitimate and lawful personal data processing purposes, with the explicit consent of the personal data owner, or if there is no explicit consent from the personal data owner, in the presence of one of the following conditions:
If there is an explicit provision in the laws regarding the transfer of personal data,
- If it is necessary for the protection of the life or physical integrity of the personal data owner or another person, and the personal dataIf the owner is unable to express their consent due to factual impossibility or if their consent is not legally valid;If the transfer of personal data belonging to the parties of a contract is necessary, provided that it is directly related to the establishment or performance of the contract,
If the transfer of personal data is necessary for our company to fulfill its legal obligations,
If the personal data has been made public by the personal data owner,If the transfer of personal data is necessary for the establishment, exercise or protection of a right,
If the transfer of personal data is necessary for the legitimate interests of our company, provided that it does not harm the fundamental rights and freedoms of the personal data owner,
17.2 Transfer of Special Categories of Personal Data Abroad
Our company will exercise due diligence, take necessary security measures and… By taking adequate measures as foreseen by the Personal Data Protection Board, the data subject’s special categories of personal data may be transferred to foreign countries where the Data Controller Provides or Commits to Provide Adequate Protection, in line with legitimate and lawful personal data processing purposes, in the following cases:
- If the personal data owner has given explicit consent or
- If the personal data owner has not given explicit consent;
- Special categories of personal data other than the personal data owner’s health and sexual life (such as race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership in associations, foundations or trade unions, data relating to criminal convictions and security measures, as well as biometric and genetic data) may be processed in cases foreseen by law,
- Special categories of personal data relating to the personal data owner’s health and sexual life may only be processed by persons or authorized institutions and organizations under an obligation of confidentiality for the purpose of protecting public health, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and their financing.
ARTICLE 18: CATEGORIZATION OF PERSONAL DATA PROCESSED BY OUR COMPANY, PURPOSES OF PROCESSING AND STORAGE PERIODS
In accordance with Article 10 of the Personal Data Protection Law, our company informs the data subject about which groups of personal data it processes, the purposes of processing their personal data, and the storage periods.
ARTICLE 19: CATEGORIZATION OF PERSONAL DATA
In accordance with Article 10 of the Personal Data Protection Law (KVKK), our company processes personal data in the categories listed below, limited to the subjects covered by this Policy, in line with our company’s legitimate and lawful personal data processing purposes, based on one or more of the personal data processing conditions specified in Article 5 of the KVKK, and in compliance with the general principles specified in the KVKK, primarily the principles regarding the processing of personal data specified in Article 4, and all obligations regulated in the KVKK. This Policy also specifies which data owners the processed personal data in these categories are related to.
IDENTITY INFORMATION; Personal data that clearly belongs to an identified or identifiable natural person, processed partially or completely automatically or non-automatically as part of a data recording system; All information contained in documents such as driver’s licenses, national identity cards, residence permits, passports, lawyer’s IDs, and marriage certificates.
CONTACT INFORMATION; Information such as telephone number, address, and email, which clearly belongs to an identified or identifiable natural person and is processed partially or fully automatically or non-automatically as part of a data recording system.
CUSTOMER INFORMATION; Information obtained and generated about the relevant person as a result of our commercial activities and the operations carried out by our business units within this framework, which clearly belongs to an identified or identifiable natural person and is processed partially or fully automatically or non-automatically as part of a data recording system.
PHYSICAL LOCATION SECURITY INFORMATION; Personal data relating to records and documents obtained during entry to and stay within a physical location, which clearly belongs to an identified or identifiable natural person and is included in the data recording system.
TRANSACTION SECURITY INFORMATION; Personal data that clearly belongs to an identified or identifiable natural person and is recorded in the data recording system; processed to ensure our technical, administrative, legal and commercial security while conducting our commercial activities.
RISK MANAGEMENT INFORMATION; An identified or identifiable natural personData that clearly belongs to the company and is included in the data risk management system; data that can be used and processed in accordance with generally accepted legal, commercial practices and principles of honesty in these areas, so that we can manage our commercial, technical and administrative risks.
FINANCIAL INFORMATION; Personal data processed relating to information, documents and records showing all kinds of financial results created according to the type of legal relationship established between our company and the personal data owner, which clearly belongs to an identified or identifiable natural person, processed partially or completely automatically or non-automatically as part of a data recording system.
PERSONNEL INFORMATION; Any personal data processed to obtain information that will form the basis of the personnel rights of our employees or natural persons who have an employment relationship with our Company, which clearly belongs to an identified or identifiable natural person.
EMPLOYEE CANDIDATE INFORMATION; Personal data processed, in whole or in part, automatically or non-automatically as part of a data recording system, that clearly relates to an identified or identifiable natural person; personal data processed relating to individuals who have applied to become employees of our Company, or who have been evaluated as job candidates in accordance with our Company’s human resources needs based on commercial customs and rules of honesty, or who are in an employment relationship with our Company.
EMPLOYEE TRANSACTION INFORMATION; Personal data processed, in whole or in part, automatically or non-automatically as part of a data recording system, that clearly relates to an identified or identifiable natural person; personal data processed relating to all transactions carried out by our employees or natural persons in an employment relationship with our Company.
WORK PERFORMANCE AND CAREER DEVELOPMENT INFORMATION; Data processed, in whole or in part, automatically or non-automatically as part of a data recording system, that clearly relates to an identified or identifiable natural person; data processed for the purpose of measuring the performance of our employees or natural persons in an employment relationship with our Company and planning and executing their career development within the scope of our Company’s human resources policy.
INFORMATION ON FRINGEMENTS AND BENEFITS; Personal data that clearly belongs to an identified or identifiable natural person, processed partially or fully automatically or non-automatically as part of a data recording system; processed for the purpose of planning the fringe benefits and advantages we offer or will offer to employees or other natural persons in an employment relationship with our Company, determining objective criteria for entitlement to these benefits, and tracking entitlements.
INFORMATION ON LEGAL PROCEDURES AND COMPLIANCE; Personal data that clearly belongs to an identified or identifiable natural person, processed partially or fully automatically or non-automatically as part of a data recording system; processed for the purpose of determining and tracking our legal claims and rights, fulfilling our obligations, and complying with our legal obligations and company policies.
INFORMATION ON AUDIT AND INSPECTION; Personal data that clearly belongs to an identified or identifiable natural person, processed partially or fully automatically or non-automatically as part of a data recording system; Your personal data is processed within the scope of our company’s legal obligations and compliance with company policies.
SPECIAL CATEGORY PERSONAL DATA; Data that clearly belongs to an identified or identifiable natural person, processed partially or completely automatically or non-automatically as part of a data recording system; data specified in Article 6 of Law No. 6698.
REQUEST/COMPLAINT MANAGEMENT INFORMATION; Personal data relating to the receipt and evaluation of all kinds of requests or complaints directed to our company, processed partially or completely automatically or non-automatically as part of a data recording system, and clearly belonging to an identified or identifiable natural person.
ARTICLE 20: PURPOSES OF PROCESSING PERSONAL DATA
The main purposes for processing personal data, according to the categorization prepared by our company, are shared below:
- To carry out the necessary work by our relevant business units and to manage the related business processes for the performance of the commercial activities carried out by our company,
- Planning and execution of our company’s commercial and/or business strategies,
- To carry out the necessary work by our business units and to manage the related processes to enable relevant individuals to benefit from the products and services offered by our company,
- Our company’s human resources policies and processesPlanning and execution of activities,
- Ensuring the legal, technical and commercial security of relevant persons with whom our company has a business relationship.
The data processing purposes within the scope of the above-mentioned main objectives are as follows:
- Event Management
- Planning and Execution of Research and Development Activities
- Planning and Execution of Business Activities
- Planning and Execution of Corporate Communication Activities
- Planning and Execution of Information Security Processes
- Establishment and Management of Information Technology Infrastructure
- Planning and Execution of Access Rights to Information and Facilities for Business Partners and/or Suppliers
- Planning and Execution of Fringe Benefits and Advantages for Supplier and/or Business Partner Employees
- Finance and/or Accounting Operations Monitoring
- Planning and Execution of Logistics Activities
- Management of Relationships with Business Partners and/or Suppliers
- Conducting Activities to Identify Financial Risks of Customers
- Planning and Execution of Customer Relationship Management Processes
- Monitoring of Contract Processes and/or Legal Claims
- Monitoring of Customer Requests and/or Complaints
- Planning of Human Resources Processes
- Execution of Personnel Recruitment Processes
- Monitoring of Legal Affairs
- Planning and Execution of Operational Activities Necessary to Ensure that Company Activities are Conducted in Accordance with Company Procedures and/or Relevant Legislation
- Business Partner/Supplier Collection of Employee Entry and Exit RecordsCreation and Tracking of Visitor Records
Planning and Execution of Company Audit Activities
Planning and/or Execution of Occupational Health and/or Safety Processes
Ensuring Data is Accurate and Up-to-Date
Managing and/or Auditing Relationships with Subsidiaries
Ensuring the Security of Company Campuses and/or Facilities
Ensuring the Security of Company Assets and/or Resources
Planning and/or Execution of Company Financial Risk ProcessesFor purposes other than those mentioned above, our Company seeks the explicit consent of personal data owners; the personal data processing activities listed below are carried out by the relevant business units in accordance with the aforementioned explicit consent of personal data owners. In this context, if the above-mentioned conditions are not met, the purposes for which the explicit consent of the personal data owners is sought are:
- Planning and Execution of Access Rights to Information and Facilities for Business Partners and/or Suppliers
- Planning and Execution of Logistics Activities
- Management of Relationships with Business Partners and/or Suppliers
- Following Up on Contract Processes and/or Legal Claims
- Planning of Human Resources Processes
- Execution of Personnel Recruitment Processes
- Planning and/or Execution of Customer Satisfaction Activities
- Planning and Execution of Operational Activities Necessary to Ensure that Company Activities are Conducted in Accordance with Company Procedures and/or Relevant Legislation
-
- Business Partner/Supplier Employees
Collection of Entry and Exit Records
- Planning and Execution of Company Audit Activities
- Planning and/or Execution of Occupational Health and/or Safety Processes
- Ensuring the Security of Company Campuses and/or Facilities
ARTICLE 21: PERSONAL DATA RETENTION PERIODS
Our company stores personal data for the period specified in the relevant laws and regulations, if required by them.
If no retention period is specified in the legislation, personal data is processed for the period required by our company’s practices and commercial customs in connection with the services provided by our company when processing that data, and then deleted, destroyed, or anonymized. Detailed information on this subject is included in this policy.
If the purpose of processing personal data has ended, and the retention periods determined by the relevant legislation and the company have also expired, personal data may only be retained for the purpose of serving as evidence in possible legal disputes, or for asserting or defending a right related to the personal data. The retention periods here are determined by the statute of limitations for asserting the aforementioned right, and also by the fact that, even after the expiration of the statute of limitations, the company has previously held similar positions on the same issues.Retention periods are determined based on examples from requests directed to our team. In this case, the stored personal data is not accessed for any other purpose and access to the relevant personal data is only provided when it is necessary to use it in the relevant legal dispute. After the aforementioned period expires, the personal data is deleted, destroyed, or anonymized.
ARTICLE 22: CATEGORIZATION OF OWNERS OF PERSONAL DATA PROCESSED BY OUR COMPANY
While our company processes the personal data of the following categories of personal data owners, the scope of application of this Policy is limited to our customers, potential customers, job applicants, company shareholders, company officials, visitors, employees, shareholders and officials of institutions with which we cooperate, and third parties.
The protection and processing of personal data of our employees will be evaluated under the Holding Employees Personal Data Protection and Processing Policy.
While the categories of individuals whose personal data is processed by our company are within the scope specified above, individuals outside these categories may also submit requests to our company under the Personal Data Protection Law; these requests will also be evaluated within the scope of this Policy.
Below, the concepts of customer, potential customer, visitor, job applicant, shareholder and board member, natural persons in institutions with which we cooperate, and third parties related to these individuals are clarified within the scope of this Policy.
ARTICLE 23: CATEGORIES AND DEFINITIONS
Visitor; Natural persons who have entered our company’s physical premises for various purposes or who have visited our websites.
Third Parties; Third-party natural persons related to these individuals to ensure the security of commercial transactions between our company and the parties, or to protect the rights and provide benefits to these individuals, or natural persons who are not covered by this policy and the company’s personal data protection and processing policy.
Job Applicant; Individuals who have applied for a job at our company through any means or who have provided their resume information to our company.
Company Shareholder; Individuals who are shareholders of our company.
Company Official; Individuals who are members of the company’s board of directors and other authorized individuals.
Employees, institutions, shareholders and officials with whom we cooperate; Individuals in institutions with which our company has any kind of business relationship (including but not limited to business partners, offices, suppliers, and the shareholders and officials of these institutions).
ARTICLE 24: THIRD PARTIES TO WHOM PERSONAL DATA IS TRANSFERRED BY OUR COMPANY AND THE PURPOSES OF TRANSFER
In accordance with Article 10 of the KVKK (Personal Data Protection Law), our company informs the personal data owner of the groups of individuals to whom personal data is transferred.
In accordance with Articles 8 and 9 of the Personal Data Protection Law, our company may transfer the personal data of service users to the following categories of individuals:
- Company business partners,
- Company suppliers,
- Company affiliates,
- Company shareholders,
- Legally authorized public institutions and organizations,
- Legally authorized private legal entities.
The scope of the individuals to whom data is transferred and the purposes of data transfer are as follows;
- Limited to ensuring the fulfillment of the purposes for which the business partnership was established,
- Limited to ensuring the provision of services that our company procures from suppliers through external sources and that are necessary for carrying out our company’s commercial activities,
- Limited to ensuring the conduct of our company’s commercial activities that require the participation of its subsidiaries,
- Limited to designing and auditing the strategies and audit activities of our company’s commercial activities in accordance with the provisions of legal legislation,
- In case of requests for information and documents from our company by legally authorized public institutions and organizations within the framework of legal legislation, limited to the purpose requested within our legal authority,
- In case of requests for information and documents from our company by legally authorized private legal entities within the framework of legal legislation, limited to the purpose requested within our legal authority,
Transfers made by our company are carried out in accordance with the matters regulated in the policy.
Our company informs the data subject about the personal data it processes in accordance with Article 10 of the Personal Data Protection Law.
Although the legal grounds for processing personal data by our company vary, each typeIn all personal data processing activities, we act in accordance with the general principles specified in Article 4 of Law No. 6698.
For the processing of personal data subject to the explicit consent of the data subject, explicit consent is obtained from visitors and third parties.
The personal data of the data subject may be processed lawfully if explicitly provided for in the law.
If the processing of the personal data of a person who is unable to express their consent due to factual impossibility or whose consent cannot be considered valid is necessary to protect the life or physical integrity of that person or another person, the personal data of the data subject may be processed.
If the processing of personal data of the parties to a contract is necessary for the establishment or performance of that contract, it is possible to process personal data.
If the processing is necessary for our company, as the data controller, to fulfill its legal obligations, the personal data of the data subject may be processed.
If the data subject has made their personal data public, the relevant personal data may be processed.
Personal data of the data subject may be processed if data processing is necessary for the establishment, exercise, or protection of a right (e.g., invoice).
Personal data of the data subject may also be processed if it is necessary for the legitimate interests of our Company, provided that it does not harm the fundamental rights and freedoms of the data subject (e.g., for internal company calculations).
Personal data processing activities carried out by our Company at building and facility entrances and within the facilities are conducted in accordance with the Constitution, the Personal Data Protection Law, and other relevant legislation.
Our Company conducts personal data processing activities for security purposes, including monitoring visitor entry and exit through security cameras in our buildings and facilities.
The use of security cameras and recording visitor entry and exit constitutes personal data processing by our Company.
In this context, our Company acts in accordance with the Constitution, the Personal Data Protection Law, and other relevant legislation. Within the scope of security camera monitoring activities, our Company; The purpose of camera surveillance is to improve the quality of the service provided, ensure its reliability, provide security for the company, its employees and other individuals, and protect the interests of third parties regarding the service they receive. The camera surveillance activity carried out by our company is conducted in accordance with the Law on Private Security Services and related legislation. Our company acts in accordance with the regulations in the Personal Data Protection Law (KVKK) when conducting camera surveillance for security purposes.
Our company conducts security camera surveillance in its buildings and facilities for the purposes stipulated in the laws and in accordance with the personal data processing conditions listed in the KVKK.
The announcement of the surveillance activity by our company is made in accordance with Article 10 of the KVKK.
In addition to providing general information, our company provides notification regarding camera surveillance activities through multiple methods in accordance with the relevant regulations in the EU. This aims to prevent harm to the fundamental rights and freedoms of the personal data owner, to ensure transparency, and to inform the personal data owner.
In accordance with Article 4 of the Personal Data Protection Law (KVKK), our company processes personal data in a manner that is relevant to the purpose for which it is processed, limited, and proportionate.
The purpose of our company’s video surveillance activities is limited to the purposes listed in this Policy. Accordingly, the areas, number, and timing of security camera surveillance are implemented in a manner that is sufficient and limited to achieving the security objective. Monitoring does not occur in areas where it could result in an intrusion into a person’s privacy beyond the scope of security purposes (e.g., restrooms).
In accordance with Article 12 of the KVKK, our company takes the necessary technical and administrative measures to ensure the security of personal data obtained as a result of camera surveillance activities.
Only a limited number of company employees have access to the records recorded and stored digitally. Live camera footage can be viewed by external security personnel. The limited number of individuals with access to the records declare, through a confidentiality agreement, that they will protect the confidentiality of the data they access.
By our company; Personal data processing activities are carried out to monitor guest entries and exits at company buildings and facilities in order to ensure security and for the purposes stated in this Policy.
As a guest, you may…The names and surnames of individuals visiting our premises are collected, or personal data owners are informed about this through texts posted on the Company’s premises or otherwise made accessible to guests. Data obtained for the purpose of tracking guest entry and exit is processed solely for this purpose, and the relevant personal data is recorded in a physical data recording system.
Regarding camera surveillance activities by our Company; this Policy is published on our Company’s website (online policy regulation) and a notification notice regarding surveillance is posted at the entrances of the areas where surveillance is conducted (on-site information).
On the websites owned by our Company; internet activity within the sites is recorded by technical means to ensure that visitors conduct their visits in a manner consistent with their visit purposes and to display personalized content to them.
Detailed explanations regarding the protection and processing of personal data related to these activities carried out by our Company are included in the “Company Website Privacy Policy” texts of the relevant websites.
Our company, in accordance with Article 138 of the Turkish Penal Code and Article 7 of the Personal Data Protection Law, may delete, destroy, or anonymize personal data at its own discretion or upon the request of the data subject, if the reasons requiring the processing of personal data cease to exist, even though the data has been processed in accordance with the relevant legal provisions. Our company fulfills this legal obligation through legal methods.
ARTICLE 25: TECHNIQUES FOR DELETION, DESTRUCTION, AND ANONYMIZATION OF PERSONAL DATA
25.1 Techniques for Deletion and Destruction of Personal Data
Our company may delete or destroy personal data at its own discretion or upon the request of the data subject, if the reasons requiring the processing of personal data cease to exist, even though the data has been processed in accordance with the relevant legal provisions. The most commonly used deletion or destruction techniques by our company are listed below:
- Physical Destruction
Personal data can also be processed through non-automatic means, provided that it is part of any data recording system. When deleting/destroying such data, a system of physically destroying the personal data in a way that it cannot be used later is applied.
25.1.2 Secure Deletion from Software
When deleting/destroying data processed entirely or partially automatically and stored in digital environments, methods related to deleting the data from the relevant software in a way that it cannot be recovered again are used.
- Secure Deletion by an Expert
In some cases, the company may contract with an expert to delete personal data on its behalf. In this case, the personal data is securely deleted/destroyed by the expert in this field in a way that it cannot be recovered again.
25.2 Techniques for Anonymizing Personal Data
Anonymizing personal data means making personal data impossible to link to an identified or identifiable natural person, even when combined with other data. Our company can anonymize personal data when the reasons requiring the processing of legally processed personal data cease to exist.
In accordance with Article 28 of the Personal Data Protection Law (KVKK), anonymized personal data may be processed for purposes such as research, planning, and statistics. Such processing is outside the scope of the KVKK, and the explicit consent of the personal data owner will not be required. Since personal data processed in anonymized form will be outside the scope of the KVKK, the rights stipulated in this Policy will not apply to this data.
The most commonly used anonymization techniques by our company are as follows:
- Masking
- Data masking is a method of anonymizing personal data by removing its essential identifying information from the dataset.
- Aggregation
With the data aggregation method, many data are aggregated, and personal data is made impossible to link to any individual.
- Data Derivation
With the data derivation method, a more general content is created from the content of the personal data, ensuring that the personal data cannot be linked to any individual.
- Data Mixing
With the data mixing method, the values within the personal data set are mixed, breaking the link between the values and the individuals.
Our company, in accordance with Article 10 of the Personal Data Protection Law, informs the personal data owner of their rights and how to exercise these rights.Our company provides guidance to the data subject on this matter and, in accordance with Article 13 of the Personal Data Protection Law, implements the necessary channels, internal procedures, administrative and technical arrangements to evaluate the rights of data subjects and to provide them with the necessary information.
ARTICLE 26: RIGHTS OF THE DATA SUBJECT AND THE EXERCISE OF THESE RIGHTS
26.1 Rights of the Personal Data Subject
Personal data subjects have the following rights:
- To learn whether personal data is being processed
- To request information regarding the processing of personal data if it has been processed
- To learn the purpose of the processing of personal data and whether it is being used in accordance with its purpose
- To know the third parties to whom personal data has been transferred, domestically or abroad
- To request the correction of personal data if it has been processed incompletely or incorrectly, and to request that the action taken in this regard be notified to the third parties to whom the personal data has been transferred
- To request the deletion or destruction of personal data if the reasons requiring its processing have ceased to exist, even if it has been processed in accordance with the Personal Data Protection Law and other relevant laws, and to request that the action taken in this regard be notified to the third parties to whom the personal data has been transferred. Request
- The right to object to a result that is detrimental to the individual arising from the analysis of processed data exclusively through automated systems
- The right to demand compensation for damages incurred as a result of the unlawful processing of personal data
26.2 Cases Where the Data Subject Cannot Assert Their Rights
In accordance with Article 28 of the Personal Data Protection Law, personal data subjects cannot assert the following rights in the cases listed below, as these cases are excluded from the scope of the Personal Data Protection Law:
- Processing of personal data for purposes such as research, planning and statistics by means of official statistics and anonymizing them
- Processing of personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that it does not violate national defense, national security, public security, public order, economic security, privacy or personality rights or constitute a crime
- Processing of personal data by public institutions and organizations authorized by law to carry out preventive, protective and intelligence activities aimed at ensuring national defense, national security, public security, public order or economic security
- Processing of personal data by judicial authorities or enforcement agencies in relation to investigation, prosecution, trial or execution proceedings
In accordance with Article 28/2 of the Personal Data Protection Law; Except for the right to claim compensation for damages, personal data owners cannot exercise the following rights in the cases listed below:
- When the processing of personal data is necessary for the prevention of crime or for criminal investigation.
- When the processing of personal data is made public by the personal data owner.
- When the processing of personal data is necessary for the performance of supervisory or regulatory duties, or for disciplinary investigation or prosecution, by authorized and competent public institutions and organizations and professional organizations with the status of public institutions, based on the authority granted by law.
- When the processing of personal data is necessary by judicial authorities or enforcement agencies in relation to investigation, prosecution, trial or execution proceedings.
26.3 Exercise of Personal Data Owner’s Rights
Personal data owners may submit their requests regarding the rights listed above in this section to our Company free of charge using the method specified below:
- nidyahotelesenyurt.com form can be filled out, signed with a wet signature, and then sent in person to info@nidyahotelesenyurt.com.
- nidyahotelesenyurt.com form can be filled out, signed with a wet signature, and then sent by cargo or post to Koza Mahallesi 1655. Sokak NO: 3 34538 İstanbul/TÜRKİYE.
- After filling out the form at nidyahotelesenyurt.com and signing it with your “secure electronic signature” within the scope of the Electronic Signature Law No. 5070, the securely electronically signed form can be sent to info@nidyahotelesenyurt.com. via emailIt is not possible for third parties to make requests on behalf of personal data owners.
For a person other than the personal data owner to make a request, there must be a special power of attorney issued by the personal data owner to the person who will make the request.This is the procedure.
Data subjects, in order to exercise their rights, will fill out the “Application Form for Applications to be Made by the Data Subject to the Data Controller Pursuant to Law No. 6698 on the Protection of Personal Data” linked above. The method of making the application is also explained in detail in this form.
26.4 Right of the Data Subject to File a Complaint with the Personal Data Protection Board
In accordance with Article 14 of the Personal Data Protection Law, if the application is rejected, the response is deemed insufficient, or no response is given within the specified time, the data subject may file a complaint with the Personal Data Protection Board within thirty days from the date they learn of the Company’s response, and in any case within sixty days from the date of application.
ARTICLE 27: COMPANY’S RESPONDENCE TO APPLICATIONS
27.1 Procedure and Timeframe for Our Company’s Response to Applications
If the personal data owner submits their request to our Company in accordance with the procedure outlined in the preceding section, our Company will process the request free of charge as soon as possible and within thirty days at the latest, depending on the nature of the request.
However, if the process requires additional costs, our Company will charge the applicant a fee according to the tariff determined by the Personal Data Protection Board.
27.2 Information Our Company May Request from the Personal Data Owner Making the Application
Our Company may request information from the relevant person to determine whether the person making the application is the personal data owner.
Our Company may ask the personal data owner questions regarding their application to clarify the matters included in the application.
27.3 Our Company’s Right to Reject the Data Subject’s Application
Our company may reject the application of the applicant, stating the reasons, in the following cases:
- Processing of personal data for purposes such as research, planning, and statistics by means of official statistics and anonymizing them.
- Processing of personal data for purposes such as national defense, national security, public security, public order,
-
- Processing of personal data for artistic, historical, literary, or scientific purposes, or within the scope of freedom of expression, provided that it does not violate national defense, national security, public security, public order, economic security, privacy, or personal rights, or constitute a crime.
- Processing of personal data within the scope of preventive, protective, and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public security, public order, or economic security.
- Processing of personal data by judicial authorities in relation to investigation, prosecution, trial, or execution proceedings.
or processing by enforcement authorities.
- The processing of personal data is necessary for the prevention of crime or for criminal investigation.
- The processing of personal data that has been made public by the data subject.
- The processing of personal data is necessary for the performance of supervisory or regulatory duties, or for disciplinary investigation or prosecution, by authorized and competent public institutions and organizations and professional organizations with the status of public institutions, based on the authority granted by law.
- The processing of personal data is necessary for the protection of the economic and financial interests of the State in relation to budget, tax and financial matters.
- The request of the data subject may hinder the rights and freedoms of other individuals.
- The requests require disproportionate effort.
- The requested information is publicly available information.
ARTICLE 28: PROTECTION AND PROCESSING OF PERSONAL DATA OF THE COMPANY RELATIONSHIP OF THIS POLICY WITH OTHER POLICIES
This Policy outlines the fundamental policies regarding the protection and processing of personal data that the Company has established to address the principles set forth herein. By establishing a link between these policies and the Company’s other core policies, harmonization is ensured between processes the Company operates with different policy principles for similar purposes.
A “Personal Data Protection Board” has been established within the Company, by decision of the Company’s senior management, to manage this policy and other related policies. The duties of this board are listed below.
-
- To prepare and implement the basic policies regarding the Protection and Processing of Personal Data and submit them to the approval of senior management.
- To decide how the implementation and supervision of the policies regarding the Protection and Processing of Personal Data will be carried out, and to make internal assignments and ensure coordination within this framework, and submit these matters to the approval of senior management.
- Measures to be taken to ensure compliance with the Personal Data Protection Law and related legislation.
To identify potential risks in the company’s personal data processing activities and submit necessary measures to the approval of senior management; to oversee implementation and ensure coordination.
To increase awareness within the company and among institutions with which the company collaborates regarding the Protection and Processing of Personal Data.
To identify potential risks in the company’s personal data processing activities and ensure that necessary precautions are taken; to submit improvement suggestions to the approval of senior management. Design and conduct training sessions on the protection of personal data and the implementation of policies. Resolve personal data owner applications at the highest level.
For personal data owners; To coordinate the execution of information and training activities to ensure that individuals are informed about personal data processing activities and their legal rights.
To prepare and submit changes to the basic policies regarding the Protection and Processing of Personal Data to the approval of senior management.
To monitor developments and regulations regarding the Protection of Personal Data; to advise senior management on what needs to be done within the Company in accordance with these developments and regulations.
To coordinate relations with the Personal Data Protection Board and Institution.
To perform other tasks assigned by the company’s senior management regarding the protection of personal data.
Some of the stated policies are intended for internal use within the Company. The principles of internal policies are reflected in publicly available policies to the extent relevant, aiming to inform stakeholders and ensure transparency and accountability regarding the personal data processing activities carried out by the Company.