Privacy Policy

DORTEL SHIP DISMANTLING IND. AND TRADE CO. LTD. PERSONAL DATA PROTECTION AND PROCESSING POLICY

SECTION 1
1.1 ENTRANCE
Protection of personal data is among the most important priorities of Dörtel Gemi Söküm San. ve Tic. Ltd. Şti. (“Company”) and maximum effort is shown to act in accordance with all legislation in force in this regard. Within the framework of this Personal Data Protection and Processing Policy (“Policy”), the principles adopted by our Company in carrying out personal data processing activities and the basic principles adopted in terms of the compliance of our Company’s data processing activities with the regulations in the Law on the Protection of Personal Data No. 6698 (“Law”) are explained and thus our Company ensures the necessary transparency by informing personal data owners. Your personal data is processed within the scope of this Policy with full awareness of our responsibility in this context.

1.2.PURPOSE
Dörtel Gemi Söküm San. ve Tic. Ltd. Şti (“Company”) undertakes to comply with the principles and rules introduced by the Constitution of the Republic of Turkey, the Personal Data Protection Law No. 6698 (LPPD) and other legislation regarding the protection of personal data and to protect the rights of the relevant persons in line with the Personal Data Protection and Processing Policy. For this purpose, it has adopted a written personal data protection policy and system to be implemented and developed.
The Personal Data Processing and Protection Policy sets forth the principles to be adopted by the Company and taken into consideration in practice regarding the protection and processing of personal data.
The Policy aims to determine the framework and ensure coordination of the compliance activities to be carried out specifically for the relevant Company in order to comply with the Personal Data Protection Law No. 6698 (“LPPD”) regarding the protection and processing of personal data. In this context, the aim is to continue to carry out the activities in accordance with the principles of legality, honesty and transparency and to ensure that the Company establishes and implements its own standards in the management of personal data; determining and supporting organizational goals and responsibilities, establishing control mechanisms in line with the acceptable risk level; fulfilling the obligations it is subject to in accordance with international agreements, the Constitution, laws, agreements and professional rules in the field of protection of personal data and protecting the interests of individuals in the best way possible.

1.3. SCOPE
This policy covers the services provided within the Company. The provisions of the policy cover all information systems and sub-information, contracts, environmental and physical areas involved in the processing of personal data in the company’s fields of activity and work areas, and the systems and regulations produced for all these. This policy covers all departments, directorates, employees of companies providing all kinds of services, interns and contract personnel of the company. Any action that violates the LPPD or this policy is evaluated within the scope of the relevant legislation and sanctions are applied accordingly. The company’s solution partners, public institutions and all third parties working with the company who have access to or are likely to access personal data are invited to read and comply with this policy. Third parties must ensure the protection of personal data with a system that is at least as strong and has sufficient standards as the company in terms of the protection of personal data.

 

1.4. TARGET
The Company’s Personal Data Protection Policy aims to create the necessary systems and establish the necessary order to ensure compliance with the legislation in line with the aim of creating awareness about the legal processing and protection of personal data within the Company.
In this context, the Company’s Personal Data Protection Policy aims to provide guidance in terms of the implementation of the regulations set forth in the Personal Data Protection Law and relevant legislation.

SECTION 2
2.1. DEFINITIONS AND ABBREVIATIONS

COMPANY DÖRTEL GEMİ SÖKÜM SAN. ve TİC. LTD. ŞTİ.
EXPLICIT CONSENT Consent based on informed consent and expressed freely on a specific subject.
ANONYMOUSATION It is the change of personal data in a way that it loses its personal data quality and this situation cannot be reversed. For example: Making personal data unassociated with a natural person through techniques such as masking, aggregation, data corruption, etc.
CONTACT PERSON Natural person whose personal data is processed. For example: Customers, visitors, employees and job candidates.
PERSONAL DATA Any information related to an identified and identifiable natural person. Therefore, the processing of information related to legal entities is not within the scope of the Law. For example: name-surname, TR ID No., e-mail, address, date of birth, credit card number, bank account number, etc.
SPECIAL NATURE PERSONAL DATA YData related to race, ethnic origin, political opinion, philosophical belief, religion, sect or other belief, dress code, association, foundation or union membership, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data are special data.
PROCESSING OF PERSONAL DATA Any operation performed on personal data, such as obtaining, recording, storing, preserving, changing, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, either fully or partially by automatic means or non-automatic means provided that it is part of any data recording system.
DATA CONTROLLER It refers to the natural or legal person who determines the purposes and means of processing personal data and manages the place where data is systematically kept (data recording system).
DATA OWNER APPLICATION FORM The application form that the Data Subject will use when applying for their rights stipulated in Article 11 of the Personal Data Protection Law.
CONSTITUTION Published in the Official Gazette dated 9 November 1982 and numbered 17863; Constitution of the Republic of Turkey dated 7 November 1982 and numbered 2709
PERSONAL DATA PROTECTION LAW Personal Data Protection Law No. 6698 dated 24 March 2016, published in the Official Gazette No. 29677 dated 7 April 2016.
POLICY Company Personal Data Protection and Processing Policy
NOTIFICATION ON THE PROCEDURES AND PRINCIPLES TO BE FOLLOWED IN FULFILLING THE ILLUMINATION OBLIGATION Communiqué on the Procedures and Principles to be Complied with in Fulfilling the Disclosure Obligation, which was published in the Official Gazette dated 10 March 2018 and numbered 30356 and entered into force.
PERSONAL DATA STORAGE AND DESTRUCTION POLICY Pursuant to the Regulation on the Deletion, Destruction and Anonymization of Personal Data, the process of determining the maximum period required for the purpose for which personal data is processed by the company and the policy on which the deletion, destruction and anonymization process is based.
PERIODIC DESTRUCTION The process of deletion, destruction or anonymization to be carried out at repeated intervals in case all the processing conditions of personal data specified in the law are eliminated.
REGISTERED ELECTRONIC MAIL (KEP) It is the system that protects all kinds of commercial, legal correspondence and document sharing in the form you send it, identifies the recipient with certainty, ensures that the content is never changed and turns the content into legal, valid, secure and definitive evidence.
DATA CONTROLLERS REGISTRY INFORMATION SYSTEM The information system created and managed by the Presidency, accessible via the internet, to be used by data controllers in applying to the Registry and other relevant transactions related to the Registry.

2.2. CLASSIFICATION OF PROCESSED PERSONAL DATA
Personal Datas:
Personal data is any information relating to an identified or identifiable natural person.
The protection of personal data is only related to real persons, and information belonging to legal entities that does not contain information about real persons is excluded from personal data protection. Therefore, this Policy does not apply to data belonging to legal entities.

Categories of Personal Data Subheadings and Descriptions
Identity Documents such as driver's license, identity card and passport containing information such as name and surname, Turkish Republic identity number, nationality information, mother's name-father's name, mother's maiden name, place of birth, date of birth, gender, as well as information such as tax number, SSI number, signature information, vehicle license plate, etc.
Communication Contact information is personal data such as telephone number, address, e-mail address, fax number, etc.
Personality Payroll information, disciplinary investigations, employment entry and exit document records, resume information, performance evaluation reports, etc.
Legal Action Correspondence information with Judicial Authorities, information in case files.
Customer Transaction Data related to customers such as invoices, promissory notes, check information, request information, order information, etc.
Physical Space Security Entry and exit records of employees and visitors, camera recordings.
Transaction Security Website login and logout information, IP address information, password and passcode information.
Finance Balance sheet information, asset information.
Professional Experience Diploma information, courses attended, in-service training information, transcript information, certificates.
Audio and Visual Recordings Audio and visual recordings
Special Personal Data Data specified in Article 6 of the LPPD (for example; health data including blood type, biometric data, religion and association membership information).

Special Personal Data:
Data regarding individuals’ race, ethnic origin, political views, philosophical beliefs, religion, sect or other beliefs, appearance and dress, membership in associations, foundations or unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data are special personal data.

 

 

2.3. ENVIRONMENTS WHERE PERSONAL DATA IS STORED

Electronic Media Non-Electronic Media
  • • Servers (Domain, backup, e-mail, database, web, file sharing, etc.) Software (office software.)
  • • Information security devices (firewall, attack detection and prevention, log file, antivirus, etc.)
  • • Personal computers (Desktop, laptop)
  • • Mobile devices (phone, tablet, etc.)
  • • Optical disks (CD, DVD, etc.)
  • • Removable memories (USB, Memory Card, etc.)
  • • Printer, scanner, photocopier
  • • Paper
  • • Manual data recording systems (survey forms, visitor log)
  • • Written, printed, visual media
  • • Unit cabinets

 

2.4.PURPOSES OF PROCESSING PERSONAL DATA:
As a company, we process personal data for purposes similar to, but not limited to, the following:
• Carrying out legal compliance processes,
• Managing operations,
• Carrying out financial and fiscal affairs,
• Determining and implementing commercial and business strategies,
• Fulfilling service obligations based on the service contract,
• Fulfilling employer responsibilities,
• Ensuring job security, managing, supervising and performing the job,
• Providing information about possible changes in our service terms,
• Organizing all records and documents that will form the basis of transactions in electronic (internet/mobile etc.) or physical environments,
• Providing information to public officials upon request and in accordance with the legislation on matters related to public safety,
• Fulfilling legal obligations and exercising rights arising from the current legislation,
• Fulfilling legal obligations in the event that the relevant authority requests and responds are mandatory within the scope of judicial and administrative investigations,
• Carrying out emergency management processes,
• Conducting communication activities,
• Conducting accounting and finance activities,
• Conducting information security processes,
• Ensuring physical space security,
• Conducting assignment processes,
• Following up and conducting legal affairs,
• Fulfilling legal obligations,
• Conducting communication activities,
• Planning human resources processes,
• Conducting / supervising business activities,
• Conducting occupational health / safety activities,
• Receiving and evaluating suggestions for improving business processes,
• Conducting business continuity activities,
• Conducting logistics activities,
• Ensuring quality standards,
• Keeping entries and exits to the institution building under control and preventing unauthorized entries,
• Conducting goods / service purchasing processes,
• Conducting goods / service after-sales support services,
• Conducting goods / service sales processes,
• Conducting goods / service production and operation processes,,
• Ensuring the security of goods resources.
• Increasing customer reliability,
• Conducting contract processes,
• Following up on requests/complaints,
• Ensuring the security of movable goods and resources,
• Conducting supply chain management processes,
• Conducting supplier relationship management processes,
• Conducting wage policy,
• Issuing product invoices,
• Conducting product policy,
• Conducting marketing processes of products/services,
• Foreign personnel work and residence permit procedures,
• Conducting talent/career development activities,
• Providing information to authorized persons, institutions and organizations,
• Conducting management activities,
• Creating and following up visitor records,
• Conducting storage and archive activities.

 

SECTION 3

ISSUES RELATED TO THE PROTECTION OF PERSONAL DATA:

3.1. Ensuring the Security of Personal Data:
In accordance with Article 12 of the Law, our Company takes the necessary measures according to the nature of the data to be protected in order to prevent unlawful disclosure, access, transfer of personal data or any other security deficiencies that may occur. In this context, our Company takes administrative measures, carries out or has audits carried out in accordance with the guidelines published by the Personal Data Protection Board (“Board”) to ensure the necessary level of security.

All our employees, stakeholders, guests, visitors and relevant third parties are obliged to cooperate throughout the Company in the operation, activities and processes and implementation of the Company’s Personal Data Protection Policy throughout the Company, and in preventing legal risks and imminent danger. All organs and departments of the Company are responsible for overseeing compliance with the Company’s Personal Data Protection Policy.

All personnel and employees are obliged to ensure that the data processed by the Company and under their responsibility are kept securely and not disclosed to third parties unless they sign a confidentiality agreement.

3.2. Protection of Special Personal Data
The Law has given special importance to certain personal data due to the risk of causing victimization or discrimination when processed illegally. These data are; data related to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, association, foundation or union membership, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data. Our Company is meticulous in protecting special personal data determined as “special” by the Law and processed in accordance with the law. In this context, the technical and administrative measures taken by the Company for the protection of personal data are meticulously implemented in terms of special personal data and the necessary controls are provided within the Company. Detailed information on the processing of special personal data is provided in section 4.3 (“Processing of Special Personal Data”) of this Policy.

3.3. Increasing Awareness and Supervision of Business Units Regarding the Protection and Processing of Personal Data
Our company ensures that the necessary training is organized for business units to increase awareness on preventing unlawful processing of personal data, unlawful access to personal data and ensuring the preservation of personal data. The necessary systems are established to raise awareness of the company employees on the protection of personal data, and when necessary, consultants are employed on the subject. In this regard, our company evaluates the participation in relevant trainings, seminars and information sessions, and updates and renews its trainings in parallel with the updating of the relevant legislation.

3.4. Increasing the Awareness and Supervision of Business Partners and/or Suppliers Regarding the Protection and Processing of Personal Data:
The Company ensures that the necessary documents are prepared for business partners and/or suppliers in order to increase awareness of preventing the unlawful processing of personal data, unlawful access to data and ensuring the preservation of data. In addition, mutual awareness is ensured by signing confidentiality commitments.

SECTION 4
ISSUES RELATED TO THE PROCESSING OF PERSONAL DATA
One of the issues that is of primary importance for the Company is to act in accordance with the general principles stipulated in the legislation in the processing of personal data. In this context, the Company acts in accordance with the principles listed below in the processing of personal data in accordance with the Constitution and the Personal Data Protection Law.

4.1. Processing of Personal Data in Accordance with the Principles Stipulated in the Legislation
4.1.1. Carrying out Personal Data Processing Activities in Accordance with Law and the Rule of Integrity
In accordance with Article 4 of the Personal Data Protection Law, the Company carries out personal data processing activities in accordance with the law and the rules of honesty; accurately and up-to-date when necessary; for specific, clear and legitimate purposes; and in a purpose-related, limited and proportionate manner.
In this context, the Company takes into account the requirements of proportionality in the processing of personal data and does not use personal data other than as required for the purpose.

4.1.2. Ensuring Personal Data is Accurate and Up-to-Date Where Necessary
Necessary measures are taken in data processing procedures to ensure that the processed data is accurate and up-to-date, and the Data Subject is provided with the opportunity to update their data and to correct any errors in their processed data, if any.

4.1.3. Processing for Specified, Clear and Legitimate Purposes
Personal data is processed in a limited and proportionate manner, in connection with clearly and precisely determined purposes. Personal data that is not relevant or does not need to be processed is avoided. Therefore, unless there is a legal requirement, we do not process special personal data, or when we need to process it, we provide information on the subject and obtain explicit consent.

4.1.4. Being Relevant, Limited and Proportionate to the Purpose of Processing
Personal data is processed in a limited and proportionate manner, in connection with clearly and precisely determined purposes. Personal data that is not relevant or does not need to be processed is avoided. Therefore, unless there is a legal requirement, we do not process special personal data, or when we need to process it, we provide information on the subject and obtain explicit consent.

4.1.5. Storage for the Period Stipulated in the Relevant Legislation or Necessary for the Purpose for which they are Processed
In accordance with Article 138 of the Turkish Penal Code and Articles 4 and 7 of the Personal Data Protection Law, the Company retains the personal data it processes only for the period stipulated in the relevant legislation and laws or required for the purpose of processing personal data.

In this context, the Company first determines whether a period is stipulated in the relevant legislation for the storage of personal data, and if a period is specified, it acts in accordance with this period. If there is no legal period, personal data is stored for the period necessary for the purpose for which it is processed. At the end of the specified storage periods, personal data is destroyed in accordance with the periodic destruction periods or the application of the Relevant Person and with the specified destruction methods (deletion and/or destruction and/or anonymization).

Details are specified in the Personal Data Storage and Destruction Policy.
4.2.Conditions for Processing Personal Data
Unless the personal data owner gives explicit consent, the basis for personal data processing may be only one of the conditions specified below, or more than one condition may be the basis for the same personal data processing activity. If the processed data is special personal data, the conditions set forth in heading 4.3 (“Processing of Special Personal Data”) of this Policy shall apply.

I. Explicitly Provided in Laws
If the personal data of the relevant Person is clearly stipulated in the law, in other words, if there is a clear provision in the relevant law regarding the processing of personal data, the existence of this data processing condition can be mentioned.

II. Failure to Obtain the Explicit Consent of the Person Concerned Due to Actual Impossibility
If the processing of personal data is necessary to protect the life or physical integrity of the person or another person who is unable to give his/her consent due to a de facto impossibility or whose consent cannot be validated, the personal data of the Relevant Person may be processed.

III. Direct Interest in the Establishment or Performance of the Contract
This condition may be deemed to be fulfilled if the processing of personal data is necessary, provided that it is directly related to the establishment or performance of a contract to which the Data Subject is a party.

IV. Fulfillment of Legal Obligations by the Data Controller
If processing is necessary for the Company to fulfill its legal obligations, the Personal Data of the Relevant Person may be processed.

V. Publication of Personal Data by the Personal Data Subject
If the Data Subject has made his/her personal data public, the relevant personal data may be processed limitedly for the purpose of making it public.

VI. Data Processing is Necessary for the Establishment or Protection of a Right
If data processing is necessary for the establishment, exercise or protection of a right, the personal data of the Relevant Person may be processed.

VII. Data Processing is Necessary for the Legitimate Interest of the Data Controller
Personal data of the Data Subject may be processed if data processing is mandatory for the legitimate interests of the Company, provided that it does not harm the fundamental rights and freedoms of the Data Subject.

4.3-Processing of Special Personal Data
The Company shows special sensitivity in the processing of special personal data, the protection of which is believed to be of more critical importance to the Relevant Person in various respects. Special personal data is processed by our Company in accordance with the principles set forth in this Policy and by taking all necessary administrative and technical measures, including the methods to be determined by the Board, and in the presence of the following conditions:
(i) Special personal data other than health and sexual life may be processed without the explicit consent of the data owner if it is clearly provided for in the laws, in other words, if there is an explicit provision regarding the processing of personal data in the law governing the relevant activity. Otherwise, the explicit consent of the data owner will be obtained for the processing of such special personal data.
(ii) Special personal data related to health and sexual life may be processed without the explicit consent of persons or authorized institutions and organizations under the obligation of confidentiality for the purposes of protecting public health, conducting preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and their financing. Otherwise, the explicit consent of the data owner will be obtained for the processing of such special personal data.

4.3.1 Measures Regarding the Protection of Special Personal Data
In the processing of Special Personal Data, as stipulated in Article 6 of the Law, the Company takes the following measures as the data controller in accordance with the Board’s decision dated 31.01.2018 and numbered 2018/10:
A- A systematic, clearly defined, manageable and sustainable separate policy has been determined for the security of special personal data,

B- For the Employees involved in the processing of special personal data;
• Regular training is provided on the Law and related regulations and Special Personal Data security,
• Confidentiality agreements are made,
• The scope and duration of authorization of users authorized to access data are clearly defined,
• Authorization checks are carried out periodically,
• The authorizations of Employees who change their duties or leave their jobs are immediately revoked in this area. In this context, the Data Controller receives the inventory allocated to it back

C- If the environments where Special Personal Data is processed, stored and/or accessed are electronic media,
• Personal Data is stored using cryptographic methods,
• Transaction records of all movements performed on Personal Data are securely logged,

D- If the environments where Special Personal Data is processed, stored and/or accessed are physical media;
• Adequate security measures (against electrical leakage, fire, flood, theft, etc.) are taken according to the nature of the environment where Special Personal Data is located, The physical security of these environments is ensured and unauthorized entry and exit are prevented.
If E-Special Personal Data is to be transferred,
• If Personal Data needs to be transferred via e-mail, it is transferred encrypted with a corporate e-mail address or using a Registered Electronic Mail (KEP) account,
• If it needs to be transferred via media such as Portable Memory, CD, DVD, it is encrypted with cryptographic methods and the cryptographic key is kept in a different medium,
• If Personal Data needs to be transferred via paper, necessary precautions are taken against risks such as theft, loss or unauthorized persons viewing the document and the document is sent in “Confidential” format.
In addition to the above-mentioned precautions, technical and administrative measures are also taken to ensure the appropriate level of security specified in the Personal Data Security Guide published on the Personal Data Protection Authority’s website.

4.4. Information to the Personal Data Owner
The Company informs personal data owners in accordance with Article 10 of the Law and secondary legislation. In this context, the Company informs the relevant persons as the data controller about who processes personal data, for what purposes, with whom it is shared and for what purposes, by what methods it is collected and the legal reason, and the rights of data owners within the scope of processing their personal data.

4.5.Transfer of Personal Data
The Company acts in accordance with the decisions and regulations stipulated in the LPPD and taken by the KVK Board regarding the transfer of personal data. Our Company may transfer the personal data and special personal data of the Relevant Person to third parties (official and private authorities, third real persons) by taking the necessary security measures in line with the purposes of processing personal data in accordance with the law. In this regard, the Company acts in accordance with the regulations stipulated in Article 8 of the Law. In the event of groups of persons with whom personal data is/may be shared, the relevant person is informed with an information text.

4.5.1 Transfer of Personal Data
Even if the personal data owner does not have explicit consent, if one or more of the conditions specified below are present, personal data may be transferred to third parties by our Company, taking due care and taking all necessary security measures, including the methods prescribed by the Board.

• The relevant activities regarding the transfer of personal data are clearly prescribed by law,
• The transfer of personal data by the Company is directly related to and necessary for the establishment or execution of a contract,
• The transfer of personal data is mandatory for our Company to fulfill its legal obligation,
• The transfer of personal data by our Company is limited to the purpose of publicization, provided that the personal data has been made public by the data owner,
• The transfer of personal data by the Company is mandatory for the establishment, exercise or protection of the rights of the Company or the data owner or third parties,
• It is mandatory to carry out personal data transfer activities for the Company’s legitimate interests, provided that it does not harm the fundamental rights and freedoms of the data owner,
• It is mandatory for the person who is unable to express his/her consent due to actual impossibility or whose consent is not legally valid to protect his/her own life or physical integrity or that of another person.
In addition to the above, personal data may be transferred to foreign countries declared by the Board to have sufficient protection (“Foreign Country with Sufficient Protection”) if any of the above conditions are met. In the absence of sufficient protection, data may be transferred to foreign countries where the data controllers in Turkey and the relevant foreign country have undertaken to provide sufficient protection in writing and where the Board has granted its permission (“Foreign Country Where the Data Controller Undertakes to Provide Sufficient Protection”) in accordance with the data transfer conditions stipulated in the legislation.

4.5.2.Transfer of Special Personal Data:
Our company may transfer the Special Personal Data of the Relevant Person to third parties by taking the necessary administrative and technical measures in line with the data processing purposes, and the Special Personal Data of the Relevant Person, which it has obtained in accordance with the law. Accordingly, the Company may transfer the Special Personal Data to third parties if one of the processing conditions specified in the section above and the conditions below are present.
(i) Special personal data other than health and sexual life may be processed without the explicit consent of the data owner if it is clearly provided for in the laws, in other words, if there is an explicit provision in the relevant law regarding the processing of personal data. Otherwise, the explicit consent of the data owner will be obtained.
(ii) Special personal data related to health and sexual life may be processed without the explicit consent of persons or authorized institutions and organizations under the obligation of confidentiality for the purposes of protecting public health, conducting preventive medicine, medical diagnosis, treatment and care services, planning and managing health services and their financing. Otherwise, the explicit consent of the data owner will be obtained.
In addition to the above, personal data may be transferred to Foreign Countries with Sufficient Protection if any of the above conditions are present. If there is no adequate protection, the data may be transferred to Foreign Countries Where the Data Controller Undertakes to Provide Adequate Protection, in accordance with the data transfer conditions stipulated in the legislation.

SECTION 5
STORAGE AND DESTRUCTION OF PERSONAL DATA
Our Company stores personal data in accordance with the period required for the purpose for which they are processed and the minimum periods stipulated in the legal legislation applicable to the relevant activity. In this context, our Company first determines whether a period is stipulated in the relevant legislation for the storage of personal data, and if a period is specified, it acts in accordance with this period. If there is no legal period, personal data is stored for the period required for the purpose for which they are processed. At the end of the specified storage periods, personal data is destroyed in accordance with the periodic destruction periods or the application of the data owner and with the specified destruction methods (deletion and/or destruction and/or anonymization).

SECTION 6
RIGHTS OF PERSONAL DATA OWNERS AND EXERCISE OF THESE RIGHTS
6.1. Rights of the Personal Data Owner
Within the scope of the obligation to inform, the relevant person is informed by the company and the systems and infrastructures related to this information are established. The technical and administrative arrangements necessary for the relevant person to exercise his/her rights regarding his/her personal data are made by our company.
The relevant person has the right to;
• Learn whether personal data is processed,
• Request information if personal data is processed,
• Learn the purpose of processing personal data and whether it is used in accordance with its purpose,
• Know the third parties to whom personal data is transferred domestically or abroad,
• Request correction of personal data if it is processed incompletely or incorrectly,
• Request deletion or destruction of personal data if the reasons requiring processing of personal data are eliminated,
• Request notification of the correction, deletion or destruction processes mentioned above to third parties to whom personal data is transferred,
• Object to an adverse result arising from the analysis of processed data exclusively through automated systems,
• Request compensation for damages in the event of damages incurred due to unlawful processing of personal data.

6.2. Personal Data Owner’s Exercise of Rights
Relevant Persons may exercise their rights listed above by submitting their requests through the Relevant Person application form available at kirlioglu.com.tr. Detailed information on filling out the form or sending it to the Company is included in this form.

6.3. Our Company’s Response to Applications
Our Company takes the necessary administrative and technical measures to finalize applications made by personal data owners in accordance with the Law and secondary legislation. If the personal data owner submits his/her request regarding the rights set forth in section 6.1 (“Rights of Personal Data Owners”) to our Company in accordance with the procedure, our Company will finalize the relevant request free of charge as soon as possible and within 30 (thirty) days at the latest, depending on the nature of the request. However, if the transaction requires an additional cost, a fee may be charged in accordance with the tariff determined by the Board.

6.4. Cases in Which the Data Subject Cannot Claim His/Her Rights
Pursuant to Article 28/2 of the LPPD, except for the right to request compensation for damages, it will not be possible for the relevant persons to benefit from the rights specified in Article 11 of the Law in the following cases;
• Personal data processing is necessary for the prevention of crime or criminal investigation,
• Personal data that has been made public by the relevant person.
• Personal data processing is necessary for the performance of supervisory or regulatory duties and disciplinary investigation or prosecution by authorized public institutions and organizations and professional organizations with the status of public institution, based on the authority granted by the law.
• Personal data processing is necessary for the protection of the economic and financial interests of the State in relation to budget, tax and financial matters.

 

SECTION 7
SPECIAL CASES WHERE PERSONAL DATA IS PROCESSED
7.1. Camera Monitoring Activities Conducted at the Entrances and Inside the Company Buildings and Facilities
The Company carries out camera monitoring activities in accordance with the Law on Private Security Services and relevant legislation in order to ensure security in its buildings and facilities. The Company carries out security camera monitoring activities in accordance with the purposes stipulated in the relevant legislation in force and the personal data processing conditions listed in the Law in order to ensure security in its buildings and facilities.
In accordance with Article 10 of the Law, the Company informs the personal data owner with more than one method regarding camera monitoring activities. In addition, the Company processes personal data in a limited and proportionate manner in connection with the purpose for which they are processed in accordance with Article 4 of the Law.
The purpose of the Company’s video camera monitoring activities is limited to the purposes listed in this Policy. Accordingly, the monitoring areas, numbers and when monitoring will be carried out by security cameras are implemented in a sufficient and limited manner to achieve the security purpose. Only a limited number of employees have access to live camera images and records recorded and stored in a digital environment. The limited number of people who have access to the records declare that they will protect the confidentiality of the data they access with a confidentiality commitment.

7.2. Monitoring of Guest Entrances and Exits at and Inside Company Buildings and Facilities

The Company carries out personal data processing activities to monitor guest entries and exits in Company buildings and facilities for the purposes of ensuring security and as specified in this Policy. While obtaining the names and surnames of persons visiting Company buildings as guests or through texts hung at the Company or made accessible to guests in other ways, the owners of the personal data in question are informed in this context. The data obtained for the purpose of monitoring guest entries and exits are processed only for this purpose and the relevant personal data is recorded in the data recording system in a physical environment.

7.3.Website Visitors
Cookie records are used to improve the operation and use of the company’s official website. The aim is to make the time spent on the company’s official website more efficient and enjoyable. In addition, some cookies are used to remember preferences made on the website, thus providing users with an improved and personalized experience. Personal data is collected through cookies on the website, and the collected data can be processed, transferred and stored. For detailed information about the cookies used on the website, you can review the Cookie Policy on the official website.

SECTION 8
LIABILITIES REGARDING PERSONAL DATA PROCESSING ACTIVITIES
Our company must comply with the obligations set forth by the Personal Data Protection Law for data controllers. The main issues we are obliged to comply with in this context are listed below:8.1. Obligation to Register and Notify the Data Controllers Registry
Our Company is obliged to register with the Data Controllers Registry in accordance with Article 16 of the Personal Data Protection Law and the procedures and principles of the Regulation on the Data Controllers Registry, and the said obligation has been fulfilled by our Company.

8.2. Obligation to Inform the Data Owner
When the company collects personal data; first of all, the relevant persons are clearly informed and enlightened in accordance with Article 10 of the LPPD and the Communiqué on the Procedures and Principles to be Complied with in Fulfilling the Obligation to Inform. In our disclosure texts;
• The company’s title, full address and contact information,
• Information on the representative identity, if any,
• Personal data categories,
• For what purpose personal data will be processed,
• To whom and for what purpose processed personal data can be transferred,
• Data collection method and legal reason,
• The rights of the relevant person listed in Article 11 of the LPPD, are included as subheadings and contents. In addition to the information provided above, application methods are also listed in our disclosure text. With these methods, it is aimed to be transparent and accessible in the Protection of Personal Data.
As a company, we take care to ensure that this Policy, which is open to the public, is clear, understandable and easily accessible. In addition, the “Information Texts” regarding the Personal Data Protection Law for employees, job candidates, visitors, customers and camera systems can be reviewed on the company’s website.

8.3. Obligation to Ensure the Security of Personal Data
The Company is obliged to take all necessary technical and administrative measures to ensure the appropriate level of security in order to;
1. Prevent the unlawful processing of personal data,
2. Prevent unlawful access to personal data, and
3. Ensure the preservation of personal data, with the awareness of the importance of ensuring the security of personal data and the fundamental rights and freedoms of data owners, in accordance with Article 12 of the Personal Data Protection Law.
Aware of the importance of ensuring security in every respect within the Company, the Company takes the necessary technical and administrative measures to prevent the unlawful processing of personal data it processes, to prevent unlawful access to data and to ensure the preservation of data, in accordance with Article 12 of the Personal Data Protection Law, and to ensure the appropriate level of security, and the necessary inspections are carried out within this scope. The Company takes the necessary technical and administrative measures, within the technological possibilities, to ensure the lawful processing of personal data. The measures taken by our Company within this scope are as follows:

8.3.1. Administrative Measures
• Information Texts (Employee, Employee Candidate, Customer, Camera Systems, Covid-19 Outbreak Process) and Explicit Consent Texts have been prepared.
• Disciplinary regulations that include data security provisions are in place for employees.

• Training and awareness activities are carried out at certain intervals for employees on data security.
• Department access authorizations have been regulated.
• Training has been provided to the department to protect certain personal data.
• Confidentiality commitments have been made.
• Disciplinary regulations to be applied to employees who do not comply with security policies and procedures have been prepared.
• Signed contracts include data security provisions.
• Layered camera information texts have been hung in the areas where cameras are located.
• Employees have been informed about the technical and administrative risks related to the storage of personal data and awareness has been raised.
• A personal data processing inventory has been prepared.• Personal Data Protection Committee has been established.
• Personal data security policies and procedures have been determined.
• Personal data security issues are reported quickly.
• Personal data security is monitored.
• Necessary security measures are taken regarding entry and exit to physical environments containing personal data.
• Security of physical environments containing personal data is ensured against external risks (fire, flood, etc.).
• Security of environments containing personal data is ensured.
• Personal data is reduced as much as possible.
Protocols and procedures for special personal data security have been determined and implemented.
• Personnel duty and title lists have been prepared.
• Contracts have been made compatible with LPPD.

8.3.2. Technical Measures
• The company employs knowledgeable and experienced people to ensure data security and provides its personnel with the necessary training on the protection of personal data.
• Necessary internal controls are carried out within the scope of the established systems.
• Network security and application security are provided.
• An authorization matrix has been created for employees.
• Access logs are kept regularly.
• Corporate policies have been prepared and implemented on access, information security, usage, storage and destruction.
• Data masking measures are implemented when necessary.
• Authorizations of employees who change their duties or leave their jobs are revoked in this area.
• Up-to-date anti-virus systems are used.
• Personal data is backed up and the security of backed up personal data is also ensured.
• Periodic and/or random audits are carried out and carried out within the institution.
• Log records are kept in a way that prevents user intervention.
• Existing risks and threats have been determined.
• Data of special persons transferred on portable memory, CD, DVD are encrypted.
• Data processing service providers are audited at certain intervals regarding data security.
• Awareness of data processing service providers regarding data security is ensured.

8.4. Obligation to Fulfill Decisions Made by the KVK Board
The Company acts in accordance with the decisions made by the KVK Board, which is the executive body of the KVK Institution and operates to ensure that personal data is processed in accordance with fundamental rights and freedoms.

8.5. Obligation to Respond to Data Owner Applications
The Company, as the data controller, finalizes the requests of data owners regarding their personal data in accordance with Article 13 of the Personal Data Protection Law, as soon as possible and within thirty (30) days at the latest, depending on the nature of the request. Data owners must make their requests regarding their personal data in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller.

8.6. Obligation to Erase, Destroy and Anonymize Personal Data:
If all the processing conditions of personal data specified in Articles 5 and 6 of the LPPD are eliminated, personal data must be erased, destroyed or anonymized by the data controller ex officio or upon the request of the relevant person. In the erasure, destruction or anonymization of personal data, it is mandatory to act in accordance with the general principles in Article 4 of the Law and the technical and administrative measures to be taken within the scope of Article 12, the relevant legislative provisions, Board decisions and the personal data storage and destruction policy. The data controller is obliged to explain the methods it applies regarding the deletion, destruction and anonymization of personal data in its relevant policies and procedures. In accordance with Article 7 of the Regulation on the Erasure, Destroy or Anonymization of Personal Data mentioned above, the company has also established a Storage and Destruction Policy.

8.6.1 Conditions for Deletion, Destruction and Anonymization of Personal Data:
According to Article 138 of the Turkish Penal Code, Article 7 of the Personal Data Protection Law and the “Regulation on Deletion, Destruction and Anonymization of Personal Data”, personal data shall be deleted, destroyed or anonymized upon the company’s own decision or upon the request of the relevant person, in case the reasons requiring processing are eliminated, despite being processed in accordance with the provisions of the relevant law. The company has established a policy in this regard in accordance with the provisions of the regulation, and the destruction process is carried out according to the nature of the data in accordance with this policy. Periodic destruction dates have been determined by the company in accordance with this regulation, and a calendar has been created according to which periodic destruction will be carried out at various intervals with the commencement of the obligation.

 

SECTION 9
9.1. Implementatıon Of The Polıcy And Related Legıslatıon
The relevant legal regulations on the deletion and protection of personal data will primarily find their area of application. If there is a discrepancy between the current legislation and the Policy, the Policy accepts to find the area of application of the current legislation. The Policy is organized by concretizing the rules set forth by the relevant legislation within the scope of Company practices.

9.2. Enforcement Of The Polıcy
The effective date of this Policy is 09/01/2024. This Policy is published on the Company’s website, kırlıoğlu.com.tr, and made accessible to relevant persons upon the request of personal data owners.

9.3. Dıstrıbutıon
The Policy is published on the Company’s website and announced to third parties and Company employees.