1. CHAPTER: INTRODUCTION

 

  1. IMPORTANCE OF PROTECTION OF PERSONAL DATA

The protection of personal data is a constitutional right and is within the scope of our Company's priorities. As a matter of fact, it is aimed to establish a system which is constantly updated in our Company and this policy has been established. Within the scope of the Personal Data Protection Law No. 6698, this Policy is made in order to fulfill the general disclosure obligation of HAUS Centrifuge Tech. (Company) as Data Responsible and to determine the basic principles of our Company's personal data processing rules and in this context, the protection of the personal data of our customers, potential customers, employees, employee candidates, trainees and students, supplier / subcontractor employees and authorities, company shareholders and company partners, visitors and other data we process.

To implement the issues specified in this Policy, necessary procedures are organized within the Company enlightening texts are created compatible with Personal Data Processing Inventory specific to person categories, personal data protection and confidentiality agreements are made with Company employees and third parties that have access to personal data, job descriptions are revised, for the protection of personal data, administrative and technical measures are taken by HAUS Centrifuge Tech. and in this context, necessary evaluations performed or being performed. The protection of personal data is also under the responsibility of the top management, and the protection of personal data is managed through the establishment of a special Committee (the Company's PDP Committee).

The main purpose of this Policy is to establish the principles of personal data processing and protection of personal data, which are carried out by HAUS Centrifuge Tech. in accordance with the law, and to ensure transparency by informing and informing the persons whose personal data is processed by our company.

This Policy relates to all personal data of individuals categorized under the titles of “our customers, potential customers, employees, employee candidates, trainees and students, supplier / subcontractor employees and officials, company shareholders and company partners, visitors, parents / guardian / representative and other third parties” that we process in an automated or non-automated manner provided that they are part of any data recording system.

  1. IMPLEMENTATION OF POLICY AND RELATED LEGISLATION

The relevant legal regulations in force regarding the processing and protection of personal data will primarily be applied. In case of any inconsistency between the current legislation and the Policy, our Company accepts that the current legislation will find its application.

  1. ACCESS AND UPDATE

Policy is published on our Company's website www.haus.com.tr and made available to the relevant persons upon request of the personal data owners and updated as necessary.

  1. CHAPTER: PROCESSING PERSONAL DATA

Our Company, in the processing of personal data, conducts personal data processing proper with the law and the rules of honesty, accurate and up to date when necessary; for specific, clear and legitimate purposes; in a limited and measured manner, in accordance with Article 20 of the Constitution and Article 4 of the PDP Law. Our Company stores personal data for the period required by law or for the purpose of personal data processing.

Our Company processes personal data in accordance with Articles 20 of the Constitution and 5 of the PDP Law and based on one or more of the provisions of Article 5 of the PDP Law on the processing of personal data.

Pursuant to Article 419 of the Code of Obligations, our Company processes the personal data of employees and prospective employees based on their tendency to work and the performance of the employment contract reserving PDP Law No.6698.

Our Company enlightens personal data owners in accordance with Articles 20 and 10 of the PDP Law and provides the necessary information if personal data owners request information and apply to use their rights arising from the law and responds to the applications within the legal period.

Our company acts in accordance with the regulations envisaged for the processing of private personal data in accordance with Article 6 of the PDP Law.

Our Company complies with the rules stipulated in the Law on the transfer of personal data in accordance with Articles 8 and 9 of the PDP Law and performs the application by taking into consideration the decisions taken and published by the PDP Board and the safe country lists.

  1. Principles of Processing of Personal Data
  1. Processing in Accordance with Law and Honesty Rule

Our company; acts in accordance with the principles brought by legal regulations and honesty in the processing of personal data. In this context, our Company identifies legal grounds that will require the processing of personal data, takes into account the requirements of proportionality, does not use personal data outside of the intended purpose and does not perform any processing without the knowledge of the persons.

  1. Ensuring That Personal Data Is Accurate and Up to Date When Necessary

Our company; considering the fundamental rights of the personal data owners and their legitimate interests, it ensures that the personal data it processes are accurate and up-to-date and takes necessary measures in this direction. In this context, data on all categories of people are kept up to date. In particular, customer and potential customer data are carefully updated and e-mails and offers are not sent to individuals for marketing and promotional purposes contrary to their consent.

  1. Processing for Specific, Clear and Legitimate Purposes

Our company clearly and accurately determines the purpose of processing legitimate and lawful personal data. Our company processes personal data in connection with the service it provides and processes it as necessary. The purpose of the processing of personal data is determined by our company before the processing activity and is also recorded in the “Personal Data Inventory”.

  1. Being Affiliated, Limited and Restrained on The Purpose of Processing

Our Company processes the use of personal data in an appropriate manner and avoids the processing of personal use that is not or is not required to achieve the purpose. In this context, processes are constantly reviewed and the principle of minimalization of personal data is tried to be implemented.

  1. Retention Time Required By The Relevant Legislation or For The Purpose For Which It Was Processed

Our Company maintains personal data only for the period required for the purpose specified in the relevant legislation or processed. In this context, our Company first determines whether a period is stipulated in the relevant legislation for the storage of personal data, if a period is determined, acts in accordance with this period, takes into account the statutory limitation periods and stores the personal data for the time required for the purpose for which they were processed. If the reasons for expiration or elimination of personal data are eliminated, personal data is deleted, destroyed or anonymized in accordance with our Company's “Storage and Deletion of Personal Data” policy.

  1. Rules for the Processing of General Personal Data

Protection of personal data is a constitutional right, and fundamental rights and freedoms may be restricted only by law, without being touched by the substance of the Constitution, solely for the reasons specified in the relevant articles of the Constitution. Pursuant to the third paragraph of Article 20 of the Constitution, personal data may be processed only in cases provided for by law or with the express consent of the person. In the processing of personal data, our company only processes personal data without the express consent of the person concerned if there are any of the following conditions;

  1. Explicitly stated in the law,
  2. It is to be compulsory for the protection of the life or body integrity of the person who is unable to disclose his consent due to the impossibility of the person or whose consent is not granted legal validity,
  3. If the processing of personal data of the parties to the contract is required, provided that it is directly related to the establishment or performance of a contract,

Ç) Obligation for the data responsible to fulfill his legal obligation,

  1. Publication by the person concerned,
  2. Data processing is mandatory for the establishment, use or protection of a right,
  3. If data is compulsory for the legitimate interests of the data responsible, provided that they do not harm the fundamental rights and freedoms of the person concerned

In the absence of the above conditions, our Company uses the consent of the person concerned based on open, free will and information. Especially in the field of Human Resources and labor relations, taking into consideration the dependency relationship of the employee, the data is primarily based on the reasons for compliance with the law which is not consented, but in the absence of such reasons, explicit consent is applied. On the other hand, processing activities are carried out based on the consent of the person concerned in activities such as marketing. However, in all cases where personal data is processed, people are always “enlightened” and data processing is carried out.

  1. Rules for the Processing of Private Personal Data

The Company complies with the regulations stipulated in the PDP Law for the processing of personal data designated as “private category by the PDP Law. In Article 6 of the PDP Law, several personal data that are at risk of causing exploitation or discrimination of persons when processed unlawfully are identified as “private category” and attention and sensitivity should be paid to the processing of such data. These include data on race, ethnicity, political thought, philosophical belief, religion, sect or other beliefs, disguise and dress, association, foundation or union membership, health, sexual life, criminal convictions, and security measures, and biometric and genetic data. Pursuant to the KVK Law, personal data are processed by our Company in the following cases provided that the necessary precautions are taken:

ü Personal data, other than the health and sexual life of the personal data owner, are based on the circumstances provided for by law or if the personal data owner has explicit consent,

üPersonal data relating to the health and sexual life of the personal data owner may only be used by persons or authorized institutions who are under the obligation of secrecy for the purpose of protection of public are processed by organizations or with the express consent of the personal data owner.

ü Regardless of the reason, the general data processing principles are always considered in the processing processes and compliance with these principles is ensured. (Art. 4 of the KVK Law; see Chapter 2 above, I, 1.

As regards the protection of private data, the “Protection of Private Data Policy” has been put into effect in our company, and our business units act in accordance with the provisions of this policy and take the necessary measures.

  1. Enlightening and Informing Related Persons Whose Data Processed

In accordance with Article 10 of the PDP Law, our Company informs the owners of personal data during the acquisition of personal data. In this context, the purpose of the processing personal data of the relevant person, the processed personal data can be transferred to whom and for what purpose, the method of collecting personal data and legal reasons and the rights of the person whose personal data is processed are explained and The relevant units of our Company fulfill the required procedures in accordance with our Company's “Enlightening Principles Policy”. Again, in Article 11 of the PDP Law, “Requesting Information” is listed among the rights of the person whose personal data is processed and in accordance with Articles 20 of the Constitution and Article 11 of the PDP Law, our Company provides the necessary information if the person whose personal data is processed requests information and in this respect, the Company performs transactions in accordance with the "Concerned Person Application Procedure".

Our company can transfer the personal data of the person whose personal data is processed to the third parties by taking necessary security measures in accordance with the legal data processing purposes. In this respect, our company acts in accordance with the regulations stipulated in article 8 of the PDP Law.

  1. Principles of Transferring Personal Data

For legitimate and lawful personal data processing purposes, our Company may transfer personal data to third parties based on one or more of the personal data processing conditions set out in Article 5 of the Law following:

If the person whose personal data is processed has explicit consent, based upon this; or

 

Regardless of the reason, the general principles of data processing are always considered in the transfer processes and compliance with these principles is ensured. (Article 4 of the PDP Law; see Chapter 2 above, I, 1).

  1. Transfer of Private Personal Data

Our company is able to transfer the personal data of the person concerned whose private personal data is processed to third parties for legitimate and lawful personal data processing purposes in the following cases with due diligence, taking necessary security measures, Taking adequate measures foreseen by the PDP Board.

Regardless of the reason, the general principles of data processing are always considered in the transfer processes and compliance with these principles is ensured. (Article 4 of the KVK Law; see Chapter 2 above, I, 1).

  1. Transferring Personal Data Abroad

Our company is able to transfer the personal data and private personal data it processes to third parties by taking the necessary security measures in accordance with the legal personal data processing purposes. Personal data  could be transferred by our company to foreign countries (Foreign Country with Adequate Protection ”) that have been declared by PDP Board to be sufficient in having protection  or in case of the lack of adequate protection if an adequate protection committed in writing by data responsible  in Turkey and in the foreign countries (Foreign Country in which the Data Responsible is Committed to Adequate Protection ”) where had the PDP Board's permission.

For the purposes of legitimate and lawful personal data processing, if the person whose personal data is processed has explicit consent or does not have explicit consent, our Company may transfer the personal data to the Foreign Countries where has the Adequate Protection or the Data Responsible Committed to Sufficient Protection in the presence of one of the following situations:

  1. Purposes of Transferring Personal Data by Our Company and Person Whose Data Transferred Categories
  1. Data Transfer Objectives

Data transfer is carried out for the purposes such as ensuring the fulfillment of the objectives of our company's activities and organizations, ensuring that the services provided by our Company from the supplier outsourced and necessary for carrying out the commercial activities of our Company are provided to our Company, ensuring the execution of human resources and employment policies of our company, ensuring the fulfillment of the obligations and the necessary measures to be taken within the framework of occupational health and safety of our company.

  1. The Persons to Whom Data Transferred

In accordance with Articles 8 and 9 of the PDP Law, personal data can be transferred to the following categories of persons:

AUTHORIZED PUBLIC INSTITUTIONS

Public institutions and organizations authorized to receive information and documents from our company

Data is shared according to the relevant legislation.

AUTHORIZED PRIVATE LAW PERSON

Private law persons authorized to receive information and documents from our company

There is limited data sharing for the purpose requested by the relevant private law persons within the legal authority.

SUBSIDIARIES

Companies in which our company is a shareholder

Data sharing is limited in order to ensure the conduct of commercial activities of our Company which require the participation of subsidiaries.

SHAREHOLDER

Shareholders of the Company

Data sharing is limited for the purpose of designing strategies for the commercial activities of our Company and for evaluation purposes.

BUSSINESS PARTNERS

The parties that the Company establishes business partnerships for the purposes of sales, promotion and marketing of our company's products and services, after-sales support, and the execution of joint customer loyalty programs while conducting commercial activities of our company.

Data sharing is limited in order to ensure that the business partnership aims to be established.

SUPPLIER

Our company's commercial activities

Data sharing is limited in order to provide the necessary services for the Company to carry out its commercial activities provided by outsourcing of the Company from the supplier.

GROUP COMPANIES UNDER OUR SUBSIDIARY

Inside Our Company's subsidiary or group

In order to conduct commercial activities of our company, data is shared with our subsidiary in a limited and measured manner.
Personal data is shared due to the operational processes and support processes carried out together, and data is shared with other group companies in a limited and limited manner in order to conduct commercial activities of our Company.

Transactions made by our Company are in compliance with the principles and rules set forth in this Policy.

Persons whose data are processed in our company and the data processed within this scope are categorized as follows;

PERSON CATEGORIZATION

EMPLOYEE CANDIDATE

Real persons who have applied for a job in any way or have opened their CV and relevant information for review.

EMPLOYEE

Real persons working in our company

SHAREHOLDERS / PARTNERS

Real persons who are shareholders and partners of our company

POTENTIAL CUSTOMER

Natural persons who have requested or are interested in the use of our products and services or have been assessed in accordance with the rules of commercial custom and honesty to which they may have interest

INTERN /STUDENT

Persons who do internships in our company and who work under the Law on Vocational Training of Employees (VTEL)

SUPPLIER EMPLOYEES

Real persons who work in organizations (such as, but not limited to, business partners, suppliers) with which our Company has business relations

SUPPLIER AUTHORIZATION

Real persons in Our company's business relationship with the institutions' shareholders and officials

CLIENT

Real persons who use or have used the products and services offered by our Company, regardless of whether they have any contractual relationship with our Company

CUSTODIAN / GUARDIAN / REPRESENTATIVE

Real persons whose personal data are processed as custodians, guardians or representatives.

VISITOR

Real persons who have entered the physical campus of our Company for various purposes or who have visited our websites

MISCELLANIOUS

Third party real persons (eg family members and relatives) associated with the Company in order to ensure the security of commercial transactions with the above-mentioned parties or to protect the rights and interests of such persons.

DATA CATEGORIZATION

The ID INFO which is processed partially or fully automated or non-automated processing as part of the data recording system and obvious that it belongs to an identified or identifiable real person; Information on documents such as driver's license, identity card, residence, passport, attorney ID, marriage certificate

The COMMUNICATION INFO which is processed partially or fully automated or non-automated processing as part of the data recording system and obvious that it belongs to an identified or identifiable real person; phone number, address, e-mail

LOCATION INFO

The INFO which is processed partially or fully automated or non-automated processing as part of the data recording system and obvious that it belongs to an identified or identifiable real person; such an information that identifies the location of the employee's use of our products and services, or the location of employees of organizations with whom we collaborate with our employees while using our Company's vehicles

PERSONNEL FILE

The INFO which is processed partially or fully automated or non-automated processing as part of the data recording system and obvious that it belongs to an identified or identifiable real person; such any personal data that is processed to obtain information that will constitute the basis for the personal rights of our employees or real persons in working relationship with our Company.

LEGAL PROCESS AND COMPLIANCE INFORMATION

The INFO which is processed partially or fully automated or non-automated processing as part of the data recording system and obvious that it belongs to an identified or identifiable real person; such personal data processed within the scope of determination, follow-up of our legal receivables and rights and performance of our debts and compliance with our legal obligations and policies of our company

CUSTOMER TRANSACTION INFORMATION

It is evident that the identity belongs to a certain or identifiable real person and is contained within the data recording system; such information on the use of our products and services, as well as instructions and requests required by the customer for the use of the products and services

PHYSICAL SPACE SAFETY INFORMATION

It is evident that the identity belongs to a certain or identifiable real person and is contained within the data recording system; such personal data on records and documents received during entry into the physical space, during the stay in the physical space

OPERATIONAL SAFETY INFORMATION

It is evident that the identity belongs to a certain or identifiable real person and is contained within the data recording system; such personal data processed to ensure technical, administrative, legal and commercial security while conducting activities.

RISK MANAGEMENT INFORMATION

It is evident that the identity belongs to a certain or identifiable real person and is contained within the data recording system; such personal data processed in accordance with generally accepted legal, commercial custom and honesty rules in these areas in order to manage our commercial, technical and administrative risks

FINANCIAL INFORMATION

The INFO which is processed partially or fully automated or non-automated processing as part of the data recording system and obvious that it belongs to an identified or identifiable real person; such personal data regarding information, documents and records showing all kinds of financial results created according to the type of legal relationship established by our company's personal data owner

PERFORMANCE AND CAREER DEVELOPMENT KNOWLEDGE (PROFESSIONAL EXPERIENCE KNOWLEDGE)

The INFO which is processed partially or fully automated or non-automated processing as part of the data recording system and obvious that it belongs to an identified or identifiable real person; such personal data processed to measure the performance of our employees or real persons in working relationship with our Company and to plan and conduct career developments within the scope of our company's human resources policy

MARKETING INFORMATION

The INFO which is processed partially or fully automated or non-automated processing as part of the data recording system and obvious that it belongs to an identified or identifiable real person; personal data of our products and services in order to be customized and marketed according to the usage habits, tastes and needs of the personal data owner and the reports and evaluations created as a result of these processing results

VISUAL / AUDIO INFORMATION

The Personal Data which is processed partially or fully automated or non-automated processing as part of the data recording system and obvious that it belongs to an identified or identifiable real person; For example: photographs and camera recordings (except those included in the Physical Space Security Information), audio recordings and data contained in documents that are copies of documents containing personal data

PRIVATE DATA I

(HEALTH / SEXUAL LIFE)

Data on health and sexual life

PRIVATE DATA II

data on race, ethnicity, political thought, philosophical belief, religion, sect or other beliefs, disguise and dress, association, foundation or union membership, criminal conviction and security measures, and biometric and genetic data

  1. CHAPTER: LEGAL BASIS AND PURPOSES OF PROCESSING PERSONAL DATA

 

  1. LEGAL BASIS OF PROCESSING PERSONAL DATA

 

  1. General Principles

Although the legal basis for the processing of personal data varies by our company, all kinds of personal data processing activities are carried out in accordance with the general principles in article 4 of the Law No. 6698. According to this; all kinds of data processing

  1. Compliance with law and honesty,
  2. Accuracy and up to date when necessary,
  3. Processing for specific, clear and legitimate purposes,
  4. Being connected, limited and restrained for the purpose they are processed,
  5. e) The general principles of keeping for the period required for the purpose for which they are envisaged or processed are taken into consideration in the relevant legislation.
  1. Reasons for Compliance with Law

 

  1. Obtaining the Explicit Consent Of The Personal Data Owner

One of the conditions for the processing of personal data is the explicit consent of the owner. The explicit consent of the personal data owner should be disclosed on a particular subject, based on information and free will.

  1. Clearly Stated in Laws

The personal data of the data owner may be processed in accordance with the law if explicitly provided for in the law.

For example, reporting the identity of our employees to the competent authorities in accordance with the Identity Legislation.

  1. Failure to Obtain Explicit Consent of The Person Due to Actual Impossibility

Personal data of the data owner may be processed if it is necessary to process the personal data of the person who is unable to disclose his consent due to the actual impossibility or whose consent cannot be validated, or to protect the life or body integrity of another person. For example, sharing the blood group information of the fainted employee with the physician.

  1. Direct Interest in The Establishment or Execution of the Contract

Provided that it is directly related to the establishment or execution of a contract, it is possible to process personal data if it is necessary to process the personal data of the parties to the contract. For example, obtaining CVs from the candidate for the establishment of the employment contract, obtaining an address for notification within the scope of the contract.

  1. Fulfilling the Company's Legal Obligation

If it is compulsory for our company to fulfill its legal obligations as data responsible, personal data of the data owner may be processed. For example, the processing of family information to benefit the Employee from the Minimum Living Allowance.

  1. Publicization of Personal Data by Data Owner

If the data owner has publicized his/her personal data, the relevant personal data may be processed. For example, if our Company's customers present their complaints, requests or suggestions on a public platform on the internet, they publicize their relevant information. In this case, it is possible for the authorized person of our Company to process the data provided that it is limited to respond to complaints, requests or suggestions.

  1. G) Requiring Data Processing to Establish or Protect a Right

If it is necessary to process data for the establishment, use or protection of a right, the personal data of the data owner may be processed. For example, storage of proof data (sales contract, invoice) and use as needed.

  1. Obligation of Data Processing for the Legitimate Benefit of Our Company

Personal data of the data owner may be processed if it is compulsory for the legitimate interests of our Company to process data provided that it does not harm the fundamental rights and freedoms of the personal data owner. For example, monitoring the Company's critical points against theft or occupational safety with a security camera.

  1. Processing of Private Personal Data and Reasons for Compliance with Law

If the personal data owner does not have explicit consent, private personal data can only be processed by our company, provided that enough measures are taken by the PDP Board. Personal data relating to the health and sexual life of the personal data owner may be processed by persons who are obliged to keep confidential information or by authorized institutions and organizations only for the purpose of protection of public health, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and financing. Regardless of the reason, the general data processing principles are always considered in the processing processes and compliance with these principles is ensured (Article 4 of the PDP Law; see Chapter 2 above, I, 1).

Our Company processes personal data limited to the purposes and conditions within the personal data processing conditions specified in article 5, paragraph 2, and paragraph 6 of article 6 of the Personal Data Protection Law No. 6698. In the process of data processing, the legal basis mentioned above is taken into consideration and the consent of the person is requested if there are no other reasons for compliance with the law. Here too, general principles are audited under Article 4, and above all, data processing is generally required to comply with the principles of lawfulness. The consent of the person concerned is obtained in an "open, informative and free will" manner. The purposes of processing personal data are also stated in the “Personal Data Inventory” of our Company.

Personal data are processed in the units of our Company especially for the following purposes;

 

 

 

 

 

 

 

 

 

 

  1. CHAPTER: STORAGE, DELETION, DISPOSAL AND ANONIMIZATION OF PERSONAL DATA

Although our Company has processed in accordance with the provisions of the relevant law as provided for in Article 138 of the Turkish Penal Code and Article 7 of the PDP Law, personal data will be deleted upon the decision of our Company or upon the request of the personal data holder, in case the reasons that require it are eliminated or anonymous.

If required by the relevant laws and regulations, our Company stores its personal data for the period specified in the related legislation. If the legislation on how long personal data should be stored is not regulated for a period of time, personal data is processed, then deleted, destroyed or anonymized for the period required to be processed in accordance with the practices and commercial practices of our Company in connection with the services provided by our company while processing that data. If the purpose of processing personal data has expired and the storage period determined by the relevant legislation and the company has been reached; personal data may only be stored in order to provide evidence in case of possible legal disputes or to assert the relevant right to personal data or to establish defense. Although the statute of limitations and the statute of limitations for the exercise of the right mentioned in the establishment of these periods have passed, retention periods are determined based on the examples in the requests submitted to our Company on the same subjects. In this case, the stored personal data is not accessed for any other purpose and is only accessible when it is required to be used in the relevant legal dispute. Here too, after the expiry of this period, personal data is deleted, destroyed or anonymized.

Although it has been processed in accordance with the provisions of the relevant law as provided for in Article 138 of the Turkish Penal Code and Article 7 of the KVK Law, personal data are deleted, destroyed or anonymized upon the decision of our Company or upon the request of the personal data owner, in case the reasons requiring processing are eliminated. In this context, our Company fulfills its obligation with the methods explained in this section.

  1. Deleting Personal Data
  1. Deletion of Personal Data

Although our company has processed in accordance with the provisions of the relevant law, personal data may be deleted in accordance with its decision or upon the request of the personal data owner in case the reasons requiring processing are eliminated. Deletion of personal data is the process of making personal data inaccessible and reusable for the users concerned. Our Company takes all kinds of technical and administrative measures to ensure that deleted personal data cannot be accessed and reused for the relevant users.

  1. Process of Deleting Personal Data
  1. Methods for Deleting Personal Data

Since personal data can be stored in various recording media, it is deleted by appropriate methods.

  1. Disposal of Personal Data
  1. Personal Data Disposal Process

Although our company has processed in accordance with the provisions of the relevant law, personal data may be disposed in accordance with its decision or upon the request of the personal data owner in case the reasons requiring processing are eliminated. Disposal of personal data is the process by which personal data cannot be accessed, retrieved or reused by anyone in any way. Our company takes all kinds of technical and administrative measures necessary for the disposal of personal data.

  1. The Methods of Personal Data Disposal

For the disposal of personal data, all copies of the data are detected and the systems in which the data is found are destroyed individually.

  1. The Anonymization of Personal Data
  1. Personal Data Anonymization Process

The anonymization of personal data means that personal data cannot be associated with a certain or identifiable natural person, even by pairing it with other data. Our company is able to anonymize the personal data when the reasons that require the processing of personal data processed in accordance with the law are eliminated. Personal data is anonymized by making it unrelated to a specific or identifiable natural person, even through the use of appropriate techniques for the recording medium and the field of activity, such as the return of data by the data responsible or recipient groups and / or the mapping of data to other data. Our company takes all kinds of technical and administrative measures necessary to anonymize personal data.

Personal data, which has been anonymized in accordance with Article 28 of the PDP Law, may be processed for research, planning and statistics purposes. Such transactions are outside the scope of the KVK Law and will not require the express consent of the personal data owner.

  1. The Methods of Personal Data Anonymization

The anonymization is that by removing or changing all direct and / or indirect identifiers in a data set, the identity of the person is prevented from being identified, or he or she loses its distinguishability in a group or crowd so that it cannot be associated with a real person. Data that does not indicate a particular person as a result of blocking or losing these features is considered anonymized data. The purpose of anonymizing is to break the link between the data and the person whom this data defines. All the relation breaking operations carried out by means of automatic or non-automatic grouping, masking, derivation, generalization, randomization, etc. are applied to the records in the data recording system where personal data is kept. The data obtained as a result of the application of these methods should not be able to identify a particular person.

  1. CHAPTER: RIGHTS OF RELATED PERSONS

 

  1. THE SCOPE OF THE RIGHTS OF THE RELATED PERSONS AND THE USE OF THESE RIGHTS

 

  1. Rights of Related Persons

Persons whose personal data are processed by our company have the rights listed below:

  1. The Use of Rights by Related Persons

It is necessary and enough for the concerned persons to submit their requests regarding the use of the rights mentioned above in accordance with article 13 paragraph 1 of the PDP Law to our Company in the following ways;

Application Method

Address of Application

Information to be specified in application submission

     

Personal Application

(Application by the applicant personally with a document proving his identity)

Ata OSB Mah. ASTİM Denizli Cad. No: 12, 09010 Organize Sanayi Bölgesi/Aydın, Turkey

"Request for Information within the Scope of the Personal Data Protection Law" will be written on the envelope.

Notification through a notary public

Ata OSB Mah. ASTİM Denizli Cad. No: 12, 09010 Organize Sanayi Bölgesi/Aydın, Turkey

"Request for Information within the Scope of the Law on Protection of Personal Data" shall be written in the notification envelope.

Through Signed with “Secure Electronic Signature” by Registered Electronic Mail (REM)

 [email protected]

"Information Request for Personal Data Protection Law “will be written in the subject part of the e-mail.

In application;

It is obligatory to have the place of Name, Surname, if application is written T.R. ID Number for Turkish citizens, nationality, passport number or identification number (if any) for foreigners, residence or business address subject to the notification, the electronic mail address, telephone and fax number, the subject of the request, if any. Information and documents related to the subject are also added to the application.

It is not possible to request by third parties on behalf of personal data owners. In order for a person other than the personal data owner to make a request, there must be a special power of attorney issued by the personal data owner on behalf of the applicant. In your application as a personal data owner, which contains your explanations of the rights you have made and which you would like to use to exercise your rights mentioned above; your request must be clear and understandable, if you are acting on behalf of yourself or you are acting on behalf of someone else, you must be specifically authorized and document your authority, the application must include identification and address information, and the documents confirming your identity must be attached to the application.

It is not possible to request by third parties on behalf of personal data owners. In order for a person other than the personal data owner to make a request, there must be a special power of attorney issued by the personal data owner on behalf of the applicant.

The application form for data owners is available on the Company website.

  1. Responding to Applications

In the event that the personal data owner submits the request to our Company in accordance with the prescribed procedure, our Company shall conclude the request free of charge within the shortest time and within thirty days at the latest according to the nature of the request. However, in case the transaction requires a separate cost, the applicant will be charged by the Company from the tariff determined by the PDP Board. Our company may request information from the person concerned to determine whether the applicant has personal data. In order to clarify the issues in the application of the personal data owner, our company may ask questions about the application of the personal data owner. Applications are managed within the Company according to the “Related Person Application Procedure” in of our Company.

  1. CHAPTER: ENSURING SECURITY OF PERSONAL DATA

 

  1. İ. TECHNICAL AND ADMINISTRATIVE MEASURES TAKEN TO PROVIDE PROPER PROCESSING OF PERSONAL DATA

Our company takes all necessary technical and administrative measures to ensure that personal data is processed in accordance with the law. In this context,

ü Within the scope of our company, Data Inventory (Data Mapping), which is compatible with VERBIS system, is prepared and compliance audits are carried out here.

üIn order to fulfill our company's obligation of disclosure in a complete and correct manner, the "Enlightening Principles of Processing Personal Data Policy" has been put into effect.

ü Employees are informed about the law on the protection of personal data and the processing of personal data in accordance with the law.

üAll activities carried out by our company are analyzed in detail in all business units, and as a result of this analysis, personal data processing activities are revealed in relation to the activities performed by the relevant business units.

üThe personal data processing activities carried out by the business units of our Company, and the requirements to be fulfilled in order to ensure the compliance of these activities with the personal data processing requirements sought by Law No. 6698 are determined in each business unit and the detail activity it carries out.

üIn the contracts and documents governing the legal relationship between the Company and the employees, records are put into the obligation not to process, not to disclose and not to use personal data, except for the Company's instructions and exceptions brought by law, and awareness of the employees is created and audits are carried out.

ü In the contracts and documents governing the legal relationship between the Company and the third parties that process the data that the Company is responsible for, except for the exceptions provided by law and the Company's exceptions, records that impose an obligation not to process, disclose and not to use personal data are made and "Principles of Privacy and Protection of Personal Data with Third Parties Policy" has been put into effect.

The PDP Law places particular importance on personal data, because of the risk of victimization or discrimination when committed in violation of the law. These data include data on race, ethnicity, political thought, philosophical belief, religion, sect or other beliefs, disguise and dress, association, foundation or union membership, health, sexual life, criminal conviction and security measures, and biometric and genetic data. Our Company treats the personal data that is designated as “private” by PDP Law and processed in accordance with the law. In this context, technical and administrative measures taken by our Company for the protection of personal data are carefully implemented and necessary controls are provided in terms of special personal data. In this perspective;

 

 

 

 

Our Company takes technical and administrative measures to prevent unlawful or unauthorized disclosure, access, transmission or otherwise unlawful access to personal data.

  1. Technical Measures to Prevent Illegal Access to Personal Data

The main technical measures taken by our Company to prevent unlawful access to personal data are listed below:

  1. Ensuring Cyber Security

Cyber security products are used primarily to provide personal data security, but measures are not limited to this. Measures such as firewall and gateway are taken. Unused software and services are removed from the devices.

  1. Software updates

Patch management and software upgrades ensure that the software and hardware work properly and that the security measures taken for the systems are enough to check regularly.

  1. Access Restrictions

Access to systems containing personal data is also restricted. In this context, employees are granted access authorization to the extent necessary for their work and duties and their powers and responsibilities, and access to related systems is provided by using username and password. When creating these passwords and passwords, combinations of uppercase and lowercase letters, numbers and symbols are preferred instead of numbers or letter sequences related to personal information that can be easily guessed. Accordingly, the access authorization and control matrix are established.

  1. Passwords

In addition to the use of strong passwords and passwords, access is restricted with methods such as limitation of the number of attempts to enter the password, keyword and password change at regular intervals to ensure that the administrator account and admin authority to be used only when needed, and to delete or to disable account of employees who have quitted with the coordination with data responsible.

  1. Antivirus Software

In order to protect against malware, products such as antivirus, antispam, which regularly scans the information system network and detect hazards, are kept up to date and the required files are regularly scanned. If personal data will be obtained from different internet sites and / or mobile application channels, the connections are provided through SSL or more secure way.

  1. Monitoring of Personal Data Security

A formal reporting procedure is set up for employees to report security weaknesses in systems and services or threats using them.

Evidence is collected and stored securely in the event of undesired events such as information system crash, malicious software, out-of-service attack, incomplete or incorrect data entry, violations of privacy and integrity, abuse of information system.

  1. G) Securing Personal Data Environments

If personal data is stored on devices or paper in the campus of the data responsible, physical security measures are taken against threats such as theft or loss of these devices and paper. The physical environments containing personal data are protected against external risks (fire, flood, etc.) by appropriate methods and the entrances / exits to these environments are controlled.

If personal data is electronically available, access between network components can be restricted or separated to prevent personal data security breach.

Measures at the same level are also taken for paper media, electronic media and devices (laptops, mobile phones, flash drives) containing personal data of the Company located outside the Company's campus. Personal data to be transmitted by e-mail or mail is sent carefully and with sufficient precautions.

Sufficient security measures are also taken in case employees provide access to the information system network with their personal electronic devices.

The use of access control authorization and / or encryption methods is applied in case of loss or theft of devices containing personal data. In this context, the password key is stored only in the environment accessible to authorized persons and unauthorized access is prevented.

Documents on paper media containing personal data are also stored in a locked and accessible environment only, and unauthorized access to such documents is prevented.

  1. Storing Personal Data in the Cloud

Applications of storing personal data in the cloud can also be used when necessary. In this case, the Company should also assess whether the security measures taken by the cloud storage service provider are adequate and appropriate. In this context, the measures specified in the guidelines and recommendations of the PDP Board are taken into consideration.

İ)            Supply, Development and Maintenance of Information Systems

The security requirements are taken into consideration when determining the requirements for the procurement, development or improvement of existing systems by the Company.

  1. Back Up Personal Data

If personal data is damaged, destroyed, stolen or lost due to any reason, the Company ensures that it is operational as soon as possible using the backed-up data. The backed up personal data is accessible only by the system administrator, and the data set backups are excluded from the network.

  1. Administrative Measures to Prevent Illegal Access to Personal Data

The main administrative measures taken by our Company to prevent unlawful access to personal data are listed below:

 

  1. STORAGE OF PERSONAL DATA IN SAFE MEDIUMS

Our company takes the necessary technical and administrative measures in accordance with technological opportunities and application costs in order to prevent personal data from being stored, kept in safe environments and destroyed, lost or changed for illegal purposes.

  1. Technical Measures to Keep Personal Data in Safe Mediums

The main technical measures taken by our Company for the storage of personal data in safe environments are listed below:

  1. Administrative Measures for Storing Personal Data in Safe Mediums

The main administrative measures taken by our Company for the storage of personal data in secure environments are listed below.:

ü Employees are informed about the safe storage of personal data.

üIn the event that an external service is received by our Company due to technical requirements for the storage of personal data, the contracts concluded with the relevant companies in which the personal data are transferred in accordance with the law, the provisions regarding that the persons to whom the personal data are transferred shall take the necessary security measures for the protection of the personal data and ensure that these measures are complied with in their own institutions in accordance with the provisions of the "Company's Principles for the Protection of Personal Data in Relations with Third Parties ”.

  1. TRAINING

ü Our Company provides its employees with the necessary trainings regarding the protection of Personal Data within the scope of Policy and PDP Procedures and PDPL Regulations.

  1. EVALUATION
  1. Increasing Awareness and Evaluation of Business Units on Protection and Processing of Personal Data

Our Company ensures that business units are notified in order to raise awareness to prevent unlawful processing of personal data, to prevent unlawful access to data and to maintain data.

  1. Increasing Awareness and Evaluation of Business Partners and Suppliers on Protection and Processing of Personal Data

Our Company provides necessary information to business partners in order to prevent unlawful processing of personal data, to prevent unlawful access to data, and to raise awareness in order to protect data.

  1. Evaluation of Measures for Protection of Personal Data

Our Company has the right to make audits regularly and without any prior notification in order to ensure that all employees, departments and contractors of the Company comply with this Policy and PDP Regulations and carries out the necessary routine audits. The results of these audits are evaluated within the scope of the Company's internal operation and necessary actions are taken to improve the measures taken.

Measures to be taken in the case of Unauthorized Disclosure of Personal Data and personal data processed in accordance with Article 12 of the PDP Law to be gathered by others , our company operates a system that enables the relevant personal data owner and the PDP Board to be notified as soon as possible.