AKC HİDROLİK MAKİNE İNŞ. TUR. SAN. TİC. LTD. ŞTİ.
PERSONAL DATA PROTECTION AND PROCESSING POLICY
Target Audience: All natural persons whose personal data are processed by AKC Hidrolik Makine İnş. Tur. San. Tic. Ltd. Şti.
Prepared by: AKC Hidrolik Makine İnş. Tur. San. Tic. Ltd. Şti. Personal Data Protection Committee
Version: 1.0
Approved by: Approved by AKC Hidrolik Makine İnş. Tur. San. Tic. Ltd. Şti.
CONTENTS
1. INTRODUCTION 3
1.1. Purpose 3
1.2. Scope 3
1.3 . Basis 3
1.4 . Definitions 3
2. PERSONAL DATA PROTECTION MATTERS 5
2.1. Ensuring the Security of Personal Data 5
2.2. Protection of Special Categories of Personal Data 5
2.3. Developing Awareness of Personal Data Protection and Processing 5
3. PROCESSING OF PERSONAL DATA 5
3.1. Processing Personal Data in Compliance with Legislation 5
3.2. Conditions for Processing Personal Data 6
3.3. Processing Special Categories of Personal Data 7
3.4. Informing the Personal Data Subject 7
3.5. Transfer of Personal Data 7
4. PERSONAL DATA INVENTORY PARAMETERS 8
5. MEASURES TAKEN FOR THE PROTECTION OF PERSONAL DATA 9
6. STORAGE AND DESTRUCTION OF PERSONAL DATA 9
7. RIGHTS OF PERSONAL DATA SUBJECTS AND EXERCISE OF THESE RIGHTS 9
7.1. Rights of the Personal Data Subject 9
7.2. Exercise of the Rights of the Personal Data Subject 9
7.3. Responding to Applications 10
7.4. Rejection of the Personal Data Subject's Application 10
7.5. Right of the Personal Data Subject to Lodge a Complaint with the KVK Board 10
8. IMPLEMENTATION 10
9. EFFECTIVE DATE AND ANNOUNCEMENT 11
ANNEX 1- Data Categories and Personal Data 12
ANNEX 2- Categorical Personal Data Processing Purposes 14
ANNEX 3 –Persons to Whom Personal Data Are Transferred and Purposes of Transfer 15
AKC HİDROLİK MAKİNE İNŞ. TUR. SAN. TİC. LTD. ŞTİ.
PERSONAL DATA PROTECTION AND PROCESSING POLICY
1. INTRODUCTION
AKC Hidrolik Makine İnş. Tur. San. Tic. Ltd. Şti. (“COMPANY”) places importance on the protection of personal data in its activities of manufacturing and selling loading and unloading machinery and regards it among its priorities in its business and operations. The COMPANY Personal Data Protection and Processing Policy (“Policy”), pursuant to the Personal Data Protection Law No. 6698 (“Law”) is the fundamental regulation aimed at aligning the personal data processing procedures and principles determined with the COMPANY's organization and business processes. In line with the principles of this Policy, the COMPANY processes and protects personal data with a high level of responsibility and awareness and provides the necessary transparency by informing personal data subjects.
1.1. Purpose
The purpose of this Policy is to ensure that the procedures and principles prescribed by the Law and other relevant legislation are harmonized with the COMPANY's organization and processes and effectively implemented in its activities. Through this Policy, the COMPANY takes all kinds of administrative and technical measures for the processing and protection of personal data, establishes the necessary internal procedures, raises awareness, and provides all necessary training to ensure awareness. All necessary measures are taken and appropriate and effective audit mechanisms are established to ensure compliance of shareholders, authorized persons, employees, and business partners with the processes under the Law.
1.2. Scope
The Policy covers all personal data obtained in the COMPANY's business processes by automatic means or by non-automatic means provided that they form part of any data recording system.
1.3 . Basis
The Policy is based on the Law and relevant legislation. Personal data are processed in order to fulfill legal obligations arising from the Law No. 5179 on the Amendment and Adoption of the Decree Law on the Production, Consumption and Inspection of Foods, the Regulation on Market Surveillance, Control and Inspection of Food and Materials and Articles in Contact with Food and Workplace Responsibilities, the Consumer Protection Law No. 6502, the Identity Notification Law No. 1774, the Labor Law No. 4857, the Occupational Health and Safety Law No. 6331, the Social Insurance and General Health Insurance Law No. 5510, the Unemployment Insurance Law No. 4447, the Turkish Commercial Code No. 6102, the Tax Procedure Law No. 213 and other relevant legislation.
In cases of inconsistency between the legislation in force and the Policy, the legislation in force shall apply. Regulations prescribed by the relevant legislation are transformed into COMPANY practices through the Policy.
1.4 . Definitions
| Explicit consent | Means consent relating to a specific subject, based on information and expressed with free will. |
|---|---|
| Application Form | The application form concerning applications to be made to the data controller by the relevant person (Personal Data Subject), prepared in accordance with the Personal Data Protection Law No. 6698 and the Communiqué on the Procedures and Principles of Application to the Data Controller issued by the Personal Data Protection Authority, containing the application that personal data subjects will make to exercise their rights. |
| Relevant user | Persons who process personal data within the data controller organization or in accordance with the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data. |
| Destruction | Deletion, destruction or anonymization of personal data. |
| Recording medium | Any medium containing personal data processed wholly or partly by automatic means or by non-automatic means provided that they form part of any data recording system. |
| Personal data | Any information relating to an identified or identifiable natural person. |
| Processing of personal data | Any operation performed on personal data, such as obtaining, recording, storing, retaining, altering, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, wholly or partly by automatic means or by non-automatic means provided that they form part of any data recording system. |
| Anonymization of personal data | Rendering personal data impossible to associate with an identified or identifiable natural person under any circumstances, even by matching them with other data. |
| Personal data subject | The natural person whose personal data are processed by or on behalf of the COMPANY. |
| Deletion of personal data |
Deletion of personal data; rendering personal data in no way accessible or reusable by Relevant Users . |
| Destruction of personal data | The process of rendering personal data inaccessible, irretrievable and unusable by anyone in any way. |
| Board | Personal Data Protection Board |
| Authority | Personal Data Protection Authority |
| Special category personal data |
Data relating to persons' race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. |
| Periodic destruction | The deletion, destruction or anonymization process to be carried out ex officio at recurring intervals specified in the personal data retention and destruction policy when all conditions for processing personal data set out in the Law cease to exist. |
| Data Processor |
A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller. |
| Data Recording System |
A recording system in which personal data are processed by being structured according to specific criteria. |
| Data subject / Relevant person | The natural person whose personal data are processed. |
| Data controller | A natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system. |
| Data Representative | A natural person appointed to perform the duties of the Data Controller under the relevant provisions of the Law. |
| Regulation | Regulation on the Deletion, Destruction or Anonymization of Personal Data published in the Official Gazette on 28 October 2017 |
2. PERSONAL DATA PROTECTION MATTERS
2.1. Ensuring the Security of Personal Data
The COMPANY takes the necessary measures prescribed in Article 12 of the Law, according to the nature of the personal data, in order to prevent unlawful disclosure, access, transfer or other security problems that may arise. The COMPANY takes measures and conducts audits to ensure the necessary level of personal data security in accordance with the guidelines published by the Personal Data Protection Authority.
2.2. Protection of Special Categories of Personal Data
Measures taken to protect special categories of personal data relating to persons' race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions, security measures, and biometric and genetic data are carefully implemented and the necessary audits are carried out.
2.3. Developing Awareness of Personal Data Protection and Processing
The COMPANY provides the relevant persons with the necessary training to develop awareness regarding the lawful processing and access of personal data, the retention of data and the exercise of rights.
In order to increase employees' awareness of personal data protection, the COMPANY establishes the necessary business processes and receives support from consultants when needed. Deficiencies encountered in practice and the results of training are evaluated by COMPANY management. New training is organized when needed depending on these evaluations and changes in the relevant legislation.
3. PROCESSING OF PERSONAL DATA
3.1. Processing Personal Data in Compliance with Legislation
Personal data are processed in accordance with the legislation in line with the principles listed below.
- Processing in Accordance with Law and Good Faith
Personal data are processed to the extent required by business processes, limited thereto, without harming the fundamental rights and freedoms of persons, and in accordance with law and the principle of good faith.
- Ensuring that Personal Data Are Up-to-Date and Accurate
Necessary measures are taken and planned and programmed work is carried out to keep the processed personal data up-to-date and accurate.
- Processing for Specified, Explicit and Legitimate Purposes
Personal data are processed in connection with the legitimate purposes determined and disclosed in the business processes carried out .
- Being Relevant, Limited and Proportionate to the Purpose for Which They Are Processed
Personal data are collected to the extent and in the nature required by business processes and are processed in a limited manner in connection with the specified purposes.
- Retention for the Period Necessary
Personal data are retained for at least the period prescribed in the relevant legislation and necessary for the purpose of processing personal data. First of all, if a period for the storage of personal data is prescribed in the relevant legislation, this period is observed; if no period is prescribed, personal data are retained for the period necessary for the purpose for which they are processed. At the end of the retention periods, personal data are destroyed by appropriate methods (deletion, destruction or anonymization) in accordance with periodic destruction periods or the data subject's application.
3.2. Conditions for Processing Personal Data
Personal data are processed based on the data subject's explicit consent or one or more of the other conditions specified below.
- Existence of the Personal Data Subject's Explicit Consent
Personal data are processed with the explicit consent of the data subject. The explicit consent of the personal data subject is obtained by informing them on a specific matter and receiving their free will.
- Absence of the Personal Data Subject's Explicit Consent
If any of the conditions listed below exists, personal data may be processed without the explicit consent of the data subject.
- Explicitly Provided for by Law
Where there is an explicit provision in the laws regarding the processing of personal data, personal data may be processed without obtaining the consent of the data subject.
- Inability to Obtain the Relevant Person's Explicit Consent Due to Actual Impossibility
Where, due to actual impossibility, a person is unable to express consent or their consent cannot be deemed legally valid, the personal data of the data subject may be processed if processing is mandatory to protect the life or physical integrity of that person or another person.
- Direct Relation to the Establishment or Performance of a Contract
If the processing of personal data is directly related to the establishment or performance of a contract to which the data subject is a party, the data subject's personal data may be processed.
- Fulfillment of a Legal Obligation
While the COMPANY fulfills its legal obligations, the personal data of the data subject may be processed if the processing of personal data is mandatory.
- Making Personal Data Public by the Personal Data Subject
Personal data belonging to data subjects who have made their personal data public may be processed limited to the purpose of making them public.
- Mandatory Data Processing for the Establishment or Protection of a Right
If data processing is mandatory for the establishment, exercise or protection of a right, the personal data of the data subject may be processed.
- Mandatory Data Processing for Legitimate Interest
Provided that the fundamental rights and freedoms of the personal data subject are not harmed, the personal data of the data subject may be processed where data processing is mandatory for the legitimate interests of the COMPANY.
3.3. Processing Special Categories of Personal Data
The COMPANY processes special categories of personal data in accordance with the principles set out in the Law and the Policy, by taking all necessary administrative and technical measures using the methods determined by the Board, in accordance with the following procedures and principles:
- Special categories of personal data other than health and sexual life, may be processed without seeking the explicit consent of the data subject where there is an explicit provision in the laws regarding their processing. In cases not explicitly provided for by law, the explicit consent of the data subject shall be obtained.
- Special categories of personal data relating to health and sexual life, may be processed without seeking the explicit consent of the data subject by persons under an obligation of confidentiality or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and management of health services and their financing. Otherwise, the explicit consent of the data subject shall be obtained.
3.4. Informing the Personal Data Subject
The COMPANY informs personal data subjects, in accordance with the relevant legislation, about the purposes for which their personal data are processed, with whom and for what purposes they are shared, by which methods they are collected, the legal basis, and the rights data subjects have regarding the processing of their personal data. In this respect, the protection of personal data is carried out in connection with other policy documents and disclosure texts prepared within the framework of the principles in the Policy.
3.5. Transfer of Personal Data
In line with its personal data processing purposes and by taking the necessary security measures, the COMPANY may lawfully transfer personal data and special categories of personal data to third parties (third-party companies, group companies, third-party natural persons). The COMPANY carries out transfer operations in accordance with the regulations prescribed in Article 8 of the Law.
- Transfer of Personal Data
Although the explicit consent of the personal data subject is sought for the transfer of personal data, personal data may be transferred to third parties based on one or more of the conditions specified below, by taking all necessary security measures, including the methods prescribed by the Board.
- It is explicitly provided for by law,
- It is directly related and necessary for the establishment or performance of a contract,
- It is mandatory for the COMPANY to fulfill its legal obligation,
- Provided that the personal data have been made public by the data subject, limited to the purpose of making them public,
- It is mandatory for the establishment, exercise or protection of the rights of the COMPANY, the data subject or third parties,
- Provided that the fundamental rights and freedoms of the data subject are not harmed, it is mandatory for securing the legitimate interests of the COMPANY,
- It is mandatory to protect the life or physical integrity of the person who is unable to express consent due to actual impossibility or whose consent is not legally valid, or of another person.
To those having the status of a foreign country determined by the Board to have adequate protection and declared as a “Foreign Country with Adequate Protection”, personal data may be transferred depending on any of the cases listed above. To those having the status of a “Foreign Country Where the Data Controller Undertaking Adequate Protection Is Located”, where adequate protection is not available and the data controllers in Türkiye and the foreign country undertake adequate protection in writing and the Board has granted permission, personal data may be transferred according to the conditions prescribed in the legislation.
ii. Transfer of Special Categories of Personal Data
Special categories of personal data may, in accordance with the principles set out in the Policy and the methods to be determined by the Board, including by taking all necessary administrative and technical measures, be transferred under the conditions specified below:
- Special categories of personal data other than health and sexual life, where there is an explicit provision in the laws regarding the processing of personal data, without seeking the explicit consent of the data subject; otherwise, where the explicit consent of the data subject is obtained.
- Special categories of personal data relating to health and sexual life, for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and management of health services and their financing, without seeking explicit consent by persons under an obligation of confidentiality or by authorized institutions and organizations; otherwise, where the explicit consent of the data subject is obtained.
Personal data may be transferred to those having the status of a “Foreign Country with Adequate Protection” if any of the above conditions is present, and where adequate protection is not available, to those having the status of a “Foreign Country Where the Data Controller Undertaking Adequate Protection Is Located” according to the data transfer conditions regulated in the legislation, personal data may be transferred.
4. PERSONAL DATA INVENTORY PARAMETERS
In the COMPANY's management, human resources, administrative affairs, financial affairs (accounting-finance), planning-logistics-information technology, production, product development-quality, R&D marketing-sales, and purchasing business processes, data categories and personal data belonging to personal data subjects consisting of employee candidates, employees, shareholders/partners, potential product or service recipients, interns, supplier representatives, persons receiving products or services, parents/guardians/representatives, and visitors (Annex-1), are processed depending on personal data processing purposes (Annex-2) . Details of processing purposes according to data categories and groups of persons who are the subjects of data are declared in the COMPANY's area at https://verbis.kvkk.gov.tr/.
Personal data processing purposes are determined according to personal data categories, in order to inform relevant persons pursuant to Article 10 of the Law and other legislation, based on and limited to at least one of the personal data processing conditions specified in Articles 5 and 6 of the Law, and to carry out processing in accordance with the general principles specified in the Law, in particular the principles set out in Article 4 of the Law regarding the processing of personal data.
Personal data may be shared, in accordance with the principles set out in the Policy section “3.5. Transfer of Personal Data”, with natural persons or private-law legal entities, shareholders, business partners, affiliates and subsidiaries, suppliers, authorized public institutions and organizations, private insurance companies, auditors, consultants, organizations from which we receive contracted services, organizations with which we cooperate, and domestic organizations, for the specified purposes (Annex-3) . There is no transfer of personal information to foreign countries.
5. MEASURES TAKEN FOR THE PROTECTION OF PERSONAL DATA
The COMPANY takes the necessary technical and administrative measures to protect the personal data it processes in accordance with the procedures and principles set out in the Law, carries out the necessary audits in this context, and conducts awareness-raising and training activities.
If the processed personal data are obtained by third parties through unlawful means despite all technical and administrative measures having been taken, the COMPANY notifies the relevant persons and units of this situation as soon as possible.
6. STORAGE AND DESTRUCTION OF PERSONAL DATA
The COMPANY retains personal data for the period necessary for the purpose of processing and at least for the period prescribed in the relevant legislation. If a period is specified in the relevant legislation, the COMPANY first retains the personal data in accordance with that period; if no legal period is prescribed, it retains personal data for the period necessary for the purpose of processing. At the end of the specified retention periods, personal data are destroyed by the specified method (deletion, destruction or anonymization) in accordance with periodic destruction periods or the data subject's application.
7. RIGHTS OF PERSONAL DATA SUBJECTS AND EXERCISE OF THESE RIGHTS
7.1. Rights of the Personal Data Subject
Personal data subjects have the following rights arising from the Law:
- To learn whether personal data are processed,
- To request information if personal data have been processed,
- To learn the purpose of processing personal data and whether they are used in accordance with their purpose,
- To know the third parties to whom personal data are transferred domestically or abroad,
- To request correction if personal data have been processed incompletely or incorrectly and to request notification of the transaction carried out within this scope to third parties to whom the personal data have been transferred,
- Although processed in accordance with the Law and other relevant provisions of law, to request deletion or destruction of personal data if the reasons requiring their processing cease to exist and to request notification of the transaction carried out within this scope to third parties to whom the personal data have been transferred,
- To object to the emergence of a result against the person by analyzing the processed data exclusively through automated systems,
- To request compensation for damage in case of suffering damage due to the unlawful processing of personal data.
7.2. Exercise of the Rights of the Personal Data Subject
Personal data subjects may submit their requests regarding the rights listed in Article 6.1 to the COMPANY by the methods determined by the Board. Personal data subjects and those who have the right to apply on their behalf may apply to the COMPANY by completing the “Data Subject Application Form” (Annex-4).
7.3. Responding to Applications
The COMPANY concludes applications made by the personal data subject in accordance with the Law and other legislation. Requests duly submitted to the COMPANY are concluded free of charge as soon as possible and no later than 30 (thirty) days. However, if the transaction requires an additional cost, a fee may be charged according to the tariff determined by the Board.
7.4. Rejection of the Personal Data Subject's Application
The COMPANY may reject the request of the applicant by explaining the reason in the following cases:
- Processing personal data for purposes such as research, planning and statistics by anonymizing them with official statistics,
- Processing personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that it does not violate national defense, national security, public security, public order, economic security, privacy or personal rights, or constitute a crime,
- Processing personal data within the scope of preventive, protective and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public security, public order or economic security,
- Processing personal data by judicial authorities or enforcement authorities in relation to investigation, prosecution, trial or execution proceedings,
- Processing of personal data being necessary for the prevention of crime or criminal investigation,
- Processing personal data made public by the personal data subject,
- Processing of personal data being necessary for the performance of supervisory or regulatory duties and for disciplinary investigation or prosecution by authorized public institutions and organizations and professional organizations with public institution status, based on authority granted by law,
- Processing of personal data being necessary for the protection of the economic and financial interests of the State in relation to budgetary, tax and financial matters,
- The personal data subject's request being likely to hinder the rights and freedoms of other persons,
- Requests having been made that require disproportionate effort,
- The requested information being publicly available information.
7.5. Right of the Personal Data Subject to Lodge a Complaint with the KVK Board
Pursuant to Article 14 of the Law, in cases where the application is rejected, the response is found insufficient or no response is given to the application within the prescribed period, a complaint may be lodged with the Board within thirty days from the date the COMPANY's response is learned and in any case within sixty days from the date of application.
7.6. Information That May Be Requested from the Applying Personal Data Subject
The COMPANY may request information from the relevant person in order to determine whether the applicant is the personal data subject. The COMPANY may ask the personal data subject questions regarding the application in order to clarify the matters included in the personal data subject's application.
8. IMPLEMENTATION
The Policy has been approved by the Board of Directors and put into effect. The technical implementation of the Policy is ensured by the “Personal Data Retention and Destruction Policy” (Annex-5).
In business processes, the implementation of the Policy before the parties is carried out through the “Customer Disclosure Text and Explicit Consent Statement” (Annex-6), “Supplier Confidentiality Undertaking, Supplier Disclosure Text and Explicit Consent Statement” (Annex-7) “Employee Disclosure Text and Explicit Consent Statement” (Annex-8), “Employee Candidate Disclosure Text and Explicit Consent Statement” (Annex-9), “Website Cookie Disclosure Text” (Annex-10), “Camera Disclosure Text and Explicit Consent Statement” (Annex-11) .
The Board of Directors is responsible for the implementation of the Law and the Policy and for updating them when necessary, and the COMPANY Personal Data Protection Committee is responsible for monitoring, coordinating and auditing all business and operations within this scope.
9. EFFECTIVE DATE AND ANNOUNCEMENT
The Policy entered into force as of its publication date. Changes to the Policy are published on the COMPANY's website (www.akcmakine.com.tr) and made accessible to personal data subjects and relevant persons. Policy changes enter into force on the date they are announced.
ANNEXES
Annex 1- Data Categories and Personal Data
Annex 2- Personal Data Processing Purposes
Annex 3- Persons to Whom Personal Data Are Transferred and Purposes of Transfer
Annex 4- Personal Data Subject Application Form
Annex 5- Personal Data Retention and Destruction Policy
Annex 6- Customer Disclosure Text on Processing Personal Data
Annex 7- Supplier Confidentiality and Personal Data Protection Agreement, Disclosure Text and Explicit Consent Statement
Annex 8- Employee Disclosure Text and Explicit Consent Statement
Annex 9- Employee Candidate Disclosure Text and Explicit Consent Statement
Annex 10- Website Cookie Disclosure Text
Annex 11- Camera Disclosure Text and Explicit Consent Statement
ANNEX 1- Data Categories and Personal Data
| Data Categories | Personal Data |
|---|---|
| Identity | Name, Surname |
| Mother's- Father's Name | |
| Date of Birth | |
| Place of Birth | |
| Marital Status | |
| Identity Card Serial Sequence No | |
| Turkish Republic Identity No | |
| Passport Number | |
| Temporary Turkish Republic Identity Number | |
| Gender Information | |
| Turkish Republic Identity Card | |
| Driver's License | |
| Contact | Address |
| Email Address | |
| Contact Address | |
| Registered Electronic Mail Address (KEP) | |
| Phone No | |
| Personnel | Payroll Information |
| Disciplinary Investigation | |
| Employment Entry- Exit Document Records | |
| Curriculum Vitae Information | |
| Performance Evaluation Reports | |
| Legal Transaction | Information in correspondence with judicial authorities, information in case files, etc. |
| Customer Transaction | Invoice |
| Promissory Note | |
| Cheque Information | |
| Entry-Exit Information | |
| Order Information | |
| Appointment Information | |
| Physical Space Security | Employee and Visitor Entry and Exit Record Information |
| Camera Records | |
| Transaction Security | Transaction Security (such as IP address information, website login/logout information, password and passcode information) |
| IP Address Information | |
| Website Login and Logout Information | |
| Password and Passcode Information | |
| Risk Management | Information processed for the management of commercial, technical and administrative risks, etc. |
| Finance | Balance Sheet Information |
| Financial Performance Information | |
| Credit and Risk Information | |
| Bank Account Number | |
| IBAN Number | |
| Professional Experience | Diploma Information |
| Courses Attended | |
| In-Service Training Information | |
| Certificates | |
| Marketing | Shopping History Information |
| Cookie Records | |
| Information Obtained Through Campaign Activities | |
| Visual and Audio Records | Closed-Circuit Camera System Image, Audio Recording |
| Health Information | Information Regarding Disability Status |
| Blood Group Information | |
| Personal Health Information | |
| Information on Devices and Prostheses Used | |
| Laboratory and Imaging Results | |
| Test Results | |
| Examination Data | |
| Prescription Information | |
| Criminal Convictions and Security Measures | Information Regarding Criminal Convictions |
| Information Regarding Security Measures | |
| Family Information | Number of Children |
| Family Record Book | |
| Spouse Employment Information | |
| Children's Education and Age Information | |
| Request/Complaint Management Information | Information Regarding Requests and Complaints |
ANNEX 2- Categorical Personal Data Processing Purposes
| Conducting Emergency Management Processes |
|---|
| Conducting Information Security Processes |
| Conducting Employee Candidate / Intern / Student Selection and Placement Processes |
| Conducting Employee Candidate Application Processes |
| Conducting Employee Satisfaction and Commitment Processes |
| Fulfilling Obligations Arising from Employment Contracts and Legislation for Employees |
| Conducting Fringe Benefits and Benefits Processes for Employees |
| Conducting Audit / Ethics Activities |
| Conducting Training Activities |
| Conducting Access Authorization Processes |
| Conducting Activities in Compliance with Legislation |
| Conducting Finance and Accounting Affairs |
| Conducting Company / Product / Service Loyalty Processes |
| Ensuring Physical Space Security |
| Conducting Assignment Processes |
| Monitoring and Conducting Legal Affairs |
| Conducting Internal Audit / Investigation / Intelligence Activities |
| Conducting Communication Activities |
| Planning Human Resources Processes |
| Conducting / Auditing Business Activities |
| Conducting Occupational Health / Safety Activities |
| Receiving and Evaluating Suggestions for Improving Business Processes |
| Conducting Business Continuity Activities |
| Conducting Logistics Activities |
| Conducting Goods / Service Procurement Processes |
| Conducting Goods / Service After-Sales Support Services |
| Conducting Goods / Service Sales Processes |
| Conducting Goods / Service Production and Operation Processes |
| Conducting Customer Relationship Management Processes |
| Conducting Activities for Customer Satisfaction |
| Organization and Event Management |
| Conducting Marketing Analysis Activities |
| Conducting Performance Evaluation Processes |
| Conducting Advertising / Campaign / Promotion Processes |
| Conducting Risk Management Processes |
| Conducting Retention and Archive Activities |
| Conducting Contract Processes |
| Monitoring Requests / Complaints |
| Ensuring the Security of Movable Property and Resources |
| Conducting Supply Chain Management Processes |
| Conducting Remuneration Policy |
| Conducting Marketing Processes for Products / Services |
| Ensuring the Security of Data Controller Operations |
| Conducting Investment Processes |
| Conducting Talent / Career Development Activities |
| Providing Information to Authorized Persons, Institutions and Organizations |
| Conducting Management Activities |
| Creating and Monitoring Visitor Records |
| Managing Relations with Business Partners and Suppliers |
ANNEX 3 –Persons to Whom Personal Data Are Transferred and Purposes of Transfer
In accordance with Articles 8 and 9 of the Law, the COMPANY may transfer the personal data of participants, customers and employees to the categories of persons listed below:
|
Persons to Whom Data May Be Transferred Persons |
Definition |
Purpose and Scope of Data Transfer |
|---|---|---|
|
Natural persons or private-law legal entities |
Natural or legal persons with whom the COMPANY has relations or carries out transactions due to its activities |
Limited to the business and transaction carried out |
|
Business Partners |
Business partners and partner banks with which the COMPANY has relations for purposes such as promotion and marketing of its products and services and after-sales support |
Limited to the purposes and activities of establishing and conducting the business partnership |
|
Authorized Public Institutions and Organizations |
Public institutions and organizations, such as the Social Security Institution and Tax Offices, authorized to obtain information and documents from the COMPANY according to the provisions of the relevant legislation |
Limited to the purpose requested based on the legal authority of the relevant public institutions and organizations |
|
Private-Law Persons Authorized by Law |
Institutions or organizations established in accordance with certain conditions pursuant to the provisions of the relevant legislation and continuing their activities within this framework |
Limited to matters falling within the areas of activity they conduct |
|
Supplier |
Parties providing services to the COMPANY in line with data processing purposes and requests |
Limited to the purpose of procuring goods and services for the COMPANY to carry out its outsourced commercial activities |