Retention and Destruction Policy

AKC HİDROLİK MAKİNE İNŞ. TUR. SAN. TİC. LTD. ŞTİ.

PERSONAL DATA PROTECTION AND PROCESSING POLICY

Target Audience: All natural persons whose personal data are processed by AKC Hidrolik Makine İnş. Tur. San. Tic. Ltd. Şti.

Prepared by: AKC Hidrolik Makine İnş. Tur. San. Tic. Ltd. Şti. Personal Data Protection Committee

Version: 1.0

Approved by: Approved by AKC Hidrolik Makine İnş. Tur. San. Tic. Ltd. Şti.

CONTENTS

1. INTRODUCTION 3

1.1. Purpose 3

1.2. Scope 3

1.3 . Basis 3

1.4 . Definitions 3

2. PERSONAL DATA PROTECTION MATTERS 5

2.1. Ensuring the Security of Personal Data 5

2.2. Protection of Special Categories of Personal Data 5

2.3. Developing Awareness of Personal Data Protection and Processing 5

3. PROCESSING OF PERSONAL DATA 5

3.1. Processing Personal Data in Compliance with Legislation 5

3.2. Conditions for Processing Personal Data 6

3.3. Processing Special Categories of Personal Data 7

3.4. Informing the Personal Data Subject 7

3.5. Transfer of Personal Data 7

4. PERSONAL DATA INVENTORY PARAMETERS 8

5. MEASURES TAKEN FOR THE PROTECTION OF PERSONAL DATA 9

6. STORAGE AND DESTRUCTION OF PERSONAL DATA 9

7. RIGHTS OF PERSONAL DATA SUBJECTS AND EXERCISE OF THESE RIGHTS 9

7.1. Rights of the Personal Data Subject 9

7.2. Exercise of the Rights of the Personal Data Subject 9

7.3. Responding to Applications 10

7.4. Rejection of the Personal Data Subject's Application 10

7.5. Right of the Personal Data Subject to Lodge a Complaint with the KVK Board 10

8. IMPLEMENTATION 10

9. EFFECTIVE DATE AND ANNOUNCEMENT 11

ANNEX 1- Data Categories and Personal Data 12

ANNEX 2- Categorical Personal Data Processing Purposes 14

ANNEX 3 –Persons to Whom Personal Data Are Transferred and Purposes of Transfer 15

AKC HİDROLİK MAKİNE İNŞ. TUR. SAN. TİC. LTD. ŞTİ.

PERSONAL DATA PROTECTION AND PROCESSING POLICY

1. INTRODUCTION

AKC Hidrolik Makine İnş. Tur. San. Tic. Ltd. Şti. (“COMPANY”) places importance on the protection of personal data in its activities of manufacturing and selling loading and unloading machinery and regards it among its priorities in its business and operations. The COMPANY Personal Data Protection and Processing Policy (“Policy”), pursuant to the Personal Data Protection Law No. 6698 (“Law”) is the fundamental regulation aimed at aligning the personal data processing procedures and principles determined with the COMPANY's organization and business processes. In line with the principles of this Policy, the COMPANY processes and protects personal data with a high level of responsibility and awareness and provides the necessary transparency by informing personal data subjects.

1.1. Purpose

The purpose of this Policy is to ensure that the procedures and principles prescribed by the Law and other relevant legislation are harmonized with the COMPANY's organization and processes and effectively implemented in its activities. Through this Policy, the COMPANY takes all kinds of administrative and technical measures for the processing and protection of personal data, establishes the necessary internal procedures, raises awareness, and provides all necessary training to ensure awareness. All necessary measures are taken and appropriate and effective audit mechanisms are established to ensure compliance of shareholders, authorized persons, employees, and business partners with the processes under the Law.

1.2. Scope

The Policy covers all personal data obtained in the COMPANY's business processes by automatic means or by non-automatic means provided that they form part of any data recording system.

1.3 . Basis

The Policy is based on the Law and relevant legislation. Personal data are processed in order to fulfill legal obligations arising from the Law No. 5179 on the Amendment and Adoption of the Decree Law on the Production, Consumption and Inspection of Foods, the Regulation on Market Surveillance, Control and Inspection of Food and Materials and Articles in Contact with Food and Workplace Responsibilities, the Consumer Protection Law No. 6502, the Identity Notification Law No. 1774, the Labor Law No. 4857, the Occupational Health and Safety Law No. 6331, the Social Insurance and General Health Insurance Law No. 5510, the Unemployment Insurance Law No. 4447, the Turkish Commercial Code No. 6102, the Tax Procedure Law No. 213 and other relevant legislation.

In cases of inconsistency between the legislation in force and the Policy, the legislation in force shall apply. Regulations prescribed by the relevant legislation are transformed into COMPANY practices through the Policy.

1.4 . Definitions

Explicit consent Means consent relating to a specific subject, based on information and expressed with free will.
Application Form The application form concerning applications to be made to the data controller by the relevant person (Personal Data Subject), prepared in accordance with the Personal Data Protection Law No. 6698 and the Communiqué on the Procedures and Principles of Application to the Data Controller issued by the Personal Data Protection Authority, containing the application that personal data subjects will make to exercise their rights.
Relevant user Persons who process personal data within the data controller organization or in accordance with the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.
Destruction Deletion, destruction or anonymization of personal data.
Recording medium Any medium containing personal data processed wholly or partly by automatic means or by non-automatic means provided that they form part of any data recording system.
Personal data Any information relating to an identified or identifiable natural person.
Processing of personal data Any operation performed on personal data, such as obtaining, recording, storing, retaining, altering, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, wholly or partly by automatic means or by non-automatic means provided that they form part of any data recording system.
Anonymization of personal data Rendering personal data impossible to associate with an identified or identifiable natural person under any circumstances, even by matching them with other data.
Personal data subject The natural person whose personal data are processed by or on behalf of the COMPANY.
Deletion of personal data

Deletion of personal data; rendering personal data in no way accessible or reusable by Relevant Users

.

Destruction of personal data The process of rendering personal data inaccessible, irretrievable and unusable by anyone in any way.
Board Personal Data Protection Board
Authority Personal Data Protection Authority
Special category personal data

Data relating to persons' race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as

biometric and genetic data.

Periodic destruction The deletion, destruction or anonymization process to be carried out ex officio at recurring intervals specified in the personal data retention and destruction policy when all conditions for processing personal data set out in the Law cease to exist.
Data Processor

A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller.

Data Recording System

A recording system in which personal data are processed by being structured according to specific criteria.

Data subject / Relevant person The natural person whose personal data are processed.
Data controller A natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.
Data Representative A natural person appointed to perform the duties of the Data Controller under the relevant provisions of the Law.
Regulation Regulation on the Deletion, Destruction or Anonymization of Personal Data published in the Official Gazette on 28 October 2017

2. PERSONAL DATA PROTECTION MATTERS

2.1. Ensuring the Security of Personal Data

The COMPANY takes the necessary measures prescribed in Article 12 of the Law, according to the nature of the personal data, in order to prevent unlawful disclosure, access, transfer or other security problems that may arise. The COMPANY takes measures and conducts audits to ensure the necessary level of personal data security in accordance with the guidelines published by the Personal Data Protection Authority.

2.2. Protection of Special Categories of Personal Data

Measures taken to protect special categories of personal data relating to persons' race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions, security measures, and biometric and genetic data are carefully implemented and the necessary audits are carried out.

2.3. Developing Awareness of Personal Data Protection and Processing

The COMPANY provides the relevant persons with the necessary training to develop awareness regarding the lawful processing and access of personal data, the retention of data and the exercise of rights.

In order to increase employees' awareness of personal data protection, the COMPANY establishes the necessary business processes and receives support from consultants when needed. Deficiencies encountered in practice and the results of training are evaluated by COMPANY management. New training is organized when needed depending on these evaluations and changes in the relevant legislation.

3. PROCESSING OF PERSONAL DATA

3.1. Processing Personal Data in Compliance with Legislation

Personal data are processed in accordance with the legislation in line with the principles listed below.

  1. Processing in Accordance with Law and Good Faith

Personal data are processed to the extent required by business processes, limited thereto, without harming the fundamental rights and freedoms of persons, and in accordance with law and the principle of good faith.

  1. Ensuring that Personal Data Are Up-to-Date and Accurate

Necessary measures are taken and planned and programmed work is carried out to keep the processed personal data up-to-date and accurate.

  1. Processing for Specified, Explicit and Legitimate Purposes

Personal data are processed in connection with the legitimate purposes determined and disclosed in the business processes carried out .

  1. Being Relevant, Limited and Proportionate to the Purpose for Which They Are Processed

Personal data are collected to the extent and in the nature required by business processes and are processed in a limited manner in connection with the specified purposes.

  1. Retention for the Period Necessary

Personal data are retained for at least the period prescribed in the relevant legislation and necessary for the purpose of processing personal data. First of all, if a period for the storage of personal data is prescribed in the relevant legislation, this period is observed; if no period is prescribed, personal data are retained for the period necessary for the purpose for which they are processed. At the end of the retention periods, personal data are destroyed by appropriate methods (deletion, destruction or anonymization) in accordance with periodic destruction periods or the data subject's application.

3.2. Conditions for Processing Personal Data

Personal data are processed based on the data subject's explicit consent or one or more of the other conditions specified below.

  1. Existence of the Personal Data Subject's Explicit Consent

Personal data are processed with the explicit consent of the data subject. The explicit consent of the personal data subject is obtained by informing them on a specific matter and receiving their free will.

  1. Absence of the Personal Data Subject's Explicit Consent

If any of the conditions listed below exists, personal data may be processed without the explicit consent of the data subject.

  1. Explicitly Provided for by Law

Where there is an explicit provision in the laws regarding the processing of personal data, personal data may be processed without obtaining the consent of the data subject.

  1. Inability to Obtain the Relevant Person's Explicit Consent Due to Actual Impossibility

Where, due to actual impossibility, a person is unable to express consent or their consent cannot be deemed legally valid, the personal data of the data subject may be processed if processing is mandatory to protect the life or physical integrity of that person or another person.

  1. Direct Relation to the Establishment or Performance of a Contract

If the processing of personal data is directly related to the establishment or performance of a contract to which the data subject is a party, the data subject's personal data may be processed.

  1. Fulfillment of a Legal Obligation

While the COMPANY fulfills its legal obligations, the personal data of the data subject may be processed if the processing of personal data is mandatory.

  1. Making Personal Data Public by the Personal Data Subject

Personal data belonging to data subjects who have made their personal data public may be processed limited to the purpose of making them public.

  1. Mandatory Data Processing for the Establishment or Protection of a Right

If data processing is mandatory for the establishment, exercise or protection of a right, the personal data of the data subject may be processed.

  1. Mandatory Data Processing for Legitimate Interest

Provided that the fundamental rights and freedoms of the personal data subject are not harmed, the personal data of the data subject may be processed where data processing is mandatory for the legitimate interests of the COMPANY.

3.3. Processing Special Categories of Personal Data

The COMPANY processes special categories of personal data in accordance with the principles set out in the Law and the Policy, by taking all necessary administrative and technical measures using the methods determined by the Board, in accordance with the following procedures and principles:

  1. Special categories of personal data other than health and sexual life, may be processed without seeking the explicit consent of the data subject where there is an explicit provision in the laws regarding their processing. In cases not explicitly provided for by law, the explicit consent of the data subject shall be obtained.
  2. Special categories of personal data relating to health and sexual life, may be processed without seeking the explicit consent of the data subject by persons under an obligation of confidentiality or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and management of health services and their financing. Otherwise, the explicit consent of the data subject shall be obtained.

3.4. Informing the Personal Data Subject

The COMPANY informs personal data subjects, in accordance with the relevant legislation, about the purposes for which their personal data are processed, with whom and for what purposes they are shared, by which methods they are collected, the legal basis, and the rights data subjects have regarding the processing of their personal data. In this respect, the protection of personal data is carried out in connection with other policy documents and disclosure texts prepared within the framework of the principles in the Policy.

3.5. Transfer of Personal Data

In line with its personal data processing purposes and by taking the necessary security measures, the COMPANY may lawfully transfer personal data and special categories of personal data to third parties (third-party companies, group companies, third-party natural persons). The COMPANY carries out transfer operations in accordance with the regulations prescribed in Article 8 of the Law.

  1. Transfer of Personal Data

Although the explicit consent of the personal data subject is sought for the transfer of personal data, personal data may be transferred to third parties based on one or more of the conditions specified below, by taking all necessary security measures, including the methods prescribed by the Board.

  1. It is explicitly provided for by law,
  2. It is directly related and necessary for the establishment or performance of a contract,
  3. It is mandatory for the COMPANY to fulfill its legal obligation,
  4. Provided that the personal data have been made public by the data subject, limited to the purpose of making them public,
  5. It is mandatory for the establishment, exercise or protection of the rights of the COMPANY, the data subject or third parties,
  6. Provided that the fundamental rights and freedoms of the data subject are not harmed, it is mandatory for securing the legitimate interests of the COMPANY,
  7. It is mandatory to protect the life or physical integrity of the person who is unable to express consent due to actual impossibility or whose consent is not legally valid, or of another person.

To those having the status of a foreign country determined by the Board to have adequate protection and declared as a “Foreign Country with Adequate Protection”, personal data may be transferred depending on any of the cases listed above. To those having the status of a “Foreign Country Where the Data Controller Undertaking Adequate Protection Is Located”, where adequate protection is not available and the data controllers in Türkiye and the foreign country undertake adequate protection in writing and the Board has granted permission, personal data may be transferred according to the conditions prescribed in the legislation.

ii. Transfer of Special Categories of Personal Data

Special categories of personal data may, in accordance with the principles set out in the Policy and the methods to be determined by the Board, including by taking all necessary administrative and technical measures, be transferred under the conditions specified below:

  1. Special categories of personal data other than health and sexual life, where there is an explicit provision in the laws regarding the processing of personal data, without seeking the explicit consent of the data subject; otherwise, where the explicit consent of the data subject is obtained.
  2. Special categories of personal data relating to health and sexual life, for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and management of health services and their financing, without seeking explicit consent by persons under an obligation of confidentiality or by authorized institutions and organizations; otherwise, where the explicit consent of the data subject is obtained.

Personal data may be transferred to those having the status of a “Foreign Country with Adequate Protection” if any of the above conditions is present, and where adequate protection is not available, to those having the status of a “Foreign Country Where the Data Controller Undertaking Adequate Protection Is Located” according to the data transfer conditions regulated in the legislation, personal data may be transferred.

4. PERSONAL DATA INVENTORY PARAMETERS

In the COMPANY's management, human resources, administrative affairs, financial affairs (accounting-finance), planning-logistics-information technology, production, product development-quality, R&D marketing-sales, and purchasing business processes, data categories and personal data belonging to personal data subjects consisting of employee candidates, employees, shareholders/partners, potential product or service recipients, interns, supplier representatives, persons receiving products or services, parents/guardians/representatives, and visitors (Annex-1), are processed depending on personal data processing purposes (Annex-2) . Details of processing purposes according to data categories and groups of persons who are the subjects of data are declared in the COMPANY's area at https://verbis.kvkk.gov.tr/.

Personal data processing purposes are determined according to personal data categories, in order to inform relevant persons pursuant to Article 10 of the Law and other legislation, based on and limited to at least one of the personal data processing conditions specified in Articles 5 and 6 of the Law, and to carry out processing in accordance with the general principles specified in the Law, in particular the principles set out in Article 4 of the Law regarding the processing of personal data.

Personal data may be shared, in accordance with the principles set out in the Policy section “3.5. Transfer of Personal Data”, with natural persons or private-law legal entities, shareholders, business partners, affiliates and subsidiaries, suppliers, authorized public institutions and organizations, private insurance companies, auditors, consultants, organizations from which we receive contracted services, organizations with which we cooperate, and domestic organizations, for the specified purposes (Annex-3) . There is no transfer of personal information to foreign countries.

5. MEASURES TAKEN FOR THE PROTECTION OF PERSONAL DATA

The COMPANY takes the necessary technical and administrative measures to protect the personal data it processes in accordance with the procedures and principles set out in the Law, carries out the necessary audits in this context, and conducts awareness-raising and training activities.

If the processed personal data are obtained by third parties through unlawful means despite all technical and administrative measures having been taken, the COMPANY notifies the relevant persons and units of this situation as soon as possible.

6. STORAGE AND DESTRUCTION OF PERSONAL DATA

The COMPANY retains personal data for the period necessary for the purpose of processing and at least for the period prescribed in the relevant legislation. If a period is specified in the relevant legislation, the COMPANY first retains the personal data in accordance with that period; if no legal period is prescribed, it retains personal data for the period necessary for the purpose of processing. At the end of the specified retention periods, personal data are destroyed by the specified method (deletion, destruction or anonymization) in accordance with periodic destruction periods or the data subject's application.

7. RIGHTS OF PERSONAL DATA SUBJECTS AND EXERCISE OF THESE RIGHTS

7.1. Rights of the Personal Data Subject

Personal data subjects have the following rights arising from the Law:

  1. To learn whether personal data are processed,
  2. To request information if personal data have been processed,
  3. To learn the purpose of processing personal data and whether they are used in accordance with their purpose,
  4. To know the third parties to whom personal data are transferred domestically or abroad,
  5. To request correction if personal data have been processed incompletely or incorrectly and to request notification of the transaction carried out within this scope to third parties to whom the personal data have been transferred,
  6. Although processed in accordance with the Law and other relevant provisions of law, to request deletion or destruction of personal data if the reasons requiring their processing cease to exist and to request notification of the transaction carried out within this scope to third parties to whom the personal data have been transferred,
  7. To object to the emergence of a result against the person by analyzing the processed data exclusively through automated systems,
  8. To request compensation for damage in case of suffering damage due to the unlawful processing of personal data.

7.2. Exercise of the Rights of the Personal Data Subject

Personal data subjects may submit their requests regarding the rights listed in Article 6.1 to the COMPANY by the methods determined by the Board. Personal data subjects and those who have the right to apply on their behalf may apply to the COMPANY by completing the “Data Subject Application Form” (Annex-4).

7.3. Responding to Applications

The COMPANY concludes applications made by the personal data subject in accordance with the Law and other legislation. Requests duly submitted to the COMPANY are concluded free of charge as soon as possible and no later than 30 (thirty) days. However, if the transaction requires an additional cost, a fee may be charged according to the tariff determined by the Board.

7.4. Rejection of the Personal Data Subject's Application

The COMPANY may reject the request of the applicant by explaining the reason in the following cases:

  1. Processing personal data for purposes such as research, planning and statistics by anonymizing them with official statistics,
  2. Processing personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that it does not violate national defense, national security, public security, public order, economic security, privacy or personal rights, or constitute a crime,
  3. Processing personal data within the scope of preventive, protective and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public security, public order or economic security,
  4. Processing personal data by judicial authorities or enforcement authorities in relation to investigation, prosecution, trial or execution proceedings,
  5. Processing of personal data being necessary for the prevention of crime or criminal investigation,
  6. Processing personal data made public by the personal data subject,
  7. Processing of personal data being necessary for the performance of supervisory or regulatory duties and for disciplinary investigation or prosecution by authorized public institutions and organizations and professional organizations with public institution status, based on authority granted by law,
  8. Processing of personal data being necessary for the protection of the economic and financial interests of the State in relation to budgetary, tax and financial matters,
  9. The personal data subject's request being likely to hinder the rights and freedoms of other persons,
  10. Requests having been made that require disproportionate effort,
  11. The requested information being publicly available information.

7.5. Right of the Personal Data Subject to Lodge a Complaint with the KVK Board

Pursuant to Article 14 of the Law, in cases where the application is rejected, the response is found insufficient or no response is given to the application within the prescribed period, a complaint may be lodged with the Board within thirty days from the date the COMPANY's response is learned and in any case within sixty days from the date of application.

7.6. Information That May Be Requested from the Applying Personal Data Subject

The COMPANY may request information from the relevant person in order to determine whether the applicant is the personal data subject. The COMPANY may ask the personal data subject questions regarding the application in order to clarify the matters included in the personal data subject's application.

8. IMPLEMENTATION

The Policy has been approved by the Board of Directors and put into effect. The technical implementation of the Policy is ensured by the “Personal Data Retention and Destruction Policy” (Annex-5).

In business processes, the implementation of the Policy before the parties is carried out through the “Customer Disclosure Text and Explicit Consent Statement” (Annex-6), “Supplier Confidentiality Undertaking, Supplier Disclosure Text and Explicit Consent Statement” (Annex-7) “Employee Disclosure Text and Explicit Consent Statement” (Annex-8), “Employee Candidate Disclosure Text and Explicit Consent Statement” (Annex-9), “Website Cookie Disclosure Text” (Annex-10), “Camera Disclosure Text and Explicit Consent Statement” (Annex-11) .

The Board of Directors is responsible for the implementation of the Law and the Policy and for updating them when necessary, and the COMPANY Personal Data Protection Committee is responsible for monitoring, coordinating and auditing all business and operations within this scope.

9. EFFECTIVE DATE AND ANNOUNCEMENT

The Policy entered into force as of its publication date. Changes to the Policy are published on the COMPANY's website (www.akcmakine.com.tr) and made accessible to personal data subjects and relevant persons. Policy changes enter into force on the date they are announced.

ANNEXES

Annex 1- Data Categories and Personal Data

Annex 2- Personal Data Processing Purposes

Annex 3- Persons to Whom Personal Data Are Transferred and Purposes of Transfer

Annex 4- Personal Data Subject Application Form

Annex 5- Personal Data Retention and Destruction Policy

Annex 6- Customer Disclosure Text on Processing Personal Data

Annex 7- Supplier Confidentiality and Personal Data Protection Agreement, Disclosure Text and Explicit Consent Statement

Annex 8- Employee Disclosure Text and Explicit Consent Statement

Annex 9- Employee Candidate Disclosure Text and Explicit Consent Statement

Annex 10- Website Cookie Disclosure Text

Annex 11- Camera Disclosure Text and Explicit Consent Statement

 

ANNEX 1- Data Categories and Personal Data

Data Categories Personal Data
Identity Name, Surname
Mother's- Father's Name
Date of Birth
Place of Birth
Marital Status
Identity Card Serial Sequence No
Turkish Republic Identity No
Passport Number
Temporary Turkish Republic Identity Number
Gender Information
Turkish Republic Identity Card
Driver's License
Contact Address
Email Address
Contact Address
Registered Electronic Mail Address (KEP)
Phone No
Personnel Payroll Information
Disciplinary Investigation
Employment Entry- Exit Document Records
Curriculum Vitae Information
Performance Evaluation Reports
Legal Transaction Information in correspondence with judicial authorities, information in case files, etc.
Customer Transaction Invoice
Promissory Note
Cheque Information
Entry-Exit Information
Order Information
Appointment Information
Physical Space Security Employee and Visitor Entry and Exit Record Information
Camera Records
Transaction Security Transaction Security (such as IP address information, website login/logout information, password and passcode information)
IP Address Information
Website Login and Logout Information
Password and Passcode Information
Risk Management Information processed for the management of commercial, technical and administrative risks, etc.
Finance Balance Sheet Information
Financial Performance Information
Credit and Risk Information
Bank Account Number
IBAN Number
Professional Experience Diploma Information
Courses Attended
In-Service Training Information
Certificates
Marketing Shopping History Information
Cookie Records
Information Obtained Through Campaign Activities
Visual and Audio Records Closed-Circuit Camera System Image, Audio Recording
Health Information Information Regarding Disability Status
Blood Group Information
Personal Health Information
Information on Devices and Prostheses Used
Laboratory and Imaging Results
Test Results
Examination Data
Prescription Information
Criminal Convictions and Security Measures Information Regarding Criminal Convictions
Information Regarding Security Measures
Family Information Number of Children
Family Record Book
Spouse Employment Information
Children's Education and Age Information
Request/Complaint Management Information Information Regarding Requests and Complaints

ANNEX 2- Categorical Personal Data Processing Purposes

Conducting Emergency Management Processes
Conducting Information Security Processes
Conducting Employee Candidate / Intern / Student Selection and Placement Processes
Conducting Employee Candidate Application Processes
Conducting Employee Satisfaction and Commitment Processes
Fulfilling Obligations Arising from Employment Contracts and Legislation for Employees
Conducting Fringe Benefits and Benefits Processes for Employees
Conducting Audit / Ethics Activities
Conducting Training Activities
Conducting Access Authorization Processes
Conducting Activities in Compliance with Legislation
Conducting Finance and Accounting Affairs
Conducting Company / Product / Service Loyalty Processes
Ensuring Physical Space Security
Conducting Assignment Processes
Monitoring and Conducting Legal Affairs
Conducting Internal Audit / Investigation / Intelligence Activities
Conducting Communication Activities
Planning Human Resources Processes
Conducting / Auditing Business Activities
Conducting Occupational Health / Safety Activities
Receiving and Evaluating Suggestions for Improving Business Processes
Conducting Business Continuity Activities
Conducting Logistics Activities
Conducting Goods / Service Procurement Processes
Conducting Goods / Service After-Sales Support Services
Conducting Goods / Service Sales Processes
Conducting Goods / Service Production and Operation Processes
Conducting Customer Relationship Management Processes
Conducting Activities for Customer Satisfaction
Organization and Event Management
Conducting Marketing Analysis Activities
Conducting Performance Evaluation Processes
Conducting Advertising / Campaign / Promotion Processes
Conducting Risk Management Processes
Conducting Retention and Archive Activities
Conducting Contract Processes
Monitoring Requests / Complaints
Ensuring the Security of Movable Property and Resources
Conducting Supply Chain Management Processes
Conducting Remuneration Policy
Conducting Marketing Processes for Products / Services
Ensuring the Security of Data Controller Operations
Conducting Investment Processes
Conducting Talent / Career Development Activities
Providing Information to Authorized Persons, Institutions and Organizations
Conducting Management Activities
Creating and Monitoring Visitor Records
Managing Relations with Business Partners and Suppliers

ANNEX 3 –Persons to Whom Personal Data Are Transferred and Purposes of Transfer

In accordance with Articles 8 and 9 of the Law, the COMPANY may transfer the personal data of participants, customers and employees to the categories of persons listed below:

Persons to Whom Data May Be Transferred Persons

Definition

Purpose and Scope of Data Transfer

Natural persons or private-law legal entities

Natural or legal persons with whom the COMPANY has relations or carries out transactions due to its activities

Limited to the business and transaction carried out

Business Partners

Business partners and partner banks with which the COMPANY has relations for purposes such as promotion and marketing of its products and services and after-sales support

Limited to the purposes and activities of establishing and conducting the business partnership

Authorized Public Institutions and Organizations

Public institutions and organizations, such as the Social Security Institution and Tax Offices, authorized to obtain information and documents from the COMPANY according to the provisions of the relevant legislation

Limited to the purpose requested based on the legal authority of the relevant public institutions and organizations

Private-Law Persons Authorized by Law

Institutions or organizations established in accordance with certain conditions pursuant to the provisions of the relevant legislation and continuing their activities within this framework

Limited to matters falling within the areas of activity they conduct

Supplier

Parties providing services to the COMPANY in line with data processing purposes and requests

Limited to the purpose of procuring goods and services for the COMPANY to carry out its outsourced commercial activities