PERSONAL DATA DESTRUCTION POLICY
Within our company, the months of January and July of the year have been designated as destruction periods for the destruction of data. Personal data obtained from data subjects will be deleted, destroyed or anonymized by the personnel responsible for the protection of data within the company during the destruction period following the end of the retention periods. The records relating to the destruction process will be kept for a period of 3 (three) years in an independent location by the personnel responsible for the protection of data within the company. After three years, the records in question will also be destroyed. Regarding the destruction process, the provisions of the Regulation on the Deletion, Destruction or Anonymization of Personal Data dated 28 October 2017 and numbered 30224, and of Law No. 6698 on the Protection of Personal Data, will be taken as the basis.
The reasons requiring destruction are as follows:
• The amendment or repeal of the relevant legislative provisions that form the basis for its processing,
• The elimination of the purpose requiring its processing or retention,
• In cases where the processing of personal data is carried out solely on the basis of the explicit consent condition, the data subject withdrawing their explicit consent,
• The acceptance by the Authority of the application made by the data subject regarding the deletion and destruction of their personal data within the framework of their rights pursuant to Article 11 of the Law,
• In cases where the Authority rejects the application made to it by the data subject requesting the deletion, destruction or anonymization of their personal data, finds its response inadequate, or does not respond within the period foreseen in the Law; the data subject filing a complaint with the Board and this request being found appropriate by the Board,
• The expiry of the maximum period requiring the retention of personal data and the absence of any condition that would justify retaining the personal data for a longer period.
For the secure retention of personal data, the prevention of its unlawful processing and access, and the lawful destruction of personal data, technical and administrative measures are taken by the Company within the framework of the adequate measures determined and announced by the Board for special categories of personal data pursuant to Article 12 of the Law and the fourth paragraph of Article 6 of the Law.
The technical measures taken by the Company regarding the personal data it processes are listed below:
• Through penetration tests, the risks, threats, vulnerabilities and, if any, weaknesses concerning our Company’s information systems are revealed and the necessary measures are taken.
• Through information security incident management, the risks and threats that would affect the continuity of information systems are continuously monitored as a result of real-time analyses.
• Access to information systems and the authorization of users is carried out through the access and authorization matrix and through security policies via the corporate active directory.
• The necessary measures are taken for the physical security of the Company’s information systems equipment, software and data.
• In order to ensure the security of information systems against environmental threats, hardware measures (an access control system allowing only authorized personnel to enter the system room, a 24/7 monitoring system, ensuring the physical security of the edge switches forming the local area network, a fire suppression system, an air conditioning system, etc.) and software measures (firewalls, attack prevention systems, network access control, systems that block malicious software, etc.) are taken.
• Risks aimed at preventing the unlawful processing of personal data are determined, technical measures appropriate to these risks are ensured to be taken, and technical controls are carried out for the measures taken.
• By establishing access procedures within the Company, reporting and analysis work regarding access to personal data is carried out.
• Accesses to the storage areas where personal data is located are recorded and inappropriate accesses or access attempts are kept under control.
• The Company takes the necessary measures to ensure that deleted personal data is inaccessible and non-reusable for the relevant users.
• In the event that personal data is unlawfully obtained by others, an appropriate system and infrastructure has been established by the Company to report this situation to the data subject and the Board.
• By following security vulnerabilities, appropriate security patches are installed and information systems are kept up to date.
• Strong passwords are used in the electronic environments where personal data is processed.
• Secure record-keeping (logging) systems are used in the electronic environments where personal data is processed.
• Data backup programs that ensure the secure retention of personal data are used.
• Access to personal data stored in electronic or non-electronic environments is limited according to access principles.
• Access to the Company’s website is encrypted with the SHA 256 Bit RSA algorithm using a secure protocol (HTTPS).
• A separate policy has been determined for the security of special categories of personal data.
• Training on the security of special categories of personal data has been provided to employees involved in special-category personal data processing processes, confidentiality agreements have been made, and the authorizations of users who have access authorization to the data have been defined.
• The electronic environments where special categories of personal data are processed, retained and/or accessed are maintained using cryptographic methods, cryptographic keys are kept in secure environments, all transaction records are logged, the security updates of the environments are continuously monitored, the necessary security tests are conducted/caused to be conducted regularly, and the test results are recorded.
• Adequate security measures are taken for the physical environments where special categories of personal data are processed, retained and/or accessed, and by ensuring physical security, unauthorized entries and exits are prevented.
• If special categories of personal data need to be transferred by e-mail, they are transferred in encrypted form using a corporate e-mail address or a KEP (registered electronic mail) account. If they need to be transferred via media such as portable memory, CD, or DVD, they are encrypted with cryptographic methods and the cryptographic key is kept in a different environment. If transfer is carried out between servers in different physical environments, data transfer is performed by establishing a VPN between the servers or via the sFTP method. If transfer via paper is required, the necessary measures are taken against risks such as the theft, loss or viewing by unauthorized persons of the documents, and the documents are sent in “confidential” format.
• The company will specify which of these items it is able to carry out.
The administrative measures taken by the Company regarding the personal data it processes are listed below:
• Training is provided to improve the qualifications of employees, on the prevention of the unlawful processing of personal data, the prevention of unlawful access to personal data, ensuring the safeguarding of personal data, communication techniques, technical knowledge and skills, the Labour Law and other relevant legislation.
• Employees are made to sign confidentiality agreements regarding the activities carried out by the Company.
• A disciplinary procedure to be applied to employees who do not comply with the security policies and procedures has been prepared.
• Before starting to process personal data, the obligation to inform the data subjects is fulfilled by the Company.
• A personal data processing inventory has been prepared.
• Periodic and random internal audits are carried out within the Company.
• Information security training is provided to employees.
Upon the expiry of the legal periods, personal data is destroyed either upon the request of the data subject or ex officio by the company in the following ways.
| DATA RECORDING MEDIUM | DESCRIPTION |
| Personal Data Located on Servers | For personal data located on servers for which the period requiring retention has ended, the deletion process is carried out by the system administrator by removing the access authorization of the relevant users. |
| Personal Data Located in Electronic Media | Personal data located in electronic media for which the period requiring retention has ended is made inaccessible and non-reusable in any way for employees (relevant users) other than the database administrator. |
| Personal Data Located in Physical Media | Personal data kept in physical media for which the period requiring retention has ended is made inaccessible and non-reusable in any way for employees other than the unit manager responsible for the document archive. In addition, a blackout process is applied by scratching/painting/erasing it so that it cannot be read. |
| Personal Data Located on Portable Media | Personal data kept on flash-based storage media for which the period requiring retention has ended is encrypted by the system administrator and, with access authorization granted only to the system administrator, is kept in secure environments together with the encryption keys. |
| Personal Data Located in Physical Media | Personal data located in paper media for which the period requiring retention has ended is destroyed irreversibly in paper shredding machines. |
| Personal Data Located on Optical / Magnetic Media | Personal data located on optical media and magnetic media for which the period requiring retention has ended undergoes a physical destruction process such as melting, burning or pulverizing. In addition, the magnetic media is passed through a special device and exposed to a high-value magnetic field, thereby rendering the data on it unreadable. |
Personal data to be obtained from employees is retained and destroyed at different time periods according to its nature. The retention periods for this data are as follows. Those for which the retention periods have expired are destroyed within the nearest destruction period, and the records relating to the destruction are kept for a period of 3 years.
| PERSONAL DATA | RETENTION PERIOD |
| Recruitment documents and personnel data forming the basis for the notifications made to the Social Security Institution regarding the term of service and wages | Retained for a period of 15 (fifteen) years both during the continuation of the service contract and from its termination. |
| Personnel data other than the recruitment documents and the personnel data forming the basis for the notifications made to the Social Security Institution regarding the term of service and wages | Retained for a period of 10 (ten) years both during the continuation of the service contract and from the beginning of the calendar year following its termination. |
| Customer Information | Pursuant to Article 82 of the Turkish Commercial Code, the information forming the basis for the issuance of invoices that constitute the basis for commercial books and records is retained for a period of 10 years as required by the said article of the law, while Customer Information other than this is retained for the period necessary for the purpose for which it is processed. |
| Contracts forming the basis of the commercial relationship and data relating to them | 10 years pursuant to the provisions of the Code of Obligations No. 6098 and other legislation. |
| Employees’ Personal Health Files | According to the Occupational Health and Safety legislation, personal health files must be retained for 15 years. |
| Job Candidate Information | Retained for a maximum of 2 years, until it becomes outdated. |
| Visitor Information | Retained for a period of 2 years. |
| Business Partner and Consultant Information | Retained for a period of 10 years during the relationship with the Company and from its termination, pursuant to Article 146 of the Turkish Code of Obligations. |
| Information Shared with the Company by Firms | Retained for a period of 10 years during the relationship with the Company and from its termination, pursuant to Article 146 of the Turkish Code of Obligations. |
| Customer | Retained for a period of 10 years from the provision of each product/service purchased by the Customer, pursuant to Article 146 of the Turkish Code of Obligations and Article 82 of the Turkish Commercial Code. |
| Customer/Potential Customer Requests and Complaints | Retained for a period of 10 years from the date of the request and/or complaint. |
| The relevant personal data being the subject of a crime within the scope of the Turkish Penal Code or other legislation introducing penal provisions | For the duration of the statute of limitations for the lawsuit. |
| Log Record Tracking Systems | 10 years |
| Execution of Hardware and Software Access Processes | 2 Years |
| Records of Visitors and Meeting Participants | If there is no contractual relationship, 2 years from the end of the event. |
| Information of non-employee trainees and interns | During their training and other activities with the Company and 1 year from the termination of their relationships. |
| Personal data obtained from job candidates | Until the nearest destruction period in the event that the candidacy application results negatively. |
When the data subject, pursuant to Article 13 of the Law, applies to …………….. the company and requests the deletion or destruction of their personal data;
1- If all of the conditions for processing personal data have been eliminated; the Company deletes, destroys or anonymizes the personal data subject to the request within 30 (thirty) days from the day it receives the request, by explaining its justification and using an appropriate destruction method. For the Company to be deemed to have received the request, the data subject must have made their request in accordance with the Personal Data Processing and Protection Policy. In any case, the Company informs the data subject about the process carried out.
2- If not all of the conditions for processing personal data have been eliminated, this request may be rejected by the Company by explaining its justification pursuant to the third paragraph of Article 13 of the Law, and the rejection response is notified to the data subject in writing or electronically within thirty days at the latest. The data subject’s right to complain to the Authority is reserved. In this context, data subjects may apply to the Board within 60 (sixty) days from learning that their requests have been rejected.
3- Within this framework, applications to be made to our Company “in writing”,
• By the personal application of the Applicant,
• Through a notary,
• Signed by the Applicant with the “secure electronic signature” defined in the Electronic Signature Law No. 5070
may be transmitted to us by being sent to the Company’s registered electronic mail address. Our contact information for exercising this right is as follows:
Company Name: Mutlucan Tuz Madencilik İnş.Tur.Otom.Pet.Nak.San. ve Tic. Aş
Mersis no: 0626034057400018
E-mail address: info@mutlucantuz.com.tr
Postal Address: Mustafa Kemal Mahallesi 2118. Cad. C Blok No:4 C/175 Çankaya/ANKARA

