EMPLOYEE PRIVACY NOTICE
As the data controller Mutlucan Tuz Madencilik İnş.Tur.Otom.Pet.Nak.San. ve Tic. Aş., all kinds of personal data processed within our company are protected under the provisions of relevant national and international legislation, primarily Law No. 6698 on the Protection of Personal Data. In order to ensure the necessary protection, our Company takes the technical and administrative measures in a timely and proper manner, and, in the event of any suspicion of a breach, promptly makes the necessary notifications to the relevant individuals, institutions and organizations within the framework of the legal provisions.
A. THE CONCEPT OF PERSONAL DATA AND EXPLANATIONS ON THE DEVELOPMENT OF THIS CONCEPT
Personal data may be defined as any kind of information suitable for making the identity of individuals identifiable. In this context, a person’s identity, contact, health and financial information, as well as information relating to their private life, religious belief and political opinion, are characterized as personal data. For example; name, surname, date of birth, mobile phone number, e-mail, gender, address, occupation, education, place and time of shopping, how much they paid, which campaign they benefited from, the amount of discount they received, product information in their purchase, browsing and click information on the application, location information from where they opened the application, etc.
Today, these data are frequently used through automated means over information systems by both the private sector and the public sector. Although the use of this information provides certain conveniences or advantages for individuals as well as for those who offer goods and services, this situation also brings with it the risk of misuse of the said information. The obtaining, use and disclosure of these data by unauthorized persons constitute a violation of the fundamental rights protected both by the contracts to which we are party and by our Constitution. A reasonable balance must be established between these two interests. The absence of a special law and an effective supervisory mechanism regarding the processing of personal data gives rise to a negative perception in our society. In order to eliminate this perception, it is necessary to determine the principles relating to the processing, retention and control of personal data under certain conditions.
In our age, in parallel with the development of awareness of the protection of human rights, the importance of the protection of personal data is also increasing day by day. For this reason, it is seen that detailed legal regulations in the field of the protection of personal data are being implemented in developed countries today.
On the other hand, in our country, there is no law that comprehensively regulates the field relating to the protection of personal data; provisions concerning this matter are found in different laws. Furthermore, there is no institution in our country to control and supervise the process of processing personal data. As a result of this, personal data can still be used by many persons or institutions without being subject to adequate regulation and supervision, and this situation may cause certain violations of rights to occur.
There are various reasons requiring the entry into force of a law that will ensure the protection of personal data in our country. First of all, in Article 135 and the following articles of the Turkish Penal Code No. 5237, the acts of obtaining, recording or disclosing personal data unlawfully are regulated as offences and subjected to sanctions. However, due to the absence of a special law regarding the processing of personal data, it is seen that hesitations arise in determining when these acts are unlawful and when they are lawful.
On the other hand, with the regulation made in Article 20 of the Constitution by Law No. 5982, which was adopted as a result of the referendum held on 12 September 2010, the protection of personal data was guaranteed as a fundamental human right and it was envisaged that the details would be regulated by law.
Again, in the European Union full membership process that is still ongoing with regard to our country, four of the negotiation chapters are directly related to personal data. In order for the process regarding these chapters to advance, a fundamental law on the protection of personal data must enter into force in our country.
The subject of the protection of personal data began to appear in international documents from the 1980s onwards. Firstly, the “Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data” were adopted on 23/9/1980 by the Organisation for Economic Co-operation and Development (OECD), of which our country is also a member. Convention No. 108, the “Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data”, prepared by the Council of Europe with the aim of protecting personal data at the same standards in all member states and determining the principles of transborder data flow, was opened for signature on 28 January 1981 and was also signed by our country.
The Council of Europe has also adopted recommendations determining the principles to be applied in various sectors such as medical data banks, scientific research and statistics, direct marketing, social security, insurance, police records, employment, electronic payment, telecommunications and the internet, aimed at the protection of personal data. While these recommendations were taken into account during the preparation of the Draft, the “framework draft” nature of the Draft was preserved. Considering that the volume of the Draft would expand greatly if regulations relating to all sectors were included, the said recommendations were not incorporated into the Draft. It was assessed that the principles contained in these recommendations could be included in the regulations to be made regarding various sectors in the future.
On the other hand, the European Union, in order to ensure harmonization among the legislation of the member states regarding the protection of personal data, put into force on 24/10/1995 the “Directive on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of Such Data” (95/46/EC). With this Directive, it was aimed to make a clear and permanent regulation that would ensure the protection of the personal data of individuals in the member states at the highest level and the free movement of personal data within the European Union. When the international documents on the protection of personal data are taken into consideration, it is seen that, in the law to be prepared regarding this matter, the conditions for processing personal data, the informing of individuals, the establishment of an authority that will supervise and regulate this field, and the taking of the necessary measures regarding data security are accepted as fundamental principles.
Faced with the fact that the said DPD and the earlier treaties and directives were inadequate in the face of current events, and that the treaties and directives signed from country to country differed, agreement was reached on 15 December 2011 on a reform that would cover the entire EU. In this context, the GDPR, prepared in 2012, was adopted by the EU Parliament on 14 April 2016. While Article 94 of the GDPR repealed the 95/46 DPD, it expanded the scope of application of the 2002/58/EC Electronic Data Protection Directive.
With the constitutional amendment made in 2010 by Law No. 5982, an additional paragraph was added to Article 20 of the Constitution. In the said paragraph, the following provision was included: “Everyone has the right to request the protection of personal data concerning them. This right includes being informed about personal data concerning oneself, accessing such data, requesting their correction or deletion, and learning whether they are used in accordance with their purposes. Personal data may only be processed in the cases envisaged by law or with the explicit consent of the person. The principles and procedures relating to the protection of personal data are regulated by law.”
The Constitution also states that detailed regulations regarding the protection of personal data will be made by law. In this context, the “Draft Law on the Protection of Personal Data” was submitted to the Presidency of the Grand National Assembly of Türkiye on 26 December 2014. The Draft became law on 24 March 2016, and the Law No. 6698 on the Protection of Personal Data entered into force upon its publication in the Official Gazette dated 7 April 2016 and numbered 29677.
With the Draft prepared by taking into account international documents, comparative law practices and the needs of our country, it is aimed to process and protect personal data at contemporary standards.
B. THE PROCESSING OF PERSONAL DATA AND THE FUNDAMENTAL PRINCIPLES GOVERNING DATA PROCESSING
Any kind of operation performed on data, such as obtaining, recording, storing, retaining, altering, rearranging, disclosing, transferring, taking over, making obtainable, classifying or preventing the use of personal data by fully or partially automated means or by non-automated means provided that it is part of any data recording system, is accepted as the processing of personal data. Any kind of activity carried out in the process from the collection of personal data in the specified manner up to the operations of deletion, destruction or anonymization is evaluated as the processing of personal data within the scope of the Law.
Your personal data are processed within the scope of the provisions of other laws, primarily the Labour Law No. 4857, the Law No. 6698 on the Protection of Personal Data, the Turkish Code of Obligations No. 6098, the Social Insurance and General Health Insurance Law No. 5510, and the Occupational Health and Safety Law No. 6331, in connection with the requirements of the commercial activity within our company, the order of the workplace and the general functioning. The said data are obtained from information within the scope of the employment contract, commercial contracts and other contractual relationships, the party’s personnel file, the information and documents submitted by you, as well as information and documents legally obtained from the relevant institutions or notified to us by such institutions. Again, the said data are processed within legal frameworks, limited to their exclusive purposes, by the data processors under the supervision and responsibility of our data controller Company, namely the personnel of Human Resources, the Data Protection Unit (DPO), the Call Centre, Accounting, Information Technology, Support Services and other service unit/units. Again, the processing of data limited to the purpose in line with the requirements of the work and legal requirements may also be carried out by the institution’s doctor and lawyer/lawyers.
There are fundamental principles relating to the processing of personal data that have been accepted in international documents and reflected in the practices of many countries. In Article 4 of the Law on the Protection of Personal Data, the procedures and principles relating to the processing of personal data have been regulated in parallel with Convention No. 108 and European Union Directive No. 95/46/EC. Accordingly, the general (fundamental) principles listed in the Law regarding the processing of personal data are as follows:
• Being in compliance with the law and the rules of good faith,
• Being accurate and, where necessary, up to date,
• Being processed for specific, explicit and legitimate purposes,
• Being relevant, limited and proportionate to the purposes for which they are processed,
• Being retained for the period envisaged in the relevant legislation or necessary for the purpose for which they are processed.
The principles relating to the processing of personal data must lie at the core of all personal data processing activities, and all personal data processing activities must be carried out in accordance with these principles. Centred on the above principles, we take the technical, legal and administrative measures necessary for the protection of data. In this context, the necessary work has been carried out within our company, and the said activities are updated in line with the decisions of the General Assembly of the Personal Data Protection Authority and legislative amendments.
C. THE CONDITIONS FOR PROCESSING PERSONAL DATA
The processing of personal data is defined as follows in subparagraph 3/e of Law No. 6698:
“Processing of personal data: any operation performed on data, such as obtaining, recording, storing, retaining, altering, rearranging, disclosing, transferring, taking over, making obtainable, classifying or preventing the use of personal data by fully or partially automated means or by non-automated means provided that it is part of any data recording system,”
The manner in which the said information of a personal data nature will be processed is expressed as follows in Article 5 of the same law:
“Conditions for processing personal data ARTICLE 5-
(1) Personal data cannot be processed without the explicit consent of the data subject.
(2) In the presence of one of the following conditions, it is possible to process personal data without seeking the explicit consent of the data subject:
a) Being expressly provided for by the laws.
b) Being necessary for the protection of the life or physical integrity of the person themselves or of another person who is unable to express their consent due to actual impossibility or whose consent is not legally valid.
c) Being necessary to process the personal data of the parties to a contract, provided that it is directly related to the establishment or performance of the contract.
ç) Being mandatory for the data controller to fulfil its legal obligation.
d) Having been made public by the data subject themselves.
e) Data processing being mandatory for the establishment, exercise or protection of a right.
f) Data processing being mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.”
D. SPECIAL CATEGORIES OF PERSONAL DATA AND THE CONDITIONS FOR THEIR PROCESSING
Some data are, by their nature and character, more indispensable compared to other personal rights. For this reason, the protection and processing of these rights are regulated separately and together with strict formal conditions within the scope of the said law. Special categories of personal rights are defined and listed as follows in paragraph 6/1 of the law:
“Data relating to persons’ race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and attire, membership of an association, foundation or trade union, health, sexual life, criminal convictions and security measures, as well as their biometric and genetic data, are special categories of personal data.”
The manner in which the said rights may be processed is expressed as follows in the other paragraphs of the same article:
” (2) It is prohibited to process special categories of personal data without the explicit consent of the person concerned.
3) Personal data listed in the first paragraph, other than those relating to health and sexual life, may be processed without seeking the explicit consent of the data subject in the cases envisaged by the laws. Personal data relating to health and sexual life, however, may only be processed without seeking the explicit consent of the person concerned by persons under an obligation of confidentiality or authorized institutions and organizations, for the purposes of the protection of public health, preventive medicine, medical diagnosis, the conduct of treatment and care services, and the planning and management of health services and their financing.
(4) In the processing of special categories of personal data, it is also mandatory to take the adequate measures determined by the Board.”
The processing of some of the special categories of personal data by non-profit organizations or formations such as political parties, foundations, associations or trade unions is regulated. Accordingly, these organizations and formations may process the special categories of data of their own members and affiliates, provided that it is in compliance with their purposes of establishment and the legislation to which they are subject, limited to their fields of activity and not disclosed to third parties. For example, the keeping of the identity and contact information of the members of a political party or trade union under the conditions specified in the paragraph will be evaluated within the scope of this subparagraph. These organizations will be able to process special categories of data only limited to their own fields of activity. For example, a trade union will be able to process only the data related to trade union membership relating to its own field of activity and purpose. On the other hand, it will not be able to process the personal data of members relating to health or religion or sect, since these are not related to its field of activity and purpose.
Special categories of personal data that have been made public by the data subject themselves may be processed. This is because, in the processing of such data made public by the data subject and thus known to everyone, it is accepted that the legal interest that needs to be protected has ceased to exist.
In the event that the processing of special categories of personal data is mandatory for the establishment, exercise or protection of a right, the said data may be processed even without consent. For example, an employer’s processing of reports and documents relating to persons employed in this status within the scope of the obligation to employ disabled persons at the workplace will be evaluated within this scope. Likewise, the obtaining and processing by the tax office of the health reports relating to the disability of a disabled person, so that they may benefit from the right to purchase a specially equipped vehicle exempt from special consumption tax, will also be evaluated within the scope of this subparagraph.
E. DEFINITIONS
Explicit consent is defined by taking into account Directive No. 95/46/EC. Accordingly, explicit consent should be understood as a declaration of consent given by the data subject regarding the processing of data concerning them, freely, on the basis of adequate information about the subject, with a clarity that leaves no room for doubt, and limited only to that operation.
Anonymization of personal data refers to making data such that they can under no circumstances be associated with an identified or identifiable natural person, even by matching them with other data. In this context, if it can be understood to whom the data belong after tracing over the remaining data and matching and supplementing it with other data, this data cannot be accepted as having been anonymized.
Data recording system refers to the recording system in which personal data are processed by being structured according to certain criteria. These systems may be created in an electronic or physical environment. Accordingly, in the data recording system, personal data may be classified by name, surname or identity number, and a classification to be created regarding those who do not pay their credit debts will also be evaluated within this scope.
The data controller is the person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system. These persons may be natural persons, as well as legal persons such as public institutions, companies, associations or foundations. Within the scope of this privacy notice, it refers to the company Mutlucan Tuz Madencilik İnş.Tur.Otom.Pet.Nak.San. ve Tic. Aş.
The data processor is the natural and legal person who processes data on behalf of the data controller. These persons may be employees who process personal data within the framework of the instructions given to them, as well as a separate natural or legal person determined by the data controller by procuring services. Any natural or legal person may be both a data controller and a data processor at the same time. For example, while an accounting firm is considered a data controller with regard to the data it keeps concerning its own personnel, it will be accepted as a data processor with regard to the data it keeps concerning its client companies.
The data subject refers to the natural person whose personal data are processed, that is, the employee within the scope of this contract.
Destruction refers to the deletion, destruction or anonymization of personal data.
F. THE RIGHTS OF THE EMPLOYEE AS A DATA SUBJECT
As the data controller company Mutlucan Tuz Madencilik İnş.Tur.Otom.Pet.Nak.San. ve Tic. Aş, our responsibilities towards employees and the rights of employees are as follows:
• Employees have the right to learn whether their personal data are being processed and, if so, in what manner and for how long they are being processed or will be processed,
• To request information regarding the processed personal data, if any,
• To learn the purpose of processing the personal data and whether these data are used in accordance with the purpose,
• To know the third parties to whom their personal data are transferred, to request the correction of errors in their personal data and, if a transfer has been made, to request that this correction be requested from the relevant third party,
• To request that complaints regarding personal data be remedied by way of objection before the institution, and, if the objection remains inconclusive or the request is rejected, to lodge a complaint with the Personal Data Protection Authority,
• To request the deletion, destruction or anonymization of these data in the event that the reasons requiring their processing cease to exist, and, if a transfer has been made, to request that this request be communicated to the third party to whom the transfer was made,
• To request that the periods relating to the destruction of personal data be notified to them and to request which data will be kept for how long,
• To object to an adverse outcome arising in relation to the person as a result of the processed data,
• Employees have the right to claim their damages within the framework of the laws in the event that damage arises due to unlawful data processing.
Data controllers must conclude, free of charge and as soon as possible and at the latest within thirty days according to their nature, the requests relating to the application of the Law submitted to them by data subjects in writing or by other methods to be determined by the Board. However, in the event that the operation additionally requires a cost, the data controller may request from the applicant data subject the fees in the tariff determined by the Board.
If the data controller accepts the request or rejects it by explaining the reason, it notifies this response to the data subject in writing or electronically. In the event that the request in the application is accepted, the requirement of this request is fulfilled by the data controller. In the event that the application arises from the fault of the data controller, the fee collected is refunded to the person concerned.
In the event that the application is rejected, the response given is found inadequate, or no response is given to the application within the period, the data subject may lodge a complaint with the Board within thirty days from the date on which they learned the response of the data controller and, in any case, within sixty days from the date of application.
For all your questions and opinions regarding your personal data, you can reach us at any time at our e-mail address info@mutlucantuz.com.tr and at our call centres via the telephone number 0312 323 71 48.
G. THE PERSONAL DATA REQUESTED AND THE WAYS IN WHICH THEY ARE RETAINED
As the data controller, it is necessary to obtain the following information from employees under the Labour Law, the employment contract made between us, and for the creation of your personnel file as a requirement of the work and for other reasons. The information and documents to be requested are as follows:
• Employment contract / regulations belonging to the enterprise
• Employment entry declaration
• Copy of identity card
• Certificate of residence
• Criminal record
• Health report
• Photograph
• Diploma and education documents
• Copies of the identity cards of spouse and children
• Periodic examination form
• Leave forms
• Documents relating to reports and incidents in which the employee is or has been involved
• Signed payrolls / account slips
• Contact information (e-mail, telephone, etc.) and the contact information of a relative for emergencies
• Other documents that may be requested as a requirement of the work
• Account information for payments
• Trade union information
Although the data requested vary according to the relationships that YOU / THE EMPLOYEE establish with our company, they may be categorized under headings as follows:
| Identity Information | Data which clearly belong to an identified or identifiable natural person; which are processed partially or fully automatically, or non-automatically as part of a data recording system; and which contain information concerning the person’s identity; information such as name-surname, Turkish ID number, nationality information, mother’s name-father’s name, place of birth, date of birth, gender, as well as documents such as driving licence, identity card and passport, and information such as tax number, social security number, signature information, vehicle plate, etc. |
| Contact Information | Data which clearly belong to an identified or identifiable natural person; which are processed partially or fully automatically, or non-automatically as part of a data recording system; information such as telephone number, address, e-mail address, fax number, IP address |
| Family Members and Relatives Information | Data which clearly belong to an identified or identifiable natural person; which are processed partially or fully automatically, or non-automatically as part of a data recording system; information about family members (e.g. spouse, mother, father, child), relatives and other persons who can be reached in emergencies, notified to our Company by the personal data owner within the framework of the operations carried out by our Company’s business units |
| Security Information | Data which clearly belong to an identified or identifiable natural person; which are processed partially or fully automatically, or non-automatically as part of a data recording system; personal data relating to records and documents taken upon entry to the Company headquarters, branches, sales offices and all kinds of facilities, and during the stay within these places; camera records, fingerprint records and records taken at the security point, etc. |
| Financial Information | Data which clearly belong to an identified or identifiable natural person; which are processed partially or fully automatically, or non-automatically as part of a data recording system; personal data processed relating to all kinds of financial information, documents and records created according to the type of legal relationship our Company has established with the personal data owner, as well as data such as bank account number, IBAN number, financial profile, asset data, income information |
| Visual/Audio Information | Data which clearly belong to an identified or identifiable natural person; which are processed partially or fully automatically, or non-automatically as part of a data recording system; photographs and camera records (excluding records falling within the scope of Security Information), audio records, and data contained in documents that are copies of documents containing personal data |
| Personnel Information | Data which clearly belong to an identified or identifiable natural person; which are processed partially or fully automatically, or non-automatically as part of a data recording system; all kinds of personal data processed for the purpose of obtaining information that will form the basis for the accrual of the personnel rights of natural persons who are in a working relationship with our Company |
| Special Categories of Personal Data | Data which clearly belong to an identified or identifiable natural person; which are processed partially or fully automatically, or non-automatically as part of a data recording system; the data specified in Article 6 of the KVKK (e.g. health data including blood type, biometric data, religion and information on the association of which the person is a member) |
| Request/Complaint Management Information | Data which clearly belong to an identified or identifiable natural person; which are processed partially or fully automatically, or non-automatically as part of a data recording system; personal data relating to the receipt and evaluation of all kinds of requests or complaints directed to our Company |
| Other |
This information and these documents will be protected within our company, and the ways in which they are protected and kept are as follows:3
| Electronic Environments | Non-Electronic Environments |
| Servers (domain, backup, e-mail, database, web, file sharing, etc.) Software (office software, portal, EBYS, VERBİS.) Information security devices (firewall, intrusion detection and prevention, log record file, antivirus, etc.) Personal computers (desktop, laptop) Mobile devices (telephone, tablet, etc.) Optical discs (CD, DVD, etc.) Removable memory (USB, Memory Card, etc.) Printer, scanner, photocopier | Paper Manual data recording systems (survey forms, visitor entry log) Written, printed, visual environments |
In Article 3 of the Law, the concept of processing of personal data is defined; in Article 4 it is stated that the processed personal data must be relevant, limited and proportionate to the purposes for which they are processed, and must be retained for the period envisaged in the relevant legislation or necessary for the purpose for which they are processed; and in Articles 5 and 6, the conditions for processing personal data are listed.
Accordingly, within the framework of our Institution’s activities, personal data are retained for the period envisaged in the relevant legislation or appropriate for our processing purposes.
Legal Reasons Requiring Retention
Within the Institution, the personal data processed within the framework of its activities are retained for the period envisaged in the relevant legislation. In this context, personal data are retained for the retention periods envisaged within the framework of;
• The Law No. 6698 on the Protection of Personal Data,
• The Turkish Code of Obligations No. 6098,
• The Public Procurement Law No. 4734,
• The Social Insurance and General Health Insurance Law No. 5510,
• The Law No. 5651 on the Regulation of Publications Made on the Internet and
• Combating Crimes Committed Through These Publications,
• The Public Financial Management Law No. 5018,
• The Occupational Health and Safety Law No. 6331,
• The Right to Information Law No. 4982,
• The Law No. 3071 on the Exercise of the Right to Petition,
• The Labour Law No. 4857,
• The Retirement Health Law No. 5434,
• The Turkish Commercial Code No. 6102
• The Law No. 6502 on the Protection of Consumers
• The Law No. 29166 on the Regulation of Electronic Commerce
and the other secondary regulations in force pursuant to these laws.
Processing Purposes Requiring Retention
The Company retains the personal data it processes within the framework of its activities for the following purposes;
• To carry out human resources processes.
• To ensure internal company communication.
• To ensure the security of the Company and Company employees and those in the position of third parties,
• To be able to carry out statistical studies.
• To ensure internal event management
• Management of relations with business partners or suppliers
• Request and complaint management
• To be able to perform the works and operations as a result of the signed contracts and protocols.
• To procure the necessary information and documents for the VERBİS system in line with the Law on the Protection of Personal Data and the Board decision and to notify the Institution
• To ensure the fulfilment of legal obligations as required or mandated by legal regulations.
• To establish contact with natural / legal persons in a business relationship with the Company.
• To carry out operations within the scope of the Company’s production and commercial policies.
• To make legal reports.
• The obligation of proof as evidence in legal disputes that may arise in the future.
The data obtained within the scope of the above legislative provisions and contractual requirements will be protected by the data processors within the legal periods, under the supervision of the data controller, by preserving their confidentiality. Our Company’s data processors are as follows:
• Our Company’s accounting department/unit
• Our Company’s human resources department/unit
• Our Company’s disciplinary board
• Persons responsible for the Protection of Personal Data at our Company
• Our Company’s contact person (this person is at the same time the person responsible for the protection of personal data)
• Administrative personnel in recruitment and, with internal company authorization, in employee interviews
• Company doctor
• Unit chiefs with regard to performance evaluations
• Company lawyers
• Certified public accountants
• Private service providers
According to the nature of the said work, other persons may also fall into this status as data processors as required by the circumstances and the work. Whoever has assumed the title of data processor will endeavour to ensure data security pursuant to the relevant legislation and will use the said data limited to the purpose. For example, health records will not be examined by the accounting unit.
Personal data will be kept by the data processors in a place inaccessible to everyone, locked with a key allocated only to the processing person. The security of the said data will be ensured by cameras operating on a 24-hour basis.
H. THE RETENTION PERIODS AND DESTRUCTION OF PERSONAL DATA
Within our company, the months of January and July of the year have been determined as the destruction periods for the destruction of data. Personal data obtained from data subjects will be deleted, destroyed or anonymized by the personnel/personnel responsible for the protection of data within the company during the destruction period following the end of the retention periods. The records relating to the destruction operation will be kept in an independent place by the personnel/personnel responsible for the protection of data within the company for a period of 3 (three) years. After three years, the said records will also be destroyed. For the destruction operation, the provisions of the Regulation on the Deletion, Destruction or Anonymization of Personal Data dated 28 October 2017 and numbered 30224, and the Law No. 6698 on the Protection of Personal Data will be taken as the basis.
The reasons requiring destruction are as follows:
• The amendment or repeal of the relevant legislative provisions that form the basis for their processing,
• The disappearance of the purpose that requires their processing or retention,
• In cases where the processing of personal data is carried out solely on the basis of the explicit consent condition, the data subject’s withdrawal of their explicit consent,
• The acceptance by the Institution of the application made by the data subject regarding the deletion and destruction of their personal data within the framework of the data subject’s rights pursuant to Article 11 of the Law,
• In the event that the Institution rejects the application made to it by the data subject with a request for the deletion, destruction or anonymization of their personal data, finds the response it gave inadequate, or does not respond within the period envisaged in the Law; the data subject’s lodging of a complaint with the Board and the finding of this request appropriate by the Board,
• The expiry of the maximum period requiring the retention of personal data and the absence of any condition that would justify retaining the personal data for a longer period.
For the secure retention of personal data, the prevention of their unlawful processing and access, and the lawful destruction of personal data, technical and administrative measures are taken by the Company within the framework of the adequate measures determined and announced by the Board for special categories of personal data pursuant to Article 12 of the Law and the fourth paragraph of Article 6 of the Law.
The technical measures taken by the Company regarding the personal data it processes are listed below:
• Through penetration tests, risks, threats, vulnerabilities and, if any, openings directed at our Institution’s information systems are revealed and the necessary measures are taken.
• Through information security incident management, as a result of the analyses carried out in real time, the risks and threats that will affect the continuity of information systems are continuously monitored.
• Access to information systems and the authorization of users are carried out through the access and authorization matrix and through security policies over the corporate active directory.
• The necessary measures are taken for the physical security of the Company’s information systems equipment, software and data.
• In order to ensure the security of information systems against environmental threats, hardware (an access control system that allows only authorized personnel to enter the system room, a 7/24 operating monitoring system, ensuring the physical security of the edge switches that make up the local area network, fire extinguishing system, air conditioning system, etc.) and software (firewalls, attack prevention systems, network access control, systems that block malicious software, etc.) measures are taken.
• Risks aimed at preventing the unlawful processing of personal data are determined, the taking of technical measures appropriate to these risks is ensured, and technical controls are carried out for the measures taken.
• By creating access procedures within the Company, reporting and analysis studies regarding access to personal data are carried out.
• Accesses to the storage areas where personal data are located are recorded, and inappropriate accesses or access attempts are kept under control.
• The Company takes the necessary measures so that deleted personal data are inaccessible and non-reusable for the relevant users.
• A system and infrastructure suitable for this have been created by the Institution in order to notify the data subject and the Board in the event that personal data are unlawfully obtained by others.
• By following up security openings, appropriate security patches are installed and information systems are kept up to date.
• Strong passwords are used in the electronic environments where personal data are processed.
• Secure record keeping (logging) systems are used in the electronic environments where personal data are processed.
• Data backup programs that ensure the secure retention of personal data are used.
• Access to personal data stored in electronic or non-electronic environments is restricted according to the access principles.
• Access to the Institution’s website is encrypted with the SHA 256 Bit RSA algorithm using a secure protocol (HTTPS).
• A separate policy has been determined for the security of special categories of personal data.
• Training on the security of special categories of personal data has been provided to employees involved in the processing of special categories of personal data, confidentiality agreements have been made, and the authorizations of users with access authorization to the data have been defined.
• The electronic environments in which special categories of personal data are processed, retained and/or accessed are preserved using cryptographic methods, cryptographic keys are kept in secure environments, all operation records are logged, the security updates of the environments are continuously followed up, the necessary security tests are carried out/had carried out regularly, and the test results are recorded,
• Adequate security measures are taken for the physical environments in which special categories of personal data are processed, retained and/or accessed, and, by ensuring physical security, unauthorized entries and exits are prevented.
• If special categories of personal data need to be transferred by e-mail, they are transferred in encrypted form using a corporate e-mail address or a KEP account.
• If they need to be transferred via environments such as portable memory, CD, DVD, they are encrypted using cryptographic methods and the cryptographic key is kept in a different environment. If the transfer is carried out between servers in different physical environments, data transfer is carried out by establishing a VPN between the servers or by the sFTP method. If it needs to be transferred by paper environment, the necessary measures are taken against risks such as the theft, loss or being seen by unauthorized persons of the document, and the document is sent in “confidential” format
• The Company will specify which of these items it can carry out
The administrative measures taken by the Company regarding the personal data it processes are listed below:
• With a view to developing the qualifications of employees, training is provided on the prevention of the unlawful processing of personal data, the prevention of unlawful access to personal data, ensuring the safeguarding of personal data, communication techniques, technical knowledge and skills, the Labour Law and other relevant legislation.
• Confidentiality agreements are signed by employees regarding the activities carried out by the Company.
• A disciplinary procedure to be applied to employees who do not comply with security policies and procedures has been prepared.
• Before starting to process personal data, the obligation to inform the data subjects is fulfilled by the Institution.
• A personal data processing inventory has been prepared.
• Periodic and random internal company audits are carried out.
• Information security training is provided to employees.
Upon the expiry of the legal periods, personal data are destroyed in the following ways, either at the request of the data subject or ex officio by the Company.
| DATA RECORDING MEDIUM | EXPLANATION |
| Personal Data Located on Servers | For those personal data located on servers whose retention period has ended, the deletion operation is carried out by the system administrator by removing the access authorization of the relevant users |
| Personal Data Located in the Electronic Environment | Those personal data located in the electronic environment whose retention period has ended are made in no way accessible and non-reusable for other employees (relevant users) except the database administrator |
| Personal Data Located in the Physical Environment | Those personal data kept in the physical environment whose retention period has ended are made in no way accessible and non-reusable for other employees except the unit manager responsible for the document archive. In addition, a blackout operation is also applied by scratching/painting over/erasing them so that they cannot be read. |
| Personal Data Located on Portable Media | Those personal data kept on flash-based storage media whose retention period has ended are encrypted by the system administrator, and, by granting access authorization only to the system administrator, they are kept in secure environments with the encryption keys |
| Personal Data Located in the Physical Environment | Those personal data located in the paper environment whose retention period has ended are destroyed in an irreversible manner in paper shredding machines. |
| Personal Data Located on Optical / Magnetic Media | For those personal data located on optical media and magnetic media whose retention period has ended, the operation of physical destruction such as melting, burning or pulverizing is applied. In addition, the magnetic media is passed through a special device and, by being exposed to a high-value magnetic field, the data on it is made unreadable. |
The personal data to be obtained from employees are retained and destroyed at different time intervals according to their nature. Recruitment documents and the personnel data forming the basis for the notifications regarding the length of service and wages made to the Social Security Institution are retained for a period of 15 (fifteen) years during the continuation of the service contract and from its termination. The said data are also destroyed during the destruction period following the end of this period. The personnel data other than the recruitment documents and the personnel data forming the basis for the notifications regarding the length of service and wages made to the Social Security Institution are retained for a period of 10 (ten) years during the continuation of the service contract and from the beginning of the calendar year following its termination. The said data are also destroyed during the destruction period following the end of this period. The Data within the Content of the Workplace Personal Health File are retained for a period of 15 (fifteen) or 20 (twenty) years during the continuation of the service contract and from its termination, or, if there is an occupational accident and a criminal case is also in question, for a period of 30 (thirty) years. The said data are also destroyed during the destruction period following the end of this period.
When the data subject, pursuant to Article 13 of the Law, applies to the company Mutlucan Tuz Madencilik İnş.Tur.Otom.Pet.Nak.San. ve Tic. Aş and requests the deletion or destruction of their personal data;
1- If all of the conditions for processing personal data have ceased to exist; the Company, by explaining its reason, deletes, destroys or anonymizes the personal data subject to the request with an appropriate destruction method within 30 (thirty) days1 from the day it received the request. In order for the Company to be deemed to have received the request, the data subject must have made their request in accordance with the Personal Data Processing and Protection Policy. The Company in any case provides information to the data subject regarding the operation carried out.
2- If all of the conditions for processing personal data have not ceased to exist, this request may be rejected by the Company by explaining its reason pursuant to the third paragraph of Article 13 of the Law, and the rejection response is notified to the data subject in writing or electronically at the latest within thirty days. The data subject’s right to complain to the institution is reserved. In this context, data subjects may apply to the Board within 60 (sixty days) from the time they learn that their requests have been rejected.
3- Within this framework, applications to be made to our Company “in writing” may be transmitted to us,
• By the personal application of the Applicant,
• Through a notary,
1In the Decision of the Personal Data Protection Board dated 24.01.2019 and numbered 2019/9 regarding the Calculation of the Periods for Application to the Data Controller and Complaint to the Board, the following principles were included:
• That in the event that a response is given by the data controller within 30 days to the application made by the data subject, the data subject may lodge a complaint within 30 days following the response of the data controller, and that, accordingly, in the said cases the data subject does not have a period of 60 days from the date on which they applied to the data controller,
• That in the case where no response is given by the data controller to the application made by the data subject, the data subject may lodge a complaint with the Board within 60 days from the date on which they applied to the data controller,
• That in the event that a response is given by the data controller to the application made by the data subject after the 30-day period granted in the Law, considering that the data subject is not obliged to wait for the response to be given after the 30-day period granted to the data controller in the Law and may lodge a complaint with the Board upon the expiry of the period granted to the data controller, the data subject may lodge a complaint with the Board within 60 days from the date on which they applied to the data controller, and not within 30 days from the date on which the data controller responded to them,
it was deemed appropriate that these matters be announced to the public by the Decision of the Personal Data Protection Board dated 24.01.2019 and numbered 2019/9.
• By being signed by the Applicant with a “secure electronic signature” as defined in the Electronic Signature Law No. 5070
and by being sent to the Company’s registered electronic mail address. Our contact information for exercising this right is as follows:
Company Name : Mutlucan Tuz Madencilik İnş.Tur.Otom.Pet.Nak.San. ve Tic. Aş
MERSIS Number : 0626034057400018
E-mail address : info@mutlucantuz.com.tr
Postal Address: Mustafa Kemal Mahallesi 2118. Cad. C Blok No:4 C/175 Çankaya/ANKARA
Tel: 0312 323 71 48
I. THE TRANSFER OF PERSONAL DATA
The manner in which and the conditions under which personal data will be transferred to third parties within the country’s borders are regulated within the scope of Article 8 of the Law on the Protection of Personal Data. According to this article, the transfer of personal data is only possible in the event that persons give their explicit consent. However, again in the same article of the law, it is set forth that personal data may also be transferred without explicit consent in the event that the conditions within the scope of Articles 5 and 6 are present. The result arising from the joint interpretation of the said articles of the law is;
• Obtaining the explicit consent of the data subject,
• Being expressly provided for by the laws,
• Being necessary for the protection of the life or physical integrity of the person themselves or of another person who is unable to express their consent due to actual impossibility or whose consent is not legally valid,
• Being necessary to process the personal data of the parties to a contract, provided that it is directly related to the establishment or performance of the contract,
• Being mandatory for the data controller to fulfil its legal obligation,
• Having been made public by the data subject themselves,
• Data processing being mandatory for the establishment, exercise or protection of a right,
• In the event that data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject, it is possible to transfer personal data.
In order for special categories of personal data to be transferred, however;
• In the event that the explicit consent of the data subject is obtained,
• In the event that it is expressly provided for by the laws with regard to special categories of personal data other than those relating to health and sexual life,
• With regard to personal data relating to health and sexual life, special categories of personal data may be transferred to third parties by persons under an obligation of confidentiality or authorized institutions and organizations, for the purposes of the protection of public health, preventive medicine, medical diagnosis, the conduct of treatment and care services, and the planning and management of health services and their financing.
Contrary to the fact that personal data can only be data belonging to natural persons, the “data controller” and the “data processor” can be both natural and legal persons. Any natural or legal person who performs operations on personal data is, according to the purposes and methods relating to the processing of data, either a data controller or a data processor. In this context, the regulations contained in Article 8 of the Law must also be complied with for any kind of data transfer to be carried out between persons in these two categories.
Within the scope of our company’s field of activity and commercial interests, it is possible for personal data to be transferred to public and private legal persons abroad in line with the legal conditions. According to Article 9 of the Law, the transfer of data abroad may be carried out in the following cases;
• The presence of the explicit consent of the data subject,
• In the presence of the cases specified in the Law (the conditions specified in the second paragraph of Article 5 and the third paragraph of Article 6 of the Law), the presence of adequate protection in the country to which the data will be transferred (countries deemed safe by the Board),
• In the presence of the cases specified in the Law (the conditions specified in the second paragraph of Article 5 and the third paragraph of Article 6 of the Law), in the event of the absence of adequate protection in the country to which the data will be transferred (countries not deemed safe by the Board), the written undertaking of adequate protection and the presence of the Board’s permission.
As the data controller, it is possible for personal data and special categories of personal data to be transferred to third parties, together with the presence of the above conditions, in line with the provision of the interests of third parties upon their requests, the requirement of company purposes, the fulfilment of obligations towards public institutions, the performance of legal obligations and other purposes. The said data may be shared with our company’s relevant personnel, our affiliated companies, our direct/indirect domestic/foreign subsidiaries, the organizations from which we procure services, the domestic and foreign servers we use, the domestic/foreign institutions from which we procure cloud services, the persons and organizations that process data on behalf of the data controller and provide measurement, targeting and profiling support, audit companies, our business and solution partners, suppliers, and public and private legal persons.
The list of the relevant data processors according to the personal data categories is as follows;
| Identity Information | Company Stakeholders, Company Officials, Company Employees, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties |
| Contact Information | Company Stakeholders, Company Officials, Company Employees, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties |
| Location Data | Company Stakeholders, Company Officials, Company Employees |
| Transaction Security Information | Company Stakeholders, Company Officials, Company Employees, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties |
| Family Members and Relatives Information | Company Stakeholders, Company Officials, Company Employees, Company Business Partners |
| Physical Space Security Information | Company Stakeholders, Company Officials, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties |
| Financial Information | Company Stakeholders, Company Officials, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties |
| Visual/Audio Information | Company Stakeholders, Company Officials, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties |
| Personnel Information | Company Stakeholders, Company Officials, Company Business Partners |
| Legal Transaction Information | Company Stakeholders, Company Officials, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties |
| Special Categories of Personal Data | Company Stakeholders, Company Officials, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties |
| Request/Complaint Management Information | Company Stakeholders, Company Officials, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties |
İ. OTHER EXPLANATIONS
When there is a change within the scope of the said policies, these will be notified to the employees by way of announcement, and the approved copies of the old policies will be kept for a period of 3 (three) years.
The Company reserves the right to make changes to the Personal Data Processing and Protection Policy or to this Personal Data Retention and Destruction Policy due to changes made in the Law, pursuant to the decisions of the Institution, or in line with developments in the sector or in the field of information technology.
The changes made in this Personal Data Retention and Destruction Policy are immediately incorporated into the text, and the explanations regarding the changes are explained at the end of the policy.
In the event that the said data are obtained unlawfully and in violation of procedure, they will be notified to the board as soon as possible pursuant to Article 12 of the KVKK. What should be understood by as soon as possible[1] is 72 hours.
[1] By the Decision of the Personal Data Protection Board dated 24.01.2019 and numbered 2019/10;
It was deemed appropriate that the expression “as soon as possible” contained in the provision of paragraph (5) of Article 12 of the Law, which states “In the event that the processed personal data are obtained by others through unlawful means, the data controller notifies this situation to the person concerned and to the Board as soon as possible….”, be interpreted as 72 hours, and that, in this context, the data controller notify the Board without delay and at the latest within 72 hours from the date on which it learned of this situation; and that, following the determination by the data controller of the persons affected by the said data breach, notification also be made to the data subjects within the shortest reasonable time, directly if the data subject’s contact address can be reached, and, if it cannot be reached, by appropriate methods such as publication on the data controller’s own website,
UPDATING AND COMPLIANCE
The Company reserves the right to make changes to this Policy and to the other policies dependent on and related to this Policy due to changes made in the Law, pursuant to the decisions of the KVK Board, or in line with developments in the sector or in the field of information technology.
The changes made in this Policy are immediately incorporated into the text, and the explanations regarding the changes are explained at the end of the Policy.
You can access the complaint form you can submit to our company at this link;
You can access the complaint form you can submit to the KVK Institution at this link;
You can access this privacy notice and the KVKK Policies at this link;
you can access.
2By the Decision of the Personal Data Protection Board dated 24.01.2019 and numbered 2019/10;
—————————————————————————————————————
It was deemed appropriate that the expression “as soon as possible” contained in the provision of paragraph (5) of Article 12 of the Law, which states “In the event that the processed personal data are obtained by others through unlawful means, the data controller notifies this situation to the person concerned and to the Board as soon as possible….”, be interpreted as 72 hours, and that, in this context, the data controller notify the Board without delay and at the latest within 72 hours from the date on which it learned of this situation; and that, following the determination by the data controller of the persons affected by the said data breach, notification also be made to the data subjects within the shortest reasonable time, directly if the data subject’s contact address can be reached, and, if it cannot be reached, by appropriate methods such as publication on the data controller’s own website,

