Our Personal Data Protection Policy

ABOUT OUR PERSONAL DATA PROTECTION POLICY

A. COMPANY STATEMENT

As the data controller Mutlucan Tuz Madencilik İnş.Tur.Otom.Pet.Nak.San. ve Tic. Aş, all personal data processed within our company is protected under the provisions of the relevant national and international legislation, primarily Law No. 6698 on the Protection of Personal Data. In order to ensure the necessary protection, our Company takes technical and administrative measures in a timely and appropriate manner, and in the face of any suspected breach, makes the necessary notifications to the relevant persons, institutions and organizations as soon as possible within the framework of the legal provisions.

The information of the Data Controller is as follows:

COMPANY NAME Mutlucan Tuz Madencilik İnş.Tur.Otom.Pet.Nak.San. ve Tic. Aş
MERSIS NUMBER 0626034057400018
ADDRESS Mustafa Kemal Mahallesi 2118. Cad. C Blok No:4 C/175 Çankaya/ANKARA
PHONE 0312 323 71 48
FAX 0312 352 57 06
E-MAIL info@mutlucantuz.com.tr
KEP (REGISTERED ELECTRONIC MAIL)


B. THE NECESSITY AND PURPOSE OF ESTABLISHING A POLICY

Within the scope of human rights that have developed over a long period, the importance of the values that make us who we are, namely personal data, has gained particular significance in the world we have reached, and legal legislation has been prepared for its protection in the context of both criminal and compensation law. The rapid progress observed in the field of Information Technologies has facilitated the sharing of such personal data and has given rise to the development of arbitrary practices. In this context, in order to prevent arbitrariness, the necessary legal and administrative arrangements have been made, and it has become a legal obligation for organizations to establish data protection policies. Thus, the arbitrary use of individuals’ personal data has been prevented and data processing has been made subject to certain conditions.

C. DEFINITION OF THE ADDRESSEE

This privacy notice and information document is addressed to all addressees who establish any kind of relationship with our company, that is, to the data subjects as they are referred to by their legal counterpart. The data subjects within this scope are as follows:

• All users who connect to/use our Company’s channels ( our company’s website names and social sharing site names are as follows:…………………………………………………………….)
• Those who connect to the guest network (wifi) in the Company’s offices, warehouses and stores
• Those who use the Company’s Mobile applications and those who use the special programs allocated to the Company
• All customers included in the Company database (in the CRM System)
• Customers who shop from the Company stores or through the website channels
• Those who visit our Company stores for any purpose
• All customers who contact the COMPANY through the Company’s social media accounts (including but not limited to sharing comments, making requests)
• Third parties who enter into a commercial relationship with our company directly or through intermediary consultancy firms
• Company employees and Company partners
• Those who are in the candidacy process at our Company
• All customers who fill out surveys and forms in order to benefit from the opportunities offered by the Company to its customers
• Our job candidates who send their résumés in order to apply for a job at the Company through career portals, İŞKUR, by e-mail, through references, or by filling out an application form physically,
• Employees who currently continue to work within the Company
• Persons who do internships at our Company or work during the trial period
• Former employees whose employment contract has been terminated for any reason
• All our business partners within the scope of our commercial activities and their employees
• All natural persons who have shared/will share their personal data with the Company face to face, remotely, verbally, in writing or electronically; who have provided/will provide it directly or who have enabled/will enable it to be obtained by the Company,
• Supplier and transport companies within the scope of the Company’s activities,

Apart from the data subjects listed above, anyone who enters into any legal, humanitarian, commercial or other relationship with our company is the addressee of this document.

The personal data obtained within the scope of the services provided by our Company (data processed through online form environments or the … application allocated to our company at the checkout) is by no means shared with third parties, and is preserved within the framework of our confidentiality and security policies only by the relevant data processors within the scope of legal obligations, together with the informed consent documents signed by the data subjects. Where required by the nature of the work or in the presence of explicit consent, the information in question may be shared with support-providing companies such as transport companies or service providers within the scope of confidentiality policies.

D. THE PROCESSING OF PERSONAL DATA AND THE FUNDAMENTAL PRINCIPLES GOVERNING DATA PROCESSING

Every kind of operation performed on data, such as the obtaining, recording, storage, preservation, alteration, rearrangement, disclosure, transfer, taking over, making available, classification or prevention of use of personal data by fully or partially automated means or by non-automated means provided that it forms part of any data recording system, is considered as the processing of personal data. Every kind of activity carried out in the process from the collection of personal data in the specified manner up to the operations of deletion, destruction or anonymization is evaluated as the processing of personal data within the scope of the Law.

Your personal data is processed, in connection with the requirements of the commercial activity, workplace order and general functioning within our company, within the scope of the provisions of other laws, primarily Labour Law No. 4857, Law No. 6698 on the Protection of Personal Data, Turkish Code of Obligations No. 6098, Social Insurance and General Health Insurance Law No. 5510, Occupational Health and Safety Law No. 6331, Law No. 6502 on Consumer Protection and Law No. 29166 on the Regulation of Electronic Commerce, and within the scope of the other legislation issued in line with these provisions. The data in question is obtained from the employment contract, commercial contracts, information within the scope of other contractual relationships, as well as the personnel file of the party, information and documents submitted by you, and information and documents legally obtained from the relevant institutions or notified to us by the institutions.

Your personal data may be collected verbally, in writing or electronically by automated or non-automated means, through our company units and offices, the website, social media channels, mobile applications and similar means. When you use our call centers or our web page, or when you visit our website and social media channels, your personal data may be processed by being created and updated.

The data in question is processed within legal frameworks, limited to exclusive purposes, under the supervision and responsibility of our company as the data controller, by the data processors, namely the personnel of Human Resources, the Data Protection Unit (DPO), Accounting, Information Technology, the Call Center, Support Services and other service units. Likewise, the processing of data may also take place, limited to the purpose, by the company doctor and lawyer/lawyers in line with the requirements of the work and legal requirements.

There are fundamental principles regarding the processing of personal data that have been accepted in international documents and reflected in the practices of many countries. In Article 4 of the Law on the Protection of Personal Data, the procedures and principles regarding the processing of personal data have been regulated in parallel with Convention No. 108 and European Union Directive No. 95/46/EC. Accordingly, the general (fundamental) principles set out in the Law regarding the processing of personal data are as follows:

​• Being processed in compliance with the law and the rules of good faith,
​• Being accurate and, where necessary, up to date,
​• Being processed for specified, explicit and legitimate purposes,
• Being relevant, limited and proportionate to the purposes for which they are processed,
​• Being retained for the period stipulated in the relevant legislation or required for the purpose for which they are processed.

The principles regarding the processing of personal data must be inherent in all personal data processing activities, and all personal data processing activities must be carried out in accordance with these principles. Centered on the above principles, we take the necessary technical, legal and administrative measures required for the protection of data. In this context, the necessary work has been carried out within our company, and the activities in question are updated in line with the decisions of the General Assembly of the Personal Data Protection Authority and legislative changes.

E. CONDITIONS FOR PROCESSING PERSONAL DATA

The processing of personal data is defined in subparagraph 3/e of Law No. 6698 as follows:

‘ Processing of personal data: Every kind of operation performed on data such as the obtaining, recording, storage, preservation, alteration, rearrangement, disclosure, transfer, taking over, making available, classification or prevention of use of personal data by fully or partially automated means or by non-automated means provided that it forms part of any data recording system,”

The manner in which the information constituting personal data is to be processed is expressed in Article 5 of the same law as follows:

Conditions for processing personal data ARTICLE 5-

(1) Personal data may not be processed without the explicit consent of the data subject.

(2) In the presence of one of the following conditions, it is possible to process personal data without seeking the explicit consent of the data subject:

a) Being expressly stipulated in the laws.

b) Being necessary for the protection of the life or bodily integrity of the person himself/herself or of another person who is unable to express his/her consent due to actual impossibility or whose consent is not granted legal validity.

c) Being necessary to process the personal data of the parties to a contract, provided that it is directly related to the establishment or performance of the contract.

ç) Being mandatory for the data controller to fulfill its legal obligation.

d) Having been made public by the data subject himself/herself.

e) Being mandatory for the establishment, exercise or protection of a right for data processing.

f) Being mandatory for data processing for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject”

F. SPECIAL CATEGORIES OF PERSONAL DATA AND CONDITIONS FOR PROCESSING

Some data, by their nature and character, are more indispensable compared to other personal rights. For this reason, the protection and processing of these rights is regulated separately and together with strict formal conditions within the scope of the law in question. Special categories of personal rights are defined and enumerated in paragraph 6/1 of the law as follows:

‘Data relating to a person’s race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and attire, association, foundation or trade union membership, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data, are special categories of personal data.”

The manner in which these rights may be processed is expressed in the other paragraphs of the same article as follows:

” (2) The processing of special categories of personal data without the explicit consent of the data subject is prohibited.

3) Personal data, other than those relating to health and sexual life, enumerated in the first paragraph may be processed without seeking the explicit consent of the data subject in cases stipulated by the laws. Personal data relating to health and sexual life, on the other hand, may be processed without seeking the explicit consent of the data subject only for the purposes of the protection of public health, preventive medicine, medical diagnosis, the conduct of treatment and care services, and the planning and management of health services and their financing, by persons under the obligation of confidentiality or authorized institutions and organizations.

(4) In the processing of special categories of personal data, it is furthermore mandatory to take the adequate measures determined by the Board.”

It is regulated that some of the special categories of personal data may be processed by non-profit organizations or formations such as political parties, foundations, associations or trade unions. Accordingly, these organizations and formations may process the special categories of data of their own members and affiliates, in accordance with their purposes of establishment and the legislation to which they are subject, limited to their fields of activity and provided that they are not disclosed to third parties. For example, the retention by a political party or trade union of the identity and contact information of its members under the conditions specified in the paragraph will be evaluated within the scope of this subparagraph. These organizations may process special categories of data only limited to their own fields of activity. For example, a trade union may only process data related to trade union membership in relation to its own field of activity and purpose. On the other hand, it will not be able to process personal data of members relating to health, religion or sect, since these have no relevance to its field of activity and purpose.

Special categories of personal data that have been made public by the data subject himself/herself may be processed. Because, in the processing of such data made public by the data subject and thereby known by everyone, it is accepted that the legal interest that needs to be protected has ceased to exist.

In cases where the processing of special categories of personal data is mandatory for the establishment, exercise or protection of a right, the data in question may be processed even without consent. For example, the processing by an employer, within the scope of the obligation to employ disabled persons, of the reports and documents relating to the persons employed in this status at the workplace will be evaluated within this scope. Likewise, in order for a disabled person to be able to benefit from the right to purchase a specially equipped vehicle exempt from special consumption tax, the obtaining and processing by the tax office of health reports relating to his/her disability will also be evaluated within the scope of this subparagraph.

G. THE PERSONAL DATA REQUESTED AND THE PURPOSES OF PROCESSING THEM

The main data sources are the contracts concluded with the data subjects, the information and documents that the parties provide to each other as a legal requirement of the legal relationship established, forms filled out online or physically, the information you have left with the call center or with our relevant unit representative, the data obtained within the scope of the cookie policy, and the information and documents obtained from other contacts.

Our company’s websites are as follows; www.mutlucantuz.com.tr

Our call center number is; 0312 323 71 48.

Our company contact numbers and fax information; 0312 352 57 06

Furthermore, in digital environments, cookie policies are applied in order to provide better service to customers and other third parties and to inform them of discounts and other opportunities that will be in their favor. Cookies: are small files in which the users in the browsers are stored when a web page is visited. They keep a record in the browser history of what people search for on websites. They allow a website by keeping the movements on the site in the browser records. Cookies were first used by the Netscape company in 1994. The initial purpose of use was to check whether a user re-enters the site he/she has entered. Today, cookies are used without deviating much from their essential purpose, but to obtain much more information. Cookies, that is, the text files we call cookies, are what enable us to be remembered. When our information is written to these files, when we enter the same sites, they recognize us and there is no need to write our information again. We browse various websites on the internet, and become members of some of them. When entering these sites of which we are members, in order not to enter our username and password each time, we click the “remember me” icon. From the moment we click on this icon, cookies come into play. Our information is recorded in a text file specific to us. Thanks to the information read from cookies, from the moment we open the site, our information reaches the site and it recognizes us.

There is also a separate cookie policy within our company, and you can access these policies from this link;

The cookie policy in question and your data obtained from virtual environments will be protected within the framework of legal provisions, limited to the purpose of establishing marketing and advertising policies. Likewise, job applications, forms filled out in virtual environments for training purposes, surveys and other information collection forms will be protected within legal frameworks, limited to their exclusive purposes. Within the framework of the execution of the Human Resources policy, the data in question may be processed separately for this purpose only within this department. In the event of a notification in the forms, the evaluation of the data by another data processor unit within our organization may also take place. Likewise, the data in question may be used as a requirement of the legal relationship entered into with customers. For example, if a delivery is to be made, the residential address and identity information; if payment is to be received from the bank, or the customer account information to be made, credit card information, and the like.

ADDITIONS MAY BE MADE TO THIS SECTION BY CONTACTING THE IT UNIT

Although the requested data vary according to the relationships that the data subjects establish with our company, they can be categorized as headings as follows:

Identity Information Data that clearly belong to an identified or identifiable natural person; that are processed partially or fully by automated means or by non-automated means as part of a data recording system; and that contain information regarding a person’s identity; such as documents containing information such as name-surname, T.R. identity number, nationality information, mother’s name-father’s name, place of birth, date of birth, gender, such as a driver’s license, identity card and passport, as well as information such as tax number, SGK number, signature information, vehicle license plate, etc.
Contact Information Data that clearly belong to an identified or identifiable natural person; that are processed partially or fully by automated means or by non-automated means as part of a data recording system; such as information such as telephone number, address, e-mail address, fax number, IP address
Family Members and Relatives Information Data that clearly belong to an identified or identifiable natural person; that are processed partially or fully by automated means or by non-automated means as part of a data recording system; information about family members (e.g. spouse, mother, father, child), relatives and other persons who can be reached in emergencies, notified to our Company by the personal data owner within the framework of the operations carried out by our Company’s business units
Security Information Data that clearly belong to an identified or identifiable natural person; that are processed partially or fully by automated means or by non-automated means as part of a data recording system; personal data relating to the records and documents obtained upon entry to the Company headquarters, branches, sales offices and all kinds of facilities, and during the stay within these places; such as camera recordings, fingerprint records and records taken at the security point, etc.
Financial Information Data that clearly belong to an identified or identifiable natural person; that are processed partially or fully by automated means or by non-automated means as part of a data recording system; personal data processed relating to every kind of financial information, document and record created according to the type of legal relationship that our Company has established with the personal data owner, as well as data such as bank account number, IBAN number, financial profile, asset data, income information
Visual/Auditory Information Data that clearly belong to an identified or identifiable natural person; that are processed partially or fully by automated means or by non-automated means as part of a data recording system; photographs and camera recordings (except for records falling within the scope of Security Information), audio recordings, as well as data contained in documents that are copies of documents containing personal data
Personnel File Information Data that clearly belong to an identified or identifiable natural person; that are processed partially or fully by automated means or by non-automated means as part of a data recording system; every kind of personal data processed with a view to obtaining the information that will form the basis for the establishment of the personnel rights of the natural persons who are in a working relationship with our Company
Special Categories of Personal Data Data that clearly belong to an identified or identifiable natural person; that are processed partially or fully by automated means or by non-automated means as part of a data recording system; the data specified in Article 6 of the KVK Law (e.g. health data including blood type, biometric data, religion and membership association information)
Request/Complaint Management Information Data that clearly belong to an identified or identifiable natural person; that are processed partially or fully by automated means or by non-automated means as part of a data recording system; personal data relating to the receipt and evaluation of every kind of request or complaint directed to our Company
Other


The conditions for processing personal data are enumerated in Article 5 of the Law, and accordingly, the processing of personal data is possible in the presence of at least one of the following situations:

• The presence of the explicit consent of the data subject,
• Being expressly stipulated in the laws,
• Being necessary for the protection of the 1 life or bodily integrity of the person himself/herself or of another person who is unable to express his/her consent due to actual impossibility or whose consent is not granted legal validity,
• Being necessary to process the personal data of the parties to a contract, provided that it is directly related to the establishment or performance of the contract,
• Being mandatory for the data controller to fulfill its legal obligation,
• Having been made public by the data subject himself/herself,
• Being mandatory for the establishment, exercise or protection of a right for data processing,
• Being mandatory for data processing for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.

The conditions for processing personal data, that is, the situations of lawfulness, are determined by enumeration in the Law, and these conditions cannot be expanded.

Special categories of personal data, on the other hand, may only be processed with the consent of the data subject. Furthermore, in addition to this, special categories of personal data other than data relating to health and sexual life may be processed within the scope of the legal conditions without seeking the condition of consent (KVKK 6/2).

Personal data relating to health and sexual life, on the other hand, may be processed without seeking the explicit consent of the data subject only for the purposes of the protection of public health, preventive medicine, medical diagnosis, the conduct of treatment and care services, and the planning and management of health services and their financing, by persons under the obligation of confidentiality or authorized institutions and organizations.

The information and documents obtained in the manner mentioned above will be protected within our company, and the ways of protecting and keeping them are as follows:

Electronic Environments Non-Electronic Environments
Servers (Domain, backup, e-mail, database, web, file sharing, etc.) Software (office software, portal, EBYS, VERBİS.) Information security devices (firewall, intrusion detection and prevention, log file, antivirus, etc.) Personal computers (Desktop, laptop) Mobile devices (phone, tablet, etc.) Optical discs (CD, DVD, etc.) Removable memories (USB, Memory Card, etc.) Printer, scanner, photocopier Paper Manual data recording systems (survey forms, visitor entry log) Written, printed, visual environments


In Article 3 of the Law, the concept of the processing of personal data is defined; in Article 4 it is stated that the processed personal data must be relevant, limited and proportionate to the purposes for which they are processed and must be retained for the period stipulated in the relevant legislation or required for the purpose for which they are processed; and in Articles 5 and 6, the conditions for processing personal data are enumerated.

Accordingly, within the framework of our Organization’s activities, personal data is retained for the period stipulated in the relevant legislation or appropriate to our processing purposes.

Legal Reasons Requiring Retention

Within the Organization, personal data processed within the framework of its activities is preserved for the period stipulated in the relevant legislation. In this context, personal data;

• Law No. 6698 on the Protection of Personal Data,
• Turkish Code of Obligations No. 6098,
• Public Procurement Law No. 4734,
• Social Insurance and General Health Insurance Law No. 5510,
• Law No. 5651 on the Regulation of Publications Made on the Internet and Combating Crimes Committed Through These Publications,
• Public Financial Management Law No. 5018,
• Occupational Health and Safety Law No. 6331,
• Right to Information Law No. 4982,
• Law No. 3071 on the Exercise of the Right to Petition,
• Labour Law No. 4857,
• Retirement Health Law No. 5434,
• Turkish Commercial Code No. 6102
• Law No. 6502 on Consumer Protection
• Law No. 29166 on the Regulation of Electronic Commerce

is retained for the retention periods stipulated within the framework of these laws and the other secondary regulations in force.

Processing Purposes Requiring Retention

The Company retains the personal data it processes within the framework of its activities in line with the following purposes.

• To carry out human resources processes.
• To ensure intra-company communication.
• To ensure the security of the Company and the Company employees and those in the position of third parties,
• To be able to conduct statistical studies.
• To ensure intra-organizational event management
• Management of relationships with business partners or suppliers
• Request and complaint management
• To be able to perform business and transactions as a result of the contracts and protocols signed.
• To procure the necessary information and documents for the VERBİS system in line with the Law on the Protection of Personal Data and the Board decision and to notify the Organization
• To ensure the fulfillment of legal obligations as required or mandated by legal regulations.
• To provide contact with the natural / legal persons who are in a business relationship with the Company.
• To carry out transactions within the scope of the Company’s production and commercial policies.
• To make legal reporting.
• The obligation of proof as evidence in legal disputes that may arise in the future.

The data obtained within the scope of the above legislative provisions and contractual requirements will be protected by the data processors within the legal periods, preserving their confidentiality under the supervision of the data controller. Our Company’s data processors are as follows:

• Our Company’s accounting department/unit
• Our Company’s human resources department/unit
• Our Company’s disciplinary board
• Our Company’s persons responsible for the Protection of Personal Data
• Our Company’s contact person (this person is at the same time the person responsible for the protection of personal data)
• Administrative personnel in recruitment and in employee interviews with intra-company authorization
• Company doctor
• Unit chiefs in terms of performance evaluations
• Company lawyers
• Certified public accountants
• Private service providers

Depending on the nature of the work in question, other persons may also fall into this status as data processors as required by the situation and the nature of the work. Whoever has taken on the title of data processor will endeavor to ensure data security as required by the relevant legislation and will use the data in question limited to the purpose. For example, health records will not be examined by the accounting unit.

Personal data will be preserved by the data processors in a place inaccessible to everyone, locked with a key allocated only to the processing person. The security of the data in question will be ensured by cameras operating on a 24-hour basis.

In the event that the data in question is processed in digital environments, it will be kept in specially locked files, and while the security of the digital environment in question is ensured, the file passwords will be allocated only to the processors.

H. RETENTION PERIODS AND DESTRUCTION OF PERSONAL DATA

Within our company, the months of January and July of the year have been determined as destruction periods for the destruction of data. The personal data obtained from the data subjects will be deleted, destroyed or anonymized by the personnel/personnel responsible for the protection of data within the company during the destruction period following the end of the retention periods. The records relating to the destruction operation will be kept in an independent place for a period of 3 (three) years by the personnel/personnel responsible for the protection of data within the company. After three years, the records in question will also be destroyed. The provisions of the Regulation on the Deletion, Destruction or Anonymization of Personal Data dated 28 October 2017 and numbered 30224, and Law No. 6698 on the Protection of Personal Data, will be taken as a basis with regard to the destruction operation.

I. TRANSFER OF PERSONAL DATA

The manner in which and the conditions under which personal data will be transferred to third parties within the country’s borders is regulated within the scope of Article 8 of the Law on the Protection of Personal Data. According to this article, the transfer of personal data is possible only in the event that the explicit consent of the persons exists. However, the same article of the law also stipulates that in the event of the presence of the conditions within the scope of Articles 5 and 6, personal data may be transferred even without explicit consent. The conclusion arising from the joint interpretation of the articles of law in question is;

• Obtaining the explicit consent of the data subject,
• Being expressly stipulated in the laws,
• Being necessary for the protection of the life or bodily integrity of the person himself/herself or of another person who is unable to express his/her consent due to actual impossibility or whose consent is not granted legal validity,
• Being necessary to process the personal data of the parties to a contract, provided that it is directly related to the establishment or performance of the contract,
• Being mandatory for the data controller to fulfill its legal obligation,
• Having been made public by the data subject himself/herself,
• Being mandatory for the establishment, exercise or protection of a right for data processing,
• In the event that data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject, the transfer of personal data is possible.

For special categories of personal data to be transferred, on the other hand;

• In the event that the explicit consent of the data subject is obtained,
• In the event that it is expressly stipulated in the laws with regard to special categories of personal data other than those relating to health and sexual life,
• With regard to personal data relating to health and sexual life, on the other hand, special categories of personal data may be transferred to third parties by persons under the obligation of confidentiality or authorized institutions and organizations for the purposes of the protection of public health, preventive medicine, medical diagnosis, the conduct of treatment and care services, and the planning and management of health services and their financing.

Contrary to the fact that personal data can only be data belonging to natural persons, the “data controller” and the “data processor” may be both natural and legal persons. Every kind of natural or legal person who carries out an operation on personal data is either a data controller or a data processor, according to the purposes and methods of the data processing. In this context, the regulations set out in Article 8 of the Law must also be complied with for every kind of data transfer to be carried out between the persons in the two categories in question.

Within the scope of our company’s field of activity and commercial interests, it is possible for personal data to be transferred to public and private legal persons abroad in line with the legal conditions. According to Article 9 of the Law, the transfer of data abroad;

• The presence of the explicit consent of the data subject,
• In the presence of the situations specified in the Law (the conditions specified in the 2nd paragraph of Article 5 and the 3rd paragraph of Article 6 of the Law), the presence of adequate protection in the country to which the data will be transferred (countries deemed safe by the Board),
• In the presence of the situations specified in the Law (the conditions specified in the 2nd paragraph of Article 5 and the 3rd paragraph of Article 6 of the Law), in the event that there is no adequate protection in the country to which the data will be transferred (countries not deemed safe by the Board), may be carried out in cases where adequate protection is undertaken in writing and the permission of the Board exists.

As the data controller, it is possible for personal data and special categories of personal data to be transferred to third parties, together with the presence of the above conditions, in line with the provision of the interests of third parties in accordance with their requests, the requirement of company purposes, the fulfillment of obligations toward public institutions, the performance of legal obligations and other purposes. The data in question may be shared with our company’s relevant personnel, our affiliated companies, our direct / indirect domestic / foreign subsidiaries, the organizations from which we receive services, the domestic and foreign servers we use, the domestic/foreign institutions from which we receive cloud services, the persons and organizations who process data on behalf of the data controller and who provide measurement, targeting and profiling support, audit companies, business and solution partners, suppliers, and public and private legal entities.

The list of the relevant data processors according to the personal data categories is as follows;

Identity Information Company Stakeholders, Company Officials, Company Employees, Company Business Partners, our Job Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Contact Information Company Stakeholders, Company Officials, Company Employees, Company Business Partners, our Job Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Location Data Company Stakeholders, Company Officials, Company Employees
Transaction Security Information Company Stakeholders, Company Officials, Company Employees, Company Business Partners, our Job Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Family Members and Relatives Information Company Stakeholders, Company Officials, Company Employees, Company Business Partners
Physical Space Security Information Company Stakeholders, Company Officials, Company Business Partners, our Job Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Financial Information Company Stakeholders, Company Officials, Company Business Partners, our Job Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Visual/Auditory Information Company Stakeholders, Company Officials, Company Business Partners, our Job Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Personnel File Information Company Stakeholders, Company Officials, Company Business Partners
Legal Transaction Information Company Stakeholders, Company Officials, Company Business Partners, our Job Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Special Categories of Personal Data Company Stakeholders, Company Officials, Company Business Partners, our Job Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Request/Complaint Management Information Company Stakeholders, Company Officials, Company Business Partners, our Job Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties


UPDATE AND COMPLIANCE

The Company reserves the right to make changes to this Policy and to the other policies dependent on and related to this Policy due to changes made in the Law, in accordance with the decisions of the KVK Board, or in line with developments in the sector or in the field of information technology.

The changes made to this Policy are immediately incorporated into the text, and the explanations regarding the changes are explained at the end of the Policy.

This Policy was approved by the ………….. Executive Committee on …/…/… . As of this date, it will be valid and binding.