Website Privacy Notice

PRIVACY NOTICE (INTERNET)

A. COMPANY DISCLOSURE

As the data controller ……………… A.Ş./LTD, every kind of personal data processed within our company is protected within the scope of the relevant national and international legislation, primarily Law No. 6698 on the Protection of Personal Data. In order to ensure the necessary protection, our Company takes the technical and administrative measures duly and in a timely manner, and in the event of any suspected breach, it makes the necessary notifications to the relevant persons, institutions and organizations as soon as possible within the framework of the legal provisions.

The information of the data controller is as follows:

COMPANY NAME Mutlucan Tuz Madencilik İnş.Tur.Otom.Pet.Nak.San. ve Tic. Aş
MERSIS NUMBER 0626034057400018
ADDRESS Mustafa Kemal Mahallesi 2118. Cad. C Blok No:4 C/175 Çankaya/ANKARA
PHONE 0312 323 71 48
FAX 0312 352 57 06
E-MAIL info@mutlucantuz.com.tr
KEP (REGISTERED ELECTRONIC MAIL)


B. THE CONCEPT OF PERSONAL DATA AND EXPLANATIONS ON THE DEVELOPMENT OF THIS CONCEPT
Personal data may be defined as any kind of information suitable for making the identity of individuals determinable. In this context, a person’s identity, contact, health and financial information, as well as information relating to their private life, religious belief and political opinion, are characterized as personal data. For example; name, surname, date of birth, mobile phone number, e-mail, gender, address, occupation, education, shopping location and time, how much they paid, which campaign they benefited from, the amount of discount they received, the product information in their purchase, the browsing and clicking information on the application, the location information from which they opened the application, etc.

Today, this data is frequently used by both the private sector and the public sector through automated means over information systems. Although the use of this information provides some conveniences or advantages for individuals and for those providing goods and services, this situation also brings with it the risk of the said information being abused. The obtaining, use and disclosure of this data by unauthorized persons appears as a violation of the fundamental rights protected both under the agreements to which we are a party and under our Constitution. A reasonable balance must be established between these two interests. The absence of a special law and an effective supervision mechanism regarding the processing of personal data gives rise to a negative perception in our society. In order to eliminate this perception, principles regarding the processing, preservation and control of personal data under certain conditions must be determined.

In our age, in parallel with the development of awareness of the protection of human rights, the importance of the protection of personal data is also increasing day by day. For this reason, it is seen today that detailed legal regulations are being implemented in the field of the protection of personal data in developed countries.

On the other hand, in our country there is no law that comprehensively regulates the field relating to the protection of personal data, and provisions on this subject are found in different laws. In addition, there is no institution in our country to control and supervise the process of processing personal data. As a result of this, personal data can still be used by many persons or institutions without being subject to adequate regulation and supervision, and this situation can cause certain rights violations to occur.

There are various reasons requiring the entry into force of a law that will ensure the protection of personal data in our country. First of all, in Article 135 and the following articles of the Turkish Penal Code No. 5237, the acts of unlawfully obtaining, recording or disclosing personal data have been regulated as crimes and made subject to sanctions. However, due to the absence of a special law aimed at the processing of personal data, it is seen that hesitations are experienced in determining when these acts are unlawful and when they are lawful.

On the other hand, with the regulation made in Article 20 of the Constitution by Law No. 5982, which was adopted as a result of the referendum held on 12 September 2010, the protection of personal data was secured as a fundamental human right and it was foreseen that the details would be regulated by law.

Again, with regard to our country, in the ongoing European Union full membership process, four of the negotiation chapters are directly related to personal data. In order for the process regarding these chapters to advance, a fundamental law regarding the protection of personal data must enter into force in our country.

The subject of the protection of personal data began to appear in international documents as of the 1980s. Firstly, the “Guidelines on the Protection of Privacy and Transborder Flows of Personal Data” were adopted on 23/9/1980 by the Organisation for Economic Co-operation and Development (OECD), of which our country is also a member. Convention No. 108, the “Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data”, prepared by the Council of Europe with the aim of protecting personal data at the same standards in all member countries and determining the principles of transborder data flow, was opened for signature on 28 January 1981 and was also signed by our country.

The Council of Europe has also adopted recommendations determining the principles to be applied in various sectors regarding the protection of personal data, such as medical data banks, scientific research and statistics, direct marketing, social security, insurance, police records, employment, electronic payment, telecommunications and the internet. While the said recommendations were taken into account during the preparation of the Draft, the “framework draft” nature of the Draft was preserved. Considering that the volume of the Draft would expand considerably if regulations relating to all sectors were included, the said recommendations were not incorporated into the Draft. It was assessed that the principles contained in these recommendations could be included in regulations to be made relating to various sectors in the future.

On the other hand, the European Union, in order to ensure harmonization among the legislation of member countries regarding the protection of personal data, put into force on 24/10/1995 the “Directive on the Protection of Individuals with regard to the Processing of Personal Data and on the Free Movement of Such Data” (95/46/EC). With this Directive, it was aimed to make a clear and lasting regulation that would ensure the high-level protection of the personal data of individuals in member countries and the free movement of personal data within the European Union. When the international documents aimed at the protection of personal data are taken into account, it is seen that in the law to be prepared on this subject, the conditions for processing personal data, the informing of individuals, the establishment of an authority to supervise and regulate this field, and the taking of the necessary measures regarding data security have been accepted as fundamental principles.

In the face of the said Data Protection Convention and the earlier treaties and directives becoming inadequate against current events, and the treaties and directives signed from country to country showing differences, an agreement was reached on 15 December 2011 on a reform that would cover the entire EU. In this context, the GDPR prepared in 2012 was adopted by the EU Parliament on 14 April 2016. While Article 94 of the GDPR repealed the 95/46 Data Protection Convention, it expanded the scope of application of the 2002/58/EC Electronic Data Protection Directive.

With the constitutional amendment made by Law No. 5982 in 2010, an additional paragraph was added to Article 20 of the Constitution. In the said paragraph, the provision “Everyone has the right to request the protection of their personal data. This right includes being informed about personal data concerning oneself, accessing this data, requesting its correction or deletion, and learning whether it is used for its intended purposes. Personal data may only be processed in cases provided for by law or with the explicit consent of the person. The principles and procedures regarding the protection of personal data shall be regulated by law.” was included.

The Constitution also states that detailed regulations regarding the protection of personal data will be made by law. In this context, the “Draft Law on the Protection of Personal Data” was submitted to the Presidency of the Grand National Assembly of Türkiye on 26 December 2014. The Draft was enacted on 24 March 2016, and Law No. 6698 on the Protection of Personal Data entered into force by being published in the Official Gazette dated 7 April 2016 and numbered 29677.

With the Draft prepared by taking into account international documents, comparative law practices and the needs of our country, it is aimed to process and protect personal data at contemporary standards.

C. IDENTIFICATION OF THE ADDRESSEE

This privacy and information notice is addressed to all addressees who establish a relationship with our company in any way, that is, to the data subjects in its legal equivalent. The data subjects within this scope are as follows:

• All users who connect to/use the channels belonging to our Company (the names of our company’s websites and social sharing sites are as follows:…………………………………………………………….)
• Those who connect to the guest network (wifi) in the Company’s offices, warehouses and stores
• Those who use the Company’s mobile applications and those who use the special programs allocated to the Company
• All customers in the Company database (in the CRM System)
• Customers who shop from the Company’s stores or through the websites
• Those who visit our Company stores for any purpose
• All customers who contact the COMPANY through the Company’s social media accounts (including but not limited to those who share comments, make requests)
• Third parties who enter into a commercial relationship with our Company directly or through intermediary consultancy firms
• Company employees and the company’s shareholders
• Those who are in the candidacy process at our Company
• All customers who fill out surveys and forms in order to benefit from the opportunities the Company offers to its customers
• Our employee candidates who send their resumes in order to apply for a job at the Company through career portals, İŞKUR, e-mail, references, or by physically filling out an application form,
• Employees who currently continue to work within the Company
• Persons who intern at our Company or work during the probationary period
• Former employees whose employment contract has ended for any reason
• All our business partners within the scope of our commercial activity and their employees
• All real persons who have shared/will share their personal data with the company face to face, remotely, orally, in writing or electronically; who have directly provided/will provide it or who have enabled/will enable it to be obtained by the company

Apart from the data subjects listed above, everyone who enters into any legal, human, commercial or other relationship with our company is also an addressee of this text.

The personal data obtained within the scope of the services provided by our Company (data processed through online form environments or through the … application allocated to our company at the checkout) is definitely not shared with third parties, and is preserved only by the relevant data processors within the framework of our confidentiality and security policies, within the scope of the informed consent texts signed by the data subjects and the legal obligations. In cases where the nature of the work requires it or where explicit consent exists, the said information may be shared with support-providing firms such as a transport firm or with service providers within the scope of confidentiality policies.

D. THE PROCESSING OF PERSONAL DATA AND THE FUNDAMENTAL PRINCIPLES GOVERNING DATA PROCESSING

Any kind of operation performed on data, such as the obtaining, recording, storing, preserving, altering, rearranging, disclosing, transferring, taking over, making obtainable, classifying or preventing the use of personal data by fully or partially automated means, or by non-automated means provided that it forms part of a data recording system, is considered to be the processing of personal data. Any kind of activity carried out in the process from the collection of personal data in the specified manner up to the operations of deletion, destruction or anonymization is evaluated as the processing of personal data within the scope of the Law.

Your personal data is processed, in connection with the requirements of the commercial activity within our company, the order of the workplace and the general functioning, within the scope of the provisions of other laws, primarily Labor Law No. 4857, Law No. 6698 on the Protection of Personal Data, Turkish Code of Obligations No. 6098, Social Insurance and General Health Insurance Law No. 5510, Occupational Health and Safety Law No. 6331, Law No. 6502 on the Protection of Consumers and Law No. 29166 on the Regulation of Electronic Commerce, and the other legislation issued in line with these provisions. The said data is obtained from the employment contract, commercial contracts, the information within the scope of other contractual relationships, as well as the personnel file of the party, the information and documents submitted by you, and the information and documents legally obtained from the relevant institutions or notified to us by the institutions.

Your personal data may be collected orally, in writing or electronically, by automated or non-automated means, through our company’s units and offices, website, social media channels, mobile applications and similar means. When you use our call centers or our web page, or when you visit our website or social media channels, your personal data may be processed by being created and updated.

The said data is processed, under the supervision and responsibility of our company as data controller, by the data processors, namely the personnel or personnel of Human Resources, the Data Protection Unit (DPO), Accounting, Information Technology, Call Center, Support Services and other service units, limited to exclusive purposes and within legal frameworks. Likewise, the processing of data limited to the purpose may also be carried out by the company doctor and lawyer/lawyers in line with the requirements of the work and the legal requirements.

There are fundamental principles regarding the processing of personal data that have been accepted in international documents and reflected in the practice of many countries. In Article 4 of the Law on the Protection of Personal Data, the procedures and principles regarding the processing of personal data have been regulated in parallel with Convention No. 108 and European Union Directive No. 95/46/EC. Accordingly, the general (fundamental) principles listed in the Law regarding the processing of personal data are as follows:

• Being in compliance with the law and the rules of good faith,
• Being accurate and up to date where necessary,
• Being processed for specific, explicit and legitimate purposes,
• Being relevant, limited and proportionate to the purposes for which they are processed,
• Being preserved for the period stipulated in the relevant legislation or required for the purpose for which they are processed.

The principles regarding the processing of personal data must be inherent in all personal data processing activities, and all personal data processing activities must be carried out in accordance with these principles. Centered on the above principles, we take the necessary technical, legal and administrative measures required for the protection of data. In this context, the necessary work has been carried out within our company, and the said activities are updated in line with the decisions of the General Assembly of the Personal Data Protection Authority and legislative changes.

E. THE CONDITIONS FOR PROCESSING PERSONAL DATA

The processing of personal data has been defined in subparagraph 3/e of Law No. 6698 as follows:

“Processing of personal data: any operation performed on data such as the obtaining, recording, storing, preserving, altering, rearranging, disclosing, transferring, taking over, making obtainable, classifying or preventing the use of personal data by fully or partially automated means, or by non-automated means provided that it forms part of a data recording system,”

The manner in which the said information of a personal data nature will be processed has been expressed in Article 5 of the same law as follows:

Conditions for processing personal data ARTICLE 5-

(1) Personal data cannot be processed without the explicit consent of the data subject.

(2) In the presence of one of the following conditions, it is possible to process personal data without seeking the explicit consent of the data subject:

a) It being expressly provided for in the laws.

b) It being mandatory for the protection of the life or bodily integrity of the person themselves or of another, who is unable to express their consent due to actual impossibility or whose consent is not given legal validity.

c) It being necessary to process the personal data of the parties to a contract, provided that it is directly related to the establishment or performance of that contract.

ç) It being mandatory for the data controller to fulfill its legal obligation.

d) It having been made public by the data subject themselves.

e) It being mandatory for data processing for the establishment, exercise or protection of a right.

f) It being mandatory for data processing for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.”

F. SPECIAL CATEGORIES OF PERSONAL DATA AND THE CONDITIONS FOR THEIR PROCESSING

Some data, by their nature and essence, are of a more indispensable character compared to other personal rights. For this reason, the protection and processing of these rights has been separately regulated within the scope of the said law, together with strict formal conditions. Special categories of personal rights have been defined and listed in paragraph 6/1 of the law as follows:

“Data relating to persons’ race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and attire, membership of associations, foundations or trade unions, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data, are special categories of personal data.”

The manner in which the said rights may be processed has been expressed in the other paragraphs of the same article as follows:

” (2) It is prohibited to process special categories of personal data without the explicit consent of the person concerned.

3) Personal data other than those relating to health and sexual life listed in the first paragraph may be processed without seeking the explicit consent of the data subject in cases provided for by the laws. Personal data relating to health and sexual life, on the other hand, may only be processed without seeking the explicit consent of the person concerned by persons under an obligation of secrecy or by authorized institutions and organizations, for the purposes of protecting public health, preventive medicine, medical diagnosis, the carrying out of treatment and care services, and the planning and management of health services and their financing.

(4) In the processing of special categories of personal data, it is also mandatory to take the adequate measures determined by the Board.”

The processing of some of the special categories of personal data by not-for-profit organizations or entities such as political parties, foundations, associations or trade unions is regulated. Accordingly, these organizations and entities may process the special category data of their own members and affiliates, provided that it is in accordance with their establishment purposes and the legislation to which they are subject, limited to their fields of activity and not disclosed to third parties. For example, a political party’s or trade union’s keeping of the identity and contact information relating to its members under the conditions specified in the paragraph will be evaluated within the scope of this subparagraph. These organizations may process special category data only limited to their own fields of activity. For example, a trade union may process only the data relating to trade union membership regarding its own field of activity and purpose. On the other hand, it may not process the personal data of members relating to their health, religion or sect, since it is not related to its field of activity and purpose.

The special categories of personal data that have been made public by the data subject themselves may be processed. For it is accepted that in the processing of such data, which is made public by the data subject and thus known by everyone, the legal benefit that needs to be protected is eliminated.

Where it is mandatory to process special categories of personal data for the establishment, exercise or protection of a right, the said data may be processed even without consent. For example, an employer’s processing of reports and documents relating to persons employed in this status at the workplace, within the scope of the obligation to employ disabled persons, will be evaluated within this scope. Likewise, the obtaining and processing by the tax office of the health reports relating to the disability of a disabled person, so that they may benefit from the right to purchase a specially equipped vehicle exempt from special consumption tax, will also be evaluated within the scope of this subparagraph.

G. THE PERSONAL DATA REQUESTED AND THE PURPOSES OF THEIR PROCESSING

The contracts concluded with the data subjects, the information and documents that the parties provide to each other as a legal requirement of the legal relationship established, forms filled out online or physically, the information you leave with our call center or our relevant unit representative, the data obtained within the scope of the cookie policy, and the information and documents obtained from other contacts are the main data sources.

Our company’s websites are as follows; ……………………………………

Our call center number is;……………………………..

Our company contact numbers and fax information; …………………………

Again, in digital environments, cookie policies are applied in order to provide better service to customers and other third parties and to inform them of discounts and other opportunities in their favor. Cookies: are small files in which users’ browsers are stored when a web page is visited. They keep a record in the browser history of what people search for on websites. They allow a website by keeping the movements on the site in the browser records. Cookies began to be used by Netscape in 1994. Their initial purpose of use was to check whether a user had entered the site they visited again. Today, cookies are used without deviating much from their essential purpose, but to obtain much more information. Cookies are the text files, that is, what we call cookies, that enable us to be remembered. When our information is written to these files, when we enter the same sites, they recognize us and there is no need to write our information again. We browse various websites on the internet and become members of some. When entering these sites of which we are members, we click the remember me icon so as not to enter our username and password each time. From the moment we click this icon, the cookies come into play. Our information is recorded in a text file special to us. Thanks to the information read from the cookies, from the moment we open the site, our information reaches the site and it recognizes us. There is also a cookie policy within our company, and you can access these policies from the following link;…………

The said cookie policy and your data obtained from virtual environments will be protected within the framework of the legal provisions, limited to the purpose of creating marketing and advertising policies. Likewise, job applications, forms filled out in virtual environments for educational purposes, surveys and other information-gathering forms will be protected within legal frameworks, limited to their exclusive purposes. Within the framework of carrying out the Human Resources policy, the said data may additionally be processed only within this department for this purpose. If there is a notification in the forms, the evaluation of the data by another data-processing unit within our organization may also be possible. Likewise, the said data may be used as a requirement of the legal relationship established with customers. For example, if a delivery is to be made, the residential address and identity information; if payment is to be received from a bank, or the customer account information or credit card information to be made.

THE IT UNIT MAY BE CONTACTED AND ADDITIONS MAY BE MADE TO THIS SECTION

Although the data requested varies according to the relationships that the data subjects establish with our company, it may be categorized under headings as follows:

Identity Information Data that is clearly belonging to an identified or identifiable real person; processed partially or fully automatically or by non-automated means as part of a data recording system; containing information relating to the person’s identity; such as documents such as a driver’s license, identity card and passport containing information such as name-surname, T.R. identity number, nationality information, mother’s name-father’s name, place of birth, date of birth, gender, as well as information such as tax number, social security number, signature information, vehicle plate, etc.
Contact Information Data that is clearly belonging to an identified or identifiable real person; processed partially or fully automatically or by non-automated means as part of a data recording system; such as information such as telephone number, address, e-mail address, fax number, IP address
Family Members and Relatives Information Data that is clearly belonging to an identified or identifiable real person; processed partially or fully automatically or by non-automated means as part of a data recording system; within the framework of the operations carried out by our Company’s business units, information about the family members (e.g. spouse, mother, father, child), relatives and other persons who can be reached in emergencies notified to our Company by the personal data owner
Security Information Data that is clearly belonging to an identified or identifiable real person; processed partially or fully automatically or by non-automated means as part of a data recording system; personal data relating to the records and documents taken upon entry to the Company’s head office, branches, sales offices and all kinds of facilities, and during the stay within these places; such as camera records, fingerprint records and records taken at the security point, etc.
Financial Information Data that is clearly belonging to an identified or identifiable real person; processed partially or fully automatically or by non-automated means as part of a data recording system; personal data processed relating to every kind of financial information, document and record created according to the type of legal relationship our Company has established with the personal data owner, as well as data such as bank account number, IBAN number, financial profile, asset data, income information
Visual/Auditory Information Data that is clearly belonging to an identified or identifiable real person; processed partially or fully automatically or by non-automated means as part of a data recording system; photographs and camera records (excluding records falling within the scope of Security Information), audio records, as well as data contained in documents that are copies of documents containing personal data
Personnel File Information Data that is clearly belonging to an identified or identifiable real person; processed partially or fully automatically or by non-automated means as part of a data recording system; every kind of personal data processed for the purpose of obtaining the information that will form the basis for the accrual of the personnel rights of real persons who are in a working relationship with our Company
Special Categories of Personal Data Data that is clearly belonging to an identified or identifiable real person; processed partially or fully automatically or by non-automated means as part of a data recording system; the data specified in Article 6 of the KVK Law (e.g. health data including blood type, biometric data, religion and information on the association of which one is a member)
Request/Complaint Management Information Data that is clearly belonging to an identified or identifiable real person; processed partially or fully automatically or by non-automated means as part of a data recording system; personal data relating to the receipt and evaluation of every kind of request or complaint directed to our Company
Other

The conditions for processing personal data are listed in Article 5 of the Law, and accordingly, it is possible to process personal data in the case of the presence of at least one of the following situations:

• The presence of the explicit consent of the data subject,
• It being expressly provided for in the laws,
• It being mandatory for the protection of the life or bodily integrity of the person themselves or of another, who is unable to express their consent due to actual impossibility or whose consent is not given legal validity,
• It being necessary to process the personal data of the parties to a contract, provided that it is directly related to the establishment or performance of that contract,
• It being mandatory for the data controller to fulfill its legal obligation,
• It having been made public by the data subject themselves,
• It being mandatory for data processing for the establishment, exercise or protection of a right,
• It being mandatory for data processing for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.

The conditions for processing personal data, that is, the cases of lawfulness, have been determined by enumeration in the Law, and these conditions cannot be extended.

Special categories of personal data, on the other hand, may only be processed with the consent of the data subject. In addition, special categories of personal data other than data relating to health and sexual life may be processed within the scope of the legal conditions without seeking the condition of consent (KVKK 6/2). Personal data relating to health and sexual life, on the other hand, may only be processed without seeking the explicit consent of the person concerned by persons under an obligation of secrecy or by authorized institutions and organizations, for the purposes of protecting public health, preventive medicine, medical diagnosis, the carrying out of treatment and care services, and the planning and management of health services and their financing.

The information and documents obtained in the manner described above will be protected within our company, and their manner of protection and retention is as follows:

Electronic Media Non-Electronic Media
Servers (domain, backup, e-mail, database, web, file sharing, etc.) Software (office software, portal, EBYS, VERBİS.) Information security devices (firewall, intrusion detection and prevention, log record file, antivirus, etc. ) Personal computers (Desktop, laptop) Mobile devices (phone, tablet, etc.) Optical disks (CD, DVD, etc.) Removable memory devices (USB, Memory Card, etc.) Printer, scanner, photocopier Paper Manual data recording systems (survey forms, visitor entry logbook) Written, printed, visual media


In Article 3 of the Law, the concept of the processing of personal data has been defined, in Article 4 it has been stated that the processed personal data must be relevant, limited and proportionate to the purposes for which they are processed and must be preserved for the period stipulated in the relevant legislation or required for the purpose for which they are processed, and in Articles 5 and 6 the conditions for processing personal data have been listed.

Accordingly, within the framework of our Organization’s activities, personal data is retained for the period stipulated in the relevant legislation or appropriate to our processing purposes.

Legal Reasons Requiring Retention

In the Organization, personal data processed within the framework of its activities is preserved for the period stipulated in the relevant legislation. In this context, personal data;

• Law No. 6698 on the Protection of Personal Data,
• Turkish Code of Obligations No. 6098,
• Public Procurement Law No. 4734,
• Social Insurance and General Health Insurance Law No. 5510,
• Law No. 5651 on the Regulation of Publications Made on the Internet and Combating Crimes Committed Through These Publications,
• Public Financial Management Law No. 5018,
• Occupational Health and Safety Law No. 6331,
• Right to Information Law No. 4982,
• Law No. 3071 on the Exercise of the Right to Petition,
• Labor Law No. 4857,
• Retirement Health Law No. 5434,
• Turkish Commercial Code No. 6102
• Law No. 6502 on the Protection of Consumers

is retained for the retention periods stipulated within the framework of the other secondary regulations in force pursuant to these laws.

Processing Purposes Requiring Retention

The Company retains the personal data it processes within the framework of its activities in line with the following purposes.

• To carry out human resources processes.
• To ensure intra-company communication.
• To ensure the security of the Company and the Company’s employees and those in the position of third parties,
• To be able to carry out statistical studies.
• To ensure intra-organization event management
• The management of relationships with business partners or suppliers
• Request and complaint management
• To be able to perform business and transactions as a result of the contracts and protocols signed.
• To provide the necessary information and documents for the VERBİS system in line with the Law on the Protection of Personal Data and the Board’s decision and to notify the Authority
• To ensure the fulfillment of legal obligations, as required or made mandatory by legal regulations.
• To establish contact with the real / legal persons with whom the Company is in a business relationship.
• To carry out transactions within the scope of the Company’s production and commercial policies.
• To make legal reports.
• The obligation of proof as evidence in legal disputes that may arise in the future.

The data obtained within the scope of the above legislative provisions and contractual requirements will be protected by the data processors within the legal periods, with their confidentiality preserved, under the supervision of the data controller. Our Company’s data processors are as follows:

• Our Company’s accounting department/unit
• Our Company’s human resources department/unit
• Our Company’s disciplinary board
• The persons Responsible for the Protection of Personal Data at our Company
• Our Company’s contact person (this person is also the person responsible for the protection of personal data)
• Administrative personnel in recruitment and in employee interviews with intra-company authorization
• The Company doctor
• Unit chiefs in terms of performance evaluations
• The Company’s lawyers
• Financial advisors
• Special service providers

Depending on the nature of the said work, other persons may also enter into this status as data processors as required by the situation and the work. Whoever has acquired the title of data processor will endeavor to ensure data security in accordance with the relevant legislation and will use the said data limited to the purpose. For example, health records will not be examined by the accounting unit.

Personal data will be preserved by the data processors in a place inaccessible to everyone, locked with a key allocated only to the processing person. The security of the said data will be ensured with cameras operating on a 24-hour basis.

In the event that the said data is processed in digital environments, it will be kept in specially locked files, and while the security of the said digital environment is ensured, the file passwords will be allocated only to the processors.

H. THE RETENTION PERIODS AND DESTRUCTION OF PERSONAL DATA

Within our Company, the months of January and July of the year have been determined as the destruction periods for the destruction of data. The personal data obtained from data subjects will be deleted, destroyed or anonymized by the personnel/personnel responsible for the protection of data within the Company, within the destruction period following the end of the retention periods. The records relating to the destruction operation will be kept in an independent place for a period of 3 (three) years by the personnel/personnel responsible for the protection of data within the Company. After three years, the said records will also be destroyed. Regarding the destruction operation, the provisions of the Regulation on the Deletion, Destruction or Anonymization of Personal Data dated 28 October 2017 and numbered 30224, and Law No. 6698 on the Protection of Personal Data, will be taken as basis.

The reasons requiring destruction are as follows:

• The amendment or repeal of the relevant legislative provisions forming the basis for their processing,
• The disappearance of the purpose requiring their processing or retention,
• In cases where the processing of personal data is carried out solely on the basis of the condition of explicit consent, the data subject withdrawing their explicit consent,
• The acceptance by the Authority of the application made by the data subject regarding the deletion and destruction of their personal data within the framework of their rights pursuant to Article 11 of the Law,
• In cases where the Organization rejects the application made to it by the data subject with the request for the deletion, destruction or anonymization of their personal data, finds the answer it gives inadequate, or does not respond within the period stipulated in the Law; the data subject filing a complaint with the Board and this request being found appropriate by the Board,
• The maximum period requiring the retention of the personal data having passed and there being no condition present that would justify retaining the personal data for a longer period.

For the secure retention of personal data, the prevention of its unlawful processing and access, and the lawful destruction of personal data, technical and administrative measures are taken by the Company within the framework of the adequate measures determined and announced by the Board for special categories of personal data pursuant to Article 12 of the Law and paragraph four of Article 6 of the Law.

The technical measures taken by the Company regarding the personal data it processes are listed below:

• With penetration tests, the risks, threats, vulnerabilities and, if any, openings directed at our Organization’s information systems are revealed and the necessary measures are taken.
• With information security incident management, the risks and threats that will affect the continuity of the information systems are continuously monitored as a result of the real-time analyses carried out.
• Access to information systems and the authorization of users is carried out through security policies via the access and authorization matrix and the corporate active directory.
• The necessary measures are taken for the physical security of the Company’s information systems equipment, software and data.
• In order to ensure the security of information systems against environmental threats, hardware (an access control system providing access to the system room only for authorized personnel, a 24/7 monitoring system, ensuring the physical security of the edge switches forming the local area network, a fire extinguishing system, an air conditioning system, etc.) and software (firewalls, attack prevention systems, network access control, systems preventing malicious software, etc.) measures are taken.
• The risks aimed at preventing the unlawful processing of personal data are determined, the taking of technical measures appropriate to these risks is ensured, and technical controls aimed at the measures taken are carried out.
• Access procedures are created within the Company and reporting and analysis studies regarding access to personal data are carried out.
• Access to the storage areas where personal data is located is recorded, and improper accesses or access attempts are kept under control.
• The Company takes the necessary measures to ensure that deleted personal data is inaccessible and unusable again for the relevant users.
• In the event that personal data is unlawfully obtained by others, a system and infrastructure suitable for this has been created by the Organization in order to notify the data subject and the Board of this situation.
• Security vulnerabilities are monitored, appropriate security patches are installed, and the information systems are kept up to date.
• Strong passwords are used in the electronic environments where personal data is processed.
• Secure record-keeping (logging) systems are used in the electronic environments where personal data is processed.
• Data backup programs that ensure the secure retention of personal data are used.
• Access to personal data stored in electronic or non-electronic media is limited according to access principles.
• Access to the Organization’s web page is encrypted with the SHA 256 Bit RSA algorithm using the secure protocol (HTTPS).
• A separate policy has been determined for the security of special categories of personal data.
• Training on the security of special categories of personal data has been provided to the employees involved in the special category personal data processing processes, confidentiality agreements have been made, and the authorizations of users having access authorization to the data have been defined.
• The electronic environments where special categories of personal data are processed, preserved and/or accessed are preserved using cryptographic methods, cryptographic keys are kept in secure environments, all transaction records are logged, the security updates of the environments are continuously monitored, the necessary security tests are carried out/had carried out regularly, and the test results are recorded,
• Adequate security measures are taken for the physical environments where special categories of personal data are processed, preserved and/or accessed, and by ensuring physical security, unauthorized entries and exits are prevented.
• If special categories of personal data need to be transferred via e-mail, they are transferred encrypted using a corporate e-mail address or a KEP account. If they need to be transferred via media such as portable memory, CD, DVD, they are encrypted with cryptographic methods and the cryptographic key is kept in a different environment. If a transfer is carried out between servers in different physical environments, data transfer is carried out by establishing a VPN between the servers or by the sFTP method. If transfer via paper media is required, the necessary measures are taken against risks such as the theft, loss or viewing by unauthorized persons of the document, and the document is sent in “confidential” format.
• The Company will specify which of these items it can carry out

The administrative measures taken by the Company regarding the personal data it processes are listed below:

• Aimed at developing the qualifications of employees, training is provided on the prevention of the unlawful processing of personal data, the prevention of unlawful access to personal data, ensuring the preservation of personal data, communication techniques, technical knowledge and skills, the Labor Law and other relevant legislation.
• Confidentiality agreements are signed by the employees regarding the activities carried out by the Company.
• A disciplinary procedure to be applied to employees who do not comply with the security policies and procedures has been prepared.
• Before starting to process personal data, the obligation to inform the data subjects is fulfilled by the Organization.
• A personal data processing inventory has been prepared.
• Intra-company periodic and random audits are carried out.
• Information security training is provided to the employees.

Upon the expiry of the legal periods, personal data is destroyed, at the request of the data subject or ex officio by the company, in the following ways.

DATA RECORDING MEDIUM DESCRIPTION
Personal Data Located on Servers For personal data located on servers whose retention period has ended, the deletion operation is carried out by the system administrator by removing the access authorization of the relevant users
Personal Data Located in Electronic Media Personal data located in electronic media whose retention period has ended is made in no way accessible and unusable again for employees other than the database administrator (the relevant users)
Personal Data Located in Physical Media For personal data kept in physical media whose retention period has ended, it is made in no way accessible and unusable again for employees other than the unit manager responsible for the document archive. In addition, a blackout operation is also applied by crossing out/painting over/erasing it so that it cannot be read.
Personal Data Located on Portable Media Personal data kept in flash-based storage media whose retention period has ended is stored in secure environments with encryption keys by being encrypted by the system administrator and access authorization being given only to the system administrator
Personal Data Located in Physical Media Personal data located in paper media whose retention period has ended is destroyed in an irreversible manner in paper shredders.
Personal Data Located on Optical / Magnetic Media For personal data located on optical media and magnetic media whose retention period has ended, the operation of physically destroying it, such as melting, burning or pulverizing it, is applied. In addition, magnetic media is passed through a special device and by being exposed to a high-value magnetic field, the data on it is rendered unreadable.


The personal data to be obtained from employees is retained and destroyed at different time intervals according to its nature. The retention periods of the said data are as follows. Those of this data whose retention periods have expired are destroyed within the nearest destruction period, and the records relating to the destruction are preserved for a period of 3 years.

PERSONAL DATA RETENTION PERIOD
Personnel file data forming the basis for the notifications regarding service period and wage made to the Social Security Institution, together with recruitment documents It is preserved during the continuation of the service contract and also for a period of 15 (fifteen) years from its termination.
Personnel file data other than the personnel file data forming the basis for the notifications regarding service period and wage made to the Social Security Institution, together with recruitment documents It is preserved during the continuation of the service contract and also for a period of 10 (ten) years from the beginning of the calendar year following its termination
Customer Information Pursuant to Article 82 of the Turkish Commercial Code, the information forming the basis for the issuance of the invoices that constitute the basis for the commercial books and records is retained for a period of 10 years pursuant to the said article of the law, while Customer Information other than this is retained for the period required for the purpose for which it is processed.
Contracts forming the basis of the commercial relationship and the data relating to them 10 years pursuant to the provisions of the Code of Obligations No. 6098 and other legislation
Employees’ Personal Health Files According to the Occupational Health and Safety legislation, personal health files must be retained for 15 years.
Employee Candidate Information It is retained for a maximum of 2 years, until it loses its currency.
Visitor Information It is retained for a period of 2 years
Business Partner and Consultant Information It is retained during its relationship with the Company and, from its termination, for a period of 10 years pursuant to Article 146 of the Turkish Code of Obligations.
Information Shared with the Company by Firms It is retained during its relationship with the Company and, from its termination, for a period of 10 years pursuant to Article 146 of the Turkish Code of Obligations.
Customer It is retained for a period of 10 years pursuant to Article 146 of the Turkish Code of Obligations and Article 82 of the Turkish Commercial Code, from the provision of each product/service that the Customer has purchased.
Customer/Potential Customer Requests and Complaints It is retained for a period of 10 years from the date of the request and/or complaint.
The relevant personal data being the subject of a crime within the scope of the Turkish Penal Code or other legislation introducing penal provisions During the statute of limitations for the lawsuit
Log Record Tracking Systems 10 years
Carrying Out the Processes of Access to Hardware and Software 2 Years
Records of Visitors and Meeting Participants If there is no contractual relationship, 2 years from the end of the event
Information of non-employee trainees, interns During their training and other activities with the Company and 1 year from the termination of their relationships
Personal data obtained from employee candidates Until the nearest destruction period in the event that the candidacy application results negatively


When the data subject, pursuant to Article 13 of the Law, applies to the …………….. company and requests the deletion or destruction of the personal data belonging to them;

1- If all of the conditions for processing personal data have disappeared; the Company deletes, destroys or anonymizes the personal data subject to the request, by explaining its reason and with the appropriate destruction method, within 30 (thirty) days from the day it receives the request. In order for the Company to be deemed to have received the request, the data subject must have made their request in accordance with the Policy on the Processing and Protection of Personal Data. The Company in any case informs the data subject regarding the operation carried out.

2- If all of the conditions for processing personal data have not disappeared, this request may be rejected by the Company by explaining its reason pursuant to the third paragraph of Article 13 of the Law, and the rejection answer is notified to the data subject in writing or electronically within thirty days at the latest. The data subject’s right to complain to the authority is reserved. In this context, the data subjects may apply to the Board within 60 (sixty days) from learning that their requests have been rejected.

3- In this framework, the applications to be made to our Company “in writing”,

• By the personal application of the Applicant,
• Through a notary,
• By being signed by the Applicant with the “secure electronic signature” defined in the Electronic Signature Law No. 5070

may be conveyed to us by being sent to the Company’s registered electronic mail address. Our contact information for exercising this right is as follows:

Company Name :
Mersis no :
E-mail address :
Postal Address:

I. THE TRANSFER OF PERSONAL DATA

The manner in and the conditions under which personal data will be transferred to third parties within the country’s borders is regulated within the scope of Article 8 of the Law on the Protection of Personal Data.

According to this article, the transfer of personal data is only possible in the event of the presence of persons’ explicit consent. However, again in the same article of the law, it has been written that in the event of the presence of the conditions within the scope of Articles 5 and 6, personal data may also be transferred without explicit consent. The result arising from the interpretation of the said articles of the law together;

• The obtaining of the explicit consent of the data subject,
• It being expressly provided for in the laws,
• It being mandatory for the protection of the life or bodily integrity of the person themselves or of another, who is unable to express their consent due to actual impossibility or whose consent is not given legal validity,
• It being necessary to process the personal data of the parties to a contract, provided that it is directly related to the establishment or performance of that contract,
• It being mandatory for the data controller to fulfill its legal obligation,
• It having been made public by the data subject themselves,
• It being mandatory for data processing for the establishment, exercise or protection of a right,
• It being possible to transfer personal data in the event that it is mandatory for data processing for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.

For special categories of personal data to be transferred, on the other hand;

• In the event of the obtaining of the explicit consent of the data subject,
• In terms of special categories of personal data other than health and sexual life, in the event that it is expressly provided for in the laws,
• In terms of personal data relating to health and sexual life, on the other hand, special categories of personal data may be transferred to third parties by persons under an obligation of secrecy or by authorized institutions and organizations, for the purposes of protecting public health, preventive medicine, medical diagnosis, the carrying out of treatment and care services, and the planning and management of health services and their financing.

Contrary to personal data being able to be only data belonging to real persons, the “data controller” and the “data processor” may be both real and legal persons. Every kind of real or legal person who performs an operation on personal data is, according to the purposes and methods relating to data processing, either a data controller or a data processor. In this context, for every kind of data transfer to be carried out between persons in these two categories, the regulations contained in Article 8 of the Law must also be complied with.

It is possible for our company to transfer personal data to public and private legal persons abroad within the scope of its field of activity and commercial interests, in line with the legal conditions. According to Article 9 of the Law, the transfer of data abroad;

• The presence of the explicit consent of the data subject,
• In the presence of the cases specified in the Law (the conditions specified in paragraph 2 of Article 5 and paragraph 3 of Article 6 of the Law), the presence of adequate protection in the country to which the data will be transferred (countries accepted as safe by the Board),
• In the presence of the cases specified in the Law (the conditions specified in paragraph 2 of Article 5 and paragraph 3 of Article 6 of the Law), in the event of the absence of adequate protection in the country to which the data will be transferred (countries not accepted as safe by the Board), may be carried out in the cases of adequate protection being committed to in writing and the presence of the Board’s permission.

As the data controller, it is possible to transfer personal data and special categories of personal data to third parties, together with the presence of the above conditions, in line with the provision of interests in accordance with the requests of third parties, the requirements of the company’s purposes, the fulfillment of obligations towards public institutions, the performance of legal obligations and other objectives. The said data may be shared with our company’s relevant personnel, our affiliated companies, our direct / indirect domestic / foreign subsidiaries, the organizations from which we receive services, the domestic and foreign servers we use, the domestic/foreign institutions from which we receive cloud services, persons and organizations processing data on behalf of the data controller and providing measurement, targeting and profiling support, audit companies, business and solution partners, suppliers, and public and private legal entities.

The list of the relevant data processors according to the categories of personal data is as follows;

Identity Information Company Shareholders, Company Officials, Company Employees, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Contact Information Company Shareholders, Company Officials, Company Employees, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Location Data Company Shareholders, Company Officials, Company Employees
Transaction Security Information Company Shareholders, Company Officials, Company Employees, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Family Members and Relatives Information Company Shareholders, Company Officials, Company Employees, Company Business Partners
Physical Space Security Information Company Shareholders, Company Officials, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Financial Information Company Shareholders, Company Officials, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Visual/Auditory Information Company Shareholders, Company Officials, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Personnel File Information Company Shareholders, Company Officials, Company Business Partners
Legal Transaction Information Company Shareholders, Company Officials, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Special Categories of Personal Data Company Shareholders, Company Officials, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties
Request/Complaint Management Information Company Shareholders, Company Officials, Company Business Partners, our Employee Candidates, our Visitors, Company and Group Company Customers, Potential Customers and Third Parties

J. THE RIGHTS OF THE DATA SUBJECT

As the data subject whose data is processed, your rights are written in Article 11 of Law No. 6698 as follows;

• You can learn whether we process personal data about you, and if we process or have processed it, you can request information relating to this.;
• You can learn the purpose of the processing of your personal data and whether it is used in accordance with its purpose.
• You can learn whether your personal data is transferred domestically or abroad and to whom it is transferred.
• You can request the correction of your incorrect and incomplete personal data and the informing of the recipients to whom this data has been transferred or may have been transferred.
• You can request the destruction (deletion, destruction or anonymization) of your personal data within the framework of the conditions stipulated in Article 7 of the KVKK. However, evaluating your destruction request, which method is appropriate will be evaluated by us according to the circumstances of the concrete case. In this context, you can always request information from us regarding why we chose the destruction method we selected.
• You can request the informing of the third parties to whom your personal data has been or may be transferred regarding the said destruction request.
• You can object to the results of the analysis of your personal data created exclusively using an automated system, if these results are against your interests.
• In the event that you suffer damage due to the unlawful processing of your personal data, you can request that the damage be remedied.

The requests contained in your Application concerning a Personal Data Breach will be concluded free of charge, within thirty days at the latest depending on the nature of the request1. However, in the event that the operation requires an additional cost for the Company, the fee in the tariff determined in the Communiqué on the Procedures and Principles of Application to the Data Controller by the Personal Data Protection Board may be charged.

1In the Decision of the Personal Data Protection Board dated 24.01.2019 and numbered 2019/9 on the Calculation of the Periods for Application to the Data Controller and Complaint to the Board, the following principles have been included:

• In the event that an answer is given by the data controller within 30 days to the application made by the data subject, the data subject may file a complaint within 30 days following the answer of the data controller, and in this respect, in the said cases the data subject does not have a 60-day period from the date on which they applied to the data controller,
• In the case where no answer is given by the data controller to the application made by the data subject, the data subject may file a complaint with the Board within 60 days from the date on which they applied to the data controller,
• In the event that an answer is given by the data controller after the 30-day period granted to the data controller in the Law to the application made by the data subject, considering that the data subject is not obliged to wait for the answer to be given after the 30-day period granted to the data controller in the Law and may file a complaint with the Board upon the expiry of the period granted to the data controller, the data subject may file a complaint with the Board not within 30 days from the date on which the data controller answered them, but within 60 days from the date on which they applied to the data controller; it has been deemed appropriate for these matters to be announced to the public with the Decision of the Personal Data Protection Board dated 24.01.2019 and numbered 2019/9.

You can make your application regarding the matters relating to the processing of your personal data by filling out the application form found on the Company’s website or, provided that you comply with the procedures and principles specified in Article 5 of the Communiqué on the Procedures and Principles of Application to the Data Controller, by the following methods:

• In writing and signed, through a notary or by registered return mail
• With an e-mail you will send from your registered electronic mail (KEP) address
• With a secure electronic signature or mobile signature
• With the notification you will make to the mail address
• With the notification you will make to the ….. line

For the above notifications, it is beneficial not to lose the registration numbers given to you in terms of file and transaction tracking, and feedback may be given to the notifications made to us by the same method or by registered return mail.

THE DATA CONTROLLER INFORMATION NECESSARY FOR YOU TO BE ABLE TO MAKE YOUR APPLICATIONS IS AS FOLLOWS;

The information of the data controller is as follows:

COMPANY NAME Mutlucan Tuz Madencilik İnş.Tur.Otom.Pet.Nak.San. ve Tic. Aş
MERSIS NUMBER 626034057400018
ADDRESS Mustafa Kemal Mahallesi 2118. Cad. C Blok No:4 C/175 Çankaya/ANKARA
PHONE 0312 323 71 48
FAX 0312 352 57 06
E-MAIL info@mutlucantuz.com.tr
KEP (REGISTERED ELECTRONIC MAIL)


The number and telephone line code contained in the above information has been created exclusively for KVKK operations.

UPDATE AND COMPLIANCE

The Company reserves the right to make changes to this Policy and to the other policies connected and related to this Policy, due to the changes made in the Law, in line with the decisions of the KVK Board, or in line with developments in the sector or in the field of information technology.

The changes made to this Policy are immediately incorporated into the text, and the explanations regarding the changes are explained at the end of the Policy.

This Policy was approved by the ………….. Executive Committee on …/…/…. It will be valid and binding as of this date.

You can access the complaint form you can make to our company from the following link;

You can access the complaint form you can make to the KVK Authority from the following link;

You can access this privacy notice and the KVKK Policies from the following link;

.