DATA POLICIES

GDPR

ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTICS INDUSTRY AND MARKETING IMPORT EXPORT LTD. STI.

Personal Data Processing and Protection Policy Purpose and Scope of the Policy

 

The Personal Data Protection Law No. 6698, which came into force in 2016 after the constitutional right to protect personal data in 2010, is a legal protection mechanism developed to preserve the privacy of private life and prevent harm to fundamental rights and freedoms in the processing of personal data.

In accordance with Article 16 of Law No. 6698 ("KVKK" or "Law"), data controllers who are obliged to register with the Data Controllers Registry are required to prepare a policy for the protection and processing of personal data in accordance with the personal data processing inventory.

This Personal Data Protection and Processing Policy has been prepared by ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTICS INDUSTRY AND MARKETING IMPORT EXPORT LTD. STI. as the data controller, in order to determine the procedures and principles to be applied by ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTICS INDUSTRY AND MARKETING IMPORT EXPORT LTD. STI. regarding the protection and processing of personal data held by us in accordance with Law No. 6698 and other legislation.

 
DEFINITIONS

Registry; is the registry of data controllers maintained by the Personal Data Protection Authority Presidency.

Explicit Consent; consent based on information about a specific subject, expressed freely and willingly Personal Data, any kind of information related to a real person who is identified or identifiable Processing of Personal Data, any operation carried out on the data, whether by automatic means or not, including collection, recording, storage, retention, alteration, disclosure, transfer, making available, classification or use, Prevention of Use, any process performed on the data that prevents its use Destruction, the process of deleting personal data, making the data unusable Personal data destruction is the process of making the data inaccessible, irretrievable, and unusable by anyone.

Data recording system; is the registration system where personal data is processed according to certain criteria.

 
Entities Defined by the Personal Data Protection Law and Regulation

 

Data Controller, is the real or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.

Related User, except for the person or unit responsible for technically storing, protecting, and backing up the data, the individuals who process personal data within the data controller organization or within the scope of the authority and instructions received from the data controller are those who process personal data.

Recipient Group, is the category of real or legal persons to whom personal data is transferred by the data controller.

Data Subject, is the real person whose personal data is processed.

Inventory, is the inventory created by data controllers by associating the personal data processing activities they perform depending on their business processes; specifying the maximum retention period necessary for the purposes of personal data processing activities, the personal data categories, the recipient groups to which the data is transferred, and the groups of data subjects; and explaining the measures taken for data security.

The reason for the obligation to prepare an inventory is to ensure compliance with the Law in all processes related to data controllers' activities, in other words, to facilitate the detection of any non-compliance with the Law in personal data processing activities. In other words, it is a kind of self-assessment by the data controller regarding the compliance of personal data processing activities with the Law.

 
Regulation on the Deletion, Destruction, or Anonymization of Personal Data

 

ARTICLE 5 – (1) Data controllers obligated to register with the Data Controllers Registry pursuant to Article 16 of the Law are required to prepare a personal data retention and destruction policy in accordance with the personal data processing inventory.

According to the Regulation on the Data Controllers Registry, ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. as a minimum in the inventory;

Data category, Purpose and legal basis of personal data processing, Transferred recipient / recipient groups, Data subject groups, Maximum retention period necessary for the purposes of processing personal data, Personal data envisaged to be transferred to foreign countries, Technical and administrative measures taken for data security are included.

 

CONDITIONS FOR PROCESSING PERSONAL DATA

 

The processing of personal data is defined in Article 3 of the Law. Accordingly; as the data controller ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. we consider any processing of data, whether fully or partially automated or non-automated, such as obtaining, recording, storing, preserving, altering, reorganizing, disclosing, transferring, taking over, making available, classifying, or using data as processing of personal data.

The conditions for processing personal data are listed in Article 5 of the Law, and based on this, we process personal data legally if at least one of the following conditions is met:

Explicit consent of the data subject, Explicitly stipulated in the laws, Necessity to protect the life or bodily integrity of the data subject or someone else in cases where it is impossible for the data subject to express consent or where consent is not legally valid, Necessity for the conclusion or performance of a contract directly related to the data subject, Necessity for the data controller to fulfill its legal obligation, Personal data made public by the data subject, Necessity for the establishment, exercise, or protection of a right, Necessity for the legitimate interests of the data controller provided that it does not harm the fundamental rights and freedoms of the data subject. The conditions for processing personal data, i.e., legality criteria, are determined by enumeration in the Law, and these conditions cannot be expanded.

As the data controller ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD., we process data by fulfilling the mentioned conditions.

 

I. EXPLICIT CONSENT

As the data controller ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD., we first evaluate whether the processing of data can be based on other processing conditions, and if none of these are available, we resort to obtaining the explicit consent of the data subject.

 

II. STIPULATED IN THE LAWS

One of the conditions for data processing is that it is explicitly stipulated in the laws. A provision in the laws regarding the processing of personal data will constitute a processing condition. For example, the maintenance of personnel files as required by relevant legislation, the taking of fingerprints of suspects by law enforcement authorities under Article 5 of Law No. 2559 on the Duties and Powers of Police (PVSK) during a criminal investigation, and the processing of individuals' conviction data by the Ministry of Justice under Law No. 5352 on Criminal Records fall within this scope.

 

III. IMPOSSIBILITY

In cases where it is impossible for the data subject to express consent or where consent is not legally valid, personal data of the data subject or someone else's life or bodily integrity may be processed if necessary for protection.

 

IV. NECESSARY FOR THE CONCLUSION AND PERFORMANCE OF A CONTRACT

In cases where the processing of personal data is necessary for the conclusion or performance of a contract directly related to the data subject, the personal data of the data subject may be processed for this purpose.

 

V. NECESSARY TO FULFILL THE LEGAL OBLIGATION OF THE DATA CONTROLLER

In cases where it is necessary to process personal data for the data controller to fulfill its legal obligation, the personal data of the data subject may be processed.

For example, as ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. in order to pay salaries to employees, data such as the employee's bank account number, dependents, spouse's employment status, social security number may be obtained and processed.

Presenting information about my employees or patients to the relevant public officials during tax audits can also be considered within this scope.

 

VI. PERSONAL DATA MADE PUBLIC BY THE DATA SUBJECT

Personal data disclosed by the individual, in other words, personal data that has been made available to the public in any way, may be processed. For example, if a person publicly announces their contact information for the purpose of being contacted in certain situations, this can be considered as making personal data public. Similarly, if the business telephone numbers and corporate email addresses of employees are shared with third parties through corporate websites, this can also be considered as making data public. However, for personal data to be considered as made public, there must be an intention to make it public by the individual. In other words, the intention to make the data public must exist for it to be considered as public.

 

VII. NECESSARY FOR THE ESTABLISHMENT, EXERCISE, OR PROTECTION OF A RIGHT

In cases where it is necessary for the establishment, exercise, or protection of a right, personal data of the data subject may be processed.

As ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD., after the contracts we have established expire, retaining documents such as invoices, contracts, and guarantees until the end of the statute of limitations period for possible legal proceedings can be considered within this scope.

 

VIII. NECESSARY FOR THE LEGITIMATE INTERESTS OF THE DATA CONTROLLER PROVIDED THAT IT DOES NOT HARM THE FUNDAMENTAL RIGHTS AND FREEDOMS OF THE DATA SUBJECT

In cases where it is necessary for the legitimate interests of the data controller provided that it does not harm the fundamental rights and freedoms of the data subject, personal data may be processed.

In some cases, data processing may be necessary for the legitimate interests of the data controller. For example, considering the fundamental rights and freedoms of our employees, personal data processing may be necessary for determining promotions, salary increases, or the regulation of social benefits, or for the redistribution of duties and roles during the restructuring process of the business.

 

BASIC PRINCIPLES OF PROCESSING PERSONAL DATA

 

ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. adopts the following basic principles for compliance with and maintaining compliance with personal data protection legislation:

There are basic principles for the processing of personal data accepted in international documents and reflected in the practices of many countries. The procedures and principles for the processing of personal data are regulated in parallel with the 108th Convention and European Union Directive 95/46/EC in Article 4 of the Law.

Accordingly, the general principles of processing personal data can be listed as follows:

Lawfulness and fairness: Personal data shall be processed in accordance with the law and integrity rules, accurately and when necessary, and updated when necessary.

Processing for specific, explicit, and legitimate purposes: Personal data shall be processed for specific, explicit, and legitimate purposes.

Relevance with the purpose: Personal data shall be relevant, limited, and proportionate to the purposes for which they are processed.

Retention for the period prescribed in the relevant legislation or required for the purpose for which they are processed.

Ensuring data security: Personal data shall be stored in a manner to ensure the appropriate level of security.

However, in addition to the general principles mentioned above, there are also some special principles that need to be considered in the processing of personal data in accordance with the Law No. 6698.

In addition to these general principles, in accordance with the Personal Data Protection Law and the secondary regulations, data processing must comply with the principles of accountability, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability.

As ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD., we strictly comply with the basic principles of personal data processing.

 

PERSONAL DATA CATEGORIES

 

A) Identity Information:

Personal data containing information about the individual's identity; such as name, surname, ID number, nationality, mother's name, father's name, place of birth, date of birth, gender, etc., contained in documents such as driver's license, identity card, passport, as well as tax number, social security number, signature information, license plate, etc.

 

B) Contact Information:

Contact information; such as phone number, address, email address, fax number, etc.

 

C) Physical Space Security Information:

Personal data related to records and documents obtained during entry to physical space, stay within the physical space, and security records; such as camera recordings, fingerprint records, and records taken at security checkpoints, etc.

 

D) Professional Experience:

Personal data including information about job application processes of job candidates, previous work experience and careers of employees, information about certificates and courses taken, etc.

 

E) Financial Information:

Personal data related to any financial result created within the scope of the legal relationship between ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. and the data subject; such as information, documents, and records showing any financial result, bank account number, IBAN number, credit card information, financial profile, asset information, income information, etc.

 

F) Personnel:

This data category includes personal data such as employee records, entry-exit documents, unemployment registration certificate, occupational accident report, release form, personnel leave form, etc.

 

G) Special Categories of Personal Data:

Data specified in Article 6 of the Law on the Protection of Personal Data (KVKK) (including health data, including blood type, biometric data, religion, and information about membership in associations, etc.).

 

H) Convictions and Security Measures:

Information about criminal records and security measures.

 

I) Family Members and Close Relatives Information:

Personal data about the family members (e.g., spouse, parents, children) and close relatives of the data subject, in order to protect the legal interests of ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. and the data subject within the framework of operations carried out by business units.

 

J) Customer Transaction:

Personal data including tax number, invoice, promissory note information of the person who purchases goods or services.

 

K) Marketing:

Information obtained through shopping history, Surveys, Cookie Records, Campaign Studies, etc.

 

L) Transaction Security:

IP address information, Website login-logout information, Password Information, etc.

 

M) Location:

Location information of where you are, etc.

 

N) Risk Management:

Information processed for the management of commercial, technical, administrative risks, etc.

 

O) Legal Proceedings:

Information in correspondence with judicial authorities and in case files, etc.

 

INFORMATION OF DATA SUBJECTS

 

ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. conducts the necessary processes to inform the data subjects during the acquisition of personal data in accordance with Article 10 of the Personal Data Protection Law and the Procedure and Principles Regarding the Fulfillment of the Obligation to Inform. In this context, the information provided to data subjects by ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. includes the following:

(1) Information about ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. as the data controller, including address and contact information.

(2) Which personal data of the data subjects will be processed by ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. and for what purpose.

(3) To whom and for what purpose the processed personal data may be transferred by ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD.

(4) Method and legal basis of personal data collection.

(5) Rights of the data subject, including:

  • To learn whether personal data is being processed,
  • If personal data has been processed, to request information regarding this,
  • To learn the purpose of processing personal data and whether they are used for this purpose,
  • To know the third parties to whom personal data is transferred, whether domestically or abroad,
  • To request correction of personal data in case of incomplete or incorrect processing, and to request notification of the correction made to third parties to whom personal data has been transferred,
  • To request the deletion or destruction of personal data within the framework of the conditions prescribed in the relevant legislation, and to request notification of the transaction made to third parties to whom personal data has been transferred,
  • To object to the emergence of a result against the person by analyzing the processed data exclusively through automated systems,
  • To request the compensation of damages in case of damage due to the unlawful processing of personal data.

 

HANDLING OF REQUESTS FROM DATA SUBJECTS BY ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD.

 

If the data subjects transmit their requests regarding their personal data to ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. in writing or through other methods determined by the Personal Data Protection Authority, ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD., as the data controller, processes any of the data subject's rights specified in Article 11 of the Law within 30 (thirty) days at the latest in accordance with Article 13 of the Law, and informs the relevant person.

Data subjects must exercise their rights regarding personal data to the Data Controller in accordance with the Procedure and Principles Regarding Application to the Data Controller.

In order to determine whether the applicant is the owner of the personal data subject to the application, ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. may request information. In addition, ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. may ask questions related to the subject of the application to ensure that the data subject's request is processed in accordance with the request.

ENSURING THE SECURITY AND CONFIDENTIALITY OF PERSONAL DATA BY ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD.

ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. takes all necessary administrative and technical measures, establishes an audit system within its structure, and acts in accordance with the measures prescribed in the Personal Data Protection Law in case of unlawful disclosure of personal data in order to prevent the unlawful disclosure, access, transfer, or other security vulnerabilities of personal data, within the possibilities, according to the nature of the data to be protected.

In this context, ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. takes the following (i) administrative and (ii) technical measures to ensure compliance with the law in personal data processing and to prevent unauthorized access to personal data:

(1) Administrative Measures taken by ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. to Ensure the Lawful Processing of Personal Data and to Prevent Unauthorized Access to Personal Data:

  • ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. educates and raises awareness of its employees about the legislation regarding the protection of personal data.
  • In cases where personal data is subject to transfer, records are added to the contracts concluded with the recipients of the personal data, ensuring that the recipients fulfill their obligations to ensure data security.
  • Personal data processing activities carried out by ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. are thoroughly examined, and steps to ensure compliance with the personal data processing conditions prescribed by the Personal Data Protection Law are identified.
  • ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. identifies the practices that need to be implemented to ensure compliance with the Personal Data Protection Law and regulates these practices with internal policies.

(2) Technical Measures taken by ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. to Ensure the Lawful Processing of Personal Data and to Prevent Unauthorized Access to Personal Data:

  • Suitable technical measures are taken to prevent unauthorized access to systems and locations where personal data is stored, and these measures are periodically updated.
  • Access and authorization technical processes are designed and put into operation by ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. according to legal compliance requirements by business unit.
  • Software and hardware including virus protection systems and security firewalls have been installed, and relevant software and systems have been established.
  • Employees of ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. are trained on the technical measures taken in this context.
  • Employees of ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. are required not to disclose personal data they have learned contrary to the provisions of the Personal Data Protection Law, and not to use them for purposes other than processing. This commitment will continue even after they leave their jobs.
  • Contracts concluded by ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. with recipients of personal data include provisions regarding taking necessary security measures for the protection of personal data.
  • The administrative and technical measures taken by ERBATUR FOOD, GLASS, ELECTRONICS, CONSTRUCTION, TEXTILE, PLASTIC INDUSTRY AND MARKETING IMPORT EXPORT LTD. to ensure the protection and confidentiality of personal data are explained in more detail in our "Personal Data Storage and Destruction Policy."