NEVRESTA TURİZM MİMARLIK İNŞAAT İŞLETMECİLİK TİCARET ANONİM ŞİRKETİ
KVKK
PERSONAL DATA RETENTION AND
DESTRUCTION POLICY
Address : Mustafa Kemal Mah. Dumlupınar Bul. No: 266a İç Kapı No: 18 Çankaya /Ankara
Phone : 0(312) 770 03 33
Web : https://www.akropol.com
E-mail : bilgi@akropol.com
TABLE OF CONTENTS
1.4. Implementation of the Policy and Relevant Legislation 4
1.5. Definitions and Abbreviations 4
RESPONSIBILITIES AND ALLOCATION OF DUTIES WITHIN THE PERSONAL DATA RETENTION AND DESTRUCTION MANAGEMENT STRUCTURE 6
4. EXPLANATIONS REGARDING RETENTION AND DESTRUCTION. 8
4.1. Categories of Data Subjects 8
4.2. Explanations Regarding Retention 9
4.2.A Legal Grounds Requiring Retention 9
4.2.B. Processing Purposes Requiring Retention 10
4.3. Reasons Requiring Destruction 11
5. TECHNICAL AND ADMINISTRATIVE MEASURES. 12
5.2. Administrative Measures 14
5.2.A. Audit of the Measures Taken for the Protection of Personal Data 14
5.2.B. Measures to Be Taken in the Event of Unlawful Disclosure of Personal Data 15
6. PERSONAL DATA DESTRUCTION TECHNIQUES 15
6.1. Deletion of Personal Data 15
6.2. Destruction of Personal Data 16
6.2. Anonymization of Personal Data 17
6.3.A. Anonymization Methods That Do Not Create Value Irregularity 17
6.3.B. Anonymization Methods That Create Value Irregularity 18
6.3.C. Assurance of Anonymity 18
7. RETENTION AND DESTRUCTION PERIODS 19
8. PERIODIC DESTRUCTION PERIOD 21
9. PUBLICATION AND STORAGE OF THE POLICY 21
10. UPDATE PERIOD, ENTRY INTO FORCE AND REPEAL OF THE POLICY 21
PERSONAL DATA PROCESSING, RETENTION AND DESTRUCTION POLICY
1.PART ONE
1.1. Introduction
We attach the utmost importance to the lawful processing and protection of personal data in accordance with Personal Data Protection Law No. 6698, and we act with this diligence in all of our planning and activities. With this awareness, we hereby present this Personal Data Processing, Retention and Destruction Policy for your information, both to fulfill our obligation to inform under Article 10 of the Law and to disclose all of the administrative and technical measures we have taken with respect to the processing and protection of personal data.
Personal Data Protection Law No. 6698 (“KVKK” / the “Law”) entered into force on April 7, 2016 and contains provisions governing the processing of “any information relating to an identified or identifiable natural person.”
The protection of the personal data of our customers, our employees and other natural persons with whom we are in a relationship is of great importance to us. The process governed by this Policy and the objective pursued with respect to the processing and protection of your personal data is the lawful processing and protection of the personal data of our customers, potential customers, employees, employee candidates, visitors, employees of the institutions with which we cooperate, employees of the other group companies of which we are a part, and third parties.
1.2. Purpose
The purpose of this Personal Data Processing, Retention and Destruction Policy is to establish the principles for the processing of all personal data belonging to the current and potential customers, employees, visitors, shareholders, company executives, employee candidates, employees and officers of cooperating institutions, and relevant third parties of Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi, whether processed by automated means or by non-automated means provided that they form part of a data filing system; to protect the fundamental rights and freedoms of individuals; to determine the rights and obligations required for the processing of such personal data in compliance with the law; to raise awareness among company employees regarding the protection of personal data and data privacy; and to ensure compliance with the relevant legislation, in particular Article 20 of the Constitution, Personal Data Protection Law No. 6698 and the secondary legislation thereunder, and to take the necessary measures accordingly.
1.3. Scope
This Policy covers all information and documents that fall within the definition of “Personal Data” under the Law, namely any information and documents that can be associated with an identified or identifiable natural person, as well as the measures taken and arrangements made in relation thereto.
The personal data of our employees, employee candidates, service providers, visitors and other third parties that are included in the company data inventory and obtained and stored in electronic and/or physical media fall within the scope of this Policy, and this Policy applies to all recording media in which personal data owned or managed by the Company are processed and to all activities involving the processing of personal data.
1.4. Implementation of the Policy and Relevant Legislation
This Personal Data Retention and Destruction Policy has been prepared by our Company in its capacity as Data Controller in order to fulfill our obligations under Personal Data Protection Law No. 6698 and the Regulation on the Deletion, Destruction or Anonymization of Personal Data, which constitutes secondary legislation under the Law and entered into force upon its publication in the Official Gazette dated October 28, 2017, and to inform data subjects about the principles for determining the maximum retention period necessary for the purposes for which their personal data are processed, as well as about the deletion, destruction and anonymization processes.
1.5. Definitions and Abbreviations
|
Recipient Group |
The category of natural or legal persons to whom personal data are transferred by the Data Controller. |
|
Explicit Consent |
Freely given consent on a specific matter, based on information. |
|
Relevant User |
Persons who process personal data within the Data Controller’s organization or in accordance with the authorization and instructions received from the Data Controller, excluding the person or unit responsible for the technical storage, protection and backup of the data. |
|
Data Subject |
The natural person whose personal data are processed. (Referred to in the “Policy” as the “data owner.”) |
|
Employee |
Personnel employed by Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi |
|
Electronic Medium |
Media in which personal data can be created, read, modified and written by means of electronic devices. |
|
Non-Electronic Medium |
All written, printed, visual and other media other than electronic media. |
|
Service Provider (Supplier) |
A natural or legal person who provides services to Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi under a specific contract. |
|
Destruction |
The deletion, destruction or anonymization of personal data. |
|
Law |
Personal Data Protection Law No. 6698. |
|
Recording Medium |
Any medium containing personal data that are processed by wholly or partly automated means or by non-automated means provided that they form part of a data filing system. |
|
Personal Data |
Any information relating to an identified or identifiable natural person. |
|
Personal Data Processing Inventory |
The inventory created by data controllers in which they detail the personal data processing activities they carry out depending on their business processes by associating them with the purposes and legal grounds for processing, the data category, the recipient group to which data are transferred and the data subject group, and by specifying the maximum retention period necessary for the purposes for which the personal data are processed, the personal data envisaged to be transferred abroad, and the measures taken regarding data security. |
|
Processing of Personal Data |
Any operation performed on personal data, such as the collection, recording, storage, preservation, alteration, reorganization, disclosure, transfer, takeover, making available, classification or blocking the use of personal data, by wholly or partly automated means or by non-automated means provided that they form part of a data filing system. |
|
Anonymization of Personal Data |
Rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even when matched with other data |
|
Deletion of Personal Data |
Deletion of personal data means rendering personal data inaccessible and non-reusable in any way for Relevant Users. |
|
Destruction of Personal Data |
The process of rendering personal data inaccessible, irretrievable and non-reusable by anyone in any way. |
|
Policy |
Personal Data Processing, Retention and Destruction Policy |
|
Board |
Personal Data Protection Board |
|
Special Categories of Personal Data |
Data relating to individuals’ race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and attire, membership in associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. |
|
Biometric |
Fingerprints, palm prints, face, iris, retina, ear, voice, signature, gait, hand veins, body odor and DNA information of individuals fall within the scope of biometric data. A general concept covering the unique physical or behavioral characteristics that enable an individual’s identity to be determined. |
|
Periodic Destruction |
The deletion, destruction or anonymization process to be carried out ex officio at recurring intervals specified in the personal data retention and destruction policy in the event that all of the conditions for processing personal data set forth in the Law cease to exist. |
|
Data Owner/ Data Subject |
The natural person whose personal data are processed |
|
Data Processor |
A natural or legal person who processes personal data on behalf of the Data Controller based on the authority granted by the Data Controller. |
|
Data Controller |
A natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system. |
|
Data Controllers’ Registry Information System |
The information system, accessible via the internet, created and managed by the Presidency of the Personal Data Protection Authority, which data controllers use in applying to the Registry and in other related Registry procedures. |
|
VERBİS |
Data Controllers’ Registry Information System |
|
Regulation |
The Regulation on the Deletion, Destruction or Anonymization of Personal Data, published in the Official Gazette on October 28, 2017 |
2. PART TWO
RESPONSIBILITIES AND ALLOCATION OF DUTIES WITHIN THE PERSONAL DATA RETENTION AND DESTRUCTION MANAGEMENT STRUCTURE
Pursuant to Personal Data Protection Law No. 6698 and the relevant legislation, a company Data Contact Person has been appointed in order to ensure the necessary coordination within the company for achieving, maintaining and sustaining compliance with the personal data protection legislation, and his or her duties and responsibilities are set out in the attached Table-1.
All activities relating to the processing and protection of personal data shall be carried out within the framework of the Policy, and the personnel to whom duties have been assigned shall serve as guides in the implementation of the company policy. All of our employees throughout our Company, our stakeholders, authorized dealers, authorized service providers, suppliers, solution partners, consultants and their employees, our guests, visitors and, without limitation, relevant third parties whose personal data are processed are obliged to cooperate with the persons authorized in the KVK process in complying with the KVK Policy of Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi and in eliminating legal risks. All personnel assigned duties in the KVK process are responsible for ensuring that all bodies and departments of our Company comply with the KVK Policy.
All units and employees of the Company actively support the responsible units in the proper implementation of the technical and administrative measures being taken by the responsible units under the Policy; in the training, awareness-raising, monitoring and continuous supervision of unit employees; and in taking technical and administrative measures to ensure data security in all media in which personal data are processed, with a view to preventing the unlawful processing of personal data, preventing unlawful access to personal data and ensuring the lawful retention of personal data.
Table-1 : Allocation of duties in the retention and destruction processes
|
TITLE |
UNIT |
RESPONSIBILITY |
|
Administrative Affairs Coordinator |
Director |
Responsible for ensuring that employees act in accordance with the Policy. |
|
Contact Person (Accounting Manager) |
Finance Officer |
Responsible for the preparation, development, execution, publication in the relevant media and updating of the Policy. |
2.1. Contact Person
A Contact Person has been appointed and announced on the website to monitor the effectiveness of the measures taken by our Company to comply with the personal data protection legislation. The primary responsibility of the Contact Person is to work in coordination with the personnel/manager assigned to KVK process management within the company. The Contact Person also acts as the contact person of our Company before the Data Controllers’ Registry and the Personal Data Protection Authority under the KVK legislation. If the Contact Person is absent from our Company due to leave and/or other reasons, another employee is temporarily assigned by the company management. In such a case, the temporarily assigned person is responsible for fulfilling all duties assigned to the Contact Person under the Personal Data Protection Policy.
2.2. Manager
The manager within our Company is responsible for carrying out data processing activities. The manager fulfills the requirements of the KVK Policy and the applicable legislation and, in this context, works in cooperation with the responsible personnel assigned in the KVK process. In these matters, the manager obtains support from other employees and department managers and may delegate responsibilities where necessary.
2.3. Department Managers
Within our Company, the manager of each department is responsible for carrying out data processing activities within the processes of that department. The Department Manager fulfills the requirements of the KVK Policy and the applicable legislation within his or her own department and, in this context, works in cooperation with the Contact Person and the responsible personnel assigned in the KVK process. In these matters, the Department Manager obtains support from other employees within the department and may delegate responsibilities where necessary.
2.4. All Employees
All employees of our Company are obliged to be thoroughly familiar with the KVK Policies and to apply the rules set forth therein. In this context, all employees of our Company work in harmony with the responsible personnel assigned in the KVK process and the Contact Person, provide feedback aimed at improving the KVK Policy and act in cooperation. In the event of any breach of the KVK Policies and Procedures, the necessary legal remedies shall be pursued within the framework of the Labor Law and other relevant laws.
2.5. Review and Audit
The responsible personnel assigned in the KVK process within our Company, as shown in Table-1, monitor legal, technological and organizational changes and developments that may arise in the field of personal data protection and ensure that the necessary actions are taken to bring our Company into line with such developments. The responsible personnel assigned in the KVK process review personal data processing activities and all matters relating to such activities, either ex officio or upon complaint. Matters found as a result of the review not to comply with the rules set forth in the KVK Policies and/or the legislation, together with recommendations for improvement, are reported to management by the responsible personnel assigned in the KVK process. The Contact Person follows up on the performance of the necessary work in this regard. The responsible personnel assigned in the KVK process conduct a review once every six months to ensure our Company’s compliance with the personal data protection legislation. Such review is carried out in person by the responsible personnel assigned in the KVK process.
At a minimum, the following matters are examined in such review activities:
a) Whether the KVK Policies are implemented effectively and correctly, and whether duties and responsibilities have been assigned by management, assumed by employees and are being fulfilled,
b) Whether the level of training and awareness of employees is adequate,
c) Whether the personal data processing inventory, privacy notices and other documents are accurate, complete and up to date,
d) Whether the administrative and technical measures taken for personal data security are effective and adequate,
e) Whether the KVK Policies are up to date in light of legal, technological and organizational developments. The areas for improvement identified following the review are reported to management by the responsible personnel assigned in the KVK process, and the Contact Person follows up on the performance of the necessary work in this regard. The responsible personnel assigned in the KVK process ensure that the necessary improvements are made, subject to management approval, in light of these findings.
3. RECORDING MEDIA
Personal data are stored lawfully and securely by our Company in the media listed in the table below.
Table-2: Personal data storage media
|
Electronic Media |
Non-Electronic Media |
|
· Servers (domain, backup, e-mail, database, web, file sharing, cloud, etc.) · Software (office software, portal, EDMS, VERBİS, Clinic Management Software) · Information security devices (firewall, intrusion detection and prevention, log files, antivirus, etc.) · Personal computers (desktop, laptop) · Mobile devices (phone, tablet, etc.) · Optical discs (CD, DVD, etc.) · Removable storage (USB, memory card, etc.) · Printers, scanners, photocopiers |
· Personal data kept on paper, · Manual data recording systems (survey forms, visitor logbook) · Written, printed and visual media, · Job Application Forms, · Contracts concluded between the Company and third parties · Manual data recording systems (survey forms, visitor logbook, etc.) · Personal data kept in written, printed and visual media · Unit Cabinets · Archive Rooms |
4. EXPLANATIONS REGARDING RETENTION AND DESTRUCTION
The personal data of employees, employee candidates, visitors and employees of third parties, institutions or organizations with which our Company has a relationship as service providers (suppliers) are retained and destroyed by our Company in accordance with the Law.
4.1. Categories of Data Subjects
Table-3: Categories of Data Subjects
|
DATA SUBJECT CATEGORY |
DESCRIPTION |
|
Visitor |
Natural persons who have entered the physical premises owned by Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi for various purposes or who visit our websites |
|
Employee |
Personnel employed by Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi. |
|
Employee Candidate |
Natural persons who have applied for a job with our Company by any means or who have made their résumés and related information available for review by Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi. |
|
Person Receiving Products or Services |
Natural persons who use or have used the products and services offered by our Company (including patients undergoing procedures/applications or receiving treatment), regardless of whether they have any contractual relationship with our Company |
|
Potential Product or Service Recipient |
Natural persons who have the potential to use the products and services offered by our Company, regardless of whether they have any contractual relationship with our Company (including patients undergoing procedures/applications or receiving treatment) |
|
Family Members and Relatives |
Spouses, children and relatives of data subjects whose personal data are processed under this Policy within the framework of the activities carried out by our Company. |
|
Reference Person |
Natural persons who provide endorsements and references for natural persons who have applied for a job with our Company by any means or who have made their résumés and related information available for review by the Company. |
|
Third Party |
Other natural persons not covered by this Policy or the Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi Employee Personal Data Protection and Processing Policy (e.g., guarantors, companions, former employees) |
|
Supplier Officer |
Natural persons who are officers or shareholders of a party providing services to the company on a contractual basis in accordance with the orders and instructions of Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi in the course of our Company’s commercial activities. |
|
Supplier Employee |
Natural persons who are employees of a party providing services to the company on a contractual basis in accordance with the orders and instructions of Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi in the course of our Company’s commercial activities. |
|
Company Shareholder |
Natural persons who are shareholders of the Company |
|
Company Officer |
Members of the Company’s board of directors and other authorized natural persons |
4.2. Explanations Regarding Retention
Article 3 of the Law defines the concept of processing of personal data; Article 4 provides that personal data must be relevant, limited and proportionate to the purposes for which they are processed and must be retained for the period stipulated in the relevant legislation or for the period necessary for the purpose for which they are processed; and Articles 5 and 6 set out the conditions for processing personal data. Accordingly, within the framework of the activities of Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi, personal data are retained for the period stipulated in the relevant legislation or appropriate to the purposes of processing.
4.2.A Legal Grounds Requiring Retention
Personal data processed by our Company within the framework of its activities are retained for the period stipulated in the relevant legislation. In this context, personal data are retained for the retention periods stipulated under
· Personal Data Protection Law No. 6698,
· Turkish Code of Obligations No. 6098,
· Law No. 6502 on Consumer Protection,
· Income Tax Law No. 193,
· Tax Procedure Law No. 213
· Social Insurance and General Health Insurance Law No. 5510,
· Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications,
· Occupational Health and Safety Law No. 6331,
· Law No. 4817 on Work Permits for Foreigners
· Labor Law No. 4857,
· Decree-Law No. 556 on the Protection of Trademarks
· Turkish Commercial Code No. 6102,
· Law No. 6563 on the Regulation of Electronic Commerce,
· Notaries Law No. 1512,
· Vocational Qualifications Authority Law No. 5544 and the related communiqués introducing the Vocational Qualification Certificate requirement,
· Regulation on Health and Safety Measures to Be Taken in Workplace Buildings and Annexes,
· Regulation on Commercial Communications and Commercial Electronic Messages, published in Official Gazette No. 29417 dated 15.07.2015,
· Regulation No. 27866 on Distance Contracts.
· Regulation on Personal Health Data,
· Regulation on the Improvement and Evaluation of Quality in Healthcare,
· Presidential Decree No. 1 on the Organization of the Presidency,
and the other secondary legislation in force pursuant to these laws.
4.2.B. Processing Purposes Requiring Retention
Our Company processes and retains personal data for the following purposes and under the following conditions, limited to the purposes and conditions within the personal data processing conditions set forth in paragraph 2 of Article 5 and in Article 6 of the KVKK.
These purposes and conditions are as follows:
· Protection of public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning and management of healthcare services and their financing.
· Conducting Emergency Management Processes
· Conducting Information Security Processes
· Conducting Employee Candidate / Intern / Student Selection and Placement Processes
· Conducting Employee Candidates’ Application Processes
· Conducting Employee Satisfaction and Engagement Processes
· Fulfilling Obligations Arising from Employment Contracts and Legislation for Employees
· Conducting Fringe Benefits and Perquisites Processes for Employees
· Conducting Audit / Ethics Activities
· Conducting Training Activities
· Managing Access Authorizations
· Conducting Activities in Compliance with the Legislation
· Conducting Finance and Accounting Affairs
· Conducting Company / Product / Service Loyalty Processes
· Ensuring Physical Premises Security
· Conducting Assignment Processes
· Monitoring and Conducting Legal Affairs
· Conducting Internal Audit / Investigation / Intelligence Activities
· Conducting Communication Activities
· Planning Human Resources Processes
· Conducting / Auditing Business Activities
· Conducting Occupational Health / Safety Activities
· Receiving and Evaluating Suggestions for the Improvement of Business Processes
· Conducting Business Continuity Activities
· Conducting Goods / Services Procurement Processes
· Conducting Goods / Services After-Sales Support Services
· Conducting Goods / Services Sales Processes
· Conducting Goods / Services Production and Operation Processes
· Conducting Customer Relationship Management Processes
· Conducting Customer Satisfaction Activities
· Organization and Event Management
· Conducting Performance Evaluation Processes
· Conducting Risk Management Processes
· Conducting Storage and Archiving Activities
· Conducting Social Responsibility and Civil Society Activities
· Conducting Contract Processes
· Conducting Strategic Planning Activities
· Tracking Requests / Complaints
· Ensuring the Security of Movable Property and Resources
· Conducting Supply Chain Management Processes
· Conducting Remuneration Policy
· Ensuring the Security of Data Controller Operations
· Conducting Talent / Career Development Activities
· Providing Information to Authorized Persons, Institutions and Organizations
· Conducting Management Activities
· Creating and Tracking Visitor Records
4.3. Reasons Requiring Destruction
Personal data shall be deleted or destroyed by the Company upon the request of the data subject, or deleted, destroyed or anonymized ex officio, in the following cases:
· Amendment or repeal of the provisions of the relevant legislation constituting the basis for their processing,
· Elimination of the purpose requiring their processing or retention,
· Withdrawal of explicit consent by the data subject, in cases where the processing of personal data is based solely on explicit consent,
· Acceptance by the company of an application made by the data subject for the deletion and destruction of his or her personal data within the framework of the data subject’s rights under Article 11 of the Law,
· Where the Company rejects an application made to it by the data subject requesting the deletion, destruction or anonymization of his or her personal data, where the data subject finds the Company’s response insufficient, or where the Company fails to respond within the period stipulated in the Law, the filing of a complaint with the Board by the data subject and the approval of this request by the Board,
· Expiry of the maximum period requiring the retention of personal data, and the absence of any condition justifying the retention of personal data for a longer period.
5. TECHNICAL AND ADMINISTRATIVE MEASURES
Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi takes all necessary measures, within its means and according to the nature of the data to be protected, to prevent the unlawful disclosure of, access to or transfer of personal data, or security deficiencies that may arise in other ways. In this context, Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi takes all necessary administrative and technical measures, establishes an audit system within the company and, in the event of unlawful disclosure of personal data, acts in accordance with the measures stipulated in the KVKK.
· Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi trains its employees and raises their awareness regarding the legislation on the protection of personal data.
· Where personal data are subject to transfer, the company ensures that the contracts concluded with the persons to whom personal data are transferred include provisions stating that the party receiving the personal data will fulfill its obligations to ensure data security.
· The personal data processing activities carried out by Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi are examined in detail, and in this context, the steps to be taken to ensure compliance with the personal data processing conditions stipulated in the KVKK are identified.
· Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi identifies the practices that must be implemented to ensure compliance with the KVKK and regulates these practices through internal policies.
· Nevresta Turizm Mimarlık İnşaat İşletmecilik Ticaret Anonim Şirketi takes technical measures for the protection of personal data to the extent permitted by technology, and the measures taken are updated and improved in line with developments.
· Expert personnel are employed for technical matters.
· The implementation of the measures taken is audited at regular intervals.
· Software and systems to ensure security are installed.
· Access authorization to personal data processed within the company is limited to the relevant employees in line with the specified processing purpose.
5.1. Technical Measures
The technical measures taken by the Company with respect to the personal data it processes are listed below:
· Through penetration tests, risks, threats, vulnerabilities and any security gaps in our Company’s information systems are identified and the necessary measures are taken.
· Through information security incident management, risks and threats that may affect the continuity of information systems are continuously monitored on the basis of real-time analyses.
· Access to information systems and the authorization of users are managed through security policies via the access and authorization matrix and the corporate active directory.
· The necessary measures are taken for the physical security of our Company’s information systems equipment, software and data.
· To ensure the security of information systems against environmental threats, hardware measures (an access control system allowing only authorized personnel to enter the system room, a 24/7 monitoring system, ensuring the physical security of the edge switches forming the local area network, a fire suppression system, an air-conditioning system, etc.) and software measures (firewalls, intrusion prevention systems, network access control, anti-malware systems, etc.) are taken.
· Risks relating to the prevention of unlawful processing of personal data are identified, appropriate technical measures are taken in line with these risks, and technical controls are performed on the measures taken.
· Access procedures are established within the Company, and reporting and analysis activities regarding access to personal data are carried out.
· Access to storage areas containing personal data is logged, and inappropriate access or access attempts are kept under control.
· The Company takes the necessary measures to ensure that deleted personal data are inaccessible and non-reusable for the relevant users.
· The Company has established an appropriate system and infrastructure to notify the data subject and the Board if personal data are unlawfully obtained by others.
· Security vulnerabilities are monitored, appropriate security patches are installed, and information systems are kept up to date.
· Strong passwords are used in electronic media where personal data are processed.
· Secure logging systems are used in electronic media where personal data are processed.
· Data backup programs that ensure the secure storage of personal data are used.
· Access to personal data stored in electronic or non-electronic media is restricted in accordance with access principles.
· Access to the corporate website is encrypted with the SHA-256-bit RSA algorithm using a secure protocol (HTTPS).
· A separate policy has been established for the security of special categories of personal data.
· Employees involved in the processing of special categories of personal data have been provided with training on the security of special categories of personal data, confidentiality agreements have been concluded, and the authorizations of users with access to the data have been defined.
· Electronic media in which special categories of personal data are processed, stored and/or accessed are protected using cryptographic methods, cryptographic keys are kept in secure environments, all transaction records are logged, security updates for such media are continuously monitored, the necessary security tests are regularly performed or commissioned, and test results are recorded,
· Adequate security measures are taken for physical environments in which special categories of personal data are processed, stored and/or accessed, and their physical security is ensured to prevent unauthorized entry and exit.
· If special categories of personal data must be transferred by e-mail, they are transferred in encrypted form using a corporate e-mail address. If they must be transferred via media such as portable storage devices, CDs or DVDs, they are encrypted using cryptographic methods and the cryptographic key is kept in a different medium. If a transfer is carried out between servers in different physical environments, the data transfer is performed by establishing a VPN between the servers or by using the sFTP method. If transfer on paper is required, the necessary measures are taken against risks such as theft, loss or viewing of the documents by unauthorized persons, and the documents are sent in “confidential” format.
5.2. Administrative Measures
The administrative measures taken by the Company for the lawful processing and protection of personal data are listed below:
· Company employees are informed and trained on personal data protection law and the lawful processing of personal data.
· All personal data processing activities carried out by the Company are conducted in accordance with the personal data inventory and its annexes, which have been created through a detailed analysis of all business units.
· With respect to the personal data processing activities carried out by the relevant departments within the Company, the obligations to be fulfilled to ensure that these activities comply with the personal data processing conditions required by the KVKK have been set out by the Company in written policies and procedures, each business unit has been informed thereof, and the matters requiring attention specific to the activities it carries out have been identified.
· Before commencing the processing of personal data, the Company fulfills its obligation to inform the data subjects.
· The audit and management of personal data security in the departments within the Company are organized by Information Security Committees. Awareness is raised to ensure compliance with the legal requirements identified for each business unit, and the administrative measures necessary to ensure the auditing of these matters and the continuity of their implementation are put into practice through in-house policies, procedures and training.
· Provisions containing information on personal data and data security are included in the service contracts and related documents between the Company and its employees, and additional protocols are executed. Work has been carried out to create the necessary awareness among employees in this regard.
· Access authorizations to physical environments containing personal data are restricted.
· Special categories of personal data are stored in a physical area allocated to the health team within the company and are closed to access.
· Personal data processing activities carried out within the Company are audited regularly.
· The contracts signed contain data security provisions.
· Additional security measures are taken for personal data transferred on paper, and the relevant documents are sent in the format of classified documents.
· Periodic and/or random internal audits are performed and commissioned.
· The security of physical environments containing personal data against external risks (fire, flood, etc.) is ensured.
5.2.A. Audit of the Measures Taken for the Protection of Personal Data
Pursuant to paragraph 3 of Article 12 of the Personal Data Protection Law, the data controller is obliged to conduct or commission the necessary audits within its own institution or organization in order to ensure the implementation of the provisions of this Law.
The Company conducts and/or commissions the necessary audits to establish the data security described above and to ensure the regularity and continuity of the measures taken.
5.2.B. Measures to Be Taken in the Event of Unlawful Disclosure of Personal Data
Within the scope of the personal data processing activities carried out by our Company, if personal data are unlawfully obtained by unauthorized persons, the situation shall be notified without delay to the Personal Data Protection Board and the relevant data subjects.
6. PERSONAL DATA DESTRUCTION TECHNIQUES
Personal data obtained by the Company in accordance with the KVKK and other relevant legislation shall, if the purposes of processing personal data listed in the Law and the Regulation cease to exist, be destroyed by the Company ex officio or upon the application of the Data Subject, again in accordance with the provisions of the Law and the relevant legislation, using the techniques set out below.
6.1. Deletion of Personal Data
The procedures and principles regarding the techniques for the deletion and destruction of personal data by the Company are listed below.
Secure Deletion of Personal Data on Servers by Software: Data processed by wholly or partly automated means and stored in digital media shall be deleted using methods for deleting the data from the relevant software in such a manner that they are rendered inaccessible and non-reusable in any way for Relevant Users.
Where the relevant data in the cloud system are deleted by issuing a delete command, the process shall be carried out using methods such as removing the relevant user’s access rights to the file or to the directory containing the file on the central server, deleting the relevant rows in databases using database commands, or deleting data on portable media, i.e., flash media, using appropriate software.
However, if the deletion of personal data within the Company, where necessary, would result in the inability to access and use other data within the system, the personal data shall also be deemed deleted if they are archived in a manner that prevents them from being associated with the data subject, provided that the following conditions are met.
The data are closed to access by any other institution, organization or person,
All necessary technical and administrative measures are taken to ensure that personal data can be accessed only by authorized persons.
Secure Deletion by an Expert: Where it deems necessary, the Company may engage an expert to delete personal data on its behalf. In this case, the personal data are securely deleted by the person who is an expert in this field in such a manner that they are rendered inaccessible and non-reusable in any way for Relevant Users.
Blacking Out Personal Data on Paper: In order to prevent the use of personal data for purposes other than those intended, or to delete data whose deletion has been requested, personal data may also be deleted by physically cutting the relevant personal data out of the document, or by rendering them invisible or covering them with permanent ink in a manner that is irreversible and cannot be read using technological solutions.
Table-4: Deletion of Personal Data
|
Data Recording Medium |
Description |
|
Personal Data on Servers |
For personal data on servers whose required retention period has expired, deletion is performed by the system administrator by revoking the access authorization of the relevant users. |
|
Personal Data in Electronic Media |
Personal data in electronic media whose required retention period has expired are rendered inaccessible and non-reusable in any way for all employees (relevant users) other than the database administrator. |
|
Personal Data in Physical Media |
Personal data kept in physical media whose required retention period has expired are rendered inaccessible and non-reusable in any way for all employees other than the unit manager responsible for the document archive. In addition, a blackout process is applied by drawing over, painting over or erasing the data so that they cannot be read. |
|
Personal Data on Portable Media |
Personal data kept in flash-based storage media whose required retention period has expired are encrypted by the system administrator, access authorization is granted only to the system administrator, and the data are stored in secure environments together with the encryption keys |
6.2. Destruction of Personal Data
The destruction methods to be used by our Company are set out below:
Degaussing: A method in which magnetic media are subjected to physical change by exposure to a high-intensity magnetic field, corrupting the data on them so that they cannot be read.
Physical Destruction: Personal data may also be processed by non-automated means provided that they form part of a data filing system. This is the process of physically destroying such data so that they cannot be used afterwards. Written paper, notebooks and microfiche, in particular, are destroyed in this manner.
Overwriting: The overwriting method is a data destruction method that makes it impossible to read and recover old data by writing random data consisting of 0s and 1s at least 8 times over magnetic media and rewritable optical media by means of special software.
Cloud Destruction: The process of destroying all copies of the encryption keys of personal data stored on cloud systems after notice of destruction of such personal data has been given to the contracted service provider.
Destruction of Personal Data in Peripheral Systems: Devices containing personal data within systems such as printers, fingerprint units and door entry turnstiles are destroyed by overwriting, degaussing or physical destruction. These destruction operations are performed before the devices are subjected to backup, maintenance and similar operations.
Table-5: Destruction of Personal Data
|
Data Recording Medium |
Description |
|
Personal Data in Physical Media |
Personal data on paper whose required retention period has expired are irreversibly destroyed in paper shredders. |
|
Personal Data on Optical / Magnetic Media |
Personal data on optical and magnetic media whose required retention period has expired are physically destroyed by means such as melting, incineration or pulverization. In addition, the data on magnetic media are rendered unreadable by passing the media through a special device and exposing them to a high-intensity magnetic field. |
6.2. Anonymization of Personal Data
Anonymization of personal data means rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even if they are matched with other data.
For personal data to be deemed anonymized, they must be rendered incapable of being associated with an identified or identifiable natural person even through the use of techniques appropriate to the recording medium and the relevant field of activity, such as reversal by the data controller or third parties and/or matching the data with other data.
6.3.A. Anonymization Methods That Do Not Create Value Irregularity
These are anonymization methods applied, without making any change, addition or removal to the stored personal data, by generalizing or swapping any group of personal data or by removing a specific data item or data subgroup from the group.
Variable Removal: Under the method of removing descriptive data, the existing data set is anonymized by removing “highly descriptive” variables from the data set created after the collected data have been compiled.
Record Removal: Under the record removal method, the stored data are anonymized by removing from the records any data row that contains uniqueness among the data. For example, if there is only one senior manager in a company, the remaining data can be anonymized by removing that person’s data from the records containing the seniority, salary and gender data of employees at the same level.
Regional Masking: Under the regional masking method, if a single data item has an identifying character because it creates a combination that is very rarely seen, masking the relevant data item ensures anonymization. For example, in a data set that stores together age, gender and information on whether a person is fit to play football in terms of health, if only one person among the relevant individuals on the reserve list of the company’s football team is 65 years old, writing ‘Unknown’ instead of ‘Age: 65’ or leaving this field blank will ensure anonymization.
Top and Bottom Coding: Under the top and bottom coding method, data are anonymized by combining the values in a data group containing predefined categories based on a specified criterion.
Generalization: Under the data aggregation method, multiple data items are aggregated and the personal data are rendered incapable of being associated with any individual. For example, indicating that there are Z employees aged X without showing the ages of employees individually.
Global Recoding: Under the data derivation method, a more general content is created from the content of the personal data, ensuring that the personal data cannot be associated with any individual. For example, stating ages instead of dates of birth, or stating the region of residence instead of the full address.
6.3.B. Anonymization Methods That Create Value Irregularity
Unlike methods that do not create value irregularity, anonymization methods that create value irregularity introduce distortion by altering certain data within personal data groups. When using these methods, deviations must be applied carefully in line with the benefit expected/desired to be obtained. By ensuring that aggregate statistics are not distorted, the expected benefit can continue to be derived from the data.
Adding Noise: Under the method of adding noise to data, particularly in a data set consisting predominantly of numerical data, the data are anonymized by adding certain positive or negative deviations at a specified rate to the existing data. For example, in a data group containing weight values, by applying a deviation of (+/−) 3 kg, the actual values are prevented from being displayed and the data are anonymized. The deviation is applied equally to each value.
Micro Aggregation: Under the micro aggregation method, all data are first sorted in a meaningful order (e.g., from largest to smallest) and divided into groups, the average of each group is calculated, and the resulting value is written in place of the relevant data in that group, thereby achieving anonymization.
(For example, for salary information, if two groups are formed, below and above TRY 10,000, the total salaries of persons earning TRY 10,000 or less are divided by the number of such persons, and the resulting value is entered in the salary field of everyone earning below TRY 10,000.)
Data Swapping: Under the data swapping method, the values of a variable are exchanged between pairs selected from among the stored data. The purpose of this method, which is generally used for data that can be categorized, is to transform the database by swapping the data of data subjects with one another.
6.3.C. Assurance of Anonymity
In order for a decision to be made to anonymize personal data instead of deleting or destroying them, the following conditions must be met.
· The anonymity of the anonymized data set cannot be broken by combining it with another data set,
· One or more values cannot form a meaningful whole in a way that could make a record unique,
· The values in the anonymized data set cannot be combined to produce an assumption or conclusion.
7. RETENTION AND DESTRUCTION PERIODS
With respect to the personal data processed by the Company within the scope of its activities;
· Retention periods on a personal-data basis for all personal data within the scope of activities carried out in connection with processes are set out in the Personal Data Processing Inventory;
· Retention periods on a process basis are set out in the Personal Data Retention and Destruction Policy
.
Where necessary, such retention periods are updated by the Company’s management.
For personal data whose retention periods have expired, ex officio deletion, destruction or anonymization is carried out by the responsible personnel assigned in the KVK process with the approval of the Company’s management.
Table-6: Retention and destruction periods by process
|
PROCESS |
RETENTION PERIOD |
DESTRUCTION PERIOD |
|
Clinical Procedures |
+ 10 Years from the Termination of the Legal Relationship |
At the first periodic destruction following the expiry of the retention period |
|
Preparation of contracts |
+ 10 Years from the Termination of the Legal Relationship |
At the first periodic destruction following the expiry of the retention period |
|
Conducting Communication Activities |
+ 10 Years from the Termination of the Legal Relationship |
At the first periodic destruction following the expiry of the retention period |
|
Conducting Human Resources Processes |
+ 10 Years from the Termination of the Legal Relationship |
At the first periodic destruction following the expiry of the retention period |
|
Log Records of Employees’ Access to Media Containing Personal Data |
2 years |
At the first periodic destruction following the expiry of the retention period |
|
Conducting Hardware and Software Access Processes |
2 Years |
At the first periodic destruction following the expiry of the retention period |
|
Payroll |
+ 10 Years from the Termination of the Legal Relationship |
Within 180 days following the expiry of the retention period |
|
Filing of training records |
+ 10 Years from the Termination of the Legal Relationship |
Within 180 days following the expiry of the retention period |
|
Registration of Visitors and Meeting Participants |
2 years from the end of the event
|
At the first periodic destruction following the expiry of the retention period |
|
Personal Data Processed for Security Purposes by CCTV Cameras (camera recordings) |
3 Months |
Within 180 days following the expiry of the retention period |
|
Payment transactions |
1 year from the termination of the business relationship |
Within 180 days following the expiry of the retention period |
|
Personal Data Processed in Contractual Relationships (Company officer, Name-Surname, Signature) |
+ 10 Years from the Termination of the Legal Relationship |
Within 180 days following the expiry of the retention period |
|
Traffic Data Processed During Use of the Company Internet Network, Internet Access and Remote Connection |
2 Years |
Within 180 days following the expiry of the retention period |
|
Customer Transaction Information (Records of Customer Requests / Complaints / Suggestions) |
+ 10 Years from the Termination of the Legal Relationship |
Within 180 days following the expiry of the retention period |
|
Data Relating to Potential Customers (Data Relating to Profiling via Social Media and Cookies) |
+ 10 Years from the Termination of the Legal Relationship |
Within 180 days following the expiry of the retention period |
|
Data Relating to Personnel Files Retained Under the Labor Law (severance pay, notice pay, payroll records, number of annual leave days) |
+ 10 Years from the Termination of the Legal Relationship |
Within 6 months following the expiry of the retention period |
|
Data Collected Within the Scope of Occupational Health and Safety |
+ 15 Years from the Termination of the Legal Relationship |
Within 6 months following the expiry of the retention period |
|
Personal data that may be processed in connection with documents supporting entries in commercial books, financial statements, etc. required to be retained in accordance with the Company’s activities |
+ 10 Years from the Termination of the Legal Relationship |
Within 180 days following the expiry of the retention period |
Table-7: Retention periods by data category
|
DATA CATEGORY |
RETENTION PERIOD |
|
Identity |
+ 10 Years from the Termination of the Legal Relationship |
|
Contact |
+ 10 Years from the Termination of the Legal Relationship |
|
Personnel File |
+ 10 Years from the Termination of the Legal Relationship |
|
Legal Transaction |
+ 10 Years from the Termination of the Legal Relationship |
|
Customer Transaction |
+ 10 Years from the Termination of the Legal Relationship |
|
Physical Premises Security |
2 Years |
|
Transaction Security |
2 Years |
|
Risk Management |
+ 10 Years from the Termination of the Legal Relationship |
|
Finance |
+ 10 Years from the Termination of the Legal Relationship |
|
Professional Experience |
+ 10 Years from the Termination of the Legal Relationship |
|
Marketing |
2 Years |
|
Visual and Audio Recordings |
3 Months |
|
Health Information |
+ 10 Years from the Termination of the Legal Relationship |
8. PERIODIC DESTRUCTION PERIOD
Pursuant to Article 11 of the Regulation, our Company has set the periodic destruction interval at 6 months. Accordingly, periodic destruction is carried out at our Company in June and December of each year.
9. PUBLICATION AND STORAGE OF THE POLICY
The Policy is published in two different media, namely with a wet signature (printed on paper) and in electronic form, and is disclosed to the public on the website. The printed paper copy is also kept at the Company’s head office.
10. UPDATE PERIOD, ENTRY INTO FORCE AND REPEAL OF THE POLICY
This Policy is submitted for the approval of the Board of Directors and enters into force upon its approval by the Board of Directors. The Board of Directors may amend this Policy at any time as necessary. The Policy becomes effective immediately upon its publication at https://www.akropol.com/ . If a decision is made to repeal the Policy, the old wet-signed copies of the Policy are canceled by resolution of the Board of Directors (by affixing a cancellation stamp or writing “canceled”), signed, and retained for a period of at least 5 years.