Personal Data Protection and Clarification Texts
Privacy Policy and Agreements
Policies
The Personal Data Protection Law no. 6698 is among top priorities of our Company. The most important pillar of this subject matter is the protection and processing of personal data of our customers, prospective customers, employee candidates, company shareholders, company officers, our visitors and the employees, shareholders and officers of the entities we cooperate with as well as third parties as managed pursuant to this Policy. Actions taken by our company for the protection of personal data of our employees are administered in line with the "Personal Data Protection and Processing Policy" for the employees of ÖZDİSAN ELEKTRONİK PAZARLAMA SAN. TİC. A.Ş. (the "COMPANY").
According to Turkish Republic Constitution, everyone has the right to demand that his personal data should be protected. With respect to the protection of personal data, which is a constitutional right, the Company pays due care and diligence to protect the personal data of our customers, prospective customers, employee candidates, company shareholders, company officers, our visitors and the employees, shareholders and officers of the entities we cooperate with as well as third parties as governed hereunder, and turns it into a corporate policy. Accordingly, the Company adopts necessary administrative and technical measures to protect personal data that are processed pursuant to the applicable legislation.
This Policy shall provide detailed explanations as to the below-listed fundamental principles adopted by the Company for processing personal data:
The basic purpose of this Policy is to make disclosures about the systems for processing personal data in line with the laws and adopted for the protection of personal data and, accordingly, to ensure transparency by informing those whose personal data are processed by us, including our customers, prospective customers, employee candidates, company shareholders, company officers, our visitors and the employees, shareholders and officers of the entities we cooperate with as well as third parties.
This Policy shall be applicable to all personal data of our customers, prospective customers, employee candidates, company shareholders, company officers, our visitors and the employees, shareholders and officers of the entities we cooperate with as well as third parties whose personal data are processed automatically, or provided to be a part of any data recording system, non-automatic means.
The scope of application of this Policy in connection with personal data groups categorized above may be the entire Policy (for instance our active customers, who are our visitors) or certain provisions of them may be applicable (e.g. for only our visitors).
Applicable laws and regulations shall have priority with respect to the processing and protection of personal data. In the case of a conflict between the applicable legislation and the Policy, our Company acknowledges that applicable legislation shall be implemented.
The Policy has been drafted by materializing the rules set out in the applicable legislation in connection with the corporate practices.
We would like to remind you that unless you accept this Policy, you should not disclose your personal data to us. If you choose not to disclose your personal data to us, we would like to inform you that it may be impossible for us to offer certain services to you, or fulfill your requests or provide you with our services completely.
We would like to remind you that whether or not the personal data disclosed by you to us are correct, complete and update is within your responsibility to the extent you are aware. In addition, if you disclose personal data of other individuals, it is your responsibility to collect such data in line with the local statutory requirements. In this case, if we collect third party personal data from third parties, this means that we have obtained all consents necessary to process, use and disclose them, and our Company shall not be held liable for such operations.
This Policy was issued and put into force by the Company on 15.06.2019. The latest revision was made on 02.02.2026.
Our Company adopts technical and administrative measures in order to prevent the unlawful processing of, and unlawful access to, personal data processed by it and ensure such level of security for the storage of data in line with Article 12 of the PDPL no.6698. Controls and audits in that respect are carried out by or on behalf of our Company.
Our Company adopts such technical and administrative measures to ensure the lawful processing of personal data to the extent technological means and implementation cost allows it.
Technical Measures adopted to ensure the lawful processing of personal data
Administrative Measures adopted to ensure the lawful processing of personal data
Major administrative measures are listed below to ensure that our Company shall process personal data in line with the applicable law:
Personal data processing operations undertaken by our business units are specifically determined for each business unit and the detailed operations undertaken by it in line with those requirements to ensure compliance with conditions for personal data processing as sought by the Law no. 6698.
An awareness is created, and implementation rules are defined, for each relevant business unit to ensure requirements for legal compliance set for that business unit. Those administrative measures necessary to audit these procedures and ensure the sustainability of the implementation are applied by in-house policies and training courses.
Reservations and provisions are incorporated into contracts and documents governing legal relation between our company and employees in order to restrict the processing, disclosure and use of the personal data, and the employee awareness is created and audits are carried out in this respect.
Our Company adopts technical and administrative measures in light of the nature of the data to be protected, technological means and cost of implementation to avoid the disclosure, transfer of, or otherwise access to personal data with recklessness or in an unauthorized manner unlawfully.
Technical Measures adopted to prevent unlawful access to personal data
Major technical measures listed below to ensure that our Company shall prevent unlawful access to personal data:
Administrative Measures adopted to prevent unlawful access to personal data
Major administrative measures listed below to ensure that our Company shall prevent unlawful access to personal data:
Our company takes all necessary technical and administrative measures to store personal data safely and prevent the destruction, loss and modification of them for unlawful purposes to the extent technological means and implementation costs allow them.
Technical Measures adopted to ensure safe storage of personal data
Below are major technical measures that our Company has adopted to ensure the safe storage of personal data:
Administrative Measures adopted to ensure safe storage of personal data
Below are major administrative measures that our Company has adopted to ensure the safe storage of personal data:
Necessary periodic audits are carried out by or on behalf of our Company in its own organization by way of sampling method in line with Article 12 of the PDPL. The results of these audits as well as any non-conformity identified in the course of the Company's in-house procedures are reported and necessary actions are taken to improve those measures taken. The Company's Board of Directors is informed about the results of the said audit.
Our Company runs a system whereby third parties capture personal data processed in line with Article 12 of the PDPL unlawfully, this is reported to the personal data subject as well as the PDP Committee as soon as possible and within 72 hours at the latest from the time the Company becomes aware of it.
If it is deemed necessary by the PDP Committee, this may be posted at the PDP Committee's web site or published by any other means.
PRP Law places a special emphasis on certain personal data as the unlawful processing of such data carries a risk that may cause individuals to be aggrieved or discriminated.
These data include race, ethnic origin, political though, philosophical beliefs, religion, sect or other faith, clothing and attire, membership to association, foundations or unions, healthcare data, sexual life, criminal conviction and security measures as well as biometric and genetic data.
Our Company acts diligently for the protection of sensitive personal data that are designated as "sensitive" by virtue of the PDP Law and are processed in line with the law. Accordingly, our Company diligently applies technical and administrative measures aimed to protect personal data to sensitive personal data, and required audits are carried out inside our organization.
Section 3 of this Policy details the information about the processing of sensitive personal data.
Our Company ensures that necessary briefing and training sessions are organized for business units to enhance awareness for preventing unlawful access to data, unlawful processing of personal data and to ensure the safe storage of the data.
Our employees are duly informed and assume basic obligations by virtue of the corporate Code of Conduct provisions necessary to raise awareness for the protection of personal data of those employees seconded to the business unit new as well as the existing employees of such business unit. and the Code of Conduct is annually reviewed and tested electronically to ensure the sustainability.
The participation in training sessions is reported to the relevant managers. In light of the foregoing, our Company assesses the participation and involvement in relevant training courses, seminars and information sessions, and necessary audits in this respect are carried out by or on behalf of the Company. Our Company updates and renews its training sessions in line with the updated legislation.
Our Company regularly provides its business partners with information to enhance awareness for preventing unlawful processing of, and unlawful access to, personal data and to ensure the storage of the data.
We basically collect your personal data when:
We process your personal data that we collect as mentioned above only in compliance with this Policy.
Our Company processes personal data in connection with, limited to, and proportional with, the purpose in line with Article 20 of the Constitution and Article 4 of the PDPL and accurately and whenever it is required and backed by up-to-date, specific, express and legitimate purposes and motives. Our Company stores personal data for such term as required by the laws or by the purpose of personal data processing.
As per Article 20 of the Constitution and Article 5 of the PDPL, our Company processes personal data in line with one or more than one terms and conditions set out in Article 5 of the PDPL as applicable to the processing of personal data. Notwithstanding the foregoing and pursuant to Article 10 of the PDPL, we provide personal data subjects with a privacy notice and give them necessary information upon their request.
Our Company acts in line with the applicable legislation for the processing of sensitive personal data pursuant to Article 6 of the PDPL. Moreover, with respect to the transfer of personal data in line with Articles 8 and 9 of the PDPL, our Company acts in line with those regulations dictated by the PDP Committee and as set out in the applicable law.
Our Company acts in line with the principles introduced by the legal regulations as well as the rule of general trust and integrity in the case of processing of personal data. Accordingly, our Company gives due consideration to the requirement of proportionality for the purposes of processing personal data, and does not use such data beyond the intended purpose.
Our Company makes sure that personal data processed by it by taking into account fundamental rights of the personal data subjects and its own legitimate interests are correct and up-to-date. It takes necessary measures in this respect. For instance, a system has been established by the Company to allow personal data subjects to correct, and confirm the accuracy of, their personal data.
Our Company explicitly and unambiguously defines the purpose of personal processing by it lawfully and legally. Our Company processes personal data in connection with, and required for, the products and services offered by it. Our Company describes the purpose underlying the process of personal data even before it starts personal data processing.
Our Company processes personal data in a manner that would reach the described purpose, and avoids processing of such personal data that are not related to, or needed for, the achievement of the purpose. For example, the Company does not carry out any personal data processing to meet potential needs that may arise subsequently.
Our Company stores personal data for such term required by the applicable legislation or as much as necessary for the purpose underlying that process. Accordingly, our Company first determines a time period for the storage of the personal data as set out in the applicable legislation; and if a term is determined, it acts in compliance with this time period and unless a term is determined, it stores the personal data that is necessary for the purpose of processing. In the event the reasons for processing are no longer applicable or the term expires, personal data are erased, destroyed or anonymized by our Company. Our Company does not store personal data with the probability that they may be used in future.
Our Company gives a privacy notice to the personal data subjects in the course of the collection of the personal data in line with Article 10 of the PDPL. Accordingly, the Company gives a privacy notice about the identity of the Company, and if any, its representative, the purpose underlying the processing of personal data, and the purposes of transferring processed personal data to whom, and the legal grounds and management of collecting personal data as well as the rights held by the personal data owner.
Pursuant to Article 11 of the PDPL, our Company provides personal data subjects with such necessary information upon their request and through all channels via which their data are collected.
Our Company diligently acts with the provisions set out in the PDPL in the case of processing personal data that are designated as "sensitive data" under the PDP Law.
Article 6 of the PDPL defines certain personal data as "sensitive data" if such data causes grief or discrimination of individuals when they are unlawfully processed. These data include race, ethnic origin, political though, philosophical beliefs, religion, sect or other faith, clothing and attire, membership to association, foundations or unions, healthcare data, sexual life, criminal conviction and security measures as well as biometric and genetic data.
Sensitive personal data are processed by our Company in the following circumstances in line with the PDPL subject to the requirement that sufficient measures to be designated by the PDP Committee are adopted.
By virtue of the new amendments adopted on 12 March 2024, provisions for the processing of Sensitive Data are amended as follows as of June 2024:
Pursuant to the Law, conditions to process sensitive personal data were re-worded in Article 6 of the PDPL:
Subject to the explicit consent of the data subject, our Company may transfer personal data and sensitive personal data of such data subject to third parties (third party companies, group companies, the Company and/ or business partners, their subsidiaries and shareholders, third party individuals, suppliers, legally authorized private and public enterprises, the Company's service providers, outsourcers or business partners) by taking security measures (see Chapter 2/ Article 1) in line with the lawful purposes of personal data processing and subject to the explicit consent of the data subject. We act in line with regulations set out in Article 8 of the PDPL in this respect.
Our Company may transfer personal data to third parties to the limited extent and based on one or several conditions for processing personal data as described in Article 5 of the Law in line with the legitimate and lawful purposes for processing personal data. Section 5.1 of this Policy details the information about these circumstances.
Our Company may transfer sensitive personal data of the data subject to third parties in circumstances described in Article 3.3 of this Policy in line with the legitimate and lawful purposes of processing personal data by paying due care and diligence, taking those necessary security measures (see Section 2/ Article 2.1) and other sufficient measures required by the PDP Committee.
Our Company acts in line with the decisions adopted by the PDP Committee as required under the PDPL and the applicable legislation, including, in particular, Article 8 of the PDPL for the transfer of personal data. Personal and sensitive data of data subjects may not be transferred by our Company to other individuals or legal persons without the explicit consent of the data subject.
Moreover, it is possible to transfer personal data without the consent of the data subject in circumstances described in Articles 5 and 6 of the PDPL. Our Company may transfer personal data to subsidiaries who are members of DMY Group and third parties based in Türkiye unless otherwise is agreed in the Law or other applicable legislation (or if there is a contract in force made with the data subject, in that contract), provided that conditions and terms set out in the PDPL and other applicable legislation are observed and security measures described in the applicable legislation are taken.
Parties to the transfers made in Türkiye and abroad
We may share your personal data in line with the following purposes to the extent it is necessary. We try our best not to share your personal data other than these circumstances. Parties to whom we share personal data are as follows:
DMY Group Companies: Your personal data may be shared with, or be made available to, DMY group companies, whose subsidiary we are. This share shall be made only with the authorized employees of the relevant DMY group subsidiaries. In certain exclusive circumstances, we may share personal data with DMY group companies in lieu of anonymized data (such as sharing details of claims to open an insurance claims file).
Service providers and business partners: These are defined as those parties with whom we build a business partnership in the course of our business operations for the sales, promotion, marketing, aftermarket services for our services. Like many other enterprises, we may cooperate with reliable third parties such as information and communication technology providers, consultants, cargo companies, travel agents in order to carry out functions and services in the most efficient manner and in line with up-to-date technologies under certain data processing operations. This disclosure shall be made to a limited extent in order to build a business partnership or ensure that purpose of performance is achieved. We use cloud computing technologies in order to take maximum advantage of technological means to carry out our operations in the most efficient manners, and accordingly, we are able to process your personal data in Türkiye and abroad by means of companies offering cloud computing services. Marketing services outsourcer to which we disclose information may be based abroad, and accordingly, data may be transferred to abroad in line with those provisions of Articles 8 and 9 of the PDPL which deals with the data transfer to abroad.
Public authorities: Where necessitated by the laws or if it is necessary to defend our rights, we can disclose your personal data to relevant public, judicial and administrative authorities (for instance, tax offices, law enforcement officers, courts and enforcement offices).
Private law entities: We may disclose personal data to the extent limited by the purpose if private law entities authorized to collect data and documents from our office request in line with their jurisdiction according to the applicable law (for instance, Occupational Health and Safety Company, OHSC).
Professional advisors: We can share your personal data with banks, insurers, auditors, lawyers, certified public accountants and other consultants and professional advisors.
Other persons connected with corporate actions: We can disclose your personal data from time to time for the handling of corporate actions such as the sale of a business owned by our company, reorganization, merger, joint venture or other disposal of our business, assets or shares (including those ones connected with any bankruptcy or a similar procedure).
Our Company may transfer personal data and sensitive data of a data subject to its business partners/ suppliers (legal persons) based abroad if necessary (by taking those measures asked by the PDP Committee) as well as such security measures necessary in line with the lawful purposes of personal data processing (see Section 2/ Article 2.1). Personal data are transferred by our Company to those data controllers in a foreign jurisdiction said by the PDP Committee to afford a sufficient protection ("Foreign Jurisdictions with Sufficient Protection") or, where there is no sufficient protection, to such data controllers based in Türkiye and the applicable foreign jurisdiction which hold a permission from the PDP Committee and which submit a written letter of undertaking to afford a sufficient level of protection or to foreign jurisdictions with a sufficient permission from the PDP Committee ("Foreign Jurisdiction where Data Controller undertaking Sufficient Protection is based"). We act in line with regulations set out in Article 9 of the PDPL in this respect.
Our Company informs to the data subject such person groups to whom personal data are transferred in line with Article 10 of the PDPL.
Our Company may transfer personal data of its customers to the following individual categories in line with Articles 8 and 9 of the PDPL (see Section 3/ Article 3.5):
The scope of those persons to whom data are transferred and the purposes of data transfer are as follows:
| Persons to whom data may be transferred | Definition | Purposes of Data Transfer |
|---|---|---|
| Business Partner | These are defined as those parties with whom we build a business partnership in the course of our business operations for the sales, promotion, marketing, aftermarket services or handling co-customer loyalty programs for our services. | limited to the purpose of achieving the purpose underlying the business partnership |
| Supplier | This term refers to those parties who provide services to our Company based on a contract in line with our Company's orders and instructions in the course of its business operations. | to the limited extent in order to ensure that our Company shall receive such services necessary to achieve our Company's business operations, provided that these services are to be outsourced to the supplier. |
| Our Subsidiaries | refer to those companies in which our Company is a shareholder. | to the extent limited to ensure the pursue of business operations involving the participation of subsidiaries of our Company that may be founded in future |
| Our Shareholders | Our main shareholders authorized to design strategies and audit operations in connection with our Company's business operations according to the applicable law. | to an extent limited to the purposes of designing and auditing strategies for our Company's business operations according to the applicable law |
| Legally authorized public agencies and institutions | Those public agencies and institutions authorized to collect data and information from our Company in line with the applicable legislation. | to the extent limited to the purpose asked by the relevant public agency and institution under its jurisdiction |
| Private Law Entities | Those private law entities authorized to collect data and information from our Company in line with the applicable legislation. | to the extent limited to the purpose asked by the relevant private law entity under its jurisdiction |
Our Company stores the personal data for such duration set out in the applicable laws and legislation if it is required thereunder.
Unless there is a time period set out in the applicable legislation for the duration of the storage of the personal data, such personal data are processed for such duration that is necessary under our corporate practices and customs of the commercial life in connection with the services offered by our company while processing such data. After its expiry, such data are erased, destroyed or anonymized. A Storage Times Table has been issued in this respect.
Where the purpose for processing personal data is no longer applicable and the storage times defined in the applicable legislation and the company have expired, personal data may be only stored for asserting a right or making a defense or serving as an evidence in a potential legal dispute only. For the purposes of setting the time periods here, storage times are determined on the basis of time bars for asserting the right in question and based on those examples set out in claims asserted against our Company in the same matter even after the expiry of a time bar. In this case, there shall be no access to stored personal data for any other purpose and access to personal data is only available whenever it is to be used in a relevant legal dispute. After the term referred to herein expires, personal data are erased, destroyed or anonymized.
While personal data of personal data subject categories listed below are processed by our company, the implementation scope of this policy is limited to our customers, prospective customers, employee candidates, company shareholders, company officers, our visitors and the employees, shareholders and officers of the entities we cooperate with as well as third parties.
Protection and processing of personal data of our employees shall be addressed under the Policy for the Protection and Processing of Personal data of Company Employees.
While categories of those persons whose personal data are processed by our Company fall within the scope mentioned above, persons that do fall outside these categories may send their requests to us pursuant to the PDPL, and such requests shall be processed in line with this Policy.
Following paragraphs clarify concepts of our customers, prospective customers, employee candidates, company shareholders, company officers, our visitors and the employees, shareholders and officers of the entities we cooperate with as well as third parties as referred to hereunder.
| Personal Data Subject Category | Description |
|---|---|
| Customer | any natural person who uses or has used such products and services offered by our Company irrespective of whether or not there is a contractual relation with our company |
| Potential customer | means any natural person who requests or is interested in using our products or services or who is considered to be interested in them in line with commercial practices and rules of good faith. |
| Visitor | a natural person who has entered in physical sites owned by our country or where an organization is carried out for various purposes or who has visited our web site |
| Third parties | any third party individuals who are associated with the foregoing parties in order to ensure the security of the business operation between our Company and said parties or to defend the rights of those parties or to secure an interest (for instance, suretyships, companions, attendants, family members or next of kin) or other natural persons that do not fall within the scope of this Policy and the Policy for Protection and Processing of Personal Data of Company Employees |
| Employee Candidate | means any natural person who has applied to our Company for a job through any channel or whose curriculum vitae and related information are submitted for our Company's review |
| Company shareholder | any natural person who is a shareholder of our Company or a representative of a shareholder if it is a legal entity; |
| Authorized Company Officer | any board member of our Company or any other natural person authorized by our Company |
| Employees, Shareholders and Authorized Officers of Agencies that we cooperate | any natural person who is employed with a company with a business relation with our Company (including, but not limited to, a business partner, supplier etc.), including shareholders and authorized officers of that company |
Your personal data that we process vary depending on the type of business relation between you and us (for instance customers, suppliers, business partners etc.) and the method by which you choose to contact us (for instance phone, e-mail, over web site or printed documents. etc.).
Our basic methods to process personal data are via our web site, phone or e-mail, electronic applications exclusive to our customers, your visits to our business events, your participation in our promotions and surveys or any other interaction with us. Accordingly, your personal data that we process may be described under the following categories:
| Personal Data Category | Personal Data |
|---|---|
| ID Data | Name, surname, position, date of birth and similar data that appear on ID papers |
| Contact Data | E-mail, GSM or a landline number, contact address |
| Account Log-IN Credentials | Log-in credentials, password or other security codes, user details |
| Audio-visual data determining the ID | Photographs and audio images that are processed for security purposes when you visit our premises or you attend our events; audio-visual data that are processed as well as CCTV records when you visit our premises |
| Financial Data | Credit card details, bank account data, accommodation and spending info, invoice details |
| Other data that you disclose to the company at your will | Any personal data that you disclose upon your consent, any feedback, opinions, demands or complaints, evaluations, comments that you send to us through social media, on-line platforms or other channels or our relevant assessments, uploaded files, areas of interests as well as details supplied for our detailed review before entering a business relation with you |
| Digital electronic data collected by automated means | We can also collect electronic data sent to us from your computer, mobile phone or other access devices in addition to such information that you directly submit to us when you visit or use our web site or applications or subscribe to our news bulletins or interact with us through other electronic channels. (for instance, device hardware model, IP address, operating system release and settings, time when you use our digital channel or product and the duration of such use, your true location (position) that may be collected when you activate location-based products or features, links that you click etc) |
| Legal Transaction Data | Your personal data that are processed to assert our legal claims and rights, to follow them and to perform our obligations, our statutory obligations and your personal data processed in compliance with our policies, audit and inspection data |
| Customer/ Supplier Data | Any data that is collected or generated about data subjects as a result of operations handled by our business units for our services, including data subject customer/ supplier or any employee or authorized signatory of it |
| Incident, Breach and Security Data | Any information and evaluation collected in respect of any incident or breach with a potential effect on our employees, managers or shareholders, license plate and motor vehicle details, access and travel info, airport transfer and access organization |
| Personal Data collected from other sources | Databases that are open to public to the extent permitted by the applicable law and regulations, social media platforms, methods and platforms over which our business partners collect personal data in our name For instance, we can proceed with a due diligence about you in order to ensure technical, administrative and legal safety of our business operations and transactions against public sources before we start a business relation with you. In addition, certain personal data of third parties may be disclosed by you to us. We may process your personal data by means of methods employed in generally accepted legal, ethical values and rules of good faith in order for us to manage our technical and administrative risks In addition, we save your personal data that you disclose via phone, web site or similar platforms subject to your consent, and process such data to solve your problems and claims. |
Our Company gives a privacy notice to the personal data subject about the personal data that we process in line with Article 10 of the PDPL.
The explicit consent by the data subject is only one of the legal grounds that make it possible to process personal data in line with the law. Other than explicit consent, personal data may be processed in case either of the following circumstances occurs. The grounds for processing your personal data may be only one of those conditions set below or there may be several reasons to serve as the basis for this data processing operations. Where processed data are sensitive personal data, those conditions listed in Article 7.1.2 hereunder below shall be applied.
Where legal grounds may differ for processing of personal data by our Company, we act in line with general principles set out in Article 4 of the Law no. 6698 (please see Section 3.1) in all kinds of data processing operations.
One of the conditions for processing personal data is the explicit consent of that data subject. Explicit consent of a personal data subject should be given at his free will and based on information and for a specific topic.
If either of the conditions listed in subparagraphs (ii), (iii), (iv) (v), (vi), (vii) and (viii) for the reasons for collecting personal data is no longer applicable, our Company process personal data based on the explicit consent of the data subject for this processing.
In order to process personal data upon the explicit consent of the personal data subject, an explicit consent should be obtained from the data subject by way of legal methods defined by the Company.
Personal data of a data subject may be processed in line with the applicable law if it is expressly foreseen in the law.
Where a person is unable to express their consent due to actual impossibility or where their consent cannot be recognized as valid, their personal data may be processed if such processing is necessary to protect their own life or physical integrity or that of another person.
Example: A customer who has fainted and whose blood type information is provided to doctors by their friends.
Personal data may be processed if it is necessary for the execution or performance of a contract, provided that it is directly related to the contract and the personal data of the parties to the contract is required.
Example: Obtaining the name and contact details of the purchaser of a product.
If processing is necessary for our Company to fulfil its legal obligations as the data controller, the data subject's personal data may be processed.
Example: Submission of information requested by a court order to the court.
Where the data subject has made their personal data public, the relevant personal data may be processed.
Where data processing is necessary for the establishment, exercise or defense of a legal claim, the data subject's personal data may be processed.
Example: Storage and use of data with evidentiary value (sales contract, invoice) when necessary.
Where data processing is necessary for the legitimate interests of our Company, provided that this does not infringe upon the fundamental rights and freedoms of the data subject, the data subject's personal data may be processed.
Example: Processing of personal data for the purpose of internal Company calculations by the accounting department.
Personal data processing at the entrance of, and inside, the building and facility is carried out by our Company in accordance with the Constitution, the Personal Data Protection Law, and other relevant legislation.
For security purposes, our Company processes personal data by monitoring guest entries and exits using security cameras in our Company buildings and facilities.
Our Company processes personal data by using security cameras and recording guest entries and exits.
Our Company carries out camera surveillance in order to improve the quality of the services provided by the Company, to ensure reliability, to ensure the safety of life and property of the Company, the data subject and other persons, and to protect the legitimate interests of the aforementioned parties.
6.1.1. Legal Ground for Camera Surveillance
The camera surveillance by our Company is conducted in accordance with the Private Security Services Law No. 5188 and related legislation.
6.1.2. Surveillance Activities by Security Cameras according to the PDP Law
In conducting surveillance activities with cameras for security purposes, our Company acts in accordance with the regulations set out in the PDP Law.
Our Company carries out security camera surveillance in its buildings and premises to ensure security, in accordance with the purposes stipulated in the laws and the personal data processing conditions listed in the PDP Law. The PDPL Privacy Notice for Camera Recordings for that surveillance monitoring is also issued.
6.1.3. Announcement of Camera Surveillance
Our Company informs the data subject in accordance with Article 10 of the PDP Law.
In addition to the information provided on general matters (see Section 3/Section 3.3), our Company also posts or provides notices about camera surveillance through multiple methods. This way, we aim to prevent any compromise to the fundamental rights and freedoms of the data subject, ensure transparency, and provide information to the data subject.
With regard to camera surveillance carried out by our Company: This Policy is posted at our Company's website (online Policy regulation) and a notice stating that surveillance is carried out is posted at the entrances to the areas under surveillance (on-site information).
6.1.4. Purpose of Camera Surveillance Activities and Limitation to Purpose
Our Company processes personal data in a manner that is relevant, limited and proportionate to the purpose for which it is processed, in accordance with Article 4 of the Personal Data Protection Law.
The purpose of video camera surveillance by our Company is limited to the purposes listed in this Policy. Accordingly, the surveillance areas, and the number of security cameras, and the surveillance time are all implemented in a manner that is sufficient to achieve the security objective and limited to that purpose. Areas where surveillance could result in interference with a person's privacy beyond security purposes (e.g., toilets) are not subject to surveillance.
6.1.5. Security of Collected Data
In accordance with Article 12 of the PDP Law, our Company takes the necessary technical and administrative measures to ensure the security of personal data collected as a result of camera surveillance activities. (See Section 2/ Section 2.1)
6.1.6. Storage Period of Personal Data collected Through Camera Surveillance
Detailed information regarding the storage period of personal data collected by our Company through camera surveillance by our Company is provided in Section 4.3 of this Policy which is titled Storage Periods of Personal Data.
6.1.7. Those parties with an Access to the Data collected from Surveillance Operations and Those to whom This Information is Transferred
Only a limited number of Company employees have access to the digitally stored and retained recordings. Live camera footage may be viewed by external security personnel. The limited number of individuals with access to the recordings are bound by a confidentiality agreement to protect the data confidentiality.
Our Company processes personal data for the purposes set out herein and for the further purposes of security, by tracking guest entry and exit at Company buildings and facilities.
When individuals visiting Company buildings as guests are given a privacy notice when their personal data are collected, or this is done by way of texts posted at the Company or made available to guests in other ways accordingly. Data collected for the purpose of tracking guest entry and exit is processed solely for this purpose, and the relevant personal data is recorded in a data recording system in physical and/or electronic form.
For the security purposes as well as for the purposes set out in this Policy, our Company may provide internet access to visitors who request it while they are inside our buildings and facilities. In this case, log records relating to your internet access are recorded in accordance with the mandatory provisions of Law No. 5651 and the regulations thereunder. These records are only processed at the request of authorized public agencies and bodies or for the purpose of fulfilling our relevant legal obligations during audit processes that take place within the Company.
Accordingly, only a limited number of Company employees shall have access to the compiled log records. Company employees with access to those records shall have access them solely for use in response to requests from authorized public agencies and institutions and organizations or during audit processes and share them only with legally authorized persons. The limited number of persons with access to the records are under an obligation to protect the confidentiality of the data they access subject to a confidentiality agreement.
Our Company uses technical means (e.g. cookies) to log internet activity on its websites in order to ensure that visitors to these sites can carry out their visits in a manner appropriate to their purposes, to display personalized content to them, and to engage in online advertising activities.
Detailed explanations regarding the protection and processing of personal data in relation to these activities carried out by our Company are included in the "Company Website Privacy Policy" texts on the relevant websites.
As stipulated in Article 138 of the Turkish Penal Code and Article 7 of the PDP Law, even if processed in accordance with the relevant provisions thereof, personal data shall be erased, destroyed or anonymized at the Company's discretion or at the request of the personal data subject when reasons for processing are no longer applicable.
In cases where our Company has the right and/ or obligation to retain personal data in accordance with the provisions of Article 5(2) of the PDPL, the right not to comply with the data subject's request is reserved.
7.2.1. Techniques for Deleting and Destroying Personal Data
In accordance with Article 7 of the PDPL, our Company shall erase, destroy or anonymize personal data at its own discretion or upon the request of the personal data subject when the reasons for processing such data are no longer applicable, even if the data are processed in accordance with the relevant provisions of the law. The Company's Personal Data Storage and Destruction Policy shall be followed as for the erasure, destruction and anonymization of personal data.
The most commonly used methods for erasure or destruction by our Company are listed below:
Physical Destruction
Personal data may also be processed by non-automated means, provided that it is part of a data recording system. When such data are erased/ destroyed, we use a system that physically destroys the personal data in such a manner that they cannot be retrieved later.
Secure Erasure from Software
Data that are processed by fully or partially automated means and stored in digital environments areas securely stored in databases to which only authorized persons have access. In ERP applications, personal data are not deleted but only restricted to access through authorization regulations.
7.2.2. Techniques for Anonymizing Personal Data
Anonymization of personal data means rendering personal data incapable of being associated with any identified or identifiable natural person, even when matched with other data. Our Company may anonymize personal data when the reasons for processing such data in accordance with the law no longer exist.
In accordance with Article 28 of the Personal Data Protection Law, anonymized personal data may be processed for purposes such as research, planning and statistics. Such processing is outside the scope of the Personal Data Protection Law and does not require the explicit consent of the data subject. As personal data processed by anonymization will fall outside the scope of the PDP Law, the rights set out in Section 10 of the Policy will not apply to such data.
Those anonymization techniques that are most commonly used by our Company are as follows:
Masking
Data masking is a method of anonymizing personal data by removing the key identifying information from the data set.
Örnek: Converting a dataset into one where it is impossible to identify the data subject by removing information such as name, Turkish ID number, etc., which enables the identification of the data subject.
Anonymization
Through data aggregation, multiple data points are combined, rendering personal data unlinkable to any individual.
Örnek: Demonstrating that customers exist between the ages of X and Z without showing their individual ages.
Data Derivation
Data derivation is a method used to create more general content from the content of personal data, ensuring that the personal data cannot be linked to any individual.
Örnek: Indicating ages instead of birth dates; indicating the region of residence instead of the full address.
Data Scrambling
The data masking method involves scrambling the values within a personal data set to sever the link between the values and the individuals.
Örnek: Altering the quality of voice recordings to prevent them from being linked to the data subject.
Our Company informs the data subject of his/ her rights in accordance with Article 10 of the PDP Law, guides the data subject on how to exercise these rights, and implements the necessary channels, internal procedures, administrative and technical arrangements in accordance with Article 13 of the PDP Law to evaluate the rights of data subjects and provide them with the necessary information.
8.1.1. Rights of the Data Subject
Data subjects shall have the following rights:
8.1.2. Cases in Which the Data Subject Cannot Exercise Their Rights
Pursuant to Article 28 of the PDP Law, personal data subjects may not assert their rights listed in 10.1.1 in the following cases, as they are excluded from the scope of the PDP Law:
8.1.3. Exercising the Rights of the Data Subject
Data subjects may submit requests regarding their rights listed under Article 10.1.1 of this section to our Company via the PDPL Application Form available on our website by using the method specified below:
Third parties may not submit requests on behalf of personal data subjects.
For a person other than the personal data subject to make a request, the original of a special power of attorney issued by the personal data subject for the person making the request must be presented.
A data subject shall fill out the "Application Form for Applications by the data subject to the Data Controller in accordance with the PDP Law No. 6698", provided in the link above when applying to exercise their rights. The method of application to be made is also described on that form in detail.
No fee shall be charged for responses up to ten pages. A processing fee of 1 Turkish Lira will be charged for each page exceeding ten pages. If the response to the application is provided on a recording medium such as a CD or flash drive, the fee requested by our Company shall not exceed the cost of the recording medium. Applications will not be taken into consideration and processed unless this fee is paid.
8.1.4. Data Subject's Right to Lodge a Complaint with the PDP Committee
In accordance with Article 14 of the PDP Law, a data subject may lodge a complaint with the PDP Committee within thirty days from the receipt of the Company's response, or within sixty days of the application date, if the application is rejected, the response is deemed insufficient, or no response is provided within the specified timeframe.
8.2.1. Company's Procedure and Timeframe to Respond to Requests
If the personal data subject submits his/ her request to our Company in accordance with the procedure set out in Article 8.1.3 of this Section, our Company will process the relevant request as soon as possible and within thirty days at the latest, depending on the nature of the request.
8.2.2. Information that may be asked by the Company from the applicant Data Subject
Our Company may request information from the data subject in order to determine whether the applicant is the data subject himself/ herself. Our Company may ask to the data subject questions regarding their request in order to clarify the issues raised in the application.
8.2.3. Our Company's Right to Reject the Data Subject's Application
Our Company may reject the applicant's request in the following circumstances on the condition that it shall provide a reason for the rejection:
The fundamental policies, procedures, and instructions that have been or will be drafted for the protection and processing of personal data, which are related to the principles set forth by the Company in this Policy, are linked to and associated with this Policy. Those policies, procedures, and instructions are also linked to the Company's fundamental processes in other areas to ensure consistency between processes operated by the Company under different policy principles for similar purposes.
| Abbreviation | Description |
|---|---|
| Law no. 6698/ Law : | means the Personal Data Protection Law no. 6698 dated 24 March 2016 as published in the Official Gazette issued on 7 April 2016 under no.29677 |
| EU : | means the European Union. |
| Constitution : | means the Turkish Republic Constitution no. 2709 enacted on 7 November 1982 as published in the Official Gazette issued on 9 November 1982 under no.17863 |
| PDP Committee : | means the Personal Data Protection Committee. |
| PDP Authority : | means the Personal Data Protection Authority. |
| Policy : | means the Personal Data Protection and Processing Policy. |
| Turkish Code of Obligations : | means Turkish Code of Obligations no. 6098 enacted on 11 January 2011 as published in the Official Gazette issued on 4 February 2011 under the issue no. 27836. |
| Turkish Criminal Code : | means Turkish Criminal Code no. 5237 enacted on 26 September 2004 as published in the Official Gazette issued on 12 October 2004 under the issue no. 25611. |
| Turkish Commercial Code : | means Turkish Commercial Code no. 6102 enacted on 13 January 2011 as published in the Official Gazette issued on 14 February 2011 under the issue no. 27846. |
| Date | Description |
|---|---|
| 7 April 2016 | As of 7 April 2016, our Company acts in accordance with the following obligations: General rules and principles applicable to the processing of personal data. Obligations regarding the submission of privacy notice to data subjects. Obligations to ensure the data security. |
| 7 October 2016 | As of 7 October 2016, the regulations listed below will come into force and our Company shall act in accordance with these regulations: Provisions regarding the transfer of personal data to third parties and abroad. Provisions regarding the data subject's right to exercise their rights against our Company (to learn whether their personal data is being processed, to request information, to learn to whom it has been transferred, to request correction) and Regulations concerning the right to lodge a complaint with the Personal Data Protection Board. |
| 7 April 2017 | Consents obtained in accordance with the law prior to 7 April 2016 shall be deemed to be in conformity with the Personal Data Protection Law as of 7 April 2017, unless the data subject makes a contrary statement. As of 7 April 2017, the Regulations relating to the Personal Data Protection Law will enter into force and Our Company will act in accordance with these regulations. |
| 7 April 2018 | Personal data processed prior to 7 April 2016 shall be made compatible and compliant with the PDP Law by our Company by 7 April 2018. |
| 1 June 2024 | New legislative amendments regarding the processing of special category data and data transfers abroad have been published in the Official Gazette and entered into force. |
| Data Subjects | Collection and Processing of Personal Data | Exercise of Rights and Application |
|---|---|---|
| Job Applicants | Personal data collected from job applicants during the recruitment process, as well as special categories of personal data collected depending on the nature of the job, are processed by our Company for the purposes set out in Sections 4.2 and 7 hereof and listed below: To assess the candidate's qualifications, experience, and suitability for the open position. Where necessary, to verify the accuracy of the information provided by the candidate or to contact third parties to conduct research on the candidate. To communicate with the candidate about the application and recruitment process or, where appropriate, to contact the candidate for any position opened domestically or abroad at a later date. To comply with the requirements of relevant legislation or the requests of the competent authority or organization. To develop and improve our Company's recruitment principles. | Because job applicants are also data subjects, they may submit their requests about their rights to us by using the method described in Section 10 hereof. |
| Job Applicants (Data Collection Methods) | The personal data of job applicants may be collected through the following methods and means: Digital application form published in written or electronic format; Curriculum vitae submitted to our Company by candidates via email, courier, references, and similar methods. Career or consultancy companies; during the interview in cases where interviews are held via video conference, telephone or personally (one to one). Checks and screening carried out to verify the accuracy of the information provided by the candidate as well as inquiries made by our Company. Recruitment tests conducted by experienced specialists to identify skills and personality traits, with the results being reviewed. | Because job applicants are also data subjects, they may submit their requests about their rights to us by using the method described in Section 10 hereof. |
| Business Partner Employees | Our Company may process personal data of a business partner employee in the course of the performance of the business operations with that business partner for the purposes defined in Section 4.2 and Section 7 hereof. | Because job applicants are also data subjects, they may submit their requests about their rights to us by using the method described in Section 10 hereof. |
Our Company processes personal data in line with those legitimate and lawful purposes underlying the processing of such data and limited to one or several personal data processing conditions as described in Article 5 of the PDP Law in compliance with those general principles set out in the PDP Law, including in particular, to those ones set out in Article 4 of the personal data processing and in compliance with all obligations defined in the PDP Law and for such durations limited to those ones set out under our Policies, provided that data subjects shall be informed pursuant to Article 10 of the PDP Law.
| Personal Data Categorisation | Descriptions for Personal Data Categorisation |
|---|---|
| Contact Data | This is a group of data that can be used to contact an individual (telephone number, address, email address, fax number, IP address). |
| Identity Data | This is a group of data containing information about a person's identity (first name, surname, Turkish Republic ID number, mother's name, father's name, place of birth, date of birth, gender, ID card serial number, ID card photocopy, tax number, social security number, nationality data, marriage certificate photocopy/scan, employee card). |
| Customer Data | Data that belongs to customers that use our products and services, which is clearly associated with an identified or identifiable natural person and is stored in the data recording system (e.g. customer number, customer's occupation or job, etc.). |
| Customer Transaction Data | Data of a customer who uses our products and services and which is clearly attributable to an identified or identifiable natural person and is stored in the data recording system (e.g. requests and instructions, order and basket information, etc.) |
| Physical Premises Security Data | Personal data relating to records and documents obtained upon entry to a physical location and during stay within the physical location, which are clearly attributable to an identified or identifiable natural person and are stored within the data recording system (e.g. entry/ exit logs, details about the visit, camera recordings, etc.) |
| Transaction Security Data | Personal data belonging to an identified or identifiable natural person, stored within the data recording system, and processed for the purpose of ensuring the technical, administrative, legal, and commercial security of our Company and related parties (e.g. information associating the transaction to the data subject and matching that person to the transaction, and showing that the person is authorized to perform that transaction. Information such as website passwords and login credentials) |
| Risk Management Data | Personal data belonging to an identified or identifiable natural person and stored in the data recording system, processed for the purpose of managing our Company's commercial, technical and administrative risks (e.g. IP address, Mac ID, etc. records) |
| Financial Data | Personal data within the scope of information, documents and records showing any financial outcome created according to the type of existing legal relationship with the personal data subject, which clearly belongs to an identified or identifiable natural person and is stored in the data recording system (information showing the financial outcome of transactions made by the data subject, credit card debt, loan amount, loan payments, interest amount and rate payable, debt balance, credit balance, etc.) |
| Biometric/Genetic Data | This is a data group containing biometric/genetic data that belongs to an individual (fingerprint, genetic information, vein mark/ pattern). |
| Job Applicant Data | Personal data belonging to data subjects who have disclosed their data in order to apply for a job in our Company, which is clearly attributable to an identified or identifiable natural person and is stored in the data recording system, and which is used in the application evaluation process (e.g. CV, interview notes, personality test results, etc.). |
| Marketing Data | Data belonging to an identified or identifiable natural person, stored in the data recording system, and used by our Company for marketing activities (e.g. reports and assessments showing the person's habits and preferences collected for marketing purposes, targeting data, cookie records, data enrichment activities) |
| Legal Transaction and Compliance Data | Personal data belonging to an identified or identifiable natural person, stored in the data recording system, processed for the purpose of determining and tracking legal claims and rights and fulfilling debts and legal obligations (e.g. data contained in documents such as court and administrative authority decisions) |
| Sensitive Personal Data | Personal data belonging to an identified or identifiable natural person, stored in a data recording system, and relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other faith, clothing and attire, membership to associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. |
| Data for Request Complaint Management | Personal data relating to any request or complaint sent to our Company, which is clearly attributable to an identified or identifiable natural person and is contained within the data recording system. (e.g. requests and complaints directed towards our Company, related records and reports) |
| Audio-visual Data | Audio-visual recordings associated with the data subject, which are clearly attributable to an identified or identifiable natural person and are stored within the data recording system (e.g. photographs, camera recordings and audio recordings) |
MERSİS No: 0683003379100011
Trade Name: ÖZDİSAN ELEKTRONİK PAZARLAMA SANAYİ TİCARET ANONİM ŞİRKETİ
Address: Dudullu OSB, DES Sanayi Sitesi 104. Sok. A07 Blok No: 54-56, Ümraniye/İstanbul/Türkiye 34776
Phone: +90 216 420 18 82 (pbx)
KEP Address: [email protected]