Personal Data Protection and Clarification Texts

plus

Privacy Policy and Agreements

plus

Policies

plus
Özdisan Elektronic KVKK Policy
Last Updated
February 2, 2026

1. INTRODUCTION TO THE POLICY

The Personal Data Protection Law no. 6698 is among top priorities of our Company. The most important pillar of this subject matter is the protection and processing of personal data of our customers, prospective customers, employee candidates, company shareholders, company officers, our visitors and the employees, shareholders and officers of the entities we cooperate with as well as third parties as managed pursuant to this Policy. Actions taken by our company for the protection of personal data of our employees are administered in line with the "Personal Data Protection and Processing Policy" for the employees of ÖZDİSAN ELEKTRONİK PAZARLAMA SAN. TİC. A.Ş. (the "COMPANY").

According to Turkish Republic Constitution, everyone has the right to demand that his personal data should be protected. With respect to the protection of personal data, which is a constitutional right, the Company pays due care and diligence to protect the personal data of our customers, prospective customers, employee candidates, company shareholders, company officers, our visitors and the employees, shareholders and officers of the entities we cooperate with as well as third parties as governed hereunder, and turns it into a corporate policy. Accordingly, the Company adopts necessary administrative and technical measures to protect personal data that are processed pursuant to the applicable legislation.

This Policy shall provide detailed explanations as to the below-listed fundamental principles adopted by the Company for processing personal data:

  • processing personal data in compliance with the law and rules of integrity;
  • keeping personal data correct and, whenever necessary, up-to-date;
  • processing personal data for specific, clear and legitimate purposes;
  • processing personal data in connection with the underlying purpose, proportionately and in a limited way;
  • storing personal data for such term required by the applicable legislation or as much as necessary for the purpose underlying that process;
  • providing information and disclosures to the personal data subjects;
  • setting the necessary system so that personal data subjects may exercise their rights;
  • adopting measures necessary to store personal data;
  • acting in compliance with the applicable legislation and the PDP Committee regulations for transferring personal data to third parties in line with the requirements underlying the purpose of processing;
  • paying due care and diligence for processing and protecting sensitive personal data

PURPOSE OF POLICY

The basic purpose of this Policy is to make disclosures about the systems for processing personal data in line with the laws and adopted for the protection of personal data and, accordingly, to ensure transparency by informing those whose personal data are processed by us, including our customers, prospective customers, employee candidates, company shareholders, company officers, our visitors and the employees, shareholders and officers of the entities we cooperate with as well as third parties.

SCOPE

This Policy shall be applicable to all personal data of our customers, prospective customers, employee candidates, company shareholders, company officers, our visitors and the employees, shareholders and officers of the entities we cooperate with as well as third parties whose personal data are processed automatically, or provided to be a part of any data recording system, non-automatic means.

The scope of application of this Policy in connection with personal data groups categorized above may be the entire Policy (for instance our active customers, who are our visitors) or certain provisions of them may be applicable (e.g. for only our visitors).

IMPLEMENTATION OF THE POLICY AND APPLICABLE LEGISLATION

Applicable laws and regulations shall have priority with respect to the processing and protection of personal data. In the case of a conflict between the applicable legislation and the Policy, our Company acknowledges that applicable legislation shall be implemented.

The Policy has been drafted by materializing the rules set out in the applicable legislation in connection with the corporate practices.

We would like to remind you that unless you accept this Policy, you should not disclose your personal data to us. If you choose not to disclose your personal data to us, we would like to inform you that it may be impossible for us to offer certain services to you, or fulfill your requests or provide you with our services completely.

We would like to remind you that whether or not the personal data disclosed by you to us are correct, complete and update is within your responsibility to the extent you are aware. In addition, if you disclose personal data of other individuals, it is your responsibility to collect such data in line with the local statutory requirements. In this case, if we collect third party personal data from third parties, this means that we have obtained all consents necessary to process, use and disclose them, and our Company shall not be held liable for such operations.

EFFECTIVENESS OF THE POLICY

This Policy was issued and put into force by the Company on 15.06.2019. The latest revision was made on 02.02.2026.

PROTECTION OF PERSONAL DATA

Our Company adopts technical and administrative measures in order to prevent the unlawful processing of, and unlawful access to, personal data processed by it and ensure such level of security for the storage of data in line with Article 12 of the PDPL no.6698. Controls and audits in that respect are carried out by or on behalf of our Company.

2.1. SECURITY OF PERSONAL DATA

2.1.1. Technical and Administrative Measures adopted to ensure the lawful processing of personal data

Our Company adopts such technical and administrative measures to ensure the lawful processing of personal data to the extent technological means and implementation cost allows it.

Technical Measures adopted to ensure the lawful processing of personal data

  • In order to ensure that our Company will process personal data lawfully, personal data processing operations carried out
  • at our Company are audited by means of installed technical systems.

Administrative Measures adopted to ensure the lawful processing of personal data

Major administrative measures are listed below to ensure that our Company shall process personal data in line with the applicable law:

  • Employees are informed and trained about the law for the protection and lawful processing of personal data.
  • These technical measures are reported to whom it may concern periodically pursuant to the internal audit mechanism.
  • Such staff members in command of technical matters are employed.
  • All these operations undertaken by us are analyzed specifically by all business units in detail, and personal data are processed for those business operations carried out by the applicable business units as a result of this analysis.

Personal data processing operations undertaken by our business units are specifically determined for each business unit and the detailed operations undertaken by it in line with those requirements to ensure compliance with conditions for personal data processing as sought by the Law no. 6698.

An awareness is created, and implementation rules are defined, for each relevant business unit to ensure requirements for legal compliance set for that business unit. Those administrative measures necessary to audit these procedures and ensure the sustainability of the implementation are applied by in-house policies and training courses.

Reservations and provisions are incorporated into contracts and documents governing legal relation between our company and employees in order to restrict the processing, disclosure and use of the personal data, and the employee awareness is created and audits are carried out in this respect.

2.1.2. Technical and Administrative Measures adopted to prevent unlawful access to personal data

Our Company adopts technical and administrative measures in light of the nature of the data to be protected, technological means and cost of implementation to avoid the disclosure, transfer of, or otherwise access to personal data with recklessness or in an unauthorized manner unlawfully.

Technical Measures adopted to prevent unlawful access to personal data

Major technical measures listed below to ensure that our Company shall prevent unlawful access to personal data:

  • Technical measures in line with technological developments are taken and those measures are periodically updated and renewed.
  • Technical solutions for access and authorization are commissioned in line with legal compliance requirements set for each business unit.
  • Those technical measures are periodically reported to whom it may concern pursuant to the internal audit mechanism and any risky matter is re-considered and necessary technological solutions are reached.
  • Software and hardware with anti-virus systems and firewalls are installed.

Administrative Measures adopted to prevent unlawful access to personal data

Major administrative measures listed below to ensure that our Company shall prevent unlawful access to personal data:

  • Employees complete training courses about technical measures to prevent unlawful access to personal data.
  • Such staff members in command of technical matters are employed.
  • Procedures for access to personal data and authorization are designed and implemented in the Company in line with the business-unit based lawful compliance requirements.
  • Employees are informed, and required to make an undertaking, that they shall not disclose such personal data to third parties in breach of the PDPL and not use them for any purpose other than the purpose of processing and that their such obligation shall survive the termination of their employment contracts.
  • Those provisions are incorporated into such contracts made with individuals to whom our Company transfers personal data lawfully to ensure that those individuals shall take such necessary security measures to protect such data and to procure that their staff members shall comply with those measures.

2.1.3. Safe storage of personal data

Our company takes all necessary technical and administrative measures to store personal data safely and prevent the destruction, loss and modification of them for unlawful purposes to the extent technological means and implementation costs allow them.

Technical Measures adopted to ensure safe storage of personal data

Below are major technical measures that our Company has adopted to ensure the safe storage of personal data:

  • Systems that are in pace with technological developments are employed to ensure the safe storage of personal data.
  • Technical security systems for storage spaces are installed and those technical measures are periodically reported to whom it may concern pursuant to the internal audit mechanism and any risky matter is re-considered and necessary technological solutions are reached.
  • Appropriate back-up programs are in place to ensure the safe storage of personal data.

Administrative Measures adopted to ensure safe storage of personal data

Below are major administrative measures that our Company has adopted to ensure the safe storage of personal data:

  • Employees complete training courses for the safe storage of personal data.
  • Such staff members in command of technical matters are employed. Where a service is outsourced due to technical constraints regarding the safe security by us of personal data, those provisions are incorporated into such contracts made with relevant entities to whom our Company transfers personal data lawfully to ensure that those individuals shall take such necessary security measures to protect such data and to procure that their staff members shall comply with those measures.

2.1.4. Audit of measures adopted for the protection of personal data

Necessary periodic audits are carried out by or on behalf of our Company in its own organization by way of sampling method in line with Article 12 of the PDPL. The results of these audits as well as any non-conformity identified in the course of the Company's in-house procedures are reported and necessary actions are taken to improve those measures taken. The Company's Board of Directors is informed about the results of the said audit.

2.1.5. Measures to be adopted in the case of unauthorized disclosure of personal data

Our Company runs a system whereby third parties capture personal data processed in line with Article 12 of the PDPL unlawfully, this is reported to the personal data subject as well as the PDP Committee as soon as possible and within 72 hours at the latest from the time the Company becomes aware of it.

If it is deemed necessary by the PDP Committee, this may be posted at the PDP Committee's web site or published by any other means.

2.2. PROTECTION OF SENSITIVE PERSONAL DATA

PRP Law places a special emphasis on certain personal data as the unlawful processing of such data carries a risk that may cause individuals to be aggrieved or discriminated.

These data include race, ethnic origin, political though, philosophical beliefs, religion, sect or other faith, clothing and attire, membership to association, foundations or unions, healthcare data, sexual life, criminal conviction and security measures as well as biometric and genetic data.

Our Company acts diligently for the protection of sensitive personal data that are designated as "sensitive" by virtue of the PDP Law and are processed in line with the law. Accordingly, our Company diligently applies technical and administrative measures aimed to protect personal data to sensitive personal data, and required audits are carried out inside our organization.

Section 3 of this Policy details the information about the processing of sensitive personal data.

2.3. RAISING AWARENESS AND AUDITS ABOUT THE PROTECTION AND PROCESSING OF PERSONAL DATA OF DATA SUBJECTS

Our Company ensures that necessary briefing and training sessions are organized for business units to enhance awareness for preventing unlawful access to data, unlawful processing of personal data and to ensure the safe storage of the data.

Our employees are duly informed and assume basic obligations by virtue of the corporate Code of Conduct provisions necessary to raise awareness for the protection of personal data of those employees seconded to the business unit new as well as the existing employees of such business unit. and the Code of Conduct is annually reviewed and tested electronically to ensure the sustainability.

The participation in training sessions is reported to the relevant managers. In light of the foregoing, our Company assesses the participation and involvement in relevant training courses, seminars and information sessions, and necessary audits in this respect are carried out by or on behalf of the Company. Our Company updates and renews its training sessions in line with the updated legislation.

Our Company regularly provides its business partners with information to enhance awareness for preventing unlawful processing of, and unlawful access to, personal data and to ensure the storage of the data.

3. WHEN DO WE COLLECT YOUR PERSONAL DATA? / PROVISIONS ABOUT THE PROCESSING OF PERSONAL DATA

We basically collect your personal data when:

  • you purchase or use our products and/ or services;
  • sell goods or supply services to us;
  • you subscribe to our news bulletin and choose to receive our marketing messages;
  • you contact us through our web site, e-mail, social media platforms, other on-line channels or by phone;
  • you apply to our Company for job;
  • you attend events and activities organized by our Company;
  • indirectly (for instance, when you use "cookies") and you personalize software that is used to adapt the web site in line with your personal preferences or we track the use by you of certain pages of the web site (for instance your IP address) or by using other technical methods that make it possible for us to track your use of the web site;
  • you contact us as a prospective customer/ supplier/ business partner/ subcontractor for any purpose whatsoever.

We process your personal data that we collect as mentioned above only in compliance with this Policy.

Our Company processes personal data in connection with, limited to, and proportional with, the purpose in line with Article 20 of the Constitution and Article 4 of the PDPL and accurately and whenever it is required and backed by up-to-date, specific, express and legitimate purposes and motives. Our Company stores personal data for such term as required by the laws or by the purpose of personal data processing.

As per Article 20 of the Constitution and Article 5 of the PDPL, our Company processes personal data in line with one or more than one terms and conditions set out in Article 5 of the PDPL as applicable to the processing of personal data. Notwithstanding the foregoing and pursuant to Article 10 of the PDPL, we provide personal data subjects with a privacy notice and give them necessary information upon their request.

Our Company acts in line with the applicable legislation for the processing of sensitive personal data pursuant to Article 6 of the PDPL. Moreover, with respect to the transfer of personal data in line with Articles 8 and 9 of the PDPL, our Company acts in line with those regulations dictated by the PDP Committee and as set out in the applicable law.

3.1. PRINCIPLES APPLICABLE TO THE PROCESSING OF PERSONAL DATA

3.1.1. Lawful Processing in line with the Rule of Good Faith

Our Company acts in line with the principles introduced by the legal regulations as well as the rule of general trust and integrity in the case of processing of personal data. Accordingly, our Company gives due consideration to the requirement of proportionality for the purposes of processing personal data, and does not use such data beyond the intended purpose.

3.1.2. Keeping personal data correct and, whenever necessary, up-to-date

Our Company makes sure that personal data processed by it by taking into account fundamental rights of the personal data subjects and its own legitimate interests are correct and up-to-date. It takes necessary measures in this respect. For instance, a system has been established by the Company to allow personal data subjects to correct, and confirm the accuracy of, their personal data.

3.1.3. Processing for Specific, Explicit and Legitimate Purposes

Our Company explicitly and unambiguously defines the purpose of personal processing by it lawfully and legally. Our Company processes personal data in connection with, and required for, the products and services offered by it. Our Company describes the purpose underlying the process of personal data even before it starts personal data processing.

3.1.4. Processing in connection with, limited to, and commensurate with, the purpose

Our Company processes personal data in a manner that would reach the described purpose, and avoids processing of such personal data that are not related to, or needed for, the achievement of the purpose. For example, the Company does not carry out any personal data processing to meet potential needs that may arise subsequently.

3.1.5. Storage of personal data for such term required by the applicable legislation or as much as necessary for the purpose underlying that process

Our Company stores personal data for such term required by the applicable legislation or as much as necessary for the purpose underlying that process. Accordingly, our Company first determines a time period for the storage of the personal data as set out in the applicable legislation; and if a term is determined, it acts in compliance with this time period and unless a term is determined, it stores the personal data that is necessary for the purpose of processing. In the event the reasons for processing are no longer applicable or the term expires, personal data are erased, destroyed or anonymized by our Company. Our Company does not store personal data with the probability that they may be used in future.

3.2. PRIVACY NOTICE FOR AND INFORMATION OF THE PERSONAL DATA SUBJECTS

Our Company gives a privacy notice to the personal data subjects in the course of the collection of the personal data in line with Article 10 of the PDPL. Accordingly, the Company gives a privacy notice about the identity of the Company, and if any, its representative, the purpose underlying the processing of personal data, and the purposes of transferring processed personal data to whom, and the legal grounds and management of collecting personal data as well as the rights held by the personal data owner.

Pursuant to Article 11 of the PDPL, our Company provides personal data subjects with such necessary information upon their request and through all channels via which their data are collected.

3.3. PROCESSING OF SENSITIVE PERSONAL DATA

Our Company diligently acts with the provisions set out in the PDPL in the case of processing personal data that are designated as "sensitive data" under the PDP Law.

Article 6 of the PDPL defines certain personal data as "sensitive data" if such data causes grief or discrimination of individuals when they are unlawfully processed. These data include race, ethnic origin, political though, philosophical beliefs, religion, sect or other faith, clothing and attire, membership to association, foundations or unions, healthcare data, sexual life, criminal conviction and security measures as well as biometric and genetic data.

Sensitive personal data are processed by our Company in the following circumstances in line with the PDPL subject to the requirement that sufficient measures to be designated by the PDP Committee are adopted.

By virtue of the new amendments adopted on 12 March 2024, provisions for the processing of Sensitive Data are amended as follows as of June 2024:

Pursuant to the Law, conditions to process sensitive personal data were re-worded in Article 6 of the PDPL:

  • The data subject should give his explicit consent.
  • Processing of all sensitive personal data, including healthcare and sexual life data are governed in the laws.
  • Where it is mandatory to process personal data to protect the vital interests or physical integrity of the data subject or another person where the data subject who is unable to explain his/her consent due to the physical disability or whose consent is not deemed legally valid,
  • Where data processing is in line with the will for publicization of the sensitive personal data made public by the data subject,
  • Where it is mandatory to process sensitive personal data in order to establish, use or protect a right;
  • Where processing of sensitive personal data is necessary for competent bodies and institutions or those individuals who are subject to the confidentiality obligation to protect public health, to fulfil preventive medicine, medical diagnosis, treatment and care services and to plan, manage and finance healthcare services;
  • where it is mandatory to process data in order to fulfill legal obligations in the field of employment, occupational health and safety, social security, social services and social aids;
  • where it is for existing or former members of foundations, associations or other non-profit organizations founded for political, philosophical, religious or union-related purposes or those persons who are in contact with them regularly, provided that this processing will be limited to the scope of business and shall not be disclosed to third parties.

3.4. TRANSFER OF PERSONAL DATA

Subject to the explicit consent of the data subject, our Company may transfer personal data and sensitive personal data of such data subject to third parties (third party companies, group companies, the Company and/ or business partners, their subsidiaries and shareholders, third party individuals, suppliers, legally authorized private and public enterprises, the Company's service providers, outsourcers or business partners) by taking security measures (see Chapter 2/ Article 1) in line with the lawful purposes of personal data processing and subject to the explicit consent of the data subject. We act in line with regulations set out in Article 8 of the PDPL in this respect.

Our Company may transfer personal data to third parties to the limited extent and based on one or several conditions for processing personal data as described in Article 5 of the Law in line with the legitimate and lawful purposes for processing personal data. Section 5.1 of this Policy details the information about these circumstances.

Our Company may transfer sensitive personal data of the data subject to third parties in circumstances described in Article 3.3 of this Policy in line with the legitimate and lawful purposes of processing personal data by paying due care and diligence, taking those necessary security measures (see Section 2/ Article 2.1) and other sufficient measures required by the PDP Committee.

Our Company acts in line with the decisions adopted by the PDP Committee as required under the PDPL and the applicable legislation, including, in particular, Article 8 of the PDPL for the transfer of personal data. Personal and sensitive data of data subjects may not be transferred by our Company to other individuals or legal persons without the explicit consent of the data subject.

Moreover, it is possible to transfer personal data without the consent of the data subject in circumstances described in Articles 5 and 6 of the PDPL. Our Company may transfer personal data to subsidiaries who are members of DMY Group and third parties based in Türkiye unless otherwise is agreed in the Law or other applicable legislation (or if there is a contract in force made with the data subject, in that contract), provided that conditions and terms set out in the PDPL and other applicable legislation are observed and security measures described in the applicable legislation are taken.

Parties to the transfers made in Türkiye and abroad

We may share your personal data in line with the following purposes to the extent it is necessary. We try our best not to share your personal data other than these circumstances. Parties to whom we share personal data are as follows:

DMY Group Companies: Your personal data may be shared with, or be made available to, DMY group companies, whose subsidiary we are. This share shall be made only with the authorized employees of the relevant DMY group subsidiaries. In certain exclusive circumstances, we may share personal data with DMY group companies in lieu of anonymized data (such as sharing details of claims to open an insurance claims file).

Service providers and business partners: These are defined as those parties with whom we build a business partnership in the course of our business operations for the sales, promotion, marketing, aftermarket services for our services. Like many other enterprises, we may cooperate with reliable third parties such as information and communication technology providers, consultants, cargo companies, travel agents in order to carry out functions and services in the most efficient manner and in line with up-to-date technologies under certain data processing operations. This disclosure shall be made to a limited extent in order to build a business partnership or ensure that purpose of performance is achieved. We use cloud computing technologies in order to take maximum advantage of technological means to carry out our operations in the most efficient manners, and accordingly, we are able to process your personal data in Türkiye and abroad by means of companies offering cloud computing services. Marketing services outsourcer to which we disclose information may be based abroad, and accordingly, data may be transferred to abroad in line with those provisions of Articles 8 and 9 of the PDPL which deals with the data transfer to abroad.

Public authorities: Where necessitated by the laws or if it is necessary to defend our rights, we can disclose your personal data to relevant public, judicial and administrative authorities (for instance, tax offices, law enforcement officers, courts and enforcement offices).

Private law entities: We may disclose personal data to the extent limited by the purpose if private law entities authorized to collect data and documents from our office request in line with their jurisdiction according to the applicable law (for instance, Occupational Health and Safety Company, OHSC).

Professional advisors: We can share your personal data with banks, insurers, auditors, lawyers, certified public accountants and other consultants and professional advisors.

Other persons connected with corporate actions: We can disclose your personal data from time to time for the handling of corporate actions such as the sale of a business owned by our company, reorganization, merger, joint venture or other disposal of our business, assets or shares (including those ones connected with any bankruptcy or a similar procedure).

Our Company may transfer personal data and sensitive data of a data subject to its business partners/ suppliers (legal persons) based abroad if necessary (by taking those measures asked by the PDP Committee) as well as such security measures necessary in line with the lawful purposes of personal data processing (see Section 2/ Article 2.1). Personal data are transferred by our Company to those data controllers in a foreign jurisdiction said by the PDP Committee to afford a sufficient protection ("Foreign Jurisdictions with Sufficient Protection") or, where there is no sufficient protection, to such data controllers based in Türkiye and the applicable foreign jurisdiction which hold a permission from the PDP Committee and which submit a written letter of undertaking to afford a sufficient level of protection or to foreign jurisdictions with a sufficient permission from the PDP Committee ("Foreign Jurisdiction where Data Controller undertaking Sufficient Protection is based"). We act in line with regulations set out in Article 9 of the PDPL in this respect.

Our Company informs to the data subject such person groups to whom personal data are transferred in line with Article 10 of the PDPL.

Our Company may transfer personal data of its customers to the following individual categories in line with Articles 8 and 9 of the PDPL (see Section 3/ Article 3.5):

  • Our business partners,
  • our suppliers,
  • our subsidiaries,
  • our shareholders,
  • legally authorized public agencies and bodies,
  • legally authorized private law entities

The scope of those persons to whom data are transferred and the purposes of data transfer are as follows:

Persons to whom data may be transferredDefinitionPurposes of Data Transfer
Business PartnerThese are defined as those parties with whom we build a business partnership in the course of our business operations for the sales, promotion, marketing, aftermarket services or handling co-customer loyalty programs for our services.limited to the purpose of achieving the purpose underlying the business partnership
SupplierThis term refers to those parties who provide services to our Company based on a contract in line with our Company's orders and instructions in the course of its business operations.to the limited extent in order to ensure that our Company shall receive such services necessary to achieve our Company's business operations, provided that these services are to be outsourced to the supplier.
Our Subsidiariesrefer to those companies in which our Company is a shareholder.to the extent limited to ensure the pursue of business operations involving the participation of subsidiaries of our Company that may be founded in future
Our ShareholdersOur main shareholders authorized to design strategies and audit operations in connection with our Company's business operations according to the applicable law.to an extent limited to the purposes of designing and auditing strategies for our Company's business operations according to the applicable law
Legally authorized public agencies and institutionsThose public agencies and institutions authorized to collect data and information from our Company in line with the applicable legislation.to the extent limited to the purpose asked by the relevant public agency and institution under its jurisdiction
Private Law EntitiesThose private law entities authorized to collect data and information from our Company in line with the applicable legislation.to the extent limited to the purpose asked by the relevant private law entity under its jurisdiction

3.5. STORAGE TIME FOR PERSONAL DATA

Our Company stores the personal data for such duration set out in the applicable laws and legislation if it is required thereunder.

Unless there is a time period set out in the applicable legislation for the duration of the storage of the personal data, such personal data are processed for such duration that is necessary under our corporate practices and customs of the commercial life in connection with the services offered by our company while processing such data. After its expiry, such data are erased, destroyed or anonymized. A Storage Times Table has been issued in this respect.

Where the purpose for processing personal data is no longer applicable and the storage times defined in the applicable legislation and the company have expired, personal data may be only stored for asserting a right or making a defense or serving as an evidence in a potential legal dispute only. For the purposes of setting the time periods here, storage times are determined on the basis of time bars for asserting the right in question and based on those examples set out in claims asserted against our Company in the same matter even after the expiry of a time bar. In this case, there shall be no access to stored personal data for any other purpose and access to personal data is only available whenever it is to be used in a relevant legal dispute. After the term referred to herein expires, personal data are erased, destroyed or anonymized.

4. PERSONAL DATA CATEGORIES

While personal data of personal data subject categories listed below are processed by our company, the implementation scope of this policy is limited to our customers, prospective customers, employee candidates, company shareholders, company officers, our visitors and the employees, shareholders and officers of the entities we cooperate with as well as third parties.

Protection and processing of personal data of our employees shall be addressed under the Policy for the Protection and Processing of Personal data of Company Employees.

While categories of those persons whose personal data are processed by our Company fall within the scope mentioned above, persons that do fall outside these categories may send their requests to us pursuant to the PDPL, and such requests shall be processed in line with this Policy.

Following paragraphs clarify concepts of our customers, prospective customers, employee candidates, company shareholders, company officers, our visitors and the employees, shareholders and officers of the entities we cooperate with as well as third parties as referred to hereunder.

Personal Data Subject CategoryDescription
Customerany natural person who uses or has used such products and services offered by our Company irrespective of whether or not there is a contractual relation with our company
Potential customermeans any natural person who requests or is interested in using our products or services or who is considered to be interested in them in line with commercial practices and rules of good faith.
Visitora natural person who has entered in physical sites owned by our country or where an organization is carried out for various purposes or who has visited our web site
Third partiesany third party individuals who are associated with the foregoing parties in order to ensure the security of the business operation between our Company and said parties or to defend the rights of those parties or to secure an interest (for instance, suretyships, companions, attendants, family members or next of kin) or other natural persons that do not fall within the scope of this Policy and the Policy for Protection and Processing of Personal Data of Company Employees
Employee Candidatemeans any natural person who has applied to our Company for a job through any channel or whose curriculum vitae and related information are submitted for our Company's review
Company shareholderany natural person who is a shareholder of our Company or a representative of a shareholder if it is a legal entity;
Authorized Company Officerany board member of our Company or any other natural person authorized by our Company
Employees, Shareholders and Authorized Officers of Agencies that we cooperateany natural person who is employed with a company with a business relation with our Company (including, but not limited to, a business partner, supplier etc.), including shareholders and authorized officers of that company

WHAT KIND OF YOUR PERSONAL DATA DO WE PROCESS?

Your personal data that we process vary depending on the type of business relation between you and us (for instance customers, suppliers, business partners etc.) and the method by which you choose to contact us (for instance phone, e-mail, over web site or printed documents. etc.).

Our basic methods to process personal data are via our web site, phone or e-mail, electronic applications exclusive to our customers, your visits to our business events, your participation in our promotions and surveys or any other interaction with us. Accordingly, your personal data that we process may be described under the following categories:

Personal Data CategoryPersonal Data
ID DataName, surname, position, date of birth and similar data that appear on ID papers
Contact DataE-mail, GSM or a landline number, contact address
Account Log-IN CredentialsLog-in credentials, password or other security codes, user details
Audio-visual data determining the IDPhotographs and audio images that are processed for security purposes when you visit our premises or you attend our events; audio-visual data that are processed as well as CCTV records when you visit our premises
Financial DataCredit card details, bank account data, accommodation and spending info, invoice details
Other data that you disclose to the company at your willAny personal data that you disclose upon your consent, any feedback, opinions, demands or complaints, evaluations, comments that you send to us through social media, on-line platforms or other channels or our relevant assessments, uploaded files, areas of interests as well as details supplied for our detailed review before entering a business relation with you
Digital electronic data collected by automated meansWe can also collect electronic data sent to us from your computer, mobile phone or other access devices in addition to such information that you directly submit to us when you visit or use our web site or applications or subscribe to our news bulletins or interact with us through other electronic channels. (for instance, device hardware model, IP address, operating system release and settings, time when you use our digital channel or product and the duration of such use, your true location (position) that may be collected when you activate location-based products or features, links that you click etc)
Legal Transaction DataYour personal data that are processed to assert our legal claims and rights, to follow them and to perform our obligations, our statutory obligations and your personal data processed in compliance with our policies, audit and inspection data
Customer/ Supplier DataAny data that is collected or generated about data subjects as a result of operations handled by our business units for our services, including data subject customer/ supplier or any employee or authorized signatory of it
Incident, Breach and Security DataAny information and evaluation collected in respect of any incident or breach with a potential effect on our employees, managers or shareholders, license plate and motor vehicle details, access and travel info, airport transfer and access organization
Personal Data collected from other sourcesDatabases that are open to public to the extent permitted by the applicable law and regulations, social media platforms, methods and platforms over which our business partners collect personal data in our name For instance, we can proceed with a due diligence about you in order to ensure technical, administrative and legal safety of our business operations and transactions against public sources before we start a business relation with you. In addition, certain personal data of third parties may be disclosed by you to us. We may process your personal data by means of methods employed in generally accepted legal, ethical values and rules of good faith in order for us to manage our technical and administrative risks In addition, we save your personal data that you disclose via phone, web site or similar platforms subject to your consent, and process such data to solve your problems and claims.

5. PROCESSING OF PERSONAL DATA BASED ON, AND LIMITED TO, THE CONDITIONS FOR PROCESSING AS SET OUT IN THE LAW

Our Company gives a privacy notice to the personal data subject about the personal data that we process in line with Article 10 of the PDPL.

The explicit consent by the data subject is only one of the legal grounds that make it possible to process personal data in line with the law. Other than explicit consent, personal data may be processed in case either of the following circumstances occurs. The grounds for processing your personal data may be only one of those conditions set below or there may be several reasons to serve as the basis for this data processing operations. Where processed data are sensitive personal data, those conditions listed in Article 7.1.2 hereunder below shall be applied.

Where legal grounds may differ for processing of personal data by our Company, we act in line with general principles set out in Article 4 of the Law no. 6698 (please see Section 3.1) in all kinds of data processing operations.

5.1. Explicit consent by the data subject

One of the conditions for processing personal data is the explicit consent of that data subject. Explicit consent of a personal data subject should be given at his free will and based on information and for a specific topic.

If either of the conditions listed in subparagraphs (ii), (iii), (iv) (v), (vi), (vii) and (viii) for the reasons for collecting personal data is no longer applicable, our Company process personal data based on the explicit consent of the data subject for this processing.

In order to process personal data upon the explicit consent of the personal data subject, an explicit consent should be obtained from the data subject by way of legal methods defined by the Company.

5.2. Where it is explicitly required under the applicable laws

Personal data of a data subject may be processed in line with the applicable law if it is expressly foreseen in the law.

5.3. Failure to Obtain Data Subject's Explicit Consent Due to Practical Impossibility

Where a person is unable to express their consent due to actual impossibility or where their consent cannot be recognized as valid, their personal data may be processed if such processing is necessary to protect their own life or physical integrity or that of another person.

Example: A customer who has fainted and whose blood type information is provided to doctors by their friends.

5.4. Direct Relevance to the Execution or Performance of a Contract

Personal data may be processed if it is necessary for the execution or performance of a contract, provided that it is directly related to the contract and the personal data of the parties to the contract is required.

Example: Obtaining the name and contact details of the purchaser of a product.

5.5. Fulfilling the Company's Legal Obligations

If processing is necessary for our Company to fulfil its legal obligations as the data controller, the data subject's personal data may be processed.

Example: Submission of information requested by a court order to the court.

5.6. Disclosure (Publicity) of Personal Data by the Data Subject

Where the data subject has made their personal data public, the relevant personal data may be processed.

5.7. Mandatory Data Processing for Asserting or Protecting a Right

Where data processing is necessary for the establishment, exercise or defense of a legal claim, the data subject's personal data may be processed.

Example: Storage and use of data with evidentiary value (sales contract, invoice) when necessary.

5.8. Where Data Processing is Necessary for the Legitimate Interests of Our Company

Where data processing is necessary for the legitimate interests of our Company, provided that this does not infringe upon the fundamental rights and freedoms of the data subject, the data subject's personal data may be processed.

Example: Processing of personal data for the purpose of internal Company calculations by the accounting department.

6. PERSONAL DATA PROCESSING AT THE ENTRANCE OF, AND INSIDE THE BUILDING AND FACILITY AND WEBSITE VISITORS

Personal data processing at the entrance of, and inside, the building and facility is carried out by our Company in accordance with the Constitution, the Personal Data Protection Law, and other relevant legislation.

For security purposes, our Company processes personal data by monitoring guest entries and exits using security cameras in our Company buildings and facilities.

Our Company processes personal data by using security cameras and recording guest entries and exits.

6.1. Camera Surveillance at the Entrances of, and Inside the Company Buildings and Facilities

Our Company carries out camera surveillance in order to improve the quality of the services provided by the Company, to ensure reliability, to ensure the safety of life and property of the Company, the data subject and other persons, and to protect the legitimate interests of the aforementioned parties.

6.1.1. Legal Ground for Camera Surveillance

The camera surveillance by our Company is conducted in accordance with the Private Security Services Law No. 5188 and related legislation.

6.1.2. Surveillance Activities by Security Cameras according to the PDP Law

In conducting surveillance activities with cameras for security purposes, our Company acts in accordance with the regulations set out in the PDP Law.

Our Company carries out security camera surveillance in its buildings and premises to ensure security, in accordance with the purposes stipulated in the laws and the personal data processing conditions listed in the PDP Law. The PDPL Privacy Notice for Camera Recordings for that surveillance monitoring is also issued.

6.1.3. Announcement of Camera Surveillance

Our Company informs the data subject in accordance with Article 10 of the PDP Law.

In addition to the information provided on general matters (see Section 3/Section 3.3), our Company also posts or provides notices about camera surveillance through multiple methods. This way, we aim to prevent any compromise to the fundamental rights and freedoms of the data subject, ensure transparency, and provide information to the data subject.

With regard to camera surveillance carried out by our Company: This Policy is posted at our Company's website (online Policy regulation) and a notice stating that surveillance is carried out is posted at the entrances to the areas under surveillance (on-site information).

6.1.4. Purpose of Camera Surveillance Activities and Limitation to Purpose

Our Company processes personal data in a manner that is relevant, limited and proportionate to the purpose for which it is processed, in accordance with Article 4 of the Personal Data Protection Law.

The purpose of video camera surveillance by our Company is limited to the purposes listed in this Policy. Accordingly, the surveillance areas, and the number of security cameras, and the surveillance time are all implemented in a manner that is sufficient to achieve the security objective and limited to that purpose. Areas where surveillance could result in interference with a person's privacy beyond security purposes (e.g., toilets) are not subject to surveillance.

6.1.5. Security of Collected Data

In accordance with Article 12 of the PDP Law, our Company takes the necessary technical and administrative measures to ensure the security of personal data collected as a result of camera surveillance activities. (See Section 2/ Section 2.1)

6.1.6. Storage Period of Personal Data collected Through Camera Surveillance

Detailed information regarding the storage period of personal data collected by our Company through camera surveillance by our Company is provided in Section 4.3 of this Policy which is titled Storage Periods of Personal Data.

6.1.7. Those parties with an Access to the Data collected from Surveillance Operations and Those to whom This Information is Transferred

Only a limited number of Company employees have access to the digitally stored and retained recordings. Live camera footage may be viewed by external security personnel. The limited number of individuals with access to the recordings are bound by a confidentiality agreement to protect the data confidentiality.

6.2. Tracking of Guest Entry and Exit at the Entrance of, and Inside, Building and Facilities

Our Company processes personal data for the purposes set out herein and for the further purposes of security, by tracking guest entry and exit at Company buildings and facilities.

When individuals visiting Company buildings as guests are given a privacy notice when their personal data are collected, or this is done by way of texts posted at the Company or made available to guests in other ways accordingly. Data collected for the purpose of tracking guest entry and exit is processed solely for this purpose, and the relevant personal data is recorded in a data recording system in physical and/or electronic form.

6.3. Recording of Internet Access Provided to Our Visitors in the Company Buildings and Facilities

For the security purposes as well as for the purposes set out in this Policy, our Company may provide internet access to visitors who request it while they are inside our buildings and facilities. In this case, log records relating to your internet access are recorded in accordance with the mandatory provisions of Law No. 5651 and the regulations thereunder. These records are only processed at the request of authorized public agencies and bodies or for the purpose of fulfilling our relevant legal obligations during audit processes that take place within the Company.

Accordingly, only a limited number of Company employees shall have access to the compiled log records. Company employees with access to those records shall have access them solely for use in response to requests from authorized public agencies and institutions and organizations or during audit processes and share them only with legally authorized persons. The limited number of persons with access to the records are under an obligation to protect the confidentiality of the data they access subject to a confidentiality agreement.

6.4. Website Visitors

Our Company uses technical means (e.g. cookies) to log internet activity on its websites in order to ensure that visitors to these sites can carry out their visits in a manner appropriate to their purposes, to display personalized content to them, and to engage in online advertising activities.

Detailed explanations regarding the protection and processing of personal data in relation to these activities carried out by our Company are included in the "Company Website Privacy Policy" texts on the relevant websites.

7. ERASURE, DESTRUCTION AND ANONYMIZATION OF PERSONAL DATA

7.1. The Company's Obligation to Erase, Destroy and Anonymize Personal Data

As stipulated in Article 138 of the Turkish Penal Code and Article 7 of the PDP Law, even if processed in accordance with the relevant provisions thereof, personal data shall be erased, destroyed or anonymized at the Company's discretion or at the request of the personal data subject when reasons for processing are no longer applicable.

In cases where our Company has the right and/ or obligation to retain personal data in accordance with the provisions of Article 5(2) of the PDPL, the right not to comply with the data subject's request is reserved.

7.2. Techniques for Deleting, Destroying and Anonymizing Personal Data

7.2.1. Techniques for Deleting and Destroying Personal Data

In accordance with Article 7 of the PDPL, our Company shall erase, destroy or anonymize personal data at its own discretion or upon the request of the personal data subject when the reasons for processing such data are no longer applicable, even if the data are processed in accordance with the relevant provisions of the law. The Company's Personal Data Storage and Destruction Policy shall be followed as for the erasure, destruction and anonymization of personal data.

The most commonly used methods for erasure or destruction by our Company are listed below:

Physical Destruction

Personal data may also be processed by non-automated means, provided that it is part of a data recording system. When such data are erased/ destroyed, we use a system that physically destroys the personal data in such a manner that they cannot be retrieved later.

Secure Erasure from Software

Data that are processed by fully or partially automated means and stored in digital environments areas securely stored in databases to which only authorized persons have access. In ERP applications, personal data are not deleted but only restricted to access through authorization regulations.

7.2.2. Techniques for Anonymizing Personal Data

Anonymization of personal data means rendering personal data incapable of being associated with any identified or identifiable natural person, even when matched with other data. Our Company may anonymize personal data when the reasons for processing such data in accordance with the law no longer exist.

In accordance with Article 28 of the Personal Data Protection Law, anonymized personal data may be processed for purposes such as research, planning and statistics. Such processing is outside the scope of the Personal Data Protection Law and does not require the explicit consent of the data subject. As personal data processed by anonymization will fall outside the scope of the PDP Law, the rights set out in Section 10 of the Policy will not apply to such data.

Those anonymization techniques that are most commonly used by our Company are as follows:

Masking

Data masking is a method of anonymizing personal data by removing the key identifying information from the data set.

Örnek: Converting a dataset into one where it is impossible to identify the data subject by removing information such as name, Turkish ID number, etc., which enables the identification of the data subject.

Anonymization

Through data aggregation, multiple data points are combined, rendering personal data unlinkable to any individual.

Örnek: Demonstrating that customers exist between the ages of X and Z without showing their individual ages.

Data Derivation

Data derivation is a method used to create more general content from the content of personal data, ensuring that the personal data cannot be linked to any individual.

Örnek: Indicating ages instead of birth dates; indicating the region of residence instead of the full address.

Data Scrambling

The data masking method involves scrambling the values within a personal data set to sever the link between the values and the individuals.

Örnek: Altering the quality of voice recordings to prevent them from being linked to the data subject.

8. RIGHTS OF DATA SUBJECTS

Our Company informs the data subject of his/ her rights in accordance with Article 10 of the PDP Law, guides the data subject on how to exercise these rights, and implements the necessary channels, internal procedures, administrative and technical arrangements in accordance with Article 13 of the PDP Law to evaluate the rights of data subjects and provide them with the necessary information.

8.1. Data Subject's Rights and How to Exercise Those Rights

8.1.1. Rights of the Data Subject

Data subjects shall have the following rights:

  • To inquire into whether or not their personal data has been processed,
  • To request information regarding the processing of personal data,
  • To inquire into the purpose of the processing of personal data and whether they are being used in accordance with that purpose,
  • To know the third parties to whom personal data has been transferred within or outside the country,
  • To request the correction of personal data if it has been processed incompletely or incorrectly, and to request that this action be communicated to third parties to whom the personal data has been transferred,
  • To request the erasure or destruction of personal data if the reasons for processing them are no longer applicable, even if they are processed in accordance with the provisions of the PDP Law and other applicable laws, and to request that the third parties to whom the personal data are transferred are to be notified of this action,
  • To raise objection to the analysis of processed data exclusively through automated systems resulting in a decision adverse to the individual,
  • To request compensation for any damage sustained as a result of the unlawful processing of personal data.

8.1.2. Cases in Which the Data Subject Cannot Exercise Their Rights

Pursuant to Article 28 of the PDP Law, personal data subjects may not assert their rights listed in 10.1.1 in the following cases, as they are excluded from the scope of the PDP Law:

  • Processing personal data for certain purposes such as research, planning and statistics by rendering it anonymous through official statistics.
  • Processing personal data for artistic, historical, literary or scientific purposes, or within the scope of freedom of expression, provided that the processing shall not violate national defense, national security, public security, public order, economic security, privacy of private life or personality rights, or shall not constitute a crime.
  • Processing personal data within the scope of preventive, protective and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public safety, public order or economic security.
  • Processing personal data by judicial authorities or enforcement authorities in relation to investigation, prosecution, trial or enforcement proceedings.
  • Pursuant to Article 28/2 of the PDP Law, personal data subjects may not assert their further rights listed in 10.1.1 in the following circumstances, except for the right to request compensation for damages:
  • Where the processing of personal data is necessary for the prevention of a crime or for a criminal investigation.
  • Processing personal data that has been made public by the data subjects themselves.
  • Where the processing of personal data is necessary for the performance of supervisory or regulatory tasks by public agencies and institutions licensed by law, or by professional organizations with public institution status, or for disciplinary investigations or prosecutions.
  • The processing of personal data is necessary for the protection of the State's economic and financial interests in relation to budget, tax and financial matters.

8.1.3. Exercising the Rights of the Data Subject

Data subjects may submit requests regarding their rights listed under Article 10.1.1 of this section to our Company via the PDPL Application Form available on our website by using the method specified below:

  • Filling out the form available at www.ozdisan.com, signing it with wet signature only to deliver it personally to the Company address specified on the PDPL application form,
  • Filling out the form available at www.ozdisan.com, signing it with wet signature only to deliver it to the Company address specified in the PDPL application form via a notary public,
  • The application form available at www.ozdisan.com must be completed and signed with your "secure electronic signature" under the Electronic Signature Law No. 5070 only to be sent via secure electronic mail to the email address [email protected],
  • Submitting an application to the email address [email protected] from the applicant's registered e-mail address.

Third parties may not submit requests on behalf of personal data subjects.

For a person other than the personal data subject to make a request, the original of a special power of attorney issued by the personal data subject for the person making the request must be presented.

A data subject shall fill out the "Application Form for Applications by the data subject to the Data Controller in accordance with the PDP Law No. 6698", provided in the link above when applying to exercise their rights. The method of application to be made is also described on that form in detail.

No fee shall be charged for responses up to ten pages. A processing fee of 1 Turkish Lira will be charged for each page exceeding ten pages. If the response to the application is provided on a recording medium such as a CD or flash drive, the fee requested by our Company shall not exceed the cost of the recording medium. Applications will not be taken into consideration and processed unless this fee is paid.

8.1.4. Data Subject's Right to Lodge a Complaint with the PDP Committee

In accordance with Article 14 of the PDP Law, a data subject may lodge a complaint with the PDP Committee within thirty days from the receipt of the Company's response, or within sixty days of the application date, if the application is rejected, the response is deemed insufficient, or no response is provided within the specified timeframe.

8.2. Company's Response to Applications

8.2.1. Company's Procedure and Timeframe to Respond to Requests

If the personal data subject submits his/ her request to our Company in accordance with the procedure set out in Article 8.1.3 of this Section, our Company will process the relevant request as soon as possible and within thirty days at the latest, depending on the nature of the request.

8.2.2. Information that may be asked by the Company from the applicant Data Subject

Our Company may request information from the data subject in order to determine whether the applicant is the data subject himself/ herself. Our Company may ask to the data subject questions regarding their request in order to clarify the issues raised in the application.

8.2.3. Our Company's Right to Reject the Data Subject's Application

Our Company may reject the applicant's request in the following circumstances on the condition that it shall provide a reason for the rejection:

  • Processing personal data for certain purposes such as research, planning and statistics by rendering it anonymous through official statistics.
  • Processing the data subject's personal data based on one or more of the processing purposes listed in the Law.
  • Processing personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that it does not violate national defense, national security, public security, public order, economic security, privacy of private life or personality rights, or shall not constitute a crime.
  • Processing personal data within the scope of preventive, protective and intelligence activities undertaken by public agencies and institutions authorized and empowered by law to ensure national defense, national security, public security, public order or economic security.
  • Processing personal data by judicial authorities or enforcement authorities in relation to investigation, prosecution, trial or enforcement proceedings.
  • If the processing of personal data is necessary to prevent or investigate a crime,
  • Processing personal data made public by the data subject himself/ herself;
  • Where the processing of personal data by public institutions and organizations with official authority and competence, or by professional organizations with the status of public institutions, based on the authority granted by law, where it is necessary for the performance of their supervisory or regulatory duties or for disciplinary investigations or proceedings.
  • Where the processing of personal data is necessary for the protection of the State's economic and financial interests in relation to budget, tax and financial matters.
  • Where the data subject's request is likely to impede the rights and freedoms of others.

9. RELATIONSHIP BETWEEN THE COMPANY'S PERSONAL DATA PROTECTION AND PROCESSING POLICY AND OTHER CORPORATE DOCUMENTS

The fundamental policies, procedures, and instructions that have been or will be drafted for the protection and processing of personal data, which are related to the principles set forth by the Company in this Policy, are linked to and associated with this Policy. Those policies, procedures, and instructions are also linked to the Company's fundamental processes in other areas to ensure consistency between processes operated by the Company under different policy principles for similar purposes.

10. ANNEXES

ANNEX-1 ABBREVIATIONS

AbbreviationDescription
Law no. 6698/ Law :means the Personal Data Protection Law no. 6698 dated 24 March 2016 as published in the Official Gazette issued on 7 April 2016 under no.29677
EU :means the European Union.
Constitution :means the Turkish Republic Constitution no. 2709 enacted on 7 November 1982 as published in the Official Gazette issued on 9 November 1982 under no.17863
PDP Committee :means the Personal Data Protection Committee.
PDP Authority :means the Personal Data Protection Authority.
Policy :means the Personal Data Protection and Processing Policy.
Turkish Code of Obligations :means Turkish Code of Obligations no. 6098 enacted on 11 January 2011 as published in the Official Gazette issued on 4 February 2011 under the issue no. 27836.
Turkish Criminal Code :means Turkish Criminal Code no. 5237 enacted on 26 September 2004 as published in the Official Gazette issued on 12 October 2004 under the issue no. 25611.
Turkish Commercial Code :means Turkish Commercial Code no. 6102 enacted on 13 January 2011 as published in the Official Gazette issued on 14 February 2011 under the issue no. 27846.

ANNEX-2 DATES OF SIGNIFICANCE FOR THE ENFORCEMENT OF THE PDP LAW

DateDescription
7 April 2016As of 7 April 2016, our Company acts in accordance with the following obligations: General rules and principles applicable to the processing of personal data. Obligations regarding the submission of privacy notice to data subjects. Obligations to ensure the data security.
7 October 2016As of 7 October 2016, the regulations listed below will come into force and our Company shall act in accordance with these regulations: Provisions regarding the transfer of personal data to third parties and abroad. Provisions regarding the data subject's right to exercise their rights against our Company (to learn whether their personal data is being processed, to request information, to learn to whom it has been transferred, to request correction) and Regulations concerning the right to lodge a complaint with the Personal Data Protection Board.
7 April 2017Consents obtained in accordance with the law prior to 7 April 2016 shall be deemed to be in conformity with the Personal Data Protection Law as of 7 April 2017, unless the data subject makes a contrary statement. As of 7 April 2017, the Regulations relating to the Personal Data Protection Law will enter into force and Our Company will act in accordance with these regulations.
7 April 2018Personal data processed prior to 7 April 2016 shall be made compatible and compliant with the PDP Law by our Company by 7 April 2018.
1 June 2024New legislative amendments regarding the processing of special category data and data transfers abroad have been published in the Official Gazette and entered into force.

ANNEX-3 PROCESSING OF PERSONAL DATA OF JOB APPLICANTS AND BUSINESS PARTNER EMPLOYEES

Data SubjectsCollection and Processing of Personal DataExercise of Rights and Application
Job ApplicantsPersonal data collected from job applicants during the recruitment process, as well as special categories of personal data collected depending on the nature of the job, are processed by our Company for the purposes set out in Sections 4.2 and 7 hereof and listed below: To assess the candidate's qualifications, experience, and suitability for the open position. Where necessary, to verify the accuracy of the information provided by the candidate or to contact third parties to conduct research on the candidate. To communicate with the candidate about the application and recruitment process or, where appropriate, to contact the candidate for any position opened domestically or abroad at a later date. To comply with the requirements of relevant legislation or the requests of the competent authority or organization. To develop and improve our Company's recruitment principles.Because job applicants are also data subjects, they may submit their requests about their rights to us by using the method described in Section 10 hereof.
Job Applicants (Data Collection Methods)The personal data of job applicants may be collected through the following methods and means: Digital application form published in written or electronic format; Curriculum vitae submitted to our Company by candidates via email, courier, references, and similar methods. Career or consultancy companies; during the interview in cases where interviews are held via video conference, telephone or personally (one to one). Checks and screening carried out to verify the accuracy of the information provided by the candidate as well as inquiries made by our Company. Recruitment tests conducted by experienced specialists to identify skills and personality traits, with the results being reviewed.Because job applicants are also data subjects, they may submit their requests about their rights to us by using the method described in Section 10 hereof.
Business Partner EmployeesOur Company may process personal data of a business partner employee in the course of the performance of the business operations with that business partner for the purposes defined in Section 4.2 and Section 7 hereof.Because job applicants are also data subjects, they may submit their requests about their rights to us by using the method described in Section 10 hereof.

ANNEX 4. CATEGORISATION OF PERSONAL DATA

Our Company processes personal data in line with those legitimate and lawful purposes underlying the processing of such data and limited to one or several personal data processing conditions as described in Article 5 of the PDP Law in compliance with those general principles set out in the PDP Law, including in particular, to those ones set out in Article 4 of the personal data processing and in compliance with all obligations defined in the PDP Law and for such durations limited to those ones set out under our Policies, provided that data subjects shall be informed pursuant to Article 10 of the PDP Law.

Personal Data CategorisationDescriptions for Personal Data Categorisation
Contact DataThis is a group of data that can be used to contact an individual (telephone number, address, email address, fax number, IP address).
Identity DataThis is a group of data containing information about a person's identity (first name, surname, Turkish Republic ID number, mother's name, father's name, place of birth, date of birth, gender, ID card serial number, ID card photocopy, tax number, social security number, nationality data, marriage certificate photocopy/scan, employee card).
Customer DataData that belongs to customers that use our products and services, which is clearly associated with an identified or identifiable natural person and is stored in the data recording system (e.g. customer number, customer's occupation or job, etc.).
Customer Transaction DataData of a customer who uses our products and services and which is clearly attributable to an identified or identifiable natural person and is stored in the data recording system (e.g. requests and instructions, order and basket information, etc.)
Physical Premises Security DataPersonal data relating to records and documents obtained upon entry to a physical location and during stay within the physical location, which are clearly attributable to an identified or identifiable natural person and are stored within the data recording system (e.g. entry/ exit logs, details about the visit, camera recordings, etc.)
Transaction Security DataPersonal data belonging to an identified or identifiable natural person, stored within the data recording system, and processed for the purpose of ensuring the technical, administrative, legal, and commercial security of our Company and related parties (e.g. information associating the transaction to the data subject and matching that person to the transaction, and showing that the person is authorized to perform that transaction. Information such as website passwords and login credentials)
Risk Management DataPersonal data belonging to an identified or identifiable natural person and stored in the data recording system, processed for the purpose of managing our Company's commercial, technical and administrative risks (e.g. IP address, Mac ID, etc. records)
Financial DataPersonal data within the scope of information, documents and records showing any financial outcome created according to the type of existing legal relationship with the personal data subject, which clearly belongs to an identified or identifiable natural person and is stored in the data recording system (information showing the financial outcome of transactions made by the data subject, credit card debt, loan amount, loan payments, interest amount and rate payable, debt balance, credit balance, etc.)
Biometric/Genetic DataThis is a data group containing biometric/genetic data that belongs to an individual (fingerprint, genetic information, vein mark/ pattern).
Job Applicant DataPersonal data belonging to data subjects who have disclosed their data in order to apply for a job in our Company, which is clearly attributable to an identified or identifiable natural person and is stored in the data recording system, and which is used in the application evaluation process (e.g. CV, interview notes, personality test results, etc.).
Marketing DataData belonging to an identified or identifiable natural person, stored in the data recording system, and used by our Company for marketing activities (e.g. reports and assessments showing the person's habits and preferences collected for marketing purposes, targeting data, cookie records, data enrichment activities)
Legal Transaction and Compliance DataPersonal data belonging to an identified or identifiable natural person, stored in the data recording system, processed for the purpose of determining and tracking legal claims and rights and fulfilling debts and legal obligations (e.g. data contained in documents such as court and administrative authority decisions)
Sensitive Personal DataPersonal data belonging to an identified or identifiable natural person, stored in a data recording system, and relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other faith, clothing and attire, membership to associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
Data for Request Complaint ManagementPersonal data relating to any request or complaint sent to our Company, which is clearly attributable to an identified or identifiable natural person and is contained within the data recording system. (e.g. requests and complaints directed towards our Company, related records and reports)
Audio-visual DataAudio-visual recordings associated with the data subject, which are clearly attributable to an identified or identifiable natural person and are stored within the data recording system (e.g. photographs, camera recordings and audio recordings)

DATA CONTROLLER IDENTITY

MERSİS No: 0683003379100011

Trade Name: ÖZDİSAN ELEKTRONİK PAZARLAMA SANAYİ TİCARET ANONİM ŞİRKETİ

Address: Dudullu OSB, DES Sanayi Sitesi 104. Sok. A07 Blok No: 54-56, Ümraniye/İstanbul/Türkiye 34776

Phone: +90 216 420 18 82 (pbx)

KEP Address: [email protected]