Purpose
AsMETAPANEL YAPI ELEMANLARI A.Ş. (Company); It is our priority to process the personal data of natural persons, including our customers, suppliers and employees, in accordance with the relevant legislation, especially the Constitution of the Republic of Turkey, international agreements on human rights to which our country is a party, and the Personal Data Protection Law No. 6698 (“KVKK”), and to ensure that the rights of the relevant persons whose data are processed are effectively exercised.
Therefore, including but not limited to; We carry out the processing, storage and transfer of data regarding our employees, suppliers, customers, users visiting our website and mobile applications, in short, all personal data we obtain during our activities, in accordance with our company's Personal Data Storage and Destruction Policy ("Policy").
Protection of personal data and respect for the fundamental rights and freedoms of natural persons whose personal data are collected are the basic principles of our policy regarding the processing of personal data. For this reason, we continue all our activities in which personal data is processed, taking into account the protection of privacy of private life, confidentiality of communication, freedom of thought and belief, and the rights to use effective legal remedies.
To protect personal data, all administrative and technical protection measures required by the nature of the relevant data are taken in accordance with the legislation and current technology.
This Policy explains the methods we follow regarding the processing, storage, transfer and deletion or anonymization of personal data shared during our commercial or social responsibility and similar activities within the framework of the principles mentioned in KVKK.
2. Scope
All personal data processed by the Company, including our customers, employees, suppliers and third parties, are within the scope of this Policy. Our policy is applied in all activities related to the processing of personal data owned or managed by our company, and has been handled and prepared by taking into account the KVKK and other relevant legislation on personal data and international standards in this field.
3. Definition and Abbreviations
In this section, special terms and expressions, concepts, abbreviations, etc. used in the Policy. briefly explained.
Explicit Consent: Consent regarding a specific subject, based on information and free will, given in a clear manner that leaves no room for hesitation, and limited only to that transaction.
Anonymization: It is the process of making personal data unable to be attributed to an identified or identifiable natural person in any way, even by matching it with other data.
Employee: Company Personnel.
Personal Data Owner (Relevant Person): Natural person whose personal data is processed.
Personal Data: Any information regarding an identified or identifiable natural person.
Special Personal Data: Data and biometric and genetic data regarding individuals' race, ethnic origin, political thought, philosophical belief, religion, sect, or other beliefs, appearance and dress, association, foundation or union membership, health, sexual life, criminal convictions, and security measures.
Processing of Personal Data: All kinds of operations performed on data such as obtaining, recording, storing, preserving, changing, rearranging, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data by fully or partially automatic or non-automatic means provided that it is part of any data recording system.
Data Processor: Real or legal person who processes personal data on behalf of the data controller, based on the authority given by the data controller.
Data Controller: Real or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.
KVK Board: Personal Data Protection Board.
KVK Authority: Personal Data Protection Authority.
KVKK: Personal Data Protection Law published in the Official Gazette No. 29677 dated April 7, 2016.
Policy: Personal Data Storage and Destruction Policy.
4. Roles and Responsibilities
4.1. Board of Directors
The Board of Directors is responsible for the top oversight of the determination and operation of notification, review and sanction mechanisms in case of non-compliance with the Policy, rules and regulations. Personal Data Protection and Processing Policy has been approved by the Board of Directors. It is the authorized approval mechanism to ensure that the policy is created, implemented and updated when necessary.
5. Legal Obligations
Legal obligations as a data controller within the scope of protection and processing of personal data in accordance with KVKK are listed below:
5.1. Disclosure Obligation
When collecting personal data as the data controller;
- Purposes for which your personal data will be processed,
- Our identity, information about the identity of our representative, if any,
- To whom and for what purpose your processed personal data may be transferred,
- Our method of collecting data and its legal reason,
- Rights arising from the law,
. We take care to ensure that this Policy, which is made available to the public by our company, is clear, understandable and easily accessible.
5.2. Obligation to Provide Data Security
As the data controller, we take the administrative and technical measures stipulated in the legislation to ensure the security of the personal data we are responsible for. Obligations regarding data security and measures taken are detailed in sections 9 and 10 of this Policy.
6. Classification of Personal Data
6.1. Personal Data
Personal data; It is all kinds of information regarding an identified or identifiable natural person. Protection of personal data is only related to real persons, and information belonging to legal entities that does not contain information about real persons is excluded from personal data protection. Therefore, this Policy does not apply to data belonging to legal entities.
6.2. Special Personal Data
Data regarding individuals' race, ethnic origin, political thought, philosophical belief, religion, sect or other beliefs, appearance, association, foundation or union memberships, health, sexual life, criminal convictions, and security measures, as well as biometric and genetic data, are special personal data.
7. Processing of Personal Data
7.1. Personal Data Processing Principles
We process personal data in accordance with the principles below.
7.1.1. Processing in accordance with the law and the rules of honesty
We process personal data in accordance with the rules of honesty, transparency and within the framework of our obligation to inform.
7.1.2 Ensuring Personal Data is Accurate and Up-to-Date Where Necessary
We take the necessary precautions in our data processing procedures to ensure that the data processed is accurate and up-to-date. We also allow the Personal Data Owner to contact us to update their data and correct any errors in the processed data.
7.1.3 Processing for specific, explicit and legitimate purposes
As a company, we process personal data within the scope and content of which are clearly determined and within the scope of our legitimate purposes determined to continue our activities within the framework of legislation and the ordinary flow of commercial life.
7.1.4 Personal Data Being Related to the Purpose for Processing, Limited and Proportionate
We process personal data in a limited and measured manner in connection with the purpose we clearly and precisely determine. We avoid processing personal data that is not relevant or does not need to be processed. For this reason, we do not process special personal data unless there is a legal requirement, or we obtain explicit consent when we need to process them.
7.1.5. Storage of Personal Data as Envisaged by Legal Regulations and During Our Legitimate Commercial Interests
Many regulations in the legislation require personal data to be stored for a certain period of time. Therefore, we keep the personal data we process for the period stipulated in the relevant legislation or for the period required for the purposes of processing personal data. If the storage period stipulated in the legislation expires or the purpose of processing no longer exists, we delete, destroy or anonymize personal data. Our principles and procedures regarding retention periods are set out in Article 9.1 of this Policy. It is detailed in the article.
7.2. Our Purposes for Processing Personal Data
Personal data is processed by our company for the following purposes:
- To carry out our activities,
- Providing support services within the scope of the contract and service standards,
- To identify the preferences and needs of our members/visitors and to shape and update the services we provide within this scope,
- To ensure that our legal obligations are fulfilled as required or required by legal regulations,
- To be able to conduct market research and statistical studies,
- Surveys, contests, promotions/channel development and sponsorships,
- Evaluating job applications,
- To contact people who have business relations with the company,
- Marketing,
- Doing legal reporting,
- Billing,
- Managing call center processes,
- Providing corporate communication,
- Providing appropriate personalized job postings and employment-related information,
- Sending newsletters or notifications via e-mail.
7.3. Processing of Special Personal Data
Special categories of personal data are processed by us by taking the administrative and technical measures prescribed by law and prescribed by the KVK Board, and if there is explicit consent or in cases required by the legislation. Since special personal data regarding health and sexual life can be processed by persons under the obligation of confidentiality or authorized institutions and organizations for the purposes of protecting public health, preventive medicine, medical diagnosis, execution of treatment and care services, planning and management of health services and their financing, they are not processed by us other than the data of our employees. Such data belonging to our employees may be processed by persons prescribed by law.
7.4. Processing of Personal Data for Human Resources and Employment Purposes
Resume, diploma, etc. that you shared with us during your application process as an employee candidate. We process, store and transfer your personal data contained in other documents for the purpose of evaluating job applications. Processing, transferring and storing the personal data you share as a candidate employee is within the scope of this Policy. Personal data of the Employee; It is collected, processed and stored within the framework of this Policy.
7.5. Processing of Personal Data Collected by Our Company Within the Scope of E-Commerce
Within the scope of services offered through our website;
- Providing detailed information to our customers online about our products
- Infrastructure services are provided that enable our customers to purchase products online.
The information shared by our members/visitors in the content of the questions asked is at their own initiative; The contents in question are subject to Article 7.2 of this Policy. It may be processed without the explicit consent of the member/visitor within the scope of our processing purposes stated in the article. Deletion, destruction or anonymization of personal data within the scope of this platform is within the scope of Article 9 of this Policy.
7.6. Exceptional Situations Where Explicit Consent is Not Required in the Processing of Personal Data
We may process personal data without explicit consent in the exceptional cases listed below and arising from the law:
- Clearly prescribed by law,
- It is necessary to process personal data of the parties to the contract, provided that it is directly related to the establishment or performance of a contract,
- Data processing is mandatory for the establishment, exercise or protection of a right,
- It is mandatory for us to process your data for our legitimate interests as the data controller, provided that fundamental rights and freedoms are not harmed.
Exceptional cases where special categories of personal data may be processed without the express consent of the Relevant Person are stated in Article 7.3 of this Policy.
8. Transfer of Personal Data
8.1. Domestic Transfer of Personal Data
As a company, we act in accordance with the decisions and regulations stipulated in the KVKK and taken by the KVK Board regarding the transfer of personal data. Without prejudice to the exceptional cases in the legislation, personal data and sensitive data will not be transferred by us to other natural persons or legal entities without the express consent of the Relevant Person.
In exceptional cases stipulated by KVKK and other legislation, data may be transferred to the authorized administrative or judicial institution or organization without the express consent of the Relevant Person, in the manner and within the limits stipulated in the legislation.
In addition, with the exceptions stipulated by the legislation;
- Policy 7.8. In cases described in the article,
- Concerning special personal data, Article 7.3 of the Policy. In the cases listed in the article,
- With the measures stipulated by the KVK Board and the relevant legislation, special personal data regarding the Relevant Person's health and sexual life can only be transferred to persons who are under the obligation of confidentiality or authorized institutions and organizations without seeking explicit consent, for the purpose of protecting public health, preventive medicine, medical diagnosis, execution of treatment and care services, planning and management of health services and their financing.
8.2. Transfer of Personal Data Abroad
As a rule, personal data are not transferred abroad without the express consent of the Relevant Person. However, Article 7.3 of this Policy. In cases where one of the exceptional circumstances stated in the article exists, third parties abroad can only:
In case it is located in countries where there is not sufficient protection, the data controllers in Türkiye and the foreign country in question must undertake in writing to provide adequate protection and have the permission of the KVK Board; In such cases, personal data may be transferred abroad without explicit consent.
- Being in countries with adequate protection declared by the KVK Board,
8.2. Institutions and organizations to which personal data is transferred
Personal data;
may be transferred according to the principles and rules described above.
- To our suppliers,
- To group companies,
- To legally authorized public institutions and organizations,
- To legally authorized private legal persons,
- To our shareholders,
8.3. Precautions We Take Regarding the Lawful Transfer of Personal Data
8.3.1. Technical Precautions
To protect personal data, including but not limited to;
- Makes in-company technical organization for the processing and storage of personal data in accordance with the legislation,
- Creating the technical infrastructure to ensure the security of the databases where your personal data will be stored,
- Follows and inspects the processes of the created technical infrastructure,
- It periodically updates and renews technical measures,
- We use protection systems, firewalls and similar software or hardware security products for risky situations and establish security systems in accordance with technological developments,
- We employ employees who are experts in technical matters.
8.3.2. Administrative Measures
To protect your personal data, including but not limited to;
- Our employees are informed and trained regarding the legal protection and processing of personal data.
- In the contracts we make with our employees and/or the policies we create, the company records the measures to be taken in cases of unlawful processing of personal data by our employees,
- We audit the personal data processing activities of the data processors we work with or the partners of the data processors.
9. PERSONAL DATA DESTRUCTION TECHNIQUES
At the end of the period stipulated in the relevant legislation or the storage period required for the purpose for which they are processed, personal data are destroyed by our company ex officio or upon the application of the relevant person, in accordance with the relevant legislation, using the techniques specified below.
9.1 Deletion of Personal Data
Personal data is deleted using the methods described below.
- Personal Data on the Servers: For personal data on the servers whose retention period has expired, the system administrator removes the access authorization of the relevant users and deletes them.
- Personal Data in the Electronic Environment: Among the personal data in the electronic environment, those whose period of storage has expired are made inaccessible and unusable in any way for other employees (relevant users) except the database administrator.
- Personal Data in the Physical Environment: Personal data kept in the physical environment, for those whose period of storage has expired, are made inaccessible and unusable for other employees, except for the unit manager responsible for the document archive. In addition, darkening is also applied by drawing/painting/erasing it so that it cannot be read.
- Personal Data on Portable Media: Among the personal data kept on Flash-based storage media, those that have expired to be stored are stored in secure environments with encryption keys, by being encrypted by the system administrator and access authorization is given only to the system administrator.
9.2 Destruction of Personal Data
Personal data is destroyed by the methods described below.
- • Personal Data in Physical Media: Among the personal data in paper media that have expired, they are irreversibly destroyed in paper clipping machines.
- • Personal Data Contained in Optical / Magnetic Media: Personal data contained in optical media and magnetic media, which have expired to be stored, are physically destroyed such as melting, burning or pulverizing. Additionally, the magnetic media is passed through a special device and exposed to a high magnetic field, making the data on it unreadable.
9.3 Anonymization of Personal Data
Anonymization of personal data means making personal data impossible to associate with an identified or identifiable natural person in any way, even if it is matched with other data.
In order for personal data to be anonymized; Personal data must be returned by the data controller or third parties and/or made unassociatable with an identified or identifiable natural person, even through the use of appropriate techniques in terms of the recording environment and relevant field of activity, such as matching the data with other data.
10. Storage of Personal Data
10.1. Storing Personal Data for the Period Envisaged in the Relevant Legislation or Necessary for the Purpose for which they are Processed
Personal data are stored for the period required by the purpose of processing personal data, without prejudice to the retention periods stipulated in the legislation. In cases where we process personal data for more than one purpose, the data is deleted, destroyed or anonymized and stored if the purposes of processing the data disappear or there is no obstacle in the legislation to delete the data upon the request of the Relevant Person. Legislative provisions and KVK Board decisions are complied with regarding destruction, deletion or anonymization.
10.2. Precautions We Take Regarding the Storage of Personal Data
10.2.1. Technical Precautions
- Creates technical infrastructures and related control mechanisms for the deletion, destruction and anonymization of personal data,
- Takes the necessary precautions to store personal data securely,
- Employs employees with technical expertise,
- Creates business continuity and emergency plans against possible risks and develops systems for their implementation,
- We establish security systems in accordance with technological developments regarding the storage areas of personal data.
10.2.2. Administrative Measures
- Raises awareness by informing our employees about the technical and administrative risks associated with storing personal data.
- In case of cooperation with third parties to store personal data, contracts made with the companies to which personal data are transferred; We include the provisions regarding taking the necessary security measures for the protection and safe storage of the transferred personal data of the persons to whom personal data is transferred.
11. Security of Personal Data
11.1. Our Obligations Regarding the Security of Personal Data
Your personal data;
We take administrative and technical measures foraccording to technological possibilities and implementation costs.
- To prevent unlawful processing,
- To prevent illegal access,
- To ensure that it is stored in accordance with the law,
11.2. Measures We Take to Prevent Unlawful Processing of Personal Data
- Educates and informs our employees about the lawful processing of personal data,
- The activities carried out by our company are evaluated in detail for all business units, and as a result of this evaluation, personal data is processed specific to the commercial activities carried out by the relevant units,
- In cases where cooperation is made with third parties for the purpose of processing personal data, in contracts made with companies that process personal data; It contains provisions regarding persons processing personal data to take the necessary security measures,
- In case of unlawful disclosure of personal data or data leakage, we report the situation to the KVK Board, carry out the investigations stipulated by the legislation and take the measures.
11.2.1. Technical and Administrative Measures Taken to Prevent Unlawful Access to Personal Data
To prevent unlawful access to personal data;
- Employs employees with technical expertise,
- It periodically updates and renews technical measures,
- Creates access authorization procedures within our company,
- We create the data recording systems used within our company in accordance with the legislation and periodically audit them,
- Educates and informs our employees about access to personal data and authorization,
- In contracts made with companies that provide access to personal data in cases where cooperation is made with third parties for activities such as processing and storing personal data; It includes provisions regarding taking the necessary security measures for people who access personal data,
- We establish security systems within technological developments to prevent unlawful access to personal data.
11.2.2. Precautions We Take in Case of Unlawful Disclosure of Personal Data
We take administrative and technical measures to prevent unlawful disclosure of personal data and update them in accordance with our relevant procedures. If we detect that personal data has been disclosed without authorization, we create systems and infrastructures to notify the Relevant Person and the KVK Board about this situation.
12. Rights of Personal Data Owner
Within the scope of our obligation to inform, we inform the Personal Data Owner and establish systems and infrastructures for this information. We make the necessary technical and administrative arrangements for the Personal Data Owner to exercise his rights regarding your personal data. Personal Data Owner on his personal data;
rights.
- Learning whether personal data is processed,
- Requesting information if personal data has been processed,
- Learning the purpose of processing personal data and whether they are used for their intended purpose,
- Knowing the third parties to whom personal data are transferred domestically or abroad,
- Requesting correction of personal data if they are incomplete or incorrectly processed,
- Requesting the deletion or destruction of personal data in case the reasons requiring the processing of personal data disappear,
- Requesting that the correction, deletion or destruction mentioned above be notified to third parties to whom personal data has been transferred,
12.1. Exercise of Rights Regarding Personal Data
Kişisel Veri Sahibi, Kişisel verileri ile ilgili talebini KVK Kurul'u tarafından ayrı bir yöntem belirlenmesi halinde bu yöntem ile veya şirket adresine şahsen, noter vasıtasıyla tebligat, kayıtlı elektronik posta (KEP) yoluyla imzalı şekilde başvuru yapabilecektir. In the application that the Personal Data Owner will make to exercise the above-mentioned rights and contain explanations regarding the right he/she requests to use; The requested matter must be clear and understandable, the requested subject must be related to the applicant personally, or if acting on behalf of someone else, he must be specifically authorized in this matter and this authority must be documented, and the application must include identity and address information and documents proving his identity must be attached to the application. These requests will be made on an individual basis and requests made by unauthorized third parties regarding personal data will not be taken into consideration. Detaylı bilgiye web sitemizde bulunan KVKK Başvuru Formunu inceleyerek ulaşabilirsiniz.
12.2. Başvurunun Değerlendirilmesi
12.2.1. Başvurunun Cevaplandırılması Süresi
Kişisel verilere ilişkin talepler, niteliğine göre en kısa sürede ve her halükarda en geç 30 (otuz) gün içinde ücretsiz olarak veya KVK Kurulu tarafından ücrete ilişkin yayınlanacak tarifedeki koşulların oluşması durumunda tarifedeki ücret mukabili sonuçlandırılır. Başvuru sırasında veya başvuru değerlendirilirken ek bilgi ve belge talep edilmesi söz konusu olabilecektir.
12.2.2. Başvuruyu Reddetme Hakkımız
Kişisel veriler ile ilgili başvurular;
hallerinde gerekçelendirilerek reddedilir.
- Kişisel verilerin resmi istatistik ile anonim hâle getirilmek suretiyle araştırma, planlama ve istatistik gibi amaçlarla işlenmesi,
- Kişisel verilerin özel hayatın gizliliğini veya kişilik haklarını ihlal etmemek ya da suç teşkil etmemek kaydıyla, sanat, tarih, edebiyat veya bilimsel amaçlarla ya da ifade özgürlüğü kapsamında işlenmesi,
- Kişisel Veri Sahibi tarafından alenileştiren kişisel verilerin işlenmesi,
- Başvurunun haklı bir nedene dayanmaması,
- Başvurunun ilgili mevzuata aykırı bir istem içermesi,
- Başvuru usulüne uyulmaması,
12.3. Başvurunun Değerlendirme Usulü
İşbu Politika'nın 11.2.1 maddesinde belirtilen cevaplandırma süresinin başlayabilmesi için yapılan taleplerin yazılı ve ıslak imzalı, noter vasıtasıyla tebligat ve ya kayıtlı elektronik posta (KEP) üzerinden gönderilmesi veya KVK Kurulu'nun belirlediği diğer yöntemlerle başvuranın kimliğinin tevsik edici bilgi ve belgelerle göndermeniz gerekmektedir. If the request is accepted, the relevant action is taken and notification is made in writing or electronically. Talebin reddi halinde ise, gerekçesi açıklanarak yazılı veya elektronik ortamda başvuru sahibine bildirilir.
12.4. Kişisel Verileri Koruma Kurulu'na Olan Şikâyet Hakkı
Başvurunun reddedilmesi, verdiğimiz cevabı yetersiz bulunması veya süresinde cevap verilmemesi hallerinde; başvuru sahibinin cevabı öğrendiği tarihten itibaren 30 (otuz) gün ve her halde başvuru tarihinden itibaren 60 (altmış) gün içerisinde KVK Kurulu'na şikâyette bulunma hakkı bulunmaktadır.
13. Güncelleme Periyodu
İşbu Politika en az yılda bir kez gözden geçirilir ve ihtiyaç halinde güncellenir.
14. Yürürlülük
İşbu Politika Şirket internet sitesinde yayınlanmasının ardından yürürlüğe girmiş kabul edilir.
