PURPOSE OF THE POLICY
This Policy has been prepared to set forth the fundamental principles and application guidelines to be adopted to ensure compliance with the obligations imposed on data controllers within the scope of the Law on the Protection of Personal Data No. 6698 (“KVKK”), which entered into force upon publication in the Official Gazette dated April 7, 2016, by KENT KATI ATIK TEMİZLİK TİC. LTD. ŞTİ.
SCOPE AND AMENDMENTS OF THE POLICY
This Policy, prepared in accordance with KVKK, applies to all personal data of our current and potential customers, employees, employees, shareholders, and officials of the institutions we cooperate with, and third parties, processed by automatic means or non-automatic means provided that they are part of a data recording system. KENT KATI ATIK TEMİZLİK TİC. LTD. ŞTİ. reserves the right to amend the Policy in line with amendments to KVKK and relevant regulations.
DEFINITIONS
Explicit Consent: Freely given, specific, informed consent regarding a particular issue.
Anonymization: Rendering personal data impossible to associate with an identified or identifiable natural person, even by matching it with other data.
Personal Data: Any information relating to an identified or identifiable natural person.
Special Categories of Personal Data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, clothing, membership of associations, foundations, or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
Processing of Personal Data: Any operation performed on personal data, whether by automated means or not, including obtaining, recording, storing, preserving, altering, reorganizing, disclosing, transferring, taking over, making available, classifying, or preventing its use.
Deletion of Personal Data: Making personal data inaccessible and unusable for relevant users.
Destruction of Personal Data: Making personal data inaccessible, irretrievable, and unusable by anyone.
Disposal: Deletion, destruction, or anonymization of personal data.
Board: The Personal Data Protection Board.
Policy: KENT KATI ATIK TEMİZLİK TİC. LTD. ŞTİ. Personal Data Retention and Disposal Policy.
Data Processor: A natural or legal person who processes personal data on behalf of the data controller based on the authorization granted.
Data Controller: The person who determines the purposes and means of processing personal data and manages the place where the data is kept systematically (data recording system).
PRINCIPLES TO BE APPLIED
The Company processes, retains, and disposes of personal data in line with the following principles:
Deletion, destruction, and anonymization of personal data are carried out in full compliance with the Law, relevant legislation, Board decisions, and this Policy.
All transactions related to deletion, destruction, and anonymization of personal data are recorded by the Company and these records are retained for at least 3 (three) years, excluding other legal obligations.
Unless otherwise decided by the Board, the appropriate method among deletion, destruction, or anonymization is selected by the Company. However, if requested by the relevant person, the selected method and justification are explained.
If all conditions for processing personal data specified in Articles 5 and 6 of the Law cease to exist, personal data are deleted, destroyed, or anonymized ex officio by the Company or upon the request of the relevant person. If the relevant person applies to the Company regarding this matter:
Requests are responded to within 30 (thirty) days.
If the conditions for processing personal data continue, the request is rejected with a justified explanation in accordance with Article 13 of the Law, and the rejection is communicated in writing or electronically within 30 (thirty) days.
If personal data subject to the request has been shared with third parties, the request is forwarded to the third party and necessary actions are requested in line with this Policy and legislation.
Deletion, destruction, and anonymization of personal data are carried out in compliance with the principles listed in Article 4 of the Law and the technical and administrative measures required under Article 12, relevant legislation, Board decisions, and this Policy.
In this context, the principles under Article 4 of the Law are prioritized:
Compliance with the law and good faith,
Accuracy and, where necessary, up-to-dateness,
Processing for specific, explicit, and legitimate purposes,
Relevance, limitation, and proportionality to the purpose for which they are processed,
Retention for the period stipulated in the relevant legislation or required for the purpose of processing.
In parallel with Article 12 of the Law, the Company takes technical and administrative measures to:
Prevent unlawful processing of personal data,
Prevent unlawful access to personal data,
Ensure the secure storage of personal data.
LEGAL, TECHNICAL, AND OTHER REASONS REQUIRING RETENTION AND DISPOSAL
The Company retains personal data of data subjects, particularly for:
Continuation of commercial activities,
Fulfillment of legal obligations,
Planning and execution of employee rights and benefits,
within the limits specified in the Law and other relevant legislation.
Reasons requiring retention:
Retention is directly related to the establishment or performance of a contract,
Retention is necessary for the establishment, exercise, or protection of a right,
Retention is necessary for the legitimate interests of the Company provided it does not harm fundamental rights and freedoms,
Retention is necessary for the Company to fulfill a legal obligation,
Retention is explicitly stipulated in the legislation,
Retention activities requiring the explicit consent of data subjects are carried out with their explicit consent.
Under the Regulation, in the following cases, personal data of data subjects are deleted, destroyed, or anonymized by the Company ex officio or upon request:
Amendments or repeal of the relevant legislative provisions that constitute the basis for processing or retention,
Disappearance of the purpose requiring the processing or retention of personal data,
Disappearance of the conditions requiring processing under Articles 5 and 6 of the Law,
Withdrawal of consent where processing is based solely on explicit consent,
Acceptance of the request of the data subject for deletion, destruction, or anonymization under Article 11 of the Law,
Complaint to the Board due to the rejection, insufficient response, or lack of response by the data controller, and the Board finding the request appropriate,
Expiration of the maximum retention period, unless there are conditions justifying longer retention.
RETENTION AND DISPOSAL PERIODS
In determining the retention and disposal periods of personal data obtained by the Company in accordance with the Law and relevant legislation, the following criteria are applied:
If a retention period is stipulated in the legislation, this period is respected. After its expiry, action is taken according to the next item.
If no period is stipulated or after the stipulated period expires:
Personal data are classified as personal or special category personal data as defined in Article 6 of the Law. Special category personal data are destroyed. The method is determined based on the nature and importance of the data.
It is assessed whether the retention complies with the principles in Article 4 of the Law. Data that contradict these principles are deleted, destroyed, or anonymized.
Applicable exceptions under Articles 5 and 6 are determined. Reasonable retention periods are set accordingly. After these periods, the data are deleted, destroyed, or anonymized.
Personal data exceeding the retention period are anonymized or destroyed every 6 (six) months in accordance with this Policy. All actions related to deletion, destruction, and anonymization are recorded and retained for at least 3 (three) years, excluding other legal obligations.
|
Process |
Retention Period |
Disposal Period |
|---|---|---|
|
Data retained under Labor Law |
10 years following termination of employment |
Within 180 days after retention period ends |
|
Data collected under occupational health and safety legislation (e.g., health reports) |
10 years following termination of employment |
Within 180 days after retention period ends |
|
Data retained under Social Security legislation |
10 years following termination of employment |
Within 180 days after retention period ends |
|
Documents related to work accidents/occupational diseases |
10 years following termination of employment |
Within 180 days after retention period ends |
|
Data collected under other relevant legislation |
As stipulated in relevant legislation |
Within 180 days after retention period ends |
|
Data subject to criminal proceedings under Turkish Penal Code or similar legislation |
Throughout statute of limitations period |
Within 180 days after retention period ends |
|
Customer and potential customer data |
10 years following the end of commercial relationship |
Within 180 days after retention period ends |
If the Company’s purpose for using the personal data has not ended, or if the applicable special legislation or statute of limitations requires longer retention than specified in the table above, the longer period applies.
METHODS, TECHNICAL AND ADMINISTRATIVE MEASURES FOR RETENTION AND DISPOSAL OF PERSONAL DATA
The Company has taken technical and administrative measures to ensure secure storage, prevent unlawful processing or access, and ensure lawful deletion and/or disposal of personal data in accordance with Article 12 of the Law and the Regulation. If the legal, technical, or other reasons requiring retention cease to exist, the relevant process is strictly monitored, and deletion, destruction, or anonymization is carried out accordingly.
Administrative Measures:
Access to personal data is limited to personnel whose job description requires such access, considering whether the data is of a special category and its importance.
Adequate security measures are provided based on the environment where personal data is stored, and unauthorized access is prevented.
Employees receive information security training.
Technical Measures:
Network and application security are ensured.
Up-to-date antivirus systems are used.
Necessary security measures are taken for physical environments containing personal data.
Security of environments containing personal data is ensured.
The amount of personal data is minimized as much as possible.
ENFORCEMENT AND IMPLEMENTATION
Updates to the entire Policy or specific articles take effect on the date of publication.
The most up-to-date version of the Policy is published on our website www.kenttemizlik.com. In case of conflict between this Policy and the Law or relevant legislation, the provisions of the Law and relevant legislation shall prevail.
Sincerely,
KENT KATI ATIK TEMİZLİK TİC. LTD. ŞTİ.