PDPL Policy

INTRODUCTION

The protection of personal data is of great importance to KENT KATI ATIK TEMİZLİK TİC. LTD. ŞTİ. (“Company” or “Our Company”) and is among our top priorities. With this Personal Data Processing and Protection Policy (“Policy”), our Company discloses the principles it has adopted regarding the processing and protection of personal data and sets out the fundamental principles for compliance with the provisions stipulated in the Law on the Protection of Personal Data No. 6698 (“Law”).

PURPOSE AND SCOPE

The main purpose of this Policy is to inform our Company officials, employees, partners, customers, institutions we cooperate with and their employees and officials, as well as individuals whose personal data is processed by our Company, about the processes related to the collection, storage, processing, sharing, and transfer of personal data by our Company.

Our Company’s primary principle is to ensure transparency in the processing of personal data, raise awareness, and clarify the rights and responsibilities of all relevant parties. KENT KATI ATIK TEMİZLİK TİC. LTD. ŞTİ. reserves the right to amend this Policy in line with changes in the Law and relevant regulations.

DEFINITIONS

Explicit Consent: Consent given for a specific subject, based on information and expressed with free will.
Relevant User: Persons who process personal data within the organization of the data controller or under its authority and instructions, excluding those responsible for the technical storage, protection, and backup of the data.
Anonymization: Making personal data impossible to associate with an identified or identifiable natural person, even by matching with other data.
Personal Data: Any information relating to an identified or identifiable natural person.
Sensitive Personal Data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance, membership of associations, foundations, or trade unions, health, sexual life, criminal convictions, security measures, biometric and genetic data.
Processing of Personal Data: Any operation performed on personal data, whether by automatic means or by non-automatic means provided that they are part of a data recording system, such as collection, recording, storage, preservation, alteration, reorganization, disclosure, transfer, acquisition, making available, classification, or prevention of use.
Destruction: Deletion, destruction, or anonymization of personal data.
Board: The Personal Data Protection Board.
Authority: The Personal Data Protection Authority.
Policy: KENT KATI ATIK TEMİZLİK TİC. LTD. ŞTİ. Personal Data Processing and Protection Policy.
Data Processor: A natural or legal person who processes personal data on behalf of the data controller based on the authority given.
Data Controller: The person who determines the purposes and means of processing personal data and manages the place where the data is systematically kept (data recording system).
Data Subject: Any natural person whose personal data is processed or may be processed, including but not limited to employees, customers, business partners, shareholders, authorized persons, potential customers, candidate employees, interns, visitors, and employees of institutions with which our Company and/or its subsidiaries have a commercial relationship.
Law: The Law on the Protection of Personal Data No. 6698, published in the Official Gazette dated 07.04.2016 and numbered 29677.
Deletion of Personal Data: Making personal data inaccessible and unusable for relevant users.
Destruction of Personal Data: Making personal data inaccessible, irretrievable, and unusable by anyone in any way.

PRINCIPLES TO BE FOLLOWED IN THE PROCESSING OF PERSONAL DATA

Our Company fulfills the conditions stipulated in the legislation regarding the protection and processing of personal data and processes personal data in compliance with the Law and relevant legislation by acting in accordance with the principles below:

  • Processing Personal Data in Compliance with the Law and the Rules of Honesty

    Our Company processes personal data in compliance with the law and the rules of honesty, limiting the processing to the extent necessary for the purpose.

  • Ensuring Personal Data is Accurate and Up-to-Date

    Our Company takes maximum care to ensure that personal data is accurate and up-to-date by communicating with data subjects or evaluating their requests.

  • Processing for Specific, Explicit, and Legitimate Purposes

    Our Company clearly determines the purpose of processing personal data and adopts legality and legitimacy as the basis for processing.

  • Data Processing Relevant, Limited, and Proportionate to the Purpose

    Our Company processes personal data to the extent necessary to fulfill its commercial activities, contractual obligations, and legal responsibilities.

  • Retention for the Period Stipulated by Relevant Legislation or Required by the Purpose

    Our Company retains personal data for the period necessary for the purpose of processing and in any case for the legal period stipulated in the legislation. When the processing purpose is fulfilled or the legal period expires, the data is deleted, destroyed, or anonymized.

PURPOSES OF PERSONAL DATA PROCESSING

Personal data collected by our Company is processed based on one or more of the conditions specified in Articles 5 and 6 of the Law. If none of these conditions apply, data is processed based on the explicit consent of the data subject.

The conditions specified in Articles 5 and 6 of the Law are as follows:

  • Processing is clearly stipulated by law,

  • Processing is necessary for the establishment or performance of a contract,

  • Processing is necessary for the data controller to fulfill its legal obligations,

  • Data is made public by the data subject and is processed limited to this purpose,

  • Processing is necessary for the establishment, exercise, or protection of rights,

  • Processing is necessary for the legitimate interests of the data controller provided that it does not harm the fundamental rights and freedoms of the data subject,

  • Processing of sensitive personal data, excluding health and sexual life, is permitted by law,

  • Processing of sensitive personal data related to health and sexual life is permitted for public health protection, preventive medicine, medical diagnosis, treatment, care services, and health service management by authorized persons or institutions under confidentiality obligations.

Our Company processes your personal data for the following purposes:

  • To carry out our commercial activities and fulfill our contractual obligations,

  • To fulfill legal and/or administrative obligations,

  • To fulfill employer obligations under employment contracts,

  • To comply with labor, social security, and occupational safety laws,

  • To plan and execute human resources processes,

  • To maintain personnel records,

  • To manage occupational health and safety processes,

  • To manage relationships with business partners, customers, or suppliers,

  • To plan and execute corporate communication and management processes,

  • To ensure the security of our Company, employees, customers, and visitors,

  • To respond to requests from official authorities and judicial bodies and fulfill legal obligations.

TRANSFER OF PERSONAL DATA

Our Company transfers personal data to third parties in accordance with legal obligations and decisions of the Personal Data Protection Board.

Sensitive personal data collected with explicit consent will only be transferred to third parties with the explicit consent of the data subject unless otherwise required by law.

In cases stipulated by Articles 5 and 6 of the Law, personal data may be transferred to third parties based on the relevant legal grounds. Our Company takes all necessary security measures during such transfers.

As of the effective date of this Policy, our Company does not transfer personal data abroad.

Within the framework of the Law and for fulfilling legal and contractual obligations, commercial purposes, and legitimate interests without violating the fundamental rights and freedoms of the data subject, personal data may be transferred to authorized institutions, judicial, official, and administrative authorities.

RIGHTS OF DATA SUBJECTS AND EXERCISING THESE RIGHTS

Data subjects have the following rights under Article 11 of the Law:

  • To learn whether personal data is processed,

  • To request information if personal data has been processed,

  • To learn the purpose of processing and whether it is used appropriately,

  • To know the third parties to whom personal data is transferred domestically or abroad,

  • To request correction of incomplete or inaccurate data,

  • To request deletion or destruction of personal data,

  • To request notification of the correction, deletion, or destruction to third parties,

  • To object to the emergence of a result against them through automatic data analysis,

  • To request compensation for damages arising from unlawful data processing.

However, the following situations are excluded from these rights under Article 28 of the Law:

  • Processing is necessary for the prevention of crime or criminal investigation,

  • Processing of publicly disclosed personal data by the data subject,

  • Processing by authorized institutions for supervisory, regulatory, or disciplinary investigation purposes,

  • Processing necessary to protect state economic or financial interests.

The following situations are entirely outside the scope of the Law:

  • Processing for research, planning, and statistics after anonymization,

  • Processing for art, history, literature, or scientific purposes or within freedom of expression without violating privacy or personal rights,

  • Processing for national defense, security, public order, or economic security by authorized institutions,

  • Processing for judicial or enforcement purposes.

Data subjects may submit their requests regarding their rights to our Company free of charge through contact details available on www.kenttemizlik.com, via notary, or through registered electronic mail using a secure electronic signature.

Requests are evaluated and finalized within thirty (30) days. If the process requires additional costs, fees may apply as specified by the legislation.

Our Company may request information or documents to verify the identity of the applicant and clarify the request.

Applications may be rejected in the following cases:

  • Situations clearly excluded from the Law,

  • Processing is necessary to prevent a crime or for an investigation,

  • The request may interfere with others’ rights and freedoms,

  • The request requires disproportionate effort,

  • The requested information is already public,

  • The legal retention period has not expired.

PERSONAL DATA SECURITY

Our Company has taken all necessary technical and administrative measures to prevent unlawful processing and unauthorized access to personal data and to ensure secure storage.

We limit access to personal data to authorized persons only. Data is stored securely, including in locked cabinets for physical documents. Special categories of personal data are processed with additional security measures in accordance with Article 6 of the Law.

If personal data is unlawfully obtained, our Company will immediately take necessary security measures and inform the relevant person and the Authority.

DELETION, DESTRUCTION, AND ANONYMIZATION OF PERSONAL DATA

In accordance with Article 7 of the Law, our Company deletes, destroys, or anonymizes personal data when the processing purpose no longer exists.

Data subjects may also request the deletion or destruction of their personal data. If all legal conditions for data processing no longer apply, the data will be deleted, destroyed, or anonymized within thirty (30) days.

If the data has been shared with third parties, they will also be informed to take necessary actions.

All such processes comply with the Law, Board decisions, and this Policy.

Detailed procedures are set out in our Company’s “Personal Data Retention and Destruction Policy.”

ORGANIZATIONAL STRUCTURE AND SUSTAINABILITY

Our Company is responsible for compliance with the Law, managing this Policy and related policies, updating them when necessary, and ensuring sustainability in personal data protection.

Our Company will continue to develop its employees and business partners in this regard.

EFFECTIVENESS AND IMPLEMENTATION

Amendments to this Policy become effective upon publication.

The most up-to-date version of the Policy is published on www.kenttemizlik.com. In case of a conflict between the Policy and the Law, the provisions of the Law and relevant legislation will prevail.

Kind regards,

KENT KATI ATIK TEMİZLİK TİC. LTD. ŞTİ.