Y���kleniyor...

KVKK Disclosure Text

Anasayfa KVKK Disclosure Text
  1. INTRODUCTION

For Tema İş Makinaları Servis Ltd. Şti., the protection of the personal data of all natural persons with whom it has a relationship is of great importance. For this reason, it is working with utmost diligence to comply with the current legislation and to apply the principles of data security.

In this context, the necessary administrative and technical measures are taken by Tema İş Makinaları Servis Ltd. Şti. for the processing and protection of personal data in accordance with Law No. 6698 and related legislation.

  1. Purpose

The Personal Data Retention and Disposal Policy has been prepared to determine the procedures and principles regarding the retention and disposal activities carried out by Tema İş Makinaları Servis Ltd. Şti., and your personal data is processed and protected within the scope of this policy.

The processes and procedures related to the retention and disposal of Personal Data are carried out in accordance with the Policy prepared by the company in this regard.

1.2 Scope

This policy applies to all personal data of our customers, potential customers, employees, employee candidates, employees of institutions we cooperate with, and third parties, which are processed by automated or non-automated means, provided that they are part of any data recording system.

  1. Abbreviations and Definitions

Explicit Consent: Refers to consent that is based on information and declared with free will regarding a specific subject.

Cookie: Small files that are saved on users' computers or mobile devices and help store preferences and other information on the web pages they visit.

Relevant User: Persons who process personal data within the data controller's organization or in accordance with the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection, and backup of the data.

Disposal: The deletion, destruction, or anonymization of personal data.

Contact Person: The natural person reported by the data controller during registration to the Registry for communication with the Authority regarding the obligations under the Law and secondary regulations to be issued based on this Law, for legal entities resident in Turkey and for the representative of a non-resident legal entity data controller.

(The contact person is not authorized to represent the Data Controller. As the name suggests, they are the person appointed solely to ensure "contact" between the data controller, the data subjects, and the Authority.)

KVKK (DPL): The Personal Data Protection Law No. 6698, dated March 24, 2016, published in the Official Gazette dated April 7, 2016, and numbered 29677.

Recording Medium: Any medium where personal data is processed wholly or partially by automated means or by non-automated means, provided that it is part of any data recording system.

Personal Data: Any information relating to an identified or identifiable natural person.

Processing of Personal Data: Any operation performed on personal data such as obtaining, recording, storing, preserving, altering, rearranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of such data, wholly or partially by automated means or by non-automated means, provided that it is part of any data recording system.

Anonymization of Personal Data: Making personal data impossible to associate with an identified or identifiable natural person under any circumstances, even by matching with other data.

Deletion of Personal Data: Making personal data inaccessible and unusable in any way for the Relevant Users.

Destruction of Personal Data: The process of making personal data inaccessible, irretrievable, and unusable by anyone in any way.

Board: The Personal Data Protection Board.

Authority: The Personal Data Protection Authority.

Special Categories of Personal Data: Data related to individuals' race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, association, foundation or union membership, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data.

Periodic Disposal: The process of deletion, destruction, or anonymization to be carried out ex officio at recurring intervals specified in the personal data retention and disposal policy, in the event that all the conditions for processing personal data cease to exist.

Policy: The personal data processing and protection policy created by the Data Controller.

VERBİS: A registration system where natural and legal persons who process personal data must register before starting to process personal data and where they will enter information on a categorical basis regarding the personal data they are processing.

Data Processor: A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by them.

Data Recording System: The recording system where personal data is structured and processed according to specific criteria.

Data Subject/Relevant Person: The natural person whose personal data is processed.

Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.

1.4 UPDATING AND AMENDING THE POLICY

This policy contains information in accordance with the Law and other legislation regarding personal data and will enter into force on the date of its publication on the Website https://temaservis.com. The policy may be updated from time to time due to legal changes, changes in the Personal Data processing processes of Tema İş Makinaları Servis Ltd. Şti., or other reasons. Updates become effective on the date of publication of the new Policy on the Website.

  • RESPONSIBILITY AND DISTRIBUTION OF DUTIES

Tema İş Makinaları Servis Ltd. Şti.; all its business units and employees support the proper implementation of the technical and administrative measures specified in this Policy and the Personal Data Protection and Processing Regulation, the training and awareness-raising of unit employees, continuous supervision, the lawful processing of personal data, and the implementation of technical and administrative measures to ensure data security in all data processing environments, and work in cooperation with the responsible units.

The Personal Data Committee established within Tema İş Makinaları Servis Ltd. Şti. is authorized and responsible for taking/having taken the necessary actions and supervising the processes to ensure that the data of data subjects are stored and processed in accordance with the legislation, the Personal Data Processing and Protection Policy, and the Personal Data Retention and Disposal Policy.

The Personal Data Committee consists of four people: a manager, a human resources specialist, a technical expert, and a lawyer. The titles and job descriptions of the employees serving on the Personal Data Committee are specified below:

TitleJob Description
Personal Data Protection CommitteeTo direct all kinds of planning, analysis, research, and risk identification studies in projects carried out in the compliance process with the Law; to manage the processes that need to be carried out in accordance with the legislation, the Personal Data Processing and Protection Policy, and the Personal Data Retention and Disposal Policy, and to decide on requests from data subjects, to follow developments regarding the protection of personal data; to make recommendations to senior management on what needs to be done within the scope of these developments, and to manage relations with the Authority and the Board.
Personal Data Protection Committee ManagerResponsible for examining and reporting the requests of data subjects to the Personal Data Committee for evaluation; for ensuring that the actions regarding the data subject requests evaluated and decided upon by the Personal Data Committee are carried out in accordance with the Committee's decision; for supervising the retention and disposal processes and reporting these supervisions to the Personal Data Committee; and for executing the retention and disposal processes.
  • MATTERS REGARDING THE PROTECTION OF PERSONAL DATA

The personal data of natural persons with whom Tema İş Makinaları Servis Ltd. Şti. has a relationship are stored and disposed of in accordance with the DPL (Data Protection Law). In addition, during the process of storing and disposing of personal data, all kinds of technical and administrative measures are taken to prevent the unlawful storage and disposal of this data by third parties. As a company, we attach importance to the protection of privacy in the processes of storing and disposing of personal data, and data security is observed at the highest level.

RECORDING MEDIA

Personal data is kept and stored securely by Tema İş Makinaları Servis Ltd. Şti. in the media listed in the table below, in accordance with the legislation.

Electronic MediaSoftware, Firewall, Intrusion Detection and Prevention System, Antivirus, Printer, Scanner, Photocopier, Computers, Camera Recording Systems, Optical Discs and Removable Memories, Mobile Devices
Non-Electronic MediaPrinted Data Recording Media; Forms and Documents, Other Written and Visual Media
  • EXPLANATIONS REGARDING RETENTION AND DISPOSAL

During its business activities, the personal data of our employees, employee candidates, visitors, customers, and third parties with whom we have a relationship as a service provider are carefully collected, processed, stored, and disposed of in accordance with the procedures stipulated in this protocol and the Law. In this context, detailed explanations regarding retention and disposal are given below, respectively.

4.1 Explanations on Retention

Article 3 of the Law defines the concept of processing personal data, Article 4 states that the processed personal data must be connected, limited, and proportionate to the purpose for which they are processed and must be retained for the period stipulated in the relevant legislation or necessary for the purpose for which they are processed, and Articles 5 and 6 list the conditions for processing personal data. Accordingly, our Company retains personal data for the period necessary for the purpose for which they are processed and in accordance with the minimum periods stipulated in the legal legislation to which the relevant activity is subject. In this context, our Company first determines whether a period for the retention of personal data is stipulated in the relevant legislation, and if a period has been determined, it acts in accordance with the most reasonable period suitable for the current situation. Personal data are disposed of at the end of the specified retention periods in accordance with the periodic disposal periods or the data subject's application, and by the specified disposal methods (deletion and/or destruction and/or anonymization).

  • Legal Reasons Requiring Retention

Personal data processed by Tema İş Makinaları Servis Ltd. Şti. within the framework of its activities are retained for the period stipulated in the relevant legislation. In this context, personal data;

  • Personal Data Protection Law No. 6698,
  • Turkish Code of Obligations No. 6098,
  • Social Insurance and General Health Insurance Law No. 5510,
  • Law on the Regulation of Publications on the Internet and Combating Crimes Committed Through These Publications No. 5651,
  • Public Financial Management Law No. 5018,
  • Occupational Health and Safety Law No. 6331,
  • Right to Information Act No. 4982,
  • Law on the Exercise of the Right to Petition No. 3071,
  • Labor Law No. 4857,
  • Retirement Health Law No. 5434,
  • Social Services Law No. 2828,
  • Regulation on Health and Safety Measures to be Taken in Workplace Buildings and Annexes,
  • Other secondary regulations in force under these laws.

In addition, personal data are retained for the periods stipulated within the framework of;

  • Explicit provision for the retention of personal data in the legislation,
    • Direct relevance of personal data to the establishment and performance of contracts,
    • Retention of personal data for the establishment, exercise, or protection of a right,
    • Necessity of retaining personal data for the legitimate interests of the Company, provided that it does not harm the fundamental rights and freedoms of individuals,
    • Retention of personal data for the Company to fulfill any of its legal obligations.

is retained for the stipulated retention periods.

  • Processing Purposes Requiring Retention

Our Company retains the personal data it processes within the framework of its activities for the following purposes.

  • To carry out human resources processes.
  • To ensure corporate communication.
  • To ensure corporate security,
  • To be able to conduct statistical studies.
  • To be able to perform business and transactions as a result of signed contracts and protocols.
  • To ensure the fulfillment of legal obligations as required or mandated by legal regulations.
  • To establish contact with natural/legal persons in a business relationship with the Company.
  • To make legal reports.
  • To manage call center processes.
  • The burden of proof as evidence in future legal disputes.
    • Reasons Requiring Disposal

Personal data;

  • In case it becomes necessary due to the amendment or repeal of the relevant legislative provisions that form the basis for the processing or storage of personal data,
  • The disappearance of the purpose requiring the processing or storage of personal data,
  • The disappearance of the conditions requiring the processing of personal data in Articles 5 and 6 of the Law,
  • In cases where the processing of personal data is based solely on the condition of explicit consent, the withdrawal of the data subject's explicit consent,
  • The acceptance by the company of the application made by the data subject for the deletion, destruction, or anonymization of their personal data within the framework of the rights in Article 11 of the Law,
  • In cases where the data controller rejects the application made by the data subject for the deletion, destruction, or anonymization of their personal data, finds the response given insufficient, or does not respond within the period prescribed by the Law; a complaint is filed with the Board and this request is found appropriate by the Board,
  • The maximum period for storing personal data has passed and there is no condition that would justify storing the personal data for a longer period,

Our Company, upon the request of the data subject, deletes, destroys, or anonymizes the data, or deletes or anonymizes it ex officio.

  • TECHNICAL AND ADMINISTRATIVE MEASURES

All administrative and technical measures taken by "Tema İş Makinaları Servis Ltd. Şti." in accordance with the principles in Article 12 of the DPL to ensure the secure storage of your personal data, to prevent its unlawful processing and access, and to ensure its lawful disposal are listed below.

  • Technical Measures

The technical measures taken by "Tema İş Makinaları Servis Ltd. Şti." regarding the personal data it processes are listed below:

  • New technological developments are followed, and technical measures are taken on systems, especially in the field of cybersecurity; the measures taken are periodically updated and renewed.
  • Software and hardware including virus protection systems, data vulnerability securities, and firewalls are installed.
  • Risks, threats, vulnerabilities, and any openings to our company's information systems are identified through penetration tests, and necessary measures are taken.
  • It ensures that the access authorities of employees in the information technology units to personal data are kept under control.
  • Our company takes the necessary measures for the physical security of information systems equipment, software, and data.
  • Hardware and software measures are taken to ensure the security of information systems against environmental threats.
  • Access to storage areas containing personal data is logged, and inappropriate access or access attempts are kept under control.
  • Our company takes the necessary measures to ensure that deleted personal data is inaccessible and unusable for the relevant users.
  • An authorization matrix is created for employees.
  • A Personal Data Protection Committee has been established to notify the data subject and the Board in case personal data is unlawfully obtained by others.
  • Strong passwords are used in electronic environments where personal data is processed.
  • Secure logging systems are used in electronic environments where personal data is processed.
  • Data backup programs that ensure the secure storage of personal data are used.
  • Access to personal data stored in electronic or non-electronic media is restricted according to access principles.

List of Technical Measures:

  1. Ensuring network security and application security.
    1. Using a closed system network for personal data transfers via the network.
    1. Implementing key management.
    1. Ensuring the security of personal data stored in the cloud.
    1. Keeping access logs regularly.
    1. Revoking the authorizations of employees who change duties or leave their jobs.
    1. Using up-to-date anti-virus systems.
    1. Using firewalls.
    1. Including data security provisions in signed contracts.
    1. Monitoring personal data security.
    1. Ensuring the security of environments containing personal data.
    1. Backing up personal data and ensuring the security of the backed-up personal data.
    1. Implementing and monitoring a user account management and authorization control system.
    1. If special categories of personal data are to be sent via e-mail, they must be sent encrypted and using a KEP or corporate e-mail account.

 

  1. Using intrusion detection and prevention systems.
    1. Taking and monitoring cybersecurity measures.
    1. Using encryption.
    1. Using data loss prevention software.
  • Administrative Measures

The administrative measures taken by our company regarding the personal data it processes are listed below:

  • Trainings on preventing the unlawful processing of personal data, preventing unlawful access to personal data, ensuring the preservation of personal data, communication techniques, technical knowledge and skills, Law No. 657, and other relevant legislation are provided to improve the qualifications of employees.
  • Confidentiality agreements are signed with employees regarding the activities carried out by the Company.
  • Before starting to process personal data, the company fulfills its obligation to inform the data subjects.
  • A personal data processing inventory has been prepared.
  • The contracts signed between "Tema İş Makinaları Servis Ltd. Şti." and its employees explain the scope of lawful personal data processing activities and include commitments to comply with these matters.

There is a Personal Data Protection Committee within "Tema İş Makinaları Servis Ltd. Şti.". This committee, on behalf of the data controller "Tema İş Makinaları Servis Ltd. Şti.", personally conducts the necessary inspections to ensure the implementation of the provisions of the Law and has them conducted by obtaining support from competent organizations when necessary. According to the results of these inspections, the identified violations, negativities, and non-conformities are reported to the Committee Manager, and the necessary measures are taken in light of these issues.

  • PERSONAL DATA DISPOSAL TECHNIQUES

In accordance with the relevant provisions of the DPL and the "Regulation on the Deletion, Destruction, and Anonymization of Personal Data" issued by the Board; even though it has been processed in accordance with the relevant legal provisions, if the reasons requiring its processing cease to exist, the personal data will be deleted, destroyed, or anonymized by "Tema İş Makinaları Servis Ltd. Şti." based on its own decision or upon the request of the data subject. "Tema İş Makinaları Servis Ltd. Şti." has established a policy in this regard in accordance with the regulation's provisions, and according to this policy, it carries out disposal according to the nature of the data.

  • Deletion of Personal Data
Deletion of Personal Data in Paper Form:
Blackout:Personal data in physical form is deleted using the blackout method. The blackout process is carried out by cutting the personal data on the relevant document where possible, and where not possible, by making it invisible using permanent ink in a way that is irreversible and unreadable with technological solutions.
Deletion Methods for Personal Data Held in Cloud and Local Digital Media
Secure deletion from software:Personal data held in cloud or local digital media is deleted by a digital command in a way that it cannot be recovered. Data deleted in this way cannot be accessed again.
  • Destruction of Personal Data
Destruction Methods for Personal Data Held in Printed Media
Physical destruction:Documents held in printed media are destroyed by shredding machines in a way that they cannot be reassembled.
Destruction Methods for Personal Data Held in Local Digital Media
Physical destruction:It is the process of physically destroying optical and magnetic media containing personal data, such as melting, burning, or grinding into powder. Data is made inaccessible through processes like melting, burning, grinding into powder, or passing it through a metal grinder.
Degaussing:It is the process of corrupting the data on magnetic media in an unreadable way by exposing it to a high magnetic field.
Overwriting:By writing random data consisting of at least seven passes of 0s and 1s over magnetic media and rewritable optical media, the reading and recovery of old data are prevented.
Destruction Methods for Personal Data Held in Cloud Media
Secure deletion from software:Personal data held in the cloud is deleted by a digital command in a way that it cannot be recovered, and when the cloud computing service relationship ends, all copies of the necessary encryption keys to make the personal data usable are destroyed. Data deleted in this way cannot be accessed again.
  • Anonymization of Personal Data

Anonymization of personal data is the process of rendering personal data in such a way that it can no longer be associated with an identified or identifiable natural person, even by matching it with other data.

For personal data to be anonymized, it must be rendered impossible to associate with an identified or identifiable natural person, even through the use of appropriate techniques for the recording medium and the relevant field of activity, such as reversal by the data controller or third parties and/or matching the data with other data.

  • RETENTION AND DISPOSAL PERIODS

Regarding the personal data processed by "Tema İş Makinaları Servis Ltd. Şti." within the scope of its activities;

  • The retention periods on a personal data basis for all personal data within the scope of activities carried out depending on the processes are in the Personal Data Processing Inventory;
  • The retention periods on a data category basis are in the VERBİS registration;
  • The retention periods on a process basis are in the Personal Data Retention and Disposal Policy.

The ex officio deletion, destruction, or anonymization process for personal data whose retention periods have expired is carried out by the Information Technology Department.

PROCESS/SOURCE TRANSACTIONRETENTION PERIODLEGAL BASISDISPOSAL PERIOD
Employee Access Restrictions – Active Directory Transactions10 Years from the end of the Employment RelationshipLabor Law No. 4857 and Relevant LegislationIn the first periodic disposal period following the end of the retention period
Data Processed for Corporate Communication Activities for Employees (e.g., Participant List, etc.)10 Years from the end of the Employment RelationshipSectoral practices apply. Accordingly, it can only be processed with explicit consent.In the first periodic disposal period following the end of the retention period
Log Records of Employee Access to Media Containing Personal Data10 Years, being at least 2 years, due to the possibility of being subject to labor lawsuitsLaw No. 5651, Labor Law No. 4857 and TIB (Telecommunication Communication Presidency) RegulationsIn the first periodic disposal period following the end of the retention period
Personal Data Processed with Documents Required to be Kept under the Tax Procedure Law such as Invoices/Expense Slips/Receipts5 YearsTax Procedure Law No. 213In the first periodic disposal period following the end of the retention period
Data Processed for General Assembly Transactions10 YearsTurkish Commercial Code No. 6102In the first periodic disposal period following the end of the retention period
General Assembly and Board of Directors Meeting Transactions10 yearsTurkish Commercial Code No. 6102In the first periodic disposal period following the end of the retention period
Job Application/Internship Application/Data on Candidate Applications if the Application is Not Accepted (e.g., CV, Resume, Cover Letter, Application Form, etc.)1 YearSectoral practices apply. Accordingly, it can only be processed with explicit consent.In the first periodic disposal period following the end of the retention period
Data Regarding the Personnel File Kept under the Labor Law10 Years from the end of the Employment RelationshipLabor Law No. 4857 and Relevant Legislation / Turkish Code of Obligations No. 6098In the first periodic disposal period following the end of the retention period
Data Kept under the Labor Law (e.g., severance pay, notice pay, bad faith compensation, information that could be subject to compensation for violation of the principle of equal treatment, payroll records, number of annual leave days, etc.)5 Years from the end of the Employment RelationshipLabor Law No. 4857 and Relevant LegislationIn the first periodic disposal period following the end of the retention period
Data Kept under the Labor Law that Could be Subject to Union Compensation (e.g., performance records, disciplinary penalties, termination documents, etc.)10 Years from the end of the Employment RelationshipTurkish Code of Obligations No. 6098In the first periodic disposal period following the end of the retention period
In Accordance with the Labor Law: Responding to Court/Enforcement Information Requests Regarding Employees10 Years from the end of the Employment RelationshipLabor Law No. 4857 and Relevant LegislationIn the first periodic disposal period following the end of the retention period
Data Collected under Occupational Health and Safety Legislation (e.g., pre-employment health tests, health reports, OHS Trainings, records of Occupational Health and Safety activities, etc.)15 Years from the end of the Employment RelationshipOccupational Health and Safety Law No. 6331, Occupational Health and Safety Services RegulationIn the first periodic disposal period following the end of the retention period
Camera Recordings6 MonthsLegitimate Interest of the Data ControllerIn the first periodic disposal period following the end of the retention period
All Records Related to Accounting and Financial Transactions10 YearsLaw No. 6102, Law No. 213In the first periodic disposal period following the end of the retention period
Personal Data of Customers10 Years after the legal relationship ends.Law No. 6098, Law No. 213, Law No. 6502In the first periodic disposal period following the end of the retention period
Personal Data Processed and Shared with the Union for Union Activities10 YearsLaw on Unions and Collective Bargaining Agreements No. 6356In the first periodic disposal period following the end of the retention period
Data Kept under SGK (Social Security Institution) Legislation (e.g., employment declarations, premium/service documents, etc.)10 Years from the end of the Employment RelationshipSocial Insurance and General Health Insurance Law No. 5510 and Relevant LegislationIn the first periodic disposal period following the end of the retention period
Personal Data Processed in Contractual Relations (e.g., Name Surname, signature circular, etc.) End of Contract10 Years following the Termination of the ContractTurkish Code of Obligations No. 6098In the first periodic disposal period following the end of the retention period
Personal Data Processed in Commercial Books to be Kept, Documents Created Based on Records in Commercial Books, Financial Statements, etc., for Company Activities10 YearsTurkish Commercial Code No. 6102In the first periodic disposal period following the end of the retention period
Information on Company Partners and Board of Directors Members (e.g., attendance fee and dividend payments, etc.)10 YearsTurkish Commercial Code No. 6102In the first periodic disposal period following the end of the retention period
Information on Company Partners and Board of Directors Members (personal data in the share ledger)Indefinite due to the Obligation to Keep the Share LedgerTurkish Commercial Code No. 6102In the first periodic disposal period following the end of the retention period
Personal Data of Suppliers10 Years after the legal relationship endsLaw No. 6102, Law No. 6098 and Law No. 213In the first periodic disposal period following the end of the retention period
Personal Data Processed due to the Obligation to Provide After-Sales Services under the Law on the Protection of the Consumer (No. 6502) (e.g., product installation date, customer contact information)15 YearsLaw on the Protection of the Consumer No. 6502, After-Sales Services Regulation published in the Official Gazette dated 13.06.2014 and numbered 29029In the first periodic disposal period following the end of the retention period
Personal Data Related to Tax Records5 YearsTax Procedure Law No. 213In the first periodic disposal period following the end of the retention period
Personal Data of Visitors2 YearsLaw No. 5651 (For Visitors Accessing the Company's Wi-Fi Network)In the first periodic disposal period following the end of the retention period
  • PERIODIC DISPOSAL PERIOD

In accordance with Article 11 of the Regulation, "Tema İş Makinaları Servis Ltd. Şti." has determined the periodic disposal period as 6 months. Accordingly, the periodic disposal process is carried out in the company every year in June and December.

  • PUBLICATION OF THE POLICY

The policy is published in two different media: with a wet signature (printed paper) and in electronic form.

  1. POLICY'S UPDATE PERIOD

The policy is reviewed as needed and the necessary sections are updated.

  1. EFFECTIVENESS AND REPEAL OF THE POLICY

This Policy, issued by "Tema İş Makinaları Servis Ltd. Şti.", came into force on the date it was published. This Policy is published on the Company's website (https://temaservis.com) and is made available to the access of data subjects upon their request.

Update NoDateReason for UpdateUpdate Page NoUpdated Section
     
     
     

The right to the protection of personal data has also found its place as a fundamental human right in Article 8 of the Charter of Fundamental Rights of the European Union and Article 16 of the Treaty on the Functioning of the European Union.

DPL Art. 4 lists the fundamental principles to be complied with for the processing of personal data. These principles are taken into account and meticulously applied within the scope of all personal data processing activities carried out by Tema İş Makinaları Servis Ltd. Şti. ("COMPANY" or the Company). The fundamental principles followed by the Company in its data processing processes are as follows:

Processing in Accordance with the Law and the Rule of Honesty: The "COMPANY" acts in accordance with the general principles of law and the rule of honesty while fulfilling its obligation to process and protect personal data.

Processing Personal Data Accurately and Up-to-Date: The "COMPANY" is aware that ensuring that personal data provides accurate and up-to-date information about individuals is of great importance for the protection of individuals' rights. It shows the utmost care expected of it to ensure that the personal data being processed is accurate and up-to-date.

Processing Personal Data for Specific, Explicit, and Legitimate Purposes: The DPL requires that data processing activities be carried out for specific, explicit, and legitimate purposes. The "COMPANY" also carries out personal data processing activities for specific, explicit, and legitimate purposes required by its activities within the framework of this principle.

Processing in Connection with, Limited to, and Proportionate to the Purpose for which they are Processed: The "COMPANY" processes personal data within the limits sufficient to achieve the purposes determined within the scope of its activities. The "COMPANY" acts in accordance with the principle of being limited and proportionate by refraining from processing personal data that is not needed.

Retaining for the Period Stipulated in the Relevant Legislation or Necessary for the Purpose for which it is Processed: Personal data being processed by the "COMPANY" is retained for the period until the conditions for processing personal data cease to exist. When these purposes disappear, the "COMPANY" will terminate the procedures for retaining the relevant personal data. The company transparently informs all relevant parties with the necessary documents regarding all data processing processes.

INTRODUCTION

The Personal Data Protection Law No. 6698 (DPL/Law) was published in the Official Gazette on April 7, 2016, to regulate the procedures and principles to be complied with by natural and legal persons who process personal data, in order to protect the fundamental rights and freedoms of individuals, especially the privacy of private life, in the processing of personal data belonging to natural persons.

1. PURPOSE OF THE POLICY

TEMA İŞ MAKİNALARI SERVİS LTD. ŞTİ. Personal Data Processing and Protection Policy (Policy) has been prepared with the aim of disciplining the processing of personal data to be processed during the activities carried out, in accordance with the legislation, and protecting fundamental rights and freedoms, especially the privacy of private life as stipulated in the Constitution.

While preparing the "Policy," the fundamental principle was to determine what data the working units within the "COMPANY" organization collect, why they collect it, and why they transfer this data to third parties, and to understand the Company's personal data processing procedure. In addition, this Policy aims to determine what administrative and technical measures will be taken to protect data privacy both inside and outside the "COMPANY" organization, to explain these measures, and to inform and enlighten the individuals whose data are processed.

2. SCOPE OF THE POLICY

All natural persons whose data are processed directly or indirectly due to the activities of the "COMPANY" fall within the scope of the "Policy".

Within the scope of this "Policy", customized information is provided about the data processed within the framework of the transactions and activities in the "COMPANY" organization, the categorization of the data, the groups of data recipients, the legal reason and method of data collection, the groups of third parties to whom the data is transferred, the processing periods of the data, and the disposal periods of the data.

3. DEFINITIONS

Explicit Consent: Refers to consent that is based on information and declared with free will regarding a specific subject.

Cookie: Small files that are saved on users' computers or mobile devices and help store preferences and other information on the web pages they visit.

Relevant User: Persons who process personal data within the data controller's organization or in accordance with the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection, and backup of the data.

Disposal: The deletion, destruction, or anonymization of personal data.

Contact Person: The natural person reported by the data controller during registration to the Registry for communication with the Authority regarding the obligations under the Law and secondary regulations to be issued based on this Law, for legal entities resident in Turkey and for the representative of a non-resident legal entity data controller.

(The contact person is not authorized to represent the Data Controller. As the name suggests, they are the person appointed solely to ensure "contact" between the data controller, the data subjects, and the Authority.)

KVKK (DPL): The Personal Data Protection Law No. 6698, dated March 24, 2016, published in the Official Gazette dated April 7, 2016, and numbered 29677.

Recording Medium: Any medium where personal data is processed wholly or partially by automated means or by non-automated means, provided that it is part of any data recording system.

Personal Data: Any information relating to an identified or identifiable natural person.

Processing of Personal Data: Any operation performed on personal data such as obtaining, recording, storing, preserving, altering, rearranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of such data, wholly or partially by automated means or by non-automated means, provided that it is part of any data recording system.

Anonymization of Personal Data: Making personal data impossible to associate with an identified or identifiable natural person under any circumstances, even by matching with other data.

Deletion of Personal Data: Making personal data inaccessible and unusable in any way for the Relevant Users.

Destruction of Personal Data: The process of making personal data inaccessible, irretrievable, and unusable by anyone in any way.

Board: The Personal Data Protection Board.

Authority: The Personal Data Protection Authority.

Special Categories of Personal Data: Data related to individuals' race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, association, foundation or union membership, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data.

Periodic Disposal: The process of deletion, destruction, or anonymization to be carried out ex officio at recurring intervals specified in the personal data retention and disposal policy, in the event that all the conditions for processing personal data cease to exist.

Policy: The personal data processing and protection policy created by the Data Controller.

VERBİS: A registration system where natural and legal persons who process personal data must register before starting to process personal data and where they will enter information on a categorical basis regarding the personal data they are processing.

Data Processor: A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by them.

Data Recording System: The recording system where personal data is structured and processed according to specific criteria.

Data Subject/Relevant Person: The natural person whose personal data is processed.

Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.

4. COMPANY DPL STRUCTURE

The data controller for the personal data processing activities covered by this Policy is Tema İş Makinaları Servis Ltd. Şti.

Our company, within the framework of the DPL compliance program, has organized a separate organization for personal data protection processes to guarantee the continuity of compliance with the DPL, has carried out the appropriate business and transactions, and has provided the necessary equipment. In this context, a "Personal Data Protection Commission" has been established within our Company, and a Contact Person has been appointed.

4.1. Personal Data Protection Commission

A DPL Commission has been established within our Company to demonstrate our commitment to ensuring sustainable compliance with the personal data protection legislation and to ensure the effectiveness of our personal data protection system. The chairman and members of the DPL Commission are determined by the board of directors and carry out their duties.

4.2. Contact Person

To fulfill the obligation to appoint a contact person as stipulated by the legislation, a contact person who has received the necessary training and has the required competence in DPL has been appointed. The primary responsibility of the contact person is to ensure communication between the data controller and the data subjects and the Authority, as stipulated by the legislation, and the contact person does not have the authority to represent the data controller. The contact person will also work towards the fulfillment of the duties and responsibilities of the DPL Commission. The Contact Person is a natural member of the DPL Commission within our organization and calls the DPL Commission to a meeting when necessary.

5. PURPOSES OF PROCESSING YOUR PERSONAL DATA, THE PERSONAL DATA WE PROCESS, COLLECTION METHODS, AND LEGAL GROUNDS

  1. Processing Purposes

Your personal data will be used to achieve the purposes shown in the relevant legislation for the "COMPANY" and by observing the limits stipulated in the DPL. The processing purposes are as follows;

  • Planning and development of commercial activities specific to the Company, within the scope of business execution;
    • Performing legally required transactions, fulfilling obligations,
    • Notifications to official institutions,
    • Activities related to the establishment and performance of contracts
    • Activities related to the execution, management, planning, and performance of customer relations
    • Activities for the performance of post-contract services
    • Follow-up, planning, and execution of consultancy activities
    • Planning, follow-up, and execution of finance and accounting activities
    • Planning and execution of information technology and data security activities
    • Planning and execution of works for the physical and electronic/network security of the Company
  • Within the scope of planning, executing, and managing corporate relations;
    • Management, development, planning, and execution of supplier/business partner/customer relations
    • Structuring and executing corporate management and communication activities
    • Planning and executing activities such as receiving and providing external training
  • Carrying out the necessary work by the relevant units for you to benefit from the services offered by our Company,
  • Within the scope of managing and concluding post-service and ongoing service request and complaint processes;
  • Activities for receiving, evaluating, and concluding requests and complaints,
  • Performing and tracking the transactions and activities for the fulfillment of obligations arising from the contractual relationship
  • Procurement of personnel in areas needed by the company, fulfillment of rights and obligations within the scope of legislation regulating business life, especially Labor Law No. 4857, Occupational Health and Safety Law No. 6331, and Social Insurance and General Health Insurance Law No. 5510,
  • Execution of activities such as salary payments to personnel, provision of per diems, making payments from the revolving fund, conducting internal correspondence,
  • Provision of information and documents to authorized public institutions and organizations and judicial authorities in cases specified by law,
  • Ensuring the functionality of organization and event (seminar, conference, meeting, training, symposium, etc.) management processes in the company and announcing them to the public, ensuring the continuity of the company's website and social media accounts with up-to-date data to ensure public awareness and maintain its currency, managing promotion and advertising processes,
  • Keeping archives in accordance with the procedures shown in the legislation to carry out storage and archive activities and to create annual unit activity reports,
  • Creating and tracking visitor records,
  • Ensuring the security of buildings, personnel, and visitors,
  • Using anonymized data for statistical activities for research purposes,
  • Receiving and responding to data subject applications to be made within the scope of the DPL.
  1. The Personal Data We Process

Identity Information: Your name, surname, T.R. identity number, mother's name, father's name, place and date of birth, personnel registration number, and other information provided by you to the Company with your explicit consent.

Contact Information: Your residence address, workplace address, telephone number, and e-mail address, KEP (Registered Electronic Mail) address, and, if available, your mobile phone number, fax number, or information on other communication channels you have indicated you prefer for us to contact you, provided with your consent.

Work and Education Information: Information on the application form you filled out for application to the Company (job application, event participation application), within the scope of registration documents and/or in job application forms sent to the Company's e-mail address, or your identity information, work status information, contact information, and education status information ("University graduate, master's degree graduate, physics department graduate," etc.) and past graduation information, course/seminar information you attended, certificate information, and national or international exam results, obtained through other online or physical application methods provided by the Company.

Customer Transaction Information: Call center records, credit card statements, customer instructions, records recorded in relevant channels, etc., depending on an instruction and request associated with the person.

Financial Information: Credit card debt, loan amount, loan payments, debt balance, credit balance, etc., in parallel with information from official authorities in case of a legal follow-up, and accounting information and related records.

Financial Information: Bank name and branch information, bank account number information, IBAN number information, acquired for the purpose of paying salaries and fringe benefits, refunding overpayments and undue payments, making payments from the revolving fund, and making payments for external assignments.

Request/Complaint Management Information: Information and records collected regarding the requests and complaints made to our Company about our products and services associated with the person, and information on the reports where these are evaluated by the relevant business units, etc.

Special Categories of Personal Data: Special categories of personal data related to health, criminal conviction, and security measures of disabled persons and persons against whom a conviction has been issued and/or a security measure has been applied, who are employed to fulfill employment obligations arising from legislation within the company, are processed.

Although the Company has no other direct purpose for processing special categories of personal data, your data on religion, attire, philosophical belief, political opinion, and health (e.g., clothing, devices, and prostheses understood from a photograph) that may be indirectly acquired within the scope of the identity document, photographs, or still/moving images obtained during events you have provided to the Company, and other special categories of information you have voluntarily stated in a document provided by the Company.

iii. Methods of Collecting Your Personal Data

Your personal data is collected through registration/application forms submitted via the internet, receipts and expense documents, security camera recordings, and in case personal data is sent to the COMPANY's official e-mail address at tema@temaservis.com, through these communication channels.

Personal data is also collected by physically sending documents, physically filling out a document provided by the Company, or by calling the lines +90 (530) 392 32 05 or other internal numbers belonging to the Company.

Your personal data is also collected through automated means via cookies used at tema@temaservis.com and its extensions. These cookies are only necessary for the visitor to use the site with full efficiency and are used to remember the visitor's preferences and do not obtain any other personal data. You can access our cookie policy at https://temaservis.com.

  1. Legal Grounds for Processing Personal Data

The DPL lists the conditions for processing personal data in Article 5, paragraph 2. If the purposes of processing personal data by a data controller can be evaluated within the framework of the personal data processing conditions listed in the DPL, that data controller can process personal data lawfully. In this context, personal data processing activities are carried out by the Company in cases where the Company's activity can be evaluated within the scope of the personal data processing conditions regulated in the DPL. The Company does not engage in any personal data processing activity that does not fall within the scope of personal data processing conditions.

The personal data processing conditions in the DPL are as follows;

  • The explicit consent of the data subject,
  • It is clearly stipulated in the laws,
  • It is necessary for the protection of the life or physical integrity of the person who is unable to express their consent due to factual impossibility or whose consent is not legally valid, or of another person,
  • It is necessary to process personal data of the parties to a contract, provided that it is directly related to the establishment or performance of a contract,
  • It is necessary for the data controller to fulfill its legal obligation,
  • The data has been made public by the data subject themself,
  • Data processing is necessary for the establishment, exercise, or protection of a right,
  • Data processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.

For special categories of personal data, the basic processing condition is also explicit consent, and the Company does not fundamentally aim to process special categories of personal data. However, your special categories of personal data that we need to process due to our activity or that you have approved with your explicit consent are also processed proportionately within the framework of the legislation.

The conditions listed in the DPL for processing special categories of personal data are as follows;

  • The explicit consent of the data subject,
  • It is clearly stipulated in the laws for special categories of personal data other than health and sexual life.

6. TRANSFER OF PERSONAL DATA

Domestic transfer: As is known, according to Article 8/2-a and b of the DPL, it is possible to transfer personal data domestically without obtaining explicit consent if they are processed within the scope of Article 5/2 and 6/3 of the DPL. The "COMPANY" makes transfers to third parties by observing the relevant provisions, and if they do not fall within the scope of these provisions, the explicit consent of the data subjects is sought.

Overseas transfer: As a rule, the "COMPANY" does not transfer data abroad. However, it may be possible for data and documents processed by the "COMPANY" to be stored on computers located outside the Company, for e-mails to be sent, and for records to be accessed from these computers, and for the databases of the systems and/or e-mail providers where this data is stored and transferred to be located abroad. In addition, especially in the organization of international events, there may be a necessity to transfer personal data abroad for hotel accommodations, obtaining visas, purchasing airline tickets, and the execution and planning of the international event. In this case, the transfer will be made in compliance with the provisions of Article 9 of the DPL.

Your personal data is shared with authorized public institutions and organizations, judicial authorities, enforcement authorities, law enforcement units, and suppliers, business partners, and shareholders from whom contracted products and/or services are received, for the purposes shown in this Policy and by the means herein. The table showing the parties with whom data is shared is below:

Persons to Whom Data May Be TransferredDefinitionPurpose
Business PartnerParties with whom the company establishes a business partnership while conducting its commercial activitiesSharing of personal data limited to ensuring the fulfillment of the purposes for which the business partnership was established
ShareholdersShareholders who are authorized to design the company's commercial strategies and auditing activities according to the relevant legislative provisionsSharing of personal data limited to the purposes of designing the company's commercial strategies and auditing
Company OfficialsBoard members and other authorized personsSharing of personal data limited to the purposes of designing the company's commercial strategies, ensuring top-level management, and auditing
Legally Authorized Private Law PersonsPrivate law persons legally authorized to receive information and documents from the companySharing of data limited to the purpose requested by the relevant private law persons within their legal authority
Legally Authorized Public Institutions and OrganizationsPublic institutions and organizations legally authorized to receive information and documents from the companySharing of personal data limited to the purpose of the relevant public institutions and organizations' request for information

No data transfer is made that does not concern the company's purposes. For example, even if we have obtained it with your consent, your IP address information or vehicle license plate information is not shared with any third party, including the persons and institutions shown above. The exception to this determination is when the transfer of said data is mandated by legislation, or is mandatory for a criminal investigation, or is requested by an official authority based on legislation and with justification.

7. RIGHTS OF THE DATA SUBJECT

Within the scope of the DPL, the data subject;

  • To learn whether your Personal Data is being processed,
  • To request information if your Personal Data has been processed,
  • To learn the purpose of processing your Personal Data and whether they are used in accordance with their purpose,
  • To know the third parties to whom your Personal Data is transferred at home or abroad,
  • To request the correction of your Personal Data if it is incomplete or incorrectly processed,
  • To request the deletion or destruction of your Personal Data within the framework of the conditions stipulated in the DPL legislation,
  • To request that the procedures for the disposal or correction of your Personal Data be notified to the third parties to whom the data has been transferred,
  • To object to the emergence of a result against you by analyzing the processed data exclusively through automated systems,
  • To demand the compensation of the damage in case of loss due to the unlawful processing of your Personal Data.

How Can You Exercise Your Rights?

Data subjects can submit their rights listed above to our Company using the following methods by filling out the application form published at https://temaservis.com or which can be obtained from the "COMPANY" headquarters.

In the application procedure, the "COMPANY" carries out its transactions within the scope of the Communiqué on the Procedures and Principles of Application to the Data Controller. In this context, the application must be made in accordance with Article 5 of the said communiqué.

After the form is completely filled out;

  • By personally submitting a wet-signed copy of the Application Form together with a document that will provide identity verification to the address Ahievran Cad. No:99 Ostim, Yenimahalle/ANKARA,
  • By sending a wet-signed copy of the fully completed Application Form together with a document that will provide identity verification to the address Ahievran Cad. No:99 Ostim, Yenimahalle/ANKARA via a notary,
  • By signing the Application Form with a "secure electronic signature" as defined in the Electronic Signature Law No. 5070 and sending it to the address tema@temaservis.com,
  • Also by filling out and signing this application form, scanning the wet-signed form and uploading it to a computer, and sending it to the address tema@temaservis.com, (if this method is preferred, a document that will provide identity verification must also be attached to the e-mail)
  • Or it should be sent to us using other methods to be determined by the Board.

In the application;

  • Name, surname, and signature,
  • T.R. identity number for citizens of the Republic of Turkey, nationality, passport number, or identity number, if any, for foreigners,
  • Residential or business address for notification,
  • E-mail address, telephone, and fax number for notification, if any,
  • The subject of the request must be included.
  • Information and documents related to the subject are attached to the application.
  • In written applications, the date on which the document is served on the data controller or its representative is the application date.
  • In applications made by other methods, the date on which the application reaches the data controller is the application date.

The "COMPANY" will conclude the requests of data subjects regarding their rights listed above, which they will submit in writing or through other methods to be determined by the Board, as soon as possible and within thirty days at the latest from the date of submission. The applications of data subjects may be charged within the framework of the tariffs published by the Board. In accordance with Article 7 of the relevant Communiqué, if the data subject's application is to be answered in writing, no fee is charged for up to ten pages. A transaction fee of 1 Turkish Lira may be charged for each page over ten pages. If the response to the application is given in a recording medium such as a CD or flash drive, the fee that can be requested by the data controller cannot exceed the cost of the recording medium.

For the purpose of responding to applications made by data subjects, the "COMPANY" may request additional information and documents to verify the identity of the applicant, to prevent the unlawful transmission of another person's personal data to unrelated persons, and to clarify the applicant's request. If such information and documents are not shared, the data subject's application may not be answered.

It is of serious importance to confirm that the application was made by the "identity owner" and/or an authorized person. Since the purpose is the protection of personal data, providing personal data to third parties and taking action within the scope of the rights explained in Article 11 of the DPL due to the inability to perform identity verification will harm the interest of the data subject that needs to be protected. For this reason, we hope that you will understand our sensitivity regarding identity verification procedures and assist our Company.

The "COMPANY" concludes the requests as soon as possible and within 30 days at the latest. The result of the evaluation is notified to the data subject in writing or electronically, and if the request is accepted, the necessary action is taken in accordance with the DPL.

In cases where the applications of data subjects are rejected, the response given is found to be insufficient, or the application is not responded to in time, the data subject may file a complaint with the Personal Data Protection Board within 30 days from the date they learn of the response, in accordance with Article 14 of the DPL.

8. LEGAL EXCEPTIONS AND EXPLICIT CONSENT EXPLANATION IN THE PROCESSING OF PERSONAL DATA AND SPECIAL CATEGORIES OF PERSONAL DATA

It is desired that the "COMPANY" adopts the method of applying for the "explicit consent" of the data subjects as a principle. Considering the processing purposes and conditions stated in this Policy, there is no need to obtain the consent of the data subjects for data processing conditions that fall within the scope of legal exceptions.

However, this situation should not be interpreted under any circumstances as the "COMPANY" will not benefit from the exception provisions and/or will choose the path of obtaining explicit consent in every case.

9. INFORMATION ON THE PROCESSING OF PERSONAL DATA

9.1. Channels Where Personal Data is Obtained

Our company mainly obtains personal data from the following channels:

  • Organization, Event, Conference Participant-Invitee
  • Employee Personnel File Documents
  • Camera Recordings,
  • SMS/E-Mail, Telephone
  • Website, Applications, Cookies and Similar Tracking Technologies,
  • Fax,
  • Mail, Cargo or Courier Services,
  • Other Physical and Electronic Media.

Depending on technological developments, new additions may be made to the above personal data collection channels by the "COMPANY", or the use of some of the existing channels may be abandoned. In such cases, the correct expression of the channels used will be ensured by updating the Policy to maintain transparency and accountability.

9.2. Classification of Personal Data

The categorization of personal data is extremely important for compliance with the legislation. Our legislation mainly gathers personal data under two categories: personal data and special categories of personal data. We have made a categorization according to data types under these categories.

The categories of personal data and special categories of personal data of the "COMPANY" are shared in the table below:

PERSONAL DATA CATEGORIZATIONEXPLANATIONS
Identity InformationInformation about the person's identity in documents such as driver's license, identity card, residence permit, passport, marriage certificate.
Contact InformationInformation for contacting the data subject, such as phone number, address, e-mail.
Family Members and Relatives InformationInformation about the family members and relatives of the personal data subject processed to protect the legal interests of the Company and the data subject, or related to the products and services we offer.
Physical Space Security InformationPersonal data related to records and documents such as camera recordings, fingerprint records taken during entry to and stay in the physical space.
Transaction Security InformationYour personal data processed to ensure our technical, administrative, legal, and commercial security while conducting our commercial activities.
Financial InformationPersonal data processed related to information, documents, and records showing any financial result created according to the type of legal relationship our Company has established with the personal data subject.
Personnel InformationPersonal data processed related to information, documents, and records showing any financial result created according to the type of legal relationship our Company has established with the personal data subject.
Employee Transaction InformationPersonal data processed related to any transaction carried out by our employees or natural persons in a working relationship with our Company in connection with their work.
Employee Performance and Career Development InformationPersonal data processed for the purpose of measuring the performance of our employees or other natural persons in a working relationship with our Company and planning and executing their career development within the scope of our Company's human resources policy.
Fringe Benefits and Interests InformationPersonal data processed for the planning of fringe benefits and interests we offer and will offer to our employees or other natural persons in a working relationship with our Company, determining the objective criteria for entitlement to these, and tracking their entitlements.
Legal Transaction and Compliance InformationPersonal data processed within the scope of determining and pursuing our legal receivables and rights, fulfilling our debts, and complying with our legal obligations and Company policies.
Audit and Inspection InformationPersonal data processed within the scope of our Company's legal obligations and compliance with Company policies.
Special Categories of DataData related to individuals' race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, association, foundation or union membership, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data.
Request/Complaint Management InformationPersonal data related to the receipt and evaluation of any request or complaint directed to our Company.
Reputation Management InformationInformation collected to protect the commercial reputation of our Company and the evaluation reports created and actions taken related to it.
Incident Management InformationPersonal data processed for the purpose of taking the necessary legal, technical, and administrative measures against incidents that develop to protect the commercial rights and interests of our Company and the rights and interests of our students.

9.3. Data Subject Classification

The "COMPANY"'s classification of data subjects is shown in the table below:

Data Subject ClassesDescription
CustomerRefers to natural persons who benefit from the products and services offered by the Company.
Employee CandidateRefers to natural persons who apply for a job by sending a resume to the Company or by other methods.
Shareholder, Official, Employee of Company Business PartnersAll natural persons, including employees, shareholders, and officials of natural and legal persons (such as business partners, suppliers) with whom the Company has any kind of business relationship.
Employee/InternNatural persons who perform services with a work contract in the Company.
Potential CustomerNatural persons who have requested or shown interest in using the Company's products and services, or who have been evaluated as having this interest in accordance with commercial custom and the rules of honesty, and who have the potential to become customers.
VisitorAll natural persons who enter the physical premises owned by the Company for various purposes or visit its websites for any purpose.
Third PartiesRefers to natural persons other than the data subject categories listed above and the company's employees.

10. RETENTION AND DISPOSAL OF PERSONAL DATA

The "COMPANY" stores the personal data of the data subjects whose data it processes in electronic and physical environments by taking the necessary technical and administrative security measures.

The retention period of personal data by the "COMPANY" is calculated by taking into account the periods determined in the relevant legislation.

In the event that the purposes for processing personal data, which would eliminate the conditions for processing personal data in the DPL, cease to exist, personal data will be disposed of by the "COMPANY". These disposal procedures are carried out ex officio at 6-month intervals in accordance with the provisions of the relevant legislation, or are concluded if the requests from data subjects are found to be appropriate. In accordance with the legislation, the "COMPANY" will fulfill the data subject's requests for deletion and/or destruction within 30 days at the latest, unless another period is stipulated in the legislation, and will inform the data subject.

The records related to the disposal of Personal Data will be kept by the "COMPANY" for a period of 3 years. The periods stipulated in special legislation are reserved, and if these periods change due to amendments in the DPL and related legislation, the current periods will be applied.

The "COMPANY" uses deletion, anonymization, or destruction disposal techniques.

The processes related to disposal are carried out and decided by the DPL Commission.

11. OBLIGATION TO INFORM

In accordance with Article 10 of the DPL, the "COMPANY" will fulfill its obligation to inform as mentioned in the DPL by presenting the following information to the relevant data subjects during the acquisition of personal data:

  • The identity of the data controller and its representative, if any,
  • The purpose for which personal data will be processed,
  • To whom and for what purpose the processed personal data can be transferred,
  • The method and legal basis for collecting personal data,
  • Other rights listed in Article 11.

The "COMPANY" prepares appropriate information notices and presents them to the relevant persons to fulfill its obligation to inform while carrying out its activities.

12. MEASURES REGARDING THE SECURITY OF PERSONAL DATA

The "COMPANY" shows all kinds of reasonable care and diligence in ensuring the confidentiality and security of the personal data it processes, with the sense of responsibility that comes with being a well-established company. The "COMPANY", in addition to the requirements of the relevant legislation, takes the necessary technical and administrative measures at a reasonable level to ensure data privacy and security within the framework of Article 12 of the DPL. With these administrative and technical security measures, it is aimed to prevent the unlawful processing of personal data, to prevent unlawful access to personal data, and to ensure that personal data is preserved at an appropriate security level.

In the event that personal data is processed on its behalf by another natural or legal person (data processor), the "COMPANY" will take the necessary measures to ensure that the above-mentioned measures are also taken by the relevant data processors.

In case of unlawful acquisition of personal data by third parties, it will notify the data subjects, the Board, and other relevant public institutions and organizations in accordance with the provisions of the relevant legislation.

While taking measures for the security of personal data, the Personal Data Security Guide (Technical and Administrative Measures) published by the Board and the decisions of the Board are taken into consideration.

Administrative Measures

  • Establishment and operation of an information security management system within the Company,
    • Signing of commitment letters and confidentiality agreements with Company personnel and relevant parties,
    • Performing risk analyses on business processes,
    • Creating personal data inventories,
    • Operating information security policies and procedures,
    • Organizing and evaluating training on information security and personal data processing activities,
    • Ensuring that tools and equipment such as employee computers are used only by authorized persons to prevent unauthorized access,
    • Reviewing activities through internal or independent audits.

Technical Measures

  • Risks, threats, vulnerabilities, and any openings to the Company's information systems are identified through penetration tests, and necessary measures are taken.
    • Through information security incident management, the risks and threats that will affect the continuity of information systems are continuously monitored as a result of real-time analyses.
    • Access to information systems and user authorization are carried out through security policies via the corporate active directory with an access and authorization matrix.
    • When software changes and/or updates are to be made on the systems, trials are conducted in a test environment, any security vulnerabilities are identified, necessary measures are taken, and the final version of the change is made after these procedures.
    • Necessary measures are taken for the physical security of the Company's information systems equipment, software, and data.
    • Hardware (access control system that allows only authorized personnel to enter the system room, ensuring the physical security of edge switches that form the local area network, fire extinguishing system, air conditioning system, etc.) and software (firewalls, attack prevention systems, network access control, systems that prevent malicious software, etc.) measures are taken to ensure the security of information systems against environmental threats.
    • Risks for preventing the unlawful processing of personal data are identified, appropriate technical measures are taken against these risks, and technical controls are carried out regarding the measures taken.
    • Access procedures are established within the Company, and reporting and analysis studies are conducted regarding access to personal data.
    • The Company takes the necessary measures to ensure that deleted personal data is inaccessible and unusable for the relevant users.
    • In case of unlawful acquisition of personal data by others, the Company has made the necessary preparations to notify the data subject and the Board.
    • Security vulnerabilities are monitored, appropriate security patches are installed, and information systems are kept up-to-date.
    • Strong passwords are used in electronic environments where personal data is processed.
    • Secure logging systems are used in electronic environments where personal data is processed.
    • Data backup programs that ensure the secure storage of personal data are used.
    • Access to personal data stored in electronic or non-electronic media is restricted according to access principles.
    • Access to the Company's website is encrypted with the SHA 256 Bit RSA algorithm using a secure protocol (HTTPS).
    • A separate policy has been determined for the security of special categories of personal data.
    • Adequate security measures are taken for the physical environments where special categories of personal data are processed, stored, and/or accessed, and unauthorized entry and exit are prevented by ensuring physical security.
    • If special categories of personal data need to be transferred via e-mail, they are transferred encrypted with a corporate e-mail address or by using a KEP account. If they need to be transferred via media such as portable memory, CD, DVD, they are encrypted with cryptographic methods, and the cryptographic key is kept in a different medium.
    • If transfer via paper is required, necessary measures are taken against risks such as theft, loss, or viewing of the document by unauthorized persons, and the document is sent in a "confidential" format.

13. PROCESSING OF PERSONAL DATA COLLECTED THROUGH COOKIES

Our Company uses Cookies to improve the functioning and use of our web pages or mobile applications and strives to make the time you spend on our digital platforms more efficient and enjoyable.

In addition, we use some cookies to remember the choices you make on our websites and mobile applications, thereby providing you with an improved and personalized experience tailored to your preferences. Your personal data is processed and transferred through the cookies on our digital platforms.

In accordance with Article 12 of the DPL, necessary technical and administrative measures are taken by our Company to ensure the security of personal data collected through cookies.

For detailed information, you can access our cookie policy using the link https://temaservis.com.

14. TRAINING AND SUPERVISION OF EMPLOYEES AND DATA PROCESSORS ON DPL

The company provides its employees with the necessary awareness training to fulfill the obligations stipulated by the legislation within the scope of personal data protection law and to protect the rights of the data subject. It is ensured that new employees joining the company also receive this training. Professional support is received in both internal and external training and audit processes.

The company also carefully selects its data processors, presents the fulfillment of their DPL compliance as a condition of business processes, and periodically questions the DPL compliance status of the data processors. In this context, the company signs the necessary contracts and commitment letters with the data processors, follows their implementation, and terminates its contractual relationship with data processors who do not meet the conditions.

15. IDENTITY OF THE DATA CONTROLLER

Information regarding the identity of the data controller for any personal data processing activity falling within the scope of this policy is provided below.

Identity of the Data Controller

Company Name/Title : Tema İş Makinaları Servis Ltd. Şti.

Tax No : Ostim Tax Office, 8370030462

Address : Ahievran Cad. No:99 Ostim, Yenimahalle/ANKARA

Phone : +90 (530) 392 32 05

E-Mail : tema@temaservis.com

Website : https://temaservis.com

16. ENTRY INTO FORCE

This Policy, issued by the Company, has entered into force on the date of its publication on the website and has been made public. In case of a conflict between the current legislation, especially the Law, and the regulations set forth in this Policy, the provisions of the legislation shall apply.

The Company reserves the right to make changes to the Policy in parallel with legal regulations. You can access the current version of the Policy at the internet address (https://temaservis.com).

Last Update Date: 

```

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.