Policy on the Protection, Processing, Retention and Destruction of Personal Data

POLICY ON THE PROTECTION, PROCESSING, RETENTION AND DESTRUCTION OF PERSONAL DATA

I. INTRODUCTION

1.1. Purpose of the Policy

Pursuant to Article 20 of the Constitution titled “Privacy of Private Life”, Law No. 6698 on the Protection of Personal Data (“Law”), and the provisions of the regulations and communiqués currently in force, the purpose of this Policy is to establish the principles governing the processing of personal data obtained by Sabancı Üniversitesi Inovent Fikri Mülkiyet Hakları Yönetim Ticaret ve Yatırım A.Ş. (“Company”), the protection of the fundamental rights and freedoms of data subjects (visitor, applicant, entrepreneur, business partner, employee, job applicant, former employee, employee of a third-party company, etc.), particularly the privacy of private life, the lawful conduct of data processing activities by the data controller processing personal data, and the protection, processing, retention and, where necessary, destruction of the personal data obtained.

1.2. Scope of the Policy

Considering that any operation performed by the Company, acting in its capacity as data controller, on any information relating to an identified or identifiable natural person, including obtaining, recording, storing, retaining, altering, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the use of such data, by fully or partially automated means or by non-automated means provided that such processing forms part of a data recording system, constitutes a data processing activity, the scope of this Policy is to establish the procedures and principles applicable to the data processing activities carried out by the Company.

1.3. Application of the Policy and Relevant Legislation

This Policy has been prepared in accordance with the applicable legislation, particularly Law No. 6098 Turkish Code of Obligations, Law No. 6102 Turkish Commercial Code, Law No. 6698 on the Protection of Personal Data, Law No. 6563 on the Regulation of Electronic Commerce, the Regulation on the Data Controllers Registry No. 30286, the Regulation on the Deletion, Destruction or Anonymization of Personal Data No. 30224, the Regulation on the Processing of Personal Health Data and Protection of Privacy, as well as the rules set forth in the regulations, communiqués, decisions and guidelines published by the Board.

If, following the publication date of the Policy, the Law or any other relevant legislation is amended and the Policy becomes inconsistent with such amendments, the amended provisions and rules shall apply. All communiqués, decisions and guidelines published by the Board are monitored by the Company, and the rules set forth under the Policy are kept up to date.

1.4. Entry into Force of the Policy

The Policy has been published on the Company’s website at www.inovent.com.tr and entered into force on the date of its publication.

II. MATTERS RELATING TO THE PROTECTION OF PERSONAL DATA

2.1. Ensuring the Security of Personal Data

Pursuant to Article 12 of Law No. 6698, the data controller is obliged to take all necessary administrative and technical measures to ensure an appropriate level of security for the purposes of;

  • Preventing the unlawful processing of personal data,
  • Preventing unlawful access to personal data,
  • Ensuring the safeguarding of personal data.

Accordingly, the Company implements security measures in order to prevent the unlawful processing, transfer and disclosure of personal data to third parties, unauthorized access, and security vulnerabilities arising through other means. Explanations regarding the administrative and technical measures adopted are set out under VI. ADMINISTRATIVE AND TECHNICAL MEASURES TAKEN FOR THE PROTECTION OF PERSONAL DATA.

2.2. Protection of Special Categories of Personal Data

Data which, due to their nature, are considered sensitive and which, if obtained by third parties, may cause data subjects to suffer harm or discrimination are classified as special categories of personal data under the Law. Special categories of personal data consist of data relating to a person’s race, ethnic origin, political opinion, philosophical belief, religion, religious sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. As a rule, the processing of special categories of personal data is prohibited and may only be carried out in the limited circumstances permitted by law.

The Company takes all necessary measures for the protection of special categories of personal data, and as a principle, aims to avoid the collection and processing of such data to the greatest extent possible.

III. MATTERS RELATING TO THE PROCESSING OF PERSONAL DATA

3.1. Processing of Personal Data in Accordance with the Principles Prescribed by Legislation

Pursuant to Article 4 of the Law, the principles applicable to the processing of your personal data are as follows:

  • Processing lawfully and fairly,
  • Being accurate and, where necessary, kept up to date,
  • Processing for specified, explicit and legitimate purposes,
  • Being relevant, limited and proportionate to the purposes for which they are processed,
  • Being retained for the period prescribed by the relevant legislation or required for the purpose for which they are processed.

3.2. Conditions for Processing Personal Data

Personal data obtained by the Company may not be processed without the explicit consent of the data subject, except in the circumstances expressly provided for under the Law.

3.3. Exceptions to the Requirement to Obtain Explicit Consent

a) Expressly provided for by law

One of the conditions for processing personal data is that such processing is expressly provided for by law. Provisions contained in laws permitting the processing of personal data may constitute a legal basis for processing. In such cases, the explicit consent of the data subject is not required.

b) Physical impossibility

Where it is necessary to protect the life or physical integrity of the person who is unable to express consent due to physical impossibility or whose consent is not legally valid, or of another person, the personal data of the relevant data subject may be processed without obtaining explicit consent.

c) Being directly related to the establishment or performance of a contract

Where the processing of personal data is necessary for the establishment or performance of a contract to which the data subject is a party, such personal data may be processed without obtaining explicit consent.

d) Fulfillment of the Company’s legal obligations

Personal data may be processed without obtaining explicit consent where such processing is necessary for the Company, acting in its capacity as data controller, to fulfill its legal obligations.

e) Having been made public by the data subject

Personal data that have been made public by the data subject, in other words, personal data that have in any manner been disclosed to the public, may be processed without obtaining explicit consent. Even in such cases, publicly disclosed personal data may not be used for purposes other than those for which they were made public.

f) Being necessary for the establishment, exercise or protection of a right

Personal data may be processed without the explicit consent of the data subject where such processing is necessary for the establishment, exercise or protection of a right.

g) Being necessary for the legitimate interests of the data controller, provided that the fundamental rights and freedoms of the data subject are not prejudiced

Where the processing of personal data is necessary for the data controller and such processing does not prejudice the fundamental rights and freedoms of the data subject, personal data may be processed without obtaining explicit consent.

The legitimate interest of the data controller refers to the interest and benefit to be obtained as a result of the relevant processing activity. The benefit to be obtained by the data controller must relate to a legitimate, sufficiently effective, specific and currently existing interest capable of being balanced against the fundamental rights and freedoms of the data subject. The relevant processing activity must be connected with the data controller’s current activities and be capable of providing a benefit to the data controller in the near future.

3.4. Processing of Special Categories of Personal Data

The processing of special categories of personal data is subject to Article 6 of the Law. Personal data relating to race, ethnic origin, political opinion, philosophical belief, religion, religious sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data, constitute special categories of personal data. The categories of data falling within this scope are exhaustive and may not be expanded by interpretation. By their nature, special categories of personal data are data which, if disclosed, may result in the data subject being subjected to discrimination or suffering harm. Therefore, they must be afforded a significantly higher level of protection than other personal data.

Special categories of personal data may be processed where the data subject has provided explicit consent; where processing is expressly provided for by law; where processing is necessary for the protection of the life or physical integrity of the person who is unable to express consent due to physical impossibility or whose consent is not legally valid, or of another person; where processing relates to personal data made public by the data subject and is consistent with the data subject’s intention in making such data public; where processing is necessary for the establishment, exercise or protection of a right; where processing by persons subject to an obligation of confidentiality or by authorized institutions and organizations is necessary for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, or the planning, management and financing of healthcare services; where processing is necessary for the fulfillment of legal obligations in the fields of employment, occupational health and safety, social security, social services and social assistance; or where processing is carried out by foundations, associations and other non-profit organizations or formations established for political, philosophical, religious or trade union purposes, provided that such processing complies with the legislation and purposes to which they are subject, is limited to their fields of activity, does not involve disclosure to third parties, and relates to their current or former members and constituents or to persons who are in regular contact with such organizations and formations. In addition, the processing of special categories of personal data is subject to the implementation of the adequate measures determined by the Personal Data Protection Board.

3.5. Clarification and Information of the Data Subject

At the time personal data are obtained, the Company, acting in its capacity as data controller, or persons authorized by the Company, provide information to data subjects. The procedures and principles regarding such information are set out in the relevant Clarification Texts published by the Company in relation to the processing of personal data, and such information generally includes the following:

    • The identity of the data controller and, if any, its representative,
    • The purposes for which personal data will be processed,
    • The persons to whom personal data may be transferred and the purposes of such transfer,
    • The method and legal basis of collecting personal data,
    • The rights of the data subject as set out under Article 11 of the Law.

a) Purposes of processing personal data

Personal data are processed for specified, explicit and legitimate purposes, based on the principle of informing data subjects. The purposes pursued by the Company in processing personal data obtained from data subjects are set out, for each relevant data subject category, in the relevant sections of the Clarification Texts available on our website.

b) Persons to whom personal data are transferred and purposes of transfer

Within the scope of the data controller’s obligation to provide clarification, the persons to whom personal data are transferred and the purposes of such transfer must be clearly specified. Personal data may not be transferred to third parties without the explicit consent of the data subject. The recipient groups to whom personal data are transferred by the Company and the purposes of such transfers are set out under IV. TRANSFER OF PERSONAL DATA.

c) Method and legal basis of collecting personal data

In accordance with Articles 5 and 6 of the Law, the data controller must clearly specify the condition for processing personal data on which the relevant processing activity is based. The method and means used to collect personal data are determined by the data controller. The conditions for processing personal data, in other words the circumstances establishing lawfulness, are exhaustively enumerated under the Law (Articles 5-6) and may not be expanded.

The Company, acting as data controller, first assesses whether the purpose of the personal data processing activity can be based on one of the processing conditions other than explicit consent. Where such purpose does not satisfy at least one of the conditions stipulated under the Law other than explicit consent, the explicit consent of the data subject is obtained in order for the relevant data processing activity to continue.

IV. TRANSFER OF PERSONAL DATA

4.1. Domestic Transfer

Personal data may not be transferred without the explicit consent of the data subject. However, where one of the conditions specified in the second paragraph of Article 5 or, provided that adequate measures are taken, in the third paragraph of Article 6 is satisfied, personal data may be transferred without obtaining the explicit consent of the data subject.

Information regarding the recipient groups to whom your personal data processed by the Company are transferred is set out in ANNEX 3 – Third Parties to Whom Personal Data Are Transferred and Purposes of Transfer of this Policy.

4.2. Transfer Abroad

Personal data may be transferred abroad where an adequacy decision as specified under Articles 8 and 9 is in place, where one of the appropriate safeguards is provided, or in other circumstances permitted thereunder.

V. CATEGORIZATION OF PERSONAL DATA PROCESSED BY THE COMPANY AND PURPOSES OF PROCESSING

The categories of data obtained by the Company from data subjects and the purposes pursued in processing such personal data are set out, for each relevant data subject category, in the relevant sections of the Clarification Texts available on our website.

VI. ADMINISTRATIVE AND TECHNICAL MEASURES TAKEN FOR THE PROTECTION OF PERSONAL DATA

The Company takes administrative and technical measures to ensure the secure retention of personal data and to prevent the unlawful processing of and unauthorized access to personal data.

Pursuant to subparagraphs (b) and (d) of paragraph 2 of Article 4 of the Law, personal data must, where necessary, be accurate and kept up to date and must be retained for the period prescribed by the relevant legislation or required for the purposes for which they are processed. Within this scope, the data processed are processed in accordance with the principles and rules applicable to data processing activities and are retained for the period necessary for the purposes for which they are processed. Information regarding the retention and destruction procedures and retention periods applicable to personal data processed by the Company is set out under VIII. RETENTION AND DESTRUCTION OF PERSONAL DATA and ANNEX–4: Personal Data Retention Periods of this Policy.

For the purposes of ensuring personal data security, the Company identifies all personal data processed by it and assesses the likelihood of risks arising in relation to the protection of such data. In identifying such risks, consideration is given to whether the personal data constitute special categories of personal data (1), the level of confidentiality required due to the nature of the data (2), and the nature and extent of the potential harm that may arise for the data subject in the event of a security breach (3). Following the identification and prioritization of such risks, control and solution alternatives aimed at mitigating or eliminating the relevant risks are evaluated in light of the principles of cost, practicability and effectiveness, and the necessary technical and administrative measures are planned and implemented within the framework of the Law.

Within this scope, the following administrative and technical measures are taken by the Company for the protection of personal data:

An authorization matrix has been established for employees.

  • User account management and authorization control systems are implemented and regularly monitored.
  • Access logs are regularly maintained.
  • Network security and application security are ensured.
  • Encryption is applied.
  • Penetration tests are conducted.
  • Personal data are backed up, and the security of the backed-up personal data is also ensured.
  • The security of personal data stored in cloud environments is ensured.
  • Firewalls are used.
  • Up-to-date anti-virus systems are used.
  • Log records are maintained in a manner that prevents user intervention.
  • Intrusion detection and prevention systems are used.
  • Key management measures are implemented.
  • Necessary security measures are taken with respect to entry to and exit from physical environments containing personal data.
  • The security of environments containing personal data is ensured.
  • Personal data are deleted, destroyed or anonymized in accordance with the applicable legislation.
  • Cybersecurity measures have been adopted, and their implementation is continuously monitored.
  • Special categories of personal data transferred via e-mail are always sent in encrypted form using a registered electronic mail (KEP) account or a corporate e-mail account.
  • Security measures are taken within the scope of the procurement, development and maintenance of information technology systems.
  • Disciplinary regulations containing data security provisions are in place for employees.
  • Executed agreements contain data security provisions.
  • Confidentiality undertakings are executed.
  • The relevant authorizations of employees whose duties have changed or whose employment has terminated are revoked.
  • Personal data security policies and procedures have been established.
  • Personal data security incidents and issues are promptly reported.
  • Personal data are minimized to the greatest extent possible.
  • Periodic and/or random internal audits are conducted and/or commissioned.

VII. PERSONAL DATA PROCESSING ACTIVITIES CONDUCTED AT BUILDING ENTRANCES AND WITHIN THE BUILDING

Camera Surveillance Activities at Building Entrances and Within the Building

Camera surveillance activities are carried out for the purposes of ensuring security at the entrance, surrounding areas and interior of the building, and protecting the interests relating to the security of the Company and other persons. Camera surveillance activities are conducted in compliance with the Law and within the scope of the personal data processing conditions set forth both under the Law and this Policy.

VIII. RETENTION AND DESTRUCTION OF PERSONAL DATA

8.1. Retention and Destruction of Personal Data

Your personal data retained by the Company are stored for the period during which the relevant data processing activity is necessary; where an obligation to delete, destroy or anonymize personal data arises, such personal data are deleted, destroyed or anonymized within the first periodic destruction period following the date on which such obligation arises. The deletion, destruction or anonymization of your personal data is carried out in accordance with the general principles set forth under Article 4 of the Law and the technical and administrative measures specified under Article 12 of the Law.

The interval for periodic destruction is limited to a maximum of 1 year. All operations relating to the deletion, destruction or anonymization of personal data carried out by the Company are recorded and retained for at least 3 years in accordance with the applicable legal obligations. The retention periods applicable to personal data processed by the Company are set out in ANNEX–4.

The personal data specialist appointed by the Company in relation to the retention and destruction of data is responsible for the implementation and supervision of the personal data retention and destruction policy.

8.2. Obligation to Delete, Destroy and Anonymize Personal Data

Personal data processed by the Company are deleted, destroyed or anonymized ex officio or upon the request of the relevant data subject where the reasons requiring their processing cease to exist, in accordance with Article 7 of the Law and the provisions of the “Regulation on the Deletion, Destruction or Anonymization of Personal Data” published by the Personal Data Protection Board in the Official Gazette dated 28 October 2017 and numbered 30224.

  • Deletion of personal data

Deletion of personal data means rendering personal data inaccessible and unusable in any manner whatsoever for the relevant employees.

All necessary technical and administrative measures are taken to ensure that deleted personal data remain inaccessible and cannot be reused.

  • Destruction of personal data

Destruction of personal data means rendering personal data inaccessible, irretrievable and unusable by anyone in any manner whatsoever.

All necessary technical and administrative measures are taken to ensure that personal data cannot be accessed, recovered or reused by anyone in any manner whatsoever.

  • Anonymization of personal data

Anonymization of personal data means rendering personal data incapable of being associated with an identified or identifiable natural person in any manner whatsoever, even when matched with other data.

All necessary technical and administrative measures are taken for the anonymization of your personal data, and such data are anonymized by applying methods in accordance with our personal data retention and destruction policy.

8.3. Personal Data Recording Environments

A personal data recording environment refers to any environment in which personal data processed by fully or partially automated means, or by non-automated means provided that such processing forms part of a data recording system, are stored.

Personal data relating to data subjects are securely stored by the Company, in accordance primarily with the provisions of the Law and other applicable legislation and within the framework of international data security principles, in the following data recording environments:

a) Technical recording environments: Computer environments, central servers, removable storage media (USB drives, memory cards, etc.), information security devices and software.

b) Non-technical data recording environments: Paper documents, manual data recording systems, written, printed and visual media.

8.4. Reasons Requiring the Destruction of Personal Data

Personal data relating to data subjects are destroyed by the Company for purposes and reasons including, but not limited to, the following;

The general principles set forth under Article 4 of the Law,

  • Amendment of the relevant legislative provisions forming the basis for the processing,
  • Withdrawal of explicit consent by the data subject where the processing of personal data is based solely on explicit consent,
  • Submission by the data subject of a request for the destruction of personal data,
  • Expiry of legal obligations relating to the retention of personal data,
  • Cessation of the purpose requiring the processing or retention of personal data,
  • Expiry of the maximum retention period applicable to personal data and the absence of any justified reason requiring continued retention.

8.5. Techniques for the Deletion, Destruction and Anonymization of Personal Data

The techniques applied by the Company for the deletion, destruction or anonymization of processed personal data are set out below, and the technique to be applied may vary depending on the nature of the personal data concerned.

During the deletion, destruction or anonymization of personal data, necessary administrative and technical measures are taken, including informing employees regarding information security and destruction processes, selecting the most appropriate method according to the nature of the data recording environment in which personal data are stored, conducting regular and periodic maintenance and monitoring activities relating to data security, using the most up-to-date destruction systems required from a technological and technical perspective, issuing automatic deletion commands, and revoking authorization to access, reuse or restore deleted data.

For this purpose, the following methods are applied: (1) first identifying the personal data subject to deletion, destruction or anonymization, (2) identifying the relevant employees for each category of personal data by using an access authorization and control matrix or a similar system, (3) identifying the relevant employees’ access, restoration and reuse authorizations and methods, and (4) disabling and eliminating the relevant employees’ access, restoration and reuse authorizations and methods in relation to the relevant personal data.

Within this scope, depending on the requirements of the circumstances;

  • For the deletion of personal data: methods such as (i) issuing deletion commands in cloud-based or application-based solutions, (ii) redacting, cutting out or otherwise rendering invisible data contained in paper records, and (iii) deleting data stored on portable media by using appropriate software;
  • For the destruction of personal data: methods such as (i) de-magnetizing data by processing the relevant media through specialized devices, (ii) melting, burning or pulverizing optical and magnetic media, (iii) overwriting magnetic media and rewritable optical media by using specialized systems, and (iv) other destruction methods applied to paper-based or electronic media;
  • For the anonymization of personal data: methods such as (i) removing variables from data that may be associated with the data subject, (ii) removing data records containing unique characteristics from the data set, and (iii) applying generalization techniques by converting the relevant personal data from a specific value into a more general value.

IX. RIGHTS OF THE PERSONAL DATA SUBJECT AND EXERCISE OF RIGHTS

9.1. Rights of the Personal Data Subject

Pursuant to Law No. 6698, as a data subject, you have the right to;

  • Learn whether your personal data are being processed,
  • Request information if your personal data have been processed,
  • Learn the purpose of the processing of your personal data and whether such data are used in accordance with such purpose,
  • Know the third parties to whom your personal data are transferred domestically or abroad,
  • Request the correction of your personal data where such data have been processed incompletely or inaccurately,
  • Request the deletion or destruction of your personal data within the framework of the conditions set forth under Article 7,
  • Request that the correction of incomplete or inaccurate processing and the deletion or destruction of personal data be notified to third parties to whom the personal data have been transferred,
  • Object to the occurrence of a result against you arising from the analysis of your processed personal data exclusively through automated systems,
  • Claim compensation for damages suffered as a result of the unlawful processing of your personal data.

9.2. Exercise of the Rights of the Personal Data Subject and Our Company’s Response to Applications

If, as personal data subjects, you submit your requests regarding your rights through the Data Subject Application Form published at www.inovent.com.tr or by using the methods specified in the Communiqué on the Procedures and Principles of Application to the Data Controller, the Company shall conclude your request free of charge, depending on the nature of the request, as soon as possible and in any event within thirty days at the latest. This period may not exceed 30 days from the date on which your application is served upon the Company. Where additional information is requested due to deficiencies or unclear statements in your application, the response period shall be suspended until the relevant additional information and documents are served upon us. If the processing of your application requires any cost, a fee may be charged in accordance with the tariff determined by the Personal Data Protection Board.

Data Controller Sabancı Üniversitesi Inovent Fikri Mülkiyet Hakları Yönetim Ticaret ve Yatırım A.Ş. (Tax Identification No: 4650296747)
Address Sabancı Üniversitesi Yerleşkesi, Orta Mahalle, Üniversite Caddesi, Rektörlük Binası No: 27 P/1, 34956 Tuzla / İstanbul
Contact info@inovent.com.tr

ANNEX – 1: Definitions

Explicit Consent: Consent relating to a specific matter, based on being informed and expressed with free will,

Anonymization: Rendering personal data incapable of being associated with an identified or identifiable natural person in any manner whatsoever, even by matching such data with other data,

Recipient Group: The category of natural or legal persons to whom personal data are transferred by the data controller,

Data Subject: The natural person whose personal data are processed,

Destruction: The deletion, destruction or anonymization of personal data,

Redaction: Operations such as crossing out, masking, obscuring or blurring all or part of personal data in a manner that prevents such data from being associated with an identified or identifiable natural person,

Recording Environment: Any environment in which personal data processed by fully or partially automated means, or by non-automated means provided that such processing forms part of a data recording system, are stored,

Personal Data: Any information relating to an identified or identifiable natural person,

Processing of Personal Data: Any operation performed on personal data, such as obtaining, recording, storing, retaining, altering, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, by fully or partially automated means or by non-automated means provided that such processing forms part of a data recording system,

Law / Law on the Protection of Personal Data (“KVKK”): Law No. 6698 on the Protection of Personal Data, which was published in the Official Gazette and entered into force on 7 April 2016,

Board: The Personal Data Protection Board,

Authority: The Personal Data Protection Authority,

Data Processor: The natural or legal person who processes Personal Data on behalf of the data controller, based on the authority granted by the data controller,

Data Recording System: The recording system in which personal data are processed by being structured according to specific criteria,

Data Controller: The natural or legal person who determines the purposes and means of processing personal data and who is responsible for the establishment and management of the data recording system.

ANNEX – 2: Personal Data Subjects (Data Subjects)

Data Subject Categories Description
Employee Refers to persons employed by the Company.
Job Applicant Refers to natural persons who apply for employment with the Company by submitting a resume or through other methods.
Business Partners Refers to natural persons and employees of legal entities with whom the Company conducts business, transactions and cooperation for the purpose of carrying out the Company’s activities.
Applicant Refers to natural persons who apply to programs organized by the Company.
Entrepreneur Refers to natural persons who apply to programs organized by the Company and whose applications are accepted by the Company, thereby participating in the relevant program.
Subscriber Refers to natural persons who register via their e-mail addresses in order to receive e-newsletters, announcements and informational content published by the Company.
Supplier Refers to natural persons and employees of legal entities from whom the Company procures services.
Visitor Refers to third parties who visit the Company and the Company’s website.
Other Relevant Third Parties Refers to natural persons whose personal data are processed by the Company and who fall outside the data subject categories described above.

ANNEX – 3: Third Parties to Whom Personal Data Are Transferred and Purposes of Transfer

Recipient Person/Unit Scope Purpose of Transfer
Legal Advisors / Financial Advisors Parties from whom the Company obtains services for support on legal and financial matters Transfer of personal data limited to the purpose of obtaining services within the scope of the establishment, exercise and protection of the Company’s legal and financial rights.
Business Partners Local and foreign parties with whom business partnerships are established within the scope of the activities carried out by the Company Transfer of personal data limited to the purposes of ensuring the performance of activities carried out with business partners and conducting the Company’s activities.
Suppliers Parties from whom services are procured for the purpose of maintaining the Company’s activities Transfer of personal data limited to the purpose of obtaining services from suppliers providing services such as website hosting, operation of technical infrastructure, analysis of visitor usage statistics, e-mail infrastructure and archiving.
Authorized Public Institutions and Organizations Legal relationships between the Company and public institutions and organizations authorized by law Transfer of information and documents requested from the Company by the relevant public institutions and organizations, limited to the purpose for which such information and documents are requested.

ANNEX – 4: Personal Data Retention Periods

Source of Personal Data Period Legal Basis
Personal Data Processed under Contracts and Contractual Relationships 10 Years from the Termination of the Contract Law No. 6102, Law No. 6098, Law No. 6563 and Law No. 213
Special Categories of Personal Data 10 Years from the Termination of the Contract Law No. 6102, Law No. 6098, Law No. 6563
Personal Data Relating to Tax Records 5 Years Tax Procedure Law No. 213
All Records Relating to Human Resources Processes, Including Personnel Files, within the Scope of the Labor Law 10 Years from the Termination of the Employment Relationship Labor Law No. 4857 and Relevant Legislation, Turkish Code of Obligations No. 6098
Data Collected within the Scope of Occupational Health and Safety Legislation 15 Years from the Termination of the Employment Relationship Labor Law No. 4857 and Relevant Legislation, Occupational Health and Safety Law No. 6331
Data Relating to Candidate Applications Where the Job Application / Program Application Is Not Accepted 2 Years Industry Practices Apply.
Commercial Electronic Message Consent Records 1 Year from the Date of Withdrawal of Consent Law No. 6563, Regulation on Commercial Communication and Commercial Electronic Messages
CCTV Camera Records 3 Months Industry Practices Apply.
Cookie, Traffic Information and Access Log Records Relating to Online Visitors 6 Months – Maximum 2 Years Law No. 5651 on Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications