K.V.K.K
“NAKOSAN NAKIŞ
KONFEKSİYON
TEKSTİL SAN. VE TİC. A.Ş.”
PERSONAL DATA
PROCESSING
AND PROTECTION POLICY
English Translation
1.1 Introduction
1.2 Scope
1.3 Implementation of the Policy and the
KVKK Legislation
1.4 Entry into Force of the Policy
2.1 Ensuring the Security of Personal
Data
2.2 Protection of Special Categories of
Personal Data
2.3 Raising and Auditing the Awareness
of Business Units Regarding the Protection and Processing of Personal Data
3.1 Processing Personal Data in
Accordance with the Principles Prescribed by Legislation
3.2 Conditions for Processing Personal
Data
3.3 Processing Special Categories of
Personal Data
3.4 Informing the Personal Data Subject
3.5 Processing by XXX of Data Processed
by XXX Companies
3.6 Transfer of Personal Data
6.1 Rights of the Data Subject
7.1 Personal Data Processing Activities
Conducted at Building and Facility Entrances and Within Buildings and
Facilities, and Website Visitors
7.2 Camera Surveillance Activities
Conducted at the Entrances and Inside the Buildings and Facilities of “NAKOSAN
NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.”
7.3 Monitoring Visitor Entries and Exits
at the Entrances and Inside the Buildings and Facilities of “NAKOSAN NAKIŞ
KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.”
Since the protection of personal data is a
fundamental human right, it is among the highest priorities of “NAKOSAN NAKIŞ
KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.” (the “Company”). In order to safeguard
the right to the protection of personal data, the Company makes every effort to
comply with all legislation currently in force in this field. This “NAKOSAN
NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş. Personal Data Protection and
Processing Policy” (the “Policy”) explains the principles adopted in conducting
the personal data processing activities carried out by our Company and the
fundamental principles adopted to ensure that our Company’s data processing
activities comply with the provisions of the Personal Data Protection Law No.
6698 (the “Law”), thereby ensuring the necessary transparency by informing the
relevant persons. With full awareness of our responsibilities in this regard,
your personal data is processed and protected within the scope of this Policy.
The “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN.
VE TİC. A.Ş.” (the “COMPANY”) Personal Data Processing and Protection Policy
(the “Policy”) has been prepared with the aim of regulating the processing of
personal data within the framework of legislation concerning personal data and
protecting the fundamental rights and freedoms stipulated in the Constitution,
particularly the right to privacy.
In preparing the “Policy,” the primary
principle was to identify, within the organizational structure of the
“COMPANY,” which data the operating units collect, why they collect such data,
and why they need to transfer such data to third parties, and thereby to
understand the COMPANY’s personal data processing procedures. While
incorporating the requirements of the relevant legislation into the “Policy,”
it was adopted as a principle, within the sensitivity required for the
protection of personal data, to explain in plain and understandable language
which data the “COMPANY” obtains, why it obtains such data, and why it
processes such data. It is also intended to take the necessary administrative
and technical measures to protect data confidentiality both within and outside
the “COMPANY” organization and to inform and enlighten the individuals whose
data is processed.
The “Policy” covers all natural persons
whose data is processed by the “COMPANY.”
Within the scope of this “Policy,” an
effort has been made to provide tailored information concerning the data
processed within the framework of the operations and activities carried out in
the “COMPANY” organization, the categorization of such data, data recipient
groups, the legal grounds and methods of data collection, the groups of third
parties to whom the data is transferred, data processing periods, and data
deletion periods. However, if the “COMPANY” processes or will process data
outside its current processing activities, such processing and the
corresponding information may be carried out through a separate privacy notice,
provided that the fundamental principles and rules specified in this Policy are
observed. In such a case, the privacy notice provided shall constitute an
integral part of this “Policy,” and it may not be claimed that it is not
included in this “Policy.” Indeed, under Article 5 of the Communiqué on the
Procedures and Principles to Be Followed in Fulfillment of the Obligation to
Inform, the information may be provided verbally, in writing, by audio
recording, through a call center, or by using physical or electronic media.
With regard to the processing and
protection of personal data, the relevant statutory regulations currently in
force shall primarily apply. In the event of any inconsistency between the
legislation in force and the Policy, our Company acknowledges that the
applicable legislation shall prevail. The Policy concretizes and regulates the
rules established by the relevant legislation within the scope of the Company’s
practices.
The effective date of this Policy is
01.01.2020. The version issued by “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE
TİC. A.Ş.,” which entered into force on xxx and was updated on yyy, has been
renewed as of the effective date of this Policy.
This Policy is published on the website of
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.” at
https://nakosantextile.com/.
In accordance with Article 12 of the Law,
our Company takes the necessary measures according to the nature of the data to
be protected in order to prevent the unlawful disclosure, access, transfer, or
other security deficiencies relating to personal data. Within this scope, our
Company takes administrative measures aimed at ensuring the required level of
security and conducts or commissions audits in accordance with the guidelines
published by the Personal Data Protection Board (the “Board”).
The Law attaches particular importance to
certain personal data due to the risk that unlawful processing may cause
victimization or discrimination. Such data consists of data relating to race,
ethnic origin, political opinions, philosophical beliefs, religion, religious
sect or other beliefs, appearance and clothing, membership of associations,
foundations or trade unions, health, sexual life, criminal convictions and
security measures, as well as biometric and genetic data.
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE
TİC. A.Ş.” acts with particular care in protecting special categories of
personal data designated as “special categories” under the Law and processed
lawfully. Within this scope, the technical and administrative measures taken by
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.” for the protection of
personal data are applied diligently with respect to special categories of
personal data, and the necessary audits are carried out within “NAKOSAN NAKIŞ
KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.”
Note: Detailed information concerning the
technical and administrative measures taken in the processing of personal data
is provided in Section “8” of this Policy.
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE
TİC. A.Ş.” organizes regular training sessions to raise awareness regarding the
prevention of unlawful processing of personal data, prevention of unlawful
access to personal data, and secure retention of personal data.
The necessary systems are established to
ensure awareness among the employees of “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN.
VE TİC. A.Ş.” regarding the protection of personal data, and consultants are
engaged where necessary. Accordingly, through its employees, our Company
participates in relevant training sessions, seminars, and information sessions,
particularly those prepared by the Personal Data Protection Authority, and
renews its training in parallel with updates to the relevant legislation.
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE
TİC. A.Ş.” acts in accordance with the principles introduced by legal
regulations and the general principles of good faith and fairness when
processing personal data. Within this framework, personal data is processed
only to the extent required by and limited to our Company’s business
activities.
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE
TİC. A.Ş.” takes the necessary measures to ensure that personal data remains
accurate and up to date throughout the processing period and establishes the
necessary mechanisms at defined intervals to ensure the accuracy and currency
of personal data.
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE
TİC. A.Ş.” clearly sets out the purposes for processing personal data and
processes such data for purposes connected with its business activities.
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE
TİC. A.Ş.” collects personal data only to the nature and extent required by its
business activities and processes it solely for the specified purposes.
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE
TİC. A.Ş.” retains personal data for the period necessary for the purpose for
which it is processed and for the minimum period prescribed by the legislation
governing the relevant activity. Within this scope, our Company first
determines whether the relevant legislation prescribes a retention period for
personal data and, where such a period is prescribed, complies with that
period. If no statutory period exists, personal data is retained for the period
required for the purpose for which it is processed. At the end of the specified
retention periods, personal data is disposed of in accordance with periodic
disposal periods or a data subject’s application and by the specified disposal
methods (deletion and/or destruction and/or anonymization).
Except where the personal data subject has
provided explicit consent, the processing of personal data may be based on only
one of the conditions set out below, or multiple conditions may constitute the
basis of the same personal data processing activity. If the processed data
constitutes a special category of personal data, the conditions set out under
Section 3.3 of this Policy (“Processing Special Categories of Personal Data”)
shall apply.
One of the conditions for processing
personal data is the explicit consent of the data subject. The personal data
subject’s explicit consent must relate to a specific matter, be based on
information, and be freely given.
Where any of the personal data processing
conditions set out below exists, personal data may be processed without
obtaining the data subject’s explicit consent.
This processing condition shall be deemed
to exist where the processing of the data subject’s personal data is expressly
prescribed by law; in other words, where the relevant law contains an explicit
provision concerning the processing of personal data.
The data subject’s personal data may be
processed where processing is mandatory to protect the life or physical
integrity of the person who is unable to express consent due to actual
impossibility, or whose consent cannot be deemed legally valid, or of another
person.
This condition shall be deemed fulfilled
where processing personal data is necessary, provided that it is directly
related to the establishment or performance of a contract to which the data
subject is a party.
The data subject’s personal data may be
processed where processing is mandatory for our Company to fulfill its legal
obligations.
Where the data subject has made personal
data public, the relevant personal data may be processed only for the purpose
for which it was made public.
The data subject’s personal data may be
processed where data processing is mandatory for the establishment, exercise,
or protection of a right.
The data subject’s personal data may be
processed where processing is mandatory for the legitimate interests of our
Company, provided that such processing does not prejudice the fundamental
rights and freedoms of the personal data subject.
Special categories of personal data are
processed by our Company in accordance with the principles specified in this
Policy, by taking all necessary administrative and technical measures,
including the methods to be determined by the Board, and where the following
conditions exist:
(i) Special categories of personal data
other than data relating to health and sexual life may be processed without
seeking the explicit consent of the data subject where such processing is
expressly prescribed by law; in other words, where the law governing the
relevant activity contains an explicit provision concerning the processing of
personal data. Otherwise, the data subject’s explicit consent shall be obtained
in order to process such special categories of personal data.
(ii) Special categories of personal data
relating to health and sexual life may be processed without explicit consent by
persons subject to a confidentiality obligation or by authorized institutions
and organizations for the purposes of protecting public health, preventive
medicine, medical diagnosis, treatment and care services, and the planning and
management of healthcare services and their financing. Otherwise, the data
subject’s explicit consent shall be obtained in order to process such special
categories of personal data.
In accordance with Article 10 of the Law
and secondary legislation, “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC.
A.Ş.” informs personal data subjects. Within this scope, “NAKOSAN NAKIŞ
KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.” informs the relevant persons of the
identity of the data controller processing the personal data, the purposes for
which it is processed, the persons with whom and purposes for which it is
shared, the methods and legal grounds for collecting it, and the rights of data
subjects in relation to the processing of their personal data.
For lawful personal data processing
purposes and by taking the necessary security measures, our Company may
transfer the personal data and special categories of personal data of the
personal data subject to third parties (third-party companies, public and
private authorities, and third-party natural persons). In this regard, our
Company acts in accordance with the provisions set out in Article 8 of the Law.
Detailed information on this matter is available in ANNEX X to this Policy
(“ANNEX x – Third Parties to Whom Personal Data Is Transferred and the Purposes
of Transfer”).
Even without the personal data subject’s
explicit consent, personal data may be transferred to third parties by our
Company where one or more of the conditions set out below exists, provided that
due care is exercised and all necessary security measures, including the
methods prescribed by the Board, are taken:
·
The relevant activities
concerning the transfer of personal data are expressly prescribed by law;
·
The transfer of personal data
by the Company is directly related to and necessary for the establishment or
performance of a contract;
·
The transfer of personal data
is mandatory for our Company to fulfill its legal obligations;
·
Provided that the personal data
has been made public by the data subject, it is transferred by our Company
solely for the purpose for which it was made public;
·
The transfer of personal data
by the Company is mandatory for the establishment, exercise, or protection of
the rights of the Company, the data subject, or third parties;
·
The transfer of personal data
is mandatory for the legitimate interests of the Company, provided that the
fundamental rights and freedoms of the data subject are not prejudiced;
·
The transfer is mandatory to
protect the life or physical integrity of the person who is unable to express
consent due to actual impossibility, or whose consent is not legally valid, or
of another person.
Special categories of personal data may be
transferred by our Company in accordance with the principles specified in this
Policy, by taking all necessary administrative and technical measures,
including the methods to be determined by the Board, and where the following
conditions exist:
(i) Special categories of personal data
other than data relating to health and sexual life may be processed without
seeking the explicit consent of the data subject where such processing is
expressly prescribed by law; in other words, where the relevant law contains an
explicit provision concerning the processing of personal data. Otherwise, the
data subject’s explicit consent shall be obtained.
(ii) Special categories of personal data
relating to health and sexual life may be processed without explicit consent by
persons subject to a confidentiality obligation or by authorized institutions
and organizations for the purposes of protecting public health, preventive
medicine, medical diagnosis, treatment and care services, and the planning and
management of healthcare services and their financing. Otherwise, the data
subject’s explicit consent shall be obtained.
Within our Company, personal data is
processed by informing the relevant persons in accordance with Article 10 of
the Law and secondary legislation, in line with our Company’s personal data
processing purposes, on the basis of and limited to at least one of the
personal data processing conditions specified in Articles 5 and 6 of the Law,
and in compliance with the general principles set out in the Law, particularly
the principles specified in Article 4 of the Law concerning the processing of
personal data. Within the framework of the purposes and conditions specified in
this Policy, the categories of personal data processed and detailed information
concerning such categories are available in ANNEX 3 to the Policy (“ANNEX 3 –
Personal Data Categories”).
Detailed information concerning the
purposes of processing such personal data is set out in ANNEX 1 to the Policy
(“ANNEX 1 – Purposes of Personal Data Processing”).
Our Company retains personal data for the
period necessary for the purpose for which it is processed and in accordance
with the minimum periods prescribed by the legislation governing the relevant
activity. Within this scope, our Company first determines whether the relevant
legislation prescribes a retention period for personal data and, where such a
period is prescribed, complies with that period. If no statutory period exists,
personal data is retained for the period required for the purpose for which it
is processed. At the end of the specified retention periods, personal data is
disposed of in accordance with periodic disposal periods or a data subject’s
application and by the specified disposal methods (deletion and/or destruction
and/or anonymization).
Under the KVKK, you have the right to:
1. Learn whether your Personal Data is being processed;
2. Request information if your Personal Data has been processed;
3. Learn the purpose of processing your Personal Data and whether it is
being used in accordance with that purpose;
4. Know the third parties in Türkiye or abroad to whom your Personal
Data has been transferred;
5. Request correction of your Personal Data if it has been processed
incompletely or inaccurately;
6. Request the deletion or destruction of your Personal Data within the
framework of the conditions prescribed by the KVKK legislation;
7. Request that the actions taken under items v and vi be notified to
the third parties to whom your Personal Data has been transferred;
8. Object to the occurrence of a result against you through the
analysis of processed data exclusively by automated systems;
9. Claim compensation for damage where you suffer damage as a result of
the unlawful processing of your Personal Data.
You may complete the “application form,”
which can be downloaded via https://nakosantextile.com/, in accordance with
your request/complaint and submit the form to us through
https://nakosantextile.com/, or you may complete the form physically and send
it by courier/post to “Ahmet Nazif Zorlu San. Sit. 7154 Sk. No:19 Gümüşler /
DENİZLİ.”
If you submit your request to us using one
of the methods indicated above, your request shall be evaluated within no later
than 30 days pursuant to Article 13/2 of the KVKK, and you shall be informed of
the outcome. If your request is accepted, the necessary action shall be taken
immediately by the data controller, the COMPANY.
As a rule, requests are handled free of
charge. However, if fulfilling the request requires an expense, the COMPANY may
charge a fee pursuant to Article 7 of the “Communiqué on the Procedures and
Principles of Application to the Data Controller,” which provides: “If the
application of the relevant person is answered in writing, no fee shall be
charged for up to ten pages. A processing fee of TRY 1 may be charged for each
page exceeding ten pages. If the response to the application is provided on a
recording medium such as a CD or flash drive, the fee that may be requested by
the data controller may not exceed the cost of the recording medium.”
For security purposes, “NAKOSAN NAKIŞ
KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.” carries out personal data processing
activities consisting of security-camera surveillance and the monitoring of
visitor entries and exits in the buildings and facilities of “NAKOSAN NAKIŞ
KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.”
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE
TİC. A.Ş.” conducts camera surveillance in its buildings and facilities for
security purposes in accordance with the Law on Private Security Services and
the relevant legislation. For the purpose of ensuring security in its buildings
and facilities, “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.” carries
out security-camera surveillance for the purposes prescribed by the relevant
legislation in force and in accordance with the personal data processing conditions
listed in the Law.
In accordance with Article 10 of the Law,
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.” informs personal data
subjects about camera surveillance activities through multiple methods.
Furthermore, in accordance with Article 4 of the Law, “NAKOSAN NAKIŞ
KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.” processes personal data in a manner that
is relevant, limited, and proportionate to the purpose for which it is
processed.
The purpose of the video-camera
surveillance carried out by “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC.
A.Ş.” is limited to the purposes set out in this Policy. Accordingly, the areas
monitored by security cameras, the number of cameras, and the periods during
which monitoring is conducted are implemented to the extent sufficient to
achieve the security purpose and limited to that purpose. Areas where
surveillance could result in an interference with a person’s privacy beyond the
security purposes (for example, restrooms) are not monitored.
Only a limited number of employees of
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.” have access to live
camera footage and recordings stored and retained in digital media. The limited
number of persons with access to the recordings declare, through
confidentiality undertakings, that they will protect the confidentiality of the
data to which they have access.
For security purposes and for the purposes
specified in this Policy, “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.”
carries out personal data processing activities for monitoring visitor entries
and exits in the buildings and facilities of “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL
SAN. VE TİC. A.Ş.”
When the names and surnames of persons
visiting the buildings of “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.”
are obtained, the relevant personal data subjects are informed within this
scope through notices posted at “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC.
A.Ş.” or otherwise made available to visitors. Data obtained for the purpose of
monitoring visitor entries and exits is processed solely for this purpose, and
the relevant personal data is recorded in the data filing system in physical form.
With an awareness of the responsibility
arising from being a well-established company, the “COMPANY” exercises all
reasonable care and diligence necessary to ensure the confidentiality and
security of the personal data it processes. In addition to the requirements of
the relevant legislation, the “COMPANY” takes the technical and administrative
measures reasonably necessary to ensure data confidentiality and security
within the framework of Article 12 of the KVKK. Through such administrative and
technical security measures, the aim is to prevent the unlawful processing of
personal data, prevent unlawful access to personal data, and ensure that
personal data is retained at an appropriate level of security.
Where personal data is processed on behalf
of the “COMPANY” by another natural or legal person (data processor), the
“COMPANY” shall take the necessary measures to ensure that the measures
specified above are also taken by the relevant data processors.
If personal data is unlawfully obtained by
third parties, the data subjects, the Board, and other relevant public
institutions and organizations shall be notified in accordance with the
provisions of the relevant legislation.
When taking measures relating to the
security of personal data, the Personal Data Security Guide (Technical and
Administrative Measures) published by the Board is taken into consideration.
·
Establishing and operating an
information security management system within the Company;
·
Signing undertakings and
confidentiality agreements with Company personnel and relevant parties;
·
Conducting risk analyses on
business processes;
·
Preparing personal data
inventories;
·
Operating information security
policies and procedures;
·
Organizing and evaluating
training on information security and personal data processing activities;
·
Ensuring that employee
computers and similar equipment are used only by authorized persons in order to
prevent unauthorized access to such tools and equipment;
·
Reviewing activities through
internal or independent audits;
·
Creating records that provide
objective evidence of the transactions performed.
·
Penetration tests are conducted
to identify risks, threats, vulnerabilities, and any security gaps in the
Company’s information systems, and the necessary measures are taken.
·
Risks and threats that may
affect the continuity of information systems are continuously monitored through
real-time analyses conducted under information security incident management.
·
Access to information systems
and user authorization are managed through security policies, an access and
authorization matrix, and the corporate active directory.
·
When software changes and/or
updates are to be made to systems, trials are conducted in a test environment,
any security vulnerabilities are identified and the necessary measures are
taken, and the change is finalized only after these procedures. (This is stated
in the decision and must be carried out.)
·
The necessary measures are
taken to ensure the physical security of the information-system equipment,
software, and data of “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.”
·
In order to ensure the security
of information systems against environmental threats, hardware measures (such
as an access-control system allowing only authorized personnel to enter the
server room, physical security for edge switches forming the local area
network, a fire-extinguishing system, and an air-conditioning system) and
software measures (such as firewalls, intrusion-prevention systems,
network-access control, and anti-malware systems) are taken.
·
Risks relating to the
prevention of unlawful processing of personal data are identified, technical
measures appropriate to such risks are implemented, and technical controls are
conducted in relation to the measures taken.
·
Access procedures are
established within the Company, and reporting and analysis studies are carried
out concerning access to personal data.
·
The Company takes the necessary
measures to ensure that deleted personal data is inaccessible and cannot be
reused by relevant users.
·
Preparatory work has been
carried out by the Company to notify the relevant person and the Board if
personal data is unlawfully obtained by others.
·
Security vulnerabilities are
monitored, appropriate security patches are installed, and information systems
are kept up to date.
·
Strong passwords are used in
electronic environments in which personal data is processed.
·
Secure record-keeping (logging)
systems are used in electronic environments in which personal data is
processed.
·
Data-backup programs are used
to ensure the secure storage of personal data.
·
Access to personal data stored
in electronic or non-electronic environments is restricted in accordance with
access principles.
·
Access to the Company’s website
is encrypted using the secure HTTPS protocol and the SHA-256-bit RSA algorithm.
·
Employees involved in the
processing of special categories of personal data have received training on the
security of special categories of personal data, confidentiality agreements
have been executed, and the authorizations of users with access to the data
have been defined.
·
Electronic environments in
which special categories of personal data are processed, retained, and/or
accessed are protected using cryptographic methods; cryptographic keys are kept
in secure environments; all transaction records are logged; security updates
for the environments are continuously monitored; the necessary security tests
are regularly conducted or commissioned; and the test results are recorded.
·
Adequate security measures are
taken for physical environments in which special categories of personal data
are processed, retained, and/or accessed, physical security is ensured, and
unauthorized entries and exits are prevented.
·
If special categories of
personal data must be transferred by email, they are transferred in encrypted
form via a corporate email address or using a KEP account. If they must be
transferred via media such as portable memory devices, CDs, or DVDs, they are
encrypted using cryptographic methods, and the cryptographic key is kept in a
separate environment.
·
If transfer via paper media is
required, the necessary measures are taken against risks such as theft, loss,
or viewing of the document by unauthorized persons, and the document is sent in
a “confidential” format.
Explicit
Consent: Consent relating to a specific matter,
based on information, and expressed with free will.
Company: “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.,” domiciled at
Akçeşme Mah. Bozburun_1 Cad. No:6 MERKEZEFENDİ / DENİZLİ.
Cookie: Small files saved on users’ computers or mobile devices that help
store preferences and other information relating to the web pages they visit.
Relevant
User: Persons who process personal data within the
data controller’s organization or in accordance with the authority and
instructions received from the data controller, excluding the person or unit
responsible for the technical storage, protection, and backup of the data.
Disposal: The deletion, destruction, or anonymization of personal data.
Contact
Person: The natural person notified to the Registry
by the data controller during registration for the purpose of communicating
with the Authority regarding the obligations under the Law and the secondary
regulations to be issued on the basis of the Law of legal persons established
in Türkiye and the representative of a legal-person data controller not
established in Türkiye. (The contact person is not authorized to represent the
Data Controller. As the name suggests, this person is appointed solely to
provide “contact” and communication between the data controller, relevant
persons, and the Authority.)
Law/KVKK: The Personal Data Protection Law No. 6698 dated 24 March 2016,
published in the Official Gazette dated 7 April 2016 and numbered 29677.
Recording
Medium: Any medium containing personal data
processed wholly or partly by automatic means or by non-automatic means,
provided that the processing forms part of a data filing system.
Personal
Data: Any information relating to an identified or
identifiable natural person.
Processing
of Personal Data: Any operation performed on
personal data, such as obtaining, recording, storing, retaining, altering,
reorganizing, disclosing, transferring, receiving, making available,
classifying, or preventing the use of personal data, wholly or partly by
automatic means or by non-automatic means, provided that the processing forms
part of a data filing system.
Anonymization
of Personal Data: Rendering personal data
impossible to associate with an identified or identifiable natural person under
any circumstances, even by matching it with other data.
Deletion
of Personal Data: Rendering personal data
inaccessible and unusable in any manner by Relevant Users.
Destruction
of Personal Data: The process of rendering personal
data inaccessible, irretrievable, and unusable by anyone in any manner.
Board: The Personal Data Protection Board.
Special
Categories of Personal Data: Data relating to a
person’s race, ethnic origin, political opinions, philosophical beliefs,
religion, religious sect or other beliefs, appearance and clothing, Company,
foundation or trade-union membership, health, sexual life, criminal convictions
and security measures, and biometric and genetic data.
Periodic
Disposal: The deletion, destruction, or
anonymization process to be carried out ex officio at recurring intervals
specified in the personal data retention and disposal policy when all
conditions required for processing personal data have ceased to exist.
Policy: The personal data protection policy created by the Company.
Data
Processor: A natural or legal person who processes
personal data on behalf of the data controller on the basis of the authority
granted by the data controller.
Data
Filing System: A filing system in which personal
data is structured and processed according to specific criteria.
Data
Subject/Relevant Person: The natural person whose
personal data is processed.
Data
Controller: The natural or legal person who
determines the purposes and means of processing personal data and is
responsible for establishing and managing the data filing system.
Regulation: The Regulation on the Deletion, Destruction or Anonymization of
Personal Data.
Source: Personal Data Protection Law No. 6698 – Regulation on the Deletion,
Destruction or Anonymization of Personal Data – Regulation on the Data
Controllers’ Registry – Communiqué on the Procedures and Principles to Be
Followed in Fulfillment of the Obligation to Inform – Communiqué on Application
Procedures and Principles to the Data Controller – Communiqué on Application
Procedures and Principles to the Data Controller.
Personal data relating to the identity
details of natural persons shall be evaluated under this category. (name and
surname, mother’s and father’s names, mother’s maiden name, date of birth,
place of birth, marital status, Turkish Republic identity number)
Any personal data that may be used to
communicate with persons shall be evaluated under this category. (address
number, email address, contact address, registered electronic mail address
(KEP), telephone number)
Location information indicating where
persons are located, etc.
Data contained in the personnel files of
Company employees under the relevant legislation (payroll information,
disciplinary investigation records, employment commencement and termination
records, asset-declaration information, leave information, curriculum vitae
information, diploma, maternity leave, incapacity-for-work report,
military-service information, performance evaluation reports, and, in
applications by convicted persons, records of criminal convictions and security
measures (criminal-record certificate), and health information).
In general, personnel files contain the
following documents:
·
Criminal-record certificate;
·
Family-status notification
form;
·
Employment certificate/service
certificate;
·
Medical report confirming
fitness to work in heavy and hazardous jobs for very hazardous work;
·
Copy of diploma;
·
Maternity-leave documents,
fit/unfit-for-work reports, and breastfeeding-leave petitions;
·
Disability report and İŞKUR
application registration document if the employee is disabled;
·
Documents showing
military-service status for male employees;
·
İŞKUR application registration
document for a former convict or an employee who is a victim of terrorism;
·
Copy of marriage certificate;
·
Employee approval letter for
overtime work;
·
Document showing the consent of
an employee who will be temporarily transferred to another workplace;
·
Documents proving justified
termination, if any, resignation petition, or termination notice;
·
Release and discharge document;
·
Certificate of residence;
·
“16. Employment contract;
·
All correspondence and records
concerning the employee;
·
Written confirmation that
employees have been informed about occupational health and safety, occupational
risks, necessary precautions, and their statutory rights and responsibilities;
·
Employee payrolls and payment
documents;
·
Employment commencement and
termination declarations;
·
Record and warning notice
relating to unauthorized absence from work or late arrival;
·
Blood-group card;
·
Severance-pay and notice-pay
payrolls;
·
Copy of identity card;
·
Civil-registry extract;
·
Curriculum vitae;
·
Medical report and periodic
medical-examination reports;
·
Photograph;
·
Medical report;
·
Letter from the Revenue
Administration confirming that a disability allowance will be applied for
persons entitled to such allowance;
·
Documents relating to
administrative procedures required in insurance incidents (work-accident
report, work-accident notification, etc.);
·
Custody/assignment document for
any tools and equipment delivered;
·
Petitions, forms, and schedules
relating to unpaid leave and annual paid leave;
·
Training certificates obtained,
if any;
·
Work authorization document for
foreign employees.
Any data relating to persons’ education and
working life shall be included in this category. (education, diploma,
certificate, transcript, in-service training information)
Information contained in correspondence
with judicial authorities, information contained in case files, etc.
Account, banking, and invoice information
of persons.
Visual/audio records maintained for
customer-satisfaction purposes.
Any personal data obtained as a result of
monitoring users’ activities in digital environments shall be classified under
this category.
Health, criminal convictions – security
measures.
Administrative personnel.
Data of members taking part in the
Company’s bodies and activities.
Third parties included in Company
commissions, working groups, and organizations.
Natural persons invited to the Company’s
organizations.
Persons participating in Company
organizations.
Third parties to whom payment is required
in connection with Company activities.
Relatives of Company employees, persons
residing at the same address, and dependents.
Potential employees applying to work for
the Company.
Persons or organizations providing goods or
services to the “COMPANY,” or persons associated with them.
Persons involved in projects conducted by
the “COMPANY.”
Persons or organizations providing external
consultancy services to the “COMPANY,” or persons associated with them.
Persons who receive or may potentially
receive products and services from the “COMPANY.”
Persons or organizations other than those
listed above that have established a continuous or occasional, direct or
indirect relationship with the “COMPANY,” or persons associated with them.
In accordance with Articles 8 and 9 of the
KVK Law, “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.” may transfer the
personal data of data subjects governed by this Policy to the following
categories of persons:
10.
Business partners of “NAKOSAN
NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.”;
11.
Suppliers of “NAKOSAN NAKIŞ
KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.”;
12.
Companies with which data is
shared;
13.
Legally authorized public
institutions and organizations;
14.
Legally authorized private-law
persons.
The scope of the persons listed above to
whom transfers may be made and the purposes of data transfer are set out below.
Definition: Parties with which “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC.
A.Ş.” establishes business partnerships for purposes such as carrying out
various projects, either independently or together with XXX Companies, and
receiving services while conducting its commercial activities. Banks; Pension
and Assistance Fund Foundation.
Purpose
of Data Transfer: Limited to ensuring fulfillment
of the purposes for which the business partnership was established.
Definition: Parties that provide services to “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL
SAN. VE TİC. A.Ş.” on a contractual basis and in accordance with the orders and
instructions of “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.” while
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.” carries out its
commercial activities.
Purpose
of Data Transfer: Limited to ensuring that services
externally procured by “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.”
from the supplier and required for the performance of the commercial activities
of “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.” are provided to
“NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.”
Definition: Companies of the xxx Group.
Purpose
of Data Transfer: Limited to ensuring the conduct
of commercial activities requiring the participation of the xxx Group
Companies.
Definition: Public institutions and organizations authorized under the
provisions of the relevant legislation to request information and documents
from “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.”
Purpose
of Data Transfer: Limited to the purpose requested
by the relevant public institutions and organizations within the scope of their
statutory authority.
Definition: Private-law persons authorized under the provisions of the relevant
legislation to request information and documents from “NAKOSAN NAKIŞ
KONFEKSİYON TEKSTİL SAN. VE TİC. A.Ş.”
Purpose
of Data Transfer: Limited to the purpose requested
by the relevant private-law persons within the scope of their statutory
authority.
Data
Controller: “NAKOSAN NAKIŞ KONFEKSİYON TEKSTİL SAN.
VE TİC. A.Ş.”
Address: Akçeşme Mah. Bozburun_1 Cad. No:6 Merkezefendi / DENİZLİ
Telephone: 0 258 372 17 77
KEP: [email protected]
Website: https://nakosantextile.com/