Our Policies

We regard respect for human rights and employee rights as an integral part of our corporate culture.

PDPL

TİTİZ PLASTİK DIŞ TİCARET VE SANAYİ LİMİTED ŞİRKETİ

PERSONAL DATA PROTECTION POLICIES

Document Date: 10.02.2020

CONTENTS

PERSONAL DATA PROTECTION POLICIES

  1. DATA PRIVACY COMMITMENT
  2. PURPOSE OF THE POLICY
  3. SCOPE OF THE POLICY
  4. DEFINITIONS
  5. PRINCIPLES OF PERSONAL DATA PROCESSING
  6. PROCESSING OF PERSONAL DATA
  7. PROCESSING OF SPECIAL CATEGORIES OF PERSONAL DATA
  8. DELETION, DESTRUCTION AND ANONYMIZATION OF PERSONAL DATA
  9. TRANSFER OF PERSONAL DATA AND PROCESSING OF PERSONAL DATA BY THIRD PARTIES
  10. THE COMPANY'S OBLIGATION TO INFORM AND THE RIGHTS OF THE DATA SUBJECT
  11. MEASURES TAKEN FOR DATA MANAGEMENT, SECURITY AND PROTECTION OF PERSONAL DATA
  12. TRAINING
  13. AUDIT
  14. VIOLATIONS
  15. RESPONSIBILITIES
  16. CHANGES TO BE MADE IN THE POLICY
  17. EFFECTIVE DATE OF THE POLICY

PERSONAL DATA PROTECTION POLICY

1. DATA PRIVACY COMMITMENT

TİTİZ PLASTİK DIŞ TİCARET VE SANAYİ LİMİTED ŞİRKETİ (‘Company’), commits to comply with this Policy and the procedures to be implemented in connection with the Policy regarding the Personal Data in its possession.

2. PURPOSE OF THE POLICY

The purpose of this policy is to determine the principles regarding the methods and processes for the protection of personal data within the scope of the Personal Data Protection Law No. 6698 (‘KVKK’) regarding the Company's activities.

3. SCOPE OF THE POLICY

The main field of activity of the Company is TİTİZ PLASTİK DIŞ TİCARET VE SANAYİ LİMİTED ŞİRKETİ. This Policy covers all activities related to Personal Data for which the Company performs any processing activity for the continuation of its activities and applies to such activities.

This Policy may be modified from time to time, provided that legal obligations are observed, in cases where the Personal Data Protection Regulations require so, or when the Data Controller Representative or the management of the Company deems it necessary.

4. DEFINITIONS

The definitions in this Policy shall have the following meanings;

“Explicit Consent” refers to the consent declared by Personal Data Subjects based on information and of their own free will, without being subject to any condition, regarding the processing of their data.

“Anonymization” refers to rendering Personal Data in such a way that it cannot be associated with an identified or identifiable natural person under any circumstances, even by matching it with other data.

“Anonymized Data” refers to data that cannot be associated with a natural person in any way.

“Personal Data” refers to any information relating to an identified or identifiable natural person.

“Processing of Personal Data” refers to any operation performed on data such as obtaining, recording, storing, retaining, modifying, reorganizing, disclosing, transferring, taking over, making available, classifying, or preventing the use of Personal Data by fully or partially automated means or non-automated means provided that it is part of a data filing system.

“Board” refers to the Personal Data Protection Board.

Authority ” refers to the Personal Data Protection Authority.

“KVKK” refers to the Personal Data Protection Law No. 6698.

“KVK Regulations/Provisions” refers to the Personal Data Protection Law No. 6698 and other relevant legislation on the protection of Personal Data, binding decisions, principle decisions, provisions, instructions given by regulatory and supervisory authorities, courts, and other official authorities, as well as applicable international agreements on data protection and any other legislation.

KVK Procedures ” refers to the procedures that determine the obligations to be complied with by the Company, employees, and the Data Controller Representative within the scope of this Policy.

“Special Categories of Personal Data” refers to data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and dress, membership of association, foundation or trade-union, health, sexual life, criminal conviction and security measures, and biometric and genetic data.

“Deletion or Being Deleted” is the process of making Personal Data inaccessible and non-reusable for the relevant users.

“Personal Data Inventory” refers to the inventory containing information regarding the Company's Personal Data Processing activities, such as Personal Data Processing processes and methods, Personal Data Processing purposes, data category, third parties to whom Personal Data is transferred, etc.

“Data Processor” refers to the natural or legal person who processes Personal Data on behalf of the Data Controller, based on the authority granted by the Data Controller.

“Data Subject” refers to the natural person whose personal data is processed.

“Data Controller” refers to the natural or legal person who determines the purposes and means of Processing Personal Data and is responsible for the establishment and management of the data filing system.

“Data Controller Representative” refers to the employee of the Company who manages relations with the Authority.

Destruction” refers to the destruction of personal data in a way that makes it inaccessible, unrecoverable, and non-reusable by anyone in any way.

5. PRINCIPLES OF PERSONAL DATA PROCESSING

5.1. Processing of Personal Data in Accordance with the Law and Principles of Honesty

Personal Data is processed by the Company in accordance with the law and principles of honesty, and based on the principle of proportionality. What is meant by the principle of proportionality is that personal data is processed only as much as required for company activities and for the necessary duration.

5.2. Taking Necessary Measures to Ensure Personal Data is Accurate and Up-to-Date When Necessary

The Company takes all necessary measures to ensure that Personal Data is complete, accurate, and up-to-date, and updates the relevant Personal Data in case the Data Subject requests changes regarding their Personal Data.

5.3. Processing of Personal Data for Specified, Explicit, and Legitimate Purposes

Prior to the Processing of Personal Data, the purpose for which the Personal Data will be processed is determined by the Company. In this context, the Data Subject is informed within the scope of the KVK Regulations, and their Explicit Consent is obtained when necessary.

5.4. Personal Data Being Relevant, Limited, and Proportionate to the Purpose for which They Are Processed

The Company processes Personal Data only in cases where explicit consent is not required under the KVK Regulations and/or in accordance with the purpose of the Explicit Consent obtained from the Data Subject in cases where explicit consent is necessary, and in compliance with the principle of proportionality.

5.5. Retention of Personal Data for as Long as Required and Deletion Thereafter

5.5.1. The Company retains Personal Data as long as required for company activities in accordance with the purpose of processing. In case the Company wishes to retain Personal Data for a period longer than the period stipulated in the KVK Regulations or required by the purpose of Personal Data Processing, the Company acts in accordance with the obligations specified in the KVK Regulations.

5.5.2. After the expiry of the period required by the purpose of Personal Data Processing, Personal Data is Deleted, Destroyed, or Anonymized. In this case, it is ensured that the third parties to whom the Company transfers Personal Data also Delete, Destroy, or Anonymize the Personal Data.

5.5.3. The Data Controller Representative is responsible for carrying out the Deletion, Destruction, and Anonymization processes. In this context, the necessary procedure is established by the Data Controller Representative.

6. PROCESSING OF PERSONAL DATA

Within the scope of Company activities, personal data may be processed for the purpose of carrying out commercial activities and providing services, including but not limited to the following purposes;

  • Execution of activities,
  • Provision of services within the scope of contract and service standards and fulfillment of contract requirements,
  • Fulfillment of legal obligations as required or made mandatory by legislation
  • Evaluation of job applications and provision of employment. Personal data contained in resumes, diplomas, etc. shared through any method during the application process as a Candidate Employee may be processed, stored, and transferred within the scope of this Policy for the purpose of job application evaluation. In case of employment, personal data of employees are processed, stored, and transferred in accordance with the Labor Law No. 4857 and other relevant legislative obligations,
  • Ensuring contact with persons in a business relationship with the Company,
  • Marketing,
  • Receiving and placing advertisements,
  • Legal and financial reporting,
  • Billing.

Personal Data can only be processed by the Company within the scope of the procedures and principles specified below.

6.1. Explicit Consent

In cases where explicit consent is required for the processing of Personal Data under the KVK Regulations;

6.1.1. Personal Data is processed after informing the Data Subjects within the framework of the fulfillment of the Obligation to Inform, and in case the Data Subjects give their Explicit Consent.

6.1.2. Within the framework of the Obligation to Inform, Data Subjects are notified of their rights before obtaining Explicit Consent.

6.1.3. The Explicit Consent of Data Subjects is obtained through methods in accordance with the KVK Regulations. Explicit Consents are stored by the Company in a provable manner for the duration required under the KVK Regulations.

6.1.4. The Data Controller Representative ensures the fulfillment of the Obligation to Inform and, when necessary, the acquisition and preservation of Explicit Consent for all Personal Data Processing processes. All department employees processing Personal Data are obliged to comply with the instructions of the Data Controller Representative and this Policy.

6.2. Processing of Personal Data Without Explicit Consent

6.2.1 In cases where the Processing of Personal Data without obtaining Explicit Consent is envisaged within the scope of the KVK Regulations (including but not limited to cases specified in laws such as Article 5.2 and Article 6.3 of the KVKK), the Company may process Personal Data without obtaining the Explicit Consent of the Data Subject. In case of processing Personal Data in this manner, the Company processes Personal Data within the limits drawn by the KVK Regulations and by complying with the Obligation to Inform. In this context:

6.2.1.1. Personal Data may be processed by the Company without Explicit Consent in order to protect the life or physical integrity of the Data Subject who is unable to declare their consent due to actual impossibility or whose consent is not granted legal validity, and/or another person.

6.2.1.2. Provided that it is directly related to the establishment, implementation, performance, or termination of a contract, Personal Data belonging to the parties to the contract may be processed by the Company without the Explicit Consent of the Data Subjects. In this sense, personal data collected by the Company under all contracts necessary for the continuation of its activities, such as service contracts, labor contracts, lease contracts, etc., to which the Company is a party, are processed, stored, deleted, and destroyed within the framework of this Policy without explicit consent.

6.2.1.3. If the Processing of Personal Data is mandatory for the Company to fulfill its legal obligation, Personal Data may be processed by the Company without the Explicit Consent of the Data Subjects.

6.2.1.4. Personal Data made public by the Data Subject may be processed by the Company without obtaining Explicit Consent.

6.2.1.5. If the processing of Personal Data without obtaining Explicit Consent is the only possible way for the establishment, exercise, or protection of a right, Personal Data may be processed by the Company within the knowledge of the Data Controller Representative without obtaining Explicit Consent.

6.2.1.6. Provided that it does not prejudice the fundamental rights and freedoms of the Data Subjects, if data processing is mandatory for the legitimate interests of the Company, Personal Data may be processed by the Company without Explicit Consent.

7. PROCESSING OF SPECIAL CATEGORIES OF PERSONAL DATA

7.1. Special Categories of Personal Data can only be processed if the Data Subject has Explicit Consent, or in terms of Special Categories of Personal Data other than sexual life and personal health data, if processing is explicitly made mandatory by law.

7.2. The Company does not collect, store, or process special categories of personal data in any way, except for special categories of personal data that are required to be obtained as a legal requirement due to the labor contracts to which it is a party or which are transferred to it.

7.3. Personal Data related to health and sexual life can only be processed without obtaining Explicit Consent for the purposes of protection of public health, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and financing. Therefore, until otherwise provided in the KVK Regulations, personal health data and sexual life data can only be processed within the scope of Explicit Consent or by the Company physician who is under the obligation of confidentiality.

7.4. While Processing Special Categories of Personal Data, measures determined by the Board are taken.

7.5. In every case requiring the Processing of Special Categories of Personal Data, the Data Controller Representative is informed by the relevant employee.

7.6. If it is not clear whether a data is a Special Category of Personal Data, an opinion is obtained from the Data Controller Representative by the relevant department.

8. RETENTION, DELETION, DESTRUCTION AND ANONYMIZATION OF PERSONAL DATA

8.1. When the legitimate purpose for Processing Personal Data ceases to exist, the relevant Personal Data is Deleted, Destroyed, or Anonymized. Cases where Personal Data must be Deleted, Destroyed, or Anonymized are monitored by the Data Controller Representative.

8.2. Resumes sent to the Company by any means are deleted within 1 year at the latest in case of no response.

8.3. Personal data shared with the Company through the contact screen specified on the address www.titizplastik.com are deleted within three months at the latest.

8.4. Personal data acquired by the Company due to labor contracts to which it is a party are destroyed upon the expiration of the retention obligation arising from the labor contract.

8.5. The Company does not store Personal Data solely considering the possibility of future use. The above articles also apply to personal data that the company does not collect but is transferred to the company for a similar purpose.

9. TRANSFER OF PERSONAL DATA AND PROCESSING OF PERSONAL DATA BY THIRD PARTIES

The Company may transfer Personal Data to a third natural or legal person (“ Contractor ”) in accordance with KVK Regulations. In this case, the Company ensures that the third parties to whom it transfers Personal Data also comply with this Policy. In this context, necessary protective regulations are added to the contracts concluded with the third party. The clause to be added to the contracts concluded with third parties to whom any Personal Data is transferred is obtained from the Data Controller Representative. Each employee is obliged to follow the process in this Policy in case of Personal Data transfer. If the third party to whom the Personal Data is transferred requests changes to the clause sent by the Data Controller Representative, the situation is immediately reported by the employee to the Data Controller Representative.

Personal data may be transferred, including but not limited to the following, in accordance with the principles and rules explained in this Policy:

  • To suppliers,
  • To business partners and business contacts,
  • To legally authorized public institutions and organizations,
  • To legally authorized private law entities,
  • To shareholders.

9.1. Transfer of Personal Data to Third Parties Located in Turkey

9.1.1. Personal Data may be transferred by the Company to third parties located in Turkey for the purpose of continuation of its activities or fulfillment of its obligations, without Explicit Consent in cases specified by the KVK Provisions, and provided that the Explicit Consent of the Data Subject is obtained in cases where Explicit Consent is sought.

9.1.2. The Company is responsible for ensuring that the transfer of Personal Data to third parties located in Turkey is in accordance with KVK Regulations.

9.2. Transfer of Personal Data to Third Parties Located Abroad

9.2.1. The Company will be able to transfer personal data abroad within the framework of this Policy and legislative provisions due to the email system.

9.2.2. Personal Data may be transferred by the Company to third parties located abroad, without Explicit Consent in cases specified by the KVK Provisions, and provided that the Explicit Consent of the Data Subject is obtained in cases where Explicit Consent is sought.

9.2.3. In case Personal Data is transferred without obtaining Explicit Consent in accordance with KVK Regulations, one of the following conditions must exist regarding the foreign country to which it will be transferred:

9.2.3.1 The foreign country to which Personal Data is transferred must have the status of countries where adequate protection is provided by the Board (for the list, please follow the current list of the Board),

9.2.3.2 In case the foreign country where the transfer will take place is not on the secure countries list of the Board, the Company and the Data Controllers in the relevant country must undertake in writing that adequate protection will be provided and obtain permission from the Board.

9.2.4. The Company is responsible for ensuring that the transfer of Personal Data to third parties abroad is in accordance with KVK Regulations.

9.2.5. The Company may receive services from service providers such as Google, Hotmail, Outlook for electronic communication purposes. In this context, personal data that may be included in the electronic communications to be made by the company are stored on the servers of the service providers and are kept, transferred, and processed within the scope of the data protection policies of the said companies.

10. THE COMPANY'S OBLIGATION TO INFORM AND THE RIGHTS OF THE DATA SUBJECT

10.1. In accordance with Article 10 of the KVKK, the Company informs the Data Subjects regarding the Processing of Personal Data. In this context, the Company fulfills its Obligation to Inform with the Informative Text it prepares during the acquisition of Personal Data. The notification to be made to Data Subjects within the scope of the Obligation to Inform includes the following elements respectively:

  • The identity of the Data Controller and, if any, its representative,
  • The purpose for which the Personal Data will be processed,
  • To whom and for what purpose the processed Personal Data may be transferred,
  • The method and legal reason for collecting Personal Data,

The relevant person may obtain information on the following matters by filling out the Application Form and sending it to the address kvkk@titizplastik.com specified in the Informative Text of the Company;

  • Learning whether their personal data is processed,
  • Requesting information if their personal data has been processed,
  • Learning the purpose of processing their personal data and whether they are used in accordance with their purpose,
  • Knowing the third parties to whom personal data are transferred in the country or abroad,
  • Requesting correction of personal data if they are processed incompletely or inaccurately,
  • Requesting the deletion or destruction of personal data in the event that the reasons requiring the processing of personal data cease to exist,
  • Requesting that the correction, deletion, or destruction operations mentioned above be notified to the third parties to whom the personal data have been transferred,
  • Objecting to the occurrence of a result against the person themselves by analyzing the processed data exclusively through automated systems,
  • Demanding the compensation of the damage in the event that the person incurs damage due to the unlawful processing of personal data.

10.2. In case the Data Subject requests information regarding their personal data processed in accordance with the KVK Provisions, the Company makes the necessary notification within 30 (thirty) days at the latest after verifying the identity of the Data Subject. The Company reserves the right to reject the application, including but not limited to the following reasons;

  • Failure to verify the identity of the person requesting information as the relevant data subject,
  • Processing of personal data for purposes such as research, planning, and statistics by anonymizing them with official statistics,
  • Processing of personal data for artistic, historical, literary, or scientific purposes or within the scope of freedom of expression, provided that it does not violate the privacy of private life or personal rights or constitute a crime,
  • Processing of personal data made public by the Personal Data Subject,
  • The application is not based on a justified reason,
  • The application contains a request contrary to the relevant legislation,
  • Non-compliance with the application procedure, in which cases it is rejected by explaining the reason for non-acceptance.

10.3. In cases where the application is rejected, the answer given to the application is found insufficient, or no answer is given within the due time; the applicant has the right to file a complaint with the KVK Board within 30 (thirty) days from the date they learn the answer and in any case within 60 (sixty) days from the application date.

10.4. The employee following the relevant process and the Data Controller Representative carry out the fulfillment of the necessary Obligation to Inform before the Processing of Personal Data.

10.5. If the Data Processor is a third party other than the Company, it must be committed in writing by the third party before starting Personal Data Processing that the third party will act in accordance with the obligations specified above. In cases where third parties transfer Personal Data to the Company, the clause to be added to the contracts is obtained from the Data Controller Representative. Each employee is obliged to follow the process in this Policy in case of Personal Data transfer to the Company by a third party. If the third party transferring the Personal Data requests changes to the clause sent by the Data Controller Representative, the situation is immediately reported by the employee to the Data Controller Representative.

11. MEASURES TAKEN FOR DATA MANAGEMENT, SECURITY AND PROTECTION OF PERSONAL DATA

11.1. The Company appoints a Data Controller Representative to fulfill its obligations under the KVK Regulations, to ensure and audit the implementation of KVK Procedures necessary for the implementation of this Policy, and to make recommendations regarding their operation.

The Company takes administrative and technical measures to ensure personal data security within the scope of the relevant guide of the KVK Authority on the subject.

11.1.1. Administrative Measures

  • The Company establishes Policies and procedures covering the entire data processing process, carries out periodic works to determine existing risks and threats, and provides transparency in the data processing process.
  • Company employees are informed and trained regarding the protection and lawful processing of Personal Data.
  • It reduces processed and stored personal data as much as possible and uses anonymized data whenever possible.
  • It manages its relations with natural and legal persons processing personal data in accordance with the job description within the Company or the business relationship with the Company. In this context, Company employees can access Personal Data only within the authority defined to them and in accordance with the relevant KVK Procedure. Any access and processing carried out by the employee exceeding their authority is unlawful and is a ground for termination of the employment contract for just cause. Each person to whom a Company device is allocated is responsible for the security of the devices allocated for their own use. Each Company employee or person working within the Company is responsible for the security of the physical and electronic files/data in their area of responsibility. If a department within the Company processes Special Categories of Personal Data, this department is informed about the importance, security, and confidentiality of the Personal Data they process, and the relevant department acts in accordance with the instructions of the Data Controller Representative. Access authority to Special Categories of Personal Data is granted only to limited employees, and their list and monitoring are carried out by the Data Controller Representative. In cases where security measures are requested or additionally requested for the security of Personal Data within the scope of KVK Regulations, all employees are obliged to comply with additional security measures and ensure the continuity of these security measures. All employees involved in the relevant process are jointly and severally responsible in proportion to their faults for protecting Personal Data in accordance with this Policy and KVK Procedures. Company employees have been informed that their obligations regarding the security and confidentiality of Personal Data will continue after the termination of the business relationship, and a commitment has been obtained from the relevant employees of the Company to comply with these rules.

11.1.2. Technical Measures

  • The Company ensures the cyber security of all personal data it processes and stores. IT personnel knowledgeable in technical issues regarding Personal Data Processing activities are employed.
  • The Company monitors the cyber security of all personal data it processes and stores, and conducts maintenance and audits at periodic intervals. Personal Data Processing activities by the Company are audited by technical systems according to technological possibilities and application costs.
  • The Company does not use a cloud storage system for all personal data it processes and stores.
  • The Company procures information technology systems and receives development and maintenance services from the firms providing this service. Software and hardware containing virus protection systems and firewalls are installed in the Company in accordance with technological developments to store Personal Data in secure environments. There is a security policy containing technical measures regarding the protection of Personal Data in the Company.
  • Backup programs are used in the Company to prevent Personal Data from being lost or damaged, and adequate security measures are taken.

12. TRAINING

The Company provides its employees with the necessary training on the protection of Personal Data within the scope of the Policy and KVKK Regulations, and keeps records of these trainings.

13. AUDIT

The Company has the right to audit that all employees, departments, and contractors of the Company act in accordance with this Policy and KVK Regulations regularly, at any time, and ex officio, without any prior notice, and conducts necessary routine audits in this context. The Data Controller Representative establishes the KVK Procedure regarding these audits and ensures the implementation of the said procedure.

14. VIOLATIONS

14.1 Each employee of the Company reports any work, transaction, or action that they think is contrary to the procedures and principles specified in the KVK Regulations and this Policy to the Data Controller Representative. In this context, the Data Controller Representative establishes an action plan for the relevant violation in accordance with this Policy and KVK Procedures.

14.2. As a result of the notifications, the Data Controller Representative prepares the notification to be made to the Data Subject or the Authority regarding the violation, taking into account the provisions of the current legislation on the subject, especially the KVK Regulations. The Data Controller Representative conducts the correspondence and communication with the Authority.

15. PROCESS MANAGEMENT

Process management regarding the Protection of Personal Data within the Company is provided by the employee, department, and the Data Controller Representative. In this context, the Data Controller Representative who will ensure the implementation of the Policy and manage the Personal Data Protection process is appointed by the decision of the Company management, and changes in this context are also made in the same way.

16. CHANGES TO BE MADE IN THE POLICY

The Company shares the updated Policy text via email with the Data Subjects in a way that the changes made on the Policy can be examined, and/or presents it to access in a way that can be visible in the workplace and/or over a website that may be established in the future.

This Policy has entered into force upon approval by the board of directors on 10.02.2020 .

Teklif Oluştur
Request a Quote
TEKLİF İSTE