We regard respect for human rights and employee rights as an integral part of our corporate culture.
Document Date: 10.02.2020
TİTİZ PLASTİK DIŞ TİCARET VE SANAYİ LİMİTED ŞİRKETİ (‘Company’), commits to comply with this Policy and the procedures to be implemented in connection with the Policy regarding the Personal Data in its possession.
The purpose of this policy is to determine the principles regarding the methods and processes for the protection of personal data within the scope of the Personal Data Protection Law No. 6698 (‘KVKK’) regarding the Company's activities.
The main field of activity of the Company is TİTİZ PLASTİK DIŞ TİCARET VE SANAYİ LİMİTED ŞİRKETİ. This Policy covers all activities related to Personal Data for which the Company performs any processing activity for the continuation of its activities and applies to such activities.
This Policy may be modified from time to time, provided that legal obligations are observed, in cases where the Personal Data Protection Regulations require so, or when the Data Controller Representative or the management of the Company deems it necessary.
The definitions in this Policy shall have the following meanings;
“Explicit Consent” refers to the consent declared by Personal Data Subjects based on information and of their own free will, without being subject to any condition, regarding the processing of their data.
“Anonymization” refers to rendering Personal Data in such a way that it cannot be associated with an identified or identifiable natural person under any circumstances, even by matching it with other data.
“Anonymized Data” refers to data that cannot be associated with a natural person in any way.
“Personal Data” refers to any information relating to an identified or identifiable natural person.
“Processing of Personal Data” refers to any operation performed on data such as obtaining, recording, storing, retaining, modifying, reorganizing, disclosing, transferring, taking over, making available, classifying, or preventing the use of Personal Data by fully or partially automated means or non-automated means provided that it is part of a data filing system.
“Board” refers to the Personal Data Protection Board.
“ Authority ” refers to the Personal Data Protection Authority.
“KVKK” refers to the Personal Data Protection Law No. 6698.
“KVK Regulations/Provisions” refers to the Personal Data Protection Law No. 6698 and other relevant legislation on the protection of Personal Data, binding decisions, principle decisions, provisions, instructions given by regulatory and supervisory authorities, courts, and other official authorities, as well as applicable international agreements on data protection and any other legislation.
“ KVK Procedures ” refers to the procedures that determine the obligations to be complied with by the Company, employees, and the Data Controller Representative within the scope of this Policy.
“Special Categories of Personal Data” refers to data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and dress, membership of association, foundation or trade-union, health, sexual life, criminal conviction and security measures, and biometric and genetic data.
“Deletion or Being Deleted” is the process of making Personal Data inaccessible and non-reusable for the relevant users.
“Personal Data Inventory” refers to the inventory containing information regarding the Company's Personal Data Processing activities, such as Personal Data Processing processes and methods, Personal Data Processing purposes, data category, third parties to whom Personal Data is transferred, etc.
“Data Processor” refers to the natural or legal person who processes Personal Data on behalf of the Data Controller, based on the authority granted by the Data Controller.
“Data Subject” refers to the natural person whose personal data is processed.
“Data Controller” refers to the natural or legal person who determines the purposes and means of Processing Personal Data and is responsible for the establishment and management of the data filing system.
“Data Controller Representative” refers to the employee of the Company who manages relations with the Authority.
“ Destruction” refers to the destruction of personal data in a way that makes it inaccessible, unrecoverable, and non-reusable by anyone in any way.
Personal Data is processed by the Company in accordance with the law and principles of honesty, and based on the principle of proportionality. What is meant by the principle of proportionality is that personal data is processed only as much as required for company activities and for the necessary duration.
The Company takes all necessary measures to ensure that Personal Data is complete, accurate, and up-to-date, and updates the relevant Personal Data in case the Data Subject requests changes regarding their Personal Data.
Prior to the Processing of Personal Data, the purpose for which the Personal Data will be processed is determined by the Company. In this context, the Data Subject is informed within the scope of the KVK Regulations, and their Explicit Consent is obtained when necessary.
The Company processes Personal Data only in cases where explicit consent is not required under the KVK Regulations and/or in accordance with the purpose of the Explicit Consent obtained from the Data Subject in cases where explicit consent is necessary, and in compliance with the principle of proportionality.
5.5.1. The Company retains Personal Data as long as required for company activities in accordance with the purpose of processing. In case the Company wishes to retain Personal Data for a period longer than the period stipulated in the KVK Regulations or required by the purpose of Personal Data Processing, the Company acts in accordance with the obligations specified in the KVK Regulations.
5.5.2. After the expiry of the period required by the purpose of Personal Data Processing, Personal Data is Deleted, Destroyed, or Anonymized. In this case, it is ensured that the third parties to whom the Company transfers Personal Data also Delete, Destroy, or Anonymize the Personal Data.
5.5.3. The Data Controller Representative is responsible for carrying out the Deletion, Destruction, and Anonymization processes. In this context, the necessary procedure is established by the Data Controller Representative.
Within the scope of Company activities, personal data may be processed for the purpose of carrying out commercial activities and providing services, including but not limited to the following purposes;
Personal Data can only be processed by the Company within the scope of the procedures and principles specified below.
In cases where explicit consent is required for the processing of Personal Data under the KVK Regulations;
6.1.1. Personal Data is processed after informing the Data Subjects within the framework of the fulfillment of the Obligation to Inform, and in case the Data Subjects give their Explicit Consent.
6.1.2. Within the framework of the Obligation to Inform, Data Subjects are notified of their rights before obtaining Explicit Consent.
6.1.3. The Explicit Consent of Data Subjects is obtained through methods in accordance with the KVK Regulations. Explicit Consents are stored by the Company in a provable manner for the duration required under the KVK Regulations.
6.1.4. The Data Controller Representative ensures the fulfillment of the Obligation to Inform and, when necessary, the acquisition and preservation of Explicit Consent for all Personal Data Processing processes. All department employees processing Personal Data are obliged to comply with the instructions of the Data Controller Representative and this Policy.
6.2.1 In cases where the Processing of Personal Data without obtaining Explicit Consent is envisaged within the scope of the KVK Regulations (including but not limited to cases specified in laws such as Article 5.2 and Article 6.3 of the KVKK), the Company may process Personal Data without obtaining the Explicit Consent of the Data Subject. In case of processing Personal Data in this manner, the Company processes Personal Data within the limits drawn by the KVK Regulations and by complying with the Obligation to Inform. In this context:
6.2.1.1. Personal Data may be processed by the Company without Explicit Consent in order to protect the life or physical integrity of the Data Subject who is unable to declare their consent due to actual impossibility or whose consent is not granted legal validity, and/or another person.
6.2.1.2. Provided that it is directly related to the establishment, implementation, performance, or termination of a contract, Personal Data belonging to the parties to the contract may be processed by the Company without the Explicit Consent of the Data Subjects. In this sense, personal data collected by the Company under all contracts necessary for the continuation of its activities, such as service contracts, labor contracts, lease contracts, etc., to which the Company is a party, are processed, stored, deleted, and destroyed within the framework of this Policy without explicit consent.
6.2.1.3. If the Processing of Personal Data is mandatory for the Company to fulfill its legal obligation, Personal Data may be processed by the Company without the Explicit Consent of the Data Subjects.
6.2.1.4. Personal Data made public by the Data Subject may be processed by the Company without obtaining Explicit Consent.
6.2.1.5. If the processing of Personal Data without obtaining Explicit Consent is the only possible way for the establishment, exercise, or protection of a right, Personal Data may be processed by the Company within the knowledge of the Data Controller Representative without obtaining Explicit Consent.
6.2.1.6. Provided that it does not prejudice the fundamental rights and freedoms of the Data Subjects, if data processing is mandatory for the legitimate interests of the Company, Personal Data may be processed by the Company without Explicit Consent.
7.1. Special Categories of Personal Data can only be processed if the Data Subject has Explicit Consent, or in terms of Special Categories of Personal Data other than sexual life and personal health data, if processing is explicitly made mandatory by law.
7.2. The Company does not collect, store, or process special categories of personal data in any way, except for special categories of personal data that are required to be obtained as a legal requirement due to the labor contracts to which it is a party or which are transferred to it.
7.3. Personal Data related to health and sexual life can only be processed without obtaining Explicit Consent for the purposes of protection of public health, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and financing. Therefore, until otherwise provided in the KVK Regulations, personal health data and sexual life data can only be processed within the scope of Explicit Consent or by the Company physician who is under the obligation of confidentiality.
7.4. While Processing Special Categories of Personal Data, measures determined by the Board are taken.
7.5. In every case requiring the Processing of Special Categories of Personal Data, the Data Controller Representative is informed by the relevant employee.
7.6. If it is not clear whether a data is a Special Category of Personal Data, an opinion is obtained from the Data Controller Representative by the relevant department.
8.1. When the legitimate purpose for Processing Personal Data ceases to exist, the relevant Personal Data is Deleted, Destroyed, or Anonymized. Cases where Personal Data must be Deleted, Destroyed, or Anonymized are monitored by the Data Controller Representative.
8.2. Resumes sent to the Company by any means are deleted within 1 year at the latest in case of no response.
8.3. Personal data shared with the Company through the contact screen specified on the address www.titizplastik.com are deleted within three months at the latest.
8.4. Personal data acquired by the Company due to labor contracts to which it is a party are destroyed upon the expiration of the retention obligation arising from the labor contract.
8.5. The Company does not store Personal Data solely considering the possibility of future use. The above articles also apply to personal data that the company does not collect but is transferred to the company for a similar purpose.
The Company may transfer Personal Data to a third natural or legal person (“ Contractor ”) in accordance with KVK Regulations. In this case, the Company ensures that the third parties to whom it transfers Personal Data also comply with this Policy. In this context, necessary protective regulations are added to the contracts concluded with the third party. The clause to be added to the contracts concluded with third parties to whom any Personal Data is transferred is obtained from the Data Controller Representative. Each employee is obliged to follow the process in this Policy in case of Personal Data transfer. If the third party to whom the Personal Data is transferred requests changes to the clause sent by the Data Controller Representative, the situation is immediately reported by the employee to the Data Controller Representative.
Personal data may be transferred, including but not limited to the following, in accordance with the principles and rules explained in this Policy:
9.1.1. Personal Data may be transferred by the Company to third parties located in Turkey for the purpose of continuation of its activities or fulfillment of its obligations, without Explicit Consent in cases specified by the KVK Provisions, and provided that the Explicit Consent of the Data Subject is obtained in cases where Explicit Consent is sought.
9.1.2. The Company is responsible for ensuring that the transfer of Personal Data to third parties located in Turkey is in accordance with KVK Regulations.
9.2.1. The Company will be able to transfer personal data abroad within the framework of this Policy and legislative provisions due to the email system.
9.2.2. Personal Data may be transferred by the Company to third parties located abroad, without Explicit Consent in cases specified by the KVK Provisions, and provided that the Explicit Consent of the Data Subject is obtained in cases where Explicit Consent is sought.
9.2.3. In case Personal Data is transferred without obtaining Explicit Consent in accordance with KVK Regulations, one of the following conditions must exist regarding the foreign country to which it will be transferred:
9.2.3.1 The foreign country to which Personal Data is transferred must have the status of countries where adequate protection is provided by the Board (for the list, please follow the current list of the Board),
9.2.3.2 In case the foreign country where the transfer will take place is not on the secure countries list of the Board, the Company and the Data Controllers in the relevant country must undertake in writing that adequate protection will be provided and obtain permission from the Board.
9.2.4. The Company is responsible for ensuring that the transfer of Personal Data to third parties abroad is in accordance with KVK Regulations.
9.2.5. The Company may receive services from service providers such as Google, Hotmail, Outlook for electronic communication purposes. In this context, personal data that may be included in the electronic communications to be made by the company are stored on the servers of the service providers and are kept, transferred, and processed within the scope of the data protection policies of the said companies.
10.1. In accordance with Article 10 of the KVKK, the Company informs the Data Subjects regarding the Processing of Personal Data. In this context, the Company fulfills its Obligation to Inform with the Informative Text it prepares during the acquisition of Personal Data. The notification to be made to Data Subjects within the scope of the Obligation to Inform includes the following elements respectively:
The relevant person may obtain information on the following matters by filling out the Application Form and sending it to the address kvkk@titizplastik.com specified in the Informative Text of the Company;
10.2. In case the Data Subject requests information regarding their personal data processed in accordance with the KVK Provisions, the Company makes the necessary notification within 30 (thirty) days at the latest after verifying the identity of the Data Subject. The Company reserves the right to reject the application, including but not limited to the following reasons;
10.3. In cases where the application is rejected, the answer given to the application is found insufficient, or no answer is given within the due time; the applicant has the right to file a complaint with the KVK Board within 30 (thirty) days from the date they learn the answer and in any case within 60 (sixty) days from the application date.
10.4. The employee following the relevant process and the Data Controller Representative carry out the fulfillment of the necessary Obligation to Inform before the Processing of Personal Data.
10.5. If the Data Processor is a third party other than the Company, it must be committed in writing by the third party before starting Personal Data Processing that the third party will act in accordance with the obligations specified above. In cases where third parties transfer Personal Data to the Company, the clause to be added to the contracts is obtained from the Data Controller Representative. Each employee is obliged to follow the process in this Policy in case of Personal Data transfer to the Company by a third party. If the third party transferring the Personal Data requests changes to the clause sent by the Data Controller Representative, the situation is immediately reported by the employee to the Data Controller Representative.
11.1. The Company appoints a Data Controller Representative to fulfill its obligations under the KVK Regulations, to ensure and audit the implementation of KVK Procedures necessary for the implementation of this Policy, and to make recommendations regarding their operation.
The Company takes administrative and technical measures to ensure personal data security within the scope of the relevant guide of the KVK Authority on the subject.
The Company provides its employees with the necessary training on the protection of Personal Data within the scope of the Policy and KVKK Regulations, and keeps records of these trainings.
The Company has the right to audit that all employees, departments, and contractors of the Company act in accordance with this Policy and KVK Regulations regularly, at any time, and ex officio, without any prior notice, and conducts necessary routine audits in this context. The Data Controller Representative establishes the KVK Procedure regarding these audits and ensures the implementation of the said procedure.
14.1 Each employee of the Company reports any work, transaction, or action that they think is contrary to the procedures and principles specified in the KVK Regulations and this Policy to the Data Controller Representative. In this context, the Data Controller Representative establishes an action plan for the relevant violation in accordance with this Policy and KVK Procedures.
14.2. As a result of the notifications, the Data Controller Representative prepares the notification to be made to the Data Subject or the Authority regarding the violation, taking into account the provisions of the current legislation on the subject, especially the KVK Regulations. The Data Controller Representative conducts the correspondence and communication with the Authority.
Process management regarding the Protection of Personal Data within the Company is provided by the employee, department, and the Data Controller Representative. In this context, the Data Controller Representative who will ensure the implementation of the Policy and manage the Personal Data Protection process is appointed by the decision of the Company management, and changes in this context are also made in the same way.
The Company shares the updated Policy text via email with the Data Subjects in a way that the changes made on the Policy can be examined, and/or presents it to access in a way that can be visible in the workplace and/or over a website that may be established in the future.
This Policy has entered into force upon approval by the board of directors on 10.02.2020 .