This Policy sets out the procedures and principles to be complied with by İnvekor Bilgi Teknolojileri ve Danışmanlık Hizmetleri Ltd. Şti. (referred to as the “Company”) regarding the protection and processing of personal data.
The Policy aims to align the Company's operations with the Personal Data Protection Law No. 6698 regarding the protection and processing of personal data, to define the framework of the compliance activities planned to be carried out within the Company, and to ensure coordination. Pursuant to the Personal Data Protection Law No. 6698, your personal data may be processed by the Company as the data controller within the scope explained below.
In this context, the aim is to ensure that the Company's activities are carried out in compliance with the law and legislation and within the framework of the principles of honesty, transparency, and fairness.
This Policy comprehensively regulates the protection and processing of the personal data of the Company's stakeholders, the Company's officers and managers, current and potential customers, employees, job candidates, visitors, and third parties, and aims to ensure transparency and accountability in data processing. All personal data processed by non-automated means, provided that they form part of any data recording system, and the owners of such data, fall within the scope of this Policy.
II. Definitions
Below are the definitions of the key terms used within the scope of the Policy:
| Term | Definition |
|---|---|
| Explicit Consent | Refers to consent related to a specific subject, based on being informed, and declared with free will. |
| Anonymization | Refers to rendering personal data incapable of being associated with an identified or identifiable natural person in any way, even by matching it with other data. |
| Data Subject / Personal Data Owner | Refers to the natural person whose personal data is processed. For example, customers, employees, candidate personnel. |
| Personal Data | Refers to any information relating to an identified or identifiable natural person. Therefore, the processing of information relating to legal entities is not within the scope of Law No. 6698. |
| Processing of Personal Data | Refers to any operation performed on data such as obtaining, recording, storing, retaining, altering, rearranging, disclosing, transferring, taking over, making obtainable, classifying, or preventing the use of personal data by fully or partially automated means, or by non-automated means provided that it forms part of a data recording system. |
| Special Categories of Personal Data | Data relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and attire, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data, are special categories of personal data. |
| Data Processor | The natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller. For example, an IT company that stores a Company's customer data is considered within this scope. |
| Data Controller | The data controller is the person who determines the purposes and means of processing personal data and manages the place (the data recording system) where the data is systematically kept. |
III. Obligations of the Company Regarding the Protection and Processing of Personal Data
3.1. General Obligations of the Company
The Company's main obligations regarding the protection and processing of personal data are as follows:
- The obligation to inform the personal data owner,
- The obligation to ensure the security of personal data,
- The obligation to comply with the legislation regarding the protection and processing of special categories of personal data,
- The obligation to comply with the legislation in the event of the transfer of personal data,
- The obligation to process personal data based on and limited to the processing conditions in the Law.
3.2. The Obligation to Inform
The Company has made it its aim to inform the personal data owner on the following matters:
- The identity of the Company as the data controller and of its representative, if any,
- The purpose for which the personal data will be processed,
- To whom and for what purpose the personal data may be transferred,
- The method and legal grounds for collecting personal data,
- The rights of the personal data owner.
The rights of the personal data owner within the scope of the Company's obligation to inform relate to the following:
- Learning whether their personal data is processed,
- Learning the purpose of processing and whether it is used in accordance with that purpose,
- Knowing the persons to whom the personal data is transferred,
- Requesting correction in case of incomplete or incorrect processing and, if the conditions are met, requesting the deletion of personal data, and requesting that these requests be communicated to third parties,
- Objecting to a result that arises to their detriment through the analysis of the processed data exclusively by automated systems,
- Requesting compensation in case of suffering damage due to unlawful processing.
3.3. The Obligation to Take Measures
Within the scope of the Personal Data Protection Law No. 6698, the Company deems it its duty to take the necessary technical and administrative measures to ensure an appropriate and adequate level of security, in order to prevent the unlawful processing of and/or unlawful access to the personal data it has processed/will process, and to ensure the protection of the relevant personal data.
In this context, the Company establishes systems for carrying out and having carried out the necessary audits regarding the operation of the technical and administrative measures to be prepared.
In the event that the personal data it has processed pursuant to Law No. 6698, the applicable legislation, and this Policy is obtained by others through unlawful means, the Company is obliged to immediately notify the relevant personal data owner and, where required by legislation, the Personal Data Protection Board of this situation. In addition, if a situation constituting a security risk is detected by the Company, the necessary measures are taken immediately to eliminate the said risk.
IV. Purposes of Processing Personal Data and Retention Periods
A. Data Processing Purposes
The Company's data processing purposes are briefly stated as follows:
- The personal data processing activity being mandatory for the protection of the life or bodily integrity of the personal data owner or another person, where the personal data owner is unable to express their consent due to actual impossibility or legal invalidity,
- The processing of personal data being mandatory for the legitimate interests of the Company, provided that it does not harm the fundamental rights and freedoms of the data subjects,
- Being stipulated in the laws, in terms of special categories of personal data other than the personal data owner's health and sexual life,
- The processing of personal data by the Company being directly related and necessary to the establishment or performance of a contract,
- The processing of personal data by the Company being mandatory for the establishment, exercise, or protection of the rights of the Company, the data subjects, or third parties,
- Provided that the personal data has been made public by the data subjects; the processing by the Company being limited to the purpose of such disclosure,
- The Company's relevant activity regarding the processing of personal data being expressly stipulated in the Laws,
- The processing of personal data being mandatory for the Company to fulfill its legal obligation,
- In terms of special categories of personal data relating to the health and sexual life of the personal data owner, being processed by persons under a confidentiality obligation or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of health services and their financing.
In this context, the Company processes the personal data of the relevant persons for the following purposes: fulfilling legal obligations as required or mandated by legal regulations; carrying out the Company's employee personnel processes; performing the necessary work to carry out the commercial activities specified in the Company's articles of association in accordance with the legislation and relevant company policies; determining, planning, and implementing short-, medium-, and long-term commercial policies; providing effective customer service; offering services and proposals; carrying out fiscal, accounting, and financial transactions including service-related invoicing activities; following up legal affairs; planning and executing corporate communication activities; ensuring that data is accurate and up to date; sustaining business and operations; ensuring the legal and commercial security of the Company and the persons with whom it has a business relationship; fulfilling obligations arising from legislation; following up and executing legal processes and communication processes with official institutions; carrying out employee personnel processes; and so on.
In the event that a processing activity carried out for the aforementioned purposes does not meet any of the conditions stipulated under the KVK Law, the explicit consent of the relevant persons is obtained by the Company within the framework of this Policy in relation to the relevant processing process.
B. Personal Data Categorization
The personal data processed within the Company is categorized as follows:
| Category | Description |
|---|---|
| Employee Information / Personnel File Information | Any kind of personal data relating to the information that will form the basis for the personnel rights of our Company staff and/or natural persons in a working relationship with the Company. |
| Financial Information | Personal data processed relating to the relevant person's financial information, documents, and records. |
| Legal Information | Personal data processed within the scope of the legal determination of our receivables and rights and the performance of our debts, our legal obligations, and compliance with the Company's policies. |
| Contact Information | Information such as the relevant person's phone number, address, and e-mail. |
| Identity Information | The relevant person's identity information; information contained in documents such as ID cards, driver's licenses, etc. |
| Premises Security Information | Personal data relating to the records and documents taken within the physical premises. |
| Customer Information | Information processed about our customers as a result of our commercial activities. |
| Professional Experience Information | Professional experience information that will form the basis for the working areas of our Company staff and natural persons. |
| Health Data | Health data kept by the data controller for the purpose of fulfilling its obligations arising from the law. |
C. Retention Periods of Personal Data
Where stipulated within the framework of the relevant legislation, the Company retains personal data for the period specified in such legislation. In cases where no period is regulated in the legislation, personal data is retained for the period requiring its processing in accordance with the Company's practices and the requirements of commercial life, in connection with the services the Company provides while processing that data; it is then deleted, destroyed, or anonymized.
V. Transfer of Personal Data to Third Parties
In accordance with the applicable legislation, the Company may transfer the personal data of customers and other relevant persons to the categories of persons listed below, to the extent necessary and limited to the purposes:
| Persons and Institutions to Whom Transfer May Be Made | Description |
|---|---|
| Administration / Authorized Public Institutions and Organizations | Public institutions and organizations authorized to receive information and documents from the Company pursuant to the relevant legislation fall within this scope. Data may be transferred to these institutions and organizations within their legal authority, limited to the purpose they request. |
| Authorized Private Law Persons / Suppliers | Private law persons authorized to receive information and documents from the Company under the provisions of the relevant legislation fall within this scope, and data may be transferred within their legal authority, limited to the purpose they request. |
| Company Officer | Data may be transferred, under the provisions of the relevant legislation, limited to the purposes of designing strategies related to the Company's commercial activities, ensuring their management at the highest level, and auditing. |
VI. Conditions for the Deletion, Destruction, and Anonymization of Personal Data
Even though it has been processed in accordance with the provisions of the relevant law, in the event that the reasons requiring its processing cease to exist, personal data is deleted, destroyed, or anonymized upon the Company's own decision or upon the request of the personal data owner.
In cases where the Company has the right and/or obligation to retain personal data pursuant to the Personal Data Protection Law, its right not to fulfill the data subject's request is reserved. This is because, pursuant to the Law, in the presence of one of the following conditions, it is possible to process a person's personal data without seeking the explicit consent of the relevant person:
- Being expressly stipulated in the laws,
- Being mandatory for the protection of the life or bodily integrity of a person who is unable to express their consent due to actual impossibility or whose consent is not legally valid, or of another person,
- Provided that it is directly related to the establishment or performance of a contract, the processing of personal data belonging to the parties to the contract being necessary,
- Being mandatory for the data controller to fulfill its legal obligation,
- Having been made public by the relevant person themselves,
- Data processing being mandatory for the establishment, exercise, or protection of a right,
- Data processing being mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the relevant person.
VII. Rights of the Personal Data Owners
A. In General
Data owners have the following rights pursuant to the relevant legislation:
- Learning whether personal data is processed,
- Requesting information about it if their personal data has been processed,
- Learning the purpose of processing the personal data and whether it is used in accordance with that purpose,
- Knowing the third parties, domestic or abroad, to whom the personal data is transferred,
- Requesting the correction of personal data in case of incomplete or incorrect processing, and requesting that the process carried out in this scope be notified to the third parties to whom the personal data has been transferred,
- Requesting the deletion or destruction of personal data in the event that the reasons requiring its processing cease to exist, even though it has been processed in accordance with the relevant legislation, and requesting that the process carried out in this scope be notified to the third parties to whom the personal data has been transferred,
- Objecting to a result that arises to the detriment of the person themselves through the analysis of the processed data exclusively by automated systems,
- Requesting the compensation of the damage in case of suffering damage due to the unlawful processing of personal data.
B. The Data Subject's Right to Apply to the Company
If data owners wish to exercise any of the rights specified above, they can apply by using the contact form on the Company's corporate website.
In the event that the Personal Data Protection Board decides that requests should be submitted by methods other than those specified above, the ways in which applications can be submitted will be announced separately.
The Company will evaluate and conclude requests from data owners within thirty days at the latest, depending on the nature of the request. Positive or negative responses to requests from data owners may be notified to the data owners in writing or electronically.
Although the requests of data owners will, as a rule, be concluded free of charge, in the event that responding to the request also requires a cost, a fee may be charged in the amounts determined within the framework of the relevant legislation. The procedures and principles regarding the payment of this fee will be specified in the application form. In the event that this fee is not paid in accordance with the explained procedures and principles, applications may not be taken into account. If the application arises from the Company's error, the fee charged is refunded to the relevant person.
C. Special Cases in Which Data Owners Cannot Assert Their Rights
Since the cases listed below are excluded from the scope of the Personal Data Protection Law, personal data owners cannot assert the rights explained above on these matters:
- The processing of personal data for purposes such as research, planning, and statistics by anonymizing it with official statistics,
- The processing of personal data for purposes of art, history, literature, or science, or within the scope of freedom of expression, provided that it does not violate national defense, national security, public safety, public order, economic security, the privacy of private life, or personal rights, or constitute a crime,
- The processing of personal data within the scope of preventive, protective, and intelligence activities carried out by public institutions and organizations assigned and authorized by law to ensure national defense, national security, public safety, public order, or economic security,
- The processing of personal data by judicial authorities or execution authorities in relation to investigation, prosecution, trial, or execution proceedings.
D. The Company's Right to Reject the Personal Data Owner's Application
The Company may reject the application of the applicant in the following cases, by explaining its reason:
- The processing of personal data within the scope of preventive, protective, and intelligence activities carried out by public institutions and organizations assigned and authorized by law to ensure national defense, national security, public safety, public order, or economic security,
- The processing of personal data for purposes such as research, planning, and statistics by anonymizing it with official statistics,
- The processing of personal data for purposes of art, history, literature, or science, or within the scope of freedom of expression, provided that it does not violate national defense, national security, public safety, public order, economic security, the privacy of private life, or personal rights, or constitute a crime,
- The processing of personal data by judicial authorities or execution authorities in relation to investigation, prosecution, trial, or execution proceedings,
- The requested information being publicly available information,
- Personal data processing being necessary for the prevention of a crime or for criminal investigation,
- Personal data processing being necessary for the performance of supervisory or regulatory duties and disciplinary investigation or prosecution by public institutions and organizations and public professional organizations authorized and assigned by law,
- Personal data processing being necessary for the protection of the State's economic and financial interests with regard to budget, tax, and financial matters,
- The processing of personal data made public by the personal data owner,
- The possibility that the personal data owner's request may prevent the rights and freedoms of others,
- Requests requiring disproportionate effort having been made.