Introduction
In accordance with Article 20 of the Constitution of the Republic of Turkey, everyone has the right to request the protection of their personal data. This right includes being informed about personal data concerning oneself, accessing such data, requesting its correction or deletion, and learning whether it is being used in accordance with its intended purposes.
The Personal Data Protection Law No. 6698 (“KVKK Law”) regulates the protection of fundamental rights and freedoms of individuals in the processing of personal data, as well as the obligations, procedures, and principles to be followed by natural and legal persons who process personal data. The purpose of this Policy, prepared in this direction, is to ensure compliance with the obligations set forth by the KVKK Law.
This Policy governs the protection of personal data of Job Candidates, Company Shareholders, Company Officials, Visitors, and employees, shareholders, and officials of institutions with which we are in cooperation, as well as Third Parties. The protection of our employees' personal data is managed under the ASDENAR PROJE Müş. Mim. Müh. Tek. A.Ş. Employee Personal Data Protection and Processing Policy, which is drafted in parallel with the principles in this Policy.
In the event of any conflict between the KVKK Law and other relevant legislation and the Asdenar Rulman Ticaret ve Sanayi A.Ş. Personal Data Protection and Processing Policy, the applicable legislation in force shall prevail.
- Purpose
ASDENAR PROJE Müş. Mim. Müh. Tek. A.Ş. (“Asdenar”) Personal Data Protection and Processing Policy (“Policy”) has been prepared to protect the fundamental rights and freedoms of individuals, especially the privacy of private life, in the processing of personal data, and to regulate the obligations, procedures, and principles to be followed by natural and legal persons who process personal data.
With this Policy, it is adopted that the activities carried out by Asdenar are conducted and developed in compliance with the principles set forth in the KVKK Law.
- Scope
The data subjects whose personal data are processed within the scope of this Policy are categorized as follows:
|
Job Candidates |
Individuals who make their resumes and related information accessible to Asdenar by applying for a job or through any other means. |
|
Intern Candidates |
Individuals who make their resumes and related information accessible to Asdenar by applying for an internship or through any other means. |
|
Former Employees |
Former employees whose employment relationship with Asdenar has ended. |
|
Customers/Prospective Customers |
Individuals whose personal data is obtained due to business relationships within the scope of activities carried out by Asdenar, regardless of whether there is a contractual relationship. |
|
Suppliers/Prospective Suppliers |
Individual manufacturers who provide raw materials, products, etc., for the purpose of offering a product or service to Asdenar. |
|
Visitors/Guests |
Individuals who have entered Asdenar's physical facilities for various purposes or who visit its websites. |
|
Third Parties |
Other individuals, including but not limited to guarantors, family members, etc., whose personal data is processed within the framework of this Policy, even if not defined in the Policy.
|
Regarding the processing of Asdenar employees' personal data, whether fully or partially automated or non-automated provided that it is part of a data filing system, the "Asdenar Employees' Personal Data Protection and Processing Policy" has been regulated separately from this Policy.
- Definitions
The definitions used in this Policy are provided below:
|
Explicit consent |
Consent that is related to a specific matter, based on information, and declared with free will |
|
Anonymization |
Rendering personal data in such a way that it can no longer be associated with an identified or identifiable natural person, even when matched with other data |
|
Employee |
All natural persons working for Asdenar on a fixed-term or indefinite basis |
|
Job applicant |
Individuals who make their resumes and related information accessible to Asdenar by applying for a job or through any other means. |
|
Intern Candidates |
Individuals who make their resumes and related information accessible to Asdenar by applying for an internship or through any other means. |
|
Employee Data Subject Application Form |
The application form to be used by Asdenar employees as personal data subjects when exercising their rights as described in Article 11 of the PDPL (Personal Data Protection Law) |
|
Personal health data |
Any health-related information concerning an identified or identifiable natural person |
|
Personal Data |
Any information relating to an identified or identifiable natural person |
|
Processing of personal data |
Any operation performed on personal data, such as obtaining, recording, storing, preserving, altering, rearranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of data, whether by fully or partially automated means or by non-automated means provided that it is part of a data filing system. |
|
KVKK Law |
Personal Data Protection Law No. 6698 |
|
KVKK Board |
Personal Data Protection Board |
|
KVKK Authority |
Personal Data Protection Authority |
|
Special categories of personal data |
Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership in associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. |
|
TCK |
Turkish Penal Code No. 5237 |
|
Data processor |
The natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller. |
|
Personal data subject |
The natural person whose personal data is processed, referred to as the "data subject" in the KVKK Law. |
|
Data Subject Application Form |
The application form to be used by personal data subjects whose personal data is processed by Asdenar when exercising their rights as set forth in Article 11 of the PDPL (Personal Data Protection Law). |
|
Data controller |
The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data filing system. |
|
Visitor/Guest |
Individuals who have entered Asdenar's physical facilities for various purposes or who visit its websites. |
|
Data Controllers' Registry |
The registry of data controllers maintained by the Personal Data Protection Authority. |
|
Data Inventory |
The inventory created and detailed by Asdenar, associating its personal data processing activities with business processes, including the purposes of processing, the recipient groups to whom personal data is transferred, and the relevant personal data subject groups. |
- General Principles Regarding the Processing of Personal Data
In accordance with Article 3 of the PDPL, any operation performed on personal data, such as obtaining, recording, storing, preserving, altering, rearranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of data, whether by fully or partially automatic means or by non-automatic means provided that it is part of any data filing system, falls within the scope of personal data processing.
The following principles must be complied with in the processing of personal data:
- Compliance with the law and rules of honesty
Our company conducts personal data processing activities in accordance with the law and the rules of good faith, in compliance with the Constitution, the PDPL, and relevant legislation.
- Being accurate and up-to-date when necessary
All necessary administrative and technical measures are taken by our company to ensure the accuracy and currency of personal data while conducting personal data processing activities.
- Processing for specific, clear, and legitimate purposes
Our company clearly and precisely determines the purpose of personal data processing before commencing any such activity.
- Being relevant, limited, and proportionate to the purpose for which they are processed
Our company processes personal data only to the extent necessary to achieve the determined purposes. Data processing activities are not conducted based on the assumption that the data might be used in the future.
- Retained for the period stipulated in the relevant legislation or required for the purpose for which they are processed
Our company retains personal data for the duration stipulated by the PDPL (Personal Data Protection Law) and relevant legislation, or for the period required by the purposes of the data processing activity.
- Conditions for Processing Personal Data
Our company may process personal data and sensitive personal data with the explicit consent of the personal data subject, or without explicit consent in cases stipulated in Articles 5 and 6 of the PDPL.
5.1. Processing of Personal Data
Our company carries out personal data processing activities in accordance with the data processing conditions set forth in Article 5 of the PDPL:
- Being expressly provided for in the laws.
- Being necessary for the protection of the life or physical integrity of the person or of another person, where the person is physically incapable of giving their consent or where their consent is not legally valid.
- Being necessary to process the personal data of the parties to a contract, provided that it is directly related to the establishment or performance of the contract.
- Being necessary for our Company to fulfill its legal obligations.
- Being made public by the personal data subject themselves.
- Being necessary for the establishment, exercise, or protection of a right.
- Being necessary for the legitimate interests of our Company, provided that it does not harm the fundamental rights and freedoms of the personal data subject.
5.2. Processing of Sensitive Personal Data:
Our company processes sensitive personal data, which carry the risk of causing discrimination if processed unlawfully, in accordance with the data processing conditions set forth in Article 6 of the PDPL. Processing sensitive personal data without the explicit consent of the personal data subject is prohibited. However, sensitive personal data may be processed without the explicit consent of the personal data subject in the following cases, provided that adequate measures determined by the PDPL Board are taken:
- Processing of Personal Health Data:
Personal health data may be processed in the presence of one of the following conditions, provided that: (i) adequate measures stipulated by the Ministry of Health are taken, (ii) general principles are followed, and (iii) the obligation of confidentiality is maintained:
– Written explicit consent of the personal data subject
– Protection of public health
– Preventive medicine
– Execution of medical diagnosis, treatment, and care services,
– Planning and management of health services and their financing
- Processing of Special Categories of Personal Data Other Than Health and Sexual Life
Data within this scope will be possible with the explicit consent of the personal data subject or in cases stipulated by law.
5.3. Categorization of Personal Data Processed by Our Company
Personal Data Categories Processed by Asdenar
|
Personal Data Category |
Description |
Data Subject Category Related to the Relevant Personal Data |
|
Identity Information |
Including but not limited to full name, Turkish ID number, nationality, mother's/father's name, place of birth, date of birth, gender, and social security number; all information contained in documents such as driver's licenses, identity cards, and residence permits. |
Third Parties, Customers, Prospective Customers, Suppliers, Visitors, Job Applicants |
|
Contact Information |
Information such as phone number, address, email, fax number, website, and social media accounts. |
Customers, Prospective Customers, Job Applicants, Visitors, Suppliers |
|
Customer Information |
Our commercial activities and business within this scope |
Customers |
5.3. Categorization of Personal Data Processed by Our Company
|
Personal Data Categories Processed by Asdenar Personal Data Category |
Description |
Data Subject Category Related to the Relevant Personal Data |
|
Identity Information |
Including but not limited to full name, Turkish ID number, nationality, mother's/father's name, place of birth, date of birth, gender, and social security number; all information contained in documents such as driver's licenses, identity cards, and residence permits. |
Third Parties, Customers, Prospective Customers, Suppliers, Visitors, Job Applicants |
|
Contact Information |
Information such as phone number, address, email, fax number, website, and social media accounts. |
Customers, Prospective Customers, Job Applicants, Visitors, Suppliers |
|
Customer Information |
Our commercial activities and business within this scope information obtained and generated about the relevant person as a result of the operations carried out by our units
|
Customers |
|
|
||
|
Customer Transaction Information |
Information such as records regarding the use of our products and services, as well as instructions and requests necessary for the customer's use of these products and services. |
Customers |
|
Supplier, Prospective Supplier |
Information required for the provision of the product or service |
Supplier, Prospective Supplier |
|
Transaction Security Information |
Personal data processed to ensure technical, administrative, legal, and commercial security during the conduct of Asdenar's commercial activities |
Customers, Visitors, Suppliers |
|
Risk Management Information |
Personal data processed through methods used in accordance with generally accepted legal, commercial practices, and integrity rules to manage our commercial, technical, and administrative risks |
Customers |
|
Financial Information |
Personal data processed regarding information, documents, and records showing all kinds of financial results created according to the type of legal relationship established with the personal data subject |
Customers, Suppliers |
|
Job Applicant Information |
Personal data processed regarding individuals who have applied to become an Asdenar employee, have been evaluated as a job candidate in line with our company's human resources needs in accordance with commercial practices and integrity rules, or are in a working relationship with Asdenar. |
Job Candidates |
|
Prospective Intern Information |
Personal data processed regarding individuals who have applied to become an Asdenar intern, have been evaluated as an intern candidate in line with our company's human resources needs in accordance with commercial practices and integrity rules, or are in a working relationship with Asdenar. |
Intern Candidates |
|
Security Information |
Personal data related to camera recording and the retention of these records by Asdenar for security purposes, |
Visitors, |
|
Legal Proceedings and Compliance Information |
Personal data processed within the scope of the determination and pursuit of our legal claims and rights, and the fulfillment of our obligations |
Customers, Suppliers, Third Parties (Enforcement Debtors, etc.) |
|
Audit, Inspection, and Compliance Information |
Personal data processed within the scope of Asdenar's legal obligations and compliance with company policies |
Customers, Job Candidates, Visitors, Suppliers |
|
Special Categories of Personal Data |
As specified in Article 6 of the PDPL (Personal Data Protection Law); data concerning individuals' race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance, membership to associations, foundations or unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data, blood type, health information, and religion. |
Suppliers, Visitors |
|
|
||
|
Marketing Information |
Personal data processed for the purpose of customizing and marketing our products and services in accordance with the personal data owner's usage habits, preferences, and needs, as well as reports and evaluations created as a result of this processing |
Customers, Prospective Customers |
|
Request / Complaint Management Information |
Personal data related to the receipt and evaluation of any kind of request or complaint directed to Asdenar. |
Customers, Job Candidates, Visitors, Third Parties |
- Ensuring the Security and Confidentiality of Personal Data
In accordance with Article 12 of the Personal Data Protection Law (KVKK), our company takes all necessary technical and administrative measures to ensure an appropriate level of security to prevent the unlawful processing of and unauthorized access to the personal data it processes, and to ensure the preservation of personal data.
6.1. Technical Measures Taken to Ensure Lawful Processing of Personal Data and Prevent Unlawful Access
Asdenar has taken all kinds of technical and technological security measures to protect personal data and has secured personal data against potential risks.
For this purpose;
– It takes technical measures to the extent permitted by technology,
– It employs experts in technical matters and/or receives external services in these areas,
– It conducts audits at regular intervals regarding the implementation of the measures taken,
– It establishes the necessary software and infrastructure to ensure security,
– It restricts access to data processed within Asdenar,
– It uses a backup program in accordance with the law to ensure that personal data is stored securely,
– It uses software that includes virus protection systems.
6.2. Administrative Measures Taken to Ensure Lawful Processing of Personal Data and Prevent Unlawful Access
– Training and raising awareness among company employees regarding the PDPL (Personal Data Protection Law),
– Ensuring that in cases involving personal data transfer, a clause is added to contracts concluded with the parties to whom personal data is transferred, stating that the receiving party will fulfill data security obligations,
– Identifying the requirements for compliance with the PDPL and preparing internal procedures for their implementation.
6.3. Measures to be Taken in Case of Unlawful Disclosure of Personal Data Measures
In the event that processed personal data is obtained by others through unlawful means, our Company will notify the relevant data subject and the PDPL Board as soon as possible.
- Purposes of Processing and Retention Periods of Personal Data
7.1. Purposes of Processing Personal Data
Personal data is processed within our Company for the purposes listed below:
– Creating and conducting test requests from customers,
– Carrying out shareholder tracking procedures, determining general assembly participants, and performing registration procedures,
– Performing goods acceptance procedures, entering material identification and notifications into the system, tracking goods and services procurement, and tracking transport companies,
– Receiving customer orders and having customers fill out evaluation survey forms,
– Tracking customers and entering customer information into the system, and conducting customer performance discount studies,
– Tracking subcontractor progress payments, tracking subcontractor payments, and tracking subcontractors,
– Investigating suspicious individuals who are prospective suppliers,
– Managing supplier registration and audits, collecting necessary documents for tenders, and conducting financial analysis of suppliers,
– Providing insurance and financing services, and performing necessary procedures for business maintenance,
– Carrying out necessary procedures for the collection of our receivables, including but not limited to mail order,
– Issuing invoices for our services and delivering e-archive invoices to the e-mail addresses you have provided to us,
– Procuring technological services for matters not directly provided by us and outside our area of expertise,
– Establishing financial reconciliation regarding our products and services with our business partners and/or third parties,
– Executing processes related to job candidates,
– Executing processes related to intern candidates,
– Executing/tracking financial reporting and risk management operations,
– Executing/tracking legal affairs and transactions,
– Planning and executing audit activities necessary to ensure that operations are carried out in accordance with our company procedures and relevant legislation,
– Providing information to authorized institutions and organizations as required by legislation,
– Planning and executing corporate sustainability activities,
– Carrying out activities aimed at protecting our company's reputation,
– Management of request and complaint processes,
– Planning and execution of corporate management and communication activities,
– Creation and tracking of visitor records,
– Controlling workplace entries and exits and collecting fingerprints to ensure security,
– Keeping security camera recordings to create security logs.
7.2. Personal Data Retention Periods
Our Company determines whether a period is stipulated in the relevant legislation for the storage of personal data. If a period is stipulated in the relevant legislation, it complies with this period; if no period is stipulated, it retains personal data for the period necessary for the purpose for which they are processed. Once the purpose of processing personal data has ended and the retention periods determined by the relevant legislation and/or our Company have expired, they may only be stored for the purpose of serving as evidence in possible legal disputes, asserting the rights related to the personal data, or establishing a defense. Our Company does not store personal data based on the possibility of future use.
- Deletion, Destruction, and Anonymization of Personal Data
In accordance with Article 7 of the PDPL (Personal Data Protection Law), even if personal data has been processed in accordance with the relevant legislation, if the reasons requiring its processing cease to exist, the personal data shall be deleted, destroyed, or anonymized by our Company, either ex officio or upon the request of the personal data owner.
The procedures and principles regarding this matter shall be carried out in accordance with the PDPL and the secondary legislation that forms the basis for this Law.
8.1. Techniques for Deletion and Destruction of Personal Data
Personal data processed within our Company, in accordance with the Regulation on the Deletion, Destruction, or Anonymization of Personal Data;
- i) Making personal data inaccessible and unusable in any way for the relevant users (deletion of personal data),
- ii) Making personal data inaccessible, unrecoverable, and unusable for the relevant users (destruction of personal data),
Will be securely deleted from systems physically for the purpose.
8.2. Techniques for Anonymization of Personal Data
This refers to making personal data such that it can in no way be associated with an identified or identifiable natural person, even when matched with other data. Within the scope of the PDPL and relevant legislation, secure methods including, but not limited to, masking, data derivation, and pseudonymization will be used in the anonymization of personal data.
- Third Parties to Whom Personal Data is Transferred and Purposes of Transfer
The procedures and principles to be applied in personal data transfers are regulated in Articles 8 and 9 of the PDPL, and the personal data and sensitive personal data of the personal data owner may be transferred to third parties domestically and abroad. For the fulfillment of its services, your personal data may be processed by Asdenar, including but not limited to cases required by the Law and other legislation, other regulations related to laws, regulations of supervisory and regulatory institutions and organizations, and public authorities.
9.1. Transfer of Personal Data Within the Country
In accordance with Article 8 of the PDPL (Personal Data Protection Law), the transfer of personal data within the country shall be possible provided that one of the conditions specified in Section 6 of this Policy, titled "Conditions for Processing Personal Data," is met.
9.2. Transfer of Personal Data Abroad
In accordance with Article 9 of the PDPL, in the event that personal data is transferred abroad, in addition to meeting the conditions for domestic transfers, the existence of one of the following circumstances is required:
– The country to which the transfer will be made is among the countries declared by the PDPL Board to have adequate protection, or
– In the absence of adequate protection in the country to which the transfer will be made, the data controllers in Turkey and the relevant foreign country must commit to adequate protection in writing, and the authorization of the PDPL Board must be obtained.
9.3. Categories of Persons to Whom Personal Data is Transferred by Our Company
Our Company may transfer the personal data of personal data subjects within the scope of this Policy, in accordance with Articles 8 and 9 of the PDPL, to the following categories of persons within the framework of the specified purposes:
|
CATEGORIES OF PERSONS |
DEFINITION |
PURPOSE OF TRANSFER |
|
Public Institutions and Organizations |
Public institutions and organizations that request information and documents from our Company in accordance with the provisions of the relevant legislation |
Limited to the purpose requested by the relevant public institutions and organizations |
|
Private Law Entities |
Private legal entities that request and receive information and documents from our Company in accordance with the provisions of the relevant legislation. |
Limited to the purpose requested by the relevant private legal entities. |
- Our Company's Disclosure Obligation
In accordance with Article 10 of the Personal Data Protection Law (KVKK), our Company must inform personal data owners during the collection of personal data. In this context, our Company fulfills its obligation to inform regarding the following matters:
- The title of our Company in the capacity of data controller,
- The purpose for which personal data will be processed,
- To whom and for what purpose the processed personal data may be transferred,
- The method and legal basis for collecting personal data,
- The rights of the personal data subject.
- Rights of Personal Data Subjects and Exercising These Rights
In accordance with Article 13 of the KVKK, the evaluation of the rights of personal data owners and the necessary information provided to them are carried out through the Asdenar Data Subject Application Form, in addition to this Policy. Personal data owners may submit their complaints or requests regarding the processing of their personal data to us within the framework of the principles specified in the relevant form.
11.1. Right to Apply
In accordance with Article 11 of the KVKK, anyone whose personal data is processed may apply to our Company and make requests regarding the following issues concerning themselves:
- To learn whether their personal data has been processed,
- To request information if their personal data has been processed,
- To learn the purpose of processing their personal data and whether they are used in accordance with their purpose,
- To learn the third parties to whom their personal data is transferred domestically or abroad,
- To request the correction of their personal data in case it is processed incompletely or incorrectly and to request that the transaction made within this scope be notified to the third parties to whom the personal data has been transferred,
- To request the deletion, destruction, or anonymization of their personal data in the event that the reasons requiring the processing of their personal data disappear, and to request that the transaction made within this scope be notified to the third parties to whom the personal data has been transferred,
- To object to the emergence of a result against the data subject by analyzing the processed data exclusively through automated systems,
- To request compensation for damages in the event that personal data is processed unlawfully.
11.2. Situations Outside the Scope of the Right to Apply
Pursuant to Article 28 of the KVKK, it will not be possible for personal data owners to assert their rights in the following cases:
- The processing of personal data by natural persons within the scope of activities related solely to themselves or their family members living in the same residence, provided that it is not disclosed to third parties and that obligations regarding data security are complied with,
- The processing of personal data for purposes such as research, planning, and statistics by making them anonymous with official statistics.
- The processing of personal data for artistic, historical, literary, or scientific purposes, or within the scope of freedom of expression, provided that it does not violate national defense, national security, public security, public order, economic security, the privacy of private life, or personal rights, and does not constitute a crime.
- The processing of personal data within the scope of preventive, protective, and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public security, public order, or economic security.
- The processing of personal data by judicial authorities or enforcement agencies regarding investigation, prosecution, trial, or execution proceedings.
Pursuant to the second paragraph of Article 28 of the KVKK, it will not be possible for data subjects to assert their rights, except for the right to demand compensation for damages:
- The necessity of personal data processing for the prevention of crime or for criminal investigation.
- The processing of personal data that has been made public by the data subject themselves.
- The necessity of personal data processing for the execution of supervisory or regulatory duties and disciplinary investigations or prosecutions by authorized and commissioned public institutions and organizations and professional organizations with public institution status, based on the authority granted by law.
- The necessity of personal data processing for the protection of the State's economic and financial interests regarding budget, tax, and financial matters.
11.3. Procedure for Responding
In accordance with Article 13 of the KVKK, our Company will conclude the application requests made by the personal data owner free of charge as soon as possible and within 30 (thirty) days at the latest, depending on the nature of the request.
The personal data owner's application may be rejected in the following cases:
- Preventing the rights and freedoms of others,
- Requiring disproportionate effort,
- The information being publicly available,
- Endangering the privacy of others,
- The existence of one of the situations excluded from the scope of the PDPL (Personal Data Protection Law).
- Personal Data Processing Activities Conducted Within the Company and Data Processing Activities Conducted on the Website
12.1. Camera Surveillance and Fingerprinting Within the Company
Camera surveillance and fingerprinting processes are carried out within our Company to protect the interests of our Company and other individuals regarding ensuring safety.
In line with the regulations in the KVKK, this Policy is published on our website regarding the camera surveillance activity carried out by our Company, and a notification sign indicating that surveillance is being conducted is posted at the entrances of the areas where surveillance takes place.
Monitoring does not take place in areas that could result in an infringement of personal privacy. Security camera footage can only be accessed by a limited number of our Company employees and, if necessary, by employees of the security company acting as a supplier. The individuals with access to the records declare that they will protect the confidentiality of the data they access through the confidentiality agreements they have signed.
12.2. Customer/Visitor Entry-Exit at the Company
Personal data processing activities are carried out to track the entry and exit of guests visiting our company. While the name, surname, telephone number, Turkish ID number, and e-mail address information of individuals coming to our company are obtained, this data is processed solely for this purpose and the relevant personal data is recorded in the recording system in a physical environment.
12.3. Website Visitors
Internet activity within the site is recorded (via technical means such as cookies) to ensure that visitors to our company's website can perform their visits in a manner appropriate to their purposes, to show them customized content, and to engage in online advertising activities. Detailed explanations regarding these activities of our company are included in the Privacy Policy texts on our website.
This Policy may be revised by Asdenar when deemed necessary. In cases where a revision is made, the most current version of the Policy will be published on the Company's website.
ASDENAR Project Consultancy Architecture Engineering Technical Inc.