PERSONAL DATA PROTECTION AND PROCESSING POLICY
The Personal Data Protection Law No. 6698 (“Law”) came into effect on April 7, 2016, and regulates the processing of all information relating to “identified or identifiable real persons.”
This Personal Data Protection and Processing Policy (“Policy”) of Tiryaki Agro Gıda San. ve Tic. A.Ş. and its affiliates and subsidiaries outlines the statements and explanations regarding the processing of personal data of real persons by Tiryaki Agro and its affiliated companies under the scope of the Law.
Scope of the Policy: The processing of personal data belonging to the following data subjects:
- Intern
- Family Member
- Executive
- Job Applicant
- Subcontractor
- Supplier
- Blue-Collar Employee
- White-Collar Employee
- Consultant
- Press
- Outsource Partner
- Companion
- Visitor
- Customer
- Former Employee
- Company Shareholder
- Third Party
- Service Providers
This Policy may be updated from time to time to comply with changing conditions and legislation.
1. PRINCIPLES REGARDING THE PROCESSING OF PERSONAL DATA
Tiryaki Agro Gıda San. ve Tic. A.Ş. and its affiliates act in accordance with the following principles when processing personal data:
Lawfulness and Fairness
Personal data is processed in compliance with applicable legislation and principles of fairness.
Accuracy and Currency
Necessary processes are established to ensure that data is accurate and up to date.
Processing for Specific, Clear, and Legitimate Purposes
Data subjects are clearly informed about the purposes for which their personal data is processed.
Purpose-Related, Limited, and Proportional Processing
Personal data is processed only in connection with the declared purposes and to the necessary extent.
Retention for the Required Period
Data is retained for a reasonable period in accordance with legislation or the purpose of processing, after which it is deleted, destroyed, or anonymized.
2. PURPOSES OF PERSONAL DATA PROCESSING
Tiryaki Agro and its affiliates process personal data for the following purposes:
- Managing the application, selection, and evaluation processes of personnel candidates
- Fulfilling legal obligations
- Conducting communication activities with business partners/public institutions
- Tracking employees and visitors entering the company
- Managing system and application access
- Operating information technology processes
- Customer relationship management
- Reporting and organizational activities
3. TRANSFER OF PERSONAL DATA
Personal data may be transferred to third parties under Article 8 of the Law in the following cases:
- Explicit consent of the data subject
- Explicitly stipulated by law
- Necessity to protect life or bodily integrity
- Directly related to the establishment or performance of a contract
- To fulfill the data controller’s legal obligations
- Publicly disclosed by the data subject
- Necessary for establishing, exercising, or protecting a right
- Processed within legitimate interests without causing harm
International Transfer:
Data can be transferred to countries with adequate protection or to countries providing a protection commitment with the approval of the Personal Data Protection Board (KVKK).
Possible Recipients of Data:
- Suppliers
- Business partners
- Authorized public institutions
- Private individuals and organizations
4. RETENTION PERIODS OF PERSONAL DATA
Data is retained for the period determined in accordance with applicable legislation and the purpose of processing. Once the purpose is fulfilled, the data is deleted, destroyed, or anonymized.
5. RIGHTS OF DATA SUBJECTS
Under Article 11 of the Law, data subjects have the following rights:
- Learn whether their personal data is processed
- Request information if processed
- Learn whether their data is used for its intended purpose
- Know the third parties to whom the data is transferred
- Request correction of incomplete or inaccurate data
- Request deletion or destruction of personal data
- Request notification of correction/deletion to third parties
- Object to automated processing
- Claim compensation for damages caused by unlawful processing
Applications can be submitted to Tiryaki Agro via the Personal Data Subject Application Form in person, through a notary, or via KEP (Registered Electronic Mail) address. The response time is 30 days. The fee schedule determined by the KVKK may apply.
6. PROTECTION OF PERSONAL DATA
Tiryaki Agro and its affiliates take technical and administrative measures to ensure the security of personal data:
- Maintaining access logs
- Firewalls and antivirus systems
- Monitoring data processing activities
- Internal policy and procedure audits
- Access authorization and additional measures for sensitive data
- Compliance commitments from external service providers
- Employee awareness training
7. INTERNAL GOVERNANCE STRUCTURE
A Personal Data Protection Committee has been established. The committee’s responsibilities include:
- Preparing and implementing policies and procedures
- Conducting audits
- Raising awareness
- Resolving data subject applications
- Managing relations with the Personal Data Protection Authority
Appendix-1: Categories of Personal Data
| Category | Description |
|---|---|
| Identity Information | Driver’s license, national ID card, residence certificate, passport, diploma, marriage certificate, Turkish ID number (TCKN), passport number, ID card serial number, full name, place of birth, date of birth, registered place of residence, occupation information, photocopy of ID card/driver’s license |
| Contact Information | Email, home phone, mobile phone, address, Registered Electronic Mail (KEP) address, residence certificate |
| Location Data | Customer Turkish ID Number (TCKN), customer occupation information, vehicle license plate, vehicle-related information, insurance policy number |
| Personnel/Employment Information | All types of information and documents collected when creating a personnel file as required by law |
| Financial Information | Loan amount, loan repayments, interest amount and rate, debt balance, receivable balance, and file information if involved as a debtor in enforcement proceedings |
| Employee Information | Employee ID, usernames, passwords, login/logout records, performance evaluation reports, interviews and their results, personality assessments, skills and knowledge tests, training/course information, leave records, performance KPIs |
| Log Information | Records of users’ internet activity, digital and biometric entry-exit logs of the company |
| Marketing Information | Targeting information, cookie records, data enrichment activities, satisfaction surveys |
| Reputation Management Information | Comments about company executives in the media and on social media, and the actions taken based on them |
| Complaint Management Information | Complaints, suggestions, and outcomes related to products and services |
| Legal Information | CAll types of information and documents regarding lawsuits filed by or against the company |
| Sensitive Personal Data | Data related to a person’s race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, clothing and appearance, membership in associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, biometric and genetic data |