Personal Data Storage and Disposal Policy

YATAY KAPI PENCERE VE SİNEKLİKLERİ İTH. İMAL. İÇ VE DIŞ TİC. LTD.ŞTİ

PERSONAL DATA STORAGE AND DISPOSAL POLICY

 

PART 1: NATURE AND PURPOSE OF THE DISPOSAL POLICY

1.1. Introduction

This disposal policy was prepared for the purpose of determining the procedures and principles to be applied by the Company regarding the deletion, disposal or anonymization of personal data we YATAY KAPI PENCERE VE SİNEKLİKLERİ İTH. İMAL. İÇ VE DIŞ TİC. LTD.ŞTİ İ, briefly (“Company”) store as data controller in accordance with the Personal Data Protection Law No. 6698 and other legislation.

In this context, the personal data of our employees, employee candidates, customers and all real persons who have personal data with the Company for any reason are managed in accordance with the laws within the framework of the Personal Data Processing and Protection Policy and this Personal Data Storage and Disposal Policy.

1.2. DEFINITIONS

Direct identifiers : Identifiers that, by themselves, directly reveal, disclose and distinguish the person with whom they are in a relationship,
Indirect identifiers : Identifiers that come together with other identifiers, revealing, disclosing and making distinguishable the person they are in a relationship with,
Related person : The real person whose personal data is processed,
Disposal : Deletion, disposal or anonymization of personal data,
Law : Law on Protection of Personal Data No. 6698 published in the Official Gazette dated 07.04.2016 and numbered 29677,
Regulation : Regulation on the Deletion, Disposal or Anonymization of Personal Data published in the Official Gazette dated 28.10.2017 and numbered 30224
Board : Personal Data Protection Board
Recording media : Any environment where personal data is processed wholly or partially automatically or non-automatically provided that it is a part of any data recording system,
Personal Data Processing and Protection Policy : The policy that determines the procedures and principles regarding the management of personal data held by the company, which can be accessed on our websites www.sinax.com.tr and www.sinekliksistemleri.com.tr,
Data logging system : The registration system in which personal data is processed and structured according to certain criteria,

 

PART 2: ENVIRONMENTS AND SAFETY PRECAUTIONS

2.1. ENVIRONMENTS WHERE PERSONAL DATA IS STORED

Personal data stored with the company are kept in a recording environment in accordance with the nature of the data and our legal obligations.

The recording media used for the storage of personal data are generally listed below. However, some data may be kept in a different environment than the ones shown here, due to their special qualities or our legal obligations. In any case, the company acts as a data controller and processes and protects personal data in accordance with the Law, the Personal Data Processing and Protection Policy and this Personal Data Storage and Disposal Policy.

 

 

 

 

 

 

a) Printed media : They are media where data is kept by printing on paper or microfilms.
b) Local digital media : Other digital media such as servers, fixed or portable disks, optical disks within the company.
c) Cloud environments : They are environments where internet-based systems encrypted with cryptographic methods are used, which are not included in the company, but are in the use of the company.

2.2. ENSURING THE SAFETY OF ENVIRONMENTS

The Company takes all necessary technical and administrative measures in accordance with the characteristics of the relevant personal data and the environment in which it is kept, in order to keep personal data safe and to prevent unlawful processing and access.

These measures include, but are not limited to, the following administrative and technical measures to the extent that they comply with the nature of the personal data and the environment in which it is kept.

2.2.1. Technical and Administrative Measures

The data security measures taken by the aforementioned data controller for the security of the personal data they process are listed below.

The company takes the following technical and administrative measures in accordance with the characteristics of all environments where personal data is stored and the environment in which the data is kept:

  • Network security and application security are provided.
  • A closed system network is used for personal data transfers via the network.
  • Key management is implemented.
  • Security measures are taken within the scope of procurement, development and maintenance of information technology systems.
  • The security of personal data stored in the cloud is ensured.
  • There are disciplinary regulations that include data security provisions for employees.
  • Training and awareness activities are carried out periodically for employees on data security.
  • An authorization matrix has been created for employees.
  • Access logs are kept regularly.
  • Institutional policies on access, information security, use, storage and disposal have been prepared and started to be implemented.
  • Data masking is applied when necessary.
  • Confidentiality commitments are made.
  • The authorizations of employees who have a change in duty or quit their job in this field are removed.
  • Current anti-virus systems are used.
  • Firewalls are used.
  • The signed contracts contain data security provisions.
  • Extra security measures are taken for personal data transferred via paper and the relevant document is sent in confidential document format.
  • Personal data security policies and procedures have been determined.
  • Personal data security issues are reported quickly.
  • Personal data security is monitored.
  • Necessary security measures are taken regarding entry and exit to physical environments containing personal data.
  • The security of physical environments containing personal data against external risks (fire, flood, etc.) is ensured.
  • The security of environments containing personal data is ensured.
  • Personal data is reduced as much as possible.
  • Personal data is backed up and the security of the backed up personal data is also ensured.
  • User account management and authorization control system is implemented and these are also followed.
  • In-house periodic and/or random audits are conducted and made.
  • Log records are kept without user intervention.
  • Existing risks and threats have been identified.
  • Protocols and procedures for special quality personal data security have been determined and implemented.
  • If sensitive personal data is to be sent via e-mail, it must be sent in encrypted form and using a KEP or corporate mail account.
  • Secure encryption / cryptographic keys are used for sensitive personal data and are managed by different units.
  • Intrusion detection and prevention systems are used.
  • Cyber security measures have been taken and their implementation is constantly monitored.
  • Encryption is performed.
  • Data processing service providers are periodically audited on data security.
  • Awareness of data processing service providers on data security is ensured.

 

2.2.3. Internal Audit

  • The company conducts internal audits regarding the implementation of the provisions of the Law and the provisions of this Personal Data Storage and Disposal Policy and Personal Data Processing and Protection Policy in accordance with Article 12 of the Law.
  • If deficiencies or defects regarding the implementation of these provisions are detected as a result of internal audits, these deficiencies or faults are immediately corrected.
  • In case it is understood that the personal data that is under the responsibility of the Company, during the audit or otherwise, has been obtained by others illegally, the Company notifies the relevant person and the Board as soon as possible.

PART 3: DISPOSAL OF PERSONAL DATA

3.1. REASONS FOR STORAGE AND DISPOSAL

3.1.1. Reasons for Storage

Personal data kept within the company are stored in accordance with the Law and our Personal Data Policy (you can access the relevant policy at www.sinax.com.tr and www.sinekliksistemleri.com.tr for the purposes and reasons stated here.

3.1.2. Reasons for Disposal

  • Personal data within the company are deleted, destroyed or anonymized ex officio in accordance with this disposal policy, upon the request of the person concerned or if the reasons listed in Articles 5 and 6 of the Law are eliminated.
  • The reasons listed in Articles 5 and 6 of the Law consist of the following:
  • it is clearly provided for by the laws.
  • it is mandatory for the protection of life or physical integrity of the person or of any other person who is bodily incapable of giving his consent or whose consent is not deemed legally valid.
  • processing of personal data belonging to the parties of a contract, is necessary provided that it is directly related to the conclusion or fulfilment of that contract. ç) it is mandatory for the controller to be able to perform his legal obligations.
  • the data concerned is made available to the public by the data subject himself.
  • data processing is mandatory for the establishment, exercise or protection of any right.
  • it is mandatory for the legitimate interests of the controller, provided that this processing shall not violate the fundamental rights and freedoms of the data subject.

3.2. DISPOSAL METHODS

The Company deletes, destroys, or ex officio, the personal data it has stored in accordance with the Law and other legislation and the Policy on the Processing and Protection of Personal Data, upon the request of the person concerned or within the periods specified in this Personal Data Storage and Disposal Policy, in case the reasons requiring the processing of the data disappear, or makes it anonymous.

The most commonly used deletion, dısposal and anonymization techniques are listed below:

3.2.1.1 Deletion Methods

Deletion Methods for Personal Data Held in Printed Media
Darkening : Personal data in the printed media are deleted using the darkening method. The darkening process is done by cutting the personal data on the relevant document when possible, and making it invisible by using fixed ink in a way that it cannot be readable with technological solutions, in cases where it is not possible.
Deletion Methods for Personal Data Stored in Cloud and Local Digital Environment
Secure deletion from software : Personal data kept in the cloud or local digital environments are deleted with a digital command, irrecoverably. Data deleted in this way cannot be accessed again.

3.2.1.2 Disposal Methods

Disposal Methods for Personal Data Held in Printed Media
Physical disposal : Documents kept in print media are destroyed by the paper shredder so that they cannot be reorganized.
Disposal Methods for Personal Data Held in Local Digital Environment
Physical Disposal : It is a physical disposal process such as melting, burning or pulverizing optical and magnetic media containing personal data. Data is rendered inaccessible by processes such as melting, incinerating, pulverizing, or passing through a metal grinder to optical or magnetic media.
De-magnetizing (degauss) : It is the process of unreadable corruption of the data on the magnetic media by exposing it to a high magnetic field.
Overwriting : Random data consisting of 0s and 1s is written at least seven times on magnetic media and rewritable optical media, preventing the reading and recovery of old data.
Disposal Methods for Personal Data Stored in the Cloud
Safe deletion from software : Personal data kept in the cloud is irrecoverably deleted by digital command, and when the cloud computing service relationship ends, all copies of encryption keys required to make personal data usable are disposed. Data deleted in this way cannot be accessed again.

 

3.2.1.3. Anonymization Methods

Anonymization is making personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching it with other data.

Removing variables : It is the removal of one or more of the direct identifiers included in the personal data of the data subject and which will help to identify the person concerned in any way.

While this method can be used to anonymize personal data, it can also be used for deletion of personal data if there is information that is not suitable for the purpose of data processing.

Regional hiding : It is the process of deleting the information that may be distinctive about the exceptional data in the data table in which the personal data is collected in an anonymous form.
Generalization : It is the process of bringing together the personal data of many people and turning them into statistical data by removing their distinctive information.
Lower and upper bound coding / Global coding : For a certain variable, the ranges of that variable are defined and categorized. If the variable does not contain a numeric value, then close data in the variable are categorized.

Values within the same category are combined.

Micro combination : With this method, all the records in the data set are first arranged in a meaningful order and then the whole set is divided into a certain number of subsets Then, by taking the average of the value of each subset of the determined variable, the value of that variable of the subset is replaced with the mean value. In this way, since the indirect identifiers in the data will be corrupted, it is difficult to associate the data with the relevant person.
Data hashing and disrupting : Direct or indirect identifiers in personal data are mixed with other values or their relationship with the person concerned is broken and they lose their descriptive qualities.

The company uses one or more of these anonymization methods, depending on the nature of the data, in order to anonymize personal data. The firm may use K-Anonymity, L-Diversity and T-Closeness statistical methods while using these anonymization methods.

 

 

 

 

 

 

 

 

3.3. DURATION OF STORAGE AND DISPOSAL

3.3.1. Storage Durations

Data Category Data Storage Period Data Category Data Storage Period
1- Identity Legal Business Relationship + 10 9- Risk management Legal Business Relationship + 10
2- Communication Legal Business Relationship + 10 10- Finance Legal Business Relationship + 10
3- Location Legal Business Relationship + 10 11- Professional experience Legal Business Relationship + 10
4- Briefness Legal Business Relationship + 10 12- Marketing Legal Business Relationship + 10
5- Legal action Legal Business Relationship + 10 13- Audio and Visual Records Legal Business Relationship + 10
6- Customer Transaction Legal Business Relationship + 10 21- Health Information Legal Business Relationship + 15
7- Physical Space Security 30 days 23- Criminal Conviction and Security Measures Legal Business Relationship + 10
8- Transaction Security Legal Business Relationship + 10

 

3.3.2.   Durations of Disposal

  • The company deletes and destroys personal data in the first periodical disposal process following the date on which the obligation to delete, dispose of or anonymize personal data for which it is responsible in accordance with the Law, relevant legislation, Personal Data Processing and Protection Policy and this Personal Data Storage and Disposal Policy. or make it anonymous.
  • When the person concerned requests the deletion or dısposal of his/her personal data by applying to the Company pursuant to Article 13 of the Law;
  • If all the conditions for processing personal data have disappeared; the company deletes, disposes or anonymizes the personal data subject to the request with the appropriate Dısposal method, explaining the reason within 30 (thirty) days from the day it receives the request.  In order for the company to be deemed to have received the request, the person concerned must have made the request in accordance with the Personal Data Processing and Protection Policy. In any case, the company informs the person concerned about the transaction.
  • If all the conditions for processing personal data have not been eliminated, this request may be rejected by the company by explaining the reason in accordance with the third paragraph of Article 13 of the Law and the refusal is notified to the relevant person in writing or electronically within thirty days at the latest.

3.4. PERIODIC DISPOSAL

In the event that all the conditions for the processing of personal data in the law are eliminated; The company deletes, disposes or anonymizes the personal data whose processing conditions have been eliminated, through a process to be carried out ex officio at repetitive intervals and specified in this Personal Data Storage and Disposal Policy.

Periodic Dısposal processes start for the first time on 30.06.2021 and repeat every 6 (six) months.

3.5. AUDIT OF LEGAL COMPLIANCE OF DISPOSAL

The company performs the disposal processes, which it performs ex officio, both on request and in periodic dısposal processes, in accordance with the Law, other legislation, the Policy on the Processing and Protection of Personal Data and this Personal Data Storage and Dısposal Policy.

The company takes a number of administrative and technical measures to ensure that disposal operations are carried out in accordance with these regulations.

3.5.1. Technical Measures

  • The company maintains technical tools and equipment suitable for each disposal method in this policy.
  • The company ensures the safety of the place where the disposal operations are carried out.
  • The company keeps the access records of the people who do the disposal.
  • The company employs competent and experienced personnel to carry out disposal operations or receives services from competent third parties when necessary.

3.5.2. Administrative Measures

  • The company works to increase the awareness and raise awareness of its employees who will carry out disposal transactions on information security, personal data and privacy.
  • The company receives legal and technical consultancy services to follow the developments in information security, privacy, protection of personal data and safe disposal techniques and to take necessary actions.
  • In cases where the company outsources the disposal to third parties due to technical or legal requirements, it signs protocols with the relevant third parties for the protection of personal data, and takes all necessary care to ensure that the relevant third parties comply with their obligations in these protocols.
  • The company regularly checks whether the disposal transactions are carried out in accordance with the law and the conditions and obligations specified in this Personal Data Storage and Disposal Policy, and takes the necessary actions.
  • The company records all transactions related to the deletion, disposal and anonymization of personal data and keeps these records for at least three years, excluding other legal obligations.

 

PART 4: PERSONAL DATA COMMITTEE

  • Establishes a Personal Data Committee within the company. The Personal Data Committee is authorized and in charge of taking the necessary actions and supervising the processes for the storage and processing of the data of the persons concerned in accordance with the law, the Personal Data Processing and Protection Policy and the Personal Data Storage and Disposal Policy.
  • The Personal Data Committee consists of three people, a manager, an administrative expert and a technical expert. The titles and job descriptions of the Company employees working in the Personal Data Committee are as follows:
Title Job Description
Personal Data Committee Manager : To direct all kinds of planning, analysis, research and risk determination studies in the projects carried out in the process of compliance with the law; It is obliged to manage the processes to be carried out in accordance with the Law, the Personal Data Processing and Protection Policy and the Personal Data Storage and Disposal Policy and to decide on the requests received by the relevant persons.
Technical Specialist and Administrative Specialist : Reporting the requests of the persons concerned to the Personal Data Committee Manager for review and evaluation; Fulfillment of the transactions regarding the requests of the persons evaluated and decided by the Personal Data Committee Manager in accordance with the decision of the Personal Data Committee Manager; auditing the storage and disposal processes and reporting these audits to the Personal Data Committee Manager; Responsible for the execution of storage and disposal processes.

 

PART 5: STATE OF BEING PUBLIC

In the capacity of data controller, YATAY KAPI PENCERE VE SİNEK. İTH. İMAL. İÇ VE DIŞ TİC. LTD.ŞTİ. the issues are publicly available on the website of the PDP institution at www.verbis.kvkk.gov.tr, and it is possible for the Relevant Person / Data Owners to obtain information about

  • Which of the processed personal and special data are processed,
  • For what purposes it is processed,
  • With which recipient group it is shared,
  • For what time it is stored,
  • Which persons’ personal or private data are received and processed,
  • Whether or not transfers are made to foreign countries,
  • With what security measures it is stored

 

PART 6: UPDATE AND COMPLIANCE

The Company reserves the right to make changes in the Personal Data Processing and Protection Policy or this Personal Data Storage and Disposal Policy due to the changes made in the Law, in accordance with the decisions of the Institution or in line with the developments in the sector or in the field of informatics.

Changes made in this Personal Data Storage and Disposal Policy are immediately processed in the text and explanations regarding the changes are announced at the end of the policy.

 

Date of update: 01.07.2021

Revision NO: 21.001

 

YATAY KAPI PENCERE VE SİNEKLİKLERİ İTH. İMAL. İÇ VE DIŞ TİC. LTD.ŞTİ