PERSONAL DATA STORAGE AND DISPOSAL POLICY

This Personal Data Retention and Disposal Policy has been prepared by Beysu Global Enerji Anonim Şirketi, acting as the data controller, in order to fulfill obligations under the Personal Data Protection Law No. 6698 and the Regulation on the Deletion, Destruction, or Anonymization of Personal Data (which constitutes the secondary legislation of the Law), and to inform data subjects about the principles for determining the maximum retention period necessary for the purposes for which their personal data are processed, as well as the processes for deletion, destruction, and anonymization.

Definitions

Explicit Consent: Consent regarding a specific matter, based on information, and declared with free will.

Relevant User: Persons who process personal data within the data controller’s organization or based on authorization and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection, and backup of the data.

Disposal: The deletion, destruction, or anonymization of personal data.

Recording Medium: Any medium containing personal data that is processed either wholly or partially by automated means, or by non-automated means provided that it is part of a data filing system.

Personal Data: Any information relating to an identified or identifiable natural person.

Processing of Personal Data: Any operation performed on personal data—such as obtaining, recording, storing, preserving, altering, rearranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of the data—whether by fully or partially automated means or by non-automated means provided that the data forms part of a data filing system.

Anonymization of Personal Data: Rendering personal data in such a way that it can under no circumstances be associated with an identified or identifiable natural person, even when matched with other data.

Deletion of Personal Data: The process of rendering personal data inaccessible and unusable for Relevant Users.

Destruction of Personal Data: The process of rendering personal data inaccessible, irretrievable, and unusable by anyone.

Board: The Personal Data Protection Board.

Periodic Destruction: The process of deletion, destruction, or anonymization carried out *ex officio* at recurring intervals specified in the personal data storage and destruction policy, in the event that all conditions for the processing of personal data set forth in the Law cease to exist.

Data Subject/Relevant Person: The natural person whose personal data is processed.

Principles

The Company acts within the framework of the following principles regarding the storage and destruction of personal data:

  • Full compliance with the Law, relevant legislative provisions, Board decisions, and this Policy is observed in the deletion, destruction, and anonymization of personal data.
  • All actions taken regarding the deletion, destruction, and anonymization of personal data are recorded by the Company, and such records are retained for a period of at least 3 (three) years, subject to other legal obligations.
  • Unless a contrary decision is made by the Board, the Company selects the appropriate method among the options of deleting, destroying, or anonymizing personal data *ex officio*.

However, upon the request of the Data Subject, an appropriate method shall be selected, and the justification for that choice shall be explained.

  • In the event that all conditions for the processing of personal data set forth in Articles 5 and 6 of the Law cease to exist, the personal data shall be deleted, destroyed, or anonymized by the Company, either *ex officio* or upon the request of the Data Subject. In the event that the Data Subject submits a request to the Company regarding this matter:

– Submitted requests shall be answered within 30 (thirty) days at the latest,

– In the event that the data subject to the request has been transferred to third parties, such transfer shall be notified to the third party to whom the data was transferred, and it shall be ensured that the necessary actions are taken by said third parties.

Explanations Regarding Reasons for Retention and Destruction

Personal data belonging to data subjects is retained by the Company within the limits specified in the Law and other relevant legislation, particularly for the purposes of (i) sustaining commercial activities, (ii) fulfilling legal obligations, and (iii) planning and administering employee rights and fringe benefits. The reasons necessitating retention are as follows:

  • Retention of personal data because it is directly related to the establishment and performance of contracts,
  • Retention of personal data for the purpose of establishing, exercising, or protecting a right,
  • Necessity of retaining personal data for the Company’s legitimate interests, provided that this does not harm the fundamental rights and freedoms of individuals,
  • Retention of personal data for the purpose of fulfilling any legal obligation of the Company,
  • Explicit provision in legislation for the retention of personal data,
  • Existence of the data subjects’ explicit consent regarding retention activities that require such consent.

In accordance with the Regulation, personal data belonging to data subjects shall be deleted, destroyed, or anonymized by the Company—either ex officio or upon request—in the following cases:

  • Where necessary due to the amendment or repeal of relevant legislative provisions forming the basis for the processing or retention of personal data,
  • Where the purpose requiring the processing or retention of personal data ceases to exist,
  • Where the conditions requiring the processing of personal data under Articles 5 and 6 of the Law cease to exist,
  • Where the data subject withdraws their consent in cases where the processing of personal data is based solely on the condition of explicit consent,
  • Where the data controller accepts the application made by the data subject regarding the deletion, destruction, or anonymization of their personal data within the scope of the rights set forth in Article 11 of the Law,
  • Where the data controller [acts] upon the data subject’s request for the deletion, destruction, or anonymization of their personal data…

in the event that the application made to the data controller is rejected, the response provided is deemed insufficient, or no response is given within the period stipulated in the Law; a complaint is lodged with the Board and this request is found justified by the Board,

  • the absence of any condition justifying the continued retention of personal data, despite the expiration of the maximum period required for their retention.

Retention and Destruction Periods

The following criteria, listed in order, are utilized to determine the retention and destruction periods for your personal data obtained by the Company in accordance with the provisions of the Law and other relevant legislation:

  • If a retention period for the personal data in question is stipulated in the legislation, such period shall be observed. Upon the expiration of said period, the data shall be processed in accordance with the following clause.
  • In the event that the retention period stipulated in the legislation for the personal data in question expires, or if no retention period is stipulated in the relevant legislation for said data, the following steps shall be taken respectively;

– Personal data are classified as “personal data” and “personal data of special nature” based on the definitions set forth in Article 6 of the Law. All personal data determined to be of a special nature are destroyed. The method to be applied for the destruction of such data is determined based on the nature of the data and the degree of importance of its retention to the Company.

– The compliance of data retention with the principles specified in Article 4 of the Law is assessed—for instance, by questioning whether the Company has a legitimate purpose for retaining the data. Data determined to be retained in a manner that violates the principles set forth in Article 4 of the Law are deleted, destroyed, or anonymized.

– It is determined under which of the exceptions stipulated in Articles 5 and 6 of the Law the retention of the data falls. Reasonable retention periods for the data are established within the framework of the applicable exceptions. Upon the expiration of said periods, the data are deleted, destroyed, or anonymized.

– You may access the retention, destruction, and periodic destruction periods determined by the Company in the annex to this Policy. Personal data for which the retention period has expired are anonymized or destroyed at six-month intervals, in accordance with the procedures set forth in this Policy and within the framework of the destruction periods specified in the annex. All actions taken regarding the deletion, destruction, and anonymization of personal data are recorded, and such records are retained for a minimum of three years, subject to other legal obligations.

Procedures, Technical and Administrative Measures Regarding the Storage and Destruction of Personal Data

Personal data collected—whether to enable our Company to fulfill its employment-related obligations; because data processing is necessary to establish a right; to facilitate your use of customer services, consumer rights, and other benefits and/or to fulfill related commercial, financial, and legal responsibilities; to ensure the security of our Company; or because processing is required for our Company’s legitimate purposes—is entered into the Company’s data systems. Additionally, all data stored in digital format is recorded on the Company’s servers.

To ensure the secure storage of your personal data, prevent unlawful processing and unauthorized access, and ensure lawful data destruction, the Company has implemented the following administrative and technical measures in accordance with the principles set forth in Article 12 of the Law:

Administrative Measures:

As part of its administrative measures, the Company:

  • Limits internal access to stored personal data to only those personnel who require such access based on their job descriptions. When restricting access, the sensitive nature and level of importance of the data are taken into consideration.
  • In the event that processed personal data is obtained by third parties through unlawful means, the relevant data subject and the Board are notified of this situation as soon as possible.
  • Regarding the sharing of personal data, a framework agreement concerning personal data protection and data security is signed with the parties with whom the data is shared, or data security is ensured through provisions added to existing contracts.
  • Personnel who are knowledgeable and experienced in personal data processing are employed, and necessary training regarding personal data protection legislation and data security is provided to the staff.
  • Necessary audits are conducted—or caused to be conducted—to ensure compliance with the provisions of the Law within its own legal entity. Any privacy and security vulnerabilities identified during these audits are remedied.
  • Adequate security measures (against electrical faults, fire, flooding, theft, etc.) are implemented based on the environment where the personal data is stored, and unauthorized entry to or exit from these areas is prevented.

Technical Measures:

Within the scope of administrative measures, the Company…

  • Conducts necessary internal controls within the scope of established systems.
  • Manages the processes for conducting information technology risk assessments and business impact analyses within the scope of established systems.
  • Ensures the provision of technical infrastructure to prevent or monitor data leakage outside the organization and the creation of relevant matrices.
  • Ensures the monitoring of system vulnerabilities by procuring penetration testing services regularly and as needed.
  • Ensures that access rights to personal data held by information technology unit personnel are kept under control.
  • Ensures the destruction of personal data in a manner that renders it unrecoverable and leaves no audit trail.
  • Protects all digital environments where personal data is stored using encryption or cryptographic methods, in compliance with Article 12 of the Law, to meet information security requirements.
  • Ensures the secure logging of transaction records for all activities involving special categories of personal data.
  • Continuously monitors security updates for environments containing data and ensures that necessary security tests are conducted regularly.
  • In cases where special categories of personal data are accessed via software, manages user authorizations for said software and ensures regular security testing of the software.
  • Implements at least a two-factor authentication system for instances requiring remote access to special categories of personal data.
  • In cases where special categories of personal data are transferred:

– If data transfer via e-mail is required, ensures transfer in encrypted form using a corporate e-mail address or a Registered Electronic Mail (KEP) account,

– If data transfer via media such as portable drives, CDs, or DVDs is required, [ensures] cryptographic… …encryption using [appropriate] methods,

– Ensuring that transfers between servers located in different physical environments are conducted via a VPN connection established between the servers or through the sFTP method,

– Ensuring that, if data transfer in paper format is required, the documents are transmitted in accordance with the “classified documents” format.

Duties and Authorities of the Personal Data Protection Committee

The Personal Data Protection Committee is responsible for communicating the Policy to the relevant business units and monitoring compliance with its requirements. The Committee issues necessary announcements and notifications to ensure that relevant business units monitor—and, where necessary, update their business processes in light of—developments such as legislative changes regarding personal data protection, the Board’s regulatory actions and decisions, court rulings, or changes in processes, practices, and systems. Furthermore, the Committee establishes and communicates to the relevant units the processes for reviewing, evaluating, monitoring, and finalizing matters related to the Law, secondary regulations, Board decisions and regulations, court rulings, and decisions and/or requests from other competent authorities.

Implementation of the Policy, Violations, and Sanctions

  • This Policy shall enter into force upon being announced to all employees and shall be binding on all business units, consultants, external service providers, and any party processing personal data from the date of its entry into force.
  • Monitoring whether employees comply with the requirements of the Policy shall be the responsibility of the respective employees’ supervisors.

Upon detection of conduct violating the policy, the matter shall be immediately reported by the relevant employee’s supervisor to their own superior.

  • In the event of a significant violation, the superior shall inform the Personal Data Protection Committee without delay.
  • Following an assessment by Human Resources, necessary administrative action shall be taken regarding the employee who acted in violation of the policy.

Personal data shall be retained for the periods specified in the table below, taking into account the matters set forth in Article 4 of the Policy, and shall be anonymized or destroyed upon the expiration of said periods:

ProcessStorage PeriodDestruction Period
Data stored within the scope of the Labor Law (e.g. performance records, etc.)5 years following the termination of the employment relationship Within 180 days following the end of the storage period
Data collected within the scope of occupational health and safety legislation (health reports, etc.)15 years following the termination of the employment relationshipWithin 180 days following the end of the storage period
Data held within the scope of SSI legislation10 years following the termination of the employment relationshipWithin 180 days following the end of the storage period
Documents that can be used in a claim/lawsuit regarding work accident/occupational disease10 years following the termination of the employment relationshipWithin 180 days following the end of the storage period
Data collected in accordance with other relevant legislationFor the period stipulated in the relevant legislationWithin 180 days following the end of the storage period
The relevant personal data is subject to a crime within the scope of the Turkish Penal Code or other legislation imposing criminal provisionsDuring the statute of limitationsWithin 180 days following the end of the storage period
Customer data10 years from registrationWithin 180 days following the end of the storage period

If the Company’s purpose of using the relevant personal data has not expired, if the storage period foreseen for the relevant personal data in accordance with the relevant legislation is longer than the periods in the table, or if the statute of limitations for the lawsuit regarding the relevant issue requires the personal location to be stored for longer than the periods in the table, the periods in the table above may not be applied. In this case, the intended use, special legislation or the statute of limitations period, whichever expires later, will find its application area.

Shopping Basket