POLICY ON THE PROTECTION AND PROCESSING OF PERSONAL DATA

SECTION 1: INTRODUCTION

1. THE IMPORTANCE OF PERSONAL DATA PROTECTION

The protection of personal data is a constitutional right and ranks among our company’s priorities. Accordingly, the aim has been to establish a continuously updated system within our company, and this policy has been formulated. This policy is established to fulfill the general disclosure obligation of Beysu Global Enerji Anonim Şirketi under the Personal Data Protection Law No. 6698 and to define the fundamental principles governing our company’s personal data processing rules; within this scope, it regulates the fundamental principles regarding the protection of personal data belonging to our customers, potential customers, employees, job applicants, interns and students, supplier/subcontractor employees and officials, company shareholders and partners, visitors, and other third parties whose data we process.

To implement the matters outlined in this policy, necessary procedures are established within the Company; disclosure texts aligned with the Personal Data Processing Inventory—tailored to specific categories of individuals—are created; personal data protection and confidentiality agreements are executed with company employees and third parties who have access to personal data; job descriptions are revised; necessary administrative and technical measures for personal data protection are implemented by Beysu Global Enerji Anonim Şirketi; and relevant audits are conducted or commissioned.

2. PURPOSE OF THE POLICY

The primary purpose of this Policy is to set forth the principles regarding personal data processing activities and the protection of personal data carried out lawfully by Beysu Global Enerji Anonim Şirketi, and to ensure transparency by informing and enlightening the individuals whose personal data is processed by our Company.

3. SCOPE

This Policy applies to all personal data processed—whether by automated means or by non-automated means provided that such data forms part of a data filing system—concerning individuals categorized under the following headings: “our customers, potential customers, employees, job applicants, interns and students, supplier/subcontractor employees and representatives, company shareholders and partners, visitors, and other third parties whose data we process.”

4. APPLICATION OF THE POLICY AND RELEVANT LEGISLATION

Applicable legal regulations regarding the processing and protection of personal data shall take precedence. In the event of any inconsistency between the applicable legislation and this Policy, our Company acknowledges that the applicable legislation shall prevail.

5. ACCESS AND UPDATING

The Policy is published on our Company’s website (https://www.beysuenerji.com), made available to relevant persons upon the request of personal data subjects, and updated as necessary.

SECTION 2: PROCESSING OF PERSONAL DATA

In accordance with Article 20 of the Constitution and Article 4 of the KVKK (Law on the Protection of Personal Data), our Company may conduct personal data processing activities that are lawful and in accordance with the rules of good faith; accurate and, where necessary, up-to-date; for specific, explicit, and legitimate purposes; and relevant, limited, and proportionate to the purpose. Our Company retains personal data for the duration prescribed by law or required by the purpose of the personal data processing.

Pursuant to Article 20 of the Constitution and Article 5 of the KVKK, our Company processes personal data based on one or more of the conditions regarding the processing of personal data set forth in Article 5 of the KVKK.

Pursuant to Article 419 of the Code of Obligations—and without prejudice to the KVKK (Law No. 6698)—our Company processes the personal data of employees and prospective employees based on the purposes of assessing suitability for employment and the performance of the employment contract.

In accordance with Article 20 of the Constitution and Article 10 of the KVKK, our Company informs personal data subjects; provides the necessary information when personal data subjects request information or apply to exercise their statutory rights; and responds to such applications within the legal timeframe. Our Company acts in accordance with the regulations stipulated for the processing of special categories of personal data, pursuant to Article 6 of the KVKK (Personal Data Protection Law).

In accordance with Articles 8 and 9 of the KVKK, our Company complies with the statutory rules regarding the transfer of personal data and conducts its operations by taking into account the decisions adopted and communiqués published by the KVKK Board, as well as the lists of safe countries.

2.1. PROCESSING OF PERSONAL DATA IN ACCORDANCE WITH THE PRINCIPLES AND RULES STIPULATED IN THE LEGISLATION

A. Principles Regarding the Processing of Personal Data

a. Processing in Accordance with the Law and the Principle of Good Faith

Our Company acts in accordance with the principles introduced by legal regulations and the principle of good faith when processing personal data. In this context, our Company processes data by identifying the legal grounds necessitating such processing, observes the requirements of proportionality, refrains from using personal data beyond what is required for the specific purpose, and does not engage in processing activities without the knowledge of the data subjects.

b. Ensuring Personal Data is Accurate and, Where Necessary, Up-to-Date

Our Company ensures that the personal data it processes is accurate and up-to-date—taking into account the fundamental rights of data subjects and its own legitimate interests—and takes the necessary measures to this end. In this context, efforts are made to keep data regarding all categories of individuals up-to-date.

In particular, customer and potential customer data is updated with care, and marketing or promotional emails and offers are not sent to individuals in a manner contrary to their consent.

c. Processing for Specific, Explicit, and Legitimate Purposes

Our Company clearly and precisely defines the legitimate and lawful purpose for processing personal data. Our Company processes personal data only to the extent necessary for and in connection with the services it provides. The purpose for which personal data will be processed is determined prior to the processing activity and is recorded in the “Personal Data Inventory.”

d. Being Relevant, Limited, and Proportionate to the Purpose of Processing

Our Company processes personal data in a manner conducive to achieving the determined purposes and refrains from processing personal data that is unnecessary or unrelated to the realization of said purpose. In this context, processes are continuously reviewed, and efforts are made to implement the principle of “data minimization.”

B. Rules Regarding the Processing of Personal Data of a General Nature

The protection of personal data is a right defined in the Constitution; fundamental rights and freedoms may only be restricted by law—without infringing upon their essence—and solely for the reasons specified in the relevant articles of the Constitution. Pursuant to Article 20, Paragraph 3 of the Constitution, personal data may only be processed in cases prescribed by law or with the explicit consent of the data subject. Our Company processes personal data without seeking the data subject’s explicit consent only when the following conditions are met:

It is expressly prescribed by law,

It is necessary for the protection of the life or physical integrity of the data subject or another person, where the data subject is unable to express their consent due to actual impossibility or where their consent is not legally valid,

It is necessary to process personal data belonging to the parties to a contract, provided that such processing is directly related to the conclusion or performance of the contract,

It is necessary for the data controller to fulfill a legal obligation,

The data has been made public by the data subject themselves,

Data processing is necessary for the establishment, exercise, or protection of a right,

Data processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.

In the absence of the above conditions, our Company relies on the data subject’s explicit consent, which is based on free will and proper information. Particularly in the fields of Human Resources and employment relations, taking into account the subordinate relationship of the employee, the fundamental principle is to rely primarily on grounds for lawfulness other than consent; explicit consent is sought only when such other grounds are not applicable. Conversely, for activities such as marketing, the processing is carried out based on the data subject’s consent. However, in all instances where personal data is processed, data processing activities based on the “informing of employees” are invariably conducted.

C. Rules Regarding the Processing of Special Categories of Personal Data

Our Company complies with the regulations stipulated in the KVKK (Personal Data Protection Law) when processing personal data designated as “special categories” under the Law. Article 6 of the KVKK identifies certain types of personal data as “special categories”—data that carries the risk of causing victimization or discrimination if processed unlawfully—and requires that care and sensitivity be exercised during their processing. These include data concerning race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and clothing, membership in associations, foundations, or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. In accordance with the KVKK, our Company processes special categories of personal data in the following situations, provided that the necessary precautions are taken:

. Special categories of personal data other than those concerning the personal data subject’s health and sexual life are processed in cases prescribed by law or based on the personal data subject’s explicit consent;

. Special categories of personal data concerning the personal data subject’s health and sexual life are processed only for the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning and management of health services and their financing, by persons or authorized institutions and organizations subject to an obligation of confidentiality, or with the personal data subject’s explicit consent.

. Regardless of the grounds for processing, general data processing principles are always taken into account during processing activities, and compliance with these principles is ensured (KVKK Art. 4).

A “Personal Data Protection and Processing Policy” has been implemented within our company regarding the protection of special categories of data; our business units act in accordance with the provisions of this policy, and necessary measures are taken.

D. Informing and Clarifying Data Subjects Whose Data Is Processed

In accordance with Article 10 of the KVKK, our company informs personal data subjects at the time their personal data is obtained. In this context, the data subject is informed regarding the purpose for which the personal data will be processed, to whom and for what purpose the processed personal data may be transferred, the method and legal basis for collecting the personal data, and the rights of the data subject. Data subjects are informed about:

. Our company’s trade name and the identity of our representative, if any

. The purpose for which personal data will be processed by Beysu Global Enerji Anonim Şirketi

. To whom and for what purposes personal data processed by Beysu Global Enerji Anonim Şirketi may be transferred

. The method and legal basis for the collection of personal data

. The rights of the data subject listed in Article VIII.

2.2. TRANSFER OF PERSONAL DATA

Our Company may transfer the personal data and special categories of personal data of the data subject to third parties, provided that necessary security measures are taken and the transfer aligns with lawful purposes for personal data processing. In this regard, our Company acts in accordance with the regulations stipulated in Article 8 of the KVKK (Personal Data Protection Law). A. Principles Regarding the Transfer of Personal Data

Our Company may transfer personal data to third parties based on and limited to one or more of the personal data processing conditions specified in Article 5 of the Law, in line with legitimate and lawful personal data processing purposes:

Based on the explicit consent of the data subject whose personal data is being processed, or

  1. If there is an explicit provision in the laws regarding the transfer of personal data,
  2. If it is necessary for the protection of the life or physical integrity of the data subject or another person, and the data subject is unable to express their consent due to actual impossibility or their consent is not legally valid;
  3. If the transfer of personal data belonging to the parties to a contract is necessary, provided that it is directly related to the conclusion or performance of the contract,
  4. If the transfer of personal data is necessary for our Company to fulfill a legal obligation,
  5. If the personal data has been made public by the data subject themselves,
  6. If the transfer of personal data is necessary for the establishment, exercise, or protection of a right,
  7. If the transfer of personal data is necessary for the legitimate interests of our Company, provided that it does not harm the fundamental rights and freedoms of the data subject whose personal data is being processed.

Regardless of the grounds, general data processing principles are always taken into account during transfer processes, and compliance with these principles is ensured (KVKK Art. 4).

B. Transfer of Special Categories of Personal Data

Our Company, by exercising due care and implementing necessary security measures as well as the adequate measures prescribed by the KVKK Board; It may transfer the special category personal data of the data subject—whose personal data is processed for legitimate and lawful purposes—to third parties in the following situations.

  1. Based on the explicit consent of the data subject, if such consent exists; or
  2. In the absence of the data subject’s explicit consent:
  3. Special categories of personal data other than those concerning the data subject’s health and sexual life (i.e., race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership in associations, foundations, or trade unions, data concerning criminal convictions and security measures, as well as biometric and genetic data) may be processed in cases prescribed by law;
  4. Special categories of personal data concerning the data subject’s health and sexual life may only be processed by persons under an obligation of confidentiality or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning and management of health services and their financing.

Regardless of the grounds for transfer, general data processing principles are always taken into account, and compliance with these principles is ensured during transfer processes (KVKK Art. 4).

C. Transfer of Personal Data Abroad

Our Company may transfer personal data and special categories of personal data—which it has processed by taking necessary security measures in line with lawful personal data processing purposes—to third parties. Personal data processed by our Company: Personal data may be transferred to countries deemed GDPR-compliant by the KVKK Board, to foreign countries declared to possess adequate protection (“Foreign Country with Adequate Protection”), or—in the absence of adequate protection—to foreign countries where data controllers in Turkey and the relevant foreign country have committed in writing to providing adequate protection and where the KVKK Board has granted authorization (“Foreign Country Where the Data Controller Commits to Adequate Protection”). Accordingly, our Company acts in compliance with the regulations stipulated in Article 9 of the KVKK.
For legitimate and lawful personal data processing purposes, our Company may transfer personal data to Foreign Countries with Adequate Protection, to Foreign Countries Where the Data Controller Commits to Adequate Protection, and to countries deemed GDPR-compliant, provided that the data subject has given their explicit consent or, in the absence of such consent, if one of the following circumstances exists:

  • If there is an explicit provision in the laws regarding the transfer of personal data,
  • If the transfer is necessary to protect the life or physical integrity of the data subject or another person, and the data subject is unable to provide consent due to actual impossibility or their consent is not legally valid,
  • If the transfer of personal data belonging to the parties to a contract is necessary, provided that it is directly related to the conclusion or performance of said contract,
  • If the transfer of personal data is mandatory for our Company to fulfill a legal obligation,
  • If the personal data has been made public by the data subject themselves,
  • If the transfer of personal data is necessary for the establishment, exercise, or protection of a right,
  • If the transfer of personal data is necessary for the legitimate interests of our Company, provided that it does not harm the fundamental rights and freedoms of the personal data subject.

2.3. PERSONAL DATA CATEGORIZATIONS

The individuals whose data is processed by our Company and the data processed within this scope are categorized as follows:

PERSON AND DATA CATEGORIZATION

Job ApplicantNatural persons who have applied for a job with our company via any means or have made their resumes and related information available for our company’s review.
WorkerNatural persons working at our company
Potential CustomerNatural persons who have requested or are interested in using our services or who have been evaluated in accordance with the rules of commercial practice and honesty as they may have this interest.
Supplier EmployeeNatural persons employed by institutions with which our company maintains any form of business relationship (such as, but not limited to, business partners and suppliers)
Supplier RepresentativeNatural persons who are shareholders and authorized representatives of the institutions with which our company maintains business relationships.
CustomerNatural persons who use or have used the services offered by our Company, regardless of whether there is any contractual relationship with our Company.
VisitorNatural persons who have entered the physical premises owned by our company for various purposes or who visit our websites.
OTHERThird-party natural persons associated with the aforementioned individuals (e.g., family members and close associates), for the purpose of ensuring the security of commercial transactions between our company and the aforementioned parties, or protecting the rights and serving the interests of said individuals.
Identity DataInformation clearly pertaining to an identified or identifiable natural person—such as details found in documents like driver’s licenses, national ID cards, residence permits, passports, attorney ID cards, and marriage certificates—that is processed either wholly or partially by automated means, or by non-automated means as part of a data filing system.
Contact DataInformation—such as a telephone number, address, or e-mail—that clearly belongs to an identified or identifiable natural person and is processed either wholly or partially by automated means, or by non-automated means as part of a data filing system.
Location DataInformation that is clearly associated with an identified or identifiable natural person; is processed—either wholly or partially by automated means, or by non-automated means as part of a data filing system—and determines the location of the personal data subject while using our services, or the location of employees of institutions with which we collaborate while they are using our Company’s vehicles.
Personnel DataAny personal data—whether processed wholly or partially by automated means or non-automatedly as part of a data filing system—that clearly relates to an identified or identifiable natural person and is processed for the purpose of obtaining information that serves as the basis for establishing the employment-related rights of our employees or of natural persons with whom our Company has a working relationship.
Legal Transaction and Compliance DataYour personal data—clearly pertaining to an identified or identifiable natural person and processed either wholly or partially by automated means, or by non-automated means as part of a data filing system—that is processed for the purposes of establishing and pursuing our legal claims and rights, fulfilling our obligations, and ensuring compliance with legal requirements and our company’s policies.
Customer Transaction DataInformation that is clearly associated with an identified or identifiable natural person and is contained within a data recording system—such as records regarding the use of our services, as well as instructions and requests necessary for the customer’s use of the services.
Physical Space Security DataPersonal data contained within a data recording system that clearly belongs to an identified or identifiable natural person, relating to records and documents obtained upon entry to or during one’s stay within a physical space.
Transaction Security DataPersonal data that clearly belongs to an identified or identifiable natural person, is contained within a data recording system, and is processed to ensure technical, administrative, legal, and commercial security during the conduct of activities.
Risk Management DataPersonal data that clearly belongs to an identified or identifiable natural person and is contained within a data recording system; processed—in order to manage our commercial, technical, and administrative risks—by means of methods used in accordance with generally accepted legal and commercial practices and the principle of good faith in these areas.
Financial DataPersonal data processed in relation to information, documents, and records—which clearly pertain to an identified or identifiable natural person and are processed either wholly or partially by automated means or by non-automated means as part of a data filing system—that reflect any financial consequences arising from the type of legal relationship established between our company and the personal data subject.
Performance and Career Development DataPersonal data belonging to an identified or identifiable natural person—processed either wholly or partially by automated means, or by non-automated means as part of a data filing system—that is processed for the purpose of measuring the performance of our employees or natural persons with whom our Company has a working relationship, and for planning and executing their career development within the scope of our Company’s human resources policy.
Marketing DataPersonal data that clearly belongs to an identified or identifiable natural person and is processed—either wholly or partially by automated means, or by non-automated means as part of a data filing system—for the purpose of marketing our services by customizing them in line with the personal data subject’s usage habits, preferences, and needs; as well as the reports and evaluations generated as a result of such processing.
Visual and Audio DataThis refers to personal data that clearly belongs to an identified or identifiable natural person and is processed either wholly or partially by automated means, or by non-automated means as part of a data filing system; e.g., photographs and camera recordings (excluding those falling under Physical Space Security Information), audio recordings, and data contained in documents that are copies of documents containing personal data.
Sensitive Data
(Health, Sexual Life)
Data concerning health and sexual life
Data regarding race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership in an association, foundation, or trade union, criminal convictions and security measures, as well as biometric and genetic data.

SECTION 3: LEGAL BASES AND PURPOSES FOR THE PROCESSING OF PERSONAL DATA

3.1. LEGAL BASES FOR THE PROCESSING OF PERSONAL DATA

General Principles

Although the legal bases for the processing of personal data by our Company may vary, all personal data processing activities are conducted in accordance with the general principles set forth in Article 4 of Law No. 6698. Accordingly, the following general principles are observed in all data processing activities:

Compliance with the law and rules of good faith,

Being accurate and, where necessary, up-to-date,

Processing for specific, explicit, and legitimate purposes,

Being relevant, limited, and proportionate to the purposes for which they are processed,

Retention for the period stipulated in the relevant legislation or required for the purpose for which they are processed.

Grounds for Lawfulness

a. Existence of the Personal Data Subject’s Explicit Consent

One of the conditions for processing personal data is the explicit consent of the data subject. The personal data subject’s explicit consent must be declared regarding a specific matter, based on information, and given of their own free will.

b. Being Expressly Provided for by Law

The data subject’s personal data may be processed lawfully if such processing is expressly provided for by law.
For example, the reporting of our employees’ identities to competent authorities in accordance with Identity Notification Legislation.

c. Inability to Obtain the Data Subject’s Explicit Consent Due to Factual Impossibility

The data subject’s personal data may be processed if such processing is necessary to protect the life or physical integrity of the data subject or another person, in cases where the data subject is unable to express their consent due to factual impossibility or where their consent cannot be deemed valid. For example, sharing the blood type information of an employee who has lost consciousness with a physician.

d. Direct Relevance to the Conclusion or Performance of a Contract

Personal data may be processed if such processing is necessary for the parties to a contract, provided that it is directly related to the conclusion or performance of said contract. For example, obtaining a CV from a candidate to conclude an employment contract, or obtaining an address to facilitate notifications within the scope of the contract.

e. Fulfillment of the Company’s Legal Obligation

The data subject’s personal data may be processed if such processing is necessary for our Company to fulfill its legal obligations as a data controller. For example, processing family information to enable an employee to benefit from the Minimum Living Allowance.

f. Making Personal Data Public by the Data Subject

The relevant personal data may be processed if the data subject has made their personal data public. For example, if our Company’s customers submit complaints, requests, or suggestions on a publicly accessible online platform, they have made the relevant information public. In such cases, it is permissible for a Company representative to process the data, provided that such processing is limited to the purpose of responding to the complaints, requests, or suggestions. g. Necessity of Data Processing for the Establishment or Protection of a Right

The personal data of the data subject may be processed if such processing is necessary for the establishment, exercise, or protection of a right. For example, the retention of data serving as evidence (such as sales contracts or invoices) and its use when necessary.

h. Necessity of Data Processing for the Legitimate Interests of Our Company

The personal data of the data subject may be processed if such processing is necessary for the legitimate interests of our Company, provided that it does not harm the fundamental rights and freedoms of the data subject. For example, the monitoring of critical areas of the Company via security cameras for the purpose of preventing theft or ensuring occupational safety.

Processing of Special Categories of Personal Data and Grounds for Lawfulness

Special categories of personal data may be processed by our Company without the data subject’s explicit consent only in cases prescribed by law and provided that adequate measures determined by the Personal Data Protection Board are taken. Special categories of personal data concerning the data subject’s health and sexual life may be processed only by persons under an obligation of confidentiality or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning and management of health services and their financing. Regardless of the grounds involved, general data processing principles are always taken into account during processing activities, and compliance with these principles is ensured (Personal Data Protection Law, Art. 4).

3.2. PURPOSES OF PROCESSING PERSONAL DATA

Our Company processes personal data within the scope of the purposes and conditions set forth in Article 5, Paragraph 2 and Article 6, Paragraph 3 of the Personal Data Protection Law No. 6698. During the data processing process, the aforementioned legal grounds are taken into account, and the data subject’s consent is requested if no other grounds for lawfulness exist. In this context, compliance with general principles under Article 4 is also assessed; above all, it is required that the data processing activity generally aligns with principles of lawfulness. The data subject’s consent is obtained in a manner that is “explicit, informed, and based on free will.” The purposes for processing personal data are also specified in our Company’s Personal Data Inventory.

Personal data within our Company’s units is processed specifically for the following purposes:

1. As an employer, it is necessary to process employees’ personal data in order to fulfill mutual obligations arising from the employment contract. Employees’ personal data are processed and stored in a manner that is lawful and in accordance with the rules of good faith; accurate and, where necessary, up-to-date; for specific, explicit, and legitimate purposes; and in a manner that is relevant, limited, and proportionate to the purpose. In this context, the legal bases for processing personal data include: the execution of processes regarding the establishment, performance, and termination of employment contracts in compliance with the law; the Company’s legitimate interests (provided they do not infringe upon fundamental rights and freedoms); situations expressly stipulated by law; the fulfillment of legal obligations related to employment; instances where data processing is necessary for the establishment, exercise, or protection of rights in legal proceedings; and—in cases falling outside these categories—the explicit, informed consent freely given by the employees.

2. The Company’s legitimate interests necessitate the processing of employees’ personal data within the scope of activities required by the Company’s line of business. Indeed, personal data processing activities may be conducted for purposes such as preventing misconduct and theft, ensuring general security, or maintaining occupational health and safety. However, even in such instances, great care is taken to ensure that employees’ fundamental rights and freedoms are not infringed upon.

3. The vast majority of the employees’ personal data being processed is obtained from information provided to the Company by the employees themselves. Additionally, in certain cases, such data may be acquired from internal sources (such as Company managers) or employee references, or obtained from systems established by public institutions and organizations as required by the nature of employment.

4. The personal data of employees being processed consists of information such as application forms and references, employment contracts and amendments thereto, contact details, payroll-related information, family or next-of-kin details (such as emergency contacts), educational records, performance evaluation records, disciplinary records, and camera footage.

5. Rules regarding the processing of employees’ personal data are set out in various Company policies and procedures. In this regard, the “Personal Data Protection and Processing Policy,” available on the Company’s website, may be consulted. This document can also be accessed via the Company’s intranet/QDMS system or obtained in hard copy from the Human Resources Department.

6. Employees’ health information is also included among the personal data processed. As a general rule, information concerning employees’ health and sexual life is processed by persons under a duty of confidentiality or by authorized institutions and organizations for purposes such as protecting public health; conducting preventive medicine, medical diagnosis, treatment, and care services; and planning and managing health services and their financing. In this context, employees’ health data and related details are generally held by the workplace physician and the health unit.

7. Once the status of “employee” is attained (such information is not requested during the candidate stage), if an employee becomes a union member, data regarding union membership may also be processed in accordance with express legal provisions in order to fulfill statutory requirements. Furthermore, as a general rule, employees’ race, ethnic origin, political views, philosophical beliefs, religion, sect or other beliefs, attire, and biometric and genetic data are not included among the personal data processed unless expressly provided for by law; should an exceptional case arise, the relevant requirements are carefully evaluated prior to the processing of such personal data.

8. The Company monitors and oversees its information and communication tools (telephones, mobile phones, computers, and the internet). Law No. 5651 and the Company’s legitimate interests constitute the legal basis for these practices.

9. Vehicle tracking systems may be implemented in the Company’s vehicles for reasons of “security and the more effective management of vehicles and personnel.” This activity is based on the Company’s legitimate interests and is carried out without infringing upon the fundamental rights and freedoms of employees.

10. Personal data is processed for the following purposes: ensuring the implementation of the Company’s human resources policies; recruiting personnel for open positions in accordance with these policies; conducting human resources operations; selecting job candidates; managing personnel records; determining training and career plans; and fulfilling obligations and taking necessary measures regarding occupational health and safety.

11. Personal data belonging to employees of suppliers or subcontractors may also be processed by our organization. Indeed, Law No. 6331 specifies the documents and information that the principal employer must verify regarding employees arriving from other workplaces in the context of occupational health and safety. Similarly, Labor Law No. 4857 and the Social Insurance and General Health Insurance Law No. 5510 impose obligations on the principal employer regarding subcontractor employees and temporary workers, outlining the matters that must be verified. Accordingly, the processing of personal data of workers employed at our workplace—who are affiliated with suppliers or other employers—is based on our business’s legitimate interests, as well as the aforementioned legal regulations.

12. Personal data are also [processed for]:

  • Execution of emergency management processes
  • Execution of information security processes
  • Execution of audit/ethics activities
  • Execution of training activities
  • Management of access authorizations
  • Conducting activities in compliance with legislation
  • Execution of finance and accounting operations
  • Execution of processes regarding loyalty to the company/services
  • Ensuring physical premises security
  • Execution of assignment processes
  • Follow-up and execution of legal affairs
  • Execution of internal audit/investigation/intelligence activities
  • Execution of communication activities
  • Execution of service and operational processes
  • Execution of customer relationship processes
  • Execution of activities aimed at customer satisfaction
  • Organization and event management
  • Execution of marketing analysis activities
  • Execution of performance evaluation processes
  • Execution of advertising/campaign/promotion processes
  • Execution of risk management processes
  • Execution of storage and archiving activities
  • Execution of social responsibility and civil society activities
  • Execution of contract processes
  • Execution of sponsorship activities
  • Execution of strategic planning activities
  • Follow-up of requests/complaints
  • Ensuring the security of movable assets and resources
  • Execution of supply chain management processes
  • Execution of service marketing processes
  • Ensuring the security of data controller operations
  • Foreign personnel

work and residence permit procedures

  • Execution of investment processes
  • Providing information to authorized persons, institutions, and organizations
  • Execution of management activities
  • Creation and tracking of visitor records

Video surveillance activities at the workplace—conducted for purposes of occupational health and safety, general security, and product safety—are carried out based on the Company’s legitimate interests, provided that the fundamental rights and freedoms of our visitors, the individuals whose data is processed in this context, and—in particular—our employees are not infringed upon.

SECTION 4: STORAGE, DELETION, DESTRUCTION, AND ANONYMIZATION OF PERSONAL DATA

Even if personal data has been processed in accordance with the relevant legal provisions—specifically Article 138 of the Turkish Penal Code and Article 7 of the KVKK (Law on the Protection of Personal Data)—our Company deletes, destroys, or anonymizes such data either upon its own decision or at the request of the personal data subject, should the grounds necessitating the processing cease to exist.

4.1. STORAGE OF PERSONAL DATA AND STORAGE PERIODS

Our Company retains personal data for the duration specified in applicable laws and regulations where such retention is mandated. If no specific retention period is prescribed by legislation, personal data is retained for the period necessary for processing—determined in accordance with our Company’s practices and commercial customs regarding the services provided—and may be stored to serve as evidence in legal disputes, to assert rights related to the personal data, or to establish a defense. Retention periods are established based on the statute of limitations applicable to the assertion of such rights, as well as precedents involving past requests made to our Company regarding similar matters, even after the statutory limitation period has expired. In such cases, the stored personal data is not accessed for any other purpose; access is granted only when required for use in the relevant legal dispute. Once the applicable period expires, the personal data is deleted, destroyed, or anonymized.

4.2. DELETION, DESTRUCTION, AND ANONYMIZATION OF PERSONAL DATA

In accordance with the provisions of Article 138 of the Turkish Penal Code and Article 7 of the Personal Data Protection Law (KVKK), personal data—even if processed lawfully—shall be deleted, destroyed, or anonymized upon the decision of our Company or at the request of the personal data subject if the grounds necessitating the processing cease to exist. In this context, our Company fulfills the relevant obligation using the methods described in this section.

A. Deletion of Personal Data

a. Process of Deleting Personal Data

Our Company may delete personal data—even if processed in accordance with the provisions of the relevant law—upon its own decision or at the request of the personal data subject, should the grounds requiring their processing cease to exist. The deletion of personal data is the process of rendering personal data inaccessible and unusable for the relevant users. Our Company takes all necessary technical and administrative measures to ensure that deleted personal data remains inaccessible and unusable for the relevant users.

b. Procedure for Deleting Personal Data

The procedure to be followed for the deletion of personal data is as follows:

  • Identifying the personal data subject to the deletion process.
  • Determining the relevant users for each piece of personal data using an access authorization and control matrix or a similar system.
  • Determining the relevant users’ authorizations and methods regarding access, retrieval, and reuse.
  • Terminating and eliminating the relevant users’ authorizations and methods for accessing, retrieving, and reusing the personal data.

c. Methods for Deleting Personal Data

Since personal data may be stored on various recording media, they are deleted using methods appropriate to the specific recording medium.

B. Destruction of Personal Data

a. Process of Destroying Personal Data

Our Company may destroy personal data—even if processed in accordance with the provisions of the relevant law—upon its own decision or at the request of the personal data subject, should the grounds requiring their processing cease to exist. The destruction of personal data is the process of rendering personal data inaccessible, irretrievable, and unusable by anyone in any way. Our Company takes all necessary technical and administrative measures regarding the destruction of personal data.

b. Methods for the Destruction of Personal Data

To destroy personal data, all copies containing the data are identified, and the systems containing the data are destroyed individually.

C. Anonymization of Personal Data

a. Process of Anonymizing Personal Data

Anonymization of personal data is the process of rendering personal data such that it can under no circumstances be associated with an identified or identifiable natural person, even when matched with other data. Our Company may anonymize personal data that has been processed in accordance with the law once the grounds requiring its processing cease to exist. Anonymization is carried out by rendering the personal data impossible to associate with an identified or identifiable natural person—even through methods such as reversal by the data controller or recipient groups, or matching the data with other data—by employing techniques appropriate to the storage medium and the relevant field of activity. Our Company takes all necessary technical and administrative measures to anonymize personal data.

Personal data that has been anonymized in accordance with Article 28 of the Personal Data Protection Law (KVK Law) may be processed for purposes such as research, planning, and statistics. Such processing activities fall outside the scope of the KVK Law, and the explicit consent of the personal data subject is not required.

b. Methods of Anonymizing Personal Data

Anonymization is the process of preventing the identification of the data subject—or causing the data to lose the characteristic of being distinguishable within a group or crowd in a way that links it to a natural person—by removing or altering all direct and/or indirect identifiers in a dataset. Data that does not point to a specific person as a result of the prevention or loss of these characteristics is considered anonymized data. The objective of anonymization is to sever the link between the data and the person whom that data identifies. Anonymization methods refer to all processes—carried out via techniques such as grouping, masking, derivation, generalization, or randomization (whether automated or not)—that sever the link between records in a personal data filing system and the individuals to whom they relate. Data obtained through the application of these methods must not allow for the identification of a specific individual.

SECTION 5: RIGHTS OF DATA SUBJECTS

5.1. SCOPE OF DATA SUBJECTS’ RIGHTS AND EXERCISE OF THESE RIGHTS

A. Rights of Data Subjects

Individuals whose personal data is processed by our Company have the following rights:

  • To learn whether or not personal data is being processed,
  • To request information regarding the processing if personal data has been processed,
  • To learn the purpose of processing personal data and whether such data is used in accordance with said purpose,
  • To know the third parties to whom personal data is transferred, domestically or abroad,
  • To request the correction of personal data in the event of incomplete or incorrect processing and to request that the action taken in this context be notified to the third parties to whom the personal data was transferred,
  • To request the deletion or destruction of personal data—even if processed in accordance with the provisions of the KVK Law and other relevant laws—in the event that the reasons requiring processing cease to exist, and to request that the action taken in this context be notified to the third parties to whom the personal data was transferred,
  • To object to a result arising to the detriment of the individual through the analysis of processed data exclusively by means of automated systems,
  • To demand compensation for damages incurred due to the unlawful processing of personal data.

SECTION 6: ENSURING THE SECURITY OF PERSONAL DATA

6.1. OUR OBLIGATIONS REGARDING DATA SECURITY

Beysu Global Enerji Anonim As the Company, administrative and technical measures—exemplified below—will be implemented to prevent the unlawful processing of and unlawful access to personal data, and to ensure the preservation of personal data.

6.2. DATA SECURITY MEASURES

  • Network security and application security are ensured.
  • Closed-system networks are used for the transfer of personal data via the network.
  • Periodic training and awareness-raising activities regarding data security are conducted for employees.
  • An authorization matrix has been established for employees.
  • Access rights in this area are revoked for employees who change roles or leave the company.
  • Up-to-date anti-virus systems are utilized.
  • Signed contracts contain provisions regarding data security.
  • Personal data security issues are reported promptly.
  • Necessary security measures are taken regarding entry to and exit from physical environments containing personal data.
  • Physical environments containing personal data are secured against external risks (fire, flood, etc.).
  • Environments containing personal data are secured.
  • Personal data is minimized to the extent possible.
  • User account management and authorization control systems are implemented and monitored.
  • Existing risks and threats have been identified.
  • Penetration testing is conducted.
  • Encryption is applied.
  • Data loss prevention software is used.

6.3. STORAGE OF PERSONAL DATA IN SECURE ENVIRONMENTS

Our Company takes the necessary technical and administrative measures—based on technological capabilities and implementation costs—to store personal data in secure environments and to prevent its destruction, loss, or alteration for unlawful purposes.

A. Technical Measures Taken to Store Personal Data in Secure Environments

The primary technical measures taken by our Company to store personal data in secure environments are listed below:

  • Systems aligned with technological advancements are utilized to store personal data in secure environments.
  • Technical security systems are implemented for storage areas; the technical measures taken are periodically audited by the audit mechanism established by our Company; and issues posing risks are re-evaluated to develop necessary technological solutions.
  • All necessary infrastructures are utilized in a lawful manner to ensure the secure storage of personal data.

B. Administrative Measures Taken for Storing Personal Data in Secure Environments

The primary administrative measures taken by our Company to ensure the storage of personal data in secure environments are listed below:

Employees are informed about ensuring the secure storage of personal data.

In cases where our Company procures external services for the storage of personal data, contracts concluded with the relevant service providers—to whom personal data is lawfully transferred—include provisions requiring the recipients to implement necessary security measures for personal data protection and to ensure compliance with these measures within their own organizations; actions in this regard are taken in accordance with the provisions of the Company’s “Principles on the Protection of Personal Data in Relations with Third Parties” Policy.

6.4. TRAINING

Our Company provides its employees with the necessary training regarding the protection of personal data, within the scope of the Policy, Personal Data Protection (KVK) Procedures, and Personal Data Protection Law (KVKK) regulations.

The training sessions place particular emphasis on the definitions of “special categories of personal data” and the practices regarding their protection.

If a Company employee accesses personal data—whether physically or via computer systems—our Company provides that employee with training specific to such access (for example, regarding the specific computer program being accessed). 6.5. AUDIT

A. Raising Awareness and Auditing Business Units Regarding the Protection and Processing of Personal Data

Our Company ensures that necessary notifications are made to business units to raise awareness regarding the prevention of unlawful processing of personal data, the prevention of unlawful access to data, and the safeguarding of data.

B. Raising Awareness and Auditing Business Partners and Suppliers Regarding the Protection and Processing of Personal Data

Our Company provides necessary information to business partners to raise awareness regarding the prevention of unlawful processing of personal data, the prevention of unlawful access to data, and the safeguarding of data.

C. Auditing Measures Taken Regarding the Protection of Personal Data

Our Company reserves the right to audit—regularly, at any time, ex officio, and without prior notice—whether all employees, departments, and contractors of the Company comply with this Policy and the KVKK Regulations; within this scope, it conducts or commissions the necessary routine audits. The results of these audits are evaluated within the Company’s internal operations, and necessary activities are carried out to improve the measures taken.

Measures to be Taken in the Event of Unauthorized Disclosure of Personal Data:

In accordance with Article 12 of the Personal Data Protection Law (KVKK), our Company operates a system ensuring that, should personal data be obtained by others through unlawful means, the situation is reported to the relevant data subject and the Personal Data Protection Board as soon as possible.

Shopping Basket