This Personal Data Retention and Disposal Policy has been prepared by Beysu Global Enerji Anonim Şirketi, acting as the data controller, in order to fulfill obligations under the Personal Data Protection Law No. 6698 and the Regulation on the Deletion, Destruction, or Anonymization of Personal Data (which constitutes the secondary legislation of the Law), and to inform data subjects about the principles for determining the maximum retention period necessary for the purposes for which their personal data are processed, as well as the processes for deletion, destruction, and anonymization.
Definitions
Explicit Consent: Consent regarding a specific matter, based on information, and declared with free will.
Relevant User: Persons who process personal data within the data controller’s organization or based on authorization and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection, and backup of the data.
Disposal: The deletion, destruction, or anonymization of personal data.
Recording Medium: Any medium containing personal data that is processed either wholly or partially by automated means, or by non-automated means provided that it is part of a data filing system.
Personal Data: Any information relating to an identified or identifiable natural person.
Processing of Personal Data: Any operation performed on personal data—such as obtaining, recording, storing, preserving, altering, rearranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of the data—whether by fully or partially automated means or by non-automated means provided that the data forms part of a data filing system.
Anonymization of Personal Data: Rendering personal data in such a way that it can under no circumstances be associated with an identified or identifiable natural person, even when matched with other data.
Deletion of Personal Data: The process of rendering personal data inaccessible and unusable for Relevant Users.
Destruction of Personal Data: The process of rendering personal data inaccessible, irretrievable, and unusable by anyone.
Board: The Personal Data Protection Board.
Periodic Destruction: The process of deletion, destruction, or anonymization carried out *ex officio* at recurring intervals specified in the personal data storage and destruction policy, in the event that all conditions for the processing of personal data set forth in the Law cease to exist.
Data Subject/Relevant Person: The natural person whose personal data is processed.
Principles
The Company acts within the framework of the following principles regarding the storage and destruction of personal data:
However, upon the request of the Data Subject, an appropriate method shall be selected, and the justification for that choice shall be explained.
– Submitted requests shall be answered within 30 (thirty) days at the latest,
– In the event that the data subject to the request has been transferred to third parties, such transfer shall be notified to the third party to whom the data was transferred, and it shall be ensured that the necessary actions are taken by said third parties.
Explanations Regarding Reasons for Retention and Destruction
Personal data belonging to data subjects is retained by the Company within the limits specified in the Law and other relevant legislation, particularly for the purposes of (i) sustaining commercial activities, (ii) fulfilling legal obligations, and (iii) planning and administering employee rights and fringe benefits. The reasons necessitating retention are as follows:
In accordance with the Regulation, personal data belonging to data subjects shall be deleted, destroyed, or anonymized by the Company—either ex officio or upon request—in the following cases:
in the event that the application made to the data controller is rejected, the response provided is deemed insufficient, or no response is given within the period stipulated in the Law; a complaint is lodged with the Board and this request is found justified by the Board,
Retention and Destruction Periods
The following criteria, listed in order, are utilized to determine the retention and destruction periods for your personal data obtained by the Company in accordance with the provisions of the Law and other relevant legislation:
– Personal data are classified as “personal data” and “personal data of special nature” based on the definitions set forth in Article 6 of the Law. All personal data determined to be of a special nature are destroyed. The method to be applied for the destruction of such data is determined based on the nature of the data and the degree of importance of its retention to the Company.
– The compliance of data retention with the principles specified in Article 4 of the Law is assessed—for instance, by questioning whether the Company has a legitimate purpose for retaining the data. Data determined to be retained in a manner that violates the principles set forth in Article 4 of the Law are deleted, destroyed, or anonymized.
– It is determined under which of the exceptions stipulated in Articles 5 and 6 of the Law the retention of the data falls. Reasonable retention periods for the data are established within the framework of the applicable exceptions. Upon the expiration of said periods, the data are deleted, destroyed, or anonymized.
– You may access the retention, destruction, and periodic destruction periods determined by the Company in the annex to this Policy. Personal data for which the retention period has expired are anonymized or destroyed at six-month intervals, in accordance with the procedures set forth in this Policy and within the framework of the destruction periods specified in the annex. All actions taken regarding the deletion, destruction, and anonymization of personal data are recorded, and such records are retained for a minimum of three years, subject to other legal obligations.
Procedures, Technical and Administrative Measures Regarding the Storage and Destruction of Personal Data
Personal data collected—whether to enable our Company to fulfill its employment-related obligations; because data processing is necessary to establish a right; to facilitate your use of customer services, consumer rights, and other benefits and/or to fulfill related commercial, financial, and legal responsibilities; to ensure the security of our Company; or because processing is required for our Company’s legitimate purposes—is entered into the Company’s data systems. Additionally, all data stored in digital format is recorded on the Company’s servers.
To ensure the secure storage of your personal data, prevent unlawful processing and unauthorized access, and ensure lawful data destruction, the Company has implemented the following administrative and technical measures in accordance with the principles set forth in Article 12 of the Law:
Administrative Measures:
As part of its administrative measures, the Company:
Technical Measures:
Within the scope of administrative measures, the Company…
– If data transfer via e-mail is required, ensures transfer in encrypted form using a corporate e-mail address or a Registered Electronic Mail (KEP) account,
– If data transfer via media such as portable drives, CDs, or DVDs is required, [ensures] cryptographic… …encryption using [appropriate] methods,
– Ensuring that transfers between servers located in different physical environments are conducted via a VPN connection established between the servers or through the sFTP method,
– Ensuring that, if data transfer in paper format is required, the documents are transmitted in accordance with the “classified documents” format.
Duties and Authorities of the Personal Data Protection Committee
The Personal Data Protection Committee is responsible for communicating the Policy to the relevant business units and monitoring compliance with its requirements. The Committee issues necessary announcements and notifications to ensure that relevant business units monitor—and, where necessary, update their business processes in light of—developments such as legislative changes regarding personal data protection, the Board’s regulatory actions and decisions, court rulings, or changes in processes, practices, and systems. Furthermore, the Committee establishes and communicates to the relevant units the processes for reviewing, evaluating, monitoring, and finalizing matters related to the Law, secondary regulations, Board decisions and regulations, court rulings, and decisions and/or requests from other competent authorities.
Implementation of the Policy, Violations, and Sanctions
Upon detection of conduct violating the policy, the matter shall be immediately reported by the relevant employee’s supervisor to their own superior.
Personal data shall be retained for the periods specified in the table below, taking into account the matters set forth in Article 4 of the Policy, and shall be anonymized or destroyed upon the expiration of said periods:
| Process | Storage Period | Destruction Period |
| Data stored within the scope of the Labor Law (e.g. performance records, etc.) | 5 years following the termination of the employment relationship | Within 180 days following the end of the storage period |
| Data collected within the scope of occupational health and safety legislation (health reports, etc.) | 15 years following the termination of the employment relationship | Within 180 days following the end of the storage period |
| Data held within the scope of SSI legislation | 10 years following the termination of the employment relationship | Within 180 days following the end of the storage period |
| Documents that can be used in a claim/lawsuit regarding work accident/occupational disease | 10 years following the termination of the employment relationship | Within 180 days following the end of the storage period |
| Data collected in accordance with other relevant legislation | For the period stipulated in the relevant legislation | Within 180 days following the end of the storage period |
| The relevant personal data is subject to a crime within the scope of the Turkish Penal Code or other legislation imposing criminal provisions | During the statute of limitations | Within 180 days following the end of the storage period |
| Customer data | 10 years from registration | Within 180 days following the end of the storage period |
If the Company’s purpose of using the relevant personal data has not expired, if the storage period foreseen for the relevant personal data in accordance with the relevant legislation is longer than the periods in the table, or if the statute of limitations for the lawsuit regarding the relevant issue requires the personal location to be stored for longer than the periods in the table, the periods in the table above may not be applied. In this case, the intended use, special legislation or the statute of limitations period, whichever expires later, will find its application area.