SECTION 1: INTRODUCTION
1. THE IMPORTANCE OF PERSONAL DATA PROTECTION
The protection of personal data is a constitutional right and ranks among our company’s priorities. Accordingly, the aim has been to establish a continuously updated system within our company, and this policy has been formulated. This policy is established to fulfill the general disclosure obligation of Beysu Global Enerji Anonim Şirketi under the Personal Data Protection Law No. 6698 and to define the fundamental principles governing our company’s personal data processing rules; within this scope, it regulates the fundamental principles regarding the protection of personal data belonging to our customers, potential customers, employees, job applicants, interns and students, supplier/subcontractor employees and officials, company shareholders and partners, visitors, and other third parties whose data we process.
To implement the matters outlined in this policy, necessary procedures are established within the Company; disclosure texts aligned with the Personal Data Processing Inventory—tailored to specific categories of individuals—are created; personal data protection and confidentiality agreements are executed with company employees and third parties who have access to personal data; job descriptions are revised; necessary administrative and technical measures for personal data protection are implemented by Beysu Global Enerji Anonim Şirketi; and relevant audits are conducted or commissioned.
2. PURPOSE OF THE POLICY
The primary purpose of this Policy is to set forth the principles regarding personal data processing activities and the protection of personal data carried out lawfully by Beysu Global Enerji Anonim Şirketi, and to ensure transparency by informing and enlightening the individuals whose personal data is processed by our Company.
3. SCOPE
This Policy applies to all personal data processed—whether by automated means or by non-automated means provided that such data forms part of a data filing system—concerning individuals categorized under the following headings: “our customers, potential customers, employees, job applicants, interns and students, supplier/subcontractor employees and representatives, company shareholders and partners, visitors, and other third parties whose data we process.”
4. APPLICATION OF THE POLICY AND RELEVANT LEGISLATION
Applicable legal regulations regarding the processing and protection of personal data shall take precedence. In the event of any inconsistency between the applicable legislation and this Policy, our Company acknowledges that the applicable legislation shall prevail.
5. ACCESS AND UPDATING
The Policy is published on our Company’s website (https://www.beysuenerji.com), made available to relevant persons upon the request of personal data subjects, and updated as necessary.
SECTION 2: PROCESSING OF PERSONAL DATA
In accordance with Article 20 of the Constitution and Article 4 of the KVKK (Law on the Protection of Personal Data), our Company may conduct personal data processing activities that are lawful and in accordance with the rules of good faith; accurate and, where necessary, up-to-date; for specific, explicit, and legitimate purposes; and relevant, limited, and proportionate to the purpose. Our Company retains personal data for the duration prescribed by law or required by the purpose of the personal data processing.
Pursuant to Article 20 of the Constitution and Article 5 of the KVKK, our Company processes personal data based on one or more of the conditions regarding the processing of personal data set forth in Article 5 of the KVKK.
Pursuant to Article 419 of the Code of Obligations—and without prejudice to the KVKK (Law No. 6698)—our Company processes the personal data of employees and prospective employees based on the purposes of assessing suitability for employment and the performance of the employment contract.
In accordance with Article 20 of the Constitution and Article 10 of the KVKK, our Company informs personal data subjects; provides the necessary information when personal data subjects request information or apply to exercise their statutory rights; and responds to such applications within the legal timeframe. Our Company acts in accordance with the regulations stipulated for the processing of special categories of personal data, pursuant to Article 6 of the KVKK (Personal Data Protection Law).
In accordance with Articles 8 and 9 of the KVKK, our Company complies with the statutory rules regarding the transfer of personal data and conducts its operations by taking into account the decisions adopted and communiqués published by the KVKK Board, as well as the lists of safe countries.
2.1. PROCESSING OF PERSONAL DATA IN ACCORDANCE WITH THE PRINCIPLES AND RULES STIPULATED IN THE LEGISLATION
A. Principles Regarding the Processing of Personal Data
a. Processing in Accordance with the Law and the Principle of Good Faith
Our Company acts in accordance with the principles introduced by legal regulations and the principle of good faith when processing personal data. In this context, our Company processes data by identifying the legal grounds necessitating such processing, observes the requirements of proportionality, refrains from using personal data beyond what is required for the specific purpose, and does not engage in processing activities without the knowledge of the data subjects.
b. Ensuring Personal Data is Accurate and, Where Necessary, Up-to-Date
Our Company ensures that the personal data it processes is accurate and up-to-date—taking into account the fundamental rights of data subjects and its own legitimate interests—and takes the necessary measures to this end. In this context, efforts are made to keep data regarding all categories of individuals up-to-date.
In particular, customer and potential customer data is updated with care, and marketing or promotional emails and offers are not sent to individuals in a manner contrary to their consent.
c. Processing for Specific, Explicit, and Legitimate Purposes
Our Company clearly and precisely defines the legitimate and lawful purpose for processing personal data. Our Company processes personal data only to the extent necessary for and in connection with the services it provides. The purpose for which personal data will be processed is determined prior to the processing activity and is recorded in the “Personal Data Inventory.”
d. Being Relevant, Limited, and Proportionate to the Purpose of Processing
Our Company processes personal data in a manner conducive to achieving the determined purposes and refrains from processing personal data that is unnecessary or unrelated to the realization of said purpose. In this context, processes are continuously reviewed, and efforts are made to implement the principle of “data minimization.”
B. Rules Regarding the Processing of Personal Data of a General Nature
The protection of personal data is a right defined in the Constitution; fundamental rights and freedoms may only be restricted by law—without infringing upon their essence—and solely for the reasons specified in the relevant articles of the Constitution. Pursuant to Article 20, Paragraph 3 of the Constitution, personal data may only be processed in cases prescribed by law or with the explicit consent of the data subject. Our Company processes personal data without seeking the data subject’s explicit consent only when the following conditions are met:
It is expressly prescribed by law,
It is necessary for the protection of the life or physical integrity of the data subject or another person, where the data subject is unable to express their consent due to actual impossibility or where their consent is not legally valid,
It is necessary to process personal data belonging to the parties to a contract, provided that such processing is directly related to the conclusion or performance of the contract,
It is necessary for the data controller to fulfill a legal obligation,
The data has been made public by the data subject themselves,
Data processing is necessary for the establishment, exercise, or protection of a right,
Data processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.
In the absence of the above conditions, our Company relies on the data subject’s explicit consent, which is based on free will and proper information. Particularly in the fields of Human Resources and employment relations, taking into account the subordinate relationship of the employee, the fundamental principle is to rely primarily on grounds for lawfulness other than consent; explicit consent is sought only when such other grounds are not applicable. Conversely, for activities such as marketing, the processing is carried out based on the data subject’s consent. However, in all instances where personal data is processed, data processing activities based on the “informing of employees” are invariably conducted.
C. Rules Regarding the Processing of Special Categories of Personal Data
Our Company complies with the regulations stipulated in the KVKK (Personal Data Protection Law) when processing personal data designated as “special categories” under the Law. Article 6 of the KVKK identifies certain types of personal data as “special categories”—data that carries the risk of causing victimization or discrimination if processed unlawfully—and requires that care and sensitivity be exercised during their processing. These include data concerning race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and clothing, membership in associations, foundations, or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. In accordance with the KVKK, our Company processes special categories of personal data in the following situations, provided that the necessary precautions are taken:
. Special categories of personal data other than those concerning the personal data subject’s health and sexual life are processed in cases prescribed by law or based on the personal data subject’s explicit consent;
. Special categories of personal data concerning the personal data subject’s health and sexual life are processed only for the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning and management of health services and their financing, by persons or authorized institutions and organizations subject to an obligation of confidentiality, or with the personal data subject’s explicit consent.
. Regardless of the grounds for processing, general data processing principles are always taken into account during processing activities, and compliance with these principles is ensured (KVKK Art. 4).
A “Personal Data Protection and Processing Policy” has been implemented within our company regarding the protection of special categories of data; our business units act in accordance with the provisions of this policy, and necessary measures are taken.
D. Informing and Clarifying Data Subjects Whose Data Is Processed
In accordance with Article 10 of the KVKK, our company informs personal data subjects at the time their personal data is obtained. In this context, the data subject is informed regarding the purpose for which the personal data will be processed, to whom and for what purpose the processed personal data may be transferred, the method and legal basis for collecting the personal data, and the rights of the data subject. Data subjects are informed about:
. Our company’s trade name and the identity of our representative, if any
. The purpose for which personal data will be processed by Beysu Global Enerji Anonim Şirketi
. To whom and for what purposes personal data processed by Beysu Global Enerji Anonim Şirketi may be transferred
. The method and legal basis for the collection of personal data
. The rights of the data subject listed in Article VIII.
2.2. TRANSFER OF PERSONAL DATA
Our Company may transfer the personal data and special categories of personal data of the data subject to third parties, provided that necessary security measures are taken and the transfer aligns with lawful purposes for personal data processing. In this regard, our Company acts in accordance with the regulations stipulated in Article 8 of the KVKK (Personal Data Protection Law). A. Principles Regarding the Transfer of Personal Data
Our Company may transfer personal data to third parties based on and limited to one or more of the personal data processing conditions specified in Article 5 of the Law, in line with legitimate and lawful personal data processing purposes:
Based on the explicit consent of the data subject whose personal data is being processed, or
Regardless of the grounds, general data processing principles are always taken into account during transfer processes, and compliance with these principles is ensured (KVKK Art. 4).
B. Transfer of Special Categories of Personal Data
Our Company, by exercising due care and implementing necessary security measures as well as the adequate measures prescribed by the KVKK Board; It may transfer the special category personal data of the data subject—whose personal data is processed for legitimate and lawful purposes—to third parties in the following situations.
Regardless of the grounds for transfer, general data processing principles are always taken into account, and compliance with these principles is ensured during transfer processes (KVKK Art. 4).
C. Transfer of Personal Data Abroad
Our Company may transfer personal data and special categories of personal data—which it has processed by taking necessary security measures in line with lawful personal data processing purposes—to third parties. Personal data processed by our Company: Personal data may be transferred to countries deemed GDPR-compliant by the KVKK Board, to foreign countries declared to possess adequate protection (“Foreign Country with Adequate Protection”), or—in the absence of adequate protection—to foreign countries where data controllers in Turkey and the relevant foreign country have committed in writing to providing adequate protection and where the KVKK Board has granted authorization (“Foreign Country Where the Data Controller Commits to Adequate Protection”). Accordingly, our Company acts in compliance with the regulations stipulated in Article 9 of the KVKK.
For legitimate and lawful personal data processing purposes, our Company may transfer personal data to Foreign Countries with Adequate Protection, to Foreign Countries Where the Data Controller Commits to Adequate Protection, and to countries deemed GDPR-compliant, provided that the data subject has given their explicit consent or, in the absence of such consent, if one of the following circumstances exists:
2.3. PERSONAL DATA CATEGORIZATIONS
The individuals whose data is processed by our Company and the data processed within this scope are categorized as follows:
PERSON AND DATA CATEGORIZATION
| Job Applicant | Natural persons who have applied for a job with our company via any means or have made their resumes and related information available for our company’s review. |
| Worker | Natural persons working at our company |
| Potential Customer | Natural persons who have requested or are interested in using our services or who have been evaluated in accordance with the rules of commercial practice and honesty as they may have this interest. |
| Supplier Employee | Natural persons employed by institutions with which our company maintains any form of business relationship (such as, but not limited to, business partners and suppliers) |
| Supplier Representative | Natural persons who are shareholders and authorized representatives of the institutions with which our company maintains business relationships. |
| Customer | Natural persons who use or have used the services offered by our Company, regardless of whether there is any contractual relationship with our Company. |
| Visitor | Natural persons who have entered the physical premises owned by our company for various purposes or who visit our websites. |
| OTHER | Third-party natural persons associated with the aforementioned individuals (e.g., family members and close associates), for the purpose of ensuring the security of commercial transactions between our company and the aforementioned parties, or protecting the rights and serving the interests of said individuals. |
| Identity Data | Information clearly pertaining to an identified or identifiable natural person—such as details found in documents like driver’s licenses, national ID cards, residence permits, passports, attorney ID cards, and marriage certificates—that is processed either wholly or partially by automated means, or by non-automated means as part of a data filing system. |
| Contact Data | Information—such as a telephone number, address, or e-mail—that clearly belongs to an identified or identifiable natural person and is processed either wholly or partially by automated means, or by non-automated means as part of a data filing system. |
| Location Data | Information that is clearly associated with an identified or identifiable natural person; is processed—either wholly or partially by automated means, or by non-automated means as part of a data filing system—and determines the location of the personal data subject while using our services, or the location of employees of institutions with which we collaborate while they are using our Company’s vehicles. |
| Personnel Data | Any personal data—whether processed wholly or partially by automated means or non-automatedly as part of a data filing system—that clearly relates to an identified or identifiable natural person and is processed for the purpose of obtaining information that serves as the basis for establishing the employment-related rights of our employees or of natural persons with whom our Company has a working relationship. |
| Legal Transaction and Compliance Data | Your personal data—clearly pertaining to an identified or identifiable natural person and processed either wholly or partially by automated means, or by non-automated means as part of a data filing system—that is processed for the purposes of establishing and pursuing our legal claims and rights, fulfilling our obligations, and ensuring compliance with legal requirements and our company’s policies. |
| Customer Transaction Data | Information that is clearly associated with an identified or identifiable natural person and is contained within a data recording system—such as records regarding the use of our services, as well as instructions and requests necessary for the customer’s use of the services. |
| Physical Space Security Data | Personal data contained within a data recording system that clearly belongs to an identified or identifiable natural person, relating to records and documents obtained upon entry to or during one’s stay within a physical space. |
| Transaction Security Data | Personal data that clearly belongs to an identified or identifiable natural person, is contained within a data recording system, and is processed to ensure technical, administrative, legal, and commercial security during the conduct of activities. |
| Risk Management Data | Personal data that clearly belongs to an identified or identifiable natural person and is contained within a data recording system; processed—in order to manage our commercial, technical, and administrative risks—by means of methods used in accordance with generally accepted legal and commercial practices and the principle of good faith in these areas. |
| Financial Data | Personal data processed in relation to information, documents, and records—which clearly pertain to an identified or identifiable natural person and are processed either wholly or partially by automated means or by non-automated means as part of a data filing system—that reflect any financial consequences arising from the type of legal relationship established between our company and the personal data subject. |
| Performance and Career Development Data | Personal data belonging to an identified or identifiable natural person—processed either wholly or partially by automated means, or by non-automated means as part of a data filing system—that is processed for the purpose of measuring the performance of our employees or natural persons with whom our Company has a working relationship, and for planning and executing their career development within the scope of our Company’s human resources policy. |
| Marketing Data | Personal data that clearly belongs to an identified or identifiable natural person and is processed—either wholly or partially by automated means, or by non-automated means as part of a data filing system—for the purpose of marketing our services by customizing them in line with the personal data subject’s usage habits, preferences, and needs; as well as the reports and evaluations generated as a result of such processing. |
| Visual and Audio Data | This refers to personal data that clearly belongs to an identified or identifiable natural person and is processed either wholly or partially by automated means, or by non-automated means as part of a data filing system; e.g., photographs and camera recordings (excluding those falling under Physical Space Security Information), audio recordings, and data contained in documents that are copies of documents containing personal data. |
| Sensitive Data (Health, Sexual Life) | Data concerning health and sexual life Data regarding race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership in an association, foundation, or trade union, criminal convictions and security measures, as well as biometric and genetic data. |
SECTION 3: LEGAL BASES AND PURPOSES FOR THE PROCESSING OF PERSONAL DATA
3.1. LEGAL BASES FOR THE PROCESSING OF PERSONAL DATA
General Principles
Although the legal bases for the processing of personal data by our Company may vary, all personal data processing activities are conducted in accordance with the general principles set forth in Article 4 of Law No. 6698. Accordingly, the following general principles are observed in all data processing activities:
Compliance with the law and rules of good faith,
Being accurate and, where necessary, up-to-date,
Processing for specific, explicit, and legitimate purposes,
Being relevant, limited, and proportionate to the purposes for which they are processed,
Retention for the period stipulated in the relevant legislation or required for the purpose for which they are processed.
Grounds for Lawfulness
a. Existence of the Personal Data Subject’s Explicit Consent
One of the conditions for processing personal data is the explicit consent of the data subject. The personal data subject’s explicit consent must be declared regarding a specific matter, based on information, and given of their own free will.
b. Being Expressly Provided for by Law
The data subject’s personal data may be processed lawfully if such processing is expressly provided for by law.
For example, the reporting of our employees’ identities to competent authorities in accordance with Identity Notification Legislation.
c. Inability to Obtain the Data Subject’s Explicit Consent Due to Factual Impossibility
The data subject’s personal data may be processed if such processing is necessary to protect the life or physical integrity of the data subject or another person, in cases where the data subject is unable to express their consent due to factual impossibility or where their consent cannot be deemed valid. For example, sharing the blood type information of an employee who has lost consciousness with a physician.
d. Direct Relevance to the Conclusion or Performance of a Contract
Personal data may be processed if such processing is necessary for the parties to a contract, provided that it is directly related to the conclusion or performance of said contract. For example, obtaining a CV from a candidate to conclude an employment contract, or obtaining an address to facilitate notifications within the scope of the contract.
e. Fulfillment of the Company’s Legal Obligation
The data subject’s personal data may be processed if such processing is necessary for our Company to fulfill its legal obligations as a data controller. For example, processing family information to enable an employee to benefit from the Minimum Living Allowance.
f. Making Personal Data Public by the Data Subject
The relevant personal data may be processed if the data subject has made their personal data public. For example, if our Company’s customers submit complaints, requests, or suggestions on a publicly accessible online platform, they have made the relevant information public. In such cases, it is permissible for a Company representative to process the data, provided that such processing is limited to the purpose of responding to the complaints, requests, or suggestions. g. Necessity of Data Processing for the Establishment or Protection of a Right
The personal data of the data subject may be processed if such processing is necessary for the establishment, exercise, or protection of a right. For example, the retention of data serving as evidence (such as sales contracts or invoices) and its use when necessary.
h. Necessity of Data Processing for the Legitimate Interests of Our Company
The personal data of the data subject may be processed if such processing is necessary for the legitimate interests of our Company, provided that it does not harm the fundamental rights and freedoms of the data subject. For example, the monitoring of critical areas of the Company via security cameras for the purpose of preventing theft or ensuring occupational safety.
Processing of Special Categories of Personal Data and Grounds for Lawfulness
Special categories of personal data may be processed by our Company without the data subject’s explicit consent only in cases prescribed by law and provided that adequate measures determined by the Personal Data Protection Board are taken. Special categories of personal data concerning the data subject’s health and sexual life may be processed only by persons under an obligation of confidentiality or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning and management of health services and their financing. Regardless of the grounds involved, general data processing principles are always taken into account during processing activities, and compliance with these principles is ensured (Personal Data Protection Law, Art. 4).
3.2. PURPOSES OF PROCESSING PERSONAL DATA
Our Company processes personal data within the scope of the purposes and conditions set forth in Article 5, Paragraph 2 and Article 6, Paragraph 3 of the Personal Data Protection Law No. 6698. During the data processing process, the aforementioned legal grounds are taken into account, and the data subject’s consent is requested if no other grounds for lawfulness exist. In this context, compliance with general principles under Article 4 is also assessed; above all, it is required that the data processing activity generally aligns with principles of lawfulness. The data subject’s consent is obtained in a manner that is “explicit, informed, and based on free will.” The purposes for processing personal data are also specified in our Company’s Personal Data Inventory.
Personal data within our Company’s units is processed specifically for the following purposes:
1. As an employer, it is necessary to process employees’ personal data in order to fulfill mutual obligations arising from the employment contract. Employees’ personal data are processed and stored in a manner that is lawful and in accordance with the rules of good faith; accurate and, where necessary, up-to-date; for specific, explicit, and legitimate purposes; and in a manner that is relevant, limited, and proportionate to the purpose. In this context, the legal bases for processing personal data include: the execution of processes regarding the establishment, performance, and termination of employment contracts in compliance with the law; the Company’s legitimate interests (provided they do not infringe upon fundamental rights and freedoms); situations expressly stipulated by law; the fulfillment of legal obligations related to employment; instances where data processing is necessary for the establishment, exercise, or protection of rights in legal proceedings; and—in cases falling outside these categories—the explicit, informed consent freely given by the employees.
2. The Company’s legitimate interests necessitate the processing of employees’ personal data within the scope of activities required by the Company’s line of business. Indeed, personal data processing activities may be conducted for purposes such as preventing misconduct and theft, ensuring general security, or maintaining occupational health and safety. However, even in such instances, great care is taken to ensure that employees’ fundamental rights and freedoms are not infringed upon.
3. The vast majority of the employees’ personal data being processed is obtained from information provided to the Company by the employees themselves. Additionally, in certain cases, such data may be acquired from internal sources (such as Company managers) or employee references, or obtained from systems established by public institutions and organizations as required by the nature of employment.
4. The personal data of employees being processed consists of information such as application forms and references, employment contracts and amendments thereto, contact details, payroll-related information, family or next-of-kin details (such as emergency contacts), educational records, performance evaluation records, disciplinary records, and camera footage.
5. Rules regarding the processing of employees’ personal data are set out in various Company policies and procedures. In this regard, the “Personal Data Protection and Processing Policy,” available on the Company’s website, may be consulted. This document can also be accessed via the Company’s intranet/QDMS system or obtained in hard copy from the Human Resources Department.
6. Employees’ health information is also included among the personal data processed. As a general rule, information concerning employees’ health and sexual life is processed by persons under a duty of confidentiality or by authorized institutions and organizations for purposes such as protecting public health; conducting preventive medicine, medical diagnosis, treatment, and care services; and planning and managing health services and their financing. In this context, employees’ health data and related details are generally held by the workplace physician and the health unit.
7. Once the status of “employee” is attained (such information is not requested during the candidate stage), if an employee becomes a union member, data regarding union membership may also be processed in accordance with express legal provisions in order to fulfill statutory requirements. Furthermore, as a general rule, employees’ race, ethnic origin, political views, philosophical beliefs, religion, sect or other beliefs, attire, and biometric and genetic data are not included among the personal data processed unless expressly provided for by law; should an exceptional case arise, the relevant requirements are carefully evaluated prior to the processing of such personal data.
8. The Company monitors and oversees its information and communication tools (telephones, mobile phones, computers, and the internet). Law No. 5651 and the Company’s legitimate interests constitute the legal basis for these practices.
9. Vehicle tracking systems may be implemented in the Company’s vehicles for reasons of “security and the more effective management of vehicles and personnel.” This activity is based on the Company’s legitimate interests and is carried out without infringing upon the fundamental rights and freedoms of employees.
10. Personal data is processed for the following purposes: ensuring the implementation of the Company’s human resources policies; recruiting personnel for open positions in accordance with these policies; conducting human resources operations; selecting job candidates; managing personnel records; determining training and career plans; and fulfilling obligations and taking necessary measures regarding occupational health and safety.
11. Personal data belonging to employees of suppliers or subcontractors may also be processed by our organization. Indeed, Law No. 6331 specifies the documents and information that the principal employer must verify regarding employees arriving from other workplaces in the context of occupational health and safety. Similarly, Labor Law No. 4857 and the Social Insurance and General Health Insurance Law No. 5510 impose obligations on the principal employer regarding subcontractor employees and temporary workers, outlining the matters that must be verified. Accordingly, the processing of personal data of workers employed at our workplace—who are affiliated with suppliers or other employers—is based on our business’s legitimate interests, as well as the aforementioned legal regulations.
12. Personal data are also [processed for]:
work and residence permit procedures
Video surveillance activities at the workplace—conducted for purposes of occupational health and safety, general security, and product safety—are carried out based on the Company’s legitimate interests, provided that the fundamental rights and freedoms of our visitors, the individuals whose data is processed in this context, and—in particular—our employees are not infringed upon.
SECTION 4: STORAGE, DELETION, DESTRUCTION, AND ANONYMIZATION OF PERSONAL DATA
Even if personal data has been processed in accordance with the relevant legal provisions—specifically Article 138 of the Turkish Penal Code and Article 7 of the KVKK (Law on the Protection of Personal Data)—our Company deletes, destroys, or anonymizes such data either upon its own decision or at the request of the personal data subject, should the grounds necessitating the processing cease to exist.
4.1. STORAGE OF PERSONAL DATA AND STORAGE PERIODS
Our Company retains personal data for the duration specified in applicable laws and regulations where such retention is mandated. If no specific retention period is prescribed by legislation, personal data is retained for the period necessary for processing—determined in accordance with our Company’s practices and commercial customs regarding the services provided—and may be stored to serve as evidence in legal disputes, to assert rights related to the personal data, or to establish a defense. Retention periods are established based on the statute of limitations applicable to the assertion of such rights, as well as precedents involving past requests made to our Company regarding similar matters, even after the statutory limitation period has expired. In such cases, the stored personal data is not accessed for any other purpose; access is granted only when required for use in the relevant legal dispute. Once the applicable period expires, the personal data is deleted, destroyed, or anonymized.
4.2. DELETION, DESTRUCTION, AND ANONYMIZATION OF PERSONAL DATA
In accordance with the provisions of Article 138 of the Turkish Penal Code and Article 7 of the Personal Data Protection Law (KVKK), personal data—even if processed lawfully—shall be deleted, destroyed, or anonymized upon the decision of our Company or at the request of the personal data subject if the grounds necessitating the processing cease to exist. In this context, our Company fulfills the relevant obligation using the methods described in this section.
A. Deletion of Personal Data
a. Process of Deleting Personal Data
Our Company may delete personal data—even if processed in accordance with the provisions of the relevant law—upon its own decision or at the request of the personal data subject, should the grounds requiring their processing cease to exist. The deletion of personal data is the process of rendering personal data inaccessible and unusable for the relevant users. Our Company takes all necessary technical and administrative measures to ensure that deleted personal data remains inaccessible and unusable for the relevant users.
b. Procedure for Deleting Personal Data
The procedure to be followed for the deletion of personal data is as follows:
c. Methods for Deleting Personal Data
Since personal data may be stored on various recording media, they are deleted using methods appropriate to the specific recording medium.
B. Destruction of Personal Data
a. Process of Destroying Personal Data
Our Company may destroy personal data—even if processed in accordance with the provisions of the relevant law—upon its own decision or at the request of the personal data subject, should the grounds requiring their processing cease to exist. The destruction of personal data is the process of rendering personal data inaccessible, irretrievable, and unusable by anyone in any way. Our Company takes all necessary technical and administrative measures regarding the destruction of personal data.
b. Methods for the Destruction of Personal Data
To destroy personal data, all copies containing the data are identified, and the systems containing the data are destroyed individually.
C. Anonymization of Personal Data
a. Process of Anonymizing Personal Data
Anonymization of personal data is the process of rendering personal data such that it can under no circumstances be associated with an identified or identifiable natural person, even when matched with other data. Our Company may anonymize personal data that has been processed in accordance with the law once the grounds requiring its processing cease to exist. Anonymization is carried out by rendering the personal data impossible to associate with an identified or identifiable natural person—even through methods such as reversal by the data controller or recipient groups, or matching the data with other data—by employing techniques appropriate to the storage medium and the relevant field of activity. Our Company takes all necessary technical and administrative measures to anonymize personal data.
Personal data that has been anonymized in accordance with Article 28 of the Personal Data Protection Law (KVK Law) may be processed for purposes such as research, planning, and statistics. Such processing activities fall outside the scope of the KVK Law, and the explicit consent of the personal data subject is not required.
b. Methods of Anonymizing Personal Data
Anonymization is the process of preventing the identification of the data subject—or causing the data to lose the characteristic of being distinguishable within a group or crowd in a way that links it to a natural person—by removing or altering all direct and/or indirect identifiers in a dataset. Data that does not point to a specific person as a result of the prevention or loss of these characteristics is considered anonymized data. The objective of anonymization is to sever the link between the data and the person whom that data identifies. Anonymization methods refer to all processes—carried out via techniques such as grouping, masking, derivation, generalization, or randomization (whether automated or not)—that sever the link between records in a personal data filing system and the individuals to whom they relate. Data obtained through the application of these methods must not allow for the identification of a specific individual.
SECTION 5: RIGHTS OF DATA SUBJECTS
5.1. SCOPE OF DATA SUBJECTS’ RIGHTS AND EXERCISE OF THESE RIGHTS
A. Rights of Data Subjects
Individuals whose personal data is processed by our Company have the following rights:
SECTION 6: ENSURING THE SECURITY OF PERSONAL DATA
6.1. OUR OBLIGATIONS REGARDING DATA SECURITY
Beysu Global Enerji Anonim As the Company, administrative and technical measures—exemplified below—will be implemented to prevent the unlawful processing of and unlawful access to personal data, and to ensure the preservation of personal data.
6.2. DATA SECURITY MEASURES
6.3. STORAGE OF PERSONAL DATA IN SECURE ENVIRONMENTS
Our Company takes the necessary technical and administrative measures—based on technological capabilities and implementation costs—to store personal data in secure environments and to prevent its destruction, loss, or alteration for unlawful purposes.
A. Technical Measures Taken to Store Personal Data in Secure Environments
The primary technical measures taken by our Company to store personal data in secure environments are listed below:
B. Administrative Measures Taken for Storing Personal Data in Secure Environments
The primary administrative measures taken by our Company to ensure the storage of personal data in secure environments are listed below:
Employees are informed about ensuring the secure storage of personal data.
In cases where our Company procures external services for the storage of personal data, contracts concluded with the relevant service providers—to whom personal data is lawfully transferred—include provisions requiring the recipients to implement necessary security measures for personal data protection and to ensure compliance with these measures within their own organizations; actions in this regard are taken in accordance with the provisions of the Company’s “Principles on the Protection of Personal Data in Relations with Third Parties” Policy.
6.4. TRAINING
Our Company provides its employees with the necessary training regarding the protection of personal data, within the scope of the Policy, Personal Data Protection (KVK) Procedures, and Personal Data Protection Law (KVKK) regulations.
The training sessions place particular emphasis on the definitions of “special categories of personal data” and the practices regarding their protection.
If a Company employee accesses personal data—whether physically or via computer systems—our Company provides that employee with training specific to such access (for example, regarding the specific computer program being accessed). 6.5. AUDIT
A. Raising Awareness and Auditing Business Units Regarding the Protection and Processing of Personal Data
Our Company ensures that necessary notifications are made to business units to raise awareness regarding the prevention of unlawful processing of personal data, the prevention of unlawful access to data, and the safeguarding of data.
B. Raising Awareness and Auditing Business Partners and Suppliers Regarding the Protection and Processing of Personal Data
Our Company provides necessary information to business partners to raise awareness regarding the prevention of unlawful processing of personal data, the prevention of unlawful access to data, and the safeguarding of data.
C. Auditing Measures Taken Regarding the Protection of Personal Data
Our Company reserves the right to audit—regularly, at any time, ex officio, and without prior notice—whether all employees, departments, and contractors of the Company comply with this Policy and the KVKK Regulations; within this scope, it conducts or commissions the necessary routine audits. The results of these audits are evaluated within the Company’s internal operations, and necessary activities are carried out to improve the measures taken.
Measures to be Taken in the Event of Unauthorized Disclosure of Personal Data:
In accordance with Article 12 of the Personal Data Protection Law (KVKK), our Company operates a system ensuring that, should personal data be obtained by others through unlawful means, the situation is reported to the relevant data subject and the Personal Data Protection Board as soon as possible.