Kaleseramik Cookie Policy

Contents

  1. PURPOSE AND SCOPE
  2. DEFINITIONS
  3. DEFINITION OF A COOKIE
  4. TYPES OF COOKIES
    • 4.1. Cookies by Duration
    • 4.2. Cookies by Purpose
    • 4.3. Cookies by Party
  5. DATA CONTROLLER CRITERIA FOR COOKIE PROCESSING
  6. CONDITIONS FOR PROCESSING PERSONAL DATA THROUGH COOKIES
    • 6.1. Use of Cookies Based on Explicit Consent
    • 6.2. Use of Cookies Under Processing Conditions Other Than Explicit Consent
  7. COOKIE WALLS
  8. RESPONSIBILITY OF THE PARTIES
  9. TRANSFERS ABROAD
  10. ENTRY INTO FORCE AND AMENDMENTS
  11. OUR DETAILS AND CONTACT INFORMATION

1. PURPOSE AND SCOPE

This Cookie Policy ("Policy") aims to provide general definitions and identify the types of cookie data relating to visitors to the website of KALESERAMİK, ÇANAKKALE KALEBODUR SERAMİK SANAYİ A.Ş. (hereinafter KALESERAMİK or the "Company"), and to establish the procedures and principles for processing and managing cookie data, taking into account Personal Data Protection Law No. 6698 and the provisions of the "GUIDELINES ON COOKIE PRACTICES" published by the Board.

This Policy covers the processing of personal data through cookies; cookies that are not used to process personal data fall outside its scope. It applies to the Company's desktop and mobile websites and web applications.

We may update this Policy when necessary. Please therefore ensure that you access our current Policy on the date you use our web and mobile services.

2. DEFINITIONS

TermDefinition
"Explicit Consent"Consent relating to a specific matter, based on information and freely expressed.
"Obligation to Inform"The Company's obligation to provide information to Data Subjects, through the Data Controller or its authorised persons, when personal data is obtained, in accordance with Article 10 of the Personal Data Protection Law and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform.
"Data Subject", "Data Owner"Natural persons whose personal data is processed by the Company or persons/institutions authorised on its behalf.
"Personal Data"Any information relating to an identified or identifiable natural person.
"Anonymisation of Personal Data"The process of rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching it with other data.
"Processing of Personal Data"Any operation performed on personal data, wholly or partly by automated means or, provided it forms part of a data filing system, by non-automated means, including obtaining, recording, storing, retaining, altering, rearranging, disclosing, transferring, taking over, making available, classifying or preventing its use.
"Deletion of Personal Data"The process of rendering personal data inaccessible and unusable for the relevant users in any way.
"Destruction of Personal Data"The process of rendering personal data inaccessible, irretrievable and unusable by anyone in any way.
"Board"Personal Data Protection Board
"Authority"Personal Data Protection Authority
"Law", "Personal Data Protection Law"Personal Data Protection Law No. 6698
"Cookie Policy"This Cookie Policy, adopted by the Company, setting out the procedures and principles for processing and managing cookie data.
"Special Categories of Personal Data"Data relating to a person's race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
"Company"KALESERAMİK, ÇANAKKALE KALEBODUR SERAMİK SANAYİ A.Ş.
"VERBİS", "Registry"The Data Controllers Registry Information System maintained by the Presidency of the Personal Data Protection Authority.
"Data Processor"A natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the controller.
"Data Controller"A natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.

A cookie is a type of text file placed on a user's device by website operators and transmitted as part of an HTTP(S) (Hypertext Transfer Protocol) request. Cookies are small rich-text-format files that allow certain information relating to users to be stored on their terminal devices when they visit a web page.

4. TYPES OF COOKIES

Cookies are categorised by their duration, purpose and the parties that place them. The types of cookies and their descriptions are set out below.

4.1. COOKIES BY DURATION

Session Cookies

A session cookie, also known as a temporary cookie, is used to maintain the continuity of a session. Session cookies are deleted when the user closes their web browser.

Persistent Cookies

A persistent cookie is not deleted when the web browser is closed, but is deleted automatically on a specified date or after a specified period. Through this cookie, the user's processed data is transmitted to the server each time the user visits a website. For this reason, persistent cookies are sometimes called tracking cookies. For example, advertisers may record and use information about a user's web browsing habits over an extended period. They may also be used to ensure that users do not have to re-enter their login details every time they sign in to their website accounts.

4.2. COOKIES BY PURPOSE

Strictly Necessary Cookies (Mandatory Cookies)

These cookies are necessary for the website to function. They are essential for providing an information society service expressly requested by the user, such as logging in, completing a form or remembering privacy preferences.

Cookies used for the purposes covered by Criteria A and B discussed in Article 5 of this Policy are examples of strictly necessary cookies. In general, they may be regarded as cookies for which processing conditions other than explicit consent apply. If mandatory cookies are blocked, some parts of the website will not function. These cookies must not be used for marketing purposes.

Functional Cookies

These cookies are used for personalisation and remembering preferences on websites or applications, including applications on desktop, mobile or IoT devices. They provide functionality beyond that supplied by mandatory cookies. Where it is not clear that the data subject has expressly requested an information society service, explicit consent must be relied upon.

Performance and Analytics Cookies

These cookies enable statistical measurement to analyse users' behaviour on websites. They are frequently used to improve a website, including measuring the impact of advertisements on data subjects. Website owners use them to estimate the number of unique visitors, identify the most important search engine keywords leading to a web page, or track navigation on the website.

Advertising/Marketing Cookies

Advertising and marketing cookies aim to track users' online activities, identify their personal interests and display advertisements tailored to those interests. Although there are many types of online advertising, online behavioural advertising is the most widely preferred because it enables advertising based on individuals' tendencies and preferences and allows advertisers to use time and financial resources more efficiently. Online behavioural advertising involves monitoring individuals' internet activities, analysing those activities to create profiles, matching the profiled individual with suitable advertisements and displaying those advertisements to that individual.

4.3. COOKIES BY PARTY

Whether a cookie is first-party or third-party depends on the web page or domain that places it.

First-party cookies are placed directly by the website the user visits, namely the URL displayed in the browser's address bar (ornek.com.tr).

Third-party cookies are placed by a third party other than the website or domain the user visits.

Personal Data Protection Law No. 6698 does not expressly regulate cookies. However, because the third paragraph of Article 51 of Electronic Communications Law No. 5809 is partially aligned with the third paragraph of Article 5 of EU Directive 2002/58/EC, the Authority considers that Law No. 5809 may have a limited scope of application to cookies for operators acting as data controllers. Article 51 of Electronic Communications Law No. 5809, entitled "Processing of Personal Data and Protection of Privacy", does not contain the provisions of the ePrivacy Directive 2002/58/EC relating to information society services. For information society services not specifically regulated by Law No. 5809, Law No. 6698 is considered applicable to the processing of personal data through cookies. In this context, the Personal Data Protection Board's Decision No. 2020/173 dated 27.02.2020 may be taken into account.

The third paragraph of Article 51 of Electronic Communications Law No. 5809 covers only companies that provide electronic communications services and/or electronic communications networks and operate their infrastructure (operators and sub-operators). Other data controllers, such as https://kale.com.tr/, do not fall within this scope. Accordingly, the phrase "ensuring communication" in that provision is considered to allow only data controllers qualifying as "operators" to process data through cookies without explicit consent, and only within "Criterion A" described below. Nevertheless, the purpose specified in Article 51 of storing information on subscribers' or users' terminal devices or accessing stored information is not exclusive to the use of cookies.

5.2. CRITERIA

Under Law No. 6698, data controllers are advised to consider the following criteria when processing personal data through cookies:

Criterion A: The cookie is used solely to transmit a communication over an electronic communications network.

Criterion B: The use of the cookie is strictly necessary for information society services expressly requested by the subscriber or user in order to receive the service.

6. CONDITIONS FOR PROCESSING PERSONAL DATA THROUGH COOKIES

The Company also takes into account the other data processing conditions listed in Articles 5 and/or 6 of the Law, on the basis of "the existence of explicit consent" or "the assessment to be made by the data controller specifically in relation to its processing of personal data through cookies".

When applying the processing conditions in Articles 5 and/or 6, explicit consent need not be obtained from the data subject if the processing is based on one of the conditions in the Law other than explicit consent. The Company first assesses whether the purpose of the personal data processing activity is based on one of these other conditions. If the purpose does not meet any of the conditions in the Law other than explicit consent, the processing activity is based on the data subject's explicit consent.

Where the processing condition in Article 5(2)(f) of the Law is relied upon—processing being necessary for the legitimate interests of the data controller, provided that the fundamental rights and freedoms of the data subject are not harmed—the Company assesses the existence of a legitimate interest by conducting a balancing test. This compares the individual's fundamental rights and freedoms with the data controller's legitimate interest, also taking into account the scope of Criterion B.

Cookie use scenarios that do not fall within Criterion A or B described above include:

Social Plug-in Tracking Cookies

Many social networks offer social plug-in modules that website owners can integrate into their websites to provide certain services that may be regarded as "expressly requested" by their members. However, these modules may also be used to track members and non-members through third-party cookies for additional purposes such as behavioural advertising, analytics or market research. Cookies used for such purposes cannot be regarded as "strictly necessary" to provide functionality expressly requested by the user, so these tracking cookies do not fall within Criterion B. It is unlikely that there is any legal basis for social networks to collect data about non-members through social plug-ins without explicit consent. By default, social plug-ins do not place third-party cookies on pages shown to non-members.

Online Behavioural Advertising Cookies

Cookies used for behavioural advertising require explicit consent. This consent requirement naturally also covers related cookies used for advertising purposes, including cookies for frequency capping, financial record-keeping, advertising affiliation, click-fraud detection, research and market analysis, product development and debugging. None of these purposes relates to a service or functionality within information society services expressly requested by the user, as required by Criterion B.

The Company explains below the purposes of cookies that, in the relevant use scenarios, may rely on personal data processing conditions other than explicit consent.

User-input Cookies (Criterion B)

These are session cookies that track the user's input and transmit it to the service provider. They are first-party cookies linked to a Session ID, typically a unique number, and are expected to expire no later than the end of the session. First-party user-input session cookies typically track a user completing an online form or shopping basket, recording the products selected by clicking a button or the information entered into a form. For these cookies, the user must expressly request the provision of an information society service, for example by completing a form or clicking a button. As this type of cookie may be assessed under Criterion B, it does not require explicit consent.

Authentication Cookies (Criterion B)

Authentication cookies identify users when they log in to a website, for example an online insurance website. They are needed to visit the website or access content, such as viewing bank accounts or making transfers. These are usually session cookies, although in some cases they may be persistent cookies.

When users log in to their accounts, they expressly request access to content or functionality for which they are authorised. Without these cookies, they would need to enter their username and password for each page request. Authentication is therefore an essential part of the information society service expressly requested by the data subject, and these cookies do not require explicit consent under Criterion B. When assessing the scope of Criterion B, the Company considers that the user has requested only access to the site and the specific functionality they need. The Company also considers that using an authentication cookie does not provide a basis for using it for secondary purposes, such as behavioural tracking or advertising.

Persistent cookies that store authentication identifiers between browser sessions are not considered to fall within Criterion B. Users may be unaware that their authentication settings have not been cleared when they close the browser, and may return to the website believing they are anonymous while still logged in. In this case, the Company has adopted the common approach of adding a separate checkbox such as "remember me (uses cookies)" when the user opens an account on the website. This clarifies whether the user has expressly requested the service.

User-centric Security Cookies (Criterion B)

Criterion B may also apply to cookies intended to improve security within a service expressly requested by the user. This applies to cookies used to detect repeated failed login attempts on a website and other cookies designed to protect the login system against abuse. While login cookies typically expire at the end of a session, user security cookies have a longer lifespan to fulfil their security purpose.

Multimedia Player Session Cookies (Criterion B)

These cookies store technical data needed to play video or audio content, such as image quality, network connection speed and buffering parameters. Multimedia player session cookies are also known as "flash cookies". They expire when the session ends. When a user wishes to access video or text content, the service has been expressly requested, so the video display function is assessed under Criterion B.

User Interface Customisation Cookies (Criterion B)

These cookies store the user's preferences for a service on web pages and are not linked to persistent identifiers such as usernames. They may be placed only at the user's express request to remember a specific item of information, for example by clicking a button or checking a box. Like session cookies, they may remain valid for the duration of a session, or for weeks or months depending on their purpose. Typical examples include:

  • Language preference cookies used to remember the language selected by a user on a multilingual website, for example by clicking a flag.
  • Results display preference cookies used to remember a user's preferences for online search queries, such as the number of results displayed per page.

Even where the user has expressly requested customisation, for example by clicking a button or checkbox, this cannot, without additional information, be interpreted as an intention to have the choice remembered beyond one session. Such session cookies are considered to fall within Criterion B and do not require explicit consent.

Social Plug-in Content-sharing (Like, Share, Comment) Cookies (Criterion B)

Many social networks offer website operators "social plug-in modules" that can be integrated into their platforms, allowing social network users to share content they like or comments they make with their "friends". These modules store and access cookies on users' terminal equipment so that the social network can identify its members when they interact with the plug-ins.

A distinction is made between users who are logged in to a social network account through their browser, people who are not members of that network, and members who have logged out. By definition, social plug-ins are intended for social network users and do not offer a use case for non-members. Criterion B therefore does not apply to non-members or logged-out members. Explicit consent is obtained from non-members and logged-out members before social plug-ins use third-party cookies.

Many logged-in users, however, expect to access and use social plug-ins on third-party websites. In this specific case, a cookie is strictly necessary for functionality expressly requested by the user, and Criterion B applies. These must be session cookies, since persistent authentication cookies do not fall within the criteria mentioned above. As they serve a specific purpose, they expire when the user logs out of the social network or closes the browser where the "remember me" feature is not used.

Cookies Used for an Explicit Consent Management Platform (Criterion B)

A cookie used to remember, for a certain period, a data subject's consent preferences for cookies requiring explicit consent on the websites they visit is also considered to fall within Criterion B and does not require separate explicit consent. Its lifespan is determined with regard to the general principles in Article 4 of the Law.

First-party Analytics Cookies (Criterion B)

The use and production of traffic and/or performance statistics to manage a website or application are necessary for its proper functioning and therefore for providing the service. Cookies whose purpose is limited to measuring the audience of the site or application may meet needs such as measuring performance, identifying navigation problems, optimising technical performance or usability, and estimating required server capacity. Since their use in the operation and day-to-day management of a website or application relates to the requested service, first-party analytics are assessed under Criterion B.

To achieve this purpose, personal data is processed in a manner that is relevant, limited and proportionate, while personal data that does not need to be processed is anonymised. These cookies are likewise used only to produce anonymous statistics and not to track individuals' browsing across different websites or applications.

The measures taken by the Company include ensuring that cookies have a reasonable lifespan and that the data collected is not transmitted to third parties.

Cookies Used for Website Security (Criterion B)

Since a website's inability to provide a service or being taken out of service because of a security vulnerability prevents users from accessing the service they request, cookies used for website security are also considered strictly necessary for that service. For example, a cookie used by a web application firewall to identify users and limit the number of requests per user per session may be considered strictly necessary to ensure website security and users' access to the service, and therefore to provide a service requested by the user under Criterion B. For cookies serving this purpose, the Company may rely on processing conditions other than explicit consent, such as processing being necessary for the legitimate interests of the data controller, provided that the fundamental rights and freedoms of the data subject are not harmed.

Cookie walls prevent visitors from viewing a website's content unless they consent to the use of all cookies on the website.

In relation to the requirement that explicit consent be freely given, cookie walls may prevent data subjects from making a genuine choice when expressing consent. Where consent to cookies is imposed as a prerequisite for the service by placing a cookie wall in front of website access, this may impair the data subject's free will, and the explicit consent obtained in this way will not be valid. Nevertheless, subject to an assessment of each individual case, the Company may offer certain fair alternatives to a cookie wall so that data subjects can obtain a service.

8. RESPONSIBILITY OF THE PARTIES

When the Company places third-party cookies on its website, both the Company, as data controller, and the third party are responsible for ensuring that users are clearly informed about the cookies and that their consent is obtained.

9. TRANSFERS ABROAD

The transfer of personal data abroad is governed by Article 9 of Law No. 6698. Under the first paragraph of that article, the first condition for transfer is obtaining the data subject's explicit consent. Apart from explicit consent, the Company may transfer a data subject's personal data abroad where the processing conditions in Article 5(2) or Article 6(3) of Law No. 6698 are met and adequate protection exists, or, where adequate protection does not exist, the data controllers in Türkiye and the relevant foreign country undertake in writing to provide adequate protection and the Personal Data Protection Board grants permission.

10. ENTRY INTO FORCE AND AMENDMENTS

This Policy is published within the Company and enters into force on its publication date. The Company may amend this Policy at any time through periodic reviews. Amendments take effect on the day the revised Policy is published.

11. OUR DETAILS AND CONTACT INFORMATION

If you have any questions about this Policy or our approach to processing and protecting your personal data, or wish to exercise any of the rights stated in this Policy, you may obtain information using any of the following contact methods:

KALESERAMİK, ÇANAKKALE KALEBODUR SERAMİK SANAYİ A.Ş.

  • Address: Büyükdere Cad., Kaleseramik Binası, Levent, TR-34330 İstanbul
  • Email: ks-kvkk@kale.com.tr
  • Registered Electronic Mail (KEP) Address: kaleseramikas@hs01.kep.tr

Compare

Compare
Compare