Personal Data Processing and Protection Policy

KALESERAMİK ÇANAKKALE KALEBODUR SERAMİK SAN. A.Ş. PERSONAL DATA PROCESSING AND PROTECTION POLICY

Contents

  1. PURPOSE AND SCOPE
  2. DEFINITIONS
  3. GENERAL PRINCIPLES FOR PROCESSING PERSONAL DATA
    • 3.1. Processing Lawfully and in Good Faith
    • 3.2. Ensuring Personal Data Is Accurate and, Where Necessary, Up to Date
    • 3.3. Processing for Specific, Explicit and Legitimate Purposes
    • 3.4. Being Relevant, Limited and Proportionate to the Purposes of Processing
    • 3.5. Retention for the Period Prescribed by Relevant Legislation or Necessary for the Purpose of Processing
  4. INFORMATION ON THE PROCESSING OF PERSONAL DATA
    • 4.1. Categories of Personal Data
    • 4.2. Groups of Persons Whose Personal Data Is Processed
    • 4.3. Purposes of Processing Personal Data
    • 4.4. Conditions for Processing Personal Data
    • 4.5. Conditions for Processing Special Categories of Personal Data
    • 4.6. Personal Data Collection Channels
    • 4.7. Transfer of Personal Data
      • 4.7.1. Domestic Transfers
      • 4.7.2. Transfers Abroad
    • 4.8. Retention and Disposal of Personal Data
  5. PERSONAL DATA SECURITY MEASURES
  6. OBLIGATION TO INFORM
  7. RIGHTS OF DATA SUBJECTS
  8. RELATED DOCUMENTS
  9. ENTRY INTO FORCE AND AMENDMENTS
  10. OUR DETAILS AND CONTACT INFORMATION

1. PURPOSE AND SCOPE

Protecting personal data and ensuring its privacy are part of the corporate culture of KALESERAMİK ÇANAKKALE KALEBODUR SERAMİK SAN. A.Ş. (hereinafter "Kale Seramik" or the "Company"). The Company exercises the utmost care and effort to process and protect individuals' personal data in the course of its activities in accordance with applicable legal rules and universal principles of law. Acting as data controller, the Company processes and protects personal data under this Personal Data Processing and Protection Policy ("Policy" or "Data Protection Policy").

This Data Protection Policy relates to the personal data of data subjects other than our employees that our Company processes as Data Controller, wholly or partly by automated means or, provided it forms part of a data filing system, by non-automated means. It explains how the principles and rules established by relevant legislation are applied in the Company's personal data protection processes. This Policy describes the Company's general policy and processes for processing and protecting personal data. The obligation to inform under Article 10 of the Personal Data Protection Law is fulfilled through the relevant privacy notices provided to data subjects for each specific process.

Applicable legislation, secondary regulations and universal principles of law take precedence in the protection and lawful processing of personal data. In the event of a conflict between our Data Protection Policy and applicable regulations, the applicable regulations prevail.

We may review, amend or renew our Policy and the way we process personal information from time to time. We will publish the updated Policy on our website at www.kalegrubu.com.tr. The revised terms take effect from their publication date.

2. DEFINITIONS

TermDefinition
"Explicit Consent"Consent relating to a specific matter, based on information and freely expressed.
"Obligation to Inform"The Company's obligation to provide information to Data Subjects, through the Data Controller or its authorised persons, when personal data is obtained, in accordance with Article 10 of the Personal Data Protection Law and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform.
"Data Subject", "Data Owner"Natural persons whose personal data is processed by the Company or persons/institutions authorised on its behalf.
"Disposal"The destruction or anonymisation of personal data.
"Personal Data"Any information relating to an identified or identifiable natural person.
"Anonymisation of Personal Data"The process of rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching it with other data.
"Processing of Personal Data"Any operation performed on personal data, wholly or partly by automated means or, provided it forms part of a data filing system, by non-automated means, including obtaining, recording, storing, retaining, altering, rearranging, disclosing, transferring, taking over, making available, classifying or preventing its use.
"Deletion of Personal Data"The process of rendering personal data inaccessible and unusable for the relevant users in any way.
"Destruction of Personal Data"The process of rendering personal data inaccessible, irretrievable and unusable by anyone in any way.
"Board"Personal Data Protection Board
"Authority"Personal Data Protection Authority
"Law", "Personal Data Protection Law"Personal Data Protection Law No. 6698
"Data Protection Policy"The Personal Data Protection and Processing Policy adopted by the Company.
"Special Categories of Personal Data"Data relating to a person's race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
"Profiling"Using automated means to process personal data to determine certain aspects about people, such as analysing or predicting their performance in activities, reliability, economic situation, personal preferences, interests, behaviour, location or movements.
"Company"KALESERAMİK ÇANAKKALE KALEBODUR SERAMİK SAN. A.Ş.
"VERBİS", "Registry"The Data Controllers Registry Information System maintained by the Presidency of the Personal Data Protection Authority.
"Data Processor"A natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the controller.
"Data Controller"A natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.
"Electronic Environment"Environments in which personal data can be created, read, altered and written using electronic devices.
"Non-electronic Environment"All written, printed, visual and other media outside electronic environments.

3. GENERAL PRINCIPLES FOR PROCESSING PERSONAL DATA

The Company complies with the mandatory "General Principles" for processing personal data listed in Article 4 of the Personal Data Protection Law:

3.1. Processing Lawfully and in Good Faith

The Company manages its personal data processing activities in accordance with legal rules, universal principles of law and good faith. It informs data subjects as necessary to ensure transparency and considers their interests and reasonable expectations. In this way, it prevents processing activities from producing results that data subjects neither expect nor should be expected to anticipate.

3.2. Ensuring Personal Data Is Accurate and, Where Necessary, Up to Date

As a rule, personal data is processed on the basis of, and as provided in, data subjects' statements, and is presumed accurate as stated. The Company exercises reasonable care and attention to ensure that personal data held within its organisation is accurate, up to date and free from incorrect information. Where a data subject notifies the Company of changes to processed personal data, the Company ensures that the necessary administrative and technical mechanisms are in place to update the data in the relevant database.

3.3. Processing for Specific, Explicit and Legitimate Purposes

Before starting a personal data processing activity, the Company defines its legitimate and lawful purposes specifically and clearly. It processes personal data in connection with its products and services and only to the extent necessary for them.

3.4. Being Relevant, Limited and Proportionate to the Purposes of Processing

Personal data is processed in a manner that is relevant, limited and proportionate to the purposes determined by the Company and explained to the data subject. The Company takes care to maintain a reasonable balance between the processing activity and its intended purpose, ensuring that processing is limited to what is needed to achieve that purpose.

3.5. Retention for the Period Prescribed by Relevant Legislation or Necessary for the Purpose of Processing

The Company retains personal data for the period prescribed by legislation or required for its processing purpose. When that statutory period expires or all processing purposes cease to exist, it deletes, destroys or anonymises the data. As Data Controller, the Company has defined retention periods, disposal intervals, and the technical and administrative measures to be applied to storage in its Personal Data Retention and Disposal Policy, and recognises its obligation to retain personal data in accordance with these rules.

These principles apply regardless of whether the Company processes personal data based on explicit consent or other processing conditions. The Company processes personal data in accordance with the processing conditions and general principles, and fulfils its obligation to inform data subjects.

4. INFORMATION ON THE PROCESSING OF PERSONAL DATA

The Company sets out below, subject to amendment and updating, the categories of personal data it processes, the groups of data subjects concerned, processing purposes, the legal conditions on which processing is based, collection channels, recipient groups, retention periods and disposal processes for data whose retention period has expired, and the security measures taken to protect personal data throughout these processes. Summaries of this information are publicly published and updated in the VERBİS registry information system on the Authority's website (verbis.kvkk.gov.tr).

4.1. CATEGORIES OF PERSONAL DATA

The Company categorises the personal data it processes to ensure compliance with legal requirements and proper management of personal data processing and protection processes.

All personal data categories are organised under two main categories: "Personal Data" and "Special Categories of Personal Data". The categories processed within our Company and their definitions are as follows:

Personal Data CategoryDefinition
Identity DataSuch as name and surname, parents' names, mother's maiden name, date and place of birth, marital status, identity card serial number, Turkish Republic identity number and signature
Contact DataSuch as address number, email address, contact address, registered electronic mail (KEP) address and telephone number
LocationInformation about the person's location
Personnel DataSuch as payroll information, disciplinary investigations, employment start and termination records, asset declarations, CV information and performance assessment reports
Legal Proceedings DataSuch as information in correspondence with judicial authorities and in case files
Customer Transaction DataSuch as call centre records, invoices, promissory notes, cheque details, information on counter receipts, orders and requests
Transaction Security DataSuch as IP address information, website login/logout details and password/passcode information
Financial DataSuch as bank, IBAN and balance sheet information, financial performance, credit and risk information, and assets
Professional Experience DataSuch as diplomas, courses attended, professional training, certificates and transcripts
Visual and Audio Recording DataSuch as photographs, videos, and visual and audio recordings
MarketingShopping history, surveys, cookie records and information obtained through campaigns
Physical Premises SecuritySuch as visitor entry/exit records and camera recordings
Special Category of Personal DataDefinition
Criminal Convictions and Security MeasuresSuch as information relating to criminal convictions and security measures
Health InformationSuch as disability information, blood group, personal health information, and information about devices and prostheses used
Biometric DataSuch as palm, fingerprint, retinal scan and facial recognition information

4.2. GROUPS OF PERSONS WHOSE PERSONAL DATA IS PROCESSED

The groups of data subjects whose personal data is processed within our Company and their definitions are publicly notified and published in VERBİS on the Authority's website (verbis.kvkk.gov.tr).

4.3. PURPOSES OF PROCESSING PERSONAL DATA

The Company processes personal data appropriately in accordance with the "General Principles for Processing Personal Data" in Article 4 of the Law, described above, and on the basis of and limited to at least one of the processing conditions in Articles 5 and 6. Under Article 10 and secondary legislation, the Company separately informs each group of data subjects of the data processing categories and purposes through the relevant privacy notices. The Company's processing purposes are declared in the Data Controllers Registry Information System (VERBİS) and remain publicly accessible there (link: verbis.kvkk.gov.tr).

4.4. CONDITIONS FOR PROCESSING PERSONAL DATA

The Company processes personal data with the data subject's explicit consent or, where one or more other processing conditions exist, in accordance with those conditions. If special categories of personal data are processed, the conditions under "Processing of Special Categories of Personal Data" in this Policy and the Company's Policy on the Processing and Protection of Special Categories of Personal Data apply.

  • Existence of the Data Subject's Explicit Consent: This condition applies when the data subject has freely given informed, explicit consent relating to a specific matter. The Company retains that consent in a demonstrable form for the period required by personal data protection legislation. Where any of the conditions below exists, personal data may be processed without the data subject's explicit consent.

  • Expressly Provided for by Law: This condition applies where the relevant law expressly provides for processing that personal data. Relevant statutory and regulatory bases include:

    • Labour Law No. 4857.
    • Law No. 5746 on Supporting Research and Development Activities.
    • Occupational Health and Safety Law No. 6331.
    • Logging Law No. 5651.
    • Social Insurance and General Health Insurance Law.
    • Tax Procedure Law No. 213.
    • Turkish Commercial Code No. 6102.
    • Individual Pension Savings and Investment System Law.
    • Law No. 6365 on the Regulation of Electronic Commerce.
    • Inheritance and Transfer Tax Law No. 7338.

    The processing condition referred to in this clause may arise under these laws and other applicable legislation.

  • Inability to Obtain Explicit Consent Due to Actual Impossibility: This condition applies where processing is necessary to protect the life or physical integrity of the person concerned or another person, and the person concerned cannot express consent due to actual impossibility or their consent is not legally valid.

  • Directly Related to the Establishment or Performance of a Contract: This condition applies where processing is necessary and directly related to establishing or performing a contract to which the data subject is a party.

  • Necessary for the Data Controller to Fulfil a Legal Obligation: This condition applies where processing personal data is necessary for the Company to fulfil its legal obligations.

  • Personal Data Made Public by the Data Subject: Personal data made public by the data subject is processed only to the extent of the purpose for which it was made public.

  • Necessary for the Establishment, Exercise or Protection of a Right: Personal data is processed on this basis where processing is necessary to establish, exercise or protect a right.

  • Necessary for the Data Controller's Legitimate Interests: Processing takes place on this basis where it is necessary for the Company's legitimate interests, provided that the data subject's fundamental rights and freedoms are not harmed.

4.5. CONDITIONS FOR PROCESSING SPECIAL CATEGORIES OF PERSONAL DATA

The Company processes special categories of personal data in compliance with the additional measures announced by the Personal Data Protection Board, taking all necessary administrative and technical measures, and where one of the following conditions exists:

  • The data subject has given explicit consent.
  • Processing special categories of personal data other than health and sexual life data is provided for by law.
  • Health and sexual life data is processed by persons subject to a duty of confidentiality for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, or planning and managing healthcare services and their financing.

The Company has separately prepared and published a detailed "POLICY ON THE PROCESSING AND PROTECTION OF SPECIAL CATEGORIES OF PERSONAL DATA" governing this process.

4.6. PERSONAL DATA COLLECTION CHANNELS

The Company obtains personal data from physical and electronic environments in accordance with legal requirements and the purposes in this Policy, based on the relevant processing conditions. These environments and collection channels are as follows:

Physical Data CollectionElectronic Data Collection
Physical PostEmail
Business Cards / Printed Materials / FormsTelephone Records
Software and Applications Used (WEB APPLICATIONS, Meditek, Workflow System, IT Request Application, Guest System, Share Point, Google Drive, Salesforce, Perkotek Software, VSRM System, KBY System, Podium System, Recruitment Platform, Pusula System, PDKS System, Vehicle Tracking System, SAP, Portakale, LMS Training Platform, Service Portal, ERP, Powerapps, QDMS)
Call Centre Records
Camera Recordings
KEP, UYAP, UETS, OSEM

These channels may change as business processes develop or change and as technology advances. In accordance with the principle of transparency, such changes will be communicated through updates to this Policy.

4.7. TRANSFER OF PERSONAL DATA

The Company transfers personal data and special categories of personal data to third parties as prescribed by Articles 8 and 9 of the Law, on the basis of lawful processing purposes and with all necessary administrative and technical measures in place.

4.7.1. DOMESTIC TRANSFERS

The Company acts lawfully in its data transfer activities and transfers data to third parties only to the extent required by the service. Through data transfer agreements, it gives appropriate data security instructions to "Recipient" groups acting as "Data Processors".

4.7.2. TRANSFERS ABROAD

The Company may transfer personal data abroad only as prescribed by Article 9 of the Personal Data Protection Law and with the necessary administrative and technical measures in place. Such transfers are possible where one of the following conditions is met:

  • To foreign countries declared by the Authority to provide adequate protection; or
  • Where adequate protection does not exist, without seeking the data subject's explicit consent, provided that the data controllers in Türkiye and the relevant foreign country undertake in writing to provide adequate protection and the Board grants permission.
  • If neither of these two conditions is met, personal data may be transferred abroad only with the data subject's explicit consent.

Examples of recipient groups and the purposes of sharing are as follows:

Recipient GroupsExample of Transfer Purpose
Authorised Public Institutions and OrganisationsTransfers to bodies such as the Social Security Institution (SGK) to fulfil our legal obligations.
AgencyEstablishing and performing contracts, and carrying out organisational processes.
BankEstablishing and performing contracts, and establishing and exercising a right.
Supplier Companies (Providing Products/Services)Procuring products/services, ensuring business continuity (continuity of services and infrastructure use), and establishing and performing contracts.
Natural Persons or Private Law Legal EntitiesFollowing up and conducting legal affairs, and ensuring activities comply with legislation.
Group CompaniesPlanning human resources processes.
Holding CompanyReceiving and assessing suggestions for improving business processes.
Business PartnersConducting advertising/campaign/promotional processes.
Dealer RepresentativeConducting goods/service sales processes.

Recipient groups and the categories of personal data transferred abroad may change. These changes and updates are publicly notified and published in VERBİS on the Authority's website (verbis.kvkk.gov.tr).

4.8. RETENTION AND DISPOSAL OF PERSONAL DATA

As Data Controller, the Company has defined retention periods, disposal intervals, and the technical and administrative measures to be applied to storage in its "Personal Data Retention and Disposal Policy", and has separately declared these periods for each data category in VERBİS. The Company recognises its obligation to ensure that personal data is retained in accordance with these rules.

Under the Personal Data Protection Law, personal data is retained for the period prescribed by relevant legislation or necessary for the purpose of processing. These periods have been established. Once they expire, the personal data is deleted, destroyed or anonymised for analytical use at the end of the periodic disposal intervals determined under the relevant Personal Data Retention and Disposal Policy, in accordance with the "Regulation on the Deletion, Destruction or Anonymisation of Personal Data". You may request further information using the contact details in this Data Protection Policy.

5. PERSONAL DATA SECURITY MEASURES

The Company takes technical and administrative measures to ensure lawful processing of personal data, within the available technological means and considering implementation costs. Measures protecting special categories of personal data are applied carefully, with additional safeguards, in accordance with the Company's Policy on the Processing and Protection of Special Categories of Personal Data. Necessary audits are periodically conducted within the Company at the highest level, and these security measures are also specified in VERBİS.

The Company takes all appropriate security measures to ensure that personal data is processed only for the specified purposes and to reduce risks such as malicious use, unauthorised access, transfer, destruction or alteration.

The personal data processed by the Company is confidential, and the Company respects this confidentiality. Only persons authorised by the Company may access personal data. Accordingly, the Company ensures that software complies with standards, third parties are selected carefully and the Data Protection Policy is observed internally.

If, despite the necessary data security measures, personal data is damaged or obtained by unauthorised third parties as a result of attacks on platforms operated by the Company or its systems, the Company acts immediately to remedy the breach and minimise harm to the data subject. It immediately notifies the affected data subjects and the Board and takes the necessary measures. Rules and procedures relating to personal data breaches are set out in the "Personal Data Breach Management Policy".

6. OBLIGATION TO INFORM

In accordance with Article 10 of the Personal Data Protection Law and the "Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform", the Company informs data subjects through the relevant privacy notices of the identity of the data controller and any representative, the methods used to collect personal data, the legal grounds and purposes of processing, the recipients and purposes of transfers, and data subjects' rights regarding the processing of their personal data.

7. RIGHTS OF DATA SUBJECTS

Under the Constitution of the Republic of Türkiye, everyone has the right to request the protection of personal data relating to them. Article 11 of the Personal Data Protection Law lists data subjects' rights as follows:

  • To learn whether their personal data is being processed.
  • To request information if their personal data has been processed.
  • To learn the purpose of processing their personal data and whether it is used in accordance with that purpose.
  • To learn the third parties to whom their personal data is transferred domestically or abroad.
  • To request correction of incomplete or inaccurate personal data.
  • To request deletion or destruction of their personal data under the conditions in Article 7 of the Personal Data Protection Law.
  • To request notification of such deletion, destruction or correction to third parties to whom their personal data has been transferred.
  • To object to a result arising against the data subject through the analysis of processed data exclusively by automated systems.
  • To request compensation for damage suffered as a result of processing their personal data in breach of the Personal Data Protection Law.

Data subjects may submit requests concerning these rights in writing to the Company's registered electronic mail (KEP) address (kaleseramikas@hs01.kep.tr), in person, by registered post with acknowledgement of receipt, or by sending an email from their contact address registered in the Company's system to ks-kvkk@kale.com.tr. They may use the "Data Subject Application Form" on the Company's website (kale.com.tr). The application must include:

  • Name, surname and, for written applications, signature.
  • Turkish Republic identity number for Turkish citizens; nationality, passport number or identity number, if any, for foreign nationals.
  • Residential or business address for service of notices.
  • Email address, telephone and fax number for notification, if available.
  • The subject of the request.

Relevant information and documents must also be attached. Applications will be assessed only if submitted in Turkish. For third parties to apply on behalf of data subjects, a special power of attorney issued through a notary by the data subject in favour of the applicant must be provided.

If data subjects submit their requests concerning the rights above as described in this Policy and, in all cases, in accordance with the application procedures in the "Communiqué on the Procedures and Principles of Applications to the Data Controller", the Company will conclude the request free of charge as soon as possible, depending on its nature, and no later than 30 (thirty) days from the application date. However, if the procedure entails an additional cost, the Company may charge the fee specified in the tariff set by the Board.

For written applications, the application date is the date on which the document is served on the data controller or its representative. For applications made by other methods, it is the date on which the application reaches the data controller.

The Company sets out its personal data protection practices in policies and publishes those policies in publicly accessible media where relevant. All Company policies and regulations prepared on this subject form an integrated whole and complement one another. By informing data subjects about its processing activities in this way, the Company aims to ensure transparency and accountability.

Other related documents referred to in this Policy are:

  • Policy on the Protection of Special Categories of Personal Data.
  • Personal Data Retention and Disposal Policy.
  • Personal Data Breach Management Policy.
  • Data Subject Application Form.

9. ENTRY INTO FORCE AND AMENDMENTS

This Policy is published on the Company's website and enters into force on its publication date. The Company may amend this Policy at any time. Amendments take effect on the day the revised Policy is published.

10. OUR DETAILS AND CONTACT INFORMATION

If you have any questions about this Data Protection Policy or our approach to processing and protecting your personal data, or wish to exercise any rights specified in the Personal Data Protection Law, you may obtain information using any of the following contact methods:

KALESERAMİK ÇANAKKALE KALEBODUR SERAMİK SAN. A.Ş.

  • Address: Büyükdere Cad., Kaleseramik Binası, Levent, TR-34330 İstanbul
  • Telephone: 0 (212) 371 52 53
  • Email: ks-kvkk@kale.com.tr
  • Registered Electronic Mail (KEP) Address: kaleseramikas@hs01.kep.tr

This message/document is classified as CONFIDENTIAL.

Compare

Compare
Compare