Success
Your request has been successfully received. We will contact you as soon as possible.
Protecting personal data and ensuring its privacy are part of the corporate culture of KALESERAMİK ÇANAKKALE KALEBODUR SERAMİK SAN. A.Ş. (hereinafter "Kale Seramik" or the "Company"). The Company exercises the utmost care and effort to process and protect individuals' personal data in the course of its activities in accordance with applicable legal rules and universal principles of law. Acting as data controller, the Company processes and protects personal data under this Personal Data Processing and Protection Policy ("Policy" or "Data Protection Policy").
This Data Protection Policy relates to the personal data of data subjects other than our employees that our Company processes as Data Controller, wholly or partly by automated means or, provided it forms part of a data filing system, by non-automated means. It explains how the principles and rules established by relevant legislation are applied in the Company's personal data protection processes. This Policy describes the Company's general policy and processes for processing and protecting personal data. The obligation to inform under Article 10 of the Personal Data Protection Law is fulfilled through the relevant privacy notices provided to data subjects for each specific process.
Applicable legislation, secondary regulations and universal principles of law take precedence in the protection and lawful processing of personal data. In the event of a conflict between our Data Protection Policy and applicable regulations, the applicable regulations prevail.
We may review, amend or renew our Policy and the way we process personal information from time to time. We will publish the updated Policy on our website at www.kalegrubu.com.tr. The revised terms take effect from their publication date.
| Term | Definition |
|---|---|
| "Explicit Consent" | Consent relating to a specific matter, based on information and freely expressed. |
| "Obligation to Inform" | The Company's obligation to provide information to Data Subjects, through the Data Controller or its authorised persons, when personal data is obtained, in accordance with Article 10 of the Personal Data Protection Law and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform. |
| "Data Subject", "Data Owner" | Natural persons whose personal data is processed by the Company or persons/institutions authorised on its behalf. |
| "Disposal" | The destruction or anonymisation of personal data. |
| "Personal Data" | Any information relating to an identified or identifiable natural person. |
| "Anonymisation of Personal Data" | The process of rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching it with other data. |
| "Processing of Personal Data" | Any operation performed on personal data, wholly or partly by automated means or, provided it forms part of a data filing system, by non-automated means, including obtaining, recording, storing, retaining, altering, rearranging, disclosing, transferring, taking over, making available, classifying or preventing its use. |
| "Deletion of Personal Data" | The process of rendering personal data inaccessible and unusable for the relevant users in any way. |
| "Destruction of Personal Data" | The process of rendering personal data inaccessible, irretrievable and unusable by anyone in any way. |
| "Board" | Personal Data Protection Board |
| "Authority" | Personal Data Protection Authority |
| "Law", "Personal Data Protection Law" | Personal Data Protection Law No. 6698 |
| "Data Protection Policy" | The Personal Data Protection and Processing Policy adopted by the Company. |
| "Special Categories of Personal Data" | Data relating to a person's race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. |
| "Profiling" | Using automated means to process personal data to determine certain aspects about people, such as analysing or predicting their performance in activities, reliability, economic situation, personal preferences, interests, behaviour, location or movements. |
| "Company" | KALESERAMİK ÇANAKKALE KALEBODUR SERAMİK SAN. A.Ş. |
| "VERBİS", "Registry" | The Data Controllers Registry Information System maintained by the Presidency of the Personal Data Protection Authority. |
| "Data Processor" | A natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the controller. |
| "Data Controller" | A natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system. |
| "Electronic Environment" | Environments in which personal data can be created, read, altered and written using electronic devices. |
| "Non-electronic Environment" | All written, printed, visual and other media outside electronic environments. |
The Company complies with the mandatory "General Principles" for processing personal data listed in Article 4 of the Personal Data Protection Law:
The Company manages its personal data processing activities in accordance with legal rules, universal principles of law and good faith. It informs data subjects as necessary to ensure transparency and considers their interests and reasonable expectations. In this way, it prevents processing activities from producing results that data subjects neither expect nor should be expected to anticipate.
As a rule, personal data is processed on the basis of, and as provided in, data subjects' statements, and is presumed accurate as stated. The Company exercises reasonable care and attention to ensure that personal data held within its organisation is accurate, up to date and free from incorrect information. Where a data subject notifies the Company of changes to processed personal data, the Company ensures that the necessary administrative and technical mechanisms are in place to update the data in the relevant database.
Before starting a personal data processing activity, the Company defines its legitimate and lawful purposes specifically and clearly. It processes personal data in connection with its products and services and only to the extent necessary for them.
Personal data is processed in a manner that is relevant, limited and proportionate to the purposes determined by the Company and explained to the data subject. The Company takes care to maintain a reasonable balance between the processing activity and its intended purpose, ensuring that processing is limited to what is needed to achieve that purpose.
The Company retains personal data for the period prescribed by legislation or required for its processing purpose. When that statutory period expires or all processing purposes cease to exist, it deletes, destroys or anonymises the data. As Data Controller, the Company has defined retention periods, disposal intervals, and the technical and administrative measures to be applied to storage in its Personal Data Retention and Disposal Policy, and recognises its obligation to retain personal data in accordance with these rules.
These principles apply regardless of whether the Company processes personal data based on explicit consent or other processing conditions. The Company processes personal data in accordance with the processing conditions and general principles, and fulfils its obligation to inform data subjects.
The Company sets out below, subject to amendment and updating, the categories of personal data it processes, the groups of data subjects concerned, processing purposes, the legal conditions on which processing is based, collection channels, recipient groups, retention periods and disposal processes for data whose retention period has expired, and the security measures taken to protect personal data throughout these processes. Summaries of this information are publicly published and updated in the VERBİS registry information system on the Authority's website (verbis.kvkk.gov.tr).
The Company categorises the personal data it processes to ensure compliance with legal requirements and proper management of personal data processing and protection processes.
All personal data categories are organised under two main categories: "Personal Data" and "Special Categories of Personal Data". The categories processed within our Company and their definitions are as follows:
| Personal Data Category | Definition |
|---|---|
| Identity Data | Such as name and surname, parents' names, mother's maiden name, date and place of birth, marital status, identity card serial number, Turkish Republic identity number and signature |
| Contact Data | Such as address number, email address, contact address, registered electronic mail (KEP) address and telephone number |
| Location | Information about the person's location |
| Personnel Data | Such as payroll information, disciplinary investigations, employment start and termination records, asset declarations, CV information and performance assessment reports |
| Legal Proceedings Data | Such as information in correspondence with judicial authorities and in case files |
| Customer Transaction Data | Such as call centre records, invoices, promissory notes, cheque details, information on counter receipts, orders and requests |
| Transaction Security Data | Such as IP address information, website login/logout details and password/passcode information |
| Financial Data | Such as bank, IBAN and balance sheet information, financial performance, credit and risk information, and assets |
| Professional Experience Data | Such as diplomas, courses attended, professional training, certificates and transcripts |
| Visual and Audio Recording Data | Such as photographs, videos, and visual and audio recordings |
| Marketing | Shopping history, surveys, cookie records and information obtained through campaigns |
| Physical Premises Security | Such as visitor entry/exit records and camera recordings |
| Special Category of Personal Data | Definition |
|---|---|
| Criminal Convictions and Security Measures | Such as information relating to criminal convictions and security measures |
| Health Information | Such as disability information, blood group, personal health information, and information about devices and prostheses used |
| Biometric Data | Such as palm, fingerprint, retinal scan and facial recognition information |
The groups of data subjects whose personal data is processed within our Company and their definitions are publicly notified and published in VERBİS on the Authority's website (verbis.kvkk.gov.tr).
The Company processes personal data appropriately in accordance with the "General Principles for Processing Personal Data" in Article 4 of the Law, described above, and on the basis of and limited to at least one of the processing conditions in Articles 5 and 6. Under Article 10 and secondary legislation, the Company separately informs each group of data subjects of the data processing categories and purposes through the relevant privacy notices. The Company's processing purposes are declared in the Data Controllers Registry Information System (VERBİS) and remain publicly accessible there (link: verbis.kvkk.gov.tr).
The Company processes personal data with the data subject's explicit consent or, where one or more other processing conditions exist, in accordance with those conditions. If special categories of personal data are processed, the conditions under "Processing of Special Categories of Personal Data" in this Policy and the Company's Policy on the Processing and Protection of Special Categories of Personal Data apply.
Existence of the Data Subject's Explicit Consent: This condition applies when the data subject has freely given informed, explicit consent relating to a specific matter. The Company retains that consent in a demonstrable form for the period required by personal data protection legislation. Where any of the conditions below exists, personal data may be processed without the data subject's explicit consent.
Expressly Provided for by Law: This condition applies where the relevant law expressly provides for processing that personal data. Relevant statutory and regulatory bases include:
The processing condition referred to in this clause may arise under these laws and other applicable legislation.
Inability to Obtain Explicit Consent Due to Actual Impossibility: This condition applies where processing is necessary to protect the life or physical integrity of the person concerned or another person, and the person concerned cannot express consent due to actual impossibility or their consent is not legally valid.
Directly Related to the Establishment or Performance of a Contract: This condition applies where processing is necessary and directly related to establishing or performing a contract to which the data subject is a party.
Necessary for the Data Controller to Fulfil a Legal Obligation: This condition applies where processing personal data is necessary for the Company to fulfil its legal obligations.
Personal Data Made Public by the Data Subject: Personal data made public by the data subject is processed only to the extent of the purpose for which it was made public.
Necessary for the Establishment, Exercise or Protection of a Right: Personal data is processed on this basis where processing is necessary to establish, exercise or protect a right.
Necessary for the Data Controller's Legitimate Interests: Processing takes place on this basis where it is necessary for the Company's legitimate interests, provided that the data subject's fundamental rights and freedoms are not harmed.
The Company processes special categories of personal data in compliance with the additional measures announced by the Personal Data Protection Board, taking all necessary administrative and technical measures, and where one of the following conditions exists:
The Company has separately prepared and published a detailed "POLICY ON THE PROCESSING AND PROTECTION OF SPECIAL CATEGORIES OF PERSONAL DATA" governing this process.
The Company obtains personal data from physical and electronic environments in accordance with legal requirements and the purposes in this Policy, based on the relevant processing conditions. These environments and collection channels are as follows:
| Physical Data Collection | Electronic Data Collection |
|---|---|
| Physical Post | |
| Business Cards / Printed Materials / Forms | Telephone Records |
| Software and Applications Used (WEB APPLICATIONS, Meditek, Workflow System, IT Request Application, Guest System, Share Point, Google Drive, Salesforce, Perkotek Software, VSRM System, KBY System, Podium System, Recruitment Platform, Pusula System, PDKS System, Vehicle Tracking System, SAP, Portakale, LMS Training Platform, Service Portal, ERP, Powerapps, QDMS) | |
| Call Centre Records | |
| Camera Recordings | |
| KEP, UYAP, UETS, OSEM |
These channels may change as business processes develop or change and as technology advances. In accordance with the principle of transparency, such changes will be communicated through updates to this Policy.
The Company transfers personal data and special categories of personal data to third parties as prescribed by Articles 8 and 9 of the Law, on the basis of lawful processing purposes and with all necessary administrative and technical measures in place.
The Company acts lawfully in its data transfer activities and transfers data to third parties only to the extent required by the service. Through data transfer agreements, it gives appropriate data security instructions to "Recipient" groups acting as "Data Processors".
The Company may transfer personal data abroad only as prescribed by Article 9 of the Personal Data Protection Law and with the necessary administrative and technical measures in place. Such transfers are possible where one of the following conditions is met:
Examples of recipient groups and the purposes of sharing are as follows:
| Recipient Groups | Example of Transfer Purpose |
|---|---|
| Authorised Public Institutions and Organisations | Transfers to bodies such as the Social Security Institution (SGK) to fulfil our legal obligations. |
| Agency | Establishing and performing contracts, and carrying out organisational processes. |
| Bank | Establishing and performing contracts, and establishing and exercising a right. |
| Supplier Companies (Providing Products/Services) | Procuring products/services, ensuring business continuity (continuity of services and infrastructure use), and establishing and performing contracts. |
| Natural Persons or Private Law Legal Entities | Following up and conducting legal affairs, and ensuring activities comply with legislation. |
| Group Companies | Planning human resources processes. |
| Holding Company | Receiving and assessing suggestions for improving business processes. |
| Business Partners | Conducting advertising/campaign/promotional processes. |
| Dealer Representative | Conducting goods/service sales processes. |
Recipient groups and the categories of personal data transferred abroad may change. These changes and updates are publicly notified and published in VERBİS on the Authority's website (verbis.kvkk.gov.tr).
As Data Controller, the Company has defined retention periods, disposal intervals, and the technical and administrative measures to be applied to storage in its "Personal Data Retention and Disposal Policy", and has separately declared these periods for each data category in VERBİS. The Company recognises its obligation to ensure that personal data is retained in accordance with these rules.
Under the Personal Data Protection Law, personal data is retained for the period prescribed by relevant legislation or necessary for the purpose of processing. These periods have been established. Once they expire, the personal data is deleted, destroyed or anonymised for analytical use at the end of the periodic disposal intervals determined under the relevant Personal Data Retention and Disposal Policy, in accordance with the "Regulation on the Deletion, Destruction or Anonymisation of Personal Data". You may request further information using the contact details in this Data Protection Policy.
The Company takes technical and administrative measures to ensure lawful processing of personal data, within the available technological means and considering implementation costs. Measures protecting special categories of personal data are applied carefully, with additional safeguards, in accordance with the Company's Policy on the Processing and Protection of Special Categories of Personal Data. Necessary audits are periodically conducted within the Company at the highest level, and these security measures are also specified in VERBİS.
The Company takes all appropriate security measures to ensure that personal data is processed only for the specified purposes and to reduce risks such as malicious use, unauthorised access, transfer, destruction or alteration.
The personal data processed by the Company is confidential, and the Company respects this confidentiality. Only persons authorised by the Company may access personal data. Accordingly, the Company ensures that software complies with standards, third parties are selected carefully and the Data Protection Policy is observed internally.
If, despite the necessary data security measures, personal data is damaged or obtained by unauthorised third parties as a result of attacks on platforms operated by the Company or its systems, the Company acts immediately to remedy the breach and minimise harm to the data subject. It immediately notifies the affected data subjects and the Board and takes the necessary measures. Rules and procedures relating to personal data breaches are set out in the "Personal Data Breach Management Policy".
In accordance with Article 10 of the Personal Data Protection Law and the "Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform", the Company informs data subjects through the relevant privacy notices of the identity of the data controller and any representative, the methods used to collect personal data, the legal grounds and purposes of processing, the recipients and purposes of transfers, and data subjects' rights regarding the processing of their personal data.
Under the Constitution of the Republic of Türkiye, everyone has the right to request the protection of personal data relating to them. Article 11 of the Personal Data Protection Law lists data subjects' rights as follows:
Data subjects may submit requests concerning these rights in writing to the Company's registered electronic mail (KEP) address (kaleseramikas@hs01.kep.tr), in person, by registered post with acknowledgement of receipt, or by sending an email from their contact address registered in the Company's system to ks-kvkk@kale.com.tr. They may use the "Data Subject Application Form" on the Company's website (kale.com.tr). The application must include:
Relevant information and documents must also be attached. Applications will be assessed only if submitted in Turkish. For third parties to apply on behalf of data subjects, a special power of attorney issued through a notary by the data subject in favour of the applicant must be provided.
If data subjects submit their requests concerning the rights above as described in this Policy and, in all cases, in accordance with the application procedures in the "Communiqué on the Procedures and Principles of Applications to the Data Controller", the Company will conclude the request free of charge as soon as possible, depending on its nature, and no later than 30 (thirty) days from the application date. However, if the procedure entails an additional cost, the Company may charge the fee specified in the tariff set by the Board.
For written applications, the application date is the date on which the document is served on the data controller or its representative. For applications made by other methods, it is the date on which the application reaches the data controller.
The Company sets out its personal data protection practices in policies and publishes those policies in publicly accessible media where relevant. All Company policies and regulations prepared on this subject form an integrated whole and complement one another. By informing data subjects about its processing activities in this way, the Company aims to ensure transparency and accountability.
Other related documents referred to in this Policy are:
This Policy is published on the Company's website and enters into force on its publication date. The Company may amend this Policy at any time. Amendments take effect on the day the revised Policy is published.
If you have any questions about this Data Protection Policy or our approach to processing and protecting your personal data, or wish to exercise any rights specified in the Personal Data Protection Law, you may obtain information using any of the following contact methods:
KALESERAMİK ÇANAKKALE KALEBODUR SERAMİK SAN. A.Ş.
This message/document is classified as CONFIDENTIAL.