Personal Data Retention and Destruction Policy
BÜLENT BÖREKÇİLİK İMALAT PAZARLAMA SANAYİ VE DIŞ TİCARET ANONİM ŞİRKETİ PERSONAL DATA RETENTION AND DESTRUCTION POLICY PURSUANT TO PERSONAL DATA PROTECTION LAW NO. 6698
1. INTRODUCTION
1.1 Purpose
The Personal Data Retention and Destruction Policy (referred to in some places as the “Policy”) has been prepared by Joint Data Controller Group Companies BÜLENT UNLU MAMÜLLER PAZARLAMA SATIŞ ANONİM ŞİRKETİ and BÜLENT BÖREKÇİLİK İMALAT PAZARLAMA SANAYİ VE DIŞ TİCARET ANONİM ŞİRKETİ (hereinafter referred to as “Bülent Börekçilik” or the “Company”) in order to determine the procedures and principles regarding the work and transactions relating to the retention and destruction activities carried out.
In line with the mission, vision and core principles determined together with its Corporate vision, our Company has set as a priority the processing of personal data belonging to Company employees, job applicants, service providers, customers, visitors and other third parties in accordance with the Constitution of the Republic of Türkiye, International Conventions, Personal Data Protection Law No. 6698 (referred to in some places as the “Law”) and other relevant legislation, and ensuring that data subjects exercise their rights effectively.
Work and transactions relating to the retention and destruction of personal data are carried out in accordance with the “Personal Data Retention and Destruction Policy” prepared by our Company in this direction.
1.2 Scope
Personal data belonging to Company employees, job applicants, service providers, customers, visitors and other third parties fall within the scope of this Policy, and this Policy is applied to all recording media in which personal data owned or managed by the Company is processed and to activities relating to the processing of personal data.
1.3 Abbreviations and Definitions
Recipient Group: The category of natural or legal persons to whom personal data is transferred by the data controller.
Explicit Consent: Consent relating to a specific matter, based on information and expressed with free will.
Anonymisation: Rendering personal data incapable of being associated with an identified or identifiable natural person in any way, even when matched with other data.
Employee: Company personnel.
Electronic Medium: Media in which personal data can be created, read, changed and written with electronic devices.
Non-Electronic Medium: All other written, printed, visual, etc. media outside electronic media.
Supplier Company: Supplier Companies working with the Company
Service Provider: A natural or legal person providing services to the Company within the framework of a specific contract.
Data Subject: The natural person whose personal data is processed.
Relevant User: Persons who process personal data within the data controller's organisation or in line with the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.
Destruction: The erasure, destruction or anonymisation of personal data.
Law: Personal Data Protection Law No. 6698.
Recording Medium: Any medium containing personal data processed wholly or partly by automated means or by non-automated means provided that it forms part of a data recording system.
Personal Data: Any information relating to an identified or identifiable natural person.
Personal Data Processing Inventory: The inventory in which data controllers detail the personal data processing activities they carry out depending on their business processes, by associating them with the purposes of processing personal data, the data category, the recipient group to whom data is transferred and the data subject group, and by explaining the maximum period necessary for the purposes for which personal data is processed, the personal data envisaged to be transferred to foreign countries and the measures taken regarding data security.
Processing of Personal Data: Any operation performed on data, such as obtaining, recording, storing, retaining, changing, reorganising, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, wholly or partly by automated means or by non-automated means provided that it forms part of a data recording system.
Board: Personal Data Protection Board
Special Categories of Personal Data: Data relating to persons' race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, association, foundation or trade union membership, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data.
Periodic Destruction: The erasure, destruction or anonymisation process to be carried out ex officio at recurring intervals specified in the personal data retention and destruction policy, in the event that all of the conditions for processing personal data set out in the Law cease to exist.
Policy: Bülent Börekçilik Personal Data Retention and Destruction Policy
Company: Group Companies Bülent Unlu Mamüller Pazarlama Satış Anonim Şirketi and Bülent Börekçilik İmalat Pazarlama Sanayi ve Dış Ticaret Anonim Şirketi
Data Processor: A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller.
Data Recording System: A recording system in which personal data is structured and processed according to certain criteria.
Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.
Data Controllers Registry Information System: The information system, accessible via the internet, created and managed by the Presidency, which data controllers will use in applying to the Registry and in other relevant transactions relating to the Registry.
VERBİS: Data Controllers Registry Information System
Regulation: The Regulation on the Erasure, Destruction or Anonymisation of Personal Data published in the Official Gazette dated 28 October 2017.
2. RESPONSIBILITIES AND DISTRIBUTION OF DUTIES
All units and employees of the Company actively support the responsible units in the proper implementation of the technical and administrative measures taken by the responsible units within the scope of the Policy, the training and raising awareness of unit employees, their monitoring and continuous supervision, and in taking technical and administrative measures to ensure data security in all media where personal data is processed, in order to prevent the unlawful processing of personal data, to prevent unlawful access to personal data and to ensure the lawful retention of personal data.
The distribution of the titles, units and job descriptions of those involved in the personal data retention and destruction processes in our Company is given in Table 1. The said table does not include the Company or Companies that establish a business relationship with the Company as a Supplier Company. The reason for this is that Supplier Companies establishing a contractual commercial relationship with our Company are, as “Data Controllers” under Law No. 6698, obliged to take legal and administrative measures on their own.
| TITLE | DUTY |
|---|---|
| Chairman of the Company Board of Directors | Responsible for the Company taking legal, administrative and technical measures within the scope of the KVKK. |
| General Manager and Employer Representatives | Responsible for the preparation, development, execution, publication in the relevant media and updating of the Policy. |
| Legal Unit | Responsible for preparing Company contracts in compliance with the KVKK. |
| Purchasing and Business Development Unit | Responsible for the preparation, development, execution, publication in the relevant media and updating of the Policy. |
| Human Resources Unit | Responsible for the execution of the Policy in accordance with its duties. |
| Company Managers | Responsible for the preparation, development, execution, publication in the relevant media and updating of the Policy. |
| Accounting Unit | Responsible for the execution of the Policy in accordance with its duties. |
| Information Technology Unit | Responsible for providing the technical solutions needed in the implementation of the Policy. |
| Call Centre Unit | Responsible for the execution of the Policy in accordance with its duties. |
| Corporate Communications Unit | Responsible for the execution of the Policy in accordance with its duties. |
| Warehouse Unit | Responsible for the execution of the Policy in accordance with its duties. |
| Support Services and Logistics – Operations Unit | Responsible for the execution of the Policy in accordance with its duties. |
| Contracted Service Providers | Obliged to act in accordance with the Company Policy. |
3. RECORDING MEDIA
Personal Data is retained lawfully and securely by our Company in the media listed in Table 2.
TABLE 2
| Electronic Media | Non-Electronic Media |
|---|---|
| 1- Servers (Domain, backup, e-mail, database, web, file sharing, etc.) | 1- Paper |
| 2- Software (office software) | 2- Manual data recording systems |
| 3- Information security devices (firewall, intrusion detection and prevention, log file, antivirus, etc.) | 3- Written and visual media |
| 4- Personal computers (Desktop, laptop) |
4. EXPLANATIONS REGARDING RETENTION AND DESTRUCTION
Personal data belonging to employees, job applicants, customers, visitors and third parties with whom the Company is in a relationship as service providers, and to employees of supplier companies, institutions or organisations, is retained and destroyed by the Company in accordance with the Law. In this context, detailed explanations regarding retention and destruction are given below respectively.
4.1 EXPLANATIONS REGARDING RETENTION
Article 3 of the Law defines the concept of processing personal data; Article 4 states that “processed personal data must be relevant, limited and proportionate to the purposes for which they are processed and must be retained for the period stipulated in the relevant legislation or necessary for the purpose for which they are processed”, and Articles 5 and 6 list the “conditions for processing personal data”.
Accordingly, within the framework of our Company's activities, personal data is retained for the period stipulated in the relevant legislation or appropriate to our processing purposes.
4.1.1 Legal Grounds Requiring Retention
In our Company, personal data processed within the framework of Company activities is retained for the period stipulated in the relevant legislation. In this context, personal data is retained for the retention periods stipulated under the following Laws and Other Regulations:
- Personal Data Protection Law No. 6698,
- Turkish Code of Obligations No. 6098,
- Public Procurement Law No. 4734,
- Social Insurance and General Health Insurance Law No. 5510,
- Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed by Means of Such Publications,
- Public Financial Management and Control Law No. 5018,
- Occupational Health and Safety Law No. 6361,
- Right to Information Law No. 4982,
- Law No. 3071 on the Exercise of the Right to Petition,
- Labour Law No. 4857,
- Social Services Law No. 2828
- Regulation on Health and Safety Measures to Be Taken in Workplace Buildings and Annexes,
- Regulation on Archive Services
- Other secondary regulations in force pursuant to these laws
4.1.2 Processing Purposes Requiring Retention
Our Company retains the personal data it processes within the framework of its activities for the following purposes:
- To carry out human resources processes.
- To ensure corporate communication.
- To ensure corporate security.
- To carry out statistical studies.
- To perform work and transactions as a result of signed contracts and protocols.
- To ensure the fulfilment of legal obligations as required or mandated by legal regulations.
- To maintain contact with natural / legal persons having a business relationship with the Company.
- To make legal reports.
- To manage call centre processes.
- To create evidence in terms of the burden of proof in legal disputes that may arise in the future.
- To fulfil the obligations imposed by the Law and Other Legislation.
4.2 Reasons Requiring Destruction
Personal data is erased or destroyed by the Company upon the request of the data subject, or erased or anonymised ex officio, in the following cases:
- In the event that the provisions of the relevant legislation constituting the basis for its processing are amended or repealed,
- In the event that the purpose requiring its processing or retention ceases to exist,
- In cases where the processing of personal data takes place solely on the basis of the explicit consent condition, in the event that the data subject withdraws their explicit consent,
- As a result of our Company accepting the application made by the data subject regarding the erasure and destruction of their personal data within the framework of the data subject's rights pursuant to Article 11 of the Law,
- In cases where our Company rejects the application made to it by the data subject with a request for the erasure, destruction or anonymisation of their personal data, finds its response insufficient or fails to respond within the period stipulated in the Law; in the event that the complaint is found appropriate by the Board,
- In the event that the maximum period requiring the retention of personal data has expired and there is no condition that would justify retaining the personal data for a longer period,
- As a result of a provision of the Law or a decision by the Judicial Authorities or the Public Administration covering the erasure of data belonging to the data subject.
5. ADMINISTRATIVE AND TECHNICAL MEASURES
For the secure retention of personal data, the prevention of its unlawful processing and access, and the lawful destruction of personal data, administrative and technical measures are taken by our Company pursuant to Article 12 of the Law and, for special categories of personal data, paragraph 4 of Article 6 of the Law, within the framework of the adequate measures deemed necessary and announced by the Board.
5.1 Administrative Measures
The administrative measures taken by our Company regarding the personal data it processes are listed below:
- Training is provided to improve the qualifications of employees on the prevention of unlawful processing of personal data, the prevention of unlawful access to personal data, ensuring the retention of personal data, communication techniques, technical knowledge and skills, Law No. 6698 and other relevant legislation.
- Where deemed necessary, employees are required to sign relevant confidentiality agreements regarding the activities carried out by the Company.
- A disciplinary procedure and internal regulation to be applied to employees who do not comply with security policies and procedures have been prepared.
- Before starting to process personal data, the obligation to inform the data subjects is fulfilled by the Company.
- A personal data processing inventory has been prepared.
- Periodic and random internal audits are carried out within the Company.
- Information security training is provided to employees.
- Letters of undertaking are obtained, as required by the Law, for the retention of Personal Data.
- The measures that must be taken pursuant to Law No. 6698 have been notified to the Companies with which there is a Business Relationship.
- Letters of undertaking under Law No. 6698 have been prepared for Supplier Companies.
- Training has been provided within the Company on the Personal Data falling within the scope of Law No. 6698 and how it must be protected.
- An internal Company Authorisation Matrix has been created within the scope of the Law.
- A Company Data Destruction Policy has been created.
- The Company's VERBİS registration has been completed and the necessary notifications have been made.
- An Application Procedure regarding Personal Data of Company Customers has been created.
- The necessary information training has been provided to Company Unit Managers.
- Explicit Consent Forms under Law No. 6698 have been created for Company employees.
- Privacy Notices under Law No. 6698 have been created for Company customers.
- A Call Centre Policy Information Procedure has been created within the scope of the Law.
- Devices containing Personal Data have been assigned to persons with authorised access.
- A separate policy has been determined for the security of special categories of personal data, and accordingly the obligation to inform has been fulfilled and explicit consent forms have been created.
- The necessary warning and information texts are used in areas where physical environments are monitored, such as by Camera Recording.
- A Personal Data Protection Committee has been established for the protection of personal data, the taking of necessary measures and the evaluation of data subjects' applications within the scope of the Law.
- Data stored in Physical Environments (paper, files) is kept in locked areas, and arrangements have been made so that only authorised persons can access it.
- No information defined as Personal Data is left in the open in the Office or any other environment, except where its authorised person is required to work on it or where its use is mandatory.
5.2 Technical Measures
- Through leak (penetration) tests, risks, threats, vulnerabilities and any gaps in our Company's information systems are identified and the necessary measures are taken.
- Risks and threats that may affect the continuity of information systems are continuously monitored as a result of information security incident and event management and real-time analyses.
- Access to information systems and the authorisation of users are carried out through computer assignment, the access and authorisation matrix and corporate security policies.
- The necessary measures are taken for the physical security of the Company's information systems equipment, software and data.
- To ensure the security of information systems against environmental threats, hardware measures (access control system allowing only authorised personnel to enter the system room, 24/7 monitoring system, ensuring the physical security of the edge switches forming the local area network, fire extinguishing system, air conditioning system, etc.) and software measures (firewalls, attack prevention systems, systems blocking malicious software, etc.) are taken.
- Risks aimed at preventing the unlawful processing of personal data are identified, appropriate technical measures are taken against these risks, and technical checks are carried out on the measures taken.
- Access procedures are established within the Company, and reporting and analysis work is carried out regarding access to personal data.
- Access to storage areas containing personal data is logged, and inappropriate access or access attempts are kept under control.
- The Company takes the necessary measures to ensure that erased personal data is inaccessible and cannot be reused by relevant users.
- A suitable system and infrastructure have been established by the Company to notify the data subject and the Board in the event that personal data is unlawfully obtained by others.
- Security vulnerabilities are monitored, appropriate security patches are installed, and information systems are kept up to date.
- Strong passwords are used in electronic media where personal data is processed.
- Access to personal data stored in electronic or non-electronic media is restricted according to access principles.
- A secure protocol (HTTPS) is used for access to the Company's website.
- No processing will be carried out regarding special categories of data that have become mandatory to obtain by law or in the interest of the Company without fulfilling the necessary obligation to inform employees and obtaining the explicit consent of the data subjects.
- Training on the security of special categories of personal data has been provided to employees involved in personal data processing processes, confidentiality agreements have been concluded, and the authorisations of users with access rights to data have been defined.
- In the event of processing special categories of personal data, the said data will under no circumstances be transferred to 3rd Parties, except in cases where the Law does not require the person's consent, to authorised Institutions as required by the Law and Other Legislation and by conventions to which the Republic of Türkiye is a party, and in cases where the data subject has given explicit consent.
6. PERSONAL DATA DESTRUCTION TECHNIQUES
At the end of the period stipulated in the relevant legislation or the retention period necessary for the purpose for which they are processed, personal data is destroyed by the Company, ex officio or upon the application of the data subject, using the techniques specified below, again in accordance with the provisions of the relevant legislation.
6.1 Erasure of Personal Data
Where processed, Personal data is erased by the methods specified below:
a. Personal Data on Servers
- For personal data on servers whose required retention period has expired, the erasure is carried out by the system administrator by removing the access authorisation of the relevant users.
b. Personal Data in Electronic Media
- Personal data in electronic media whose required retention period has expired is rendered inaccessible and non-reusable in any way for employees (relevant users) other than the database administrator.
c. Personal Data in Physical Media
- Personal data kept in physical media whose required retention period has expired is rendered inaccessible and non-reusable in any way for employees other than the unit manager responsible for the document archive. In addition, a blackout process is applied to the said documents by crossing out/painting over/erasing them so that they cannot be read.
d. Personal Data on Portable Media
- Personal data kept on flash-based storage media whose required retention period has expired is encrypted by the system administrator, with access authorisation granted only to the system administrator, and stored in secure environments with encryption keys.
6.2 Destruction of Personal Data
Personal data is destroyed by our Company by the methods specified below.
a. Personal Data in Physical Media
- Personal data on paper whose required retention period has expired is irreversibly destroyed in paper shredding machines or by being cut manually with scissors.
b. Personal Data on Optical / Magnetic Media
- Personal data on optical media and magnetic media whose required retention period has expired is physically destroyed, such as by melting, burning, shredding, scratching or pulverising.
6.3 Anonymisation of Personal Data
Anonymisation of personal data means rendering personal data incapable of being associated with an identified or identifiable natural person in any way, even if matched with other data.
For personal data to be anonymised, personal data must be rendered incapable of being associated with an identified or identifiable natural person, even through the use of techniques appropriate to the recording medium and the relevant field of activity, such as reversal by the data controller or third parties and/or matching the data with other data.
7. RETENTION AND DESTRUCTION PERIODS
With regard to the personal data processed by our Company within the scope of our activities:
- a. Retention periods on a personal data basis for all personal data within the scope of the activities carried out depending on the processes are generally limited by the Law; however, where retention periods are determined at will, the determination has been made according to our Company Policies.
- b. Retention periods on the basis of data categories are included in the “Data Controllers Registry Information System”.
- c. Retention periods on a process basis are included in the “Personal Data Retention and Destruction Policy”.
Where necessary, the said retention periods are updated by the authorised bodies of our Company, and the ex officio erasure, destruction or anonymisation of personal data whose retention periods have expired is carried out by the Relevant Units of our Company.
The retention and destruction table for personal data processed by our Company is as follows:
| PROCESS | RETENTION PERIOD | DESTRUCTION PERIOD |
|---|---|---|
| Company Board of Directors Resolution Records | 10 Years | In the first periodic destruction period following the end of the retention period |
| Contracts forming the basis of decisions taken by the Company | 10 Years | In the first periodic destruction period following the end of the retention period |
| Carrying out Human Resources Processes (Only for Persons Who Have Started Work) | 15 years following the end of the activity | In the first periodic destruction period following the end of the retention period |
| Execution of Internal Company Communication Activities (Processed Data Only) | 1 Year | In the first periodic destruction period following the end of the retention period |
| Carrying out Hardware and Software Access Processes | 1 Year | In the first periodic destruction period following the end of the retention period |
| Visitor and Meeting Records, Where Processed | 10 Years | In the first periodic destruction period following the end of the retention period |
| Company Building Closed-Circuit Recording System Records | 14 Days | In the first periodic destruction period following the end of the retention period |
| Customer Records (For Persons and Companies for Whom the Obligation to Inform Has Been Fulfilled and an Explicit Consent Declaration Has Been Obtained) | 10 Years | In the first periodic destruction period following the end of the retention period |
| Job Application Documents (Persons Who Have Not Been Hired) | 2 Years | In the first periodic destruction period following the end of the retention period |
*For periods not included in this table, the provisions mandated by the Personal Data Protection Law together with other mandatory provisions in force shall apply.
8. PERIODIC DESTRUCTION PERIOD
Pursuant to Article 11 of the Regulation on the Erasure, Destruction or Anonymisation of Personal Data published in the Official Gazette dated 28 October 2017, our Company has set the periodic destruction period as 6 months. Accordingly, periodic destruction is carried out in our Company on the last day of “June” and “December” each year.
9. PUBLICATION AND RETENTION OF THE POLICY
Our Company's Personal Data Retention and Destruction Policy is published in two different media, wet-signed (printed paper) and electronic, and is disclosed to the public on the website. The printed paper copy is kept in our Company's Human Resources Unit.
10. UPDATE PERIOD OF THE POLICY
The Policy is reviewed in the event of changes to the Law and as needed, and the necessary sections are updated. For the said updates, the publication procedure is followed within the framework of the provisions of Article 9 of our Company's Personal Data Retention and Destruction Policy.
11. ENTRY INTO FORCE AND REPEAL OF THE POLICY
Our Company's Personal Data Retention and Destruction Policy is deemed to have entered into force after its publication on the Company's website. In the event that a decision is taken to repeal the Policy, the old wet-signed copies of the Policy are cancelled (by stamping or writing "cancelled") and signed by the Human Resources Unit upon a resolution of our Company's Board of Directors, and are kept by our Company's Human Resources Unit for at least 5 years.