PDPL Policy
MAQRE TEKSTİL SAN. VE TİC. LTD. ŞTİ. POLICY ON THE PROTECTION, PROCESSING AND DESTRUCTION OF PERSONAL DATA
CONTENTS
1. INTRODUCTION
2. PURPOSE
3. SCOPE
4. PROCESSING OF PERSONAL DATA OBTAINED/TO BE OBTAINED FROM EMPLOYEE CANDIDATES, EMPLOYEES AND WITHIN THE SCOPE OF COMMERCIAL ACTIVITIES (MANUFACTURER-SUPPLIER-SUBCONTRACTOR-CUSTOMER)
4.1- Documents to Be Requested from Employees and Employee Candidates
4.2- Purpose of Processing Employee Candidate Personal Data
4.3- Special Categories of Personal Data of Employees and Employee Candidates
4.4- Parties to Whom Employee Candidate Personal Data May Be Transferred
4.5- Purpose of Processing Employee Personal Data
4.6- Parties to Whom Employee Personal Data May Be Transferred
4.7- Purpose of Processing Customer, Supplier and Visitor Personal Data
4.8- Special Categories of Personal Data of Customers, Suppliers and Visitors
4.9- Parties to Whom Customer, Supplier and Visitor Personal Data May Be Transferred
4.10- Processing of Personal Data Relating to Internet Usage
4.11- Processing of Personal Data Relating to Security Camera Use
5- PERSONAL DATA RETENTION AND DESTRUCTION PERIODS
5.1- Personal Data Recording Media
5.2- Personal Data Retention Periods
5.3- Destruction of Personal Data
6- PERSONAL DATA SECURITY AND MEASURES
6.1- Technical and Administrative Measures for the Processing, Protection and Retention of Personal Data
7- DESTRUCTION OF PERSONAL DATA
8- RIGHTS OF PERSONAL DATA SUBJECTS
9- ENTRY INTO FORCE AND UPDATABILITY
10- DEFINITIONS
Within the scope of Personal Data Protection Law No. 6698, which entered into force on 7 APRIL 2016, the obligations of natural and legal persons who process personal data and the procedures and principles with which they must comply have been regulated in order to protect individuals’ fundamental rights and freedoms, particularly the privacy of private life, in the processing of personal data. In this context, in order to monitor and ensure the actions and procedures required to be carried out as the DATA CONTROLLER regarding the retention and processing of information obtained by our business and regarded as personal data under the Law, and its destruction once the need for its retention and processing ceases to exist, this POLICY ON THE PROTECTION, PROCESSING AND DESTRUCTION OF PERSONAL DATA has been prepared.
In this context, acting as the Data Controller as defined under the Personal Data Protection Law and within the scope of the diligence and responsibility we exercise regarding the security of the personal data of employee candidates, employees, visitors, employees of organisations with which we cooperate, and other natural persons, this Policy has been prepared for the following purposes: to ensure that the personal data of all natural persons associated with the Company are processed, recorded and retained in accordance with the law; transferred/disclosed to third parties within the limits permitted by the applicable legislation and only for the purposes for which they are processed; and destroyed in compliance with, without limitation, the Personal Data Protection Law and other applicable legislation, while also taking into consideration social rules and the principles of good faith; and to ensure that such data are processed in connection with, limited to, and proportionate to the purposes for which they may be processed within the scope of business requirements, for lawful purposes, and retained and destroyed for the periods stipulated under the applicable legislation and/or necessary for the purposes for which they are processed.
2-PURPOSE
This Policy has been prepared with the principal purpose of establishing the fundamental principles concerning Company practices determined for the processing and protection of the personal data of employee candidates, employees, visitors, employees of organisations with which we cooperate, and other natural persons, and ensuring that these principles are understood by the relevant persons.
3- SCOPE
This Policy applies to all personal data belonging to employee candidates, employees, visitors, employees of organisations with which we cooperate, and other natural persons that are processed automatically or by non-automatic means, provided that such processing forms part of a data recording system.
4- PROCESSING OF PERSONAL DATA OBTAINED/TO BE OBTAINED FROM EMPLOYEE CANDIDATES, EMPLOYEES AND WITHIN THE SCOPE OF COMMERCIAL ACTIVITIES (MANUFACTURER-SUPPLIER-SUBCONTRACTOR-CUSTOMER)
4.1- Documents to Be Requested from Employees and Employee Candidates;
|
Identity Data |
|
Contact Data |
|
Special Categories of Personal Data |
|
Education Data |
|
Your educational status, educational information (name of school, term information and graduation grade average), foreign language knowledge, education and skills, seminars and courses attended, certificate information and computer knowledge. |
|
Visual and Audio Data |
|
Photograph, identity document and driving licence data, and personnel file. |
4.2- Purpose of Processing Employee Candidate Personal Data
Employee candidate personal data are processed for the following purposes within the framework of the employee candidate-employer relationship arising from the job application submitted to our Company, as such processing is necessary for evaluating the job application and establishing the employment agreement:
Recruiting new personnel, reviewing candidates and identifying the new candidate to be employed,
Sharing the notes added to your résumé with the manager so that the manager may better understand and become acquainted with the candidate,
Verifying the data with the references specified in your résumé,
Verifying the extent to which you are suited to the position and recording the information in your résumé for future verification,
Recording the CV shared with you by email in case we may need it in the short or long term,
4.3- Special Categories of Personal Data of Employees and Employee Candidates;
Within the scope of the Personal Data Protection Law, data relating to race, ethnic origin, political opinion, philosophical belief, religion, religious denomination or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, if any, and biometric and genetic data are special categories of personal data.
4.4- Parties to Whom Employee Candidate Personal Data May Be Transferred;
Your personal data may be shared with the persons you have identified as references for verification purposes and with the human resources department responsible for monitoring the recruitment process.
4.5- Purpose of Processing Employee Personal Data
The personal data specified above are processed for the following purposes within the scope of your existing employment with our Company and within the framework of the employee-employer relationship:
• Planning and carrying out Human Resources processes,
• Creating personnel files and payroll processing,
• Managing personnel employment agreement processes,
• Providing healthcare services to personnel,
• Allocating telephones, telephone lines and vehicles to personnel within the scope of their employment agreements,
• Conducting processes for preparing powers of attorney and signature circulars,
• Making emergency preparations and conducting emergency operations,
• Conducting occupational health and safety processes,
• Managing accidents and applicable legislation within the scope of occupational health and safety,
• Structuring service procurement agreement processes,
• Planning, auditing and carrying out information security processes,
• Opening and authorising email accounts for employees,
• Maintaining internet log records,
• Planning and carrying out corporate communication activities,
• Planning personnel travel and conducting advance payment processes,
• Creating card and shuttle service records for personnel entry,
• Ensuring the continuity of budgeting processes,
• Providing and managing personnel training,
• Planning and carrying out internal training and orientation programmes,
• Managing board of directors’ resolutions,
• Planning and managing general assembly meetings,
• Monitoring litigation and legal affairs,
4.6- Parties to Whom Employee Personal Data May Be Transferred
Personal data processed for the purposes explained above may, in accordance with the fundamental principles stipulated under the Personal Data Protection Law and within the framework of the personal data processing conditions and purposes specified in Articles 8 and 9 of the Personal Data Protection Law, be transferred to business partners, shareholders and, where relevant, public institutions and organisations (the Social Security Institution, İŞKUR and other legally authorised public institutions and organisations), banks, independent audit companies within the framework of legal obligations and statutory limitations for the purpose of conducting our activities, companies with which we have commercial relationships in respect of certain data belonging to you (professional qualification certificates, occupational safety training forms, Social Security Institution records and others), and other institutions and organisations permitted within the legal framework.
4.7- Purpose of Processing Customer, Supplier and Visitor Personal Data,
Sale of products,
Performance of after-sales services,
Wholesale sale of spare parts and accessories,
Fulfilment of the requirements of licence and dealership agreements,
Carrying out collection transactions, including mail order and transfer instructions,
Providing customers with product and service promotions, information, personalised advertisements, campaigns and other benefits; sending commercial electronic communications within the framework of loyalty programmes; conducting surveys and telesales practices; and providing various advantages through statistical analyses,
Conducting activities to improve service quality and providing better service,
Issuing invoices in return for our services,
Procuring outsourced services,
Obtaining services and technology services in matters outside our own field of expertise,
Identity verification,
Responding to questions and complaints,
Taking the necessary technical and administrative measures within the scope of data security,
Ensuring financial reconciliation with relevant business partners and other third parties regarding the products and services provided,
Providing the necessary information in line with the requests and inspections of regulatory and supervisory institutions and official authorities,
Retaining information relating to data required to be retained pursuant to the applicable legislation,
Ensuring the auditing of information consistency,
Measuring customer satisfaction,
Using data obtained through the website or social media channels for marketing purposes through third-party agencies,
Fulfilling legal obligations,
Carrying out/monitoring financial reporting and risk management activities,
Carrying out/monitoring legal affairs,
Creating and monitoring visitor records.
4.8- Special Categories of Personal Data of Customers, Suppliers and Visitors
Within the scope of the Personal Data Protection Law, data relating to race, ethnic origin, political opinion, philosophical belief, religion, religious denomination or other beliefs, appearance and clothing, criminal convictions, if any, security measures, and biometric and genetic data are special categories of personal data.
4.9- Parties to Whom Customer, Supplier and Visitor Personal Data May Be Transferred
Our Company may transfer the personal data and special categories of personal data of the personal data subject to third parties by taking the necessary security measures and in line with lawful personal data processing purposes. Although our Company’s records are generally not shared with foreign countries, personal data may be transferred to foreign countries determined and announced as providing adequate protection within the scope of the Personal Data Protection Law and its associated regulations. The reasons for transfer are explained below:
If the law expressly provides for the transfer of personal data,
If the transfer of personal data belonging to the parties to an agreement is necessary, provided that it is directly related to the conclusion or performance of that agreement,
If the transfer of personal data is mandatory for the fulfilment of a legal obligation,
If the transfer of personal data is mandatory for the establishment, exercise or protection of a right,
If the transfer of personal data is mandatory for our Company’s legitimate interests, provided that it does not prejudice the fundamental rights and freedoms of the personal data subject.
4.10- Processing of Personal Data Relating to Internet Usage
Our Company maintains log records relating to internet access on the computers and network systems available within the Company for the purposes of preventing industrial espionage, preventing any materials belonging to the Company from being taken outside the Company or shared with others, and monitoring and controlling engagement in activities unrelated to assigned duties during working hours, within the framework of the Law on the Regulation of Publications on the Internet and Combating Crimes Committed Through Such Publications and other applicable legislation. These records may be processed if requested by authorised public institutions and organisations or for the purpose of fulfilling legal obligations within the scope of our Company’s internal audits.
4.11- Processing of Personal Data Relating to Security Camera Use
Our Company may process certain personal data and special categories of personal data for the purpose of ensuring and protecting workplace security. Through security camera monitoring activities at our Company, guests and employees present within the Company are monitored and recorded. These activities conducted by our Company are carried out with the knowledge of all employees and by informing incoming visitors within the scope of ensuring the security of the workplace and the employees and guests present at the workplace. Such data are protected by taking the technical, administrative and technological measures necessary to ensure the security of personal data within the scope of the Personal Data Protection Law.
5- PERSONAL DATA RETENTION AND DESTRUCTION PERIODS AND DESTRUCTION POLICY
5.1- Personal Data Recording Media
Personal data processed by our Company for the creation of personnel files, maintenance of visitor records, evaluation of job applications, customer and supplier records, and other reasons are securely retained in non-electronic media such as paper, forms, written and printed documents, cards and card indexes, and in electronic media through servers, all types of software, workplace personal computers, mobile devices, optical disks and memory devices.
5.2- Personal Data Retention Periods
Personal data and/or special categories of personal data belonging to our Company’s employee candidates, employees, customers, suppliers, visitors, and employees of third-party institutions and organisations are retained at a minimum in accordance with the retention conditions established under the Personal Data Protection Law and for periods limited to those prescribed under other laws concerning the retention of personal data. If no period is prescribed under the applicable legislation, such data are retained for as long as required under our Company’s practices and existing industry customs, taking into consideration the requirements of the circumstances.
In this context;
- Personal Data Protection Law No. 6698
- Turkish Code of Obligations No. 6098
- Social Insurance and General Health Insurance Law No. 5510
- Labour Law No. 4857
- Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed Through Such Publications
- Occupational Health and Safety Law No. 6331
- Tax Procedure Law No. 213
- Turkish Civil Code No. 4721
- Turkish Commercial Code No. 6102
- Enforcement and Bankruptcy Law No. 2004
- And the retention periods prescribed under all other applicable legislation which, although not listed herein, contains provisions concerning personal data retention periods.
5.3- Destruction of Personal Data (Deletion, Destruction and Anonymisation)
Personal Data processed by our Company shall, within the scope of the Regulation on the Deletion, Destruction or Anonymisation of Personal Data, be destroyed in the following circumstances:
If all conditions requiring the processing of personal data cease to exist,
If the data subject withdraws their explicit consent,
Upon the data subject’s request for the deletion, destruction or anonymisation of their personal data,
Pursuant to a decision of the Personal Data Protection Authority,
Upon expiry of the periods prescribed under the applicable legislation, personal data shall be deleted, destroyed or anonymised by the data controller
ex officio or upon the request of the data subject.
6-PERSONAL DATA SECURITY AND MEASURES
6.1- Technical and Administrative Measures for the Processing, Protection and Retention of Personal Data
Within the scope of the Personal Data Protection Law and the Regulation on the Deletion, Destruction or Anonymisation of Personal Data, this Policy includes the arrangements made and/or to be made by our Company to establish the necessary technical and administrative measures for securely retaining personal data and special categories of personal data, preventing access by third parties, preventing their processing for purposes other than those prescribed by law, and destroying such data when the purpose requiring their retention ceases to exist.
Technical Measures to Be Implemented
- Preventing external interference with our Company’s computer systems through antivirus software,
- Authorising users regarding access to information systems, restricting access authorisations and blocking access by former employees,
- Subjecting information systems to external penetration testing to inspect security vulnerabilities and taking new measures based on the results,
- Taking the necessary measures to prevent unauthorised entry into the Server Room,
- Maintaining access logs for personal data,
- Establishing a separate system and implementing protection measures for special categories of personal data,
- Ensuring the security of computer passwords and regularly renewing passwords,
- Employing personnel specialising in technical matters,
- Retaining printed documentary materials in closed and locked environments accessible only by authorised personnel,
Administrative Measures to Be Implemented
- Providing relevant training to personnel,
- Conducting internal audits,
- Creating an inventory,
- 7- DESTRUCTION OF PERSONAL DATA
If the conditions specified above arise and the destruction of personal data becomes necessary, personal data stored on servers and in electronic environments shall be irreversibly deleted, and users’ access authorisations shall be revoked.
Records maintained in physical environments shall be destroyed using a document shredder.
Portable memory devices and optical and magnetic cards shall be destroyed.
Although our Company’s periodic destruction period has been determined as 6 MONTHS, if personal data for which the processing conditions have ceased to exist and whose statutory retention periods have expired are identified, action shall immediately be taken within the scope of the destruction policy.
Anonymisation of personal data;
Anonymisation means rendering personal data processed by our Company incapable of being associated with an identified or identifiable natural person, even if matched with other data, when the reasons requiring its processing cease to exist or upon the request of the data subject.
8-RIGHTS OF PERSONAL DATA SUBJECTS
Pursuant to Article 11 of the Personal Data Protection Law, applicants have the following rights concerning their personal data, provided that they apply in person and verify their identity:
a) To learn whether personal data are being processed,
b) To request information if personal data have been processed,
c) To learn the purpose of processing personal data and whether they are used in accordance with that purpose,
d) To know the third parties to whom personal data have been transferred domestically or abroad,
e) To request the correction of personal data if they have been processed incompletely or inaccurately,
f) To request the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7,
g) To request that the actions taken pursuant to paragraphs (d) and (e) be communicated to the third parties to whom the personal data have been transferred,
h) To object to the occurrence of a result against the person arising from the analysis of processed data exclusively through automated systems,
i) To request compensation for damages if the person suffers damage due to the unlawful processing of personal data.
Requests included in applications shall be concluded free of charge within no later than thirty days, depending on the nature of the request. However, if the transaction requires an additional cost for the Company, the fee specified in the tariff determined by the Personal Data Protection Board may be charged.
9- ENTRY INTO FORCE AND UPDATABILITY
This Policy concerning the Processing, Protection, Retention and Destruction of Personal Data, prepared by our workplace, may be updated from time to time, taking into consideration the applicable legislation, implementing regulations and the Company’s needs. Such updates shall be shared through appropriate methods and the website, and the relevant persons may remain informed of the amendments by following them through these channels.
You may contact us regarding your opinions and questions.
Company Title: MAQRE TEKSTİL SAN. VE TİC. LTD. ŞTİ.
Telephone: +90 533 950 79 29
MERSIS Number: 0612181488600001
Tax Office: Merter Tax Office
Tax Number: 612 181 4886
Address: Mehmet Nesih Özmen Mah. Sedir Sk. No: 5 İç Kapı No: 1 Güngören / İstanbul
Email: info@maqre.com
10- DEFINITIONS
Personal Data: Any information relating to an identified or identifiable natural person.
Personal Data Subject: The natural person whose personal data are processed.
Processing of Personal Data: Any operation performed on personal data, such as obtaining, recording, storing, retaining, altering, reorganising, disclosing, transferring, taking over, making available, classifying, or preventing the use of personal data, wholly or partially by automated means or by non-automated means, provided that such processing forms part of a data recording system.
Special Categories of Personal Data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, religious denomination or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data are special categories of personal data.
Explicit Consent: Consent relating to a specific matter, based on information and expressed with free will.
Anonymisation: Altering personal data in such a way that they lose their status as personal data and this condition cannot be reversed. (Rendering personal data incapable of being associated with a natural person.)
Employees, Shareholders and Authorised Representatives of the Organisations with Which We Cooperate: Natural persons, including employees, shareholders and authorised representatives of organisations with which our Company has any type of business relationship (including, without limitation, business partners and suppliers).
Third Party: Other natural persons who do not fall within the scope of this Policy and the Personal Data Protection Policy (e.g. guarantors, accompanying persons and employee candidates). Data processor.
Data Controller: The person who determines the purposes and means of processing personal data and manages the place where the data are systematically maintained (the data recording system).
Visitor: Natural persons who enter the immovable properties owned by our Company for various purposes or visit our websites.


