Personal Data Protection Law
1. PURPOSE AND SCOPE
These Principles on Privacy and Protection of Personal Data (hereinafter referred to as the "Principles") determine the principles adopted by Sönmez Global Yapı ve Ticaret A.Ş. (hereinafter referred to as the "Company") regarding the protection of personal data and aim to inform all relevant data subject groups within the scope of the Personal Data Protection Law No. 6698 (hereinafter referred to as "KVKK No. 6698").
2. PRINCIPLES REGARDING THE PROCESSING OF PERSONAL DATA
As the Company, in our capacity as Data Controller, we process your personal data within the framework of the following principles:
2.1 Processing in Accordance with the Law and Good Faith
In processing your personal data, actions are taken in accordance with the principles set forth by legal regulations, general trust, and good faith. Under this principle, in particular, while striving to achieve our personal data processing purposes, we take into account your interests and reasonable expectations, do not abuse our rights, and act in accordance with the principle of transparency in our data processing activities.
2.2 Ensuring Personal Data is Accurate and Up to Date When Necessary
In line with this principle emphasizing the importance of accuracy and currency of personal data, taking into account your legitimate interests, periodic checks and updates are carried out to ensure that the processed data is accurate and up to date, and necessary measures are taken accordingly. In this context, systems aimed at checking the accuracy of personal data and making necessary corrections are established within the Company. Furthermore, the accuracy of the sources from which personal data is collected is verified, and requests arising from inaccurate personal data are taken into consideration. Therefore, this principle is applied in line with your right to request the correction of personal data under KVKK No. 6698.
2.3 Processing for Specific, Explicit, and Legitimate Purposes
Your personal data is processed based on explicit, specific, and legitimate data processing purposes. In this context, we ensure that our personal data processing activities are clearly understandable by data subjects, and we determine and explicitly state the purposes and legal processing conditions upon which they are based in Article 3 of these Principles.
2.4 Being Relevant, Limited, and Proportionate to the Purpose for Which They Are Processed
Your personal data is processed in a proportionate, relevant, and limited manner to achieve the specified purpose(s), and processing of personal data that is not relevant or required for the realization of the purpose is avoided. Likewise, under this principle, personal data is not collected or processed for non-existent purposes that might be contemplated in the future.
2.5 Retention for the Period Stipulated in Relevant Legislation or Required for the Purpose for Which They Are Processed
Your personal data is retained only for the duration stipulated in the relevant legislation or required for the purpose for which it is processed. In this regard, the Company takes and implements the necessary administrative and technical measures. Within this scope, it is first determined whether a period is stipulated in the relevant legislation for the storage of personal data; if a period is specified, it is complied with; if no period is specified, personal data is stored for as long as necessary for the purpose for which it is processed. If the necessity of the relevant processes ceases to exist, access to your personal data by irrelevant departments is prevented within the framework of the deletion action specified in KVKK No. 6698. Upon expiration of the period or the disappearance of the reasons requiring its processing, provided that there is no legal reason permitting longer processing, your personal data will be destroyed or anonymized in accordance with the personal data protection legislation.
3. CONDITIONS FOR PROCESSING PERSONAL DATA
Your personal data and special categories of personal data may be processed within the scope of KVKK No. 6698 under the conditions set forth below:
3.1 Explicit Provision in Laws
The fundamental rule is that personal data cannot be processed without the explicit consent of data subjects; under this exception, in cases where the processing of personal data is explicitly provided for by law, your personal data may be processed.
3.2 Inability to Obtain Explicit Consent Due to Actual Impossibility
Your personal data may be processed if it is mandatory to process personal data to protect the life or physical integrity of the data subject or another person when the data subject is unable to express consent due to actual impossibility or whose consent cannot be validated legally.
3.3 Direct Relation to the Establishment or Performance of a Contract
Your personal data may be processed provided that it is necessary to process the personal data of the parties to a contract, on the condition that it is directly related to the establishment or performance of the contract.
3.4 Fulfillment of Legal Obligations by the Company
Your personal data may be processed if processing is mandatory for the Company to fulfill its legal obligations arising from legislation, contracts, and similar requirements to which it is subject and responsible.
3.5 Personal Data Made Public
If your personal data has been made public by you—that is, shared with the public by yourself—it may be processed in a manner proportionate to and connected with the purpose of making it public.
3.6 Processing Data Being Mandatory for the Establishment or Protection of a Right
Your personal data may be processed if data processing is mandatory for the establishment, exercise, or protection of a right within the scope of executing and managing processes regarding the legal and commercial rights owned by the Company.
3.7 Processing Data Based on Legitimate Interest
Your personal data may be processed if data processing is necessary for the legitimate interests of the Company. If data processing is required based on this condition, our Company conducts an evaluation taking into account your fundamental rights and freedoms, and decides based on the outcome of the evaluation.
3.8 Processing Based on Explicit Consent
Although processing personal data based on explicit consent is the general rule, explicit consent of data subjects is not relied upon in the presence of other conditions specified in this article. Otherwise, an abuse of right could be cited. In this context, when your personal data is not processed based on any of the conditions specified in these Principles, it is processed based on your explicit consent.
3.9 Processing of Special Categories of Personal Data
We process your special categories of personal data based on your explicit consent pursuant to Article 6 of KVKK No. 6698. In accordance with the same article, special categories of personal data other than health and sexual life may be processed without explicit consent only in cases provided for by law; whereas special categories of personal data regarding health and sexual life may be processed without explicit consent only by persons under a confidentiality obligation or authorized institutions and organizations for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, and planning and management of health services and financing.
4. TRANSFER OF PERSONAL DATA
Your personal data and special categories of personal data may be transferred to our domestic business partners, public institutions and organizations, and similar entities within the scope of Article 2 of these Principles. While carrying out such transfers, compliance with Article 8 of KVKK No. 6698 is observed. Where necessary, your explicit consent is obtained, and the transfer is provided within this framework.
5. SECURITY OF PERSONAL DATA
In order to ensure the security of personal data and prevent unlawful processing, the Company takes all reasonable administrative and technical measures to prevent unauthorized access risks, accidental data loss, intentional data deletion, or damage to data.
All reasonable technical and physical precautions are taken to prevent persons other than those authorized to access personal data from gaining access. In this context, the authorization system, in particular, is designed in a way that makes it impossible for persons and systems to access more personal data than necessary.
The Company conducts or has conducted necessary audits within its own organization or entity to ensure the implementation of the provisions of KVKK No. 6698.
The measures taken are as follows:
Network security and application security are ensured.
Closed system networks are used for personal data transfers via network.
Security measures within the scope of IT systems procurement, development, and maintenance are taken.
The security of personal data stored in the cloud is ensured.
Disciplinary regulations containing data security provisions for employees are in place.
Training and awareness studies on data security are conducted for employees at regular intervals.
An authorization matrix has been created for employees.
Access logs are kept regularly.
Corporate policies regarding access, information security, use, retention, and destruction have been prepared and put into practice.
Confidentiality undertakings are executed.
Authorizations of employees who undergo job changes or leave employment are revoked.
Up-to-date anti-virus systems are used.
Firewalls are used.
Signed contracts contain data security provisions.
Extra security measures are taken for personal data transferred in paper form, and the relevant documents are sent in confidential document format.
Personal data security policies and procedures have been established.
Personal data security issues are reported promptly.
Monitoring of personal data security is carried out.
Necessary security measures regarding entries and exits to physical environments containing personal data are taken.
The security of environments containing personal data is ensured.
Personal data is minimized as much as possible.
Personal data is backed up, and the security of backed-up personal data is also ensured.
User account management and authorization control systems are implemented and monitored.
Periodic and/or random internal audits are conducted or had conducted.
Log records are maintained in a manner preventing user intervention.
Existing risks and threats have been identified.
Protocols and procedures for the security of special categories of personal data have been established and implemented.
Penetration testing is conducted.
Cybersecurity measures are taken, and their implementation is continuously monitored.
Special categories of personal data transferred via portable memory, CD, or DVD media are encrypted prior to transfer.
Data processor service providers are audited at regular intervals regarding data security.
Awareness of data processor service providers regarding data security is ensured.
6. RIGHTS OF THE DATA SUBJECT, APPLICATION PROCEDURES AND PRINCIPLES
6.1 Rights of the Data Subject
The rights of the data subject are regulated in Article 11 of KVKK No. 6698 as follows. Everyone has the right to apply to the data controller to:
a) Learn whether personal data is processed or not,
b) Request information if personal data has been processed,
c) Learn the purpose of processing personal data and whether they are used in accordance with their purpose,
ç) Know the third parties to whom personal data is transferred domestically or abroad,
d) Request correction of personal data if it is processed incompletely or inaccurately,
e) Request the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the Law,
f) Request notification of the operations carried out pursuant to sub-paragraphs (d) and (e) to third parties to whom personal data has been transferred,
g) Object to the occurrence of a result against the person oneself by analyzing the processed data exclusively through automated systems,
ğ) Request compensation for damages in case of incurring damage due to unlawful processing of personal data.
6.2 Application Procedures and Principles
As a data subject, you may submit your requests regarding your rights under Article 11 of KVKK No. 6698 by filling out the Personal Data Protection Application Form available on our website, or through an application fulfilling the minimum conditions set forth in the Communiqué on the Procedures and Principles for Application to the Data Controller, using the methods provided below. As the Company, we will conclude your application free of charge as soon as possible and within thirty days at the latest, depending on the nature of your request. However, if the transaction requires an additional cost, the fee specified in the tariff determined by the Personal Data Protection Board will be charged by the Company.
Application Address
Electronic transmission via Registered Electronic Mail (KEP)
sonmezglobalas@hs03.kep.tr
Transmission via your e-mail address registered in our system, or with a secure electronic signature / mobile signature
kvkk@sonmezglobal.com
Application submitted in writing in person or through a notary public
Merdivenköy Mah. Yumurtacı Abdi Bey Cad, Nur Sk. No:1/1A D:180 34732 Kadıköy/İstanbul