Persoanl Data Protection Policy
PURPOSE AND SCOPE
The protection of personal data and ensuring its privacy have been adopted as a corporate culture by KURTSAN GROUP COMPANIES (comprising Kurtsan İlaçları Anonim Şirketi, Kurtsan Medikal Sanayi ve Ticaret Anonim Şirketi, and Otacı Bitkisel Ürünler Sanayi ve Ticaret Anonim Şirketi; hereinafter briefly referred to within the scope of the Policy as “KURTSAN” or the “Company”). In the course of its activities, the Company exercises the utmost care and effort to process and protect personal data belonging to natural persons in accordance with applicable legal rules and universal principles of law. Acting as the data controller, the Company processes and protects personal data within the scope of this Personal Data Processing and Protection Policy (the “Policy” or the “PDP Policy”).
This PDP Policy concerns the personal data of data subjects other than our employees that our Company, acting as the Data Controller, processes wholly or partly by automated means or by non-automated means, provided that such processing forms part of a data-recording system. The PDP Policy shows how the principles and rules established by the relevant legislation are applied in the Company’s personal-data protection processes. This Policy describes the Company’s general policy and processes concerning the processing and protection of personal data; the obligation to provide information under Article 10 of the Personal Data Protection Law is fulfilled through the relevant privacy notices presented to data subjects for each specific process.
The applicable legislation in force in this field, secondary regulations, and universal principles of law shall apply first and foremost to the protection and lawful processing of personal data. In the event of any conflict between our PDP Policy and the applicable regulations in force, the applicable regulations shall prevail.
We may update this Policy when necessary; therefore, please ensure that you access our current Policy on the date on which you use our services.
DEFINITIONS
| ABBREVIATION | DEFINITION |
|---|---|
| “Explicit Consent” | Consent concerning a specified matter, based on information and expressed of one’s free will. |
| “Obligation to Inform” | The Company’s obligation requiring the Data Controller or persons authorized by it, when personal data are obtained, to provide Data Subjects with information within the scope of Article 10 of the Personal Data Protection Law and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform. |
| “Data Subject” | Natural persons whose personal data are processed by the Company or by persons/institutions authorized on behalf of the Company. |
| “Destruction” | The deletion, destruction, or anonymization of personal data. |
| “Personal Data” | Any information relating to an identified or identifiable natural person. |
| “Anonymization of Personal Data” | The process of rendering personal data impossible to associate in any way with an identified or identifiable natural person, even by matching them with other data. |
| “Processing of Personal Data” | Any operation performed on personal data, such as obtaining, recording, storing, retaining, altering, rearranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of personal data, wholly or partly by automated means or by non-automated means, provided that such processing forms part of a data-recording system. |
| “Deletion of Personal Data” | The process of rendering personal data inaccessible and unusable in any way for the relevant users. |
| “Destruction of Personal Data” | The process of rendering personal data inaccessible, irretrievable, and unusable in any way by anyone. |
| “Board” | Personal Data Protection Board |
| “Authority” | Personal Data Protection Authority |
| “Law”, “Personal Data Protection Law” | Personal Data Protection Law No. 6698 |
| “PDP Policy” | The Personal Data Protection and Processing Policy adopted by the Company. |
| “Special Categories of Personal Data” | Data concerning individuals’ race, ethnic origin, political opinion, philosophical belief, religion, religious sect or other beliefs, appearance and clothing, membership in an association, foundation, or trade union, health, sexual life, criminal convictions and security measures, and biometric and genetic data. |
| “Company” | KURTSAN GROUP COMPANIES |
| “VERBIS”, “Registry” | The Data Controllers’ Registry Information System maintained by the Presidency of the Personal Data Protection Authority. |
| “Data Processor” | A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller. |
| “Data Controller” | A natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data-recording system. |
GENERAL PRINCIPLES FOR THE PROCESSING OF PERSONAL DATA
The Company complies with the “General Principles” set out in Article 4 of the Personal Data Protection Law, which must be observed when processing personal data:
Processing Lawfully and Fairly
The Company manages its personal-data processing activities in accordance with legal rules, universal principles of law, and the rules of good faith; duly informs data subjects to ensure the transparency of the processes; and takes into account the interests and reasonable expectations of the data subject in those processes. In this context, it prevents the data-processing activity from producing results that the data subject does not and should not reasonably expect.
Ensuring That Personal Data Are Accurate and, Where Necessary, Up to Date
As a rule, personal data are processed on the basis of and in the form declared by data subjects, and personal data are presumed accurate as declared. The Company exercises the reasonable care and attention required to keep personal data held within its legal entity accurate and up to date and to ensure that they do not contain incorrect information. If the data subject informs the Company of changes in the personal data processed, the Company ensures that the necessary administrative and technical mechanism is established to update the personal data in the relevant database.
Processing for Specified, Explicit, and Legitimate Purposes
Before commencing a personal-data processing activity, the Company sets out its legitimate and lawful data-processing purposes in a specified and explicit manner and processes personal data in connection with the Company’s products and services and only to the extent necessary for them.
Being Relevant, Limited, and Proportionate to the Purposes for Which They Are Processed
Personal data are processed in a manner that is relevant, limited, and proportionate to the purposes determined by the Company and disclosed to the data subject. The Company seeks to establish a reasonable balance between the data-processing activity and the purpose sought to be achieved and ensures that processing is limited to the extent necessary to achieve that purpose.
Retaining Personal Data for the Period Prescribed by the Relevant Legislation or Necessary for the Purpose for Which They Are Processed
The Company retains personal data for the period prescribed by legislation or required by the purpose of processing. However, when the period prescribed by legislation expires or when all purposes of processing cease to exist, it deletes, destroys, or anonymizes the personal data. Acting as the Data Controller, the Company has determined, in its Personal Data Retention and Destruction Policy, the retention periods, destruction intervals, and technical and administrative measures to be implemented for retaining personal data, and it is aware of its obligation to ensure that personal data are retained in accordance with those principles.
These principles apply regardless of whether the Company has processed personal data on the basis of explicit consent or in accordance with other data-processing conditions. In this regard, the Company processes personal data in accordance with the data-processing conditions and general principles and also fulfills its obligation to inform data subjects.
INFORMATION ON THE PROCESSING OF PERSONAL DATA
The Company has defined below, in a manner that may be revised and updated, the categories of personal data it processes; the groups of data subjects whose data are processed; the purposes of processing personal data; the legal conditions on which the processing of personal data is based; the channels through which personal data are collected; the recipient groups to which they are transferred; the retention periods and destruction processes applicable to personal data whose retention period has expired; and the security measures taken to ensure the security of personal data throughout all these processes. All such information is published publicly in summarized and updated form in the Data Controllers’ Registry Information System, VERBIS (verbis.kvkk.gov.tr), available on the Authority’s website, and is updated on that platform.
Categories of Personal Data
The Company has categorized the personal data it processes in order to ensure compliance with legal regulations and properly manage its personal-data processing and protection processes.
All categories of personal data are essentially organized under two main categories: “Personal Data” and “Special Categories of Personal Data.”
All categories of personal data processed within our Company and their definitions are as follows:
| Personal Data Category | Definition |
|---|---|
| Identity Data | Such as name and surname, mother’s and father’s names, mother’s maiden name, date of birth, place of birth, marital status, identity card series and serial number, Turkish Republic identity number, and signature |
| Contact Data | Such as address number, email address, contact address, registered electronic mail (KEP) address, and telephone number |
| Location Data | Location information concerning the person’s whereabouts |
| Personnel Data | Such as payroll information, disciplinary investigations, employment entry and exit document records, asset-declaration information, résumé information, and performance-evaluation reports |
| Legal Transaction Data | Such as information in correspondence with judicial authorities and information in case files |
| Customer Transaction Data | Such as call-center records, invoices, promissory-note and check information, information in cash-desk receipts, order information, and request information |
| Physical Premises Security | Such as employee and visitor entry and exit records and camera recordings |
| Transaction Security Data | Such as IP-address information, website login and logout information, and password information |
| Financial Data | Such as bank and IBAN information, balance-sheet information, financial-performance information, credit and risk information, and asset information |
| Professional Experience Data | Such as diploma information, courses attended, in-service training information, certificates, and transcript information |
| Marketing | Such as shopping-history information, surveys, cookie records, and information obtained through campaign activities |
| Visual and Audio Recordings | Such as photographs, videos, and visual and audio recordings |
| Special Category of Personal Data | Definition |
|---|---|
| Criminal Convictions and Security Measures | Such as information concerning criminal convictions and information concerning security measures |
| Health Information | Such as information concerning disability status, blood-group information, personal health information, and information concerning devices and prostheses used |
Groups of Persons Whose Personal Data Are Processed
The groups of data subjects whose personal data are processed within our Company and their definitions are publicly notified and published in VERBIS (verbis.kvkk.gov.tr), available on the Authority’s website.
Purposes of Processing Personal Data
The Company processes personal data in accordance with the “General Principles for the Processing of Personal Data” set out in Article 4 of the Law and described above, based on and limited to at least one of the personal-data processing conditions specified in Articles 5 and 6 of the Law. Pursuant to Article 10 of the Law and secondary legislation, the Company separately informs the relevant groups of data subjects, through the relevant privacy notices, about the categories and purposes of data processing. The Company’s purposes for processing personal data have been declared in the Data Controllers’ Registry Information System (VERBIS) and are maintained in the system for public access (link: verbis.kvkk.gov.tr).
Conditions for Processing Personal Data
The Company processes personal data with the explicit consent of the data subject or, where one or more of the other data-processing conditions exist, in accordance with such condition or conditions. Where the personal data processed are special categories of personal data, the conditions specified under the heading “Processing of Special Categories of Personal Data” in this Policy shall apply.
Existence of the Data Subject’s Explicit Consent
This data-processing condition applies where the data subject has given explicit consent concerning a specified matter, based on information and expressed of their free will. Explicit consent obtained from the data subject is retained by the Company in a demonstrable manner for the period required under personal-data protection legislation. Where the personal-data processing conditions set out below exist, personal data may be processed without requiring the data subject’s explicit consent.
Expressly Provided for by Law
This data-processing condition applies where the relevant law contains an express provision concerning the processing of the personal data in question. By way of example, personal data are processed for the purpose of fulfilling legal obligations under the Personal Data Protection Law, the Law on Consumer Protection, the Turkish Code of Obligations, the Turkish Commercial Code, the Tax Procedure Law, and other relevant legislation.
Inability to Obtain the Data Subject’s Explicit Consent Due to Actual Impossibility
Where it is necessary to process the personal data of a person who is unable to express consent due to actual impossibility or whose consent is not recognized as legally valid in order to protect the life or physical integrity of that person or another person, the data subject’s data are processed on the basis of this data-processing condition.
Being Directly Related to the Establishment or Performance of a Contract
Where processing personal data is necessary, provided that it is directly related to the establishment or performance of a contract to which the data subject is a party, processing takes place on the basis of this data-processing condition.
Being Necessary for the Data Controller to Fulfill Its Legal Obligation
Where processing personal data is necessary for our Company to fulfill its legal obligations arising from legislation or a contract, processing takes place on the basis of this data-processing condition.
Personal Data Having Been Made Public by the Data Subject
Personal data made public by the data subject may be processed only to the extent consistent with the purpose for which they were made public.
Processing Being Necessary for the Establishment, Exercise, or Protection of a Right
Where data processing is necessary for the establishment, exercise, or protection of a right, the data subject’s personal data are processed on the basis of this data-processing condition.
Processing Being Necessary for the Legitimate Interests of the Data Controller
Where data processing is necessary for the legitimate interests of the Company, provided that the fundamental rights and freedoms of the data subject are not prejudiced, processing is carried out on the basis of this data-processing condition.
Conditions for Processing Special Categories of Personal Data
The Company processes special categories of personal data by complying with the additional measures announced by the Personal Data Protection Board, taking all necessary administrative and technical measures, and where one of the following data-processing conditions exists:
Pursuant to Article 6/3 of the Personal Data Protection Law, the processing of special categories of personal data is prohibited. However, such data may be processed where:
a) the data subject has given explicit consent,
b) processing is expressly provided for by law,
c) processing is necessary to protect the life or physical integrity of the person who is unable to express consent due to actual impossibility or whose consent is not recognized as legally valid, or of another person,
ç) processing concerns personal data made public by the data subject and is consistent with the data subject’s intention to make them public,
d) processing is necessary for the establishment, exercise, or protection of a right,
e) processing is necessary, by persons subject to a duty of confidentiality or by authorized institutions and organizations, for protecting public health, conducting preventive medicine, medical diagnosis, treatment, and care services, and planning, managing, and financing healthcare services,
f) processing is necessary for fulfilling legal obligations in the fields of employment, occupational health and safety, social security, social services, and social assistance,
g) processing is carried out by foundations, associations, and other non-profit organizations or entities established for political, philosophical, religious, or trade-union purposes, provided that it is consistent with the legislation to which they are subject and their purposes, is limited to their fields of activity, is not disclosed to third parties, and relates to their current or former members and affiliates or to persons who are in regular contact with such organizations and entities.
Channels for Collecting Personal Data
The Company obtains personal data from physical and electronic environments in accordance with legal regulations and the purposes set out in this Policy and on the basis of the processing conditions. These environments and the channels through which personal data are obtained are as follows:
| Physical Data Collection | Electronic Data Collection |
|---|---|
| Physical Mail | |
| Printed Forms | Website |
| Software and Applications Used | |
| Devices within the Scope of IT | |
| Corporate Social Media Accounts | |
| Communication Platform |
These channels may vary depending on the development and modification of business processes and technological developments. In accordance with the principle of transparency, such changes will be presented through updates to the Policy.
Transfer of Personal Data
The Company transfers personal data and special categories of personal data to third parties in the manner prescribed by Articles 8 and 9 of the Law, on the basis of lawful purposes for processing personal data, and by taking all necessary administrative and technical measures.
Domestic Transfers
The Company acts lawfully in its data-transfer activities. It transfers data to third parties to whom personal data are transferred only to the extent required by the service. Through data-transfer agreements, it appropriately instructs the “Transfer Recipient” groups that are “Data Processors” concerning data security.
| Recipient Groups | Example Purpose of Transfer |
|---|---|
| Authorized Public Institutions and Organizations | Transferred for the purpose of fulfilling our legal obligations. |
| Natural persons or legal entities governed by private law | Transferred for the purposes of following up and conducting legal affairs, obtaining consultancy services, and conducting activities in compliance with legislation. |
| Supplier (Product / Service Provider) Companies and Agencies | Transferred for the purposes of procuring products/services, ensuring business continuity, and establishing and performing contracts. |
| Customer Companies / Business Partners / Group Companies | Transferred for the purposes of conducting contractual processes, selling products/services, and maintaining the continuity of commercial activities. |
| Bank | Transferred for the purpose of conducting finance and accounting processes. |
| Independent Audit Company | Transferred for the purpose of conducting audit activities. |
| Certification Companies | Transferred for the purpose of conducting quality processes. |
| Group / Community Companies | Transferred for the purposes of conducting business processes and providing support services. |
| Lawyers | Transferred within the scope of establishing a right. |
| Insurance Companies | Transferred for the purpose of conducting insurance transactions. |
Transfers Abroad
The Company may transfer personal data abroad only in the manner prescribed by Article 9 of the Personal Data Protection Law and by taking the necessary administrative and technical measures. Such transfer is possible if one of the following conditions is met:
Personal data may be transferred abroad by our Company where one of the conditions specified in Articles 5 and 6 exists and an adequacy decision has been issued concerning the country to which the transfer will be made, sectors within that country, or international organizations.
In the absence of an adequacy decision, personal data may be transferred abroad by our Company where one of the conditions specified in Articles 5 and 6 exists, provided that the data subject has the opportunity to exercise their rights and seek effective legal remedies in the country to which the transfer will be made and that the parties provide one of the following appropriate safeguards:
The existence of an agreement that is not in the nature of an international treaty between public institutions and organizations or international organizations abroad and public institutions and organizations or professional organizations having the status of public institutions in Türkiye, and authorization of the transfer by the Board.
The existence of binding corporate rules approved by the Board that contain provisions concerning the protection of personal data and that companies within a group of undertakings engaged in a joint economic activity are obliged to comply with.
The existence of a standard contract announced by the Board that contains matters such as data categories, the purposes of the data transfer, recipients and recipient groups, the technical and administrative measures to be taken by the data recipient, and additional measures taken for special categories of personal data.
The existence of a written undertaking containing provisions that ensure adequate protection and authorization of the transfer by the Board. If either of the two conditions in question is not met, personal data may be transferred abroad only with the explicit consent of the data subject.
In the absence of an adequacy decision and where none of the appropriate safeguards described above can be provided, our Company may transfer personal data abroad only on an occasional basis and only where one of the following circumstances exists:
The data subject gives explicit consent to the transfer, provided that the data subject is informed of the possible risks.
The transfer is necessary for the performance of a contract between the data subject and the data controller or for the implementation of pre-contractual measures taken at the data subject’s request.
The transfer is necessary for the conclusion or performance of a contract to be entered into between the data controller and another natural or legal person for the benefit of the data subject.
The transfer is necessary for an overriding public interest.
The transfer of personal data is necessary for the establishment, exercise, or protection of a right.
The transfer of personal data is necessary to protect the life or physical integrity of a person who is unable to express consent due to actual impossibility or whose consent is not recognized as legally valid, or of another person.
The transfer is made from a register open to the public or to persons with a legitimate interest, provided that the requirements for accessing the register under the relevant legislation are met and the person with a legitimate interest requests the transfer.
Retention and Destruction of Personal Data
Acting as the Data Controller, the Company has determined, in its “Personal Data Retention and Destruction Policy,” the retention periods, destruction intervals, and technical and administrative measures to be implemented for retaining personal data, and has separately declared those periods in VERBIS for each category of personal data. The Company is aware of its obligation to ensure that personal data are retained in accordance with those principles.
Pursuant to the Personal Data Protection Law, personal data are retained for the period prescribed by the relevant legislation or required for the purpose for which they are processed. Those periods have been determined, and upon their expiry, the relevant personal data are deleted, destroyed, or anonymized for use for analytical purposes at the end of the periodic destruction intervals specified in the relevant Policy pursuant to the “Regulation on the Deletion, Destruction or Anonymization of Personal Data.” You may request further information using the contact details provided in this PDP Policy.
SECURITY MEASURES CONCERNING PERSONAL DATA
The Company takes technical and administrative measures, within technological capabilities and taking implementation costs into account, to ensure that personal data are processed lawfully. The technical and administrative measures taken to protect personal data are applied diligently and with additional measures in relation to special categories of personal data; the necessary audits are periodically conducted at the highest level within the Company, and these security measures are also specified in VERBIS.
The Company takes all appropriate security measures to ensure that personal data are processed only within the scope of the specified purposes and to reduce risks such as malicious use, unauthorized access to, transfer, destruction, or alteration of personal data. These security measures also include other measures taken in relation to matters such as ensuring that personal data are not transferred to countries that do not provide an adequate level of data protection.
The personal data processed by the Company are confidential, and the Company respects such confidentiality. Only persons authorized by the Company may access personal data. In this context, the Company ensures that software complies with standards, that third parties are selected with due care, and that the PDP Policy is observed within the Company.
Although the Company takes the necessary data-security measures, if personal data are damaged or obtained by unauthorized third parties as a result of attacks on platforms operated by the Company or on the Company’s system, the Company immediately takes action to remedy the breach and minimize the harm suffered by the data subject. The Company immediately notifies the data subjects and the Board of the situation and takes the necessary measures. The rules and procedures concerning personal-data breaches are set out in the “Personal Data Breach Management Policy.”
OBLIGATION TO INFORM
In accordance with Article 10 of the Personal Data Protection Law and the provisions of the “Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform,” the Company informs data subjects, through the relevant privacy notices, of the identity of the data controller; the methods by which their personal data are collected; the legal ground and purposes of processing; the persons to whom personal data are transferred and the purposes of such transfers; and the rights held by data subjects in connection with the processing of their personal data.
RIGHTS OF DATA SUBJECTS
Under the Constitution of the Republic of Türkiye, everyone has the right to request the protection of personal data concerning them. In this context, the data subject’s rights concerning their personal data are listed in Article 11 of the Personal Data Protection Law as follows:
to learn whether their personal data are processed,
to request information if their personal data have been processed,
to learn the purpose of processing their personal data and whether they are used in accordance with that purpose,
to know the third parties in Türkiye or abroad to whom their personal data have been transferred,
to request correction of their personal data if they have been processed incompletely or inaccurately,
to request deletion or destruction of their personal data within the framework of the conditions set out in Article 7 of the Personal Data Protection Law,
to request that such deletion, destruction, or correction operations be notified to third parties to whom the personal data have been transferred,
to object to the occurrence of a result against the data subject through analysis of the processed data exclusively by automated systems,
to claim compensation for damage suffered due to the unlawful processing of their personal data in breach of the Personal Data Protection Law.
Within the scope of the rights specified above, the data subject may submit requests in writing to the Company’s registered electronic mail (KEP) address using a secure electronic signature, mobile signature, or the email address previously notified to the Company by the data subject and registered in the Company’s system. The data subject may use the “Data Subject Application Form” available on the Company’s website. The application must include:
name and surname and, if the application is in writing, signature,
for citizens of the Republic of Türkiye, the Turkish Republic identity number; for foreigners, nationality, passport number, or identity number, if any,
residential or workplace address for service of notices,
email address, telephone number, and fax number for notifications, if any,
the subject matter of the request; and
information and documents relating to the matter must also be attached to the application. Applications will be considered only if they are in Turkish. For third parties to submit an application request on behalf of data subjects, a special power of attorney issued by a notary public by the data subject in the name of the applicant must be provided.
Where data subjects submit requests concerning the rights listed above to the Company as specified in this PDP Policy and, in all circumstances, in accordance with the application procedures prescribed in the “Communiqué on the Procedures and Principles of Application to the Data Controller,” the Company will conclude the request free of charge as soon as possible and no later than 30 (thirty) days from the date of application, depending on the nature of the request. However, if the transaction entails an additional cost, the Company may charge the fee set out in the tariff determined by the Board.
For written applications, the application date is the date on which the document is served on the data controller or its representative. For applications made by other methods, the application date is the date on which the application reaches the data controller.
RELATED DOCUMENTS
Other policies, procedures, and documents implemented within the Company in connection with this PDP Policy (such as the Personal Data Retention and Destruction Policy, Personal Data Breach Management Policy, relevant privacy notices, and Data Subject Application Form) are deemed an integral part of this Policy and are applied together with it.
EFFECTIVE DATE AND AMENDMENTS
This Policy is published on the Company’s website and enters into force on the date of publication. The Company may amend this Policy at any time. Such amendments take effect on the date on which the new amended Policy is published.
OUR DETAILS AND CONTACT INFORMATION
If you have any questions about the PDP Policy or our approach to the processing and protection of your personal data, or if you wish to exercise any of the rights specified in the Personal Data Protection Law, you may obtain information using any of the following methods:
KURTSAN GROUP COMPANIES
Address: Merkez Mah. Bağlar Cad. No: 14c Interior Door No: 4 Kağıthane / Istanbul
Email: kurtsan@kurtsan.com