Personal Data Storage and Destruction Policy
Personal data retention and destruction policy TURCONN METAL SANAYİ ve TİCARET A.Ş. It has been prepared to determine the procedures and principles regarding the work and transactions regarding the storage and destruction of personal data processed by.
TAKE THE FIRST STEP FOR OUR COOPERATION
If you have any request about our products and services, please feel free to contact us. Our sales team will support you as soon as possible.
Personal Data Storage and Destruction Policy
TURCONN METAL SANAYİ ve TİCARET A.Ş.
PERSONAL DATA STORAGE AND DESTRUCTION POLICY
ARTICLE 1- PURPOSE
Personal data storage and destruction policy TURCONN METAL SANAYİ ve TİCARET A.Ş. It has been prepared to determine the procedures and principles regarding the work and transactions regarding the storage and destruction of personal data processed by.
ARTICLE 2 – SCOPE
Personal data of company employees, employee candidates, interns, product and service buyers, potential customers, partners, visitors, suppliers and other third parties are within the scope of this policy.
This policy applies to all recording environments where personal data owned or managed by the company is processed and activities related to personal data processing.
ARTICLE 3 – DEFINITIONS
Recipient Group : Category of natural or legal persons to whom personal data is transferred by the data controller.
Explicit Consent : Consent regarding a specific subject, based on information and expressed with free will.
Anonymization : Making personal data impossible to associate with an identified or identifiable natural person in any way, even by matching it with other data.
Employee : Company personnel
Electronic Environment : Environments where personal data can be created, read, changed and written with electronic devices.
Non-Electronic Media : All written, printed, visual, etc. other than electronic media. other media
Service Provider : Natural or legal person who provides services within the framework of a specific contract with the Company.
Relevant Person : Natural person whose personal data is processed
Relevant User : Persons who process personal data within the data controller organization or in line with the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.
Destruction : Deletion, destruction or anonymization of personal data
Law : Personal Data Protection Law No. 6698
Recording Medium : Any environment containing personal data processed by fully or partially automated or non-automatic means, provided that it is part of any data recording system.
Personal Data : Any information regarding an identified or identifiable natural person.
Personal Data Processing Inventory : Personal data processing activities carried out by data controllers depending on their business processes; The inventory they create by associating the purposes and legal reason for processing personal data with the data category, the transferred recipient group and the data subject person group, and detailing the maximum retention period required for the purposes for which personal data are processed, the personal data envisaged to be transferred to foreign countries and the measures taken regarding data security.
Processing of Personal Data : Obtaining, recording, storing, preserving, changing, rearranging, disclosing, transferring, taking over, making available, classifying personal data by fully or partially automatic or non-automatic means provided that it is part of any data recording system. Any action taken on the data, such as preventing its use or
Board : Personal Data Protection Board
Personal Data of Special Qualifications: Personal data about individuals’ race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance, association, foundation or union membership, health, sexual life, criminal convictions and security measures, as well as biometric data and genetic data
Periodic Destruction : In case all the processing conditions of personal data specified in the law are eliminated, the process of deleting, destroying or anonymizing personal data specified in the personal data storage and destruction policy and to be carried out ex officio at recurring intervals.
Policy : Personal Data Storage and Destruction Policy
Company: TURCONN METAL SANAYİ ve TİCARET A.Ş.
Data Processor : Natural or legal person who processes personal data on behalf of the data controller, based on the authority given by the data controller.
Data Recording System : Recording system where personal data is structured and processed according to certain criteria.
Data Controller: Real or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system
Data Controllers Registry Information System: The information system created and managed by the Presidency, accessible over the internet, that data controllers will use in applying to the Registry and other relevant transactions related to the Registry.
VERBİS : Data Controllers Registry Information System
Regulation : Regulation on Deletion, Destruction or Anonymization of Personal Data published in the Official Gazette dated 28 October 2017
ARTICLE 4 – RESPONSIBILITIES AND DUTIES
All employees and units of the company; It provides full and active support to the units responsible for obtaining, processing and storing personal data in accordance with the law. All employees and units support the responsible units in the implementation of administrative and technical measures taken within the scope of the policy, in training unit employees, in ensuring, increasing and monitoring the awareness of employees, in preventing unlawful access to personal data and in maintaining personal data in accordance with the law.
The distribution of the titles, units and job descriptions of those involved in the storage and destruction processes of personal data are shown in ANNEX TABLE: 1.
ARTICLE 5 – RECORDING MEDIA
Personal data is kept securely by the company in accordance with the law in the environments listed in ANNEX TABLE: 2.
ARTICLE 6 – LEGAL REASONS REQUIRING STORAGE
– Personal data processed within the scope of activities in the company are kept for the period stipulated in the relevant legislation and within the scope of the relevant legislation. The reasons that require storage in this context are as follows:
– Storing personal data because it is directly related to the establishment and execution of contracts,
– Storing personal data for the purpose of establishing, exercising or protecting a right,
– It is mandatory to keep personal data for the legitimate interests of the company, provided that it does not harm the fundamental rights and freedoms of individuals,
– Storing personal data for the purpose of fulfilling any legal obligations of the company,
– The storage of personal data is clearly stipulated in the legislation,
– Existence of explicit consent of data owners in terms of storage activities that require explicit consent of data owners,
ARTICLE 7 – PURPOSE OF PROCESSING THAT REQUIRES STORAGE
The company may process the personal data of the data subject or third parties specified by the data subject for various purposes, including but not limited to the following:
– Carrying out human resources processes,
– Providing corporate communication,
– Ensuring company security,
– Conducting statistical studies,
– To be able to carry out work and transactions as a result of signed contracts and protocols,
– To ensure that legal obligations are fulfilled as required or required by legal regulations,
– To contact real/legal persons who have business relations with the Company,
– Making legal reports,
– To fulfill the burden of proof as evidence in legal disputes that may arise in the future,
– Execution/monitoring of company legal and accounting affairs,
ARTICLE 8 – LEGAL REASONS REQUIRING DESTRUCTION
Personal data is deleted or destroyed by the company upon the request of the relevant person or ex officio in case of the following situations:
– Amending or removing the relevant legislative provisions that form the basis for the processing of personal data,
– The purpose that requires processing or storing personal data is eliminated,
– In cases where personal data is processed only on the basis of explicit consent, the relevant person must withdraw his/her explicit consent,
– In accordance with Article 11 of the Law, the application made by the relevant person for the deletion and destruction of his personal data within the framework of his rights is accepted by the data controller,
– The maximum period requiring personal data to be stored has passed and there are no conditions that justify storing personal data for a longer period of time,
ARTICLE 9 – TECHNICAL MEASURES
The technical measures taken by the Company regarding the personal data it processes are as follows:
– It carries out the necessary internal controls within the scope of the established systems.
– Conducts information technologies risk assessment and business impact analysis processes within the scope of established systems.
– Ensures the provision of technical infrastructure to prevent or monitor data leakage outside the company and the creation of relevant matrices.
– Ensures control of system vulnerabilities by receiving penetration testing service regularly and when needed.
– Ensures that the access rights of employees in information technology units to personal data are kept under control.
– Destruction of personal data is ensured in a way that cannot be recycled and does not leave an audit trail.
– In accordance with Article 12 of the Law, any digital environment where personal data is stored is protected by encrypted or cryptographic methods to meet information security requirements.
ARTICLE 10 – ADMINISTRATIVE MEASURES
The administrative measures taken by the company regarding the personal data it processes are as follows:
– Limits internal access to stored personal data to personnel who are required to access it according to their job description. In restricting access, whether the data is of special nature and its degree of importance are also taken into account.
– If the processed personal data is obtained by others through illegal means, it notifies the relevant person and the Board as soon as possible.
– Regarding the sharing of personal data, it signs a framework contract regarding the protection of personal data and data security with the persons with whom the personal data is shared, or ensures data security by adding provisions to the existing contract.
– It employs knowledgeable and experienced personnel about the processing of personal data and provides its personnel with the necessary training within the scope of personal data protection legislation and data security.
– It carries out the necessary inspections and has them carried out in order to ensure the implementation of the provisions of the Law within its own legal entity. It eliminates privacy and security vulnerabilities that arise as a result of audits.
ARTICLE 11- METHODS OF DELETION OF PERSONAL DATA
Personal data is deleted by the methods specified in ADDITIONAL TABLE: 3.
ARTICLE 12- METHODS OF DESTRUCTION OF PERSONAL DATA
Personal data is destroyed by the methods specified in ADDITIONAL TABLE: 4.
ARTICLE 13 – STORAGE AND DISPOSAL PERIOD
When determining the retention period of personal data by the company; First of all, if a period of time is stipulated in the legal legislation for the storage of personal data in question, this period is respected. Except that; The storage and destruction period table in ANNEX TABLE: 5 is taken as basis.
ARTICLE 14 – PERIODIC DESTRUCTION PERIOD
The company carries out periodic destruction in June and December every year.
ARTICLE 15- PUBLISHING, STORING AND UPDATING THE POLICY
The policy is published in two different media, with wet signatures (printed paper) and electronically, and is announced to the public on the website. The printed paper copy is kept within the company. The policy is reviewed as needed and necessary sections are updated.
ARTICLE 16 – ENFORCEMENT
The policy is deemed to come into force after it is published on the company’s website. If it is decided to abolish the policy, the old signed copies of the policy are canceled and signed (with a cancellation stamp or written cancellation) and kept by the company for at least 5 years.
ADDITIONAL TABLE: 1 Storage and disposal processes task distribution
|
TITLE |
UNIT OF |
DUTY |
|
Company Manager |
Company |
Responsible for employees to comply with the policy. |
|
…. |
Responsible for the preparation, development, execution, publication and updating of the policy in relevant media. |
|
|
All Other Units |
He is responsible for the execution of the Policy in accordance with his duties. |
|
ADDITIONAL TABLE: 2 Personal Data Storage Environments
|
Electronic Media |
Non-Electronic Media |
|
Personal computers Mobile Devices Printers, scanners, copiers Removable and portable memories Servers Softwares Information security devices |
Papers Written and printed media Visual recordings Manual data recording systems |
ADDITIONAL TABLE: 3 Methods of Deletion of Personal Data
|
Data Recording Environment |
Deletion Method |
|
Servers |
For personal data on the servers whose retention period has expired, the system administrator removes the access authorization of the relevant users and deletes them. |
|
Electronic environment |
Among the personal data in the electronic environment, those whose period of storage has expired are made inaccessible and unusable in any way for other employees (relevant users) except the database administrator. |
|
Physical environment |
Personal data kept in physical environment, for those whose period of storage has expired, are made inaccessible and unusable by all employees except the unit manager responsible for the document archive. In addition, blackening is also applied by drawing/painting/erasing the surface so that it cannot be read. |
|
Portable media |
Among the personal data kept in Flash-based storage media, those that have expired are stored in secure environments with encryption keys, by being encrypted by the system administrator and access authorization is given only to the system administrator. |
ADDITIONAL TABLE: 4 Methods for Destruction of Personal Data
|
Data Recording Environment |
Destruction Method |
|
Physical environment |
Personal data stored on paper that have expired are irreversibly destroyed in document shredder machines. |
|
Optical or magnetic media |
Personal data contained in optical media and magnetic media whose storage period has expired are physically destroyed, such as melting, burning or pulverizing. In addition, the data on the magnetic media is rendered unreadable by passing it through a special device and exposing it to a high magnetic field. |
APPENDIX TABLE: 5 Storage and Disposal Period Table
|
PERIOD |
STORAGE PERIOD |
DESTRUCTION PERIOD |
|
Occupational health and safety practices |
10 years following the end of the employment relationship |
180 days following the end of the storage period |
|
Payroll |
10 years following the end of the employment relationship |
180 days following the end of the storage period |
|
Answering personnel court/courthouse requests |
10 years following the end of the employment relationship |
180 days following the end of the storage period |
|
Filing of education records |
10 years after organizing the training |
180 days following the end of the storage period |
|
Emergency preparations |
10 years following preparation |
180 days following the end of the storage period |
|
Log record tracking systems |
10 years from creation |
180 days following the end of the storage period |
|
Camera recordings |
15 days from registration |
Automatically at the end of the storage period |

