Document Namemi | : | FERAH KONFEKSIYON SAN.VE TUR TIC.A.S. Policy on Protection and Processing of Personal Data |
Effective Date | : | 15/06/2020 |
We, FERAH KONFEKSIYON SAN.VE TUR. TIC.A.S.(the “Company”), attach maximum importance to legally process and protect personal data in accordance with the Law no. 6698 on the Protection of Personal Data (the “Law”), and act elaborately in all our planning and activities. With this awareness, we present this Policy on Processing and Protection of Personal Data (“Policy”) to your information in order to fulfill the obligation of explanation within the scope of Article 10 of the Law and to inform all administrative and technical measures we have taken within the scope of processing and protection of personal data.
The main purpose of this Policy is to make explanations about the systems for the processing and protection of personal data in accordance with law and the purpose of the Law, and within this context, to inform the persons, especially the Stakeholders and Officials of the Company, our Business Partners, Suppliers, Employees of the Suppliers, Legal Persons from which we Procure Services, our Employee Candidates, our Visitors, Customers of the Company, Potential Customers, and Third Parties, whose personal data is processed by our Company. Thus, it is aimed to ensure full compliance with the legislation for the processing and protection of personal data performed by our Company and to protect all rights of the owners of personal data arising from the legislation on personal data.
This Policy has been prepared either by automated, or non-automatic means, provided that it is part of any data recording system, for persons, especially the Stakeholders and Officials of the Company, our Business Partners, Suppliers, Employees of the Suppliers, Legal Persons from which we Procure Services, our Employee Candidates, our Visitors, Customers of the Company, Potential Customers, and Third Parties, whose personal data is processed by our Company, and it shall be applied for these persons. This Policy shall in no way be applied to legal entities and legal entity data as already required by the Law.
Our Company informs such Personal Data Owners about the Law by publishing this Policy on its website. “Policy on Processing of Personal Data for Employees” shall be applied for the employees of our Company. This Policy shall not apply in case the data is not included as “Personal Data” within the scope specified below or if the Personal Data processing activity carried out by our Company is not performed by the means mentioned above.
Stakeholder of the Company | : | They are the real person Stakeholders of the Company. |
Real Person Business Partner of the Company | : | They are the real persons with whom the Company has any business relationship. |
Stakeholder, Official and Employee of Business Partners of the Company | : | They are all the natural persons, including employees, stakeholders and officials of real and legal persons (such as business partners, suppliers) with whom the Company has any business relationship. |
Employee Candidate | : | They are the real persons who have made job application to the Company in any way or who have allowed the Company to review their resumes and related information. |
Employee | : | They are the real persons who have an employment contract with the Company within the scope of the Labor Law. |
Customers of the Company | : | They are the real persons who use or have used the products and services offered by the Company, regardless of whether they have any contractual relationship with the Company. |
Potential Customer | : | They are the real persons who have requested or had an interest in using the products and services of the Company or who have been assessed that they could have this interest in accordance with the commercial customs and good faith rules. |
Visitor | : | They are all the real persons who access the physical premises of the Company or visit the websites for various purposes. |
Third Party | : | They are other real persons who do not fall within the scope of the Policy on the Protection and Processing of Personal Data prepared for Company Employees and into any personal data owner category in this Policy. |
Supplier’s Authorized Person | : | They are the authorized persons of the main employer or sub-employer we work with. |
Supplier’s Employees | : | Refers to the employees of the main employer or sub-employer we work with who have employment contracts. |
The concepts included in this Policy shall have the following meanings:
Our Company | : | FERAH KONFEKSİYON SAN VE TUR TİC AŞ. |
Personal Data | : | Any information related to the person whose identity is identified or identifiable. |
Private Personal Data | : | Data with respect to race, ethnicity, political thought, philosophical belief, religion, sect or other beliefs, appearance, association, foundation or trade union membership, health, sexual life, criminal conviction and security measures, and biometric and genetic data are private data. |
Processing of Personal Data | : | All kinds of operations performed on data such as obtaining, recording, storing, maintaining, altering, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the using of Personal Data through fully or partially automated or non-automatic means provided that it is part of any data recording system. |
Personal Data Owner/Relevant Person | : | Refers to the Stakeholders and Employees of the Company, Business Partners of the Company, Company Officials, Employee Candidates, Visitors, Customers of the Company, Potential Customers, Third Parties and persons whose personal data are processed by the Company. |
Data Recording System | : | Refers to the recording system where personal data are structured and processed based on certain criteria. |
Data Officer | : | Real or legal person who determines the purposes and methods of processing personal data and is responsible for the establishment and management of the data recording system. |
Data Operator | : | A real or legal person who processes personal data on behalf of the data officer basing on the authority given by him/her. |
Explicit Consent | : | Consent with regard to a specific subject, based on information and expressed in free will. |
Anonymization | : | Making data, which was previously associated with a person, in no way to be associated with an identified or identifiable natural person, even by matching with other data. |
Law | : | Refers to the Law No. 6698 on the Protection of Personal Data. |
KVK Board | : | Personal Data Protection Board. |
This Policy, which entered into force on the date of publication by the Company, shall be published on the Company website (www.ferah.com) and made available to the relevant persons upon the request of Personal Data Owners.
Personal Data is processed by the Company in accordance with the procedures and principles stipulated in the Law and this Policy. The Company acts in accordance with the following principles while processing Personal Data:
The Company shall not process Personal Data without the explicit consent of the data owner. Personal Data can be processed “without seeking for the explicit consent of the data owner” in the event of the presence of one of the following conditions.
The Company shall not process Private Personal Data without the explicit consent of the concerned. However, Personal Data other than health and sexual life may be processed without the explicit consent of the relevant person in cases stipulated by the law. Personal Data on health and sexual life shall only be processed by the Company for the purpose of protecting public health, conducting preventive medicine, medical diagnosis and treatment and care services, health services, and planning and management of their financing, without seeking the explicit consent of the relevant person under conditions where we are under the obligation to keep confidential. The Company carries out the necessary actions to take adequate measures determined by the Board for the processing of Private Personal Data.
Our Company may transfer Personal Data of Personal Data Owners and Private Personal Data to third parties in accordance with the Law by establishing the necessary privacy conditions and taking security measures in line with the purposes of processing Personal Data. Our Company acts in accordance with the regulations stipulated in the Law during the transfer of Personal Data. In this context, our Company may transfer Personal Data to third parties, based on one or more of the following Personal Data processing conditions specified in Article 5 of the Law and in a limited manner, in line with legitimate and lawful Personal Data processing purposes:
Our Company does not transfer the Personal Data and Private Personal Data of Personal Data Owners to third parties abroad for the purposes of processing Personal Data. The situation in the context of future projects regarding this is mentioned in 2.5.1 in the context of both Personal Data and Private Personal Data.
The Company may transfer the Private Personal Data of Personal Data Owner to third parties in the following cases, in line with the legitimate and lawful Personal Data processing purposes, by showing the necessary care, taking the necessary security measures and taking the adequate precautions stipulated by the KVK Board:
(i) If the Personal Data Owner gives explicit consent, or
(ii) Without seeking the explicit consent of the Personal Data Owner in the presence of the following conditions;
Our Company does not transfer any of the personal data it has processed abroad for now. However, as required by the projects it will take in the future, the Company may transfer the Private Personal Data of the Personal Data Owner to foreign countries where the data officer has adequate protection or undertakes sufficient protection in the following cases, in line with the legitimate and lawful purposes of Personal Data processing, by making the relevant changes in accordance with the KVK Law and the Board decisions, showing the necessary care, taking the necessary security measures and taking the adequate precautions stipulated by the KVK Board:
(i) If the Personal Data Owner gives explicit consent, or
(ii) Without seeking the explicit consent of the Personal Data Owner in the presence of the following conditions;
PERSONAL DATA CATEGORIZATION | DESCRIPTION OF PERSONAL DATA CATEGORIZATION |
Identity Data | Data that clearly belongs to an identified or identifiable real person, is processed partially or fully automatically, or non-automatically as part of the data recording system and contains information about the identity of the person; documents such as the driver’s license, identity card and passport containing the name and surname, national ID number, nationality information, mother’s and father’s name, place of birth, date of birth, and gender, and tax ID number, SSI number, signature information, vehicle plate, etc. information. |
Communication Data | Information such as phone number, address, e-mail address, fax number, and IP address that clearly belongs to an identified or identifiable real person, is processed partially or fully automatically, or non-automatically as part of the data recording system. |
Location Data | Data such as GPS location, travel data, etc. that clearly belongs to an identified or identifiable real person, is processed partially or fully automatically, or non-automatically as part of the data recording system and determines the location of the Personal Data Owner during the use of the products and services of the group companies within the frame of the operations carried out by the business units of the Company or the employees of the institutions the Company cooperates with while using the Company vehicles. |
Transaction Security Data | Personal data processed regarding the technical, administrative, legal and commercial security of both the Personal Data Owner and the Company while carrying out the activities of the Company. For example, IP address information, Internet site login and exit information, Password information, etc. |
Data on Family Members and Relatives | Data that clearly belongs to an identified or identifiable real person, is processed partially or fully automatically, or non-automatically as part of the data recording system, and is about the family members (e.g. spouse, mother, father, children) and relatives of the Personal Data Owner, and other persons who can be accessed in case of emergency in order to protect the legal and other interests of the Company and the Personal Data Owner regarding the products and services offered by the group companies within the frame of the operations carried out by the business units of the Company. |
Data on Physical Space Security | Data such as camera records, fingerprint records and records taken at the security point, etc. that clearly belongs to an identified or identifiable real person, is processed partially or fully automatically, or non-automatically as part of the data recording system, is related to the records and documents received during the entrance to the physical space and the stay in the physical space. |
Financial Data | Data that clearly belongs to an identified or identifiable real person, is processed partially or fully automatically, or non-automatically as part of the data recording system, and is processed in relation to data, documents and records showing all kinds of financial results created according to the type of legal relationship established with the Personal Data Owner, and data such as bank account number, IBAN number, credit card information, financial profile, assets data, and income data. |
Audio/Visual Data | Data that clearly belongs to an identified or identifiable real person, and is contained in photo and camera recordings (excluding the records included within the scope of Physical Space Security Data), audio recordings and papers that are copies of documents containing personal data. |
Personal Data | Any data that clearly belongs to an identified or identifiable real person, is processed partially or fully automatically, or non-automatically as part of the data recording system, and is processed to obtain information that will be the basis for the personal rights of real persons who have an employment relationship with the Company. |
Legal Transaction Data | Data processed within the scope of the determination and follow-up of the legal receivables and rights of the Company, payment of its debts and its legal obligations. |
Risk Management | Information processed for the management of commercial, technical and administrative risks, etc. |
Private Personal Data | Data that clearly belongs to an identified or identifiable real person, is processed partially or fully automatically, or non-automatically as part of the data recording system, and specified in Article 6 of the Law (e.g. health data including blood type, biometric data, religion and membership association data). |
Demand/Complaint Management Data | Data that clearly belongs to an identified or identifiable real person, is processed partially or fully automatically, or non-automatically as part of the data recording system, and is related to the receipt and evaluation of any request or complaint directed to the Company. |
Personal data in the following categories are processed within the Company by informing the relevant persons in accordance with Article 10 of the Law, complying with the general principles specified in the Law, especially the principles specified in Article 4 regarding the processing of personal data and all obligations regulated in the Law, and limited to the subjects within the scope of this Policy, based on one or more of the personal data processing conditions specified in Article 5 of the Law and in a limited manner, in line with the legitimate and legal personal data processing purposes of the Company. It is also stated in this part which data owners the personal data processed in these categories are related to.
The type of Personal Data of the Personal Data Owners specified in article (1.3.) of Part 1 of the Policy is specified as follows:
Data Category – Data Subject Person Group
,
1-Identity |
|
2-Communication |
|
3-Location |
|
4-Personal Information |
|
5-Legal Action |
|
6-Customer Transaction |
|
7-Physical Space Security |
|
8-Transaction Security |
|
11-Professional Experience |
|
12-Marketing |
|
13-Visual and Audio Records |
|
21-Health Information |
|
23-Criminal Convictions and Security Measures |
|
24-Biometric Data |
|
Personal Data is processed within the scope of the personal data processing conditions specified in Articles 5 and 6 of the Law in accordance with the law and the purpose of the Law, limited to the following purposes of the Company:
If the processing activity carried out for the afore-mentioned purposes does not meet any of the conditions stipulated under the Law, your explicit consent shall be obtained by the Company regarding the relevant processing process.
Your Personal Data can be transferred to the following categories of persons managed by the Policy in accordance with the law and the purpose of the Law for the following purposes:
Persons to whom Data can be Transferred | Purpose of Data Transfer |
Legally Authorized Public Institutions and Organizations, Shareholders, Internal Audit Company, | It can be transferred in a limited manner for the purpose requested by the relevant public institutions and organizations, shareholders, and internal audit company within their legal authority. |
Legally Authorized Private Law Persons | It can be transferred in a limited manner for the purpose requested by the relevant private law persons, such as banks, within the scope of their legal authority in accordance with the provisions of the legislation. |
Personal Data is collected in order to fulfill the responsibilities arising from the law completely and accurately within the framework of legislation, contract, demand and legal reasons, in order to realize the purposes stated in the Policy through various means such as call center, Company website and mobile applications via technical and other methods in all kinds of verbal, written and electronic media for the purpose of controlling compliance with Article 1 regulating the purpose of the Law and Article 2 regulating the scope of the Law, and is processed by the Company or data processors appointed by the Company.
Provided that the provisions of other laws regarding the deletion, destruction or anonymization of Personal Data are reserved, the Company deletes, destroys or anonymizes the Personal Data, either sua sponte or upon the request of the data owner, although it has processed them in accordance with the provisions of this Law and other laws. With deletion of Personal Data, these data are destroyed in a way that they cannot be used and retrieved in any way. Accordingly, Personal Data is deleted from the tools such as documents, files, CDs, floppy disks, hard disks, etc. in which they are recorded in a way that cannot be retrieved. Destruction of Personal Data, on the other hand, means the destruction of materials suitable for data storage such as documents, files, CDs, floppy disks, hard disks, etc. in which the data is recorded, so that the information cannot be retrieved and used. Anonymization of the data means making the Personal Data not to be associated with an identified or identifiable real person even if it is matched with other data.
The Company stores Personal Data for the period specified in this legislation, in case it is stipulated in the legislation. If a period is not regulated in the legislation regarding how long the personal data should be stored, Personal Data are processed for a period that requires processing in accordance with the Company’s practices and commercial life customs, depending on the activity carried out by the Company while processing that data, then they are deleted, destroyed or anonymized.
If the purpose of processing personal data has expired and the storage periods determined by the relevant legislation and the Company have come to an end, Personal data can only be stored in order to provide evidence in possible legal disputes or to assert the relevant right regarding the personal data or to establish a defense. For the establishment of the periods here, the storage periods are determined based on the time-out periods for the claiming of such right, and the examples in the requests made to the Company on the same issues before although the time-out periods have passed. In this case, the stored personal data is not accessed for any other purpose, but only accessed when it is required to be used in the relevant legal dispute. Here too, after the aforementioned period expires, personal data is deleted, destroyed or anonymized.
In accordance with Article 12 of the Law, the Company takes the necessary technical and administrative measures for providing the appropriate security level in order to prevent illegal processing of Personal Data it processes, prevent illegal access to the data and ensure the maintenance of data, and carries out the necessary audits within this scope or has them carried out.
The Company takes technical and administrative measures according to technological facilities and cost of implementation to ensure that Personal Data is processed in accordance with the law.
(i) Technical Measures Taken to Ensure the Legal Processing of Personal Data
Main technical measures taken by the Company to ensure the legal processing of Personal Data are listed below:
(ii) Administrative Measures Taken to Ensure the Legal Processing of Personal Data
Main Administrative Measures taken by the Company to ensure the legal processing of Personal Data are listed below:
The Company takes technical and administrative measures according to the nature of data to be protected, technological facilities and implementation cost to prevent the imprudent or unauthorized disclosure, access, transfer or other illegal access of Personal Data.
(i) Technical Measures Taken to Prevent Illegal Access to Personal Data
Main technical measures taken by the Company to prevent illegal access to Personal Data are listed below:
(i) Administrative Measures Taken to Prevent Illegal Access to Personal Data
Main administrative measures taken by the Company to prevent illegal access to Personal Data are listed below:
The Company takes the necessary technical and administrative measures according to technological facilities and cost of implementation to store Personal Data in safe environments and to prevent it to be destroyed, lost or altered with illegal purposes.
(i) Technical Measures Taken for the Storage of Personal Data in Safe Environments
The main technical measures taken by the Company for the storage of Personal Data in safe environments are listed below:
(ii) Administrative Measures Taken for the Storage of Personal Data in Safe Environments
The main administrative measures taken by the Company for the storage of Personal Data in safe environments are listed below:
The Company performs or have the necessary inspections been performed within itself in accordance with Article 12 of the Law. The results of these results are reported to the relevant department within the scope of the internal operation of the Company and necessary activities are carried out to improve the measures taken.
In case Personal Data processed in accordance with Article 12 of the Law is obtained illegally by others, the Company manages the system that enables the relevant Personal Data Owner and the KVK Board to be notified of this issue as soon as possible. If deemed necessary by the KVK Board, this may be announced on the website of the KVK Board or by any other method.
The Company protects all legal rights of Personal Data Owners with the implementation of the Policy and the Law and takes all necessary measures to protect these rights. Detailed information about the rights of Personal Data Owners is given in the sixth part of this Policy.
The Law attaches special importance to certain Personal Data due to the risk of causing the victimization and/or discrimination of persons when processed illegally. These data are data with respect to race, ethnicity, political thought, philosophical belief, religion, sect or other beliefs, appearance, association, foundation or trade union membership, health, sexual life, criminal conviction and security measures, and biometric and genetic data. The Company pays utmost attention to the protection of private Personal Data determined as “private” by the law and processed in accordance with the law. In this context, the technical and administrative measures taken by the Company for the protection of Personal Data are applied with the utmost care in terms of Private Personal Data and the necessary audits are provided within the Company on this issue.
The Company enlightens Personal Data Owners during the acquisition of Personal Data, in accordance with Article 10 of the Law. In this context, it enlightens about the identity of the Company representative, if any, the purpose for which Personal Data will be processed, to whom and for what purpose the processed Personal Data can be transferred, the method of Personal Data collection and its legal basis, and the rights of the Personal Data Owner.
The Company informs you of your rights in accordance with Article 10 of the Law, provides guidance on how to exercise these rights and carries out the necessary internal functioning, administrative and technical regulations for all of these. In accordance with Article 11 of the Law, the Company enlightens the persons, whose Personal Data is collected, on their rights about;
As the following cases are excluded from the scope of the Law in accordance with Article 28 of the Law, Personal Data Owners cannot claim their rights listed in Article (6.2.) of this Policy in the following cases:
Pursuant to Article 28/2 of the Law, Personal Data Owners cannot claim their rights listed in Article (6.2.) of this Policy, except for the right to demand compensation, in the following cases:
Personal Data Owners may submit their requests regarding their rights listed in Article (6.2.) of this Policy to the Company free of charge by filling and signing the following Application Form with the information and documents that will identify their identities and with the methods specified below or by other methods determined by the KVK Board:
(i) Submission of a copy of the application form with wet signature to the (current address will be written) by hand or through a notary public after it is filled,
(ii) Filling out the application form and sending the secure electronically signed form to [email protected] by registered e-mail after you sign with your “secure electronic signature” within the scope of Electronic Signature Law No. 5070.
In order for the third parties to make an application request on behalf of the personal data owners, there must be a special power of attorney issued by the data owner through a notary public on behalf of the applicant.
The Company finalizes the requests in the application free of charge, within thirty days at the latest, depending on the nature of the request. However, if such procedure requires a cost, the fee in the tariff determined by the KVK Board may be charged. The Company can either accept the request or refuse it by giving the reason, and notifies its response in writing or electronically. If the request in the application is accepted, the Company fulfills the request.
In case the application is refused, the response is found insufficient or the application is not responded on time, the data owner has the right to make a complaint to the KVK Board within thirty days from the date of learning the response, and in any case within sixty days from the date of application.
A Personal Data Committee has been established within the Company in accordance with the decision of the Company’s senior management to manage this Policy and other policies related to and in association with this Policy. Personal Data Committee is authorized and in charge of carrying out the necessary procedures for the storage and processing of the data of Personal Data Owners in accordance with the law, this Policy and other policies related to and in association with this Policy.
The Company reserves the right to make amendments to this Policy and other policies related to and in association with this Policy in accordance with the decisions of the KVK Board or in line with the developments in the sector or data processing field due to the amendments to the Law.
The amendments to this Policy are immediately entered into the text and explanations regarding the amendments are described at the end of the Policy.
Policy on Processing and Protection of Personal Data was published on 15.06.2020. There are no previous amendments.
We, FERAH KONFEKSIYON SAN.VE TUR TIC.A.S.(the “Company”), attach importance to the processing and protection of all personal data belonging to all persons in relation to the Company, including those who benefit from our products and services, in accordance with the Law No. 6698 on Protection of Personal Data (“KVK Law”). As Data Officer, we process your personal data as explained below and within the limits prescribed by legislation.
Personal Data is processed in accordance with the law and the purpose of the Law under personal data processing conditions specified in Articles 5 and 6 of the Law limited to the purposes of correct planning, execution and management of the Company’s human resources policies, commercial partnerships, management and communication activities and strategies, making the best use of its products and services by Personal Data Owners and making them private for their demands, needs and requests, providing the highest level of data security, improving the services offered on the website and eliminating the errors on the website, communicating with the Personal Data Owners who communicated their requests and complaints, and providing the management of requests and complaints, event management, providing information to the authorized organizations based on the legislation, and creating and tracking visitor records, and within the scope of the personal data transfer conditions specified in Articles 8 and 9 of the Law, it is acquired by the Company partners-business partners, successors and / or third parties / organizations determined by them, or shared with them, recorded and transferred to their electronic systems. If the processing activity carried out for the afore-mentioned purposes does not meet any of the conditions stipulated under the Law, your explicit consent is obtained by the Company regarding the relevant processing process.
Personal Data is collected in order to fulfill the responsibilities arising from the law completely and accurately within the framework of legislation, contract, demand and legal reasons, in order to realize the purposes stated in the Policy through various means such as call center, Company website and mobile applications via technical and other methods in all kinds of verbal, written and electronic media for the purpose of controlling compliance with Article 1 regulating the purpose of the Law and Article 2regulating the scope of the Law, and is processed by the Company or data processors appointed by the Company.
The Company informs you of your rights in accordance with Article 10 of the Law, provides guidance on how to exercise these rights and carries out the necessary internal functioning, administrative and technical regulations for all of these. In accordance with Article 11 of the Law, the Company enlightens the persons, whose Personal Data is collected, about their rights to learn whether their Personal Data is processed, to request information if their Personal Data has been processed, to learn the purpose of processing Personal Data and whether they are used in accordance with their purpose, to know the third parties to whom Personal Data is transferred at home or abroad, to request the correction of Personal Data in case they were incompletely or incorrectly processed, to request the deletion or destruction of Personal Data within the framework of the conditions stipulated in Article 7 of the Law, to request the notification of the transactions carried out pursuant to sub-paragraphs (d) and (e) of Article 11 of the Law to the third parties to whom personal data is transferred, to object to the occurrence of a result against the person himself/herself by analyzing the processed data exclusively through automated systems, and to claim compensation in case of loss due to the illegal processing of personal data.
Personal Data Owners may submit their requests regarding their rights to the Company free of charge by filling and signing the Application Form, which can be accessed from the link below, with the information and documents that will identify their identity and the methods specified below or by other methods determined by the KVK Board:
(i) Submission of a copy of the application form with wet signature to Turgut Özal Mah. 68 Sok. No:42/B 34513 Esenyut / Istanbul by hand or through a notary public after it is filled,
(ii) Filling out the application form and sending the secure electronically signed form to [email protected] by registered e-mail after you sign with your secure electronic signature within the scope of Electronic Signature Law No. 5070.
(iii) They may submit their requests to the Company free of charge by filling and signing the following Application Form with the information and documents that will identify their identity and by the methods specified below or by other methods determined by the KVK Board: Submission of a copy of the application form with wet signature to Turgut Özal Mah. 68 Sok. No:42/B 34513 Esenyut / Istanbul by hand or through a notary public after it is filled, Filling out the application form and sending the secure electronically signed form to [email protected] by registered e-mail after you sign with your secure electronic signature within the scope of Electronic Signature Law No. 5070.
In order for the third parties to make an application request on behalf of the personal data owners, there must be a special power of attorney issued by the data owner through a notary public on behalf of the applicant.