Personal Data Retention and Destruction Policy

Icon

This book ([1]) contains the principles of the Personal Data Retention and Destruction Policy (PDR Policy) belonging to the DATA CONTROLLER specified in the table below, for its workplaces and operations:

DATA CONTROLLER COMPANY / PERSON

DATA CONTROLLER COMPANY / PERSON

MERSIS NO

TAX OFFICE / NO

ADDRESS

PHONE

E-MAIL

CEYLAN İŞLETME TURİZM YATIRIM NAKLİYAT GIDA İÇECEK SANAYİ VE TİCARET ANONİM ŞİRKETİ

0208040029700013

Antalya Corporate Tax-2080400297

Kemerağzı Mah. Yaşar Subutay Blvd. No:48 Aksu/ANTALYA

02423522755

CEYLANER TURİZM MADENCİLİK İNŞAAT MATERIALS TRANSPORTATION AGRICULTURE LIVE ANIMALS COMPUTER AND SOFTWARE TRADE INDUSTRY INC.

0209017207900018

Antalya Corporate Tax-2090172079

Kemerağzı Mah. Yaşar Subutay Blvd. Sherwood Hotel Site No:364/1 Aksu/ANTALYA

02423522755

KARDELEN TOURISM SERVICES MARKETING INDUSTRY TRADE CONSTRUCTION IMPORT AND EXPORT INC.

0523006302500028

Antalya Corporate Tax-5230063025

Kemezağzı Mah. 32017 St. P Block Apt. No:34 P/3 Aksu/ANTALYA

02423522755

ABC BEVERAGE FOOD TRANSPORTATION MARKETING INDUSTRY AND TRADE INC.

0207053809300018

Antalya Corporate Tax-2070538093

Kemerağzı Mah. Yaşar Subutay Blvd. Sherwood Hotel Site No:364/1 Aksu/ANTALYA

02423522755

KARPAK TEXTILE WASHING SERVICES LOGISTICS IMPORT EXPORT INDUSTRY TRADE INC.

0524148379000001

Antalya Corporate Tax-5241483790

Fener Mah. Tekelioğlu Cd. No:90A/1 Muratpaşa/ANTALYA

02423522755

BASIS, PURPOSE AND SCOPE

BASIS

This policy is based on Article 7/3(f) and Article 22/1(e) of the Turkish Personal Data Protection Law No. 6698 and the Regulation on Deletion, Destruction or Anonymization of Personal Data published in the Official Gazette dated 28.10.2017 No. 30224.

PURPOSE

The purpose of this policy is to define the procedures, principles, responsibilities and obligations regarding the deletion, destruction or anonymization of personal data after processing, in compliance with KVKK and other applicable national and international regulations.

SCOPE

This policy applies to all individuals, institutions, partners, employees, suppliers and all third parties with whom the DATA CONTROLLER interacts, and covers all personal data processing activities, legal, commercial and financial relationships, and data retention and destruction processes.

TERMS AND DEFINITIONS

Includes definitions of GDPR, consent, anonymization, deletion, destruction, personal data, processing, data controller, data processor, VERBIS, etc.

DELETION, DESTRUCTION OR ANONYMIZATION OF PERSONAL DATA

General

Personal data whose processing purposes have ceased are deleted, destroyed or anonymized in accordance with this policy and applicable legislation.

Processing Before KVKK

Personal data processed before the enforcement of KVKK were aligned with the law and consent requirements within the legal transition period.

Processing After KVKK

Data is deleted, destroyed or anonymized when processing conditions cease, in accordance with legal obligations and technical measures.

DELETION METHODS

  • Cloud systems deletion

  • Paper destruction (shredding)

  • Server deletion

  • Mobile media deletion

  • Database deletion

DESTRUCTION METHODS

  • De-magnetization

  • Physical destruction

  • Overwriting

ANONYMIZATION METHODS

  • Removing identifiers

  • Generalization

  • Data swapping

  • Noise addition

COMMON PROVISIONS

This policy is an integral part of the Personal Data Protection Policy and is available to authorized personnel and stakeholders.

[1] All content is protected under Copyright Law No. 5846 and cannot be copied or used without permission.