Personal Data Storage and Destruction Policy

Personal Data Storage and Destruction Policy

CARPEX KURUMSAL HİJYEN ÇÖZÜMLERİ TİC. A.Ş. 
PERSONAL DATA STORAGE, DESTRUCTION AND ANONYMIZATION POLICY 

1.PURPOSE AND SCOPE 

The Personal Data Storage and Destruction Policy (“Policy”) has been prepared to determine the procedures and principles regarding the storage and destruction activities carried out by Carpex Kurumsal Hijyen Çözümleri Tic. A.Ş. (referred to as “Carpex Kurumsal” or “Company”). As a Company, our fundamental principle is the processing of personal data belonging to product or service recipients, employees, employee candidates, service providers, visitors, and other third parties in accordance with the Constitution of the Republic of Turkey, International Conventions, the Law on the Protection of Personal Data No. 6698 (“Law”), and other relevant legislation.

In this context, it has been prioritized to ensure that relevant persons do not suffer loss of rights and can exercise their rights effectively. This Policy has been prepared in compliance with the Law No. 6698, the Regulation on the Deletion, Destruction or Anonymization of Personal Data (“Regulation”) published in the Official Gazette dated 28.10.2017 and numbered 30224, and other legislative provisions.

2.DEFINITIONS 

Term

Definition

Recipient Group

The category of natural or legal persons to whom personal data is transferred by the data controller.

Explicit Consent

Consent regarding a specific subject, based on information and expressed with free will.

Anonymization

Making personal data impossible to associate with an identified or identifiable natural person under any circumstances, even by matching it with other data.

Employee

Carpex Kurumsal personnel.

Electronic Media

Environments where personal data can be created, read, changed, and written with electronic devices.

Non-Electronic Media

All written, printed, visual, etc. media other than electronic media.

Service Provider

Natural or legal person providing services to the Personal Data Protection Authority within the framework of a specific contract.

Data Subject (Relevant Person)

The natural person whose personal data is processed.

Relevant User

Persons who process personal data within the organization of the data controller or in accordance with the authority and instructions received from the data controller, excluding the person or unit responsible for technical storage, protection, and backup of the data.

Destruction

Deletion, destruction, or anonymization of personal data.

Law

Personal Data Protection Law No. 6698.

Recording Medium

Any environment where personal data is processed by fully or partially automated means or by non-automated means provided that it is part of any data recording system.

Personal Data

Any information that makes a person identified or identifiable.

Personal Data Processing Inventory

An inventory in which data controllers detail their personal data processing activities based on business processes, associating them with the purposes and legal reasons for processing, data category, transferred recipient group, and data subject group, and explaining the maximum retention period required for the purposes for which personal data are processed, personal data envisaged to be transferred to foreign countries, and the measures taken regarding data security.

Processing of Personal Data

Any operation performed on data such as obtaining, recording, storing, preserving, changing, reorganizing, explaining, transferring, taking over, making available, classifying, or preventing the use of personal data by fully or partially automated means or by non-automated means provided that it is part of any data recording system.

Board

Personal Data Protection Board.

Special Categories of Personal Data

Data regarding race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, dress and appearance, membership to associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data.

Periodic Destruction

The process of deletion, destruction, or anonymization to be carried out ex officio at repeated intervals specified in the personal data storage and destruction policy in case all the conditions for processing personal data in the Law disappear.

Policy

Personal Data Storage and Destruction Policy.

Data Processor

Natural or legal person processing personal data on behalf of the data controller based on the authority granted by the data controller.

Data Recording System

The recording system where personal data are structured and processed according to specific criteria.

Data Controller

Natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.

Data Controllers Registry Information System

The information system created and managed by the Presidency, accessible via the internet, which data controllers will use for application to the Registry and other relevant transactions.

VERBİS

Data Controllers Registry Information System.

Regulation

The Regulation on the Deletion, Destruction or Anonymization of Personal Data published in the Official Gazette dated October 28, 2017.

3. RECORDING MEDIA 

Personal data stored by Carpex Kurumsal is recorded in the environments shown in the table below and is kept in the most appropriate recording medium according to its nature and legal status.

Data Recording Medium

Description

Electronic Media

Servers (Domain, backup, e-mail, database, web, file sharing, file server, etc.), Disk Units, Software (Office software, Intranet Portal, ERP software, “Netsis”, etc.), Information security devices (Firewall, intrusion detection and prevention, log files, anti-virus, etc.), Company computers (Desktop, laptop), Company-owned mobile devices (Phone, tablet, etc.), Optical disks (CD, DVD, etc.), Removable memories (USB, memory card, etc.)

Non-Electronic Media

Paper, Manual data recording systems (Notebooks, printed forms), Written, printed, visual media

4. RESPONSIBILITY AND DISTRIBUTION OF DUTIES 

Pursuant to Article 6, paragraph (f) of the Regulation, the titles, duties, and units of the persons involved in the storage and destruction processes of personal data are specified below.

Title

Job Description

Personal Data Manager

Responsible for directing all kinds of planning, analysis, research, and risk identification studies in projects carried out during the Law compliance process; managing the processes that must be carried out in accordance with the Law, the Personal Data Processing and Protection Policy, the Personal Data Storage and Destruction Policy, and other regulated policies and procedures; and deciding on and responding to requests from relevant persons.

Carpex Kurumsal Personal Data Protection Specialist (Technical and Administrative)

Responsible for examining the requests of relevant persons and reporting them to the Personal Data Manager for evaluation; performing the transactions regarding the requests of relevant persons evaluated and decided by the Personal Data Manager in accordance with the decision of the Personal Data Manager; auditing the storage and destruction processes and reporting these audits to the Personal Data Manager; and carrying out the storage and destruction processes.

Human Resources Manager

Responsible for the execution and audit of policies and procedures in terms of personnel in accordance with job descriptions, and for audits regarding the protection, storage, and destruction of personal data.

5. EXPLANATIONS REGARDING STORAGE AND DESTRUCTION 

Personal data belonging to the persons served within the Company are processed in accordance with the matters specified by the Law and stored in the recording media specified in this policy, and are also destroyed in the manner specified in this policy.
In addition, our company stores and destroys personal data regarding its personnel. Personal data are stored based on one or more of the processing conditions specified in Articles 5 and 6 of the Law, and in this context, personal data are stored during the validity of the conditions specified for processing. When the said processing conditions end or upon the application of the relevant person to our Company (after checking other legal obligations that our Company must comply with), the personal data being stored are deleted, destroyed, or anonymized upon request.
Legal Reasons Requiring Storage 
Personal data processed within the framework of the Company's activities are stored for the period stipulated in the relevant legislation. In this context, personal data are stored for the periods provided under:
-Labor Law No. 4857 
-Turkish Commercial Code No. 6102 
-Turkish Code of Obligations No. 6098 
-Vocational Education Law No. 3308 
-Occupational Health and Safety Law No. 6331 
-Personal Data Protection Law No. 6698 
-Tax Procedure Law No. 213 
-Social Insurance and General Health Insurance Law No. 5510 
- Industrial Property Law No. 6769 
-Customs Law No. 4458 
-Law No. 3577 on the Prevention of Unfair Competition in Imports 
-Regulation on Occupational Health and Safety Services 
-Other secondary regulations in force pursuant to these laws.

Processing Purposes Requiring Storage 
The Company stores personal data for specific purposes. These purposes include, but are not limited to:
-Emergency Management 
-Information Security 
-Recruitment/Intern Selection 
-Fulfillment of Employment Contract & Legal Obligations 
-Finance and Accounting 
-Physical Space Security 
-Legal Affairs Tracking 
-Occupational Health and Safety 
-Logistics and Supply Chain Management 
-Sales and After-Sales Support 
-Marketing and Advertising 
-Visitor Records 

Reasons Requiring Destruction 
Personal data shall be deleted, destroyed, or anonymized by the Company upon the request of the relevant person or ex officio in the following cases:
-Amendment or abolition of the relevant legislation serving as the basis for processing.
-Disappearance of the purpose requiring processing or storage.
-Withdrawal of explicit consent by the relevant person where processing is based solely on that consent.
-Acceptance by the Company of the application made by the relevant person for the deletion/destruction of data.
-The maximum storage period has expired and no conditions exist to justify longer storage.

6. TECHNICAL AND ADMINISTRATIVE MEASURES 

Carpex Kurumsal takes all necessary technical and administrative measures appropriate to the nature of the personal data and the environment in which it is kept to ensure secure storage and prevent unlawful processing/access.

6.1 Technical Measures 
-An authorization matrix has been created for employees.
-Authorizations of employees who change roles or leave the job are removed.
-Up-to-date anti-virus systems and firewalls are used.
- Physical security measures are taken for environments containing personal data.
-Log records are kept in a way that prevents user intervention.

6.2 Administrative Measures 
-Disciplinary regulations containing data security provisions are in place.
-Training and awareness studies are conducted for employees.
-Corporate policies on access, security, usage, storage, and destruction have been implemented.
-Confidentiality agreements and undertakings are signed.
- Personal data is reduced as much as possible.


7. PERSONAL DATA DESTRUCTION TECHNIQUES 

Personal data is deleted, destroyed, or anonymized ex officio or upon request when processing reasons disappear.
7.1 Deletion Methods 

Method

Description

Blacking Out (Physical)

Cutting out data from documents or making it invisible with permanent ink.

Secure Software Deletion

Deletion via digital command so that only the database manager can access it, making it unusable.

Removal of Access Rights

Removing user access rights from servers by the system administrator.

7.2 Destruction Methods 

Method

Description

Physical Destruction

Using paper shredders for physical documents; melting, burning, or pulverizing optical/magnetic media.

Degaussing

Corrupting data on magnetic media by exposing it to a high magnetic field.

Overwriting

Writing random data (0s and 1s) at least seven times on rewriteable media.

Cloud Destruction

Deleting via digital command and destroying encryption keys upon termination of the cloud service relationship.

7.3 Anonymization Methods 

Method

Description

Variable Extraction

Removing direct identifiers that could identify the person.

Generalization

Aggregating data into statistical values, removing distinguishing details.

Masking

Making data unintelligible (encryption, symbols, blurring) without changing the format.

Data Shuffling

Mixing or corrupting identifiers to break the link with the relevant person.

8. STORAGE AND DESTRUCTION PERIODS 

Regarding the personal data processed by Carpex Kurumsal within the scope of its activities;
-Retention periods for all personal data within the scope of activities carried out depending on the processes are specified on a personal data basis in the Carpex Kurumsal Personal Data Processing Inventory;
-Retention periods based on data categories are specified in the VERBIS registration;
-Retention periods based on processes are specified in the Personal Data Retention and Destruction Policy.Updates to the aforementioned retention periods are made by Carpex Kurumsal as deemed necessary.
 

8.1 Storage and Disposal 

PROCESS

STORAGE PERIOD

DESTRUCTION PERIOD

Human Resources Processes

10 years following the end of activity

First periodic destruction period following storage expiry

OHS Personal Health Files

15 years following resignation

First periodic destruction period following storage expiry

Log Records Systems

10 years following the end of activity

First periodic destruction period following storage expiry

Internet Access Records

2 years following the end of relationship

First periodic destruction period following storage expiry

Visitor Records

1 year following the record

First periodic destruction period following storage expiry

Camera Recordings

2 Months

Destroyed on the first day following the storage period

Contracts Execution

10 years following the end of contract

First periodic destruction period following storage expiry

8.2 Data Destruction Periods 
If the relevant person requests destruction:
-If all processing conditions have disappeared, the request is finalized within 30 days.
-If conditions have not disappeared, the request may be rejected with a reasoned explanation within 30 days.


9. PERIODIC DESTRUCTION PERIOD 

Periodic destruction processes begin on [Date] and repeat every 6 (six) months.

10. PUBLICATION, STORAGE, AND UPDATING 

The Policy is published in both physical (wet-signed) and electronic formats and is disclosed to the public on the Company's website. It is reviewed and updated as needed.

11. COMPLIANCE AND AMENDMENTS 

The Company reserves the right to make changes to the policy due to legislative requirements or company policy. Date of Publication: ../../....