1. ENTRANCE

KENOBI FOREIGN TRADE LIMITED COMPANY As the (“Company”), we attach importance to the protection of the personal data of our customers who purchase our products and services offered for sale in our Company’s stores and/or through the website named karabatak.com.tr or the Mobile Application; our users and members who use our Company’s Website and Mobile Application and who are members of this Website and Mobile Application; other natural persons who establish a relationship with us by visiting our stores, Website, Mobile Application or through our social media accounts or in any other way; persons who contact us/establish a contract with us personally or as a representative of a company or organization; our business partners, employees and candidate employees who apply for a job with our Company; and we present our principles and policy regarding the processing of personal data within the framework of the Personal Data Protection Law No. 6698 (KVKK).

  1. PURPOSE AND SCOPE

 

Our aim is to determine the necessary management instructions, procedures and conditions to ensure that personal data is processed and protected by the Company in accordance with the KVKK.

  1. PERSONAL DATA 

 

  1. Definition of Personal Data

Personal Data refers to any information relating to identified or identifiable natural persons within the scope of Article 3/I(d) of the KVKK. Anonymous information, anonymized information, and data not associated with a specific person are not considered personal data.

  1. General Principles

Data processing is defined within the framework of Article 3/I(e) of the KVKK and includes any operation that may be performed on personal data, such as obtaining, recording, storing, preserving, altering, rearranging, disclosing, transferring, acquiring, making available, classifying, or preventing the use of personal data, whether fully or partially by automatic means, or non-automated means provided that they are part of any data recording system. In this context, our Company processes personal data within the framework of the following principles. These principles are: (i) compliance with legislation and integrity principles, (ii) being accurate and up-to-date when necessary, (iii) being processed for legitimate purposes, (iv) being relevant to the purpose, (v) being limited and proportionate, and (vi) being retained for the required period.

In this context, your personal and/or sensitive personal data obtained by the Company in written, verbal or electronic media through branches, the Website and all kinds of channels, including but not limited to branches, within the scope of the KVKK and related legislation may be obtained, recorded, stored, kept, modified, shared with third party natural or legal persons at home and abroad and processed by other methods deemed appropriate by the Company for legal and statutory reasons or in line with the legal and actual requirements of product sales and services provided.

  1.  Data Processed by the Company 

 

  1. Generally

The Company may process personal data with the explicit consent of the data subject or without explicit consent in the cases stipulated in Articles 5 and 6 of the KVKK. In this context, if: a) It is expressly provided for by law. b) It is necessary for the protection of the life or physical integrity of the person who is unable to give his consent due to a practical impossibility, or whose consent is not legally valid, or of another person. c) The processing of personal data belonging to the parties to a contract is necessary, provided that it is directly related to the establishment or performance of a contract. ç) It is necessary for the data controller to fulfill its legal obligation. d) It is made public by the data subject. e) The processing is necessary for the establishment, exercise, or protection of a right. f) Data may be processed without explicit consent if processing is necessary for the legitimate interests of the data controller, provided that it does not prejudice the fundamental rights and freedoms of the data subject. Similarly, personal data other than those related to health and sexual life may be processed without the explicit consent of the data subject in the cases stipulated by law.

Personal data may be processed by the Company within the scope of the Law on Consumer Protection No. 6502, the Distance Contracts Regulation issued within the scope of this law, the Subscription Agreements Regulation, the Law on the Regulation of Electronic Commerce No. 6563, the Regulation on Service Providers and Intermediary Service Providers in Electronic Commerce prepared based on this law, the Labor Law No. 4857, the Social Security and General Health Insurance Law No. 5510, the Turkish Commercial Code No. 6102, the Tax Procedure Law No. 213, and all other laws, regulations attached to these laws, communiqués and all other legal regulations, and the provisions specified in the relevant legislation.

  1. Other additional data to identify and distinguish the data owner, such as name, surname, profession, CV, gender, marital status, nationality,
  2. In cases where identification is required, data contained in identification documents such as ID, passport, driver's license,
  3. Contact information such as address, telephone, e-mail and fax number and mobile phone number of home, workplace or temporary residence,
  4. Communication records such as telephone conversations with the company, e-mail correspondence, and other audio and video data, complaints and request records
  5. Data used to determine consumer and user habits and Website usage data in order to raise service and product sales standards,
  6. Internet protocol (IP) address, device ID, statistics regarding web page views and mobile and other digital applications, incoming and outgoing traffic information, referral URL, internet log information, location information, information regarding visited sites and transactions and actions performed through our websites and advertising and e-mail content.
  1. Specially

 

In light of other legislation, the personal data that may be processed by the Company in line with the principles set forth in this Policy and the Company's legitimate interests are listed below:

  1.  Data regarding Website and Mobile Application Users and online visitor data: Identity Information (Name, surname), Location Information (User's city, region, etc.), Contact Information (mobile phone, e-mail address, address, etc.), User Information (Membership-related information, etc.), IP address, Transaction Security Information (Password information, etc.), Cookie records, data and evaluations showing user habits and likes, commercial electronic message approval/permission given by users electronically, Membership and User Agreement approved by users, other written texts included on the Website and/or Mobile Application and approved by the user, commercial electronic messages sent within the scope of the approval given by users, records related to the management of request and complaint processes.
  2. Data of the Buyer who purchased the Product offered for sale over the Internet, data subject to the purchase transaction, transaction data regarding sales made at branches, and camera recordings kept for certain periods of time in branches for security reasons.: Identity information of the Buyer, Contact Information (mobile phone, e-mail address, address, etc.), invoice and collection information, type of the purchased Product, quantity, price, order date, data of the person purchasing the Product, discount coupons used during shopping, campaigns, if any; commercial electronic message permission given by the Buyer electronically, the Distance Selling Agreement and Preliminary Information Form approved by the Buyer, other written texts approved by the Buyer, commercial electronic messages sent within the scope of the Buyer's approval, records related to the management of request and complaint processes, IP address, password, passcode information, security camera records kept for certain periods for security purposes within the scope of the services offered in branches, data on the workplace copy of the slip if the purchase made in branches is made by credit card.

iii. Data regarding suppliers, other companies with which contracts have been signed, company officials and employees: Information such as name, surname, Turkish ID Number, telephone number, e-mail address, etc. of the authorized persons and/or employees of the suppliers or contracted companies, if necessary.   

 

  1. Employee / Job Applicant candidate data:Identity Information (Name, surname, date of birth, gender, Turkish ID number), Contact Information (mobile phone, e-mail address, address, etc.), educational background, employment history, CV information
  1. Purposes of Processing Personal Data 

 

The Company may process personal data for the following purposes and retain it for the period required for these purposes and, in any case, for the period required by legal legislation:

  1. Fulfilling all legal and administrative obligations,
  2. Negotiation, establishment and execution of contracts that have been concluded/are planned to be concluded,
  3. Processing data regarding online visitors within the scope of other legislation,
  1. Carrying out membership transactions via the Website/Mobile Application by the Users, creating and editing personal accounts of the Users via the Website and managing membership transactions via the personal account, informing the individuals and users who have consented to commercial electronic messages about campaigns and opportunities or presenting prices, marketing, other opportunities, benefits, offers and information to the customers,
  1. Ability to make purchases regarding products offered for sale via the Website/Mobile Application,
  1. Monitoring purchasing transactions and accounting processes,
  2. Ensuring the security of all websites and other electronic systems, social media accounts and physical environments belonging to the Company,
  1. Promoting and marketing the Company's products and services, and developing them, obtaining the data owner's opinion through surveys and polls,
  2. To organize birthday celebrations, raffles, inclusion in campaigns or competitions, giving gifts and other similar events, promotions and campaigns in favor of the data owner,
  3. Investigating, detecting, preventing and reporting any violations of the contract or the law to the relevant administrative or judicial authorities,
  1. Resolving existing and future legal disputes,
  1. Answering requests and questions, evaluating and resolving complaints
  2. Carrying out corporate and partnership law transactions,
  3. Carrying out recruitment processes within the framework of human resources policies,
  1. Evaluating the suitability of job applications, finalizing them and contacting job applicants,
  2. Data processing is necessary for the establishment, exercise or protection of a right,
  3. To protect the legitimate interests of the Company, provided that it does not harm the fundamental rights and freedoms of the data owner.
  1. Transfer of Personal Data within Türkiye

 

The Company may transfer the personal data obtained to third parties for the purposes specified in this Policy, provided that it complies with the general principles set forth in the KVKK and the conditions stipulated in Articles 8 and 9 of the KVKK, and takes the necessary security measures. The third parties to whom personal data may be transferred may vary depending on the type and nature of the relationship between the data subject and the Company (/user/membership relationship, employment relationship, etc.) and various other factors, but are generally as follows: (i) Company Group Companies; (ii) storage institutions, platform owners, data broadcasting organizations, infrastructure providers, and other business partners, suppliers, and subcontractors with whom the Company works; (iii) all official authorities and institutions; (iv) banks and/or institutions authorized to collect data for collection purposes, organizations with which it works for the conduct of activities related to these purposes, and other relevant third parties.

On the other hand, the data entered by the Mobile Application users is transferred to the software program-service partner from which the Company receives services to carry out its technical activities through the mobile application, by taking the necessary measures to protect the confidentiality of the said data and by complying with the legal principles regarding the processing of personal data; thus, only the information entered into the system by the user through the Mobile Application is stored and processed on the servers of the said company located abroad, without exceeding the legal periods and in compliance with all matters referred to in the Law.

  1. Method of Collection of Personal Data 

The Company may collect personal data in written, verbal, visual, or other physical or electronic formats for the purposes specified in this Policy, in accordance with the conditions set forth in Articles 5 and 6 of the Personal Data Protection Law. Personal data may also be collected through branches, headquarters, and other physical environments belonging to the Company, websites, mobile applications, electronic transaction platforms, social media and other publicly accessible channels, organized events, sales and marketing units, customer forms, digital marketing channels, contracts, applications, forms, offers, and cookies used during website visits.

  1. Storage Period of Personal Data 

Except for cases where longer storage periods are legally required or permitted, the Company stores personal data it has obtained and processed in accordance with the KVKK in line with the purposes set out in this Policy and the Personal Data Storage and Destruction Policy, for the periods specified in the KVKK and other special laws.

If the purpose of processing personal data ceases and the retention periods determined by the Company in accordance with other legislation and the KVKK expire, personal data is retained solely for the purpose of providing evidence in potential legal disputes, asserting and/or establishing a defense for rights related to personal data, or for submission upon request by authorized official authorities. The statute of limitations and retention periods specified in the relevant legislation for asserting the aforementioned right are taken into account in determining these periods. In this case, stored personal data is not accessed for any other purpose and is only accessed when necessary in the relevant legal dispute.

The specified periods are meticulously monitored by the Company, and personal data that is determined to have expired within the above-mentioned retention periods are deleted, destroyed or anonymized by the Company in accordance with the KVKK, as detailed in the Personal Data Storage and Destruction Policy.

  1. Security and Control of Personal Data 

 

Within the framework of Article 12 of the KVKK, the Company, in order to prevent the unlawful processing of personal data and unlawful access to data and to ensure the preservation of personal data,data controller” takes the necessary technical and administrative measures to ensure the appropriate level of security. For this purpose, (i) activities are carried out in accordance with the internal policies and rules prepared for the protection of personal data, (ii) necessary training and responsibilities are provided to employees regarding the personal data protection legislation and the internal policies and rules prepared in this direction, (iii) all necessary declarations and commitments are obtained from employees and persons and institutions processing data on behalf of the Company for the confidentiality and protection of data, (iv) necessary information security measures are implemented to ensure the security of personal data inside and outside the Company and to prevent unauthorized access to data, (v) compliance with the internal policies and rules established for the protection of personal data is ensured, (vi) the adequacy of the measures taken is checked and new data security systems are provided according to the needs and possibilities and/or existing data security systems are developed and updated, and necessary audits are carried out in this regard.

  1.  Measures Taken by the Company Regarding the Protection and Security of Personal Data

Company;

  1. It ensures that all personal data collected is processed in accordance with the principles listed in Article 4 of the KVKK and in compliance with the conditions set out in Articles 5 and 6.
  2. It fulfills the “Information and Clarification Obligation”, which is the obligation of the data controller within the scope of the KVKK, through the Clarification Texts it publishes on the internet and all other relevant platforms.
  3. As the Data Controller, it creates the necessary infrastructure to ensure "explicit consent" for the collection and processing of personal data in accordance with the KVKK, if legally required.
  4. For communication, marketing, opportunity notifications and promotional purposes; it creates the necessary infrastructure for the collection of personal data in accordance with KVKK and makes the necessary revisions in the applications within the Company.
  5. It takes the necessary measures by creating the necessary conditions for the collection and storage of personal data in accordance with KVKK during job applications and recruitment processes.
  6. Personal data processed in accordance with the provisions of the Personal Data Protection Law and other relevant laws will be deleted, destroyed, or anonymized, ex officio or upon the request of the relevant person, in a manner that will prevent any use or recovery, once the reasons requiring processing have ceased and the periods specified in the article titled "Personal Data Retention Periods" of this Policy and the Personal Data Retention and Destruction Policy have expired. To ensure data security, the Company imposes restrictions on internal data access authorizations consistent with the Personal Data Protection Law and carries out the destruction of data deemed necessary.
  7. It takes all technical and administrative measures to prevent the unlawful processing of and access to personal data, and to ensure that personal data is stored in accordance with the Personal Data Protection Law. It develops internal encryption policies and configures existing encryption systems for data security and safekeeping.
  8. It takes the necessary internal measures to prevent data leaks, using company-based applications and externally provided support products.
  9. Determines the legal retention periods in accordance with the relevant legislation, depending on the nature of the data provided, and develops and implements retention policies in accordance with these periods in company practice.
  10. It takes measures to prevent unauthorized access and use of personal data processed and transferred or received as a result of transfer by different departments within the Company and by real or legal persons who process personal data on its behalf based on the authority granted by the Company.
  11. It periodically audits the personal data protection activities carried out by natural or legal persons who process personal data on its behalf based on the authority granted to it.
  12. If, despite the necessary technical and administrative measures being taken regarding the processing, transfer and storage of personal data, third parties have unlawfully accessed personal data, all technical and administrative measures are taken to prevent any harm to the relevant parties in accordance with the relevant legislation on the protection of personal data and the decisions of the Personal Data Protection Law Board.
  13. Periodically monitors and audits whether the data recording systems used within the company are created and used in accordance with the KVKK and relevant legislation.
  1. Data Owner's Rights Within the Framework of KVKK 

Pursuant to Article 11 of the KVKK, data owners:

  1. To learn whether your personal data is being processed,
  2. Requesting information if personal data has been processed,
  3. To learn the purpose of processing personal data and whether they are used in accordance with their purpose,
  4. To know the third parties to whom personal data is transferred, either domestically or abroad,
  5. To request correction of personal data if it is processed incompletely or incorrectly,
  6. Request the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the KVKK,
  7. To request that the transactions made pursuant to clauses (d) and (e) be notified to third parties to whom personal data has been transferred,
  8. To object to the emergence of a detrimental result by analyzing the processed data exclusively through automated systems,
  9. In case of any damage caused by the unlawful processing of personal data, the person has the right to demand compensation for the damage.

If data owners wish to exercise any of their rights mentioned above, they must fill out the application form in the annex of this Policy and submit a signed copy of the form along with information and documents that will identify them, either in person or through a notary public. “Etiler Neighborhood, Aydın Street, No:12, Beşiktaş/Istanbul/Türkiye” If the Personal Data Protection Board decides that the requests should be forwarded by methods other than those specified above, the methods by which the applications can be forwarded will be announced separately.

The Company will evaluate and finalize the requests received from data owners in due form as soon as possible and, in any case, within 30 (thirty) days at the latest, depending on the nature of the request, within the framework of Article 13 of the KVKK.

While requests from data owners will, as a rule, be resolved free of charge, if responding to the request requires an additional cost, a fee may be charged in amounts determined within the framework of the relevant legislation.

  1. COOKIES AND SIMILAR TECHNOLOGIES 

 

When accessing websites, electronic platforms, mobile and digital applications owned by the Company, or email messages or advertisements sent by the Company, the Company may place small data files on users' computers, mobile phones, tablets, or other devices accessed/used that enable the recording and collection of certain data through technical means in order to display personalized content to visitors and engage in online advertising. These data files placed on computers and other devices may include cookies, pixel tags, flash cookies, web beacons, or other similar technologies for data storage. (Briefly, "Cookies") Personal data may also be collected through cookies, and to the extent that the data obtained through cookies constitutes personal data under Turkish law, the Company may process it within the scope of this Policy and the Personal Data Protection Law. The user can remove cookies and reject cookies by rejecting them. If the user rejects cookies, the user can continue to use the website in question, but may not be able to access all of the website's functions or may have limited access. Detailed information about cookies and their use is available in the karabatak.com.tr Cookie Policy.

  1. THIRD-PARTY SITES, PRODUCTS AND SERVICES 

 

The Company's websites, platforms, and applications may contain links to third-party websites and products. These links are subject to the third-party privacy policies, and the third-party websites and third-party websites are independent of the Company, and the Company shall not be responsible for the privacy practices of any third party.

  1. CHANGES 

 

The Company reserves the right to make changes to this Personal Data Protection and Privacy Policy from time to time, in light of the Regulations and other legislation to be issued pursuant to the KVKK, and for other reasons, including, but not limited to, the following. The current version of the Policy will be published on the Company's websites and will be accessible to users and members on the websites.

  1. FORCE

 

This Policy will come into force on the date of publication and will remain in force until it is removed from the website.

ANNEX - COMPANY PERSONAL DATA STORAGE AND DESTRUCTION POLICY

  1.   DEFINITIONS

 

Related UserPersons who process personal data within the data controller organization or in accordance with the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of data.
DestructionIt means deleting, destroying or anonymizing personal data.
Periodic DestructionIt refers to the process of deletion, destruction or anonymization, which will be carried out ex officio at recurring intervals and specified in the personal data storage and destruction policy, in the event that all the processing conditions of personal data specified in the law are eliminated.
Deletion of Personal DataIt is the process of making personal data inaccessible and non-reusable for the relevant users in any way.
Destruction of Personal Data It is the process of making personal data inaccessible, irretrievable and reusable by anyone.
Anonymization of Personal DataIt is the process of making personal data incapable of being associated with an identified or identifiable natural person, even when matched with other data.

 

  1. PURPOSE AND SCOPE OF PERSONAL DATA STORAGE AND DESTRUCTION POLICY

 

The purpose of this Storage and Destruction Policy is to establish management instructions, procedural requirements and a technical policy to ensure that the personal data of the relevant persons are processed, stored and protected by the Company in accordance with the Law on the Protection of Personal Data (“Law” or “KVKK”) and that, despite processing in accordance with the provisions of the law, the reasons requiring processing are eliminated and the legal retention periods expire, they are deleted, destroyed or anonymized in accordance with the Regulation on the Deletion, Destruction or Anonymization of Personal Data (“Regulation”), which entered into force upon publication in the Official Gazette dated 28.10.2017 and numbered 30224, which constitutes the secondary regulation of the KVKK, and to ensure the fulfillment of the obligations arising from the Regulation.

This Storage and Destruction Policy applies to activities related to the storage and destruction of personal data processed by the Company. This Storage and Destruction Policy is in accordance with the KVKK, “Regulation on the Deletion, Destruction or Anonymization of Personal Data”It has been handled and prepared based on other legislation regarding the storage and destruction of e- and personal data.

 

  1. DELETION, DESTRUCTION AND ANONYMIZATION ACTIVITIES OF PERSONAL DATA CARRIED OUT BY THE COMPANY

Personal data is retained by the Company only within the retention and statute of limitations specified in relevant legislation and/or for the period necessary for the purpose for which it is processed. Accordingly, the Company first determines whether any specific retention periods and/or statute of limitations apply to personal data storage under relevant legislation and retains personal data in accordance with these periods. If no specific period is stipulated in relevant legislation, personal data is retained in accordance with the Personal Data Protection Law and for the period necessary for the purpose for which it is processed.

As regulated in Article 7 of the KVKK, the Company destroys personal data by deleting, destroying or anonymizing them in accordance with Articles 8, 9 and 10 of the “Regulation on the Deletion, Destruction or Anonymization of Personal Data”, either ex officio or upon the request of the relevant person, in case the reasons requiring processing are eliminated and/or the legal retention periods have expired, even though the data has been processed in accordance with the relevant law provisions.

In order to fulfill its obligations arising from the Law and Regulation, the Company has taken the necessary technical and administrative measures and developed the necessary operational mechanisms in this regard; it trains its relevant units and makes the necessary assignments in this regard to comply with these obligations.

  1. CASES REQUIRING DESTRUCTION OF PERSONAL DATA AND METHODS OF DELETION, DESTRUCTION AND ANONYMIZATION OF PERSONAL DATA

 

  • Circumstances Requiring Destruction of Personal Data

In accordance with the KVKK and the Regulation, personal data of data owners are deleted, destroyed or anonymized by the Company ex officio or upon request in the following cases:

  1. Amendment and/or repeal of other legislative provisions that form the basis for the processing, storage and storage periods of personal data in a way that eliminates the obligation to store personal data,
  1. The purpose requiring the processing or storage of personal data disappears,
  1. The “Conditions for Processing Personal Data” specified in Articles 5 and 6 of the Law are eliminated.
  2. In cases where the processing of personal data is carried out only on the basis of the condition of "explicit consent", the data owner may withdraw his consent,
  3. The data controller accepts the data subject's application for the deletion, destruction or anonymization of his/her personal data, within the scope of the rights referred to in subparagraphs 1/ef of Article 11 of the KVKK.
  4. The Board decides on the deletion, destruction or anonymization of personal data,
  5. After the maximum period for which personal data must be stored has expired, there is no legal requirement that would justify storing personal data for a longer period,
  1. Methods of Deletion, Destruction and Anonymization of Personal Data

The Company uses deletion, destruction and anonymization methods in accordance with the KVKK when destroying personal data:

 

  1. Deletion Methods: The Company uses one or more of the following methods as a deletion method depending on the nature of the personal data and the environment in which it is located: deletion by command from the database, obfuscation.
  2. Destruction Methods: The Company uses one or more of the following methods as a method of destruction depending on the nature of personal data and the environment in which it is located: physical destruction, demagnetization, or overwriting.
  3. Anonymization Methods: In order to anonymize personal data, the Company uses one or more of the following anonymization methods: regional hiding, variable extraction, record extraction, generalization, lower and upper bound coding, global coding, sampling, data exchange, noise addition, micro-aggregation, data hashing and corruption, depending on the nature, size, physical environment, diversity, desired benefit from the data, and processing purpose of the data.

 

  1. UNIT, TITLE AND JOB DEFINITIONS OF COMPANY PERSONNEL INVOLVED IN THE STORAGE AND DESTRUCTION PROCESSES OF PERSONAL DATA

 

The person(s) in the position detailed below will be responsible for the storage, deletion, destruction, and anonymization of personal data from the database. The job descriptions for these individuals have been determined by the Company as follows:

Position: Operations Manager

Summary job description:  Managing and securing the infrastructure necessary for the smooth operation of applications and business systems used. Identifying suitable locations in line with brand strategies. Following all legal and technical processes required for branch openings in designated locations approved by management. Selecting branch personnel. Maintaining a thorough understanding of all branch employee work processes. Supervising franchises and branches, and informing relevant departments to meet any needs.

  1. STORAGE AND DESTRUCTION PERIODS

 

Data CategoriesRetention PeriodsDestruction Times
Data related to the Customer, Membership and Buyer and Subject to the Order/Purchase Transaction10 years after the legal relationship ends under the Turkish Commercial Code No. 6102; 3 years under the Law on Regulation of Electronic Commerce No. 6563 and related secondary legislationUpon expiration of the storage period, at the first periodic destruction.
All records related to financial and accounting transactions           10 years under the Turkish Commercial Code No. 6102, 5 years under the Tax Procedure Law No. 213Upon expiration of the storage period, at the first periodic destruction.
Records of electronic commerce transactions3 years from the date of transactionUpon expiration of the storage period, at the first periodic destruction.
Commercial Electronic Message records3 years from the date of withdrawal of approvalUpon expiration of the storage period, at the first periodic destruction.
Security camera recordings kept for certain periods of time1 month from the date of registrationUpon expiration of the storage period, at the first periodic destruction
CVsDuring his/her employment period in accordance with company policyResumes that exceed the length of your employment will be destroyed electronically. Physical resumes are destroyed within six months.
  1. TECHNICAL AND ADMINISTRATIVE MEASURES TAKEN BY THE COMPANY TO SECURELY STORAGE PERSONAL DATA AND PREVENT UNLAWFUL PROCESSING AND ACCESS

 

  1. The Company has taken the necessary technical and administrative measures to prevent the unlawful processing of personal data, unlawful access to personal data, and to ensure that personal data is stored in accordance with the KVKK.
  2. The company limits the access rights of its personnel in order to ensure data security and limit their authority.
  3. It limits personnel access rights on the company's main server.
  4. To ensure data security within the company, encryption techniques are introduced and the obligation to change passwords periodically is implemented.
  5. The Company protects all areas of the website or mobile application where personal data is collected with SSL.
  6. Software and hardware including virus protection systems and firewalls are installed on the company and its owned platforms.