Personal Data Protection and Processing Policy
General Makina personal data protection and processing policy — principles under the KVKK, data subject rights and application methods.
General Taş Kırma Makinaları Sanayi ve Ticaret Anonim Şirketi (the “Company”) attaches the utmost importance to protecting the fundamental rights and freedoms of individuals, particularly the privacy of private life regulated under Article 20 of the Constitution, in the protection and processing of personal data. In this framework, in accordance with the Personal Data Protection Law No. 6698 (the “Law” or the “PDP Law”), it takes care to protect and process personal data lawfully and acts with this understanding in all its planning and activities.
Our Company does not regard the protection and processing of personal data, which is the basis of the privacy of private life, merely as a matter of legal compliance; it places the value it attributes to people at the heart of its approach. Acting with this awareness, our Company takes all necessary administrative and technical measures for the lawful protection and processing of personal data.
The purpose of the Personal Data Protection and Processing Policy (the “Policy”) is, in line with the purpose of the Law, to protect to the maximum extent the fundamental rights and freedoms of individuals, in particular the privacy of private life regulated under Article 20 of the Constitution, in the protection and processing of personal data processed wholly or partly by automated means or by non-automated means provided that they form part of any data recording system, and to inform personal data subjects (relevant persons) about our Company’s obligations and the procedures and principles it will observe under the Law. In line with the purpose of the Policy, it is aimed to ensure full compliance with the legislation in the personal data protection and processing activities carried out by our Company and to protect personal data subjects’ right to privacy of private life and data security.
1.3 Scope of the PolicyThis Policy has been prepared for, and shall be applied in respect of, the following persons, provided that they are natural persons: Job Candidate, Subcontractor Employee, Trainer, Service Provider, Service Provider Employee, Service Provider Representative, Customer, Customer Representative, Company Shareholder Partner, Company Representative, Driver, Subcontractor Employee, Carrier, Supplier, Supplier Representative, Third Parties (Employee’s Emergency Contact Person), Third Parties (Reference person), Visitors. By publishing this Policy on its website, the Company informs these personal data subjects about the Law. This Policy shall not apply to legal entities in any capacity whatsoever. For our Company’s employees, the “Personal Data Processing Policy for Employees” shall apply.
This Policy shall apply where the personal data of the relevant persons stated above are processed by our Company wholly or partly by automated means or by non-automated means provided that they form part of any data recording system. This Policy shall not apply where the data does not fall within the scope of “Personal Data” as set out below, or where the personal data processing activity carried out by our Company is not performed by the means stated above.
| Explicit Consent | Consent relating to a specific subject, based on information and expressed with free will. |
| Making Public | The concept of making public, meaning “making known to everyone”, is listed in Article 5 of Law No. 6698 as one of the exceptions to the “requirement to obtain the explicit consent of the natural person whose personal data is processed”, which is necessary for the processing of personal data. |
| Obligation to Inform | The obligation of the data controller to inform the persons whose personal data it processes about by whom, for what purposes and on which legal grounds their data may be processed, and to whom and for what purposes it may be transferred. |
| Relevant User | Persons who process personal data within the data controller’s organisation or in accordance with the authorisation and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and back-up of the data. |
| Destruction | Refers to the deletion, destruction or anonymisation of personal data. |
| Processing of Personal Data | Any operation performed on data such as obtaining, recording, storing, retaining, altering, rearranging, disclosing, transferring, taking over, making available, classifying or preventing the use of Personal Data, wholly or partly by automated means or by non-automated means provided that it forms part of any data recording system. |
| PDP Board | The Personal Data Protection Board. |
| Relevant Person / Personal Data Subject | Refers to the Job Candidate, Subcontractor Employee, Trainer, Service Provider, Service Provider Employee, Service Provider Representative, Customer, Customer Representative, Company Shareholder Partner, Company Representative, Driver, Subcontractor Employee, Carrier, Supplier, Supplier Representative, Third Parties (Employee’s Emergency Contact Person), Third Parties (Reference person), Visitors whose Personal Data (including special categories of personal data) are processed. |
| Personal Data | Any information relating to an identified or identifiable natural person. |
| Authority | The Personal Data Protection Authority, consisting of the Board and the Presidency. |
| Automated Data Processing | Processing activity carried out by devices with processors such as computers, telephones, watches, etc., occurring automatically without human intervention within the scope of algorithms prepared in advance through software or hardware features. |
| Special Categories of Personal Data | Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data are special categories of data. |
| Registry | The Data Controllers’ Registry. |
| Company / Our Company | General Taş Kırma Makinaları Sanayi ve Ticaret Anonim Şirketi. |
| Data Processor | The natural or legal person who processes Personal Data on behalf of the data controller based on the authority granted by the data controller. |
| Data Recording System | Refers to the recording system in which Personal Data is processed by being structured according to certain criteria. |
| Data Category | The class of personal data belonging to the data subject person group or groups in which personal data are grouped according to their common characteristics. |
| Data Subject Person Group | The group of relevant persons whose personal data are processed by the data controller. |
| Data Controller | The natural or legal person who determines the purposes and means of processing Personal Data and is responsible for the establishment and management of the data recording system. |
The Policy, drawn up by General Taş Kırma Makinaları Sanayi ve Ticaret Anonim Şirketi and entering into force on 25 / 11 / 2022, has been published on our Company’s website (www.general-makina.com.tr) and made available to relevant persons.
2. PROTECTION OF PERSONAL DATA 2.1 Security of Personal DataIn accordance with the Law, our Company takes all necessary administrative and technical measures to ensure an appropriate level of security in order to store personal data securely and to prevent the unlawful processing of and access to personal data. The administrative and technical measures taken regarding the security of personal data are set out in detail in our Company’s Personal Data Retention and Destruction Policy.
In order to ensure compliance with the provisions of the Law and other legislation, our Company has established a “Personal Data Protection Management System” and, in this context, has set up a Personal Data Protection Committee within its structure to ensure the implementation of the Policy and other related policies.
Our Company carries out and has carried out the necessary audits in order to establish the data security explained above and to ensure the regularity and continuity of the measures taken. The Personal Data Protection Committee audits the measures taken for the security of personal data.
2.3 ConfidentialityOur Company takes all necessary administrative and technical measures, in line with technological possibilities and implementation costs, to ensure that the relevant data controllers and data processors do not disclose the personal data they hold to others contrary to the provisions of the Law and the Policy, and do not use it for purposes other than processing. In this context, information and training activities on the Law and the Policy are carried out for company employees, and confidentiality agreements are signed with the relevant employees as part of their recruitment processes.
2.4 Unauthorised Disclosure of Personal DataIn the event that personal data processed by our Company is obtained by others through unlawful means, our Company carries out the necessary procedures to notify the relevant person and the PDP Board within the periods determined by the PDP Board. If deemed necessary by the PDP Board, this situation is announced on the PDP Board’s website or by another method deemed appropriate by the PDP Board.
2.5 Observance of the Legal Rights of Relevant PersonsOur Company observes all legal rights of relevant persons in connection with the implementation of the Policy and the Law and takes all necessary measures to protect these rights.
2.6 Protection of Special Categories of Personal DataData relating to individuals’ race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data, are special categories of personal data. Our Company is aware that special categories of personal data are data which, if learned by others, may cause the relevant person to suffer harm or be subjected to discrimination, and therefore takes with due sensitivity the adequate measures determined by the Board for the protection of such personal data processed lawfully. In this framework, it has a separate policy (Security Policy for Special Categories of Personal Data) and procedure that is systematic, with clearly defined rules, manageable and sustainable.
3. PROCESSING AND TRANSFER OF PERSONAL DATA 3.1 General Principles in the Processing and Transfer of Personal DataPersonal data is processed by our Company in accordance with the procedures and principles set out in the Law and in this Policy. Our Company complies with the following principles when processing personal data.
3.1.1 Compliance with the Law and Rules of Good Faith
Our Company processes personal data in accordance with the relevant legislation and the requirements of the rule of good faith and uses it within these limits. In accordance with the principle of compliance with the rule of good faith, our Company takes into account the interests and reasonable expectations of the relevant persons while pursuing its objectives in data processing. It acts in a manner that prevents the emergence of outcomes that the relevant person does not expect and should not be expected to anticipate. Pursuant to this principle, it also ensures that the data processing activity in question is transparent for the relevant person and acts in accordance with its obligations to inform and warn.
3.1.2 Being Accurate and Up to Date Where Necessary
Taking into account the fundamental rights and legitimate interests of relevant persons, our Company ensures that the personal data it processes is accurate and up to date. In this context, it carefully takes into account matters such as the sources from which the data is obtained being identified, the accuracy of the data being verified, and assessing whether updating is required. In accordance with its duty of active care, our Company always keeps open the channels that ensure that the personal data subject’s information is accurate and up to date. Keeping personal data accurate and up to date protects our Company’s interests and is also necessary for the protection of the relevant person’s fundamental rights and freedoms.
3.1.3 Processing for Specific, Explicit and Legitimate Purposes
Our Company determines the purpose of data processing clearly and definitively and ensures that this purpose is legitimate. The legitimacy of the purpose means that the personal data processed by our Company is connected with and necessary for the business it conducts or the service it provides. Our Company does not carry out data processing for purposes other than those stated. In this respect, it shows sensitivity in complying with the principle of specificity and clarity in legal transactions and texts in which the purposes of personal data processing are explained.
3.1.4 Being Connected with, Limited to and Proportionate to the Purposes for Which They Are Processed
Our Company ensures that the personal data processed is suitable for achieving the determined purposes and avoids processing data that is unrelated to the achievement of the purpose or not needed. Our Company does not collect or process personal data for purposes that do not currently exist and are contemplated to occur later. In order to process data for the fulfilment of needs that may arise later, it fulfils the processing conditions regulated in the Law as if it were beginning processing for the first time. It also keeps the processed data limited to what is necessary for the achievement of the purpose. Within the scope of the principle of proportionality, it establishes a reasonable balance between the data processing and the purpose sought to be achieved.
3.1.5 Being Retained for the Period Stipulated in the Relevant Legislation or Required for the Purpose for Which They Are Processed
Where a period is stipulated in the relevant legislation for the retention of data, our Company complies with such periods; otherwise, it retains personal data only for the period necessary for the purpose for which it is processed. Where there is no valid reason for our Company to retain personal data any longer, such data is deleted, destroyed or anonymised. The procedures relating to the retention and destruction of personal data are set out in detail in our Company’s Personal Data Retention and Destruction Policy.
3.2 Conditions for Processing Personal DataOur Company does not process personal data without the explicit consent of the relevant person. Personal data may be processed without seeking the explicit consent of the relevant person only in the presence of one of the following conditions:
3.2.1 Being Expressly Provided for by Laws
Our Company may process personal data without seeking the explicit consent of the relevant person in cases expressly provided for by laws.
3.2.2 Being Mandatory for the Protection of the Life or Physical Integrity of the Person Himself/Herself or of Another Person Who Is Unable to Express His/Her Consent Due to Actual Impossibility or Whose Consent Is Not Legally Valid
In cases where consent cannot be expressed or is not valid, our Company may process personal data without seeking explicit consent for the protection of the life or physical integrity of persons.
3.2.3 Being Necessary to Process Personal Data of the Parties to a Contract, Provided That It Is Directly Related to the Establishment or Performance of the Contract
Where it is compulsory to process the personal data of the parties to a contract in direct relation to the establishment or performance of that contract, our Company may, in accordance with the ordinary course of life and limited to this purpose, process the personal data of the relevant persons without seeking explicit consent.
3.2.4 Being Mandatory for Our Company to Fulfil Its Legal Obligation
Our Company may process the personal data of the relevant person without seeking explicit consent in cases where this is mandatory in order for it to fulfil its legal obligations as data controller.
3.2.5 Having Been Made Public by the Relevant Person
Our Company may process personal data made public by the relevant persons themselves, in other words disclosed to the public in any way, limited to the purpose of making it public, on the grounds that the legal interest requiring protection is deemed to have ceased in the processing of such data which has been made public by the relevant persons and thus become knowable by everyone.
3.2.6 Data Processing Being Mandatory for the Establishment, Exercise or Protection of a Right
Our Company may process the personal data of relevant persons without seeking explicit consent in cases where data processing is mandatory for the exercise or protection of a legally legitimate right.
3.2.7 Data Processing Being Mandatory for the Legitimate Interests of Our Company, Provided That It Does Not Harm the Fundamental Rights and Freedoms of the Relevant Persons
Our Company may process the personal data of relevant persons in cases where processing personal data is mandatory for securing its legitimate interests, provided that it does not harm the fundamental rights and freedoms of the relevant persons protected under the Law and the Policy. Our Company shows the necessary sensitivity in complying with the basic principles concerning the protection of personal data and in observing the balance of interests between our Company and personal data subjects. Legitimate interest means an interest that is legitimate, effective at a level capable of competing with the fundamental rights and freedoms of the relevant person, specific and already existing. Our Company takes additional protective measures so that the rights of the relevant person are not harmed. A reasonable balance is established between our Company’s interest and the fundamental rights and freedoms of the relevant person.
3.3 Conditions for Processing Special Categories of Personal DataOur Company does not process special categories of personal data without the explicit consent of the relevant person. Special categories of personal data may be processed without seeking the explicit consent of the relevant person only in the presence of one of the following conditions:
3.3.1 Being Expressly Provided for by Laws
Special categories of personal data other than the relevant person’s health and sexual life may be processed without seeking the explicit consent of the relevant person in cases expressly provided for by laws.
3.3.2 For the Purposes of Protection of Public Health, Preventive Medicine, Medical Diagnosis, the Conduct of Treatment and Care Services, and the Planning and Management of Health Services and Their Financing
Special categories of personal data relating to the relevant person’s health and sexual life may be processed for the purposes of protection of public health, preventive medicine, medical diagnosis, the conduct of treatment and care services, and the planning and management of health services and their financing, by persons under the obligation of confidentiality or by authorised institutions and organisations.
3.4 Conditions for the Transfer of Personal Data Our Company may transfer personal data to third parties, taking the necessary security measures and pursuant to Article 8 of the Law, based on and limited to one or more of the personal data processing conditions set out below:- The explicit consent of the relevant person,
- There being an express provision in the laws regarding the transfer of personal data,
- The transfer of personal data being mandatory for the protection of the life or physical integrity of the relevant person or of another person, and the relevant person being unable to express his/her consent due to actual impossibility or his/her consent not being legally valid,
- The transfer of personal data belonging to the parties to a contract being necessary, provided that it is directly related to the establishment or performance of the contract,
- The transfer of personal data being mandatory for our Company to fulfil its legal obligation,
- The personal data having been made public by the relevant person,
- The transfer of personal data being mandatory for the establishment, exercise or protection of a right,
- The transfer of personal data being mandatory for the legitimate interests of our Company, provided that it does not harm the fundamental rights and freedoms of the relevant person.
- The explicit consent of the relevant person,
- Where special categories of personal data other than the relevant person’s health and sexual life are concerned, there being an express provision in the laws regarding the transfer of such data.
- Where special categories of personal data relating to the relevant person’s health and sexual life are concerned, such data may be transferred for the purposes of protection of public health, preventive medicine, medical diagnosis, the conduct of treatment and care services, and the planning and management of health services and their financing, by persons under the obligation of confidentiality or by authorised institutions and organisations.
3.4.1 Conditions for the Transfer of Personal Data Abroad
Our Company may transfer personal data abroad, taking the necessary security measures and pursuant to Article 9 of the Law, based on the explicit consent of the relevant person.
In addition, in the presence of one of the conditions set out in the second paragraph of Article 5 and the third paragraph of Article 6 of the Law, and without prejudice to the provisions of international conventions to which Türkiye is a party, our Company may also transfer personal data without seeking the explicit consent of the relevant person only to foreign countries declared by the PDP Board to have adequate protection, or, in the absence of adequate protection, to foreign countries where the data controllers in Türkiye and in the relevant foreign country have undertaken adequate protection in writing and the PDP Board’s permission has been obtained.
Personal data is processed by our Company by being categorised as follows:
| Identity | Data containing information about the identity of personal data subjects: Name and surname, Turkish ID number, marital status, mother’s and father’s name and surname, place and date of birth and other identity information, and copies of driving licence, ID card and passport containing such information; tax number, social security number, signature information, etc. |
| Contact | Contact details of personal data subjects: Telephone number, address, e-mail address, registered electronic mail address (KEP), fax number, etc. |
| Personnel File | Information processed in order to obtain data that will form the basis for the protection of personal data subjects’ personnel rights: CV, title information; employment entry-exit document records; social security/retirement information, payroll information, declaration of assets information, information in disciplinary investigation and performance evaluation reports, etc. |
| Legal Transaction | Data processed within the scope of the determination and follow-up of the Company’s legal receivables and rights, the performance of its debts and its legal obligations: Power of attorney information, court and administrative authority decisions, information in correspondence with judicial authorities, information in case files, etc. |
| Physical Space Security | Personal data relating to records and documents taken upon entry to and while inside the physical premises belonging to the Company: Entry-exit records, magnetic card records, security camera recordings, vehicle licence plate, etc. |
| Finance | Personal data processed in relation to information, documents and records showing the outcome of any financial relationship established by the Company with personal data subjects, as well as bank account information, credit information, balance sheet information, financial profile, assets and insurance information, etc. |
| Professional Experience | Diploma, transcript, education/course/certificate information, driving licence information, foreign language information, reference information, etc. recorded during and after the recruitment process of personal data subjects. |
| Visual and Audio Records | Photographs, camera and voice recordings that may be taken of personal data subjects outside the scope of physical space security, and other documents to which such data is transferred: Photographs attached to forms, video interview and meeting recordings, etc. |
| Transaction Security | Personal data processed in relation to the technical, administrative, legal and commercial security of both the personal data subject and the Company while carrying out Company activities: IP address information, website entry-exit (traffic) information, internet access records, password and passcode information, etc. |
| SPECIAL CATEGORIES OF PERSONAL DATA | |
| Health Information | Health data belonging to personal data subjects: Examination information, health reports, disability status, health leave, blood group information, etc. |
| Criminal Convictions and Security Measures | Documents containing information on criminal conviction and security measure decisions regarding personal data subjects: Criminal record certificates. |
Only natural persons can benefit from the protection of this Policy and the Law. Personal data subjects within this scope are grouped as follows:
| Job Candidate | Natural persons who have applied for a job with our Company in any way or who have made their CV and related information available for our Company’s review. |
| Trainer | Natural persons who provide training services to employees within our Company on various subjects. |
| Service Provider | Natural persons, or the natural persons of legal entities, who are not included in the Customer, Subcontractor and Supplier groups but who are in a business relationship with our Organisation and are independent of our Organisation. |
| Service Provider Employee | Natural person employees of natural persons or legal entities who are not included in the Customer, Subcontractor and Supplier groups but who are in a business relationship with our Organisation and are independent of our Organisation. |
| Service Provider Representative | Natural persons or natural person representatives of legal entities who are not included in the Customer, Subcontractor and Supplier groups but who are in a business relationship with our Organisation, are independent of our Organisation and supply services to our organisation. |
| Customer | Natural persons such as dealers, distributors, points of sale, etc. who deliver our Company’s products to the end consumer within the scope of a contractual relationship. |
| Customer Representative | Natural person representatives of the firms that purchase our Company’s products within the scope of a contractual relationship. |
| Company Shareholder Partner | Persons who are shareholders of General Taş Kırma Makinaları Sanayi ve Ticaret Anonim Şirketi. |
| Company Representative | Refers to natural persons authorised to carry out legal transactions on behalf of our Company. |
| Driver | Natural persons who are assigned the task of driving vehicles in our Company’s supply or sales processes and whose personal data is included in the relevant delivery notes. |
| Subcontractor Employee | Identified/identifiable employees of natural or legal persons with whom our Company has established a principal employer–subcontractor relationship through a contract. |
| Carrier | Natural person transport firms involved in our Company’s supply or sales processes and whose personal data is included in the relevant delivery notes. |
| Supplier | Natural persons who provide inputs, raw materials or products to our Company in order to offer a product or service. |
| Supplier Representative | Natural persons, or representatives of legal entities, who provide inputs, raw materials or products to our Company in order to offer a product or service. |
| Third Parties (Reference Person, Employee’s Emergency Contact Person) | Natural persons who have no direct legal relationship with our Company and whose data has been lawfully obtained by indirect means. |
| Visitor | All natural persons who have entered the physical premises owned by our Company for various purposes or who visit our websites for any purpose. |
5. METHOD OF COLLECTING PERSONAL DATA AND LEGAL GROUNDS 5.1 Method of Collecting Personal Data In line with the purposes stated in article 6.1, our Company collects personal data wholly or partly by automated or non-automated means; in any verbal, written or electronic medium; through the following channels, but not limited to them:
- Job application forms,
- Personnel information forms,
- Various documents submitted to the Company,
- Mail and e-mails sent to the Company,
- Telephone exchanges,
- Corporate telephones,
- ERP programmes,
- Servers,
- Relevant software,
- Purchase-sale invoices,
- Payroll calculation programmes,
- Health policies,
- Health reports,
- Security cameras,
- Persons working in other departments of the Company, third parties (subcontractor firms) and data subjects.
- The explicit consent of the relevant person,
- Being expressly provided for by laws;
- The personal data having been made public by the relevant person himself/herself,
- The processing of personal data belonging to the parties to a contract being necessary, provided that it is directly related to the establishment or performance of the contract,
- Being mandatory for our Company to fulfil its legal obligation,
- Data processing being mandatory for the establishment, exercise or protection of a right,
- Data processing being mandatory for the legitimate interests of our Company, provided that it does not harm the fundamental rights and freedoms of the relevant persons.
The matching of the data subject person groups whose definitions and scope are given above with the processing purposes relating to personal data categories is presented below: (Natural persons may be included in only one person group.)
- Job Candidate
Data Categories: Identity, Contact, Personnel File, Health Information, Criminal Conviction and Security Measure Information, Professional Experience
Processing Purposes: Processed for the purposes of Conducting Job Candidates’ Application Processes, Conducting Assignment Processes, Conducting / Auditing Business Activities, Planning Human Resources Processes, Conducting Job Candidate Selection and Placement Processes.
- Subcontractor Employee
Data Categories: Identity, Contact, Personnel File, Health Information, Criminal Conviction and Security Measure Information, Transaction Security, Professional Experience, Visual and Audio Information, Physical Space Security, Legal Transaction
Processing Purposes:
Processed for the purposes of Conducting Emergency Management Processes, Fulfilling Obligations Arising from Employment Contract and Legislation for Employees, Conducting Fringe Benefits and Interests Processes for Employees, Conducting Employees’ Annual Leave Activities, Conducting Audit / Ethics Activities, Conducting Training Activities, Conducting Access Authorisations, Conducting Activities in Compliance with the Legislation, Ensuring Physical Space Security, Following Up and Conducting Legal Affairs, Conducting Internal Audit / Investigation / Intelligence Activities, Planning Human Resources Processes, Conducting / Auditing Business Activities, Conducting Response to Occupational Accidents and Post-Accident Follow-Up Activities, Conducting Occupational Health / Safety Activities, Conducting Business Continuity Activities, Conducting Employer Incentive Processes, Organisation and Event Management, Conducting Performance Evaluation Processes, Conducting Personnel Attendance Control Processes, Conducting Risk Management Processes, Conducting Subcontractor Agreement Processes, Ensuring the Security of Movable Property and Resources, Providing Information to Authorised Persons, Institutions and Organisations.
- Trainer
Data Categories: Identity, Personnel File
Processing Purposes: Processed for the purposes of Conducting Training Activities, Conducting Activities in Compliance with the Legislation, Conducting Contract Processes.
- Service Provider
Data Categories: Identity, Contact, Personnel File, Finance
Processing Purposes: Processed for the purposes of Conducting Emergency Management Processes, Fulfilling Obligations Arising from Employment Contract and Legislation for Employees, Conducting Audit / Ethics Activities, Conducting Training Activities, Conducting Activities in Compliance with the Legislation, Conducting Invoicing Activities, Conducting Finance and Accounting Affairs, Conducting Assignment Processes, Following Up and Conducting Legal Affairs, Conducting Communication Activities, Conducting / Auditing Business Activities, Conducting Occupational Health / Safety Activities, Conducting Business Continuity Activities, Conducting Logistics Activities, Conducting Goods / Services Procurement Processes, Making Payments, Conducting Risk Management Processes, Conducting Contract Processes, Conducting Supply Chain Management Processes.
- Service Provider Employee
Data Categories: Identity, Contact, Personnel File
Processing Purposes: Processed for the purposes of Conducting Emergency Management Processes, Fulfilling Obligations Arising from Employment Contract and Legislation for Employees, Conducting Audit / Ethics Activities, Conducting Training Activities, Conducting Assignment Processes, Conducting Communication Activities, Conducting Response to Occupational Accidents and Post-Accident Follow-Up Activities, Conducting Occupational Health / Safety Activities, Conducting Business Continuity Activities, Conducting Logistics Activities, Organisation and Event Management, Conducting Risk Management Processes, Providing Information to Authorised Persons, Public Institutions and Organisations.
- Service Provider Representative
Data Categories: Identity, Personnel File, Contact, Legal Transaction
Processing Purposes: Processed for the purposes of Conducting Supply Chain Management Processes, Conducting Goods / Services Procurement Processes, Conducting Finance and Accounting Affairs, Conducting Business Continuity Activities, Conducting Contract Processes, Conducting / Auditing Business Activities, Following Up and Conducting Legal Affairs.
- Customer
Processing Purposes: Processed for the purposes of Conducting Activities in Compliance with the Legislation, Conducting Finance and Accounting Affairs, Conducting Price Quotation Processes, Following Up and Conducting Legal Affairs, Conducting Communication Activities, Conducting / Auditing Business Activities, Conducting Business Continuity Activities, Conducting Import and Export Processes, Conducting Logistics Activities, Conducting After-Sales Support Services for Goods / Services, Conducting Goods / Services Sales Processes, Conducting Customer Relationship Management Processes, Conducting Activities for Customer Satisfaction, Conducting Contract Processes, Fulfilling Tax Obligations, Providing Information to Authorised Persons, Institutions and Organisations.
- Customer Representative
Data Categories: Identity, Contact
Processing Purposes: Processed for the purposes of Conducting Activities in Compliance with the Legislation, Conducting Finance and Accounting Affairs, Conducting / Auditing Business Activities, Conducting Business Continuity Activities, Conducting Contract Processes, Conducting Goods / Services Procurement Processes, Following Up and Conducting Legal Affairs, Conducting Supply Chain Management Processes.
- Company Shareholder / Partner
Processing Purposes: Processed for the purposes of Conducting Information Security Processes, Conducting Employee Satisfaction and Loyalty Processes, Providing the Information Necessary for Employees’ Credit Limit Assessments, Conducting Audit / Ethics Activities, Conducting Access Authorisations, Conducting Activities in Compliance with the Legislation, Following Up and Conducting Legal Affairs, Conducting / Auditing Business Activities, Providing Information to Authorised Persons, Institutions and Organisations, Conducting Management Activities.
- Company Representative
Data Categories: Identity, Contact, Legal Transaction, Visual and Audio Information
Processing Purposes: Processed for the purposes of Conducting Emergency Management Processes, Conducting Information Security Processes, Conducting Employee Satisfaction and Loyalty Processes, Fulfilling Obligations Arising from Employment Contract and Legislation for Employees, Conducting Fringe Benefits and Interests Processes for Employees, Providing the Information Necessary for Employees’ Credit Limit Assessments, Conducting Audit / Ethics Activities, Conducting Training Activities, Conducting Access Authorisations, Conducting Activities in Compliance with the Legislation, Conducting Finance and Accounting Affairs, Following Up and Conducting Legal Affairs, Conducting Internal Audit / Investigation / Intelligence Activities, Planning Human Resources Processes, Conducting / Auditing Business Activities, Conducting Response to Occupational Accidents and Post-Accident Follow-Up Activities, Conducting Occupational Health / Safety Activities, Conducting Business Continuity Activities, Organisation and Event Management, Conducting Performance Evaluation Processes, Conducting Risk Management Processes, Conducting Contract Processes, Providing Information to Authorised Persons, Institutions and Organisations, Conducting Management Activities.
- Driver
Data Categories: Identity, Personnel File
Processing Purposes: Processed for the purposes of Conducting Finance and Accounting Affairs, Conducting Invoicing Activities, Creating and Receiving Delivery Notes, Following Up and Conducting Legal Affairs, Fulfilling Tax Obligations.
- Carrier
Data Categories: Identity
Processing Purposes: Processed for the purposes of Conducting Finance and Accounting Affairs, Conducting Invoicing Activities, Creating and Receiving Delivery Notes, Following Up and Conducting Legal Affairs, Fulfilling Tax Obligations.
- Supplier
Data Categories: Identity, Contact, Personnel File, Finance, Legal Transaction
Processing Purposes: Processed for the purposes of Conducting Activities in Compliance with the Legislation, Conducting Invoicing Activities, Conducting Finance and Accounting Affairs, Following Up and Conducting Legal Affairs, Conducting / Auditing Business Activities, Conducting Business Continuity Activities, Conducting Goods / Services Procurement Processes, Making Payments, Conducting Contract Processes, Obtaining Supply Quotations, Conducting Supply Chain Management Processes.
- Supplier Representative
Data Categories: Identity, Personnel File, Contact, Legal Transaction
Processing Purposes: Processed for the purposes of Conducting Activities in Compliance with the Legislation, Conducting Finance and Accounting Affairs, Following Up and Conducting Legal Affairs, Conducting / Auditing Business Activities, Conducting Business Continuity Activities, Conducting Goods / Services Procurement Processes, Conducting Contract Processes, Obtaining Supply Quotations, Conducting Supply Chain Management Processes.
- Third Parties (Reference Person)
Data Categories: Identity, Personnel File, Contact
Processing Purposes: Processed for the purposes of Conducting Job Candidate Selection and Placement Processes, Conducting Job Candidates’ Application Processes, Conducting Assignment Processes, Conducting / Auditing Business Activities, Planning Human Resources Processes.
- Third Parties (Employee’s Emergency Contact Person)
Data Categories: Identity, Contact
Processing Purposes: Processed for the purposes of Conducting Emergency Management Processes, Fulfilling Obligations Arising from Employment Contract and Legislation for Employees, Conducting Audit / Ethics Activities, Conducting Training Activities, Conducting Occupational Health / Safety Activities, Conducting Risk Management Processes.
- Visitor
Data Categories: Identity, Personnel File, Physical Space Security, Visual and Audio Information
Processing Purposes: Processed for the purposes of Conducting Emergency Management Processes, Fulfilling Obligations Arising from Employment Contract and Legislation for Employees, Conducting Audit / Ethics Activities, Conducting Activities in Compliance with the Legislation, Ensuring Physical Space Security, Conducting / Auditing Business Activities, Conducting Management Activities, Conducting Occupational Health / Safety Activities, Providing Information to Authorised Persons, Institutions and Organisations, Creating and Following Up Visitor Records.
Personal Data Processing Activities Carried Out in Physical Spaces
Entries and exits are recorded and monitoring is carried out with cameras in common areas in our Company’s buildings and facilities in order to ensure security. Notices to this effect are posted in areas monitored by cameras.
Records relating to the internet access provided in our Company’s buildings and facilities are kept pursuant to Law No. 5651 on the Regulation of Publications Made on the Internet and Combating Crimes Committed Through Such Publications and other legislation, and these records may be shared with authorised public institutions and organisations upon request and may be used, where necessary, in audit activities for the fulfilment of the relevant legal obligation.
The traffic information of online visitors to our website is processed automatically for the purpose of conducting information security processes. On the other hand, pursuant to Law No. 5651 and other legislation, hosting providers have an obligation to record and retain website traffic information.
Detailed explanations regarding the personal data processed through the website are available on the relevant website.
Relevant persons must use these channels only within the scope of business activities.
7. PURPOSES OF TRANSFERRING PERSONAL DATA AND THE PERSONS/ORGANISATIONS TO WHOM IT IS TRANSFERRED 7.1 Purposes of Transferring Personal Data Our Company transfers personal data, within the framework of the conditions set out in Articles 8 and 9 of the Law, limited to the following purposes:
- Conducting emergency management processes,
- Conducting information security processes,
- Conducting job candidate selection and placement processes,
- Conducting job candidates’ application processes,
- Conducting employee satisfaction and loyalty processes,
- Fulfilling obligations arising from employment contract and legislation for employees,
- Conducting fringe benefits and interests processes for employees,
- Providing the information necessary for employees’ credit limit assessments,
- Conducting employees’ annual leave activities,
- Conducting audit / ethics activities,
- Conducting training activities,
- Conducting access authorisations,
- Conducting activities in compliance with the legislation,
- Following up and conducting legal affairs,
- Conducting invoicing activities,
- Conducting finance and accounting affairs,
- Conducting price quotation processes,
- Ensuring physical space security,
- Conducting assignment processes,
- Conducting internal audit / investigation / intelligence activities,
- Conducting communication activities,
- Planning human resources processes
- Creating and receiving delivery notes,
- Conducting / auditing business activities,
- Conducting response to occupational accidents and post-accident follow-up activities
- Conducting occupational health / safety activities,
- Conducting business continuity activities,
- Conducting employer incentive processes,
- Conducting import and export processes,
- Conducting logistics activities,
- Conducting goods / services procurement processes,
- Conducting after-sales support services for goods / services,
- Conducting goods / services sales processes,
- Conducting customer relationship management processes,
- Conducting activities for customer satisfaction,
- Organisation and event management,
- Making payments,
- Conducting performance evaluation processes,
- Conducting personnel attendance control processes,
- Conducting risk management processes,
- Conducting contract processes,
- Conducting subcontractor agreement processes,
- Ensuring the security of movable property and resources,
- Conducting drill activities,
- Obtaining supply quotations,
- Conducting supply chain management processes,
- Fulfilling tax obligations,
- Providing information to authorised persons, institutions and organisations,
- It is transferred for the purpose of conducting management activities.
- Natural Persons or Private Law Legal Entities (Certified Public Accountant, Legal Advisor, Banks, Service Provider Training Firms, Customers, Consultant OHS Firms, Software Firm, Supplier, Environmental Consultancy Firm, Sworn Financial Advisor, Auditors)
- Authorised Public Institutions and Organisations (EGM, GENDARMERIE, public institutions within the scope of incentives, authorised health institutions where necessary, Social Security Institution, Courts, relevant public institutions in the event of an audit, Ministry of Labour and Social Security, Ministry of Health, Tax Office Presidency, Notary)
Without prejudice to the provisions of other laws regarding the destruction of personal data, our Company deletes, destroys or anonymises the personal data it has processed in accordance with this Law and the provisions of other laws, ex officio or upon the request of the relevant person, in accordance with the Personal Data Retention and Destruction Policy, where the reasons requiring its processing cease to exist.
The deletion of personal data refers to the process of making personal data in no way accessible and reusable for relevant users.
The destruction of data refers to the process of making personal data in no way accessible, retrievable or reusable by anyone.
The anonymisation of data refers to the process of making personal data in no way associable with an identified or identifiable natural person, even if matched with other data, through techniques such as masking, variable removal, generalisation, etc.
9. INFORMING THE PERSONAL DATA SUBJECT AND RIGHTS UNDER THE PDP LAW 9.1 Informing the Relevant Person
In accordance with Article 10 of the PDP Law, our Company informs relevant persons at the time personal data is obtained. In this context, it clarifies the identity of the Company representative, if any, for what purpose personal data will be processed, to whom and for what purpose the processed personal data may be transferred, the method and legal ground of personal data collection, and the rights of the relevant person.
9.2 Cases in Which the Policy and the Law Will Not Apply in Whole or in Part The provisions of this Policy and the Law shall not apply in the following cases:- Processing of personal data by natural persons within the scope of activities entirely related to themselves or to family members living in the same residence, provided that they are not given to third parties and the obligations regarding data security are complied with,
- Processing of personal data for purposes such as research, planning and statistics by anonymising it with official statistics,
- Processing of personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that it does not violate national defence, national security, public security, public order, economic security, the privacy of private life or personal rights, or constitute a crime,
- Processing of personal data within the scope of preventive, protective and intelligence activities carried out by public institutions and organisations assigned duties and powers by law to ensure national defence, national security, public security, public order or economic security,
- Processing of personal data by judicial authorities or enforcement authorities in relation to investigation, prosecution, trial or enforcement proceedings.
Provided that it is in compliance with and proportionate to the purpose and basic principles of this Policy and the Law, Article 10 governing the data controller’s obligation to inform, Article 11 governing the rights of the relevant person, except for the right to demand compensation for damage, and Article 16 governing the obligation to register with the Data Controllers’ Registry shall not apply in the following cases:
- Personal data processing being necessary for the prevention of a crime or for a criminal investigation,
- Processing of personal data made public by the relevant person himself/herself,
- Personal data processing being necessary for the performance of supervisory or regulatory duties and for disciplinary investigation or prosecution by authorised and competent public institutions and organisations and by professional organisations having the status of public institutions, based on the authority granted by law,
- Personal data processing being necessary for the protection of the State’s economic and financial interests with regard to budgetary, tax and financial matters.
- To learn whether their personal data is processed,
- To request information if their personal data has been processed,
- To learn the purpose of processing personal data and whether it is used in accordance with its purpose,
- To know the third parties to whom personal data is transferred domestically or abroad,
- To request the correction of personal data if it has been processed incompletely or incorrectly,
- To request the deletion or destruction of personal data within the framework of the conditions set out in Article 7 of the Law,
- To request that the operations carried out pursuant to subparagraphs (d) and (e) of Article 11 of the Law (correction and destruction) be notified to the third parties to whom personal data is transferred,
- To object to the emergence of a result to the person’s detriment by means of the analysis of the processed data exclusively through automated systems,
- To demand compensation for the damage in the event of suffering damage due to the unlawful processing of personal data.
Requests and applications regarding the implementation of the Law may be submitted by completing the application form available on our website (www.general-makina.com.tr) and delivering it in writing in person to the address “Yazıbaşı Sanayi Bölgesi, Balkan Cad. 322 Sk. 29 Ekim Torbalı/İzmir/Türkiye”, or by sending it via notary public, or transmitted electronically using registered electronic mail (KEP) ( [email protected] ), secure electronic signature or mobile signature.
Requests and applications may also be sent to ( [email protected] ) if there is an e-mail address belonging to the relevant person that has previously been notified to our Company and is registered in the Company’s system.
In requests and applications, the following are mandatory:
- Name, surname and, if the application is in writing, signature,
- Turkish ID number for citizens of the Republic of Türkiye; nationality, passport number or, if any, identity number for foreigners,
- Place of residence or workplace address for notification purposes,
- E-mail address, telephone and fax number for notification purposes, if any,
- Subject of the request
Information and documents relating to the matter must be attached to the application.
Our Company concludes the requests contained in the application free of charge as soon as possible and within thirty days at the latest, depending on the nature of the request. However, if the transaction in question requires an additional cost, the fee in the tariff determined by the Board may be charged.
Our Company may accept the request submitted to it or may reject it by explaining its reasons, and notifies its response to the relevant person in writing or electronically. If the request contained in the application is accepted, our Company fulfils the requirement as soon as possible and informs the relevant person. If the application arises from our Company’s error, the fee charged is refunded to the relevant person.
In cases where the application is rejected, the response given is found insufficient, or no response is given to the application within the prescribed period; the relevant person has the right to lodge a complaint with the Board within thirty days from the date on which he/she learns of the response and, in any case, within sixty days from the date of application.
