Data Destruction Policy
PERSONAL DATA RETENTION AND DESTRUCTION POLICY
1. PURPOSE AND SCOPE
BULKOON FOOTWEAR AND LEATHER PRODUCTS INDUSTRY TRADE LIMITED COMPANY ("Our Company") undertakes to comply with personal data protection, processing, and destruction regulations as required by applicable legal obligations. This Personal Data Retention and Destruction Policy ("Policy") sets out the framework and principles for necessary retention and destruction activities within the scope of relevant legislation.
According to the Regulation on Deletion, Destruction or Anonymization of Personal Data published in the Official Gazette dated October 28, 2017, No. 30224 ("Regulation"), data controllers are obliged to prepare personal data retention and destruction policies in accordance with their personal data processing inventories. This Policy, prepared based on the aforementioned regulation, aims to determine the maximum retention periods for personal data processed by our Company, as well as the deletion, destruction, or anonymization processes and to define the roles and responsibilities of persons involved in these processes.
The scope of this Policy includes the maximum retention periods for personal data, the technical and administrative measures taken for lawful retention and destruction of personal data, the units responsible for related processes within our Company, and the recording environments;
2. DEFINITIONS
Electronic Environment: Environments where personal data can be created, read, modified, and written using electronic devices.
Non-Electronic Environment: All written, printed, visual, and other environments outside electronic environments.
Law: Law No. 6698 on the Protection of Personal Data.
Personal Data: Any information relating to an identified or identifiable natural person.
Processing of Personal Data: Any operation performed on personal data, whether fully or partially by automated means or otherwise as part of a data recording system, including obtaining, recording, storing, preserving, modifying, reorganizing, disclosing, transferring, acquiring, making accessible, classifying, or preventing use.
Data Controller: BULKOON FOOTWEAR AND LEATHER PRODUCTS INDUSTRY TRADE LIMITED COMPANY as a legal entity.
KVK Committee: The Personal Data Protection Committee appointed by the Data Controller to administratively monitor processes established under the Personal Data Protection Law and its sub-regulations.
Relevant Person: The natural person whose personal data is processed.
Board: Personal Data Protection Board.
Anonymization: Making personal data unidentifiable with any specific or identifiable natural person, even when matched with other data.
Destruction: Deletion, destruction, or anonymization of personal data.
Recording Environment: Any environment where personal data is processed either fully or partially automatically or otherwise as part of a data recording system.
Personal Data Processing Inventory: An inventory associating personal data processing activities with their purposes, data categories, recipient groups, and data subjects, detailing maximum retention periods, data transfers, and security measures.
Personal Data Retention and Destruction Policy/Policy: This policy that data controllers rely on to determine maximum retention periods and deletion, destruction, and anonymization procedures.
Periodic Destruction: Deletion, destruction, or anonymization carried out at recurring intervals when all conditions for processing personal data cease to exist, as specified in the Policy.
Relevant User: Persons processing personal data within the Data Controller’s organization or authorized by it, excluding those responsible for technical storage, protection, and backup of personal data.
Regulation: Regulation on Deletion, Destruction or Anonymization of Personal Data.
VERBIS: Data Controllers Registry Information System.
3. RECORDING ENVIRONMENTS
During our Company’s activities, personal data is collected from employees, job applicants, customers, potential customers, visitors, and supplier employees and officials. The collected personal data is stored in compliance with applicable legislation in the following environments:
Electronic Environments
Servers (domain, backup, email, database, web, file sharing, etc.)
Software (office software, portal, EBYS, VERBIS)
Information security devices (firewall, intrusion detection and prevention, log files, antivirus, etc.)
Personal computers (desktop, laptop)
Mobile devices (phone, tablet, etc.)
Optical disks (CD, DVD, etc.)
Removable storage (USB, memory card, etc.)
Printers, scanners, photocopiers
Non-Electronic Environments
Paper
Manual data recording systems (survey forms, service forms, job application forms)
Other written, printed, visual media
RESPONSIBILITY
To publish, keep updated, and monitor the implementation of this Policy, our Company’s Board of Directors will establish a KVK Committee authorized for all related matters. The KVK Committee consists of the Human Resources Manager, Administrative Affairs Manager, and IT Manager. The KVK Committee’s duties and responsibilities include;
Ensuring compliance with personal data retention periods,
Managing the personal data destruction process during periodic destruction periods,
Reviewing the Policy at least annually,
Preparing and publishing detailed Personal Data Retention and Destruction Procedures and other necessary procedures based on the Policy,
Assigning tasks and authorizations for the implementation of the Policy and procedures, organizing training on compliance with the Law,
Monitoring and planning audits of all technical and administrative measures taken pursuant to Article 12 of the Law,
Identifying and overseeing compliance requirements with the Law and relevant legislation, ensuring necessary coordination,
Tracking requests and applications made by data subjects and ensuring necessary actions to resolve issues related to the Law and/or Policy and procedures,
Managing relations with the Board.
5. REASONS FOR DATA RETENTION
Article 3 of the Law defines the concept of personal data processing, and Article 4 sets the principles for processing personal data as follows:
a) Compliance with lawfulness and fairness rules.
b) Accuracy and updating when necessary.
c) Processing for specific, explicit, and legitimate purposes.
d) Being relevant, limited, and proportionate to the purpose of processing.
e) Retention for the period prescribed by relevant legislation or necessary for the purpose of processing.
Articles 5 and 6 of the Law specify the conditions for processing personal data. Accordingly, personal data within our Company’s activities are retained for the period prescribed by relevant legislation or appropriate for our processing purposes.
5.1. LEGAL REASONS
Law No. 6698 on the Protection of Personal Data,
Turkish Code of Obligations No. 6098,
Turkish Commercial Code No. 6102,
Social Insurance and General Health Insurance Law No. 5510,
Law No. 5651 on Regulation of Publications on the Internet and Combating Crimes Committed through These Publications,
Occupational Health and Safety Law No. 6331,
Labour Law No. 4857,
Other secondary regulations in force under these laws.
5.2. PROCESSING PURPOSES REQUIRING RETENTION
Personal data held within our Company are retained for the purposes and reasons specified in the Law and our Personal Data Policy (accessible at https://bulkoon.com/kvk-politikasi).
6. TECHNICAL AND ADMINISTRATIVE MEASURES
Our Company takes all necessary technical and administrative measures appropriate to the nature of the personal data and its storage environment to securely store personal data and prevent unlawful processing and access.
These measures include but are not limited to the following, depending on the nature of the personal data and storage environment.
6.1. TECHNICAL MEASURES
Network and application security are ensured.
Closed system networks are used for personal data transfers over the network.
Key management is implemented.
Security measures are taken in IT system procurement, development, and maintenance.
Security of personal data stored in the cloud is ensured.
Authorization matrices for employees are established.
Access logs are regularly maintained.
Data masking measures are applied when necessary.
Up-to-date antivirus systems are used.
Firewalls are used.
Extra security measures are taken for personal data transferred on paper, and related documents are sent as confidential classified documents.
Personal data security is monitored.
Security measures are taken for physical environments containing personal data regarding entry and exit.
Physical environments containing personal data are protected against external risks (fire, flood, etc.).
Security of environments containing personal data is ensured.
Personal data minimization is practiced.
Personal data backups are made and their security is ensured.
User account management and authorization control systems are implemented and monitored.
Log records are maintained without user intervention.
Existing risks and threats are identified.
Special category personal data sent via email are always encrypted and sent using KEP or corporate mail accounts.
Intrusion detection and prevention systems are used.
Penetration testing is applied.
Cybersecurity measures are implemented and continuously monitored.
Encryption is applied.
Data loss prevention software is used.
6.2. ADMINISTRATIVE MEASURES
Disciplinary regulations including data security provisions exist for employees.
Regular training and awareness activities on data security are conducted for employees.
Corporate policies on access, information security, use, retention, and destruction have been prepared and implemented.
Confidentiality agreements are signed.
Access rights of employees with role changes or who leave the company are revoked.
Signed contracts include data security provisions.
Personal data security policies and procedures are established.
Personal data security issues are reported promptly.
Periodic and/or random internal audits are conducted and commissioned.
Protocols and procedures for special category personal data security are established and implemented.
Data processors are periodically audited for data security.
Awareness of data security is ensured among data processors.
7. REASONS REQUIRING DATA DESTRUCTION
Personal data stored within our Company are deleted, destroyed, or anonymized upon the following conditions;
Change or repeal of relevant legislation governing their processing,
The purpose requiring processing or retention ceases to exist,
In cases where processing is based solely on explicit consent, withdrawal of that consent by the relevant person,
Acceptance by our Company of a request for deletion or destruction of personal data made by the relevant person within their rights under Article 11 of the Law,
If our Company rejects a request for deletion, destruction, or anonymization, finds its response insufficient, or fails to respond within the legally prescribed period, and the relevant person files a complaint with the Board and the Board approves the request,
The maximum retention period requiring storage has expired and no condition justifies longer retention.
In such cases, personal data is deleted, destroyed, or anonymized upon request or ex officio by our Company.
7. DESTRUCTION METHODS
7.1. DELETION OF DATA
Making personal data inaccessible and unusable for Relevant Users.
Personal Data in Physical Environments: Data whose retention period has expired is made completely inaccessible and unusable. Blackout methods may be used, involving cutting out personal data on documents when possible, or otherwise obscuring it with permanent ink to prevent reading by others.
Personal Data in Electronic Environments: Data whose retention period has expired is deleted using software methods ensuring irrecoverability.
7.2. DESTRUCTION OF DATA
Making personal data completely inaccessible, unrecoverable, and unusable by anyone.
Data whose retention period has expired is destroyed using appropriate physical destruction or overwriting methods.
Network Devices: Switches, routers, etc., are destroyed by magnetization, physical destruction, or overwriting.
Flash-Based Media: Destroyed using manufacturer-recommended methods, physical destruction, or overwriting.
SIM Cards and Fixed Memory Cards: Destroyed by physical destruction or overwriting.
Optical Disks: Destroyed by physical methods.
Printers and Fingerprint Door Access Systems with Fixed Data Storage: Destroyed by physical destruction or overwriting.
Paper and Similar Media: Personal data on paper is destroyed using paper shredders.
7.3. ANONYMIZATION OF DATA
Making personal data unidentifiable with any specific or identifiable natural person, even when matched with other data. Anonymization involves removing or altering all direct and/or indirect identifiers in a data set to prevent identification of the individual or distinguishability within a group. Data that no longer points to a specific person is considered anonymized. Methods include grouping, masking, derivation, generalization, randomization, and other techniques breaking the link to identity. The risk of re-identification through interventions is assessed and appropriate measures taken.
8. RETENTION PERIODS UNDER RELEVANT LEGISLATION
Retention periods are determined for all personal data stored within our Company. Priority is given to relevant legislation; if no period is specified, retention is based on the purpose of processing. These periods are recorded in the Personal Data Inventory and VERBIS.
Unless interrupted or suspended by legal reasons, personal data listed in the Personal Data Processing Inventory are retained according to the legal regulations in the table below and destroyed at the first periodic destruction date after the retention period expires.
Data Category
Retention Period
Identity
Legal relationship/employment contract/termination + 10 years
Contact
Legal relationship/employment contract/termination + 10 years
Location
Legal relationship/employment contract/termination + 10 years
Legal Proceedings
Until final court decision or statute of limitations expires
Customer Transactions
Legal relationship/employment contract/termination + 10 years
Transaction Security
5 years
Risk Management
Legal relationship/employment contract/termination + 10 years
Finance
Legal relationship/employment contract/termination + 10 years
Marketing
Legal relationship/employment contract/termination + 10 years
9. PERIODIC DESTRUCTION INTERVAL
According to Article 11 of the Regulation, our Company has set the periodic destruction interval at 6 months.
When a data subject requests deletion or destruction of their personal data, the request is evaluated based on whether the processing conditions still exist. If all processing conditions have ceased, the data is deleted, destroyed, or anonymized. If not, the request is rejected with explanation. Requests are concluded within 30 days and the data subject is notified.
All deletion, destruction, and anonymization actions are recorded and these records are kept for at least 3 years, excluding other legal obligations.
10. POLICY REVIEW PERIOD
The Policy is reviewed and updated by the KVK Committee as needed.
11. POLICY ENFORCEMENT
This Policy is considered effective and binding upon publication on our Company’s website.
