Data Destruction Policy
PERSONAL DATA STORAGE and DESTRUCTION POLICY
1. PURPOSE AND SCOPE
BULKOON FOOTWEAR AND LEATHER PRODUCTS INDUSTRY TRADE LIMITED COMPANY (“Our Company”) is committed to complying with the regulations regarding the protection, processing, and destruction of personal data as required by relevant legal regulations. This Personal Data Storage and Destruction Policy (“Policy”) contains the framework and principles for necessary storage and destruction activities under the relevant legislation.
According to the Regulation on the Deletion, Destruction, or Anonymization of Personal Data published in the Official Gazette dated October 28, 2017, and numbered 30224 (“Regulation”), data controllers are obliged to prepare a personal data storage and destruction policy in accordance with the personal data processing inventory. The purpose of this Policy, prepared based on the above regulation, is to determine the maximum periods necessary for the deletion, destruction, or anonymization processes of personal data processed by our Company and to define the roles and responsibilities of individuals involved in these processes.
The scope of this Policy includes the maximum storage periods of personal data and the technical and administrative measures taken to store and destroy personal data in accordance with the law, as well as the units involved in carrying out the relevant processes within our Company and the recording environments.
2. DEFINITIONS
Electronic Environment: Environments where personal data can be created, read, modified, and written with electronic devices.
Non-Electronic Environment: All written, printed, visual, etc. environments outside electronic environments.
Law: The Law on the Protection of Personal Data No. 6698.
Personal Data: Any information relating to an identified or identifiable natural person.
Processing of Personal Data: Any operation performed on personal data, such as collection, recording, storage, alteration, disclosure, transfer, and destruction.
Data Controller: BULKOON FOOTWEAR AND LEATHER PRODUCTS INDUSTRY TRADE LIMITED COMPANY as a legal entity.
KVK Committee: The committee established to carry out the administrative follow-up of the processes created under the Personal Data Protection Law and its subordinate regulations, appointed by the Data Controller.
Relevant Person: The natural person whose personal data is processed.
Board: The Personal Data Protection Board.
Anonymization: The process of making personal data no longer associated with an identifiable natural person.
Destruction: The deletion, destruction, or anonymization of personal data.
Recording Environment: Any environment where personal data is processed either fully or partially automatically or as part of a data recording system.
Personal Data Processing Inventory: An inventory detailing the purposes of processing personal data, data categories, recipient groups, and maximum retention periods.
Periodic Destruction: The deletion, destruction, or anonymization processes that will be carried out automatically at regular intervals when all conditions for processing personal data cease to exist.
Relevant User: Individuals who process personal data within the Data Controller's organization, except for those responsible for the technical storage, protection, and backup of personal data.
Regulation: The Regulation on the Deletion, Destruction, or Anonymization of Personal Data.
VERBIS: Data Controllers Registry Information System.
3. RECORDING ENVIRONMENTS
During the activities of our Company, personal data is collected from employees, job candidates, customers, potential customers, visitors, and supplier employees and representatives, and the collected personal data is stored in the environments shown below in accordance with relevant legal regulations:
Electronic Environments: Servers (domain, backup, email, database, web, file sharing, etc.), Software (office software, portal, EBYS, VERBIS), Information security devices (firewall, intrusion detection and prevention, log files, antivirus, etc.), Personal computers (desktop, laptop), Mobile devices (phones, tablets, etc.), Optical disks (CD, DVD, etc.), Removable storage (USB, memory card, etc.), Printers, scanners, photocopiers.
Non-Electronic Environments: Paper, manual data recording systems (survey forms, service forms, job application forms), other written, printed, visual environments.
RESPONSIBILITY
To publish, maintain, and monitor the implementation of this Policy, our Company will establish a KVK Committee authorized by the Board of Directors, which will consist of the Human Resources Manager, Administrative Affairs Manager, and Information Technology Manager. The KVK Committee will perform the following duties and responsibilities:
Ensure compliance with the personal data storage period.
Manage the personal data destruction process during the periodic destruction period.
Review the Policy at least annually.
Prepare and publish the Personal Data Storage and Destruction Procedure and other necessary procedures based on the Policy.
Distribute duties necessary for the implementation of the Policy and procedures, authorize individuals as deemed appropriate, and organize training on compliance with the Law.
Monitor and plan the implementation of all technical and administrative measures taken under Article 12 of the Law.
Identify the necessary actions to ensure compliance with the Law and relevant regulations, oversee their implementation, and ensure necessary coordination.
Follow up on applications and requests made by natural persons whose personal data are processed and ensure necessary actions are taken to resolve any issues arising from the implementation of the Law and/or the Policy and procedures.
Manage relations with the Board.
5. REASONS FOR STORING DATA
The concept of processing personal data is defined in Article 3 of the Law, and Article 4 stipulates that personal data must be processed in accordance with the following principles:
a) Compliance with the law and honesty.
b) Accuracy and, when necessary, up-to-date.
c) Processed for specific, explicit, and legitimate purposes.
d) Adequate, relevant, and limited to what is necessary for the purposes for which they are processed.
e) Retained only for the period necessary for the purposes for which the personal data are processed or as stipulated by relevant legislation.
Articles 5 and 6 of the Law list the conditions for processing personal data. Accordingly, personal data will be stored for the duration stipulated by relevant legislation or for the duration necessary for our processing purposes.
5.1. LEGAL REASONS
The Law on the Protection of Personal Data No. 6698, the Turkish Code of Obligations No. 6098, the Turkish Commercial Code No. 6102, the Social Insurance and General Health Insurance Law No. 5510, the Law on Regulating Publications Made on the Internet and Combating Crimes Committed Through These Publications No. 5651, the Occupational Health and Safety Law No. 6331, the Labor Law No. 4857, and other secondary regulations in force under these laws.
5.2. PROCESSING PURPOSES REQUIRING STORAGE
The personal data held by our Company is stored in accordance with the Law and our Personal Data Policy (which can be accessed at https://bulkoon.com/kvk-politikasi) for the purposes and reasons stated here.
6. TECHNICAL AND ADMINISTRATIVE MEASURES
OUR COMPANY takes all necessary technical and administrative measures appropriate to the nature of the personal data and the environment in which it is held to ensure the secure storage of personal data and to prevent unlawful processing and access. These measures include, but are not limited to, the following:
6.1. TECHNICAL MEASURES
Network security and application security are ensured.
A closed system network is used for personal data transfers over the network.
Key management is implemented.
Security measures are taken regarding the procurement, development, and maintenance of information technology systems.
The security of personal data stored in the cloud is ensured.
A user authorization matrix has been created for employees.
Access logs are maintained regularly.
Data masking measures are applied when necessary.
Current antivirus systems are used.
Firewalls are utilized.
Extra security measures are taken for personal data transferred in paper format, and relevant documents are sent in confidentiality-rated document format.
The security of personal data is monitored.
Necessary security measures are taken regarding access to physical environments containing personal data.
The security of physical environments containing personal data against external risks (fire, flood, etc.) is ensured.
The security of environments containing personal data is ensured.
Personal data is minimized as much as possible.
Personal data is backed up, and the security of backed-up personal data is also ensured.
User account management and authorization control systems are implemented and monitored.
Log records are maintained without user intervention.
Current risks and threats have been identified.
If sensitive personal data is to be sent via email, it is sent encrypted and using a KEP or corporate email account.
Intrusion detection and prevention systems are used.
Pentest is conducted.
Cybersecurity measures have been taken and their implementation is continuously monitored.
Encryption is performed.
Data loss prevention software is used.
6.2. ADMINISTRATIVE MEASURES
There are disciplinary regulations containing data security provisions for employees.
Periodic training and awareness activities on data security are conducted for employees.
Corporate policies on access, information security, usage, storage, and destruction have been prepared and implemented.
Confidentiality agreements are made.
The authorizations of employees who change positions or leave the company are revoked.
Signed contracts contain data security provisions.
Personal data security policies and procedures have been established.
Data security issues are reported quickly.
Periodic and/or random audits are conducted and carried out within the institution.
Protocols and procedures for the security of sensitive personal data have been established and implemented.
Data processors are periodically audited for data security.
Data processors are made aware of data security.
7. REASONS FOR DATA DESTRUCTION
The personal data stored by our Company will be deleted, destroyed, or anonymized upon the request of the relevant person in the following cases:
Amendment or repeal of the relevant legal provisions that constitute the basis for processing.
The purpose for processing or storing has ceased to exist.
In cases where processing personal data is based solely on explicit consent, the relevant person withdraws their explicit consent.
Upon the acceptance of the request for deletion and destruction of personal data by our Company in accordance with the rights of the relevant person under Article 11 of the Law.
If our Company rejects the request made by the relevant person for the deletion, destruction, or anonymization of their personal data, finds the response insufficient, or does not respond within the period stipulated by the Law, the relevant person may lodge a complaint with the Board, and if this request is deemed appropriate by the Board.
When the maximum period for storing personal data has expired and there are no conditions justifying the retention of personal data for a longer period.
7.1. DELETION OF DATA
The process of making personal data inaccessible and unusable for Relevant Users in any way. For personal data in physical environments, those whose storage period has expired will be made inaccessible and unusable in any way. In this context, the blackout method may be used on the relevant data. The blackout method involves making personal data on the relevant document invisible to other users by cutting it off where possible or, where not possible, making it unreadable with irreversible and technological solutions using permanent ink.
For personal data in electronic environments, those whose storage period has expired will be deleted using methods that ensure the data is irretrievably deleted from the relevant software.
7.2. DESTRUCTION OF DATA
The process of making personal data inaccessible, unrecoverable, and unusable by anyone in any way. For personal data in such environments, those whose storage period has expired will be destroyed using the appropriate physical destruction or overwriting methods.
Network Devices: Destroyed using appropriate methods such as magnetization, physical destruction, or overwriting in switches, routers, etc.
Flash-Based Environments: Destroyed using methods recommended by the relevant manufacturer or appropriate physical destruction or overwriting methods.
SIM Cards and Fixed Memory Cards: Destroyed using appropriate physical destruction or overwriting methods.
Optical Disks: Destroyed using physical methods.
Data Recording Environment Fixed Printers, Fingerprint Door Access Systems: Destroyed using appropriate physical destruction or overwriting methods.
Paper and similar environments: Personal data in paper format is destroyed using paper shredders.
7.3. ANONYMIZATION OF DATA
The process of making personal data no longer associated with an identifiable natural person, even when matched with other data. Anonymization involves removing or altering all direct and/or indirect identifiers in a dataset to prevent the identification of the relevant person or to lose the ability to be distinguished within a group or crowd in a way that cannot be associated with a natural person. Data that does not point to a specific person as a result of preventing or losing these characteristics is considered anonymized data. All disconnection processes carried out using methods such as grouping, masking, deriving, generalizing, and randomizing applied to records in the data recording system where personal data is held are referred to as anonymization methods. The risk of reversing anonymized personal data through various interventions and the potential for anonymized data to revert to identifiable and distinguishable natural persons is considered, and actions are taken accordingly.
8. STORAGE PERIODS OF DATA UNDER RELEVANT LEGISLATION
Storage periods for all Personal Data held by our Company are determined. In determining the storage periods, the relevant legislation is primarily considered, and if there is no period stipulated by the relevant legislation, the duration necessary for the purpose of processing Personal Data is taken into account. Relevant periods are included in the Personal Data Inventory and VERBIS. Personal Data mentioned in the Personal Data Processing Inventory will be stored in accordance with the legal regulations listed in the table below, unless there is any legal situation that interrupts or suspends the statute of limitations, and will be destroyed on the first periodic destruction date following the storage period.
Data CategoryData Storage PeriodIdentityLegal relationship/employment contract/end of employment +10 YearsContactLegal relationship/employment contract/end of employment +10 YearsLocationLegal relationship/employment contract/end of employment +10 YearsLegal ActionUntil the relevant court decision becomes final or the statute of limitations expiresCustomer TransactionLegal relationship/employment contract/end of employment +10 YearsTransaction Security5 YearsRisk ManagementLegal relationship/employment contract/end of employment +10 YearsFinanceLegal relationship/employment contract/end of employment +10 YearsMarketingLegal relationship/employment contract/end of employment +10 Years
9. PERIODIC DESTRUCTION PERIOD
In accordance with Article 11 of the Regulation, our Company has determined the periodic destruction period as 6 months. When a request is made to our Company to delete or destroy personal data, the relevant request is evaluated based on whether the conditions for processing personal data have ceased to exist. If the conditions for processing personal data have completely ceased to exist, our Company will delete, destroy, or anonymize the personal data subject to the request. If the conditions for processing personal data have not completely ceased to exist, the relevant request will be rejected with an explanation of the reason. Requests will be concluded and notified to the relevant person within 30 days in all cases. All transactions related to the deletion, destruction, and anonymization of personal data are recorded, and these records will be kept for at least 3 (three) years, excluding other legal obligations.
10. POLICY UPDATE PERIOD
The Policy will be reviewed by the KVK Committee as needed, and necessary sections will be updated.
11. EFFECTIVENESS OF THE POLICY
This Policy is deemed to have come into effect upon publication on our Company's website. It is considered valid and binding from this date.