KVK Policy

You are here:

Gencer Otomotiv Karasör Ve Beyaz Eşya Sanayi Ticaret Limited Şirketi  

CORPORATE PERSONAL DATA PROTECTION POLICY

GENCER AUTOMOTIVE CAR BODY AND WHITE GOODS INDUSTRY TRADE LIMITED COMPANY 

CORPORATE PERSONAL DATA PROTECTION POLICY

1. PURPOSE

The right of every individual to request the protection of personal data about him/herself is a sacred right arising from the Constitution. Gencer Otomotiv Karasör Ve Beyaz Eşya Sanayi Ticaret Limited Şirketi
we consider fulfilling the requirements of this right as one of our most valuable duties. Therefore, we attach importance to the processing and protection of your personal data in accordance with the law.
As a result of the importance we attach to the protection of personal data, the Corporate Personal Data Protection Policy has been prepared to determine the principles and procedures we apply when processing and protecting personal data.

2. SCOPE

The Policy covers all personal data managed by Gencer Otomotiv Karasör Ve Beyaz Eşya Sanayi Ticaret Limited Şirketi and includes all kinds of operations performed on the data such as obtaining, recording, storing, storing, preserving, modifying, rearranging, disclosing, transferring, taking over, making it available, classifying or preventing its use by fully or partially automatic means or by non-automatic means provided that it is part of any data recording system.
The Policy relates to all personal data of Gencer Otomotiv Karasör Ve Beyaz Eşya Sanayi Ticaret Limited Şirketi's partners, officials, customers, employees, supplier officials and employees, and third parties.
Gencer Kasa may change the Policy for the purposes of compliance with the legislation and the decisions of the Personal Data Protection Authority and better protection of personal data.

3. DEFINITIONS

4. GENERAL PRINCIPLES

Gencer Kasa checks the compliance of the data to be processed with the following principles during the preparation phase of each new workflow that requires personal data processing. Inappropriate workflows are not implemented.
Gencer Kasa processes personal data;
(I) Complies with the law and the rules of honesty.
(II) Ensure that personal data is accurate and, where necessary, up to date.
(III) Ensure that the purpose of processing is specific, explicit and legitimate.
(IV) Checks that the processed data is related to the purpose of processing, that it is limited to the extent necessary to be processed and that it is proportionate.
(V) Retain the data only for as long as stipulated in the relevant legislation or as necessary for the purpose of processing, and destroy the data when the purpose of processing is no longer necessary.

5. DUTIES AND RESPONSIBILITIES

The Personal Data Protection Commission has been established within Gencer Kasa to manage this Policy and other relevant procedures regarding the processing of personal data and to ensure the enforcement of the Policy. General Manager, Human Resources Officer, Financial Affairs Officer and Quality Officer constitute the Commission. Gencer Kasa also receives KVKK consultancy support when necessary to comply with the Personal Data Protection Law No. 6698. The Commission may invite the KVKK consultant to its meetings if deemed necessary.
The duties and responsibilities of the Commission are set out below.
(I)Ordinarily meets every 6 months. Extraordinary meetings may be convened if circumstances require (e.g. in the event of a possible data breach).
(II) Discuss the aspects of the Policy that need to be changed/improved.
(III) Determines the issues that can be fulfilled for the lawful processing and protection of personal data.
(IV)The Commission determines the steps that can be taken to raise awareness of the LPPD within the company and among business partners.
(V) Identifies the risks that may be encountered in the processing and protection of personal data and takes the necessary administrative and technical measures.
(VI) Provides liaison and manages relations with the Institution.
(VII) Evaluates the requests received from the Relevant Person.
(VIII) Follows periodic destruction processes.
(IX) Updates the Data Inventory.
(X) Makes assignments related to the above-mentioned matters.

6. MEASURES TAKEN FOR DATA SECURITY

Gencer Kasa takes all necessary technical and administrative measures to ensure the appropriate level of security in order to (i) prevent unlawful processing of personal data, (ii) prevent unlawful access to personal data, (iii) ensure the preservation of personal data.

6.1. Technical Measures

(I)Network security and application security are ensured.
(II) Security measures are taken within the scope of procurement, development and maintenance of information technology systems.
(III) Access logs are kept regularly.
(IV) Up-to-date anti-virus systems are used.
(V) Firewalls are used.
(VI) Necessary security measures are taken for entry and exit to and from physical environments containing personal data.
(VII) Physical environments containing personal data are secured against external risks (fire, flood, etc.).
(VIII) Security of media containing personal data is ensured.
(IX) Personal data is backed up and the security of backed up personal data is also ensured.
(X) User account management and authorization control system are implemented and monitored.
(XI) Log records are kept in such a way that there is no user intervention.
(XII) Intrusion detection and prevention systems are used.
Encryption is performed (XIII).

6.2. Administrative Measures

(I) There are disciplinary arrangements in place for employees that include data security provisions.
(II) Training and awareness raising activities on data security for employees are carried out at regular intervals.
(III) Institutional policies on access, information security, use, storage and disposal have been prepared and started to be implemented.
(IV) Data masking measures are applied when necessary.
(V) Confidentiality undertakings are made.
(VI) An authorization matrix has been created for employees.
(VII) Employees who are reassigned or leave their jobs are de-authorized in this area.
(VIII) The signed contracts contain data security provisions.
(IX) Personal data security policies and procedures have been determined.
(X)Personal data security issues are reported quickly.
(XI) Personal data security is monitored.
(XII) Personal data is minimized as much as possible.
(XIII) Internal periodic and/or random audits are conducted and commissioned.
(XIV) Existing risks and threats have been identified.
(XV) Protocols and procedures for the security of sensitive personal data have been determined and implemented.
(XVI) If sensitive personal data is to be sent via electronic mail, it is sent encrypted and using a KEP or corporate mail account.
(XVII) Awareness of data processing service providers on data security is ensured.

7. RIGHTS OF THE DATA SUBJECT IN RELATION TO PERSONAL DATA 

The relevant person may apply to Gencer Kasa and make a request on the following issues:
(I)To learn whether their personal data is being processed,
(II) Request information if their personal data has been processed,
(III) To learn the purpose of processing personal data and whether they are used in accordance with their purpose,
(IV) Learning the third parties to whom personal data are transferred domestically or abroad,
(V) To request correction of personal data in case of incomplete or incorrect processing and to request notification of the transaction made within this scope to third parties to whom personal data is transferred,
(VI) Requesting the deletion, destruction or anonymization of personal data in the event that the reasons requiring its processing disappear, although it has been processed in accordance with the provisions of KVKK and other relevant laws, and requesting that the transaction made within this scope be notified to third parties to whom personal data is transferred,
(VII) To object to the occurrence of a result against them by analyzing their processed data exclusively through automated systems,
(VIII) In case of damage due to unlawful processing of personal data, to demand the compensation of the damage.

8. BREACH NOTIFICATIONS

Gencer Kasa employees report to the Committee the work, action or fact that they think violates the provisions of the KVKK and / or the Policy. The Committee convenes if deemed necessary following this violation notification and creates an action plan regarding the violation.
If the breach has occurred through the unlawful acquisition of personal data by others, the Commission shall notify the relevant person and the Board within 72 hours within the scope of the Board's decision dated 24.01.2019 and numbered 2019/10.

9. AMENDMENTS

Amendments to the Policy are prepared by the Commission and submitted to the approval of the Gencer Kasa Board of Directors. The updated Policy may be sent to employees via e-mail or published on the website.

10. EFFECTIVE DATE

This version of the Policy was approved by the Board of Directors on 01.01.2023 and entered into force.