Personal data protection policy (KVKK)
Last updated:
Personal Data Protection and Processing Policy
Target audience: All natural persons whose personal data is processed by KEF Endüstriyel İmalat İthalat İhracat Turizm Ticaret Limited Şirketi.
Prepared by: Personal Data Protection Committee of KEF Endüstriyel İmalat İthalat İhracat Turizm Ticaret Limited Şirketi.
Approved by: Management of KEF Endüstriyel İmalat İthalat İhracat Turizm Ticaret Limited Şirketi.
Version: 1.0
1. Introduction
KEF Endüstriyel İmalat İthalat İhracat Turizm Ticaret Limited Şirketi (“Kef”) is a leading company operating in the industrial kitchen and refrigeration sector with an experienced and dynamic team.
“Kef” attaches importance to the protection of personal data in its activities and regards it as one of the priorities in its business and operations. The “Kef” Personal Data Protection and Processing Policy (the “Policy”) is the core framework for aligning the “Kef” organisation and its business processes with the procedures and principles for processing personal data set out in Turkish Personal Data Protection Law No. 6698 (the “Law”). In line with the principles of this Policy, “Kef” processes and protects personal data with a high level of responsibility and awareness, and ensures the necessary transparency by informing data subjects.
1.1. Purpose
The purpose of this Policy is to align the procedures and principles set out in the Law and other relevant legislation with the “Kef” organisation and its processes, and to ensure their effective implementation. Through this Policy, “Kef” takes all administrative and technical measures for the processing and protection of personal data, establishes the necessary internal procedures, raises awareness and provides all necessary training. All necessary measures are taken, and appropriate and effective control mechanisms are established, to ensure that shareholders, officers, employees and business partners comply with the requirements of the Law.
1.2. Scope
The Policy covers all personal data obtained in the business processes of “Kef” by automated means, or by non-automated means provided they form part of a data filing system.
1.3. Legal basis
The Policy is based on the Law and the relevant legislation. Personal data is processed to fulfil legal obligations arising from Public Procurement Law No. 4734, State Tender Law No. 2886, Identity Notification Law No. 1774, Labour Law No. 4857, Occupational Health and Safety Law No. 6331, Social Insurance and General Health Insurance Law No. 5510, Unemployment Insurance Law No. 4447, Turkish Commercial Code No. 6102, Tax Procedure Law No. 213 and other relevant legislation.
In the event of any inconsistency between the legislation in force and the Policy, the legislation in force applies. The requirements of the relevant legislation are turned into “Kef” practices through the Policy.
1.4. Definitions
Explicit consent: Consent relating to a specific matter, based on information and given freely.
Application form: The form, prepared in accordance with the Law and the Communiqué on the Procedures and Principles of Applications to the Data Controller issued by the Personal Data Protection Authority, through which data subjects apply to the data controller to exercise their rights.
Relevant user: Persons who process personal data within the data controller's organisation or under the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.
Destruction: The erasure, destruction or anonymisation of personal data.
Recording medium: Any medium containing personal data processed by fully or partially automated means, or by non-automated means provided they form part of a data filing system.
Personal data: Any information relating to an identified or identifiable natural person.
Processing of personal data: Any operation performed on data, such as obtaining, recording, storing, preserving, altering, reorganising, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, by fully or partially automated means, or by non-automated means provided they form part of a data filing system.
Anonymisation of personal data: Rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even when matched with other data.
Data subject: The natural person whose personal data is processed by or on behalf of “Kef”.
Erasure of personal data: Rendering personal data inaccessible and unusable in any way for the relevant users.
Destruction of personal data: Rendering personal data inaccessible, irretrievable and unusable in any way by anyone.
Board: The Personal Data Protection Board.
Authority: The Personal Data Protection Authority.
Special categories of personal data: Data relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sex life, criminal convictions and security measures, as well as biometric and genetic data.
Periodic destruction: The erasure, destruction or anonymisation carried out ex officio at recurring intervals, as specified in the personal data retention and destruction policy, when all the conditions for processing personal data set out in the Law have ceased to exist.
Data processor: A natural or legal person who processes personal data on behalf of the data controller under the authority granted by the data controller.
Data filing system: A recording system in which personal data is structured and processed according to specific criteria.
Data subject / relevant person: The natural person whose personal data is processed.
Data controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.
Data controller representative: The natural person appointed under the Law to perform the data controller's duties under the relevant articles of the Law.
Regulation: The Regulation on the Erasure, Destruction or Anonymisation of Personal Data published in the Official Gazette of 28 October 2017.
2. Protection of personal data
2.1. Ensuring the security of personal data
To prevent the unlawful disclosure of, access to or transfer of personal data, or other security issues that may arise, “Kef” takes the necessary measures set out in Article 12 of the Law according to the nature of the personal data. “Kef” takes measures and carries out audits to ensure the required level of data security in line with the guidelines published by the Personal Data Protection Authority.
2.2. Protection of special categories of personal data
Measures to protect data relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sex life, criminal convictions and security measures, as well as biometric and genetic data, are applied with care and the necessary audits are carried out.
2.3. Raising awareness of personal data protection and processing
“Kef” provides the necessary training to the relevant persons to raise awareness of the lawful processing of, access to and storage of personal data and the exercise of rights.
To increase employees' awareness of personal data protection, “Kef” establishes the necessary business processes and obtains support from consultants where needed. Shortcomings encountered in practice and the results of training are evaluated by “Kef” management; new training is organised where necessary in line with these evaluations and changes in legislation.
3. Processing of personal data
3.1. Processing personal data in compliance with the law
Personal data is processed in compliance with the law in line with the following principles:
Processing lawfully and in good faith: Personal data is processed lawfully and in good faith, to the extent required by and limited to business processes, without harming people's fundamental rights and freedoms.
Keeping personal data accurate and up to date: The necessary measures are taken, and planned and scheduled work is carried out, to keep processed personal data accurate and up to date.
Processing for specific, explicit and legitimate purposes: Personal data is processed in connection with legitimate purposes defined and disclosed in the business processes carried out.
Being relevant, limited and proportionate to the purpose of processing: Personal data is collected in the nature and to the extent required by business processes and processed only for the specified purposes.
Retaining data only for as long as necessary: Personal data is retained for the period set out in the relevant legislation or required for the purpose of processing. Where the legislation sets a retention period, that period is observed; otherwise, the period necessary for the purpose of processing applies. Personal data whose retention period has expired is destroyed by erasure, destruction or anonymisation in line with periodic destruction intervals or upon the data subject's application.
3.2. Conditions for processing personal data
Personal data is processed on the basis of the data subject's explicit consent or one or more of the other conditions set out below.
Explicit consent of the data subject: Personal data is processed with the explicit consent of the data subject. Explicit consent relates to a specific matter, is based on information and is given freely.
Cases where explicit consent is not required: Where any of the following conditions apply, personal data may be processed without seeking the data subject's explicit consent:
Expressly provided for by law: There is an explicit provision in the law regarding the processing of personal data.
Physical impossibility: Processing is necessary to protect the life or physical integrity of a person, or of another person, who is unable to give consent due to physical impossibility or whose consent is not legally valid.
Conclusion or performance of a contract: Processing is directly related to the conclusion or performance of a contract to which the data subject is a party.
Legal obligation: Processing is necessary for “Kef” to fulfil its legal obligations.
Made public: The data subject has made their personal data public; in this case the data may be processed only for the purpose for which it was made public.
Establishing or protecting a right: Processing is necessary for the establishment, exercise or protection of a right.
Legitimate interest: Processing is necessary for the legitimate interests of “Kef”, provided that it does not harm the fundamental rights and freedoms of the data subject.
3.3. Processing of special categories of personal data
“Kef” processes special categories of personal data in accordance with the principles set out in the Law and this Policy, using the methods determined by the Board and taking all necessary administrative and technical measures, on the following basis:
Special categories of personal data other than health and sex life may be processed without the data subject's explicit consent where the law expressly provides for their processing. In cases not expressly provided for by law, the data subject's explicit consent is obtained.
Special categories of personal data relating to health and sex life may be processed without explicit consent by persons under a duty of confidentiality or by authorised institutions and organisations for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of health services and their financing. Otherwise, the data subject's explicit consent is obtained.
3.4. Informing the data subject
“Kef” informs data subjects, in accordance with the relevant legislation, of the purposes for which their personal data is processed, with whom and for what purposes it is shared, the methods by which it is collected, the legal grounds, and the rights they have. In this context, other policy documents and privacy notices prepared within the framework of the Policy are applied.
3.5. Transfer of personal data
In line with the purposes of processing and by taking the necessary security measures, “Kef” may lawfully transfer personal data and special categories of personal data to third parties (third-party companies, group companies and third-party natural persons). Transfers are carried out in accordance with Articles 8 and 9 of the Law.
Transfer of personal data: As a rule, the data subject's explicit consent is required for the transfer of personal data. However, where one or more of the following conditions apply, personal data may be transferred to third parties by taking all necessary security measures, including the methods prescribed by the Board:
It is expressly provided for by law,
It is directly related to and necessary for the conclusion or performance of a contract,
It is necessary for “Kef” to fulfil its legal obligations,
It is limited to the purpose of making the data public, provided the data has been made public by the data subject,
It is necessary for the establishment, exercise or protection of the rights of “Kef”, the data subject or third parties,
It is necessary for the legitimate interests of “Kef”, provided that it does not harm the fundamental rights and freedoms of the data subject,
It is necessary to protect the life or physical integrity of a person, or of another person, who is unable to give consent due to physical impossibility or whose consent is not legally valid.
The transfer of personal data abroad is carried out in accordance with the conditions and safeguards set out in Article 9 of the Law and the relevant legislation.
Transfer of special categories of personal data: Special categories of personal data may be transferred in accordance with the principles set out in the Policy and by taking all necessary administrative and technical measures, including the methods to be determined by the Board, under the following conditions:
Special categories of personal data other than health and sex life: without the data subject's explicit consent where the law contains an explicit provision, and otherwise with their explicit consent.
Special categories of personal data relating to health and sex life: without explicit consent by persons under a duty of confidentiality or by authorised institutions and organisations for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of health services and their financing; otherwise with explicit consent.
4. Personal data inventory
In its human resources, accounting, occupational health and safety and workplace medicine, production, sales and marketing, technical service, import, export, purchasing, project and R&D business processes, “Kef” processes the personal data of the following data subject groups in connection with the specified processing purposes: job applicants, employees, shareholders/partners, potential buyers of products or services, interns, supplier representatives, purchasers of products or services, parents/guardians/representatives and visitors. The processing purposes by data category and the data subject groups are registered, together with “Kef” company information, in VERBİS (the Data Controllers' Registry Information System).
Personal data is processed by informing the relevant persons in accordance with Article 10 of the Law and other legislation, on the basis of and limited to at least one of the processing conditions set out in Articles 5 and 6 of the Law, and in line with the general principles of the Law, in particular those set out in Article 4.
Personal data may be shared, for the specified purposes and on the basis set out in section “3.5. Transfer of personal data” of the Policy, with natural persons or private legal entities, shareholders, business partners, affiliates and subsidiaries, suppliers, authorised public institutions and organisations, private insurance companies, auditors, consultants and domestic organisations from which services are obtained or with which we cooperate. No data is transferred to foreign countries.
5. Measures to protect personal data
“Kef” takes the necessary technical and administrative measures to protect the personal data it processes in accordance with the procedures and principles set out in the Law, carries out the necessary audits in this context, and conducts awareness and training activities.
If, despite all technical and administrative measures taken, processed personal data is obtained by third parties through unlawful means, “Kef” notifies the data subject and the Board of this as soon as possible.
6. Retention and destruction of personal data
“Kef” retains personal data for the period set out in the relevant legislation or required for the purpose of processing. Where the legislation sets a period, personal data is retained accordingly; where no legal period is set, it is retained for as long as necessary for the purpose of processing. At the end of the specified retention periods, personal data is destroyed by erasure, destruction or anonymisation in line with periodic destruction intervals or upon the data subject's application.
7. Rights of data subjects and how to exercise them
7.1. Rights of the data subject
Under Article 11 of the Law, data subjects have the right to:
Learn whether their personal data is being processed,
Request information about the processing if their personal data has been processed,
Learn the purpose of the processing and whether the data is used in line with that purpose,
Know the third parties, in Türkiye or abroad, to whom their personal data is transferred,
Request the correction of personal data that is incomplete or inaccurate, and request that third parties to whom the data has been transferred be notified of this,
Request the erasure or destruction of personal data where the reasons for processing no longer exist, even though it was processed in accordance with the Law and other applicable laws, and request that third parties to whom the data has been transferred be notified of this,
Object to a result that is to their detriment arising from the analysis of the processed data exclusively by automated systems,
Claim compensation for damage suffered as a result of the unlawful processing of their personal data.
7.2. Exercising rights
Data subjects may submit their requests regarding the rights listed in section 7.1 to “Kef” using the methods determined by the Board. Data subjects and those entitled to apply on their behalf may apply in writing by completing the “Data Subject Application Form” (Annex 1) and sending it to Ferhatpaşa Mah. G-27 Sk. No:17, 34888 Ataşehir / Istanbul, Türkiye, or to the e-mail address kef@kef.com.tr.
7.3. Responding to applications
“Kef” concludes applications made by data subjects in accordance with the Law and other legislation. Duly submitted requests are concluded free of charge as soon as possible and within 30 (thirty) days at the latest. However, if the process involves an additional cost, a fee may be charged according to the tariff set by the Board.
7.4. Rejection of an application
“Kef” may reject an applicant's request, stating its reasons, in the following cases:
Personal data is processed for purposes such as research, planning and statistics by being anonymised through official statistics,
Personal data is processed for artistic, historical, literary or scientific purposes, or within the scope of freedom of expression, provided that this does not violate national defence, national security, public safety, public order, economic security, privacy or personal rights, or constitute a crime,
Personal data is processed within the scope of preventive, protective and intelligence activities carried out by public institutions and organisations authorised by law to ensure national defence, national security, public safety, public order or economic security,
Personal data is processed by judicial or enforcement authorities in connection with investigation, prosecution, trial or enforcement proceedings,
Processing personal data is necessary for the prevention of crime or for a criminal investigation,
The personal data being processed has been made public by the data subject themselves,
Processing personal data is necessary for the performance of supervisory or regulatory duties, or for disciplinary investigation or prosecution, by public institutions and organisations and professional organisations with public institution status authorised by law,
Processing personal data is necessary to protect the economic and financial interests of the State in relation to budgetary, tax and financial matters,
The data subject's request is likely to hinder the rights and freedoms of others,
The request requires disproportionate effort,
The requested information is publicly available.
7.5. Right to complain to the Board
Under Article 14 of the Law, if the application is rejected, the response is found insufficient or no response is given in time, the data subject may file a complaint with the Board within thirty days from the date they learn of the response of “Kef”, and in any case within sixty days from the date of application.
7.6. Information that may be requested from the applicant
“Kef” may request information from the applicant to determine whether they are the data subject, and may ask the applicant questions to clarify matters in the application.
8. Implementation
The Policy has been approved by management and put into effect. The technical implementation of the Policy is ensured by the “Personal Data Retention and Destruction Policy” (Annex 2).
In business processes, the Policy is implemented towards the relevant parties through the “Product or Service Purchaser Privacy Notice and Explicit Consent Statement”, the “Supplier Privacy Notice and Explicit Consent Statement”, the “Job Applicant Privacy Notice and Explicit Consent Statement” and the “CCTV Privacy Notice and Explicit Consent Statement”. These documents are available on request at kef@kef.com.tr.
Company management is responsible for implementing the Law and the Policy and for updating the Policy when necessary; the Kef Personal Data Protection Committee is responsible for monitoring, coordinating and auditing all related work and processes.
9. Entry into force and publication
The Policy entered into force on the date of its publication. Changes to the Policy are made available to data subjects and relevant persons by publishing them on the “Kef” website (www.kef.com.tr). Changes take effect on the date they are announced.
Annexes
Annex 1: Data Subject Application Form
Annex 2: Personal Data Retention and Destruction Policy
This English version is provided for information only. In case of any discrepancy, the Turkish version prevails.