YILDIZ TEKNOLOJİ GELİŞTİRME BÖLGESİ TEKNOPARK ANONİM ŞİRKETİ
POLICY ON THE PROTECTION AND PROCESSING OF PERSONAL DATA
As Yıldız Teknoloji Geliştirme Bölgesi Teknopark Anonim Şirketi ("YTU Yildiz Technopark"), we care about the protection and processing of your personal data in accordance with the Law on the Protection of Personal Data No. 6698 (the "Law"). This Personal Data Protection and Processing Policy (the "Policy") has been prepared in order to make statements about the personal data processing activity and the processes for the protection of personal data, to ensure transparency and compliance with the law in practice and to inform the real persons whose personal data has been processed by YTU Yildiz Technopark.
2. SCOPEThis Personal Data Protection and Processing Policy is related to all personal data processed for our company's employees, business partners, suppliers, visitors and real third parties, provided that they are a part of our system in any manner.
3. DEFINITIONSExplicit Consent | The statement of consent given by the personal data owner about a specific subject based on information and expressed in free will. |
Related Person/Personal Data Owner | The real person whose data has been processed |
Law | Law on Protection of Personal Data No. 6698 |
Recording Environment | Shall refer to any environment in which personal data has been processed, which is fully or partially automated or non-automated provided that it is part of any data recording system. |
Personal Data | Any information related to the identitied or identifiable real person |
Processing of Personal Data | Any transaction performed on the data such as obtaining, recording, storage, preservation, alteration, rearrangement, disclosure, transfer, acquisition, recapture, classification or preventing the use of the same by non-automated means provided that personal data is a part of a wholly or partially automated data recording system. |
Personal Data Owner | The real person whose data has been processed |
Board | Personal Data Protection Board |
Sensitive Personal Data | Shall refer to the data about the race, ethnicity, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership to an association, foundation or trade union, medical condition, sexual life, criminal conviction and security measures as well as biometric and genetic data of persons. |
Policy | Personal Data Protection and Processing Policy of YTU Yildiz Technopark |
Data Processor | Shall refer to the real person or the legal entity who processes personal data on behalf of the data controller based on the authority vested to it by the same, |
Data Recording System | The recording system where Personal Data is processed by means of configuring the same according to certain criteria, |
Data Controller | YTU Yildiz Technopark |
Regulation | The Regulation on the Deletion, Destruction or Anonymization of Personal Data, |
Business Partner | The parties with whom YTU Yildiz Technopark has established business partnerships for purposes such as carrying out various projects and receiving services while conducting company commercial activities. Data will be transferred only limited to the fulfillment of the purpose of establishing a business partnership. |
Legally Authorized Public Institutions and Organizations | Shall refer to public institutions and organizations authorized to receive information and documents from YTU Yildiz Technopark in accordance with the provisions of the legislation. |
Any personal data obtained by YTU Yildiz Technopark and included in this Policy may be processed for the following purposes.
PERSONAL DATA CATEGORIZATION | DESCRIPTION |
Identity Information | These is the personal data containing information about the identity of the person: documents such as driver's license, ID card, and passport that contain such information as name-surname, Turkish Republic ID number, nationality information, mother's name-father's name, place of birth, date of birth, and gender as well as information such as tax number, SSI number, signature information, vehicle license plate, etc. |
Contact Information | Information such as telephone number, address, e-mail and fax number. |
Transaction Security Information | Your personal data (e.g. log records, IP information, identity verification information) processed to ensure our technical, administrative, legal and commercial security |
Information on Family Members and Relatives | Personal data about family members (spouse, mother, father, child, etc.) and relatives of the personal data owner in order to protect the legitimate interests of YTU Yildiz Technopark and the data owner. |
Financial Information | Personal data processed in relation to information, documents and records showing any financial outcome between YTU Yildiz Technopark and the data controller, as well as personal data such as bank account number, IBAN number, credit card information, receivable/debt information, financial profile, asset data and income information. |
Physical Field Security Information | Personal data related to the records and documents taken at the entrance to the physical field and during the stay in the physical field; camera recordings, etc. |
Legal Transaction Information | Personal data processed within the scope of the determination, follow-up and performance of our legal receivables and rights, our legal obligations and compliance with the legislation (information in correspondences with the judicial authorities, information in the case file, etc.). |
Customer Transaction Information | Personal data collected from customers within the scope of conducting commercial activities (call center records, invoice, promissory note, check information, information in box office receipts, order information, request information, etc.). |
Marketing Information | Personal data collected within the scope of marketing activities (shopping history information, survey, cookie records, information obtained through campaign work, etc.) |
Audio/Visual Information | Photographic and camera recordings, audio recordings (Except for physical space security records, photo on the resumé, etc.) |
Professional Experience Information | Personal data such as diploma information, courses attended, in-service training information, certificates, transcript information collected from employees and employee candidates. |
Sensitive Personal Data | The data specified in Article 6 of the Law (e.g., health data including blood type, biometric data, religion and association information, etc.). |
BUYER CATEGORIES | DESCRIPTION | PURPOSE OF DATA TRANSFER |
Business Partner | Parties to the business partnership established by YTU Yildiz Technopark in the course of its business activities | Only limited to the fulfillment of the purpose of the business partnership, |
Supplier | Parties providing contractual services to YTU Yildiz Technopark as part of YTU Yildiz Technopark's business activities | Limited to the purpose of providing services necessary to sustain YTU Yildiz Technopark's business activities |
Authorized Public Institutions and Organizations | Public institutions and organizations authorized to receive information and documents in accordance with the provisions of the legislation | As limited to the purpose requested by the relevant public institutions and organizations within their legal authority |
Real Persons or private legal entities | Parties to whom information and documents are shared within the scope of the provisions of the relevant legislation and within the legitimate interests of YTU Yildiz Technopark | Limited to the sharing activities requested by the relevant private legal entities within the scope of their legal authority and performed by YTU Yildiz Technopark for the parties such as consulting firms, etc. |
The following administrative and technical measures are taken by YTU Yildiz Technopark in the processing and storage of personal data, within the framework of the responsibilities regarding the data controller in Article 12 of the Law, in order to store personal data securely and to prevent unlawful processing and access.
The data owner shall have the right to apply to the data controller and make a request in accordance with the article Article 11 of the Law. You can file an application and make a request to YTU Yildiz Technopark on the following issues within the scope of this right stipulated by the Law.
You can deliver your applications regarding your above-mentioned rights in written form and with an original signature personally by hand at the address of our company, YTÜ Yıldız Teknopark Çifte Havuzlar Mahallesi, Eski Londra Asfaltı Caddesi, İdari Bina Dış Kapı No:151/1L İç Kapı No:1 Esenler/İstanbul, or through a notary public or by sending an e-mail to the address [email protected] via your e-mail address in accordance with the "Communiqué on the Procedures and Principles of Application to the Data Controller".
10. PERIODIC DESTRUCTION PERIODIn accordance with Article 11 of the Regulation on Deletion, Destruction or Anonymization of personal data, YTU Yildiz Technopark has determined the periodic destruction period to be 6 months. Accordingly, periodic destruction is carried out by YTU Yildiz Technopark twice a year, in June and December.
11. UPDATE AND COMPLIANCEYTU Yildiz Technopark reserves the right to make changes to this Policy in line with changes to the Law and other relevant legislation, decisions of the Board, decisions to be taken as a company or developments in the sector or in the field of informatics.
12. ENFORCEMENT AND ANNULMENT OF THE POLICYThis Policy shall be deemed to have entered into force on the date written on it. If this Policy is updated or repealed and a new policy is determined, the updated or newly determined policy will be considered effective.