1. INTRODUCTION AND PURPOSE OF THE POLICY
As Betav Balcılık ve Arıcılık Anonim Şirketi, hereinafter referred to as “Betav Balcılık” or the “Company”, we attach the utmost importance to the lawful processing and protection of personal data in accordance with the Personal Data Protection Law No. 6698, hereinafter referred to as the “PDPL”, and the relevant legislation, and we act with this level of care in all our planning and activities.
With this awareness, we present this Policy on the Processing and Protection of Personal Data, hereinafter referred to as the “Policy”, for your information, both to fulfill our obligation to inform under Article 10 of the Law and to disclose all administrative and technical measures taken by us within the scope of the processing and protection of personal data.
2. PURPOSE AND SCOPE OF THE POLICY
The main purpose of this Policy is to provide explanations regarding the systems implemented for the processing and protection of personal data in accordance with the law and the purpose of the Law, and, within this scope, to inform the persons whose personal data is processed by our Company, primarily including Company Stakeholders, Company Officials, Company Business Partners, Employee Candidates, Visitors, Company and Group Company Customers, Potential Customers, Company Suppliers, Company Supplier Officials and Employees, Company Business Partner Officials and Employees, Company Customer Officials and Employees, the Company, and Third Parties.
In this way, it is aimed to ensure full compliance with the legislation in the personal data processing and protection activities carried out by our Company and to protect all rights of personal data subjects arising from the legislation regarding personal data. Detailed information regarding the relevant personal data subjects can be accessed from Annex 2 of this Policy, titled “Annex 2 - Personal Data Subjects”.
3. DEFINITIONS AND ABBREVIATIONS
| Abbreviation / Term |
Definition |
| Explicit Consent |
Consent relating to a specific subject, based on information and expressed with free will. |
| Relevant User |
Persons who process personal data within the organization of the data controller or in line with the authorization and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection, and backup of data. |
| Destruction |
Deletion, destruction, or anonymization of personal data. |
| Law / PDPL |
Personal Data Protection Law No. 6698. |
| Recording Medium |
Any medium containing personal data processed wholly or partly by automated means or by non-automated means provided that it forms part of a data filing system. |
| Personal Data |
Any information relating to an identified or identifiable natural person. |
| Processing of Personal Data |
Any operation performed on personal data, such as collection, recording, storage, preservation, alteration, rearrangement, disclosure, transfer, takeover, making available, classification, or prevention of use, whether wholly or partly by automated means or by non-automated means provided that it forms part of a data filing system. |
| Anonymization of Personal Data |
Rendering personal data impossible to associate with an identified or identifiable natural person under any circumstances, even by matching it with other data. |
| Deletion of Personal Data |
Rendering personal data inaccessible and non-reusable for Relevant Users in any way. |
| Destruction of Personal Data |
The process of rendering personal data inaccessible, unrecoverable, and non-reusable by anyone in any way. |
| Authority |
Personal Data Protection Authority. |
| Board |
Personal Data Protection Board. |
| Special Categories of Personal Data |
Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. |
| Periodic Destruction |
The deletion, destruction, or anonymization process carried out ex officio at recurring intervals specified in the personal data retention and destruction policy when all personal data processing conditions set out in the Law cease to exist. |
| Data Subject / Relevant Person |
The natural person whose personal data is processed. |
| Data Controller |
The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data filing system. |
| Regulation |
Regulation on the Deletion, Destruction, or Anonymization of Personal Data published in the Official Gazette on October 28, 2017. |
4. DUTIES AND RESPONSIBILITIES
4.1.
Betav Balcılık ve Arıcılık Anonim Şirketi is responsible for determining the purposes and means of processing the personal data registered in its database and for the establishment and management of the data filing system, and has registered as a data controller with the Data Controllers Registry.
4.2.
A data controller representative has been appointed for the Data Controllers Registry.
4.3.
Natural or legal persons who process personal data on behalf of Betav Balcılık ve Arıcılık Anonim Şirketi based on the authority granted by the Company shall be considered data processors. If personal data is processed by another natural or legal person on behalf of Betav Balcılık ve Arıcılık Anonim Şirketi, Betav Balcılık ve Arıcılık Anonim Şirketi, as the data controller, and the data processors shall be jointly responsible for taking the relevant measures.
As the data controller, Betav Balcılık ve Arıcılık Anonim Şirketi periodically audits the compliance of data processors with this Policy in order to ensure that the trust provided to the relevant persons who share their personal data with the Company is also maintained in the same manner by its business partners, service providers, suppliers, and contractors.
5. MATTERS REGARDING THE PROTECTION OF PERSONAL DATA
5.1. Ensuring the Security of Personal Data
In accordance with the legislation, particularly Article 12 of the PDPL, our Company takes the necessary measures according to the nature of the data to be protected in order to prevent unlawful disclosure, access, transfer, or any other security deficiencies that may occur with respect to personal data.
Within this scope, our Company conducts the necessary audits itself and, when needed, has them conducted with support in order to ensure the implementation of the provisions of the Law in accordance with the guidelines published by the Board. According to the results of these audits, any identified violations, negativities, and non-conformities are reported to the board of directors, and the board of directors takes the necessary measures in relation to such matters.
5.1.1. Administrative and Technical Measures Taken to Ensure the Lawful Processing of Personal Data
Administrative Measures Taken to Ensure the Lawful Processing of Personal Data
The main administrative measures taken by our Company to ensure the lawful processing of personal data are as follows:
Employees are informed about personal data protection law and the lawful processing of personal data.
All activities carried out by our Company are analyzed in detail for all business units, and as a result of this analysis, personal data processing activities specific to the activities carried out by the relevant business units are identified. The requirements to be fulfilled in order to ensure that these activities comply with the personal data processing conditions required by Law No. 6698 are determined. Awareness is created within the relevant business units in order to meet the identified legal compliance requirements, and implementation rules are established. Necessary administrative measures are implemented through internal Company policies and information notices in order to audit these matters and ensure the continuity of implementation.
Provisions imposing obligations not to process, disclose, or use personal data, except for Company instructions and exceptions provided by law, are included in contracts and documents governing the legal relationship between our Company and its employees. Employee awareness is raised in this regard, and audits are conducted.
In cases where personal data is subject to transfer, our Company includes provisions in the contracts concluded with the persons to whom personal data is transferred, stating that the party receiving the personal data shall fulfill its obligations to ensure data security. Within this scope, the receiving party undertakes to take all necessary measures to protect personal data and to ensure the implementation of such measures within its own organization.
Technical Measures Taken to Ensure the Lawful Processing of Personal Data
The main technical measures taken by our Company to ensure the lawful processing of personal data are as follows:
Personal data processing activities carried out within our Company are audited through technical systems that are established and updated when necessary.
The technical measures taken are periodically audited by the audit and security mechanism determined by the Authority.
Necessary software and systems are installed to ensure security.
5.1.2. Administrative and Technical Measures Taken to Prevent Unlawful Access to Personal Data
a. Administrative Measures
The main administrative measures taken by Betav Balcılık ve Arıcılık Anonim Şirketi to prevent unlawful access to personal data are as follows:
Employees are informed about the technical measures to be taken to prevent unlawful access to personal data. Employees are also informed that they may not disclose personal data they have learned to others in violation of the provisions of the PDPL, and may not use such data for purposes other than the processing purpose, and that this obligation continues after they leave their position. Necessary undertakings are obtained from employees accordingly.
Provisions are included in the contracts concluded by Betav Balcılık ve Arıcılık Anonim Şirketi with persons to whom personal data is lawfully transferred, stating that such persons shall take the necessary security measures for the protection of personal data and ensure compliance with these measures within their own organizations.
The technical measures taken are periodically audited by the audit and security mechanism determined by the Company.
b. Technical Measures
The main technical measures taken by Betav Balcılık ve Arıcılık Anonim Şirketi to prevent unlawful access to personal data are as follows:
Technical measures appropriate to technological developments are taken, and such measures are periodically updated and renewed.
Access and authorization technical solutions are implemented in accordance with the legal compliance requirements determined on a business-unit basis.
The technical measures taken are periodically audited by the audit mechanism determined by the Authority, and risk-related matters are reassessed and necessary technological solutions are developed.
Software and hardware including antivirus systems and firewalls are installed.
5.1.3. Storage of Personal Data in Secure Environments
Administrative Measures Taken for the Storage of Personal Data in Secure Environments
The main administrative measures taken by the Company to store personal data in secure environments are as follows:
Employees are informed about ensuring the secure storage of personal data.
If the Company obtains an external service due to technical requirements related to the storage of personal data, provisions are included in the contracts concluded with the relevant companies to which personal data is lawfully transferred, stating that the persons receiving the personal data shall take the necessary security measures for the protection of personal data and ensure compliance with such measures within their own organizations.
Technical Measures Taken for the Storage of Personal Data in Secure Environments
The main technical measures taken by the Company to store personal data in secure environments are as follows:
Systems appropriate to technological developments are used for the storage of personal data in secure environments.
Technical security systems are established for storage areas. The technical measures taken are periodically audited by the audit mechanism determined by our Company. Matters posing risk are reassessed and necessary technological solutions are developed.
All necessary infrastructures are used in a lawful manner to ensure the secure storage of personal data.
5.1.4. Auditing the Security Measures Taken for the Protection of Personal Data
In accordance with Article 12 of the PDPL, our Company conducts or has conducted the necessary internal audits. The results of these audits are reassessed within the internal functioning of the Authority/Company, and necessary activities are carried out to improve the measures taken.
5.1.5. Measures to Be Taken in the Event of Unauthorized Disclosure of Personal Data
If personal data processed by our Company is unlawfully obtained by unauthorized persons, the situation shall be notified to the Personal Data Protection Board and the relevant data subjects without delay.
5.2. Protection of Special Categories of Personal Data
The technical and administrative measures taken by our Company for the protection of personal data that is classified as special categories of personal data under the Law and processed lawfully are also applied to special categories of personal data, and the necessary audits are carried out.
5.3. Raising Awareness and Auditing Business Units Regarding the Protection and Processing of Personal Data
Our Company carries out activities to raise the necessary awareness and ensures that the necessary training is organized in order to prevent the unlawful processing of personal data, prevent unlawful access to personal data, and ensure the preservation of personal data.
5.4. Raising Awareness and Auditing Business Partners and Suppliers Regarding the Protection and Processing of Personal Data
Our Company provides the necessary information to business partners in order to increase awareness for preventing the unlawful processing of personal data, preventing unlawful access to data, and ensuring the preservation of data. In contracts, protocols, and confidentiality agreements concluded between business partners and the Company, reference is made to the necessary warnings and notices required under the PDPL legislation.
6. PRINCIPLES TO BE APPLIED IN THE PROCESSING OF PERSONAL DATA
Betav Balcılık ve Arıcılık Anonim Şirketi accepts that it shall process personal data within the scope of this Policy in accordance with the following principles under Article 4 of the PDPL.
6.1. Processing Personal Data in Accordance with the Law and the Principle of Good Faith
As a data controller and a prudent merchant, Betav Balcılık ve Arıcılık Anonim Şirketi carries out personal data processing activities in accordance with all legislation in force and to enter into force, particularly the Constitution and the PDPL, and in compliance with the principle of good faith stipulated under Article 2 of the Turkish Civil Code. Within this framework, personal data is processed only to the extent required by and limited to the business activities of our Company.
6.2. Ensuring the Accuracy and Currency of Personal Data
Betav Balcılık ve Arıcılık Anonim Şirketi takes the necessary measures to ensure that personal data remains accurate and up to date throughout the period during which it is processed, and establishes administrative and technical mechanisms to ensure the accuracy and currency of personal data at certain intervals.
6.3. Processing for Specific, Explicit, and Legitimate Purposes
Betav Balcılık ve Arıcılık Anonim Şirketi processes personal data lawfully, clearly sets forth the purposes of personal data processing, and processes data within the scope of purposes connected with its business activities.
6.4. Processing Personal Data in a Manner That Is Relevant, Limited, and Proportionate to the Purposes for Which It Is Processed
Personal data is processed by Betav Balcılık ve Arıcılık Anonim Şirketi in a manner that is relevant and limited to the purposes of processing and only to the extent necessary for achieving such purposes. Within this scope, the processing of personal data that is unrelated to or not needed for the purpose of processing is avoided.
6.5. Processing for the Period Stipulated in the Relevant Legislation or Required by the Purpose of Processing
Personal data is retained for the periods stipulated under the relevant legislation or for the period required by the purpose of processing. At the end of the period stipulated by the legislation or required by the purpose of processing, personal data is deleted, destroyed, or anonymized by Betav Balcılık ve Arıcılık Anonim Şirketi.
7. POLICY ON THE TRANSFER OF PERSONAL DATA
7.1. Transfer of Personal Data
Where necessary, Betav Balcılık ve Arıcılık Anonim Şirketi may transfer the personal data and special categories of personal data of the data subject to third parties by taking the necessary security measures in line with lawful personal data processing purposes. Our Company acts in accordance with the provisions stipulated under Article 8 of the Law in this regard. Detailed information can be accessed from Annex 4 of this Policy, titled “Annex 4 - Third Parties to Whom Personal Data Is Transferred by Our Company and Purposes of Transfer”.
The grounds for transferring personal data are as follows:
The relevant activities concerning the transfer of personal data are explicitly provided for by law.
It is necessary to transfer personal data belonging to the parties to a contract, provided that it is directly related to the establishment or performance of the contract.
The transfer of personal data is mandatory for our Company to fulfill its legal obligation.
Personal data has been made public by the data subject, provided that the transfer by our Company is limited to the purpose for which the data was made public.
The transfer of personal data by the Company is mandatory for the establishment, exercise, or protection of the rights of the Company, the data subject, or third parties.
Personal data transfer is mandatory for the legitimate interests of the Company, provided that it does not harm the fundamental rights and freedoms of the data subject.
In addition to all these, where any of the above conditions exist and where necessary, personal data may be transferred by our Company to foreign countries declared by the Board to have adequate protection, referred to as “Foreign Countries with Adequate Protection”, or, in the absence of adequate protection, to foreign countries where data controllers in Turkey and in the relevant foreign country undertake adequate protection in writing and where the approval of the Personal Data Protection Board is obtained, referred to as “Foreign Countries Where the Data Controller Undertakes Adequate Protection”. Our Company acts in accordance with the provisions stipulated under Article 9 of the PDPL in this regard.
7.2. Transfer of Special Categories of Personal Data
By exercising the necessary care, and in accordance with the principles set forth in this Policy and by taking all administrative and technical measures, including the measures determined by the Board, special categories of personal data may be transferred by our Company if the following conditions exist:
Special categories of personal data other than health and sexual life data, namely race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, data relating to criminal convictions and security measures, and biometric and genetic data, may be processed without seeking the explicit consent of the data subject if explicitly provided for by law, in other words if there is an explicit provision in the relevant law regarding the processing of personal data. Otherwise, the explicit consent of the data subject shall be obtained.
Special categories of personal data relating to health and sexual life may be processed without seeking explicit consent by persons under a confidentiality obligation or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, medical diagnosis, conducting treatment and care services, and planning and managing healthcare services and their financing. Otherwise, the explicit consent of the data subject shall be obtained.
In addition to all these, personal data may be transferred to Foreign Countries with Adequate Protection or to foreign countries where the data controller undertakes adequate protection if any of the above conditions exist.
8. MATTERS REGARDING THE PROCESSING OF PERSONAL DATA
8.1. Conditions for Processing Personal Data
Except for the exceptions listed in the Law, our Company processes personal data only by obtaining the explicit consent of data subjects. If any of the following circumstances listed in the Law exist, personal data may be processed even without the explicit consent of the data subject:
It is explicitly provided for by law.
It is mandatory for the protection of the life or physical integrity of the person who is unable to express consent due to actual impossibility or whose consent is not legally valid, or of another person.
It is necessary to process personal data belonging to the parties to a contract, provided that it is directly related to the establishment or performance of a contract.
It is mandatory for the data controller to fulfill its legal obligation.
The data has been made public by the data subject.
Data processing is mandatory for the establishment, exercise, or protection of a right.
Processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.
8.2. Conditions for Processing Special Categories of Personal Data
Special categories of personal data are not processed without the explicit consent of data subjects, provided that adequate measures determined by the Board are taken. However, special categories of personal data other than data relating to health and sexual life may be processed without the explicit consent of the data subject in cases provided for by law.
Data relating to health and sexual life may be processed without explicit consent, provided that adequate measures are taken and if the following grounds exist:
Protection of public health,
Preventive medicine,
Medical diagnosis,
Conducting treatment and care services,
Planning and management of healthcare services and their financing.
8.3. Informing the Personal Data Subject
Betav Balcılık ve Arıcılık Anonim Şirketi carries out the necessary processes to ensure that data subjects are informed at the time their personal data is obtained, in accordance with Article 10 of the PDPL and the Communiqué on the Procedures and Principles to be Followed in Fulfillment of the Obligation to Inform. Within the framework of the obligation to inform, the information to be provided to data subjects is as follows:
Identity of the data controller and its representative, if any,
The purpose for which personal data will be processed,
To whom and for what purpose the processed personal data may be transferred,
The method and legal ground for collecting personal data,
Rights of the relevant person.
9. RETENTION PERIOD OF PERSONAL DATA
In determining the retention periods of personal data obtained by Betav Balcılık ve Arıcılık Anonim Şirketi in accordance with the PDPL and other relevant legislation:
If a period is stipulated in the legislation regarding the retention of the relevant personal data, such period is complied with.
If no period is specified in the legislation, personal data is retained for the period necessary for the purposes for which it is processed.
At the end of the determined retention periods, personal data is destroyed in accordance with periodic destruction periods or data subject applications and by using the determined destruction methods, namely deletion, destruction, and/or anonymization.
10. DELETION, DESTRUCTION, AND ANONYMIZATION OF PERSONAL DATA
Personal data obtained by Betav Balcılık ve Arıcılık Anonim Şirketi in accordance with the PDPL and other relevant legislation shall be destroyed by Betav Balcılık ve Arıcılık Anonim Şirketi ex officio or upon the application of the Relevant Person, in accordance with the Law and the relevant legislation, using the techniques specified below, if the personal data processing purposes listed in the Law and the Regulation cease to exist.
a. Deletion of Personal Data
Personal data obtained by Betav Balcılık ve Arıcılık Anonim Şirketi in accordance with the PDPL and other relevant legislation may be deleted by the Company on its own decision or upon the request of the personal data subject if the reasons requiring its processing cease to exist.
Deletion of personal data is the process of rendering personal data inaccessible and non-reusable for Relevant Users in any way. Our Company shall take all necessary technical and administrative measures to ensure that deleted personal data is inaccessible and non-reusable for Relevant Users.
The process to be followed for deletion of personal data is as follows:
Determining the personal data that will be subject to deletion.
Identifying the Relevant Users for each personal data item by using an access authorization and control matrix or a similar system.
Identifying, disabling, and eliminating the authorizations and methods of Relevant Users such as access, recovery, and reuse.
The methods for deletion of personal data are as follows:
Personal data contained in printed documents must be deleted by masking. Masking is performed by cutting out the personal data on the relevant document where possible, or, where this is not possible, by rendering it invisible to Relevant Users using permanent ink in a way that cannot be reversed or read through technological solutions.
Office files located on a central server are deleted by using the delete command in the operating system, or the access rights of the Relevant User to the file or the directory where the file is located are removed.
Personal data located on portable external disks must be stored in encrypted form and deleted by using software suitable for the characteristics of the disk.
Personal data located in databases is deleted by deleting the relevant rows containing the personal data through database commands such as DELETE.
b. Destruction of Personal Data
Personal data obtained by Betav Balcılık ve Arıcılık Anonim Şirketi in accordance with the PDPL and other relevant legislation may be destroyed by the Company on its own decision or upon the request of the personal data subject if the reasons requiring its processing cease to exist.
Destruction of personal data is the process of rendering personal data inaccessible, unrecoverable, and non-reusable by anyone in any way. The data controller is obliged to take all necessary technical and administrative measures regarding the destruction of personal data.
1. Methods for Destroying Personal Data on Local Systems
Degaussing: This is a method of corrupting the data on magnetic media in an unreadable manner by passing the magnetic media through a special device and exposing it to a high-value magnetic field.
Physical Destruction: This is the physical destruction of optical media and magnetic media by methods such as melting, burning, pulverizing, or passing through a metal grinder. Physical destruction must be applied for devices that cannot be degaussed.
Overwriting: This is a data destruction method that makes it impossible to read and recover old data by writing random data consisting of 0s and 1s at least seven times over magnetic media and rewritable optical media through special software.
2. Methods for Destroying Personal Data on Peripheral Systems
Network devices such as switches and routers: Such devices have delete commands but do not have a destruction feature. They must be destroyed by using one or more of the appropriate methods specified under the methods for destroying personal data on local systems.
Flash-based disks: For flash-based hard disks with ATA interfaces such as SATA and PATA, or SCSI interfaces such as SCSI Express, the block erase command should be used if supported. If not supported, they should be destroyed by using the method recommended by the manufacturer or one or more of the appropriate methods specified under the methods for destroying personal data on local systems.
Magnetic tape and magnetic disk units: Magnetic tapes and magnetic disk units must be destroyed by exposing them to strong magnetic fields and degaussing them or by physical destruction methods such as burning or melting.
Mobile phones, including SIM cards and fixed memory areas: Fixed memory areas in mobile phones must be destroyed by using the appropriate methods specified under the methods for destroying personal data on local systems.
Optical disks such as CDs and DVDs: Optical disks must be destroyed by physical destruction methods such as burning, cutting into small pieces, or melting.
Peripheral devices with removable data recording media, such as printers and fingerprint door access systems: It must be verified that all data recording media have been removed, and such media must be destroyed by using the appropriate methods specified under the methods for destroying personal data on local systems.
Peripheral devices with fixed data recording media, such as printers and fingerprint door access systems: Destruction must be carried out by using the appropriate methods specified under the methods for destroying personal data on local systems.
3. Method for Destroying Personal Data on Paper and Microfiche Media
For the destruction of personal data written on permanent and physical media, the medium must be divided into small pieces using paper destruction or shredding machines, in a size that cannot be understood and, where possible, both horizontally and vertically, so that it cannot be reassembled.
4. Method for Destroying Personal Data in Cloud Environments
During the storage and use of personal data in such systems, the data must be encrypted using cryptographic methods, and, where possible for personal data, separate encryption keys must be used for each cloud solution from which services are received. When the cloud computing service relationship ends, all copies of the encryption keys required to render personal data usable must be destroyed.
In addition to the above media, the destruction of personal data contained in devices that fail or are sent for maintenance is carried out as follows:
Before the relevant devices are transferred to third-party institutions such as manufacturers, sellers, or service providers for maintenance or repair, the personal data contained in them must be destroyed by using one or more of the appropriate methods specified under the methods for destroying personal data on local systems.
If destruction is not possible or appropriate, the data storage medium must be removed and stored, and the other defective parts must be sent to third-party institutions such as manufacturers, sellers, or service providers.
Necessary measures must be taken to prevent personnel coming from outside for maintenance, repair, or similar purposes from copying personal data and taking it outside the organization.
c. Anonymization of Personal Data
Anonymization is the process of rendering personal data impossible to associate with an identified or identifiable natural person even if it is matched with other data. Our Company takes all necessary technical and administrative measures to anonymize personal data.
The methods for anonymization of personal data are as follows:
a) Anonymization Methods That Do Not Create Value Irregularity
Anonymization methods that do not create value irregularity are methods applied without changing, adding to, or removing from the stored personal data, but through the generalization of any personal data group, the replacement of data with each other, or the removal of a specific data or sub-data group from the group.
Removing Variables: This is an anonymization method achieved by completely deleting one or more variables from a table. This method may be used for reasons such as the variable being a high-level identifier, the absence of a more appropriate solution, or the variable being sensitive data.
Removing Records: In this method, anonymity is strengthened by removing a row containing uniqueness from the data set, and the possibility of making assumptions about the data set is reduced. Generally, the removed records are records that do not share a common value with other records and that persons having knowledge of the data set may easily guess.
Regional Masking: If the combination of values belonging to a particular record creates a very rarely visible situation and this causes the person to become distinguishable within the relevant community, the value creating the exceptional situation is changed to “unknown”.
Generalization: This is the process of converting the relevant personal data from a specific value into a more general value. It is one of the most commonly used methods when producing cumulative reports and conducting operations based on aggregate figures.
Lower and Upper Bound Coding: Lower and upper bound coding is the anonymization of values within a grouping created by defining a category for a specific variable and combining the values that fall within such category.
Global Coding: Through the data derivation method, more general content is created from the content of personal data, ensuring that the personal data cannot be associated with any person. For example, specifying age instead of date of birth, or specifying the residential region instead of the full address.
Sampling: In the sampling method, a subset taken from the data set is shared instead of the entire data set. Thus, the risk of producing accurate predictions about persons is reduced because it is not known whether a person known to be included in the entire data set is included in the disclosed or shared sample subset.
b) Anonymization Methods That Create Value Irregularity
With methods that create value irregularity, existing values are changed and distortion is created in the values of the data set. Even if the values in the data set change, the data may continue to be useful by ensuring that overall statistics are not distorted.
Micro-Aggregation: With this method, all records in the data set are first arranged in a meaningful order and then the entire set is divided into a certain number of subsets. Subsequently, the average value of the variable determined for each subset is calculated and the value of that variable for the subset is replaced with the average value. Thus, the average value of that variable for the entire data set will not change.
Data Swapping: The data swapping method consists of record changes obtained by exchanging the values of a variable subset between selected pairs of records. This method is mainly used for variables that can be categorized. The database is transformed by swapping variable values between records belonging to individuals.
Adding Noise: With this method, additions and subtractions are made to create distortions at a determined level in a selected variable. The deviation is applied equally to each value.
c) Statistical Methods That Strengthen Anonymization
In anonymized data sets, as a result of certain values in records coming together in unique scenarios, there may be a possibility of identifying the persons in the records or deriving assumptions regarding their Personal Data. Therefore, in anonymized data sets, anonymity may be strengthened by minimizing the uniqueness of records in the data set through various statistical methods.
Anonymity: Anonymity has been developed to prevent the disclosure of information specific to persons who show unique characteristics in certain combinations by enabling more than one person to be identified through certain fields in a data set.
Diversity: The diversity method, developed through studies addressing the shortcomings of anonymity, considers the diversity created by sensitive variables corresponding to the same variable combinations.
Proximity: Proximity is the process of calculating the degree of closeness of values within personal data and anonymizing the data set by dividing it into subclasses according to such degrees of closeness.
11. RIGHTS OF PERSONAL DATA SUBJECTS AND EXERCISE OF THESE RIGHTS
11.1. Rights of Personal Data Subjects
Personal data subjects have the following rights:
To learn whether personal data is being processed,
To request information if their personal data has been processed,
To learn the purpose of processing personal data and whether such data is used in accordance with its purpose,
To know the third parties to whom personal data has been transferred domestically or abroad,
To request correction if personal data has been processed incompletely or inaccurately, and to request that the transaction carried out in this scope be notified to third parties to whom the personal data has been transferred,
To request deletion or destruction of personal data if the reasons requiring its processing cease to exist, despite having been processed in accordance with the Law and other relevant legal provisions, and to request that the transaction carried out in this scope be notified to third parties to whom the personal data has been transferred,
To object to the occurrence of a result against the person by analyzing the processed data exclusively through automated systems,
To request compensation for damages if they suffer damage due to the unlawful processing of personal data.
11.2. Exercise of Rights by Personal Data Subjects
It is necessary and sufficient for data subjects to submit their requests regarding the exercise of the above-mentioned rights under paragraph 1 of Article 13 of the PDPL to our Company through the following methods:
Filling out the form available at www.kalderabal.com, signing it with a wet signature, and delivering it personally to Betav Balcılık ve Arıcılık Anonim Şirketi at Saray Mah. 629 Sok. No:12 Merkez/BİTLİS.
Filling out the form available at www.kalderabal.com, signing it with a wet signature, and sending it via notary public to Betav Balcılık ve Arıcılık Anonim Şirketi at Saray Mah. 629 Sok. No:12 Merkez/BİTLİS.
Filling out the application form available at www.kalderabal.com, signing it with your “secure electronic signature” within the scope of the Electronic Signature Law No. 5070, and sending the securely electronically signed form to [email protected] via registered electronic mail.
It is not possible for third parties to make requests on behalf of personal data subjects. In order for a person other than the personal data subject to make a request, the original special power of attorney issued by the personal data subject in favor of the person who will make the application must be submitted.
In the application you submit to exercise your rights as a personal data subject as stated above, and containing your explanations regarding the right you request to exercise, the matter requested must be clear and understandable, the subject of the request must relate to you personally, or, if you are acting on behalf of another person, you must be specifically authorized in this regard and document your authority. The application must include identity and address information, and documents verifying your identity must be attached to the application.
Such applications are free of charge. However, if the transaction requires an additional cost, the fee specified in the tariff determined by the Personal Data Protection Board may be charged.
12. RESPONDING TO APPLICATIONS BY BETAV BALCILIK VE ARICILIK ANONİM ŞİRKETİ
12.1. Response Period and Procedure of Betav Balcılık ve Arıcılık Anonim Şirketi for Applications
If the personal data subject submits their request to our Company in accordance with the procedure set forth under section 11.2 of this chapter, our Company shall conclude the relevant request as soon as possible and in any case within thirty days, depending on the nature of the request.
Requests made by the relevant person are accepted or rejected by the data controller representative by explaining the reason, and the response is notified in writing or electronically. If the application is accepted, the necessary action is taken by Betav Balcılık ve Arıcılık Anonim Şirketi, and if the fee collected is due to the fault of Betav Balcılık ve Arıcılık Anonim Şirketi, such fee is refunded to the relevant person.
In certain cases concerning requests for the processing, modification, or deletion of personal data, a positive response may not be provided due to legal obligations or other reasons determined under Articles 5 and 6 of the PDPL. In such case, the reasons shall be explained in detail in the rejection response and the legal basis shall be notified.
If the application is rejected by Betav Balcılık ve Arıcılık Anonim Şirketi, if the response provided is found insufficient, or if no response is provided within the prescribed period, the relevant person has the right to lodge a complaint with the Board within 30 days from the date on which the response is learned and, in any case, within 60 days from the application date.
12.2. Information That Betav Balcılık ve Arıcılık Anonim Şirketi May Request from the Applicant Personal Data Subject
Betav Balcılık ve Arıcılık Anonim Şirketi may request information from the relevant person in order to determine whether the applicant is the personal data subject. Our Company may ask questions to the personal data subject regarding their application in order to clarify the matters included in the application.
12.3. Right of Betav Balcılık ve Arıcılık Anonim Şirketi to Reject the Application of the Personal Data Subject
Our Company may reject the application of the applicant by explaining the reason in the following cases:
Processing personal data for purposes such as research, planning, and statistics by anonymizing it for official statistics.
Processing personal data for artistic, historical, literary, or scientific purposes, or within the scope of freedom of expression, provided that it does not violate national defense, national security, public safety, public order, economic security, privacy of private life, or personal rights, and does not constitute a crime.
Processing personal data within the scope of preventive, protective, and intelligence activities carried out by public institutions and organizations authorized and assigned by law to ensure national defense, national security, public safety, public order, or economic security.
Processing personal data by judicial authorities or enforcement authorities regarding investigation, prosecution, trial, or execution proceedings.
The processing of personal data is necessary for the prevention of crime or for criminal investigation.
Processing personal data made public by the personal data subject themselves.
The processing of personal data is necessary for the performance of supervisory or regulatory duties or for disciplinary investigation or prosecution by public institutions and organizations and professional organizations with public institution status, based on the authority granted by law.
The processing of personal data is necessary for the protection of the economic and financial interests of the State in relation to budgetary, tax, and financial matters.
The request of the personal data subject is likely to prevent the rights and freedoms of other persons.
Requests requiring disproportionate effort have been made.
The requested information is publicly available information.
13. SPECIAL CASES WHERE PERSONAL DATA IS PROCESSED
13.1. Personal Data Processing Activities at Building and Facility Entrances and Inside Buildings and Facilities, and Website Visitors
For the purpose of ensuring security, our Company carries out personal data processing activities through security camera monitoring in its buildings and facilities and through the tracking of guest entry and exit records.
13.2. Camera Monitoring Activities Conducted at Building and Facility Entrances and Inside Buildings and Facilities
Our Company carries out camera monitoring activities in its buildings and facilities in accordance with the Law on Private Security Services and the relevant legislation for the purpose of ensuring security.
Betav Balcılık ve Arıcılık Anonim Şirketi conducts security camera monitoring activities in its buildings and facilities for the purposes stipulated in the applicable legislation in force and in accordance with the personal data processing conditions listed in the Law. In accordance with Article 10 of the Law, personal data subjects are informed by our Company through multiple methods regarding camera monitoring activities. Furthermore, Betav Balcılık ve Arıcılık Anonim Şirketi processes personal data in a manner that is relevant, limited, and proportionate to the purposes for which it is processed, in accordance with Article 4 of the Law.
The purpose of carrying out video camera monitoring activities by Betav Balcılık ve Arıcılık Anonim Şirketi is limited to the purposes listed in this Policy. Accordingly, the monitoring areas, number of security cameras, and timing of monitoring are implemented in a manner sufficient for and limited to achieving the security purpose. Areas that may result in interference with personal privacy beyond security purposes, such as restrooms, are not subject to monitoring. Only a limited number of employees of Betav Balcılık ve Arıcılık Anonim Şirketi have access to live camera images and digitally recorded and stored footage.
In accordance with Article 12 of the PDPL, the necessary technical and administrative measures are taken to ensure the security of personal data obtained as a result of camera monitoring activities.
13.3. Tracking of Guest Entry and Exit Records at Building and Facility Entrances and Inside Buildings and Facilities
Betav Balcılık ve Arıcılık Anonim Şirketi carries out personal data processing activities for tracking guest entries and exits in its buildings and facilities for the purpose of ensuring security and for the purposes set forth in this Policy. When the names and surnames of persons visiting Company buildings as guests are obtained, or through texts posted within the Company or otherwise made accessible to guests, the relevant personal data subjects are informed within this scope. Data obtained for the purpose of tracking guest entries and exits is processed only for this purpose, and the relevant personal data is recorded in the data filing system in physical media.
14. COORDINATION OF PERSONAL DATA PROTECTION AND PROCESSING PROCESSES BY BETAV BALCILIK VE ARICILIK ANONİM ŞİRKETİ
A management structure has been established by our Company to ensure compliance with the provisions of the PDPL and the implementation of the Personal Data Protection and Processing Standard.
Within our Company, a Personal Data Protection Committee, hereinafter referred to as the “Committee”, has been established by decision of the senior management of the Company to manage this Policy and other policies related and connected to this Policy.
The duties of the Committee are as follows:
To prepare and put into effect the main policies relating to the protection and processing of personal data and, where necessary, amendments, and to submit them for the approval of senior management.
To identify risks that may arise in the personal data processing activities of our Company and to ensure that necessary measures are taken, and to submit improvement recommendations for the approval of senior management.
To ensure that personal data subjects are informed about personal data processing activities and their legal rights regarding the protection of personal data and the implementation and dissemination of the Policies.
To forward the applications of personal data subjects to senior management for the highest-level decision-making.
To perform other duties assigned by the senior management of the Company regarding the protection of personal data.
To forward requests directed by the Authority to the data controller and to transmit the response to be received from the data controller to the Authority.
To carry out transactions and procedures relating to the Registry on behalf of the data controller.
To review and audit the Company’s data processing, protection, and destruction policies.
To ensure that necessary measures and legal notification obligations are fulfilled in the event of a data breach.
ANNEX 1. PERSONAL DATA PROCESSING PURPOSES
| First-Level Purpose |
Second-Level Purpose |
| Carrying out the necessary work by our relevant business units for the performance of commercial activities conducted by the Company and conducting related business processes |
Conducting communication activities; conducting supply chain management processes; conducting/supervising business activities; conducting goods/services production and operation processes; conducting information security processes; managing access authorizations of business partners or suppliers to information; conducting finance and accounting affairs; conducting management activities; conducting business continuity activities; conducting logistics activities; conducting investment processes; organization and event management; conducting goods/services procurement processes; planning and executing the Company’s commercial and/or business strategies; managing relations with business partners or suppliers; conducting strategic planning activities. |
| Carrying out the necessary work by our business units to enable relevant persons to benefit from the products and services offered by the Company and conducting related business processes |
Conducting goods/services sales processes; conducting after-sales support services for goods/services; conducting customer relationship management processes; conducting contract processes; tracking requests/complaints; conducting marketing analysis activities. |
| Planning and executing the Company’s human resources policies and processes |
Conducting talent/career development activities; fulfilling obligations arising from employment contracts and legislation for employees; conducting fringe benefits and employee benefits processes; conducting assignment processes; conducting wage policy processes; planning human resources processes; conducting performance evaluation processes; conducting/supervising business activities; conducting training activities; conducting employee satisfaction and engagement processes; managing employees’ access authorizations to information; conducting work and residence permit procedures for foreign personnel; receiving and evaluating suggestions for improving business processes; conducting employee candidate/intern/student selection and placement processes; conducting application processes of employee candidates; conducting internal audit/investigation/intelligence activities. |
| Planning and executing activities necessary for customizing and promoting the products and services offered by the Company according to the preferences, usage habits, and needs of relevant persons |
Conducting marketing processes for products/services; conducting loyalty processes for the company/products/services; conducting customer satisfaction activities. |
| Ensuring the legal, technical, and commercial-business security of the Company and relevant persons who have a business relationship with the Company |
Following up and conducting legal affairs; ensuring the security of data controller operations; providing information to authorized persons, institutions, and organizations; creating and tracking visitor records; conducting emergency management processes; conducting audit/ethics activities; conducting occupational health and safety activities; ensuring physical premises security; conducting risk management processes; ensuring the security of movable property and resources; conducting storage and archive activities; ensuring that activities are carried out in accordance with the legislation. |
ANNEX 2. PERSONAL DATA SUBJECTS
| Personal Data Subject Category |
Description |
| Visitor |
Natural persons who have entered the physical premises of our Company for various purposes or who visit our website. |
| Person Receiving Products or Services |
Natural persons who purchase or have purchased the products and services of our Company, regardless of whether they have any contractual relationship with our Company. |
| Supplier Official / Employee |
Natural persons who are employees and officials of the party providing services to the Company on a contractual basis and in accordance with Company orders and instructions while our Company conducts its commercial activities. |
| Intern |
Natural persons who carry out internships within our Company. |
| Potential Person Receiving Products or Services |
Natural persons who have requested or shown interest in purchasing the products or services of our Company, or who have been evaluated, in accordance with commercial practice and good faith, as potentially having such interest. |
| Shareholder / Partner |
Natural persons who are shareholders/partners of our Company. |
| Employee |
Natural persons employed within our Company. |
| Employee Candidate |
Natural persons who have applied for employment with our Company by any means or have made their resume and relevant information available for review by our Company, but who are not employed or interning within our Company. |
| Employees, Shareholders, and Officials of Institutions with Which We Cooperate |
Natural persons, including employees, shareholders, and officials of institutions with which our Company has any kind of business relationship, such as business partners and suppliers, without limitation. |
| Employee Family Members |
Spouses, children, and relatives of employees working within our Company. |
ANNEX 3. PERSONAL DATA CATEGORIES
| Personal Data Category |
Explanations |
| Identity Information |
Data containing information relating to a person’s identity; documents such as driver’s license, identity card, and passport containing information such as name-surname, Turkish Republic identity number, nationality information, mother’s name, father’s name, place of registration and other civil registry information, place of birth, date of birth, gender, marital status, as well as tax number, social security number, signature information, and similar information. |
| Contact Information |
Contact information such as phone number, address, email address, and fax number. |
| Location Information |
Personal data that identifies the location of Company vehicles and devices when used, such as GPRS location and travel information. |
| Personnel Information |
Any personal data processed to obtain information that forms the basis for the personal rights of natural persons in an employment relationship with our Company and that is legally required to be included in personnel files, such as education status, certificate and diploma information, foreign language information, training and skills, CV, courses attended, leave seniority base date, additional leave seniority days, leave group, departure/return date, day, reason for leave, address/phone number during leave, position name, department and unit, title, last employment start date, employment entry and exit dates, insurance entry/retirement, social security number, flexible working status, travel status, number of working days, projects worked on, monthly total overtime information, severance pay base date, additional severance pay days, days spent on strike, employee internet access logs, entry-exit logs, and performance information required for the employee to progress in their position. |
| Legal Transaction Information |
Personal data processed within the scope of determining and following up the legal claims and rights of our Company, performing debts, and fulfilling legal obligations. |
| Customer Transaction Information |
Information that is clearly related to an identified or identifiable natural person and included in a data filing system, obtained and generated about the relevant person as a result of our commercial activities and operations carried out by our business units within this framework; such as customer number associated with the person, customer income information, customer profession information, vehicle license plate, vehicle-related information, and education information. |
| Physical Premises Security |
Personal data that is clearly related to an identified or identifiable natural person and included in a data filing system, relating to records and documents obtained at entry to physical premises and during presence within physical premises, such as entry and exit record information and camera recordings of employees and visitors. |
| Transaction Security Information |
Personal data that is clearly related to an identified or identifiable natural person and included in a data filing system, processed to ensure our technical, administrative, legal, and commercial security while conducting our commercial activities, such as IP address information, website entry-exit information, password and credential information. |
| Risk Management Information |
Personal data processed through methods used for the management of commercial, technical, and administrative risks in accordance with generally accepted legal and commercial practices and the rules of good faith. |
| Financial Information |
Personal data that is clearly related to an identified or identifiable natural person and included in a data filing system, relating to information, documents, and records showing all financial results created according to the type of legal relationship established by our Company with the personal data subject, such as balance sheet information, financial performance information, credit and risk information. |
| Professional Experience Information |
Any personal data that is clearly related to an identified or identifiable natural person and processed wholly or partly by automated means or by non-automated means as part of a data filing system, processed to obtain information forming the basis for professional experience information of our employees or natural persons in a working relationship with the Authority/Company, such as diploma information, courses attended, in-service training information, and certificates. |
| Marketing Information |
Personal data that is clearly related to an identified or identifiable natural person and processed wholly or partly by automated means or by non-automated means as part of a data filing system, processed for the purpose of marketing our products and services by customizing them in line with the usage habits, preferences, and needs of the personal data subject, such as shopping history information, surveys, and cookie records. |
| Visual and Audio Records |
Visual and audio records associated with the personal data subject, such as photographs, camera recordings, and audio recordings. |
| Special Categories of Personal Data |
Data clearly related to an identified or identifiable natural person and included in a data filing system, as specified in Article 6 of Law No. 6698; data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. |
| License Plate Information |
Vehicle license plate information belonging to natural persons, clearly related to an identified or identifiable natural person and processed wholly or partly by automated means or by non-automated means as part of a data filing system. |
ANNEX 4. THIRD PARTIES TO WHOM PERSONAL DATA IS TRANSFERRED BY OUR COMPANY AND PURPOSES OF TRANSFER
Our Company may transfer the personal data of data subjects to third parties and institutions in accordance with Articles 8 and 9 of the PDPL, within the scope of the personal data processing conditions specified in Articles 5 and 6 of the PDPL and limited to the purposes set forth in this Policy.
The scope of recipients and the purposes of data transfer are specified below. These persons and institutions are as follows:
Business partners of Betav Balcılık ve Arıcılık Anonim Şirketi,
Suppliers of Betav Balcılık ve Arıcılık Anonim Şirketi,
Natural persons or private law legal entities,
Public institutions and organizations legally authorized to receive information,
Affiliates and subsidiaries with which Betav Balcılık ve Arıcılık Anonim Şirketi cooperates.
| Recipient Groups to Whom Data May Be Transferred |
Definition |
Purpose of Transferring the Processed Data |
| Business Partner |
Parties with which our Company establishes business partnerships for purposes such as conducting various projects together or receiving services within the framework of its commercial and investment activities. |
Limited to ensuring the fulfillment of the purposes for which the business partnership was established. |
| Supplier |
Parties that provide services to our Company, whether on a contractual basis or individually without a contract, in accordance with Company orders and instructions while our Company conducts its commercial and investment activities. |
Limited to ensuring the provision to our Company of services outsourced from the supplier and necessary for our Company to carry out its commercial activities. |
| Natural Persons or Private Law Legal Entities |
Natural persons or private law legal entities authorized to receive information and documents from our Company pursuant to the relevant legislation. |
Limited to the purpose requested within the legal authority of the relevant natural persons and private law entities. |
| Public Institutions and Organizations Legally Authorized to Receive Information |
Public institutions and organizations authorized to receive information and documents from our Company pursuant to the relevant legislation. |
Limited to the purposes requested within the legal authority of the relevant public institutions and organizations. |
| Affiliates and Subsidiaries with Which Betav Balcılık ve Arıcılık Anonim Şirketi Cooperates |
Companies in which our Company is a shareholder. |
Limited to ensuring the conduct of commercial activities that require the participation of our Company’s affiliates. |
ANNEX 5. ASSOCIATION OF DATA SUBJECT GROUPS WITH DATA CATEGORIES BELONGING TO SUCH PERSONS
| Personal Data Category |
Data Subject Category Related to the Relevant Personal Data |
| Identity Information |
Employee Family Members; Visitor; Person Receiving Products or Services; Supplier Official; Supplier Employee; Intern; Potential Person Receiving Products or Services; Shareholder/Partner; Employee; Employee Candidate. |
| Contact Information |
Person Receiving Products or Services; Supplier Official; Supplier Employee; Intern; Potential Person Receiving Products or Services; Shareholder/Partner; Employee; Employee Candidate. |
| Location Information |
Employee. |
| Personnel Information |
Intern; Employee; Employee Candidate. |
| Legal Transaction Information |
Person Receiving Products or Services; Supplier Official; Supplier Employee; Potential Person Receiving Products or Services; Shareholder/Partner; Employee. |
| Customer Transaction Information |
Person Receiving Products or Services; Potential Person Receiving Products or Services. |
| Physical Premises Security |
Visitor; Person Receiving Products or Services; Supplier Official; Supplier Employee; Intern; Potential Person Receiving Products or Services; Shareholder/Partner; Employee; Employee Candidate. |
| Transaction Security Information |
Employee. |
| Risk Management Information |
Person Receiving Products or Services; Supplier Official; Supplier Employee; Intern; Potential Person Receiving Products or Services; Employee. |
| Financial Information |
Person Receiving Products or Services; Supplier Official; Supplier Employee; Potential Person Receiving Products or Services; Employee. |
| Professional Experience Information |
Intern; Employee; Employee Candidate; Subcontractor Official; Subcontractor Employee. |
| Marketing Information |
Person Receiving Products or Services; Potential Person Receiving Products or Services. |
| Visual and Audio Records |
Visitor; Person Receiving Products or Services; Supplier Official; Supplier Employee; Intern; Potential Person Receiving Products or Services; Shareholder/Partner; Employee; Employee Candidate. |
| Special Categories of Personal Data |
Intern; Shareholder/Partner; Employee; Employee Candidate; Employee Family Members. |
| License Plate Information |
Visitor; Person Receiving Products or Services; Supplier Official; Supplier Employee; Intern; Potential Person Receiving Products or Services; Shareholder/Partner; Employee; Employee Candidate. |