Skip to main content
Checklas

Personal Data Retention and Destruction Policy

CHECKLAS OTOMOTİV ANONİM ŞİRKETİ

PERSONAL DATA RETENTION AND DESTRUCTION POLICY

DATA CONTROLLER

Your personal data may be processed within the scope described below by CHECKLAS OTOMOTİV ANONİM ŞİRKETİ (hereinafter referred to as "the Company"), acting as data controller. "Data controller" is understood to mean the natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.

You may use the following channels to contact the data controller:

DATA CONTROLLER: CHECKLAS OTOMOTİV ANONİM ŞİRKETİ

Address: Merkez Mah. Ayazma Cad. Papirus Plaza No: 37/94 Kağıthane / ISTANBUL

Mersis No: 0209068064600012

Phone: 0850 433 66 44

E-mail: [email protected]

Website: https://www.checklas.com.tr

1. INTRODUCTION

1.1 PURPOSE

This Personal Data Retention and Destruction Policy ("Policy") has been prepared by CHECKLAS OTOMOTİV ANONİM ŞİRKETİ (referred to as "the Company") to set out the principles concerning the Company's activities and operations related to the retention and destruction of personal data.

Where all of the conditions for processing personal data set out in Articles 5 and 6 of the Law have ceased to apply, the Company deletes, destroys or anonymizes personal data either on its own initiative or upon the request of the data subject.

The Company has prepared this policy in accordance with the relevant laws, other legislation and Board decisions. All data processing activities within the Company are carried out in accordance with this policy.

1.2 SCOPE

The data subjects covered by this policy are: Employees, Job candidates, Service providers, Supplier representatives, Supplier employees, Persons receiving products or services, Potential recipients of products or services, Visitors. Personal data belonging to online visitors is within the scope of this Policy. All personal data processing activities carried out by the Company are conducted in accordance with this policy.

1.3 ABBREVIATIONS AND DEFINITIONS

Recipient Group: The category of natural or legal persons to whom personal data is transferred by the data controller.

Explicit Consent: Consent relating to a specific matter, based on being informed and expressed with free will.

Anonymization: Rendering personal data in such a way that it can no longer be associated with an identified or identifiable natural person, even when matched with other data.

Employee: Company personnel.

Electronic Environment: Environments in which personal data can be created, read, altered and written using electronic devices.

Non-Electronic Environment: All written, printed, visual and other environments other than electronic environments.

Service Provider: A natural or legal person providing services to the Company within the framework of a specific contract.

Data Subject: The natural person whose personal data is processed.

Authorized User: Persons who process personal data within the data controller's organization or under the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.

Destruction: The deletion, destruction or anonymization of personal data.

Law: Law No. 6698 on the Protection of Personal Data.

Recording Medium: Any medium containing personal data that is processed wholly or partly by automated means, or that is processed by non-automated means provided that it forms part of a data recording system.

Personal Data: Any information relating to an identified or identifiable natural person.

Personal Data Processing Inventory: The inventory that data controllers create by associating the personal data processing activities they carry out based on their business processes with the purposes and legal grounds for processing personal data, the data category, the recipient group to whom the data is transferred, and the group of persons to whom the data relates, detailing the maximum retention period required for the purposes for which the personal data are processed, any personal data anticipated to be transferred to foreign countries, and the measures taken regarding data security.

Processing of Personal Data: Any operation performed on personal data, such as collection, recording, storage, retention, alteration, reorganization, disclosure, transfer, acquisition, making retrievable, classification or prevention of use, whether wholly or partly by automated means, or by non-automated means provided that it forms part of a data recording system.

Board: The Personal Data Protection Board

Special Categories of Personal Data: Data relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of an association, foundation or trade union, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data.

Periodic Destruction: The process of deletion, destruction or anonymization to be carried out ex officio at recurring intervals specified in the personal data retention and destruction policy, in the event that all of the conditions for processing personal data set out in the Law cease to apply.

Policy: Personal Data Retention and Destruction Policy

Data Processor: A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller.

Data Recording System: The recording system in which personal data is structured and processed according to specific criteria.

Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.

Data Controllers' Registry Information System: The information system, accessible over the internet, created and managed by the Presidency, that data controllers use for registry applications and other related registry transactions.

VERBİS: Data Controllers' Registry Information System

Regulation: The Regulation on the Deletion, Destruction or Anonymization of Personal Data, published in the Official Gazette dated 28 October 2017.

2. RESPONSIBILITY AND DIVISION OF DUTIES

The Company has established a personal data committee to carry out and oversee the personal data processing process. The Committee controls and executes the process from the collection of personal data to its destruction and disposal, within the framework of the Law and relevant legislation. It also carries out effective activities within the Company by keeping the measures and documents required to be maintained in the process following the destruction of personal data.

DIVISION OF DUTIES OF THE PERSONAL DATA COMMITTEE

The Personal Data Committee consists of three persons: a manager, an administrative expert and a technical expert. The Company employees on the Personal Data Committee and their duties are as follows.

CHAIR OF THE PERSONAL DATA COMMITTEE

MEHMET ÖZAĞAN — Responsible for the preparation, execution and updating of the Policy, and for all operations that need to be carried out in the personal data processing process.

MEMBERS OF THE PERSONAL DATA COMMITTEE (TECHNICAL MEMBER AND ADMINISTRATIVE MEMBER)

DURSUN GÜL, ABDULKERİM KESKİN — Responsible for the technical and administrative implementation of the decisions taken by the personal data committee, and for the entire process from the commencement of personal data processing through to the execution of retention and destruction processes.

3. RECORDING MEDIA

Personal data is stored securely and lawfully by the Company in the media listed below.

ELECTRONIC MEDIA: Servers, Server, Software, Information security devices, Personal computers, Mobile devices, Optical disks, Removable storage media, Printers, scanners, photocopiers.

NON-ELECTRONIC MEDIA: Paper, Manual data recording systems (survey forms, visitor entry logbook), Written, printed, visual media, Unit cabinets (locked and with limited access), Archive (specially protected).

4. EXPLANATIONS REGARDING RETENTION AND DESTRUCTION

Personal data belonging to Employees, Service providers, Supplier representatives, Supplier employees, Persons receiving products or services, Potential recipients of products or services, Visitors and online visitors are retained and destroyed by the Company in accordance with the Law.

4.1 EXPLANATIONS REGARDING RETENTION

Personal data, as defined under Article 3 of the Law, is processed in accordance with the principles set out in Article 4 of the Law — being lawful and fair, being accurate and, where necessary, kept up to date, being processed for specified, explicit and legitimate purposes, being relevant, limited and proportionate to the purposes for which they are processed, and being retained for the period stipulated by the relevant legislation or required for the purpose for which they are processed — and in accordance with Articles 5 and 6 of the Law. Personal data is retained for a period appropriate to the legislation and the Company's interests.

4.1.1 LEGAL GROUNDS REQUIRING RETENTION

Personal data processed within the scope of the Company's activities is retained for the period stipulated by the relevant legislation, including: Law No. 6698 on the Protection of Personal Data; Law No. 5510 on Social Insurance and General Health Insurance; Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed through Such Publications; Law No. 6331 on Occupational Health and Safety; Law No. 3071 on the Exercise of the Right to Petition; Law No. 4857 on Labor; Law No. 6102 on the Turkish Commercial Code; Law No. 213 on Tax Procedure; and other secondary regulations in force pursuant to these laws.

4.1.2 PURPOSES OF PROCESSING REQUIRING RETENTION

The Company retains personal data for purposes including: emergency management; information security; employee satisfaction and loyalty; employment contract and legislative obligations; employee benefits; training activities; access authorizations; finance and accounting; company/product/service loyalty; physical space security; assignment processes; legal affairs; internal audit/investigation/intelligence; communication activities; human resources planning; execution/audit of business activities; occupational health/safety; improvement of business processes; business continuity; logistics; purchasing; after-sales support; sales processes; production and operations; customer relationship management; customer satisfaction; marketing analysis; advertising/campaigns/promotions; contract processes; requests/complaints; wage policy; product/service marketing; talent/career development; providing information to authorized persons/institutions; visitor records; and processing responsibility arising from applicable laws.

4.2 GROUNDS REQUIRING DESTRUCTION

Personal data shall be deleted, destroyed or anonymized by the Company, either upon the request of the data subject or ex officio, where: the relevant legislative provisions forming the basis for processing are amended or repealed; the purpose requiring processing or retention ceases; where personal data is processed solely on the basis of explicit consent, that consent is withdrawn; an application by the data subject under Article 11 of the Law regarding deletion/destruction is accepted by the Company; the Company rejects such an application, finds the response insufficient, or fails to respond within the legal period, and the Board upholds the data subject's complaint; or the maximum retention period has elapsed with no justification for further retention.

5. TRANSFER OF PERSONAL DATA

Personal data processed by the Company, within the framework of the personal data processing conditions and purposes specified in Article 8 of Law No. 6698, limited to and related to the Company's field of activity, may — subject to explicit consent and limited to that consent, or in accordance with Article 5(2) and Article 6(3) of Law No. 6698 — be transferred to: 1. Dealers, for commercial activities; 2. Our affiliates; 3. Audit firms, for financial/legal/technical audits; 4. Legal, financial and tax advisors; 5. Our shareholders, for planning commercial activities; 6. Public institutions and organizations, within legal obligation; 7. Banks; 8. Principal employers and subcontractors; 9. The data processor, under contract; 10. Business partners; 11. Travel agencies, hotels and airlines, for planning employee business travel; 12. Our suppliers and supplier employees; 13. Insurance companies; 14. The customer, for product/service delivery.

TRANSFER ABROAD

Your personal data may be transferred abroad by the Company in accordance with Article 9 of the Law, either where explicit consent exists in accordance with Article 4(2) of Law No. 6698, or, without explicit consent, where the conditions set out in Article 5(2) and Article 6(3) of the Law are met.

6. TECHNICAL AND ADMINISTRATIVE MEASURES

Technical and administrative measures are taken by the Company, within the framework of the adequate measures determined and announced by the Board for special categories of personal data pursuant to Article 6(4) and Article 12 of the Law, to ensure the secure storage of personal data, prevent unlawful processing and access, and ensure lawful destruction.

6.1 TECHNICAL MEASURES

Unauthorized access is logged and controlled; strong passwords are used in electronic environments; network and application security are ensured; a closed system network is used for network transfers; security measures are taken for IT system procurement, development and maintenance; the security of cloud-stored data is ensured; an authorization matrix has been established for employees; access logs are kept regularly; firewalls are used; personal data security is monitored; environments containing personal data are secured; personal data is minimized wherever possible; personal data is backed up and backups are secured; log records are kept without user intervention; existing risks and threats have been identified; attack detection and prevention systems are used; penetration testing is applied; cyber security measures are taken and continuously monitored; special categories of personal data transferred via portable media, CDs or DVDs are encrypted; the awareness of data processor service providers regarding data security is ensured; access to the Company's website is encrypted using SHA-256-bit RSA via HTTPS; data transfer between servers is carried out via VPN or sFTP; where transfer via paper is required, necessary measures are taken against theft, loss or unauthorized viewing, and documents are sent in "confidential" format.

6.2 ADMINISTRATIVE MEASURES

Necessary security measures are taken regarding entry/exit to physical environments containing personal data; employees receive training and awareness training; disciplinary regulations containing data security provisions are in place; data security measures are applied in signed contracts; personal data is minimized wherever possible; a retention and destruction policy has been prepared and put into effect; confidentiality undertakings are applied; provisions are included in service agreements; access authorizations of departing or reassigned employees are revoked; a disclosure notice is prepared and explicit consent is obtained; destruction processes in accordance with the Retention and Destruction Policy are defined.

6.3 INTERNAL COMPANY AUDIT

The Company conducts audits, at set or unset intervals, regarding the implementation of the Personal Data Processing and Protection Policy. Non-compliant situations identified are remedied immediately, and any unauthorized access or unlawful acquisition of personal data identified during an audit is reported immediately to the Board and the relevant data subjects.

7. PERSONAL DATA DESTRUCTION TECHNIQUES

At the end of the legally or purpose-required retention period, personal data is destroyed by the Company, either ex officio or upon application of the data subject, using the techniques below.

7.1 DELETION OF PERSONAL DATA

For personal data on servers whose retention period has expired, the system administrator revokes access authorization to delete the data. In the cloud, deletion is carried out via a delete command. For data in physical media, access is revoked for all employees other than the archive-responsible unit manager, and a blackout process is applied by obscuring the data so it cannot be read. For data on portable/flash media, it is encrypted with access limited to the system administrator and securely stored with encryption keys.

7.2 DESTRUCTION OF PERSONAL DATA

Personal data on paper is irreversibly destroyed using paper shredders. Data on optical/magnetic media is physically destroyed by melting, burning or pulverizing; magnetic media is additionally exposed to a high-value magnetic field to render data unreadable, and random 0/1 data is written at least seven times to prevent recovery. Data held in the cloud is deleted via digital command in an unrecoverable manner, and all copies of encryption keys are destroyed when the cloud service relationship ends.

7.3 ANONYMIZATION OF PERSONAL DATA

Anonymization renders personal data impossible to associate with an identified or identifiable natural person, even when matched with other data. Methods that may be used include: a) Removing variables; b) Removing records; c) Regional suppression; ç) Generalization; d) Lower and upper bound coding; e) Global coding; f) Sampling; g) Micro aggregation; h) Data swapping; ı) Adding noise.

8. RETENTION AND DESTRUCTION PERIODS

10 years following contract termination; Communication Activities — 10 years after activity ends; Human Resources Processes — 10 years after activity ends; employee health data — 10 years after employment ends; log tracking systems — 2 years; hardware/software access processes — 2 years; visitor and meeting participant records — 2 years after the event; camera recordings — 2 months; responses to court/enforcement information requests about personnel — 10 years after employment ends; contracts with third parties — 10 years from termination; personnel personal file — 10 years after employment ends; unsuccessful job applications — 2 years from the negative outcome; wage/salary documents — 10 years after employment ends; personnel private health and accident insurance policies — 10 years after employment ends; vehicle license plate information (third parties) — 5 years from recording; occupational health and safety records — 15 years after employment ends; payment transactions — 10 years from payment; personnel financing processes — 10 years after employment ends; contract-related personal data — 10 years after employment ends; internet/wifi access information (guests/employees) — 2 years from recording; request/complaint information — 5 years from recording; filing of documents and training records — 10 years; customer data — 10 years from transaction termination. All personal data will be destroyed at the first periodic destruction period following the end of its determined retention period. Where personal data relates to a criminal offense, it is retained for the duration of the relevant statute of limitations under the Turkish Penal Code.

9. PERIODIC DESTRUCTION PERIOD

Pursuant to Article 11 of the Regulation, the periodic destruction period is set at 6 months. The Company carries out periodic destruction every June and December.

10. PUBLICATION AND RETENTION OF THE POLICY

The Policy is published in both physical and electronic media and disclosed on the Company's website. A printed copy is kept in the Company's KVKK compliance file.

11. ENTRY INTO FORCE AND REPEAL OF THE POLICY

The Policy entered into force on 01/02/2025. If repealed, the prior version is retained in the Company's KVKK compliance file for at least 5 years.

12. UPDATE PERIOD OF THE POLICY

This policy is reviewed and updated as needed in the event of legislative, sector or technical developments. Updates are reflected in the text immediately along with an explanation of the change.

13. UPDATE TABLE

Changes made to this Policy: Update Date 01/02/2025 — Changes: VERSION 2.