POLICY FOR CONFIDENTIALITY AND PROTECTION OF PERSONAL DATA
- POLICY OBJECTIVE AND SCOPE
- APPLICANTS
- Personal Data Collected in Relation to Applicant Group of Individuals
- Personal background, work experience, educational background, foreign language certificate and other certificates,
- Name and surname, address, date of birth, e-mail address, telephone number and other contact details,
- Records of information obtained during face to face interviews or via teleconference, video call or telephone,
- References or information obtained via research conducted by MODANISA,
- Results of recruitment assessment tools determining skills and personal attributes,
- Salary expectations, disabilities and liabilities,
- Purposes for Collecting and Processing Personal Data of Applicants
- Evaluating the suitability of the applicant’s qualifications, experience and interest in relation to the vacant position,
- Checking the validity of the information submitted by the applicant or contacting third parties for reference check purposes when required,
- Contacting applicant concerning the recruitment process or, if suitable, contacting the applicant for any position subsequently opened in the country or abroad,
- Meeting the requirements of regulations or those of an authorized body or organization,
- Developing and improving the recruitment principles implemented by MODANISA,
- Implementing operations which are required within the context of occupational health and safety.
- Methods of Collecting and Processing of Personal Data of Applicants
- Application form in print or published in an electronic environment,
- CVs which have been submitted to MODANISA by applicants via e-mail, cargo, references and similar methods.
- Recruitment or consultancy firms and LinkedIn,
- Research carried out by MODANISA with the aim of confirming the accuracy of information obtained from the applicant during interviews conducted
- Via tools such as video conferencing and telephones,
- Recruitment tests which determine skills and personal attributes, carried out and analyzed by experienced experts.
- Applicant Reference Checks
In the context of the reference check, necessary personal data such as the identification information of third parties and applicants, work and educational backgrounds may be shared. Personal data concerning the applicant may be obtained from third parties .
Applicants may, at all times, contact MODANISA regarding the reference check process.
- Applicants’ Rights Related to their Personal Data
- The Personal Data Collected During the Application Process Which will Continue to be Processed in the Instance of Recruitment
- Security of Applicants’ Personal Data
- PRINCIPLES IN RELATION TO PROCESSING OF PERSONAL DATA
- Processing in Compliance with Law and Principle of Honesty
- Ensuring that the Personal Data is Accurate and Up-To-Date when Necessary
- Processing for Specific, Clear and Legitimate Purposes
- Being related to and Limited to the Purpose of Processing thereof, and Being Measured
- Preserving for the Period Stipulated in the Relevant Legislation or the Period Required for the Purpose of Processing Thereof
Preservation periods have been additionally indicated below.
- TERMS AND CONDITIONS IN RELATION TO PROCESSING OF PERSONAL DATA
The basis on which personal data processing activity is carried out may be one or more than one of the below-specified conditions specified by the law. In the case where the personal data processed constitute private personal data; conditions listed under the heading “Circumstances Where Private Personal Data May be Processed” will be applied.
Individuals are informed of which personal data are being processed under this hereby POLICY, for which purposes and reasons the personal data are being processed, from which resources the personal data are collected, with whom these personal data will be shared, and how they will be used.
- Being Explicitly Stipulated by Laws
- Inability to Obtain Express Consent of the Relevant Person Due to Actual Impossibility
- Direct Relationship with Conclusion or Performance of a Contract
- Performance by MODANİSA of its Legal Obligation
- Making Public the Personal Data of Individuals
- Obligation to Process Data for Establishment or Protection of a Right
- Processing of Data Based on Legitimate Interest
- Processing of the Employee’s Personal Data Based on Express Consent
- CIRCUMSTANCES WHERE PRIVATE PERSONAL DATA MAY BE PROCESSED
- Processing of Private Personal Data Based on Express Consent
- Circumstances Where Private Personal Data may be Processed Without Express Consent
- Private personal data other than the individual’s health condition and sexual life, in cases where stipulated by laws,
- Private personal data in respect of the health of the individuals and sexual life shall be only available to persons who are bound by the duty of confidentiality or authorized bodies and institutions for the purpose of public health protection, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and financing.
- ENLIGHTENING AND INFORMING INDIVIDUALS
In case individuals request information in relation to their personal data, MODANİSA shall inform them through [email protected] . Physical visitors shall be informed about the video cameras present on MODANISA's premises . Additionally, there are signs placed at visible points inside the building, which offer brief information. With this hereby Policy, users visiting the MODANISA web site are informed; those who become Members are informed yet again not only by this hereby Policy, but also with the details presented on the Membership page.
MODANISA Contact Person: Lawyer Fatih Onur LENGERLİ
[email protected]
- CATEGORIZATION OF PERSONAL DATA
- Credentials
- Contact Details
- Location Data
- Information on Family Members and Kith and Kin
- Physical Space Security Information
- Financial Information
- Personal Information
- Candidate Employee Information
- Individuals Processing Information
- Legal Transactions and Compliance Information
- Private Personal Data
- Information on Complaint Management
- PURPOSE OF PROCESSING OF PERSONAL DATA
- Processing Conditions
- The relevant activity in relation to the processing of your personal data is explicitly stipulated by laws,
- The processing of your personal data by MODANİSA is directly related to and necessary for the conclusion or performance of a contract,
- The processing of personal data is mandatory for the fulfillment of MODANİSA’s legal obligation,
- Provided that the personal data has been shared with public by the individuals; to be processed by MODANISA in a proportional manner for the purpose of publicity .
- Processing by MODANİSA of personal data is mandatory for the establishment, exercise or protection of rights of MODANİSA or its individuals or third persons,
- Provided that the fundamental rights and freedoms of individuals are not infringed , the processing personal data is obligatory in order to uphold the legitimate interests of MODANİSA,
- The processing of personal data by MODANİSA is mandatory for the preservation of the life and physical integrity of the data owner or another person, and in such a case where the owner of personal data is in a position where he /she cannot give his/her consent due to an actual impossibility or legal invalidity.
- Processing Purposes
Candidate Working Group:
- Ensuring completion and implementation of human resources policies and processes ,
- Planning the selection and evaluation procedures of candidate worker’s applications,
- Implementing required operations within the framework of occupational health and safety regulations,
- The communication activities necessary for the placement of the working candidate,
- Internship recruitment, placing and planning of operational processes.
- For intern lawyers; To fulfill the legal requirements within the scope of professional solidarity under the Legal Profession Act.
- Fulfilling the legal requirements stipulated in the law on electronic trade and the Turkish code of commerce.
- Planning activities focusing on customer satisfaction and/or experience.
- Legal, regulatory and company management legislations and ensuring compliance with correct application.
- Preparation of product to be delivered in accordance with the customer’s order and providing assurance that delivery shall be made e within guaranteed time frame.
- In cases of cancellation and returns, relaying information to relevant department to ensure that the customer is reimbursed as soon as possible.
- .Establishing and implementing processes for ensuring the security of information.
- For the risk to be reduced to an acceptable level.
- Risk Management.
- Forming Access Authorization and Control Matrix.
- Identifying Data Transfer techniques.
- Creating data preservation processes and procedures
- Identification and implementation of remote access procedures an processes
- Use of results derived from the sharing of anonymous data within the framework of customer CRM applications in decision support systems.
- Correct targets within the scope of campaign planning, feasibility studies and CRM.
- Invoicing and regular pursuance.
- Fulfilling company obligations.
- Data collection to form a customer portfolio.
- Data collection to bring a product which is not in stock for customers.
- Data collection to be able to provide tailoring services to customers.
- Management of the business process with suppliers.
- Implementation of legal processes and requirements such as contracts for the service required .
- Establishing communication with the relevant supplier for production on behalf of the company.
- Drawing up contracts with selected suppliers.
- Carrying out purchasing procedures.
- Monitoring and supervision of manufacturing process.
- Managing communication with the depot during the cancellation procedures when deficient or faulty products are received.
- Supervision of payments and granting approvals.
- In accordance with the Occupational Health law and agreement.
- Payment and supervision of premiums to be paid to employees and the government, pursuant of the SGK (Social Security Institution) regulation.
- Checking whether employees hold a certificate of competency (a certificate, document of authority, etc. depending on their occupation)
- Inspection of documents regarding hygiene and working at heights.
- Evaluation of supplier employees’ suitability according to OHS laws.
- Checking whether Social Security Institution premium debts have been paid.
- Gathering of required information and documents in order to establish a legal relationship with the supplier.
- Managing relationships with suppliers.
- Ensuring company resources are used economically and focusing on improvement of company operations based on customer oriented approach.
- Determining the needs of the depot and resolving it in a speedy and cost-effective manner.
- Carrying out purchasing transactions required by the company.
- Preparation of required visuals for product promotion and marketing.
- Recruitment of manpower required for the preparation of visuals necessary for product promotion and marketing.
- Obtaining documentation from real person or legal entity supplier processing personal data indicating adherence to liabilities in terms of Modanisa’s data security, pursuant to the LPPD.
- Supervision of whether obligations are fulfilled and planning auditing.
- Foreseeing the liability for suppliers to preserve confidentiality indefinitely.
- Drafting a clause indicating that in the the case where personal data relayed to suppliers is not obtained via legal channels, the supplier is obliged to inform Modanisa of the situation as soon as possible.
- Legal, regulatory and company management legislations and ensuring compliance with correct application.
- Obtaining information and documents required for the management of legal and administrative procedures.
- Fulfilling legal obligations .
- Requirement of adherence to legislative regulations.
- Logging of online visitors and user’s system actions.
- Obtaining information and documents required for the management of legal and administrative procedures.
- TRANSFER OF PERSONAL DATA TO THIRD PERSONS NATIONALLY AND ABROAD
- Transfer of Personal Data
E-mail and/or telephone number may be shared with third parties abroad for singularization and match-up purposes. Information of anonymous quality about online visitors which are non-member and their website use habits are collected with cookies and can be shared.
- Third Persons to Whom the Personal Data are Transferred, and Their Purpose of Processing
- Business partners of MODANİSA,
- Suppliers of MODANİSA,
- Affiliates of MODANİSA,
- Shareholders of MODANİSA
- Legally competent public institutions and organizations,
- Legally competent private jurists.
- PRESERVATION PERIOD OF PERSONAL DATA
| DEPARTMENT NAME | PERSONAL DATA GROUP | PERSONAL DATA CATEGORY | PRESERVATION PERIOD |
| LAW | Employee Data | Credentials Contact Details Financial Information Information on Legal Transactions Personal Information Educational Information Professional Experience and Knowledge Information on Side Benefits Personnel Group Information Organization Information Information on the Employee’s Performance and Career Development Private Personal Data | 10 years pursuant of Turkish Code of Obligations |
| Supplier Data (Real Person, Supplier Executive, Supplier Employee) | Credentials Contact Details Financial Information Information on Legal Transactions Risk Management Private Personal Data | 10 years following conclusion of legal relationship | |
| Consultant/Trainer | Credentials Contact Details Financial Information Information on Legal Transactions Private Personal Data | 10 years following conclusion of legal relationship | |
| Intern Lawyer | Credentials Private Personal Data | 1 year following conclusion of internship | |
| Customer | Credentials Contact Details Financial Information Information on Legal Transactions Private Personal Data | 10 years following conclusion of legal relationship | |
| Claimant 3. Individuals | Credentials Contact Details Financial Information Information on Legal Transactions Information on Customer Transactions Transaction Security Information Risk Management Information Private Personal Data | 10 years as of final judgment | |
| Public official representative of the office running the investigation and proceedings | Credentials Information on Legal Transactions Private Personal Data | 10 years as of final judgment | |
| Shareholder/Partner | Credentials Contact Details Financial Information Information on Legal Transactions Educational Information Private Personal Data | Unlimited Time | |
| HUMAN RESOURCES | Employee Data | Credentials Contact Details Personal Information Professional Experience and Knowledge Financial Information Information on Legal Transactions Educational Information Side Benefits Private Personal Data | 50 years |
| Copy of Marriage Certificate Copy of Children’s IDs Personnel Group Contact Details | 10 years | ||
| Employee Candidate | Credentials Contact Details Personal Information | 3 years | |
| Intern (Normal) | Credentials Contact Details Personal Information Financial Information Educational Information Information on Transactions of Employee Private Personal Data | 10 years | |
| Intern (Mandatory) | Credentials Contact Details Private Personal Data Educational Information | 10 years | |
| PRODUCT | Employee Data | Credentials Contact Details Corporate Identity Information Information on Transactions of Employee | 5 years following the end of legal relationship |
| Customer Data | Contact Details | Upon the end of the legal relationship; 1 year as of the date of retrieval of the commercial electronic message permit, 3 years for all records related to electronic trade, 2 years of traffic information pursuant of the law no. 5651, 10 years pursuant to TPL, TCO, TCC, Consumer Protection Law. | |
| Supplier Data (Supplier Employee, Supplier Executive) | Credentials Contact Details Financial Information Corporate Identity Information Private Personal Data | Upon the end of the legal relationship, 10 years in accordance with TCC and TPL. | |
| PRIVATE LABEL | Supplier Data (Supplier Employee, Supplier Executive, Accounting Executive. | Credentials Personal Information Contact Details Private Personal Data Corporate Identity Information Financial Information | 10 years following the end of legal relationship |
| Employee Data | Private Personal Data | 10 years following the end of legal relationship | |
| ADMINISTRATIVE AFFAIRS | Supplier Data (Supplier Employee, Supplier Executive) | Personal Information Credentials Private Personal Data Financial Information Contact Details Information on Legal Transactions | 10 years following the end of legal relationship |
| IT ( INFORMATION TECHNOLOGIES) | Employee Data | Credentials Personal Information Contact Details Risk Management Information Transaction Security Information | 10 years |
| Risk Management Information (Mac Adress, Internet Logs) | 2 years | ||
| Online Visitor Data | Transaction Security Information Risk Management Information | 2 years | |
| Customer Data | Credentials Contact Details Financial Information Information on Customer Transactions Transaction Security Information Risk Management Information Information on Legal Transactions | 10 years | |
| Supplier Data | Credentials Transaction Security Information Corporate Identity Information Contact Details Financial Information | 10 years | |
| STORE | Employee Candidate Information | Credentials Contact Details Personal Information Private Personal Data | 2 years |
| Supplier Data | Credentials Financial Information Contact Details Private Personal Data | 10 years | |
| BUSINESS DEVELOPMENT | Customer Data | Credentials Financial Information Contact Details Purchase Order Information | Until the end of the project period. |
| Supplier Data | Contact Details Corporate Identity Information Financial Information | Until the end of the project period. | |
| On-line Visitor Data | Credentials Contact Details Location Information Information on Pages Visited | Until the end of the project period. | |
| ACCOUNTING | Employee Data | Credentials Contact Details Corporate Identity Information Financial Information Personal Information Private Personal Data | 5 years in accordance with TPL, 10 years in accordance with TCC |
| Supplier Data | Credentials Contact Details Financial Information Private Personal Data | 5 years in accordance with TPL, 10 years in accordance with TCC | |
| Customer Data | Credentials Financial Information Contact Details | 5 years in accordance with TPL, 10 years in accordance with TCC | |
| Purchase Department | Employee Data | Credentials Corporate Identity Information Contact Details | 5 years following conclusion of legal relationship |
| Supplier Data | Credentials Contact Details Financial Information Corporate Identity Information Private Personal Data Risk Management Information | 10 years following the end of legal relationship | |
| STUDIO | Employee Data | Credentials Corporate Identity Information Contact Details | 5 years following the end of legal relationship |
| Supplier Data | Credentials Contact Details | 10 years following conclusion of legal relationship | |
| Private Personal Data (Photograph, video recordings) | 70 years following the end of legal relationship | ||
| Transaction Information | Arranged to be updated on an annual basis |
- SAFETY OF PERSONAL DATA
To prevent access to personal data by persons other than those who have been granted authorisation to access , all necessary technical and physical measures are taken. .In this context, particularly the authorization system shall be designed in such a way to make it impossible for anyone to access personal data to an extent which is more than required While ensuring safety of private personal data such as health data, measures which are more strict compared to measures related to other personal data are taken.
Authorized persons are subjected to necessary safety checks . In addition, the aforementioned persons are trained in relation to their duties and responsibilities.
Records of access to personal data are kept to the extent permitted by technical opportunities, and these records are reviewed at regular intervals. When an unauthorized access is suspected , an investigation is immediately initiated .
MODANISA shall comply with the obligations specified below for the purpose of ensuring safety of the data being processed:
- Acting lawfully and honestly regarding the matters related to the protection of personal data,
- Processing the personal data accurately and in full,
- Carrying out the necessary practices for the purpose of updating the personal data which are outdated.
- When he/she notices any contradiction with the law in relation to processing of personal data, it shall inform the relevant manager,
- Making necessary referrals for the exercise of legal rights related to personal data,
- LEGAL RIGHTS OF INDIVIDUALS AND METHODS FOR EXERCISING THESE RIGHTS
- Rights Related to Personal Data in the Context of LPPD
- Learn whether or not personal data have been processed,
- Request information on the procedure, if personal data have been processed,
- Obtain information on the purpose of processing personal data and find out whether personal data were used as fit for the purpose,
- Obtain information about the third persons to whom personal data were communicated domestically or abroad,
- Request the correction of personal data that may have been incompletely or inaccurately processed,
- Request the deletion or destruction of personal data within the provisions set forth in applicable legislation,
- Request that the third parties to whom personal data are transferred are informed about the transaction carried out pursuant to sub-paragraphs (d) and (e),
- Object to an outcome which is detrimental to the concerned as a result of the analysis of the processed data exclusively through automatic systems,
- Request compensation for damages in the case that damages are sustained as a result of the illegal processing of personal data..
- Principles in Relation to Exercising Rights in Relation to Personal Data
13 EFFECTIVENESS AND UPDATABILITY
This hereby POLICY has entered into force on date of publication. The Policy may be updated for the purpose of adaptation to changing conditions and compliance with the legislation. Information regarding the relevant update will be provided via www.modanisa.comANNEX-1
DEFINITIONS STATED IN THE POLICY
Express Consent: Consent in relation to a specific matter, which is based on informing and which is expressed with free will.
Anonymization : Anonymization of personal data is to render it impossible for personal data to be associated in any manner with the identity of a real person who is is identified or identifiable, even if they are matched with other data.
Personal Data Owner: Real persons whose personal data is being processed. For example, Members, Customers...
Personal Data: means any kind of information about an identified or identifiable real person.
Private Personal Data: Data in relation to race, ethnic origin, political opinion, philosophic belief, religion, sect or other beliefs, appearance, membership to associations, foundations or unions, health, sexual life, imprisonment and security measures and biometric and genetic data are private personal data.
Personal Data
Protection : Any transaction carried out with the data, such as obtaining, recording, storage, preservation, alteration, reorganization, disclosure, transfer, takeover, making available , classifying the personal data or blocking its usage by full or partly automatic means, or by non-automatic means provided that they are part of a data entry system.
Data Processor: Real and legal persons who process personal data on behalf of the data supervisor depending on the authorization granted by the data supervisor.
Data Responsible: Real and legal persons who determine the aims and tools with which personal data will be processed , real and legal persons responsible for responsible for the establishment and management of the data record system .
KVKK: means the Law on the Protection of Personal Data No. 6698
Click for the Data Protection Law application form.
Click for the Data Protection Law violation notice form.
