Image Alt

Storage and Destruction Policy

ÜNALLAR METAL İNŞAAT SANAYİ VE TİCARET ANONİM ŞİRKETİ

PERSONAL DATA STORAGE AND DESTRUCTION POLICY

ÜNALLAR METAL İNŞAAT SANAYİ VE TİCARET ANONİM ŞİRKETİ

PERSONAL DATA STORAGE AND DESTRUCTION POLICY

INFORMATION FORM

Document Name:

Ünallar Metal İnşaat Sanayi ve Ticaret Anonim Şirketi Personal Data Storage and Destruction Policy

Target Group:

All natural persons whose personal data are processed by Ünallar Metal İnşaat Sanayi ve Ticaret Anonim Şirketi

Prepared and Approved By:

Ünallar Metal İnşaat Sanayi ve Ticaret Anonim Şirketi Board of Directors

Version:

2.0 

Effective Date:

20/02/2023

The Policy has been prepared in Turkish language and in case of translation into any other language, if there is a discrepancy between the translation and the Turkish text, the Turkish text should be taken into consideration.

CONTENTS

  1. INTRODUCTION
  2. PURPOSE AND SCOPE OF THE POLICY
  3. DEFINITIONS. 3
  4. TITLES, UNITS AND JOB DESCRIPTIONS OF PERSONS INVOLVED IN DATA STORAGE AND DESTRUCTION PROCESSES
  5. REGISTRATION ENVIRONMENTS REGULATED BY THE POLICY
  6. REASONS FOR STORING AND DESTROYING PERSONA DATA.
  7. DESTRUCTION METHODS OF PERSONAL DATA
  8. TECHNICAL AND ADMINISTRATIVE MEASURES TAKEN FOR SECURELY STORING PERSONAL DATA AND PREVENTING ILLEGAL PROCESSING AND ACCESS
  9. STORAGE AND DESTRUCTION PERIODS
  10. PERIODIC DESTRUCTION PERIODS
  11. ENFORCEMENT

ANNEX – 1 Storage and Destruction Periods Table

ANNEX – 2 Personal Data Categories

ANNEX -3 Personal Data Holders

ÜNALLAR METAL İNŞAAT SANAYİ VE TİCARET A.Ş.

PERSONAL DATA STORAGE AND DESTRUCTION POLICY

1.   

INTRODUCTION

Processing and ensuring the security of personal data in compliance with the regulations in the relevant legislation, thus disciplining the processing of personal data is among the priorities of Ünallar Metal İnşaat Sanayi ve Ticaret A.ş. (“Ünallar Metal” or “Company”).

With regard to this, Ünallar Metal stores and destroys personal data obtained during activities in compliance with the general principles and regulations stated in Ünallar Metal İnşaat Sanayi ve Ticaret A.Ş. Personal Data Storage and Destruction Policy (“Policy“) prepared primarily in line with the Constitution, Personal Data Protection Law (“Law“) numbered 6698, Regulation on Erasure, Destruction and Anonymization of Personal Data (“Regulation“) and other relevant legislation.

 

2.     

PURPOSE AND SCOPE OF THE POLICY

The purpose of hereby Policy is to determine principles and procedures regarding the storage and destruction of personal data in compliance with regulations specified in the relevant legislation regarding the personal data processed within the scope of various activities carried out by Ünallar Metal.

Hereby Policy covers all personal data subject to data processing activities of the Company under the scope of the Law.

 

3.     

DEFINITIONS

Provided that the content does not require otherwise, the following shall have the above meanings in hereby Policy:

Explicit Consent

The consent expressed related to a specific subject based on the information and with free will,

Buyer Group

Natural or legal person category to whom the personal data is transferred by the data responsible,

Constitution

The Constitution of the Republic of Türkiye

Relevant User

Persons who process personal data within the organization of the data controller or in line with the authorization and instruction received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.

Destruction

Deletion, destruction or anonymization of personal data,

Recording Media

Any environment that is fully or partially automated, or any environment where personal data is processed by non-automatic means, provided that it is part of any data recording system,

Personal Data

All kinds of information about an identified or identifiable natural person. The Categories of Personal Data processed by the Company and their descriptions are included in Annex-2.

Personal Data Owner

The natural person whose personal data is processed. The Personal Data Owners who are the subject of the Company’s Personal Data Processing activities are included in Annex-2.

Processing of Personal Data

All kinds of operations performed on the data, such as obtaining, recording, storing, preserving, changing, rearranging, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data in whole or in part by automatic or non-automatic means provided that it is a part of any data recording system,

Board

Personal Data Protection Board,

Sensitive Personal Data

Data on race, ethnicity, political thought, philosophical belief, religion, sect or other beliefs, dress, association, foundation or union membership, health, sexual life, criminal conviction and security measures, and biometric and genetic data. Health data and data on criminal convictions and security measures are processed by the company.

Periodic Destruction

in the event that the conditions of processing of personal data contained in the Law cease to exist, the deletion, destruction or anonymization process specified in this Policy, which will be carried out ex officio at repetitive intervals,

Data Controller

It means the natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the place where the data is stored in a systematic way

(Recording Environment)

 

4.     

TITLES, UNITS AND JOB DESCRIPTIONS OF PERSONS INVOLVED IN DATA STORAGE AND DESTRUCTION PROCESSES

All units and employees of the Company support the responsible units in the proper implementation of the technical and administrative measures taken by the responsible units within the scope of the Policy, the prevention of illegal processing and access of personal data, the storage of personal data in accordance with the provisions of the Law and other relevant legislation, and their destruction in accordance with the destruction periods and methods of destruction. In this context, processes related to increasing the education and awareness of employees and Related Users, monitoring and continuous supervision are carried out.

The details about the persons involved in the storage and destruction processes of the Company are as follows:

Title

Unit

Position

 

Human Resources Manager

Human Resources Department

It is responsible for the preparation, dissemination and execution and updating of the Policy within the Company. In addition, it is responsible for the implementation of the Policy in terms of the personal data of employees, employee candidates, subcontractor employees.

IT manager

Information Technology Department

It is responsible for the preparation, dissemination and execution and updating of the Policy within the Company. It is responsible for the irreversible removal of the expired personal data stored in digital media from access in accordance with the periodic destruction periods.

Assistant to the Chairman of the Board of Directors

Management

The Company is responsible for the compliance of the website with the Law and the implementation of the Policy in terms of supplier and customer personal data, personal data of event participants.

Chairman of the Board of Directors and General Manager

 

It is responsible for ensuring compliance with the Law within the Company and ensuring coordination on the implementation of the Policy. 

 

 

 

5. REGISTRATION ENVIRONMENTS REGULATED BY THE POLICY

Electronic and Physical Environments where Personal Data is Stored:

Electronic  Environments

Non-Electronic Environments (Physical)

· Servers (e-mail, website, backup, file servers)

· Systems and Applications (Logo (Accounting and Human resources modules), PDKS (Microprocessor), CCTV system (Camuratech), GPS records(Mobile Trust), social media accounts (Meta Inc.))

· Information security devices (firewall, antivirus, log records, etc. )

· Personal devices (Desktop, laptop computers)

· Printer, scanner, copier,

· HR Archive (Personnel Files, Job Application Files)

· Case Files

· Files for Power of Attorneys and Contracts

· Financial Services Archive

· Activity File

· Occupational Physician Health File

· OHS Training File

·  OHS Personnel File

· Work Accident Files,

· Vehicle Embezzlement File,

· Subcontractor File,

· Supplier and Customer Files,

· General Board File, Board of Directors Decision Book

 

 

6.     

REASONS THAT REQUIRE THE STORAGE AND DESTRUCTION OF PERSONAL DATA

Ünallar Metal is based on the following principles in its personal data processing activities:

·  Compliance with the law and the rule of honesty,

·  Ensuring that personal data is accurate and up-to-date when necessary,

·  Processing for specific, clear and legitimate purposes,

·  Being related, limited and restrained to the purposes for which they are processed, and

·  Storage for the period stipulated in the relevant legislation or required for the purpose for which they are processed.

Ünallar Metal processes personal data in accordance with the above-mentioned principles, for the purposes of processing personal data in the Ünallar Metal Data Processing Inventory and in accordance with the processing conditions of personal data, and if the processing purposes and conditions cease to exist or the storage periods stipulated in the relevant legislation expire, the personal data is destroyed ex officio or upon the request of the personal data owner.

Ünallar Metal stores the personal data as long as the specified storage periods within the framework of the following:

· Law No. 6698 on the Protection of Personal Data,

· Turkish Commercial Code No. 6102,

· Turkish Code of Obligations No. 6098,

· Labor Law No. 4857,

· Social Insurance and General Health Insurance Law No. 5510,

·  Occupational Health and Safety Law No. 6361,

·  Law No. 5651 on the Regulation of Publications Made on the Internet and Combating Crimes Committed Through These Publications,

·  Highway Transportation Law No. 4925

·  Private Security Law No. 5188,

·  Other secondary regulations in force in accordance with these laws

7.     

KİŞİSEL VERİLERİN İMHA EDİLMESİ İŞLEMİ İLE İLGİLİ UYGULANAN YÖNTEMLER

Ünallar Metal deletes, destroys or anonymizes personal data by the following methods in case the purposes and conditions of processing personal data cease to exist or the storage periods stipulated in the relevant legislation expire. Ünallar Metal applies the appropriate method of deletion, destruction, ex officio  deletion, destruction or anonymization in the process of legally destroying personal data in accordance with the provisions of Article 12 of the Law and the provisions of the Regulation, the general principles set forth in Article 4 of the Law, and the relevant technological possibilities and risk/application cost analysis. All transactions performed within the scope of destruction are recorded by us and these records are stored for at least three years, excluding other legal obligations.

(a)    Methods of Erasure of Personal Data

Deletion of personal data is the process of making personal data inaccessible and irrevocable for the Relevant Users in any way. Ünallar Metal applies the following methods in order to make deleted personal data inaccessible and unusable again for the Relevant Users within the scope of technological possibilities and according to the risk / implementation  cost analysis:

Data Recording Environment

Explanation

Personal Data on Servers, Systems and Applications and 3rd  Party Servers

Among the personal data on servers, systems and applications, for those whose period has expired, the access authorization of the relevant users is removed and the deletion process is performed. Any person other than the database administrator is prevented from gaining irreversible access to the said data. For personal data on 3rd  Party servers, it is ensured and controlled that service providers remove access to personal data irreversibly.

Personal Data Contained on Electronic Environment Other Than Servers

Among the personal data on computer and electronic environment, for those whose period has expired, are made inaccessible and unusable again in any way for the relevant users.

Personal Data Contained on the Physical Environment

Among the personal data in a physical environment, for those whose period has expired, are made inaccessible and unusable again in any way for the Relevant Users, except for the unit manager responsible for the document archive. In addition, the darkening process is also applied by drawing / painting/erasing in such a way that it cannot be read on it.

 

(b)   Methods of Destruction of Personal Data

The destruction of personal data is the process of making the personal data inaccessible, irretrievable and unusable again by no one in any way. Ünallar Metal applies the following methods within the scope of technological possibilities related to the destruction of personal data and according to the risk / application cost analysis:

Data Recording Environment

Explanation

Personal Data Contained on the Physical Environment

Among the personal data on the paper environment, for those whose period has expired, are irreversibly destroyed by paper trimming machines or by burning.

 

(c)    Methods of Anonymization of Personal Data

 

Anonymization of personal data means that personal data cannot be associated with an identified or identifiable natural person under any circumstances, even if it is matched with other data. In order for personal data to be anonymized, it is necessary to make personal data irreplaceable to an identified or identifiable natural person even through the use of appropriate techniques in terms of the recording environment and related field of activity, such as returning by Ünallar Metal, buyers or buyer groups, and matching the data with other data.

Ünallar Metal does not use anonymization methods in the destruction of Personal Data.

8.     

TECHNICAL AND ADMINISTRATIVE MEASURES TAKEN FOR SECURELY STORING PERSONAL DATA AND PREVENTING ILLEGAL PROCESSING AND ACCESS

Ünallar Metal shows the utmost care and diligence regarding the safe storage of personal data and the prevention of unlawful processing and access, and takes the necessary technical and administrative measures in accordance with the technological possibilities and implementation costs, in accordance with the provisions of Article 12 of the Law and the provisions of the Regulation, the general principles stated above, this Policy and Board decisions:

Technical Measures

·         The user account management and authorization control system is being implemented, and the powers of employees who have changed their duties or have left their jobs in this area are being removed.

·         An authority matrix has been established for employees.

·         Necessary measures are taken for the physical security of information systems equipment, software and data.

·         It takes the necessary measures to make the deleted personal data inaccessible and reusable for the Relevant Users.

·          Data backup programs are used that ensure the safe storage of personal data.

·          Firewall and antivirus systems are used.

·         Log records are kept in such a way that there is no user intervention.

·         Access to the storage areas where personal data is stored is recorded and inappropriate access or access attempts are kept under control.

·         Secure encryption is used for private personal data.

·         If sensitive personal data is to be sent via electronic mail, it is necessarily sent encrypted and using a KEP or corporate mail account.

Administrative Measures

·         Employees are required to sign confidentiality agreements related to the activities carried out by the company.

·         Training and awareness-raising activities on data security are carried out periodically for employees.

·        Necessary security measures are taken regarding entry and exit to physical environments containing personal data.

·         The security of physical environments containing personal data against external risks (fire, flood, etc.) is provided.

·         Periodic and/or random inspections are carried out and have made.

·         Data minimization is being performed.

·         Before starting to process personal data, the obligation to inform the relevant persons is fulfilled by Ünallar Metal.

·         Monitoring of personal data security is carried out. In the event that personal data is unlawfully obtained by others, an appropriate administrative structure has been established to notify the data owner and the Board within 72 hours at the latest.

·         The Personal Data Processing Inventory has been prepared, current risks and threats and actions to be taken have been determined.

·        The Protection and Processing of Personal Data Policy and the Storage and Destruction Policy have been established.

·         Security measures are taken within the scope of hosting, supply, development and maintenance of information technology systems.

·         Data Transfer Agreements have been signed with the parties to whom personal data is transferred outside the company or who have transferred data to the Company.

 

9.     

STORAGE AND DESTRUCTION PERIODS

 

Ünallar Metal retains personal data only for the period specified in the relevant legislation that it is obliged to comply with or necessary for the purpose for which they were processed, and destroys them after the expiration of this period. Within this scope, Ünallar Metal stores the personal data on a process basis for the maximum periods specified in the Table of Retention and Destruction Periods contained in the annex to this Policy (ANNEX-1) and then destroys it in accordance with the Periodic Destruction Period.

The storage periods related to all personal data within the scope of the activities carried out depending on the processes on the basis of personal data are included in the Personal Data Processing Inventory in detail.

The maximum storage periods based on data categories are included in the VERBİS records.

In the event that the personal data owner requests the destruction of their personal data by contacting the Company, the Company:

(a) In the event that all of the conditions for the processing no longer exist,

(i) finalizes the request of the personal data owner within thirty days at the latest and provides information to the personal data owner,

(ii) In the event that the personal data which are subject to the request have been transferred to any third party; the data controller shall notify the third party of such request and ensure the performance of necessary operations by the third party.

(b) In the event that all of the conditions for the processing have not disappeared completely, the request may be rejected by the data controller in accordance with the Article 13 of the Law together with its justified grounds and such rejection shall be communicated to the data subject in writing or by electronic means at the latest within thirty days.

10.  

PERIODIC DESTRUCTION PERIODS

The Company destroys personal data during the first Periodic Destruction period following the date on which the obligation to destroy personal data arises. In this context, Ünallar Metal has determined the Periodic Destruction period as 6 (six) months in accordance with Article 11 of the Regulation.

 

11.  

ENFORCEMENT

This Policy hereby entered into force on February 20, 2023. The policy may be updated from time to time in order to adapt to changing conditions and legislation. The Current Policy shall enter into force on the day it is published.

In the event that there is a conflict between the policy hereby and Law an Regulation provisions, Law and Regulation provisions shall prevail.

 

ANNEX – 1 Storage and Destruction Periods Table

Process

 

Data Owner

Storage Period

Receiving, evaluating and finalizing job applications

Employee Candidate

The personal data of the candidates whose applications have been rejected and those who may be evaluated for future open positions will be stored for one year from the conclusion of the process. The others are destroyed during the first Periodic Destruction Period. It is determined which data of the candidates whose application has resulted in success should be transferred to the personnel file, and other personal data processed during the job application process are destroyed.

Job Entry and Personnel Procedures

Employee

10 years from the end of the employment period

Payroll, scoring

Employee

10 years from the end of the employment period

Education activities

Employee

Subcontractor Employee

10 years from the end of the Legal Relationship or employment period

Occupational Health and Safety Processes

Employee

Subcontractor Employee

15 years from the end of the Legal Relationship or employment period

Sales Processes

Person Receiving the Product or Service

10 years from the end of the agreement

Information Security and Information Technologies Activities

Employee

Process Security Records are stored for 10 years from the end of employment. Other records are destroyed during the first Periodic Destruction Period after the termination of the legal relationship.

Information Security and Information Technologies Activities

Visitor

Logging records are stored for 2 years.

Vehicle Allocation Processes

Employee

GPS records are stored for 2 years. Vehicle Liability Reports are stored for 10 years from the conclusion of the legal relationship.

Other records are destroyed during the first Periodic Destruction Period after the legal relationship ends.

Finance and Accounting Transactions

Provider Employee/Executive

10 years from the conclusion of the legal relationship

Finance and Accounting Transactions

Employee

10 years from the conclusion of the legal relationship

Finance and Accounting Transactions

Person Receiving the Product or Service

10 years from the conclusion of the legal relationship

Activitiy Management

Participant

1 year from the end of the activity

Purchase Processes

Provider Employee/Executive

10 years from the conclusion of the legal relationship

Facility Security

Employee, Visitor

CCTV records are stored for 90 days.

Institution Management Processes

Employee, Company Executive, Shareholder

10 years from the conclusion of the legal relationship

Lawsuit and Enforcement Processes

Legal Action Party, Person Receiving the Service

It is stored according to the quality of the case during the prescription.

 

ANNEX – 2 Personal Data Categories

PERSONAL DATA CATEGORIES

EXPLANATION

ID Information

The whole information about one’s name – surname, Turkish ID number, place of birth, sex, military status, workplace information, title, etc. with such documents as driver’s license, occupational identity, identity card, and passport and the information contained in these documents

Contact Details

Information of telephone number, address, e-mail address, fax number, etc.

Personnel Information

All kinds of processed personal data for obtaining information that will be the basis for the formation of the personal rights of natural persons who are in a working relationship with the Company

Legal Action and Alignment Information

Information about the tracking of legal transactions, tracking and fulfilling our receivables and debts, fulfilling our legal obligations, personal data processed within the scope of dispute resolution and signatures that constitute a legal basis, etc.

Location Information

Records of GPS system

Physical Location Security Information

Personal data related to the records and documents taken at the entrance to the physical place, during the stay in the physical place; camera recordings, records taken at the entrance/exit point of the facility, etc.

Process Security Information

Your processed personal data to ensure our technical, administrative, legal, and commercial security during the execution of our activities (for example, data such as device ID, IP information, authentication information, and internet access records)

Financial Information

Personal data such as bank account number, IBAN number, debt/receivable information, wage information, as well as personal data processed related to information, documents, and records showing all kinds of financial results created according to the type of legal relationship the company has established with the personal data owner

Occupational Experience Information

Personal data about received training of employees and those who applied for a job, professional competency information, title, information regarding work experience, etc

Visual Audial Data

Photograph and camera records

Health Information – Sensitive Personal Data

In order to perform our legal responsibilities within the scope of conducting the recruitment, personnel, and work health and work security processes health information such as processed disability information, examination results, blood type information, accident status, incapacity, etc. based on the explicit consent condition

Data About Conviction and Security Measures – Sensitive Personal Data

Within the scope of conducting recruitment process, sensitive personal data such as criminal record certificate, criminal record, etc. for the purpose of creating personal file

Family Members and Close Relatives Information

Within the frame of actions conducted by the Company or for the purpose of protecting the legal interest of the Company and employees; received and processed information about these people’s family members and close relatives (partner/children information, a close relative’s phone number, contact person in case of emergency, etc.)

Employee Candidate Information

Processed personal data about individuals, who applied for a job or internship to the Company, considered as employee candidate in line with our human resources needs by customs of trade and good faith

Request/Complaint Information

Information or petitions, etc. regarding requests and complaints communicated about various subjects by those who receive products or service from the Company, employees, and applicant

Performance and Career Development Information

During the employment of employees, data such as assignation/promotion, performance assessment information in order for tracking their performance and career development

Process Information

Data such as cookie records, travel information, and shift information within the scope of work activities of our Company

Client Process Information

Data such as every kind of instruction received from its clients and order status of clients within the scope of our Company

ANNEX -3 Personal Data Holders

 

CATEGORIES OF PERSONAL DATA HOLDERS

EXPLANATION

Employee

Natural persons who have a work relationship with our Company within the coverage of a contract of employment

Employee Candidate

Natural persons who applied for a job through any method or disclosed their Curriculum Vitae and relevant information to review by our Company (including intern candidates)

Company Official

A board of directors member of our Company and other authorized natural persons

Shareholder

Natural person partners of the company

Employees, Officials of the Institutions with which We Cooperate

Natural persons who work for institutions with which our Company has any business relationship (including but not limited to business partners, suppliers, and sub-employer), including shareholders and officials of these institutions

Participant

Natural persons who attend events organized by the company

Person Receiving the Product or Service

Natural persons who procure products or services from our Company regardless of whether they have a contractual relationship with our Company or not

Visitor

Natural persons who enter the physical premises of our Company or visit our websites

Party to Legal Proceedings

Natural persons (ex-employee, etc.) who are parties to the legal proceedings carried out by the company

 

Data Owner Application Form

ÜNALLAR METAL

DATA OWNER IS WITHIN THE SCOPE OF APPLICATION PROCESS

CLARIFICATION TEXT ON THE PERSONAL DATA PROTECTION AUTHORITY

 

Pursuant to the Personal Data Protection Law No. 6698 (the “Law”), your personal data may be processed by Ünallar Metal Construction Industry and Trade Joint Stock Company (“Ünallar Metal” or the “Company”) as the data controller within the scope described below.

Detailed information about the purposes of processing your personal data by the Company; https://unallarmetal.com/kisisel-verilerin-korunmasi/kvkk-politikasi/ located at the address Ünallar Metal Construction Industry and Trade Joint Stock Company, you can access the Personal Data Protection and Processing Policy. 

Purpose of Personal Data Processing

Identity, Communication, Request and Complaint, Dispute Subject Information obtained within the scope of the Data Subject Application Process; Evaluation and conclusion of your applications submitted to our Institution within the scope of exercising your rights specified in Article 11 of the Law, storage during the general statute of limitations for the purpose of providing evidence in possible legal disputes, tracking and conducting legal affairs, fulfilling official institution requests and providing information to authorized organizations based on legislation are processed.

To whom and with what Purpose the Processed Personal Data can be Transferred

Your processed personal data within the scope of the purposes listed above; provided that it does not harm your fundamental rights and freedoms, if it is mandatory to ensure the legitimate interests of our company, to the people we provide legal advice to, to our suppliers to whom we transfer data depending on the conditions for the establishment, use, and protection of a right as clearly stipulated in the Laws, the establishment of a right, based on the condition that data processing is mandatory for use and protection and fulfillment of the Company’s legal obligation, it may be transferred to legally authorized public institutions and legally authorized private persons, including the Personal Data Protection Authority, in accordance with the personal data processing conditions specified in the Article 8 of the Law.

Method and Legal Reason of Personal Data Collection

Your personal data is collected by means of the application form, petition, or e-mail on the Ünallar Metal website, which you transmit electronically and physically depending on the application method you have made to our Company.

Your personal data is collected and processed in accordance with the personal data processing conditions specified in Article 5 of the Law, based on the legal reasons that data processing is mandatory to ensure the legitimate interests of our Company, provided that it does not harm your fundamental rights and freedoms, it is clearly stipulated in the Laws, and the fulfillment of the legal obligation of our Company and the necessity of data processing for the establishment, use, and protection of a right.

Enumerated Rights of the Personal Data Holder In the Article 11 of the Law

We hereby declare that you as the personal data holder, have the following rights in accordance with Article 11 of the Law:

  • Learn if the personal data is processed or not;
  • Demand information if the personal data is processed with regards to this;
  • Learn the purpose of personal data processing and whether they are used relevant to their purpose;
  • Know the third parties to whom the personal data information is transferred both abroad and at home;
  • In the event that personal data is processed incompletely or incorrectly, demanding a correction and requesting that the procedure carried out within this scope is communicated to the third persons to whom the personal data is transferred;
  • Requesting the deletion or destruction of personal data in the event that the reasons requiring its processing cease to exist despite the fact that it has been processed in accordancewith the provisions of Law No. 6698 and other relevant laws, and requesting the notification of the transaction made within this scope to the third parties to whom the personal data has been transferred,
  • Objecting to the occurrence of a result against the person himself by analyzing the processed data exclusively through automated systems,
  • To request the compensation of the damage in case of damage due to unlawful processing of personal data.

You can submit your applications regarding your rights listed above to our Company by filling out the Data Owner Application Form, which you can access at https://unallarmetal.com/wp- content/uploads/2023/01/KVK-BasvuruFormu.pdf. Depending on the nature of your request, your applications will be concluded free of charge as soon as possible and within thirty days at the latest; however, if the transaction requires an additional cost, you may be charged a fee according to the tariff determined by the Personal Data Protection Board.