Personal Data Retention and Disposal Policy

DESi Alarm and Security Systems Industry and Trade Inc.

Personal Data Retention

and

Disposal Policy

1. Purpose

The Personal Data Retention and Disposal Policy ("Policy") is established by DESi Alarm and Security Systems Industry and Trade Inc. ("Company") to define the procedures and principles related to the storage and disposal activities of personal data processing.

Our company prioritizes the processing of personal data of employees, job applicants, former employees, customers, potential customers, service providers, suppliers, dealers, dealer candidates, business partner authorities and employees, visitors (including physical premises and websites), and other relevant third parties in compliance with the Constitution of the Republic of Turkey, international agreements, the Law on the Protection of Personal Data No. 6698 ("KVKK"), and other related legislation. Additionally, it ensures the effective exercise of the rights of the individuals concerned.

The processing and disposal of personal data are carried out in accordance with the Policy prepared by the Company. Thus, the Company ensures necessary transparency by informing personal data subjects and demonstrating all their rights and the procedures and methods for exercising them. Fully aware of our responsibility in this scope, your personal data is processed and protected within the framework of this Policy.

1.1. Scope

All personal data of company employees, job applicants, former employees, customers, potential customers, service providers, suppliers, branches, dealers, business partner authorities and employees, visitors, and other third parties related to our Company that are processed automatically or non-automatically as part of any data recording system fall within the scope of this Policy. This Policy applies to all record environments where personal data and special category personal data owned or managed by the Company are processed, and to activities aimed at processing personal data.

Due to the risk of causing harm or discrimination to individuals through the unlawful processing of certain personal data under KVKK, special importance is attributed to these data. These data are special category personal data as explained in the table below under Abbreviations and Definitions.

The Company treats the protection of special category personal data determined as "sensitive" under KVKK with utmost care and processes them lawfully. In this context, technical and administrative measures taken by our Company to protect personal data are diligently applied concerning special category personal data, and necessary audits are conducted within the Company.

Detailed information regarding the processing of special category personal data is provided in sections 4.3; 4.5.2 and 7.1 of this Policy.

Relevant legal regulations in force concerning the processing and protection of personal data will primarily apply. In case of inconsistency between the current legislation and the Policy, our Company acknowledges that the prevailing legislation will take precedence. The Policy concretizes the rules established by the relevant legislation within the scope of the Company's practices.

1.2. Abbreviations and Definitions

Term Definition
Recipient Group The category of natural or legal persons to whom personal data is transferred by the data controller.
Explicit Consent Consent that is informed and freely given in relation to a specific subject.
Anonymization The process of rendering personal data unidentifiable by ensuring that it cannot be associated with any specific individual, even when combined with other data.
Employee Personnel of DESi Alarm and Security Systems Industry and Trade Inc.
Electronic Environment Environments where personal data can be created, read, modified, and written using electronic devices.
Non-Electronic Environment All written, printed, visual, and other environments outside of electronic settings.
Service Provider A natural or legal person providing services to DESi Alarm and Security Systems Industry and Trade Inc. within the framework of a specific contract.
Data Subject The natural person whose personal data is being processed.
Relevant Employee Individuals within the data controller's organization or those who process personal data based on authority and instructions received from the data controller.
Disposal The deletion, destruction, or anonymization of personal data.
Law Law on the Protection of Personal Data No. 6698.
Record Environment Any environment where personal data is processed automatically or non-automatically as part of a data recording system.
Personal Data Any information relating to an identified or identifiable natural person.
Personal Data Processing Inventory An inventory created by data controllers detailing their personal data processing activities, including purposes, legal basis, data categories, recipient groups, retention periods, data transfers to foreign countries, and security measures.
Board Personal Data Protection Board.
KVKK Law on the Protection of Personal Data No. 6698.
Special Category Personal Data Data related to race, ethnic origin, political opinions, philosophical beliefs, religious or other beliefs, physical appearance, membership in associations, foundations, or trade unions, health, sexual life, criminal convictions, biometric and genetic data.
Periodic Disposal The routine deletion, destruction, or anonymization of personal data once the legal processing conditions no longer apply.
Policy Personal Data Protection, Retention, and Disposal Policy.
Company DESi Alarm and Security Systems Industry and Trade Inc.
Data Processor A natural or legal person processing personal data on behalf of the data controller based on the authority given by the data controller.
Data Recording System A system where personal data is structured and processed according to specific criteria.
Data Controller The natural or legal person determining the purposes and means of processing personal data.
Data Controller Register Information System An information system managed by the Personal Data Protection Board, accessible online, used by data controllers for registration and related procedures.
VERBİS Data Controller Register Information System.
Regulation The Regulation on the Destruction, Annihilation, or Anonymization of Personal Data published in the Official Gazette on October 28, 2017.

2. Responsibilities and Duties

All departments and employees of the Company actively support responsible units in implementing the technical and administrative measures required under this Policy, ensuring the proper handling of personal data. This includes training employees, increasing awareness, monitoring, continuous auditing, preventing unlawful processing of personal data, preventing unauthorized access, and ensuring lawful storage of personal data across all environments where personal data is processed.

Furthermore, individuals acting as data controllers, data controller representatives, employees, and those processing data on behalf of the Company are prohibited from disclosing personal data to others or using it for purposes outside the processing objectives defined in this Policy and KVKK. This obligation continues even after termination of their duties.

The titles, departments, and job descriptions of those involved in the data retention and disposal processes are detailed in Table 1 below.

Table 1: Distribution of Responsibilities in Retention and Disposal Processes

Title Department Duty
Company Personal Data Officer DESi Alarm and Security Systems Industry and Trade Inc. Responsible for ensuring employees act in accordance with the Policy.
General Manager General Management Responsible for the preparation, development, implementation, publication in relevant environments, and updating of the Policy.
Company Data Controller Contact Person Administrative and Financial Management Responsible for providing the necessary administrative, physical, and technical solutions required for the implementation of the Policy.

3. Data Retention Periods

Personal data will be retained for the duration necessary to fulfill the purposes for which it was collected, in accordance with legal obligations and the Policy. Specific retention periods are outlined in the Personal Data Processing Inventory.

4. Data Disposal Methods

Upon the expiration of the retention period or when the data is no longer needed for the specified purposes, personal data will be disposed of through deletion, destruction, or anonymization. The methods employed ensure that data cannot be reconstructed or retrieved.

5. Technical and Administrative Measures

The Company implements appropriate technical and administrative measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption, access controls, regular security assessments, and employee training.

6. Compliance and Monitoring

Regular audits and monitoring activities are conducted to ensure compliance with this Policy and relevant data protection laws. Non-compliance will be addressed promptly through corrective actions.

7. Rights of Data Subjects

Data subjects have the right to access, rectify, erase, restrict processing, and object to the processing of their personal data. They can exercise these rights by contacting the Company through the provided channels.

8. Contact Information

For any questions or concerns regarding this Policy or the handling of personal data, please contact us at:

DESi Alarm and Security Systems Industry and Trade Inc.
Website: en.desi.com.tr
Email: privacy@desi.com.tr

9. Policy Review and Updates

This Policy will be reviewed annually and updated as necessary to reflect changes in legislation, business practices, or operational requirements. All updates will be communicated to relevant stakeholders.

10. Enforcement

Violation of this Policy may result in disciplinary action, up to and including termination of employment or legal action. The Company is committed to enforcing this Policy to protect personal data and uphold data protection standards.

Effective Date:(20.01.2024)

 

Prepared by  T-Soft E-Commerce.