PERSONAL DATA RETENTION AND DESTRUCTION POLICY

PERSONAL DATA RETENTION AND DESTRUCTION POLICY

1 İstanbul Ephesus Hotel Ephesus Otelcilik ve Turizm Anonim Şirketi PERSONAL DATA RETENTION AND DESTRUCTION POLICY 1. PURPOSE OF THE POLICY This Personal Data Retention and Destruction Policy ("Policy") has been prepared by Ephesus Otelcilik ve Turizm A.Ş. ("İstanbul Ephesus Hotel", "Ephesus Hotel" or briefly the "Company") in its capacity as data controller, in order to fulfill its obligations under the Turkish Law No. 6698 on the Protection of Personal Data ("KVKK" – Turkish Data Protection Law, the "Law") and the Regulation on the Deletion, Destruction or Anonymization of Personal Data published in the Official Gazette on 28 October 2017 ("Regulation"), and other relevant legislation. The Policy informs data subjects about the principles for determining the maximum retention period required for the purposes for which personal data are processed, and about the deletion, destruction and anonymization procedures. The transactions and procedures regarding the retention and destruction of personal data are carried out by the Company in accordance with the Policy prepared for this purpose. 2. DEFINITIONS AND EXPLANATIONS You can find the basic conceptual definitions and explanations regarding the protection of personal data in the Ephesus Hotel Personal Data Protection Policy prepared and shared with the public by Ephesus Otelcilik ve Turizm A.Ş. 3. RESPONSIBILITY All units and employees of İstanbul Ephesus Hotel actively support the responsible units in the proper implementation of the technical and administrative measures taken under this Policy, in training and raising the awareness of unit employees, in monitoring and continuous auditing, in preventing the unlawful processing of personal data, in preventing unlawful access to personal data, and in ensuring the lawful retention of personal data. For this purpose, technical and administrative measures are taken to ensure data security in all environments where personal data are processed. 4. RECORDING ENVIRONMENTS Personal data stored within the Company are carefully maintained in the following recording environments in a manner appropriate to the nature of the relevant data and to legal obligations. 2 Electronic environments: Non-electronic environments: • Personal computers (desktop, laptop), Company computers (desktop, laptop) • Network devices • Mobile devices and storage areas within them (phone, tablet, etc.) • Shared/non-shared disk drives used for data storage on the network • Servers (e-mail, database, web, file sharing, domain, backup) • Software (office software, portal, etc.) • Printer, photo camera, camera, scanner, photocopier • Optical discs (CD, DVD, etc.) • Removable disks (USB, memory card, etc.) • Archive • Unit cabinets • Unit archive • Accounting unit • Written, printed, visual material and environments • Manual data recording systems (customer survey forms, visitor book, candidate evaluation forms) 5. PRINCIPLES İstanbul Ephesus Hotel acts in accordance with the following principles when retaining and destroying personal data: A. In the deletion, destruction and anonymization of personal data, full compliance is ensured with the principles listed in Article 4 of the Law, the technical and administrative measures to be taken under Article 12 and specified in this Policy, the provisions of the relevant legislation, the decisions of the Board, and this Policy. B. All transactions related to the deletion, destruction and anonymization of personal data are recorded by İstanbul Ephesus Hotel, and such records are kept for at least 2 years, excluding other legal obligations. C. Unless the Board decides otherwise, the appropriate one among the methods of ex-officio deletion, destruction or anonymization of personal data is selected by us. However, upon the request of the relevant person, the appropriate method will be selected by explaining the reason. D. In the event that all of the conditions for processing personal data set out in Articles 5 and 6 of the Law cease to exist, personal data are deleted, destroyed or anonymized by İstanbul Ephesus Hotel ex officio or upon the request of the relevant person. In the event that the Relevant Person applies to İstanbul Ephesus Hotel in this regard: - i) Requests submitted are concluded within a maximum of 30 (thirty) days and the relevant person is informed, - ii) In the event that the data subject to the request have been transferred to third parties, this situation is notified to the third party to whom the data were transferred, and it is ensured that the necessary actions are carried out before the third parties. 6. EXPLANATIONS REGARDING THE REASONS REQUIRING THE RETENTION AND DESTRUCTION OF PERSONAL DATA Personal data within the Company are stored securely and sensitively in the electronic or non-electronic environments specified in this Policy within the data processing conditions listed below, for the purposes of providing the Company's services, uninterrupted maintenance of commercial activities, planning and execution of human resources processes, conducting customer relations, planning the rights and benefits of employees, planning and executing supplier and business partner processes, ensuring effective communication, fulfilling legal obligations as required or compelled by legal regulations, fulfilling sector-specific obligations, carrying out necessary quality and standard audit processes, providing information to public institutions and organizations, ensuring corporate communication, ensuring security, 3 conducting statistical work, conducting analysis work, conducting reporting work, fulfilling obligations imposed by signed contracts and protocols, fulfilling the conditions required by legislation, using them as evidence in possible future legal disputes or fulfilling the obligation of proof, conducting written, printed and electronic journal and bulletin work, planning training processes, conducting archive processes and supply chain management. Personal data within the Company are destroyed ex officio or upon the request of the relevant person in the event that the data processing conditions below cease to exist. These conditions are: - Existence of explicit consent, - Existence of legal regulation (express provision in the legislation), - Inability to obtain explicit consent due to actual impossibility, - Necessity of processing personal data of the parties to a contract, provided that it is directly related to the establishment or performance of the contract, - Necessity for the data controller to fulfill its legal obligation, - The personal data of the relevant person having been made public by themselves, - Necessity of data processing for the establishment, exercise or protection of a right, - Necessity of data processing for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject. In the cases listed below, the personal data of data subjects are deleted, destroyed or anonymized by İSTANBUL EPHESUS HOTEL ex officio or upon request: - a. The purpose requiring the processing or retention of personal data has ceased, - b. The provisions of the relevant legislation underlying the processing or retention of personal data have been changed or abolished, - c. The application of the relevant person within the framework of the rights under sub-paragraphs (e) and (f) of Article 11 of the Law for the deletion, destruction or anonymization of personal data has been accepted by the data controller, - d. The conditions requiring the processing of personal data in Articles 5 and 6 of the Law have ceased to exist, - e. In cases where the processing of personal data is carried out solely on the condition of explicit consent, the relevant person withdraws their consent, - f. Although the maximum period required for the retention of personal data has elapsed, there is no condition justifying the retention of personal data for a longer period, - g. In cases where the data controller rejects the application made to them by the relevant person for the deletion, destruction or anonymization of personal data, finds the response given inadequate or does not respond within the period stipulated in the Law; a complaint is filed with the Board and this request is deemed appropriate by the Board. 7. LEGAL GROUNDS FOR RETENTION - Law No. 6698 on the Protection of Personal Data (KVKK – Turkish Data Protection Law), - Law No. 6098 – Turkish Code of Obligations (TBK), - Law No. 6102 – Turkish Commercial Code (TTK), - Law No. 213 – Tax Procedure Law (VUK), - Law No. 5510 – Social Insurance and General Health Insurance Law, - Law No. 6361 – Occupational Health and Safety Law (İSG), 4 - Law No. 4982 – Right to Information Law, - Law No. 3071 – Law on the Use of the Right of Petition, - Law No. 4857 – Turkish Labor Law (İK), - Law No. 6502 – Law on the Protection of the Consumer, The personal data collected within our Company are retained for the retention purposes and retention periods stipulated under the above-mentioned laws and, without being limited to these, within the framework of other secondary regulations currently in force. 8. TECHNICAL AND ADMINISTRATIVE MEASURES TAKEN FOR THE SECURE RETENTION OF PERSONAL DATA AND TO PREVENT UNLAWFUL PROCESSING AND ACCESS All administrative and technical measures taken by İSTANBUL EPHESUS HOTEL within the framework of the principles in Article 12 of KVKK No. 6698 to ensure the secure retention of your personal data, prevent unlawful processing and access, and lawfully destroy the data are listed below: ✓ Network and application security are ensured. ✓ Security measures are taken within the scope of the procurement, development and maintenance of information technology systems. ✓ Disciplinary regulations containing data security provisions for employees are in place. ✓ Training and awareness activities on data security are conducted for employees at regular intervals. ✓ Corporate policies on access, information security, use, retention and destruction have been prepared and put into practice. ✓ Data masking measures are applied when necessary. ✓ Confidentiality undertakings are made. ✓ The authorizations of employees who have changed positions or left the job in this area are removed. ✓ In addition to the use of strong passwords and codes, passwords and codes are changed at regular intervals. ✓ Up-to-date anti-virus systems are used. ✓ Firewalls are used. ✓ The contracts signed contain data security provisions. ✓ Additional security measures are taken for personal data transferred via paper, and the relevant documents are sent in the format of confidential documents. ✓ A personal data inventory has been prepared. ✓ Personal data security policies and procedures have been determined. ✓ Personal data security issues are reported quickly. ✓ Personal data security is monitored. ✓ Necessary security measures are taken for entries and exits to physical environments containing personal data. ✓ The security of physical environments containing personal data against external risks (fire, flood, etc.) is ensured. ✓ The security of environments containing personal data is ensured. ✓ Personal data are reduced as much as possible. ✓ Personal data are backed up and the security of the backed-up personal data is also ensured. 5 ✓ A user account management and authorization control system is implemented and monitored. ✓ Existing risks and threats have been identified. ✓ Protocols and procedures for the security of special categories of personal data have been determined and implemented. 9. TECHNICAL AND ADMINISTRATIVE MEASURES TAKEN FOR THE LAWFUL DESTRUCTION OF PERSONAL DATA Personal data obtained by İSTANBUL EPHESUS HOTEL in accordance with KVKK and other relevant legislation will be destroyed by İSTANBUL EPHESUS HOTEL ex officio or upon the application of the relevant person, in accordance with the provisions of the Law and relevant legislation, using the techniques specified below, in the event that the personal data processing purposes specified in the Law and the Regulation cease to exist. The applications within the Company for destroying personal data (deletion, destruction and anonymization) are as follows: Deletion of Personal Data • Personal data on paper are deleted using the blackening method (by scratching/painting/erasing). The blackening operation is carried out by, where possible, cutting the personal data on the relevant document, and where not possible, by making them invisible to the relevant users using permanent ink in a way that cannot be reversed and cannot be read by technological solutions. • Secure Deletion by an Expert: In some cases, an expert may be contracted to delete personal data on its behalf. In this case, the personal data are securely deleted by the person who is an expert in this area in a way that they cannot be accessed or used again in any way for the relevant users. • Secure Deletion by Software: When deleting data processed by fully or partially automated means and stored in digital environments, methods related to deleting the data from the relevant software in a way that they cannot be accessed or used again in any way for the relevant users are used. • Office files on the central server are deleted by the deletion command of the file system or by removing the access rights of the relevant user on the file or on the directory containing the file. • Personal data on portable media (for example, data on flash-based storage media) are stored encrypted and deleted using software suitable for these environments. • Deletion in the cloud system can be carried out by giving a deletion command for the relevant data; removing the access rights of the relevant user on the file or the directory containing the file on the central server; deleting the relevant rows in databases by database commands; or deleting the data on portable media, namely flash environments, by using appropriate software. However, if the deletion of personal data will result in inability to access and use other data within the system, personal data will also be considered deleted in the event that the personal data are archived in a way that cannot be associated with the relevant person, provided that the following conditions are met. • Personal data in databases are deleted by database commands (DELETE, etc.) for the relevant rows/columns or for the cells in the table. Destruction of Personal Data • The destruction of personal data on local systems is carried out by methods such as de-magnetizing (subjecting the media to a high magnetic field by passing it through a special device), physical destruction (melting, burning, using shredders on media and magnetic media), and overwriting. • The destruction of personal data on peripheral systems such as network devices (switch, router, etc.), Flash-based environments/fixed disks (ATA, SATA, PATA, SCSI, SCSI Express, etc.), magnetic tapes, magnetic disks, mobile phones (SIM card and fixed memory areas), peripheral units such as 6 printers and fingerprint door access systems whose data recording environment is removable or fixed, and optical disks must be destroyed using the command if the digital environment supports it as a product feature, or by using the destruction method recommended by the manufacturer if it does not support it as a product feature, or by using one or more of the methods specified as de-magnetizing, physical destruction, overwriting, and finally, for non-digital environments, by using one or more of the de-magnetizing, physical destruction, overwriting methods. • Physical Destruction: Personal data may also be processed by non-automatic means, provided that they are part of any data recording system. When such data are destroyed, the system of physically destroying personal data in such a way that they cannot be used later is applied. The destruction of data on paper and microfiche must also be carried out in this way because there is no other way to destroy them. • Overwriting: The overwriting method is a data destruction method that makes it impossible to read and recover the data. • Personal data in the cloud environment are stored encrypted and the destruction command is applied when the destruction time comes. During the occurrence of the above-mentioned situations, İSTANBUL EPHESUS HOTEL fully complies with the provisions of KVKK, the Regulation and other relevant legislation to ensure data security and takes all necessary administrative and technical measures. Anonymization of Personal Data • With the masking method, the basic identifying information that enables the identification of the data subject (e.g., name, surname, Turkish ID number (TCKN)) is removed and anonymization is carried out. • In the record extraction method, the data are anonymized by removing data row records containing uniqueness from among the records of stored data. • In the regional concealment method, if there is a distinguishing nature due to a combination in which a single piece of data appears very rarely, concealing the relevant data provides anonymization. • With the method of removing descriptive data, the existing data set is anonymized by removing the "high-degree descriptive" variables from the data set created after the collected data are brought together. • With the aggregation method, personal data are anonymized by being removed in a way that cannot be associated with any person (e.g., higher number of job applications from people between 25 and 30 years of age). • With the data aggregation method, many data are aggregated, and pursuant to Article 28 of KVKK, in the event that personal data are processed for purposes such as research, planning and statistics by being anonymized through official statistics, this situation will fall outside the scope of the Law and explicit consent will not be required. • With the data derivation method, anonymization is carried out by creating a more general content from the content of the personal data and in a way that the personal data cannot be associated with any person in any way (e.g., writing age instead of date of birth). 10. TABLE FOR THE RETENTION AND DESTRUCTION PROCESS AND PERIODS Personal data within the Company are retained for the period specified in the relevant legislation, if so prescribed by the relevant legislation. If the purpose of processing personal data has ended and the retention period determined by the relevant legislation and the Company has come to an end, personal data are retained for the purpose of resolving possible legal disputes, responding to lawful requests of authorized public institutions and 7 organizations, or asserting rights related to personal data. The criteria specified below are used in determining the retention and destruction periods of personal data obtained by İstanbul Ephesus Hotel in accordance with KVKK and other relevant legislation: 1. If a period has been stipulated in the legislation regarding the retention of the relevant personal data, this period is complied with. After the expiration of the said period, the data are processed within the scope of paragraph 2. 2. In the event that the period stipulated in the legislation regarding the retention of the relevant personal data expires or no period is stipulated in the relevant legislation regarding the retention of the said data, respectively: - a. Personal data are classified as personal data and special categories of personal data, based on the definition in Article 6 of KVKK. All personal data determined to be of a special nature are destroyed. The method to be applied in the destruction of the said data is determined according to the nature of the data and the level of importance of its retention before İstanbul Ephesus Hotel. - b. It is questioned whether the retention of the data complies with the principles specified in Article 4 of KVKK, for example, whether İstanbul Ephesus Hotel has a legitimate purpose in retaining the data. Data determined to potentially constitute a violation of the principles in Article 4 of KVKK are deleted, destroyed or anonymized. - c. It is determined under which of the exceptions stipulated in Articles 5 and 6 of KVKK the retention of personal data can be evaluated. Within the framework of the determined exceptions, reasonable periods for which the data must be retained are determined. In the event that the said periods expire, the data are deleted, destroyed or anonymized. You can find the retention, destruction and periodic destruction periods determined by İstanbul Ephesus Hotel in the "Retention and Destruction Periods Document" in the continuing part of this Policy. Personal data whose retention period has expired are destroyed at 6-month intervals in accordance with the procedures specified in this Policy, within the framework of the Retention and Destruction Periods document in the continuing section. All transactions related to the deletion, destruction and anonymization of personal data are recorded, and the said records are kept for at least three years, excluding other legal obligations. ANNEX – RETENTION PERIODS OF PERSONAL DATA: Data Category Retention Period 1 – Identity Personal Data 10 Years 2 – Contact Personal Data 10 Years 3 – Personnel Personal Data 10 Years 4 – Legal Transaction Personal Data 10 Years 5 – Customer Transaction Personal Data 10 Years 6 – Physical Space Security Camera Records 30 days 7 – Transaction Security Personal Data 2 Years 8 – Finance Personal Data 10 Years 9 – Professional Experience Personal Data 10 Years 10 – Marketing Personal Data 10 Years 8 Data Category Retention Period 11 – Visual and Audio Records Personal Data 10 Years 12 – Health Information Special Category Personal Data 15 Years 13 – Criminal Conviction and Security Measures Special Category Personal Data 10 Years 14 – Employee transaction information Personal Data 10 Years 15 – Family members and relatives information Personal Data 10 Years 16 – Gender Personal Data 10 Years 17 – Insurance information Personal Data 10 Years Processes, Legal Grounds and Retention Periods Process (Activity) Legal Basis of the Activity Time of Deletion Legal Basis of Retention Time of Destruction Receipt of customer reservation information. 6098 TBK If a contract is not established as a result of the reservation, the relevant personal data are deleted at the end of a 1-year period; if a contract is established, at the end of a 10-year period. KVKK Destroyed in the first periodic destruction operation following the deletion date. Receipt of customer registration information. 6098 TBK The relevant personal data are deleted at the end of a 10-year period from the date of the contract. KVKK Destroyed in the first periodic destruction operation following the deletion date. Keeping participant information for meetings, seminars, weddings and all other organizations 6098 TBK Deleted at the end of a 10-year period from the creation of the event registration documents. KVKK Destroyed in the first periodic destruction operation following the deletion date. Keeping records of other works and transactions made by the Company outside of hotel, accommodation and organization services General legal rules and relevant legislation The relevant documents are deleted at the end of a 10-year period from the moment the work and transaction has legal consequences. KVKK Destroyed in the first periodic destruction operation following the deletion date. Personnel candidate evaluation / Interview General provisions If the candidate is hired, transferred to the personnel file. If the candidate is not hired, deleted at the end of a 1-year period from the application date. KVKK Destroyed in the first periodic destruction operation following the deletion date. 9 Process (Activity) Legal Basis of the Activity Time of Deletion Legal Basis of Retention Time of Destruction Personnel file (private health insurance information, mandate forms, payrolls, accruals, fringe benefits and benefits, contact information, disciplinary records, training-certificate-skill information, leave, time sheets, declarations, CV information, transcripts, account information, driving license, residence permit transactions, incentives, exams, photograph, work certificate, social benefits and social leave, deductions, payments, records, travels, insurance information, license plate, vehicle, etc.) 4857 İK (Turkish Labor Law), 6098 TBK Deleted at the end of a 10-year period from the termination of the contract. İK, TBK, KVKK Destroyed in the first periodic destruction operation following the deletion date. Criminal record — Up-to-dateness is queried in parallel with the periods in the Criminal Record Law No. 5352 and the existence of explicit consent is investigated. — — Keeping personnel identity information and entry and exit information 4857 İK, 6098 TBK, 6331 İSG (Turkish OHS Law) Deleted at the end of a 10-year period from the termination of the contract. İK, TBK, İSG, KVKK Destroyed in the first periodic destruction operation following the deletion date. Personnel payment/deduction transactions (such as Business advance, Premium, Bonus, Benefits in Kind, Bank Promotions, BES, Severance, Notice, Settlement, Participation, Per Diem and Travel Payments) 4857 İK, 6098 TBK Deleted at the end of a 10-year period from the termination of the contract. İK, KVKK Destroyed in the first periodic destruction operation following the deletion date. Entry and periodic-polyclinic health examinations, sick leave reports (very dangerous works group) 4857 İK, 6098 TBK, 6331 İSG Deleted at the end of a 10-year period from the termination of the contract. İSG, İK, TBK, KVKK Destroyed in the first periodic destruction operation following the deletion date. Entry and periodic-polyclinic health examinations, sick leave reports (other than very dangerous works group) 4857 İK, 6098 TBK, 6331 İSG Deleted at the end of a 10-year period from the termination of the contract. İSG, İK, TBK, KVKK Destroyed in the first periodic destruction operation following the deletion date. 10 Process (Activity) Legal Basis of the Activity Time of Deletion Legal Basis of Retention Time of Destruction Work accident report, emergency record form, work accident examination and incident records, result notification (very dangerous works group) 6331 İSG If there is a contract with the person involved in the accident: Deleted at the end of a 20-year period from the termination of the contract. If there is no contract with the person involved in the accident: Deleted at the end of a 10-year period from the accident date. İSG, KVKK Destroyed in the first periodic destruction operation following the deletion date. Work accident report, emergency record form, work accident examination and incident records, result notification (other than very dangerous works group) 6331 İSG If there is a contract with the person involved in the accident: Deleted at the end of a 20-year period from the termination of the contract. If there is no contract with the person involved in the accident: Deleted at the end of a 10-year period from the accident date. İSG, KVKK Destroyed in the first periodic destruction operation following the deletion date. Training records carried out within Occupational Health and Safety (very dangerous works group) 4857 İK, 6331 İSG Deleted at the end of a 10-year period from the termination of the contract. İK, İSG, KVKK Destroyed in the first periodic destruction operation following the deletion date. Training records carried out within Occupational Health and Safety (other than very dangerous works group) 4857 İK, 6331 İSG Deleted at the end of a 10-year period from the termination of the contract. İK, İSG, KVKK Destroyed in the first periodic destruction operation following the deletion date. Informed Consent Form 4857 İK, 6098 TBK, 6331 İSG If there is a contract with the person: Deleted at the end of a 10-year period from the termination of the contract. If there is no contract with the person: Deleted at the end of a 10-year period from the consent date. İK, İSG, TBK Destroyed in the first periodic destruction operation following the deletion date. Other work area control forms 6098 TBK Deleted within 10 years upon the form becoming outdated. TBK, İK Destroyed in the first periodic destruction operation following the deletion date. Vaccination, Dressing and Injection Register, Polyclinic Register 6331 İSG Moved to archive when transitioning to a new register. Deleted 15 years after being moved to archive. İSG, TBK, İK Destroyed in the first periodic destruction operation following the deletion date. Training records carried out outside of Occupational Health and Safety 4857 İK, 4721 MK (Turkish Civil Code), 6098 TBK Deleted at the end of a 10-year period from the termination of the contract. İK, MK, TBK Destroyed in the first periodic destruction operation following the deletion date. Holding OHS Committee meetings 6331 İSG Evaluated 10 years after the meeting date, those that have become outdated are deleted. İSG Destroyed in the first periodic destruction operation following the deletion date. Cases requiring investigation under Turkish Penal Code No. 5237 — Retained for the duration of the criminal statute of limitations, destroyed in the first periodic destruction operation after this period. — — 11 Process (Activity) Legal Basis of the Activity Time of Deletion Legal Basis of Retention Time of Destruction Keeping case/enforcement/ mediation files 1136 AVK (Turkish Attorneys Act), 7251 HMK (Civil Procedure Code), 2004 İİK (Enforcement & Bankruptcy Code) Deleted at the end of a 10-year period from the finalization of the file. AVK, HMK, İİK, KVKK Destroyed in the first periodic destruction operation following the deletion date. In matters requiring criminal investigation, destroyed in the first periodic destruction operation following the expiry of the criminal statute of limitations. Portal – Data in the automation (HOTELIA) used for hotel operations 6098 TBK, 6102 TTK Deleted at the end of a 10-year period. KVKK Destroyed in the first periodic destruction operation following the deletion date. Non-process-extended service – goods – product procurements 6098 TBK, 6102 TTK Deleted at the end of a 10-year period from the date of purchase. TBK, TTK Destroyed in the first periodic destruction operation following the deletion date. Process-extended service – goods – product procurements (Tender/Offer) 6098 TBK, 6102 TTK If the Tender/Offer result is positive: Deleted at the end of a 10-year period from the end of the contractual or legal relationship. If the Tender/Offer result is negative: Deleted at the end of a 5-year period from the tender date. TBK, TTK Destroyed in the first periodic destruction operation following the deletion date. Incoming – outgoing cargo recipient and sender — Deleted at the end of a 1-year period from the end of the process. KVKK Destroyed in the first periodic destruction operation following the deletion date. Incoming – outgoing call records — Deleted at the end of a 1-year period after the records are kept. KVKK Destroyed in the first periodic destruction operation following the deletion date. Directory – telephone and e-mail addresses (employee) 6098 TBK Deleted at the end of a 1-year period from the termination of the contract. TBK, KVKK Destroyed in the first periodic destruction operation following the deletion date. Camera recordings — Overwritten in 30-day periods. KVKK, İK, TBK Overwritten in 30-45 day periods. Destroyed automatically. Log records and Internet Traffic Information 6698 KVKK, Law No. 5651 Deleted at the end of a 5-year period from the date of the recording. KVKK Digital data are destroyed at the time of deletion; documents suitable for destruction are destroyed in the first periodic destruction operation following the deletion date. Phone voice recording — Deleted at the end of a 1-year period from the recording. KVKK Destroyed in the first periodic destruction operation following the deletion date. 12 Process (Activity) Legal Basis of the Activity Time of Deletion Legal Basis of Retention Time of Destruction Audit documents 4721 MK, 6102 TTK, 213 VUK and other laws The type, nature of the audit and the actions to be taken as a result of the audit are observed. In any case, the relevant documents are deleted at the end of a 10-year period from the audit date. MK, TTK, VUK, KVKK and other laws Documents that are not deemed necessary to be kept are destroyed on the deletion date. The destruction period for documents deemed necessary to be kept is determined by considering the Company's needs and currency. Invoices (process-extended transactions) 213 VUK, 6102 TTK Deleted at the end of a 10-year period following the end of the process. VUK, TTK Destroyed in the first periodic destruction operation following the deletion date. Invoices (non-process-extended transactions) 213 VUK, 6102 TTK Deleted at the end of a 10-year period following the year in which the invoice was issued. VUK, TTK, KVKK Destroyed in the first periodic destruction operation following the deletion date. Processes and documents conducted with suppliers (e.g., supplier payments, payment receipts, waybills, policies, reconciliations, accruals, enforcement letters, declarations, addenda, service and consultancy procurements, declarations, forms, signature circulars, mail orders) 6098 TBK, 213 VUK, 6102 TTK Deleted at the end of a 10-year period following the year in which the invoice was issued. TBK, VUK, TTK, KVKK Destroyed at the end of 5 years from the termination of the contractual or legal transaction with the supplier. Letter of Guarantee / Check 6102 TTK Deleted at the end of a 10-year period from the end of the relationship. TTK, KVKK Destroyed in the first periodic destruction operation following the deletion date. GSM expenses / Vehicle expenses — Deleted at the end of 10 years following the year in which the transaction took place. TBK, KVKK Destroyed in the first periodic destruction operation following the deletion date. Request, complaint and satisfaction process (arising from contract) 6098 TBK Deleted at the end of a 10-year period after the request or complaint is resolved. KVKK Destroyed in the first periodic destruction operation following the deletion date. Request, complaint and satisfaction process (not arising from contract) — Deleted at the end of a 10-year period after the request or complaint is resolved. KVKK Destroyed in the first periodic destruction operation following the deletion date. Emergency planning 6331 İSG Deleted within a 10-year period upon becoming outdated. KVKK Destroyed in the first periodic destruction operation following the deletion date. 13 Process (Activity) Legal Basis of the Activity Time of Deletion Legal Basis of Retention Time of Destruction Photographing and creating videos of organized or attended corporate events 6698 KVKK There is no obligation to delete in cases where explicit consent is not sought. They are not deleted unless explicit consent is withdrawn. However, since they must be used in a purpose-bound and proportionate manner, they cannot be used for different purposes. KVKK For those carried out within the scope of explicit consent and that can be destroyed, destroyed in the first periodic destruction operation following the withdrawal of explicit consent. Device (computer, mobile device and GSM line) mandate form 6098 TBK, 4857 İK Deleted at the end of a 10-year period from the termination of the contract. TBK, İK, KVKK Destroyed in the first periodic destruction operation following the deletion date. Signature circulars 6102 TTK and other laws Determined according to currency and need. Documents that have become outdated are deleted at the end of a 10-year period from the loss of currency. TTK and other laws Determined according to currency and need. Those that are not current and not needed are destroyed. Destruction report 6698 KVKK Deleted at the end of a 5-year period from the destruction. KVKK Destroyed 5 years after the termination of the legal entity. Incoming – outgoing documents / Following correspondences and documents related to the Company operation — The periods specified in this table apply according to the nature of the document. — — E-mail contents — E-mails are reviewed at 6-month intervals. The periods in this table apply by examining documents and records containing personal data in the e-mail. — — Matters not specified in the table — Retention and destruction periods for personal data related to processes not specified in this table are determined by considering matters such as the period during which documents and records containing personal data must be kept, periods accepted as customary in the sector, the period during which the legal relationship with the relevant persons will continue, the period during which the legitimate interest of the data controller will be valid in accordance with the law and rules of integrity, the currency of the personal data, and by benefiting from the table. — — 14 Process (Activity) Legal Basis of the Activity Time of Deletion Legal Basis of Retention Time of Destruction Operation of the retention and destruction process on a unit basis — While the retention and destruction processes are being operated, personal data or documents containing personal data subject to retention and destruction are obtained from the relevant unit(s). The retention and destruction processes are operated in coordination with the relevant unit(s). — — Postponement of destruction — At the end of the retention, deletion, destruction, anonymization times specified in this table, an evaluation regarding retention and destruction is made. As a result of the evaluation, the retention and destruction process is operated or postponed for a reasonable period by evaluating the currency of the personal data (or the document containing personal data), the continuation status of the legal or contractual relationship and obligations, and the objective need for the personal data or the relevant document. This operation is taken under report. The report is kept for at least 3 years. — — WITHDRAWAL OF EXPLICIT CONSENT — Personal data that can be processed with the explicit consent of the relevant person are destroyed when the relevant person withdraws their explicit consent. — — 11. PERIODIC DESTRUCTION PERIODS The time intervals in which periodic destruction will take place will be determined by the Company officials. However, the interval between two periodic destruction operations will, in principle, be a maximum of 6 months. In the first periodic destruction operation following the date on which the obligation to destroy personal data arose, personal data will be deleted, destroyed or anonymized. Reports containing the transactions for deleted, destroyed and anonymized data are kept for at least 3 years, excluding other legal obligations. 15 First Publication: November 2025 Last Updated: 29 April 2026 Note: This is an English translation of the Turkish original policy. In case of interpretation questions or legal disputes, the Turkish original version shall prevail.