PERSONAL DATA RETENTION AND DESTRUCTION POLICY
1 İstanbul Ephesus Hotel Ephesus Otelcilik ve Turizm Anonim Şirketi PERSONAL DATA RETENTION AND DESTRUCTION POLICY 1. PURPOSE OF THE POLICY This Personal Data Retention and Destruction Policy ("Policy") has been prepared by Ephesus Otelcilik ve Turizm A.Ş. ("İstanbul Ephesus Hotel", "Ephesus Hotel" or briefly the "Company") in its capacity as data controller, in order to fulfill its obligations under the Turkish Law No. 6698 on the Protection of Personal Data ("KVKK" – Turkish Data Protection Law, the "Law") and the Regulation on the Deletion, Destruction or Anonymization of Personal Data published in the Official Gazette on 28 October 2017 ("Regulation"), and other relevant legislation. The Policy informs data subjects about the principles for determining the maximum retention period required for the purposes for which personal data are processed, and about the deletion, destruction and anonymization procedures. The transactions and procedures regarding the retention and destruction of personal data are carried out by the Company in accordance with the Policy prepared for this purpose. 2. DEFINITIONS AND EXPLANATIONS You can find the basic conceptual definitions and explanations regarding the protection of personal data in the Ephesus Hotel Personal Data Protection Policy prepared and shared with the public by Ephesus Otelcilik ve Turizm A.Ş. 3. RESPONSIBILITY All units and employees of İstanbul Ephesus Hotel actively support the responsible units in the proper implementation of the technical and administrative measures taken under this Policy, in training and raising the awareness of unit employees, in monitoring and continuous auditing, in preventing the unlawful processing of personal data, in preventing unlawful access to personal data, and in ensuring the lawful retention of personal data. For this purpose, technical and administrative measures are taken to ensure data security in all environments where personal data are processed. 4. RECORDING ENVIRONMENTS Personal data stored within the Company are carefully maintained in the following recording environments in a manner appropriate to the nature of the relevant data and to legal obligations. 2 Electronic environments: Non-electronic environments: • Personal computers (desktop, laptop), Company computers (desktop, laptop) • Network devices • Mobile devices and storage areas within them (phone, tablet, etc.) • Shared/non-shared disk drives used for data storage on the network • Servers (e-mail, database, web, file sharing, domain, backup) • Software (office software, portal, etc.) • Printer, photo camera, camera, scanner, photocopier • Optical discs (CD, DVD, etc.) • Removable disks (USB, memory card, etc.) • Archive • Unit cabinets • Unit archive • Accounting unit • Written, printed, visual material and environments • Manual data recording systems (customer survey forms, visitor book, candidate evaluation forms) 5. PRINCIPLES İstanbul Ephesus Hotel acts in accordance with the following principles when retaining and destroying personal data: A. In the deletion, destruction and anonymization of personal data, full compliance is ensured with the principles listed in Article 4 of the Law, the technical and administrative measures to be taken under Article 12 and specified in this Policy, the provisions of the relevant legislation, the decisions of the Board, and this Policy. B. All transactions related to the deletion, destruction and anonymization of personal data are recorded by İstanbul Ephesus Hotel, and such records are kept for at least 2 years, excluding other legal obligations. C. Unless the Board decides otherwise, the appropriate one among the methods of ex-officio deletion, destruction or anonymization of personal data is selected by us. However, upon the request of the relevant person, the appropriate method will be selected by explaining the reason. D. In the event that all of the conditions for processing personal data set out in Articles 5 and 6 of the Law cease to exist, personal data are deleted, destroyed or anonymized by İstanbul Ephesus Hotel ex officio or upon the request of the relevant person. In the event that the Relevant Person applies to İstanbul Ephesus Hotel in this regard: - i) Requests submitted are concluded within a maximum of 30 (thirty) days and the relevant person is informed, - ii) In the event that the data subject to the request have been transferred to third parties, this situation is notified to the third party to whom the data were transferred, and it is ensured that the necessary actions are carried out before the third parties. 6. EXPLANATIONS REGARDING THE REASONS REQUIRING THE RETENTION AND DESTRUCTION OF PERSONAL DATA Personal data within the Company are stored securely and sensitively in the electronic or non-electronic environments specified in this Policy within the data processing conditions listed below, for the purposes of providing the Company's services, uninterrupted maintenance of commercial activities, planning and execution of human resources processes, conducting customer relations, planning the rights and benefits of employees, planning and executing supplier and business partner processes, ensuring effective communication, fulfilling legal obligations as required or compelled by legal regulations, fulfilling sector-specific obligations, carrying out necessary quality and standard audit processes, providing information to public institutions and organizations, ensuring corporate communication, ensuring security, 3 conducting statistical work, conducting analysis work, conducting reporting work, fulfilling obligations imposed by signed contracts and protocols, fulfilling the conditions required by legislation, using them as evidence in possible future legal disputes or fulfilling the obligation of proof, conducting written, printed and electronic journal and bulletin work, planning training processes, conducting archive processes and supply chain management. Personal data within the Company are destroyed ex officio or upon the request of the relevant person in the event that the data processing conditions below cease to exist. These conditions are: - Existence of explicit consent, - Existence of legal regulation (express provision in the legislation), - Inability to obtain explicit consent due to actual impossibility, - Necessity of processing personal data of the parties to a contract, provided that it is directly related to the establishment or performance of the contract, - Necessity for the data controller to fulfill its legal obligation, - The personal data of the relevant person having been made public by themselves, - Necessity of data processing for the establishment, exercise or protection of a right, - Necessity of data processing for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject. In the cases listed below, the personal data of data subjects are deleted, destroyed or anonymized by İSTANBUL EPHESUS HOTEL ex officio or upon request: - a. The purpose requiring the processing or retention of personal data has ceased, - b. The provisions of the relevant legislation underlying the processing or retention of personal data have been changed or abolished, - c. The application of the relevant person within the framework of the rights under sub-paragraphs (e) and (f) of Article 11 of the Law for the deletion, destruction or anonymization of personal data has been accepted by the data controller, - d. The conditions requiring the processing of personal data in Articles 5 and 6 of the Law have ceased to exist, - e. In cases where the processing of personal data is carried out solely on the condition of explicit consent, the relevant person withdraws their consent, - f. Although the maximum period required for the retention of personal data has elapsed, there is no condition justifying the retention of personal data for a longer period, - g. In cases where the data controller rejects the application made to them by the relevant person for the deletion, destruction or anonymization of personal data, finds the response given inadequate or does not respond within the period stipulated in the Law; a complaint is filed with the Board and this request is deemed appropriate by the Board. 7. LEGAL GROUNDS FOR RETENTION - Law No. 6698 on the Protection of Personal Data (KVKK – Turkish Data Protection Law), - Law No. 6098 – Turkish Code of Obligations (TBK), - Law No. 6102 – Turkish Commercial Code (TTK), - Law No. 213 – Tax Procedure Law (VUK), - Law No. 5510 – Social Insurance and General Health Insurance Law, - Law No. 6361 – Occupational Health and Safety Law (İSG), 4 - Law No. 4982 – Right to Information Law, - Law No. 3071 – Law on the Use of the Right of Petition, - Law No. 4857 – Turkish Labor Law (İK), - Law No. 6502 – Law on the Protection of the Consumer, The personal data collected within our Company are retained for the retention purposes and retention periods stipulated under the above-mentioned laws and, without being limited to these, within the framework of other secondary regulations currently in force. 8. TECHNICAL AND ADMINISTRATIVE MEASURES TAKEN FOR THE SECURE RETENTION OF PERSONAL DATA AND TO PREVENT UNLAWFUL PROCESSING AND ACCESS All administrative and technical measures taken by İSTANBUL EPHESUS HOTEL within the framework of the principles in Article 12 of KVKK No. 6698 to ensure the secure retention of your personal data, prevent unlawful processing and access, and lawfully destroy the data are listed below: ✓ Network and application security are ensured. ✓ Security measures are taken within the scope of the procurement, development and maintenance of information technology systems. ✓ Disciplinary regulations containing data security provisions for employees are in place. ✓ Training and awareness activities on data security are conducted for employees at regular intervals. ✓ Corporate policies on access, information security, use, retention and destruction have been prepared and put into practice. ✓ Data masking measures are applied when necessary. ✓ Confidentiality undertakings are made. ✓ The authorizations of employees who have changed positions or left the job in this area are removed. ✓ In addition to the use of strong passwords and codes, passwords and codes are changed at regular intervals. ✓ Up-to-date anti-virus systems are used. ✓ Firewalls are used. ✓ The contracts signed contain data security provisions. ✓ Additional security measures are taken for personal data transferred via paper, and the relevant documents are sent in the format of confidential documents. ✓ A personal data inventory has been prepared. ✓ Personal data security policies and procedures have been determined. ✓ Personal data security issues are reported quickly. ✓ Personal data security is monitored. ✓ Necessary security measures are taken for entries and exits to physical environments containing personal data. ✓ The security of physical environments containing personal data against external risks (fire, flood, etc.) is ensured. ✓ The security of environments containing personal data is ensured. ✓ Personal data are reduced as much as possible. ✓ Personal data are backed up and the security of the backed-up personal data is also ensured. 5 ✓ A user account management and authorization control system is implemented and monitored. ✓ Existing risks and threats have been identified. ✓ Protocols and procedures for the security of special categories of personal data have been determined and implemented. 9. TECHNICAL AND ADMINISTRATIVE MEASURES TAKEN FOR THE LAWFUL DESTRUCTION OF PERSONAL DATA Personal data obtained by İSTANBUL EPHESUS HOTEL in accordance with KVKK and other relevant legislation will be destroyed by İSTANBUL EPHESUS HOTEL ex officio or upon the application of the relevant person, in accordance with the provisions of the Law and relevant legislation, using the techniques specified below, in the event that the personal data processing purposes specified in the Law and the Regulation cease to exist. The applications within the Company for destroying personal data (deletion, destruction and anonymization) are as follows: Deletion of Personal Data • Personal data on paper are deleted using the blackening method (by scratching/painting/erasing). The blackening operation is carried out by, where possible, cutting the personal data on the relevant document, and where not possible, by making them invisible to the relevant users using permanent ink in a way that cannot be reversed and cannot be read by technological solutions. • Secure Deletion by an Expert: In some cases, an expert may be contracted to delete personal data on its behalf. In this case, the personal data are securely deleted by the person who is an expert in this area in a way that they cannot be accessed or used again in any way for the relevant users. • Secure Deletion by Software: When deleting data processed by fully or partially automated means and stored in digital environments, methods related to deleting the data from the relevant software in a way that they cannot be accessed or used again in any way for the relevant users are used. • Office files on the central server are deleted by the deletion command of the file system or by removing the access rights of the relevant user on the file or on the directory containing the file. • Personal data on portable media (for example, data on flash-based storage media) are stored encrypted and deleted using software suitable for these environments. • Deletion in the cloud system can be carried out by giving a deletion command for the relevant data; removing the access rights of the relevant user on the file or the directory containing the file on the central server; deleting the relevant rows in databases by database commands; or deleting the data on portable media, namely flash environments, by using appropriate software. However, if the deletion of personal data will result in inability to access and use other data within the system, personal data will also be considered deleted in the event that the personal data are archived in a way that cannot be associated with the relevant person, provided that the following conditions are met. • Personal data in databases are deleted by database commands (DELETE, etc.) for the relevant rows/columns or for the cells in the table. Destruction of Personal Data • The destruction of personal data on local systems is carried out by methods such as de-magnetizing (subjecting the media to a high magnetic field by passing it through a special device), physical destruction (melting, burning, using shredders on media and magnetic media), and overwriting. • The destruction of personal data on peripheral systems such as network devices (switch, router, etc.), Flash-based environments/fixed disks (ATA, SATA, PATA, SCSI, SCSI Express, etc.), magnetic tapes, magnetic disks, mobile phones (SIM card and fixed memory areas), peripheral units such as 6 printers and fingerprint door access systems whose data recording environment is removable or fixed, and optical disks must be destroyed using the