OSKON Privacy Policy regarding the processing, protection, retention and transfer of personal data under Turkish Personal Data Protection Law No. 6698.

Version: 2.23
Last Updated: 13 June 2022

1. PURPOSE AND SCOPE

Oskon Otomasyon Pazarlama Elektrik End. İnş. San. ve Tic. Ltd. Şti. (“OSKON” or the “Company”) attaches great importance to protecting your personal data and private information. Acting as the Data Controller, the Company therefore exercises all due care required to process your personal data in accordance with Turkish Personal Data Protection Law No. 6698 (the “KVKK”), including its use, recording, storage, updating, transfer and/or classification for purposes connected with our business activities and within the framework described below.

Within this scope, the Company takes all appropriate technical and administrative measures necessary to ensure an adequate level of security, prevent the unlawful processing of or access to personal data, and safeguard such data in accordance with the laws and regulations enacted to protect fundamental rights and freedoms, particularly the right to privacy.

This notice is addressed to all natural persons whose personal data is processed through our websites and corporate processes, as well as to our employees. OSKON provides web-based and cloud-based services (the “Services”) over the internet. This Privacy Notice covers all such software, websites and applications.

Our Website: www.oskon.com.tr

Personal information processed through our website is handled in accordance with applicable data-protection legislation. In relation to our web-based services, we act as the “Data Controller” only for users who create an account and use our websites; this Privacy Policy applies only to the processing of those users’ data.

Customers who process and record data using our Services are independent data controllers. In such circumstances, the Company acts only as a “Data Processor”. Where necessary, we therefore recommend consulting the privacy policies, privacy notices and similar documents issued by the relevant Customer that processes your personal data.

We do not warrant the data-security and data-protection practices or policies of third-party websites linked from our Sites. We recommend reviewing the relevant data controller’s own data-security and data-protection policies separately.

3. IDENTITY OF THE DATA CONTROLLER

OSKON (also referred to as the “Organisation”) acts as the “Data Controller” in relation to all natural persons it encounters and whose personal data it processes while conducting its commercial activities, including employees, job applicants, customers, suppliers, supplier employees and visitors. OSKON is responsible for fulfilling its statutory obligations and does so through administrative measures supported by compliance and control mechanisms, together with appropriate and proportionate technical safeguards.

OSKON processes your personal data as the “Data Controller” defined in Article 3 of Turkish Personal Data Protection Law No. 6698. Its contact details are provided below.

OSKON acts as the “Data Controller” in relation to the personal data of website visitors and users of services it provides online. In that capacity, OSKON fulfils its obligations arising from legislation and decisions of the Personal Data Protection Board by implementing administrative measures and appropriate, proportionate technical safeguards.

Our corporate identity and contact details for personal-data matters are as follows:

Company Name:Oskon Otomasyon Pazarlama Elektrik End. İnş. San. ve Tic. Ltd. Şti.
Address:Aydınlı Mah. Yanyol Cad. Melodi Sk. S.S. Bilmo Sanayi Sitesi No:2/62 Tuzla/İstanbul, Türkiye
Website:www.oskon.com.tr
Telephone:+90 (216) 593 08 18
Email:kvkk@oskon.com.tr

4. KEY DEFINITIONS

Explicit consent: Freely given, informed consent relating to a specific matter. Anonymisation: Rendering personal data impossible to associate with an identified or identifiable natural person under any circumstances, even when matched with other data.

Data subject: The natural person whose personal data is processed.

Personal data: Any information relating to an identified or identifiable natural person.

Employee handling personal data: An employee who processes the personal data of data subjects on behalf of the Organisation as part of their job description.

Processing of personal data: Any operation performed on personal data, whether wholly or partly by automated means or by non-automated means forming part of a data filing system, including collection, recording, storage, retention, alteration, rearrangement, disclosure, transfer, acquisition, making available, classification or restriction of use.

Committee: The internal committee established within the Organisation in accordance with the “Directive on the Duties and Responsibilities of the Personal Data Protection Committee”. Its duties include monitoring all personal-data processes carried out by the Organisation, its departments and employees; checking compliance with policies; and administering personal-data processes on behalf of the Organisation.

Board: The Turkish Personal Data Protection Board.

Authority: The Turkish Personal Data Protection Authority.

KVKK: Turkish Personal Data Protection Law No. 6698.

Special categories of personal data: Data concerning a person’s race, ethnic origin, political opinion, philosophical belief, religion, religious denomination or other beliefs, appearance and clothing, association, foundation or trade-union membership, health, sex life, criminal convictions and security measures, as well as biometric and genetic data.

Data processor: A natural or legal person who processes personal data on behalf of and under the authority granted by the Data Controller.

Data filing system: A filing system in which personal data is structured and processed according to specified criteria.

Data controller: A natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.

Joint data controller: Another data controller with whom the Organisation shares personal data within the scope of its commercial and corporate activities and with whom it jointly carries out processing operations on that personal data during such sharing.

Independent data controller: Another independent data controller that processes personal data relating to the same individuals for its own commercial and corporate purposes.

5. PURPOSES OF PROCESSING PERSONAL DATA

The personal data of data subjects is processed by our Organisation solely and directly in connection with the Organisation’s activities and its commercial, employment or legal relationship with the relevant data subject for the following purposes:

  • Purposes Relating to Management Processes:
    • Conducting commercial activities,
    • Ensuring business continuity and maintaining legal, administrative and operational security,
    • Planning and executing business and implementation strategies,
    • Managing occupational health and safety processes,
    • Delivering presentations, promotions and information about the Organisation, its services and products,
    • Fulfilling obligations arising from legislation and contracts,
    • Ensuring the physical security of the Organisation’s premises and surrounding areas,
    • Obtaining legal support,
    • Using electronic and other social-media tools and printed, periodical and non-periodical publications,
    • Conducting dealership processes,
    • Establishing and maintaining communication with members of the press and media organisations,
    • Informing the public about the Organisation’s activities,
    • Conducting business meetings in a timely and effective manner,
    • Ensuring work is completed on time and in accordance with applicable requirements,
    • Planning and conducting activities at local, national and international levels,
    • Managing relationships with business partners and group companies in Türkiye and abroad,
    • Conducting procedures relating to intellectual and industrial property,
    • Promoting, marketing and providing information about the Organisation, its products and services,
    • Receiving notifications and feedback from customers and prospective customers,
    • Providing technical support to customers,
    • Responding to questions from customers and prospective customers,
    • Providing support relating to electronic invoicing services,
    • Participating in events such as trade fairs and seminars.
  • Purposes Relating to Employees:
    • Establishing and performing employment contracts,
    • Delivering and administering services provided to employees,
    • Providing employees with socioeconomic benefits,
    • Managing domestic and international assignments, travel and accommodation processes,
    • Planning and conducting human-resources processes,
    • Conducting recruitment, employment-relationship and performance-evaluation processes,
    • Creating personnel files and retaining them in physical and electronic environments,
    • Monitoring working hours and attendance,
    • Conducting exit procedures and interviews,
    • Conducting performance and audit activities.
  • Purposes Relating to Information-Technology Processes:
    • Establishing and updating information and communication infrastructure,
    • Managing users of information-technology tools and systems,
    • Managing corporate email accounts,
    • Managing corporate social-media accounts,
    • Managing, auditing and closing the email accounts of departing employees,
    • Managing, monitoring and auditing portable and/or desktop electronic devices,
    • Conducting procedures relating to website members,
    • Ensuring data security and archiving data,
    • Keeping internet-access logs,
    • Tracking vehicles owned by the Organisation and their authorised users,
    • Protecting and managing customers’ digital assets and rights.

6. CATEGORIES OF DATA SUBJECTS WHOSE PERSONAL DATA IS PROCESSED

OSKON generally and extensively processes the data of the following data subjects within the scope of this Privacy Policy and other administrative and technical safeguards. When processing the personal data of natural persons outside these categories, the Organisation will continue to comply with its data-processing policies, particularly this Privacy Policy. The categories of natural persons whose personal data is processed are:

  • Employees,
  • Employees working under indefinite-term employment contracts,
  • Interns and participants assigned under İŞKUR on-the-job training programmes,
  • Job applicants,
  • Customer representatives and employees,
  • Supplier representatives and employees,
  • Consultants and auditors,
  • Public officials,
  • Visitors to our premises,
  • Visitors to our websites,
  • Prospective customers and users,
  • Our dealers.

7. LEGAL GROUNDS AND CATEGORIES OF PERSONAL DATA PROCESSED

7.1. Personal Data of Employees, Employees Working Under Indefinite-Term Employment Contracts and Interns

The Organisation processes the personal data of employees, job applicants and interns in accordance with:

  • Employment contracts,
  • Turkish Labour Law No. 4857,
  • Turkish Code of Obligations No. 6098,
  • Social Insurance and Universal Health Insurance Law No. 5510,
  • Occupational Health and Safety Law No. 6331,
  • Individual Pension Savings and Investment System Law No. 4632,
  • Enforcement and Bankruptcy Law No. 2004,
  • Law No. 4904 on the Turkish Employment Agency and Certain Related Regulations,
  • Vocational Education Law No. 3308,
  • Turkish Commercial Code No. 6102,
  • Electronic Signature Law No. 5070,
  • Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed through Such Publications,
  • Social Insurance Procedures Regulation,
  • Identity Notification Law No. 1774,
  • Regulation on the Payment of Salaries, Bonuses, Premiums and Other Remuneration of This Nature through Banks,

and other applicable laws, regulations and communiqués.

Within this scope, the Organisation processes employee data in the categories of identity, contact information, personnel records, financial information, professional experience, physical-premises security, legal transactions, transaction security, risk management, visual and audio records and other information. It also processes special categories of personal data such as beliefs, association and foundation memberships, health information, criminal convictions and security measures.

7.2. Personal Data of Job Applicants

We process personal data that job applicants voluntarily provide through instruments such as CVs and cover letters, or that online recruitment platforms and/or talent agencies share with us at the applicant’s request for disclosure to relevant organisations. This may include identity and personnel information, contact and family details, financial and educational information, professional experience and habits, as well as special categories of data voluntarily included in a CV, such as association or foundation memberships.

7.3. Personal Data of Individual Suppliers and Corporate Supplier Representatives

When conducting its commercial activities, the Organisation processes the personal data of individual suppliers and representatives of corporate suppliers with whom it establishes a relationship in accordance with:

  • Service agreements,
  • Turkish Code of Obligations No. 6098,
  • Enforcement and Bankruptcy Law No. 2004,
  • Turkish Commercial Code No. 6102,
  • Tax Procedure Law No. 213,
  • General Communiqués issued under the Tax Procedure Law,

and other applicable laws, regulations and communiqués. The Organisation processes personal data relating to individual customers and suppliers and their representatives in the categories of identity, contact information, financial information, legal transactions and other information.

7.4. Personal Data of Auditors, Consultants and Public-Sector Employees

For the purpose of conducting the Organisation’s commercial and manufacturing activities and ensuring their sustainability and quality, the Organisation processes the personal data of auditors, consultants and public-sector employees who perform control and audit duties in accordance with:

  • Turkish Commercial Code No. 6102,
  • Customs Law No. 4458,
  • Tax Procedure Law No. 213,
  • Turkish Labour Law No. 4857,
  • Law No. 4904 on the Turkish Employment Agency and Certain Related Regulations,
  • Social Insurance and Universal Health Insurance Law No. 5510,
  • General Communiqués issued under the Tax Procedure Law,

and other applicable laws, regulations and communiqués.

Within this scope, the Organisation processes identity, contact and personnel-record data relating to auditors, consultants and public officials.

7.5. Personal Data of Individual Customers and Corporate Customer Representatives

Our products and services are purchased, trialled and managed through user accounts created on our website. We process identity and personnel information, contact details, customer-transaction data and financial data relating to users who use our proprietary services either individually or on behalf of an organisation.

7.6. Personal Data of Visitors to Our Premises

For the purpose of ensuring information-system and premises security, we process visitors’ personal data pursuant to:

  • Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed through Such Publications,

and on the basis of our legitimate interests.

Within this scope, personal data relating to visitors is processed in categories such as identity, transaction security and physical-premises security.

7.7. Personal Data of Website Visitors and Members

On the basis of our legitimate interests, the personal data of visitors to our websites is processed through “cookies”. For further information about cookies, please review our Cookie Policy.

7.8. Personal Data of Prospective Customers

In addition to advertisements on our Sites, we may inform users, trial users, customers and prospective customers about new products or services by email, social media or telephone after obtaining their consent. Prospective customers may request information from us through forms on our website. Data subjects may object to promotional, advertising and marketing communications at any time. Recipients who no longer wish to receive emails or SMS messages may block them, use the unsubscribe option or ask us to remove them from the relevant lists. We process information relating to prospective customers in categories such as identity, contact details, personnel information, financial information and customer transactions.

We also operate a newsletter to inform people interested in our products and/or services. Every newsletter contains a link through which recipients can unsubscribe, and users may also unsubscribe through their account settings. Within this limited scope, we process identity, personnel and contact data relating to prospective customers.

7.9. Personal Data of Our Dealers

We process the identity, contact and personnel data of representatives of dealers involved in the sale, marketing and after-sales support of our products and services pursuant to:

  • Dealership agreements,
  • Turkish Code of Obligations No. 6098,
  • Enforcement and Bankruptcy Law No. 2004,
  • Turkish Commercial Code No. 6102,
  • Tax Procedure Law No. 213,
  • General Communiqués issued under the Tax Procedure Law,

and other applicable laws, regulations and communiqués.

8. RIGHTS OF THE DATA SUBJECT

The Organisation acknowledges that, under the Law, data subjects have the right to provide or withhold approval before their personal data is processed and retain the right to determine the future of their data after processing.

In this context, data subjects may apply to the Contact Person to exercise the right to:

  • a) Learn whether their personal data is being processed,
  • b) Request information if their personal data has been processed,
  • c) Learn the purpose for which their personal data is processed and whether it is used in accordance with that purpose,
  • d) Know the third parties in Türkiye or abroad to whom their personal data has been transferred,
  • e) Request the correction of personal data that has been processed incompletely or inaccurately,
  • f) Request the deletion or destruction of personal data under the conditions stipulated in Article 7 of the Law,
  • g) Request that operations carried out pursuant to paragraphs (e) and (f) above be notified to third parties to whom the personal data has been transferred,
  • h) Object to an outcome arising against the data subject as a result of processed data being analysed exclusively through automated systems,
  • i) Claim compensation for damage suffered as a result of the unlawful processing of personal data.

However, individuals have no rights in relation to data that has been anonymised within the Company. Where required by an employment or contractual relationship, or where a judicial or public authority exercises a statutory power, personal data may be shared with the relevant institutions and organisations.

Requests relating to the rights listed above must be submitted to the Contact Person by completing the Organisation’s Application Form in full and sending it by registered mail with a handwritten signature and a photocopy of the applicant’s identity document (for a Turkish identity card, a copy of the front side only). For further information about the application process, please review the Personal Data Protection Notice.

9. CORE PRINCIPLES FOR PROCESSING PERSONAL DATA

When processing the personal data of data subjects, OSKON’s departments and employees must observe the following core principles, on which this Privacy Policy and the Organisation’s other corporate policies are based:

  • Lawfulness and fairness: The Organisation checks and verifies whether personal data collected directly or shared with it by other parties has been obtained in compliance with the conditions prescribed by the KVKK, including informing the data subject and, where required, obtaining the data subject’s explicit consent to processing. It acts fairly when informing data subjects, obtaining explicit consent and responding to requests for information.
  • Accuracy and keeping data up to date where necessary: To the extent permitted by its control mechanisms, the Organisation endeavours to ensure that personal data it processes and retains in its databases is accurate. It takes reasonable steps to keep data current, encourages data sources to provide accurate information and report changes, and seeks to verify accuracy and currency at the point of collection.
  • Processing for specified, explicit and legitimate purposes: The Organisation processes personal data only for the specified, explicit and legitimate purposes set out in this Privacy Policy.
  • Relevance, limitation and proportionality to the purposes of processing: The Organisation does not process personal data for purposes beyond those for which it was collected. If a new need arises, it informs the data subject and obtains explicit consent where required. Data is used only within the limits of its processing purpose and to the extent required to deliver the relevant service. It is not processed, used or made available for use outside business purposes. Where personal data must be processed for another purpose, the relevant compliance and control mechanisms are amended under the supervision and with the approval of the Committee.
  • Storage limitation: The Organisation retains personal data for the period prescribed by applicable legislation or required for the purpose for which it is processed. Personal data arising from contracts is retained for the applicable limitation periods and for the periods required by commercial and tax law. Once those purposes cease to exist, the Organisation deletes or anonymises the personal data. Retention periods for each data category are defined in the Personal Data Inventory.
  • Data minimisation: Except for the scope and periods required by law and applicable legislation, the Organisation, its departments and employees collect only the volume and categories of data necessary for the processing purpose and retain it in their systems only for as long as necessary.
  • Deletion and destruction: The Organisation retains personal data only for the periods prescribed by the laws and regulations to which it is subject—including social-security, obligations, tax and commercial legislation—and/or for as long as required by the processing purpose. Once those periods expire, personal data is deleted, destroyed or anonymised with the permission and under the supervision of the Committee, in accordance with the Personal Data Retention, Deletion, Destruction and Transfer Policy.
  • Confidentiality and data security: General confidentiality requirements and data-security principles are observed throughout all personal-data processing, transfer and storage activities within the Organisation. Operations are carried out in accordance with the policies and rules established for this purpose, and the necessary administrative and technical safeguards are implemented.

10. TRANSFER OF PERSONAL DATA

To conduct its manufacturing and commercial activities and obtain the specialist services required by the Organisation, OSKON works with service and product suppliers in Türkiye and abroad. Depending on their duties, activities and the nature of the services they provide, these suppliers may be regarded as “data processors”, “data controllers” or “joint data controllers”. OSKON may transfer personal data to these suppliers, business partners and authorised public or private institutions and organisations.

10.1. Matters to Be Observed When Transferring Personal Data

  • Every personal-data transfer must be safeguarded by entering into a data-transfer agreement, undertaking or similar document with each recipient.
  • Every department and employee must assess in advance the risks that a recipient may create in relation to personal data and exercise due care to prevent circumstances that could give rise to such risks.
  • When applications and services originating abroad are used, due care must be taken to comply with applicable legislation, including the KVKK and GDPR.
  • Data transfers to parties and suppliers must be performed using appropriate and secure tools and channels. It is mandatory to verify that natural-person recipients have been authorised by the relevant organisation and to delete any copies created for transfer from all media as soon as their function has ended.
  • The Organisation’s departments and employees must consider the personal-data practices and level of care demonstrated by recipients and suppliers and promptly report circumstances that may create risk to their managers. Employees must seek timely support from their managers regarding personal-data issues they cannot resolve.

10.2. Circumstances and Parties to Which Personal Data Is Transferred

Personal data is shared with the following parties for the purposes stated below:

  • Where necessary to plan and conduct the Organisation’s commercial activities, with group companies, business partners, affiliates, consultancy firms and other service providers in Türkiye and abroad, as well as private and public institutions and organisations;
  • With natural and legal persons providing relevant services, and the third parties with whom they work, for ensuring business continuity and legal, technical and commercial security and for planning and executing human-resources, occupational-health-and-safety, emergency-response processes and strategies;
  • With persons with whom the Organisation enters into contracts for procured services and the third parties with whom those persons work;
  • With external suppliers that support services delivered by the Organisation or provide employees with socioeconomic benefits, and the third parties with whom those suppliers work;
  • During recruitment and termination processes, with the Organisation’s internal departments, group companies and previous or subsequent employers;
  • Where required for the Organisation to fulfil its legal obligations, with business partners, consultancy firms, suppliers, private institutions and organisations, courts, public institutions and authorised bodies;
  • With relevant banks to make payments, receive collections and perform obligations required for establishing and performing contracts entered into by the Organisation;
  • With insurance agencies and insurance companies so employees can benefit from insurance and similar rights;
  • With law firms, accounting and certified-public-accountancy practices, lawyers and other advisers to obtain legal and financial support for establishing, exercising and protecting the Organisation’s rights;
  • With cloud-service providers in Türkiye and abroad to obtain the infrastructure and services required for corporate electronic communication channels and ensure data security;
  • With platforms and applications originating abroad from which services are obtained to use online communication channels and tools such as instant messaging, file sharing, video conferencing and email;
  • With suppliers providing and authorising services such as electronic signatures and corporate telephone lines;
  • With suppliers providing services for employee-engagement activities, including supportive messages on special occasions, events and employee-recognition programmes designed to improve motivation and strengthen team spirit;
  • With auditors and domestic or international audit organisations conducting quality, social-compliance and other audits commissioned by the Organisation or requested by customers;
  • With private and public institutions and organisations for conducting legal and technical procedures relating to intellectual and industrial property.

10.3. Transfer of Personal Data Abroad

OSKON shares personal data with service providers established abroad for the operation of our website, improvement of services, conduct of office operations, provision of services to users and visitors, ensuring satisfaction, meeting expectations and maintaining communication. Within this scope, data may be shared with:

  • US-based WhatsApp (Facebook) for instant messaging,
  • US-based Zoom and Google for video conferencing,
  • US-based Tawk.to for customer support and requests,
  • US-based Google and WeTransfer for file sharing,
  • Germany-based AnyDesk and TeamViewer for remote access,
  • US-based Apple and Google for mobile operating systems and associated services,
  • US-based Facebook, Twitter, Instagram, YouTube and Google for social-media services,
  • France-based SendinBlue for email delivery,
  • US-based RapidSSL for SSL certificate services,
  • US-based TheSSLStore for SSL certificate services,
  • Netherlands-based Realtime Register for domain registrations,
  • India-based P.D.R Solutions for domain registrations.

Each service provider’s privacy policy is available through the following links:

  • Microsoft (https://privacy.microsoft.com/en-us/privacystatement)
  • WhatsApp (https://www.whatsapp.com/legal/client)
  • Google (https://policies.google.com/privacy?hl=en-US)
  • WeTransfer (https://wetransfer.com/legal/privacy)
  • AnyDesk (https://anydesk.com/en/privacy)
  • TeamViewer (https://www.teamviewer.com/en/privacy-policy/)
  • Facebook (https://www.facebook.com/policy.php)
  • Twitter (https://twitter.com/en/privacy)
  • Instagram (https://help.instagram.com/519522125107875)
  • LinkedIn (https://www.linkedin.com/legal/privacy-policy)
  • Cloudflare (https://www.cloudflare.com/privacypolicy/)
  • Tawk.to (https://www.tawk.to/privacy-policy/)
  • SendinBlue (https://www.sendinblue.com/legal/privacypolicy/)

11. AUDITS, APPLICATIONS AND PERSONAL-DATA BREACH NOTIFICATIONS

The Organisation may arrange the internal and external audits necessary for the protection of personal data.

Applications submitted by data subjects are answered within no more than 30 days by the Committee after obtaining the relevant department’s opinion.

If the Organisation is notified of a personal-data breach, it reports the breach to the Turkish Personal Data Protection Board without undue delay and no later than 72 hours after becoming aware of it. Relevant parties and affected individuals are informed accordingly.

12. UPDATES

This policy document is updated whenever the Organisation’s conditions, tools, purposes or scope of personal-data processing change or where the parties with whom personal data is shared change. Amendments to each provision are maintained in a separate change log.