Maxton Yapı Ürünleri San. ve Tic. A.Ş. (“BIQSLAB” or the “Company”) places utmost importance on the processing of personal data in compliance with applicable legislation and on ensuring the confidentiality and security of such data. BIQSLAB processes personal data within the limits prescribed by the Law No. 6698 on the Protection of Personal Data (the “Law” or “KVKK”), the secondary legislation issued thereunder, and the decisions of the Personal Data Protection Board.
This Policy has been prepared by BIQSLAB, in its capacity as the Data Controller, for the purposes of fulfilling the disclosure obligation set forth under Article 10 of the Law and providing data subjects with the most transparent information regarding their rights set forth under Article 11 of the Law.
This Policy covers all personal data of BIQSLAB employees, employees’ family members, job applicants, referees, supplier employees, supplier representatives, customers, and other third parties that are processed by fully or partially automated means or by non-automated means, provided that such processing forms part of a data recording system.
This Policy provides general information regarding personal data processing activities as a whole. Separate Privacy Notices have been prepared for specific personal data processing activities, and data subjects are informed accordingly. Information regarding the personal data processed, the purposes of processing, the method of collection and legal basis, and the purposes for and recipients to whom such data are transferred is provided in the relevant Privacy Notices prepared specifically for each category of data subject.
BIQSLAB has adopted the following principles as its operating principles in order to ensure the processing and protection of personal data in accordance with the procedures and principles stipulated primarily under Article 20 of the Constitution, the Law No. 6698 on the Protection of Personal Data, other secondary legislation, and the decisions of the Personal Data Protection Board.
Personal data may be processed by BIQSLAB in accordance with the principles set forth in Article 4 of the Law and the procedures and principles stipulated under other applicable laws.
Principle of compliance with the law and the rules of good faith: BIQSLAB processes the minimum amount of data possible, taking into consideration the reasonable expectations of data subjects and without exceeding the purpose of processing. BIQSLAB takes due care to ensure transparency of processing activities for the relevant person and fulfills its disclosure obligation.
Principle of accuracy and keeping personal data up to date: BIQSLAB places importance on ensuring that personal data are accurate and up to date. Where necessary, data are updated and their accuracy is verified.
Principle of processing personal data for specific, explicit, and legitimate purposes: Personal data are processed for specific, explicit, and legitimate purposes. BIQSLAB does not process personal data for any purpose other than those communicated to the relevant person.
Principle of processing personal data in connection with, limited to, and proportionate to the purposes for which they are processed: BIQSLAB limits its data processing activities to data that are sufficient and necessary to achieve the relevant purpose. Data that are not suitable or necessary for achieving the purpose are avoided.
Principle of retaining personal data for the period required: In accordance with Article 138 of the Turkish Criminal Code and Articles 4 and 7 of the KVKK, BIQSLAB retains personal data only for the period stipulated under the applicable legislation or required by the purpose of processing the personal data. In this regard, the Company first determines whether a specific retention period is prescribed under the relevant legislation for the personal data in question. If a statutory period has been established, the Company complies with such period. If no statutory period has been established, the period necessary to fulfill the purpose of processing is determined, and the personal data are retained only for such period. At the end of the designated retention periods or upon the request of the relevant person, personal data are destroyed by BIQSLAB using the designated destruction methods, including deletion, destruction, and/or anonymization.
Your personal data may be collected automatically or non-automatically through various means, including during physical visits to our Company, camera recordings, call recordings, our business units, verbal communication, hand delivery, paper-based documents, contracts, information collection forms, e-mail, registered electronic mail (KEP), fax, telephone, website, and other similar means, whether verbally, in writing, or electronically.
As long as you benefit from BIQSLAB’s services, your personal data may be processed and, where necessary, updated in order to ensure the accuracy and currency of your data.
Pursuant to paragraph 1 of Article 5 of the Law, personal data may not, as a rule, be processed without the explicit consent of the data subject. Explicit consent is obtained after the data subject has been informed about the relevant matter and has provided consent based on their free will.
However, pursuant to paragraph 2 of Article 5 of the Law, personal data may be processed without seeking the explicit consent of the data subject where one of the following conditions applies:
Explicitly provided for by law: Personal data may be processed without obtaining the consent of the data subject where the processing of personal data is expressly provided for by law.
Failure to obtain explicit consent due to actual impossibility: Where it is necessary to process the personal data of a person who is physically incapable of expressing consent or whose consent cannot be legally recognized, in order to protect the life or physical integrity of that person or another person, the personal data of the data subject may be processed.
Directly related to the establishment or performance of a contract: Personal data may be processed where such processing is necessary for the establishment or performance of a contract, provided that it is directly related to the parties to such contract.
Necessary for the Data Controller to fulfill its legal obligation: Where processing personal data is necessary for the Data Controller to fulfill its legal obligations, the personal data of the data subject may be processed.
Made public by the data subject: Personal data that have been made public by the data subject in any manner and thereby made available to the public may be processed to the extent consistent with the purpose for which they were made public.
Necessary for the establishment, exercise, or protection of a right: Where processing personal data is necessary for the establishment, exercise, or protection of a right, the personal data of the data subject may be processed.
Necessary for the legitimate interests of the Data Controller: The Data Controller first identifies the legitimate interest to be obtained through the processing of personal data and assesses the potential impact of such processing on the rights and freedoms of the data subject. Where it concludes that the balance of interests has not been adversely affected, the processing activity may be carried out.
BIQSLAB exercises particular care in processing special categories of personal data, as additional measures are required for their retention and transfer compared to other personal data. Special categories of personal data are data which, if disclosed, may result in discrimination against or victimization of the relevant person.
The special categories of personal data exhaustively listed under Article 6 of the Law include data relating to a person’s race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
The processing of special categories of personal data is prohibited. However, such data may be processed where:
a) The explicit consent of the relevant person has been obtained;
b) It is expressly provided for by law;
c) It is necessary to protect the life or physical integrity of the person or another person where the relevant person is physically incapable of expressing consent or where their consent cannot be legally recognized;
ç) It relates to personal data made public by the relevant person and is consistent with the relevant person’s intention to make such data public;
d) It is necessary for the establishment, exercise, or protection of a right;
e) It is necessary for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning, management, and financing of health services, by persons or authorized institutions and organizations under an obligation of confidentiality;
f) It is necessary for the fulfillment of legal obligations in the fields of employment, occupational health and safety, social security, social services, and social assistance;
g) It concerns existing or former members or persons who have regular contact with foundations, associations, and other non-profit organizations established for political, philosophical, religious, or trade union purposes, provided that the processing complies with the legislation and purposes to which such organizations are subject, is limited to their fields of activity, and is not disclosed to third parties.
When processing special categories of personal data, adequate measures determined by the Board must also be implemented.
Within the scope of the personal data processing conditions specified under Articles 5 and 6 of the Law, BIQSLAB may process personal data falling into the following categories: identity, contact, personnel, legal transaction, customer transaction, transaction security, risk management, financial, marketing, professional experience, visual and audio recordings, physical premises security, health information, criminal conviction, and security measures.
The personal data processed may vary depending on the activities carried out by BIQSLAB. Data subjects are informed through separate Privacy Notices prepared specifically for the relevant personal data processing activity.
This Policy on the Processing and Protection of Personal Data covers all personal data of BIQSLAB employees, employees’ family members, job applicants, interns, referees, supplier employees, supplier representatives, customers, and other third parties that are processed by fully or partially automated means or by non-automated means, provided that such processing forms part of a data recording system.
Personal data obtained by BIQSLAB’s business units may be processed within the scope of the personal data processing conditions specified under Articles 5 and 6 of the Law.
BIQSLAB may transfer personal data, in accordance with the conditions for the transfer of personal data specified under Articles 8 and 9 of the Law and for the relevant data processing purposes, to:
The Revenue Administration, Social Security Institution, and other legally authorized public institutions and organizations, as well as legally authorized private-law entities, for the fulfillment of legal obligations such as reporting and sharing information and documents;
Natural persons and private-law legal entities, such as Occupational Health and Safety Services Units (OSGB), Certified Public Accountants (SMMM), Sworn-in Certified Public Accountants (YMM), and law firms, for the purpose of obtaining support services in areas such as training, accounting, and legal services;
Independent Audit Firms for the purposes of risk management and internal audit activities;
Banks for the execution of payment transactions;
Relevant insurance companies for the execution of Private Pension System (BES) payments;
Companies from which information technology support services are obtained, for the purpose of receiving IT support services;
Relevant suppliers for the execution of procurement activities;
Business partners, group companies, and companies that have an organic relationship with BIQSLAB and/or have similar ownership structures, for the purposes of carrying out commercial activities and implementing Company policies.
Data transfers are carried out in a manner that is connected to, limited to, and proportionate to the purpose of the transfer.
The right to request the protection of personal data was constitutionally safeguarded within the scope of the “right to privacy and protection of private life” through the addition of a paragraph to Article 20 of the Constitution by Constitutional Amendment Law No. 5982 enacted in 2010.
Pursuant to Article 12 of the Law, BIQSLAB implements the necessary measures to ensure an appropriate level of security in accordance with the nature of the personal data, in order to prevent the unlawful processing of personal data, prevent unlawful access to personal data, and ensure the secure retention of personal data.
Our Company places great importance on the protection of personal data. Particular attention is paid to ensuring that employees participate in KVKK training and develop awareness of personal data protection.
KVKK Policies have been established for our Company, and activities involving personal data are carried out in accordance with the procedures and principles set forth in these policies. Responsible persons and corresponding duties have been designated for the implementation of the policies, monitoring employees’ compliance with the policies, publishing and updating the policies, and carrying out data destruction activities.
Our Company is authorized to make the necessary updates concerning the processing and protection of personal data and information security in accordance with legislative amendments and decisions of the Board. The Company conducts and/or commissions the necessary audits within the scope of the KVKK. Expert support may be obtained from professionals specialized in the relevant fields for the execution of these processes.
BIQSLAB retains personal data for the period necessary for the purposes for which they are processed and in accordance with the periods stipulated under the applicable legislation governing the relevant activity.
In this regard, our Company first determines whether a specific retention period is prescribed under the relevant legislation for the retention of personal data. Where a statutory period has been established, the Company complies with such period. Where no statutory period exists, personal data are retained for the period necessary for the purposes for which they are processed.
At the end of the designated retention periods or upon the request of the data subject, personal data are destroyed by BIQSLAB using the designated destruction methods, including deletion, destruction, and/or anonymization.
This Policy provides general information regarding personal data processing activities as a whole. Relevant persons are informed in detail through separate Privacy Notices specific to each data processing activity, and explicit consent is obtained where necessary.
Accordingly, separate Privacy Notices and explicit consent texts are used for specific categories of data subjects, such as employees, job applicants, and customers.
During personal data processing activities, our Company informs the relevant persons whose data are processed about the categories of data processed, purposes of processing, method and legal basis of data collection, recipient groups to which data are transferred and the purposes of such transfers, their rights as data subjects, and our Company as the Data Controller.
Our Company fulfills its disclosure obligation stipulated under Article 10 of the Law in accordance with the procedures and principles set forth in the Guide on Fulfilling the Disclosure Obligation published by the Authority. Necessary disclosures are published electronically or physically in accordance with the method used to collect the relevant data.
Data subjects have the right to:
Learn whether their personal data are being processed;
Request information if their personal data have been processed;
Learn the purpose of processing their personal data and whether such data are used in accordance with that purpose;
Know the third parties to whom their personal data are transferred within or outside Türkiye;
Request the correction of personal data that are incomplete or inaccurately processed and request that such correction be notified to third parties to whom the personal data have been transferred;
Request the deletion or destruction of personal data where the reasons requiring their processing have ceased to exist, even though the data have been processed in accordance with the Law and other applicable laws, and request that such deletion or destruction be notified to third parties to whom the personal data have been transferred;
Object to a result arising against them where their processed data are analyzed exclusively through automated systems;
Request compensation for damages where they suffer damage due to the unlawful processing of their personal data.
You may submit your applications and requests listed above by completing the Data Subject Application Form available on our website and delivering a wet-signed copy in person or through a notary public to our address at Gökyaka Mah. 18. Cadde No:8/1, Çine/Aydın, or by sending it to info@maxton.com.tr.
Detailed information regarding the matters that must be included in your application and the applicable application methods is available in the Data Subject Application Form.
The application must include your full name and, if the application is submitted in writing, your signature; your Turkish Republic identification number for Turkish citizens; your nationality, passport number, or identification number, if any, for foreign nationals; your residential or business address for notification purposes; your e-mail address, if any, for notification purposes; your telephone and fax numbers; and the subject of your request.
Information and documents relating to the subject matter must be attached to the application. Where an application is prepared without using the Data Subject Application Form, all of the information specified in this paragraph must be submitted to our Company in full. Otherwise, the application will not be considered a valid application.
For a third party to submit an application on behalf of a data subject whose personal data are processed, a special power of attorney issued by the relevant person through a notary public in favor of the person making the application must be provided.
Our Company may request additional verification information in order to verify that the applicant is the relevant data subject and to ensure that the results of the application are communicated to the correct person. For example, additional verification may be requested, such as sending a message to your registered telephone number or contacting you by telephone.
Your request will be concluded free of charge as soon as possible and no later than 30 days, depending on the nature of the request. However, if the process requires an additional cost for the Company, a fee may be charged in accordance with the tariff determined by the Personal Data Protection Board.
If your request is accepted, the necessary action will be taken. If your request is rejected following the examination and assessment, you will be notified of the rejection and the reasons for it in writing or electronically.
Detailed information regarding your rights to apply to the Data Controller and lodge a complaint with the Board is available in Articles 13, 14, and 15 of Part Four of the Law.
Pursuant to Article 28 of the Law, BIQSLAB may reject a data subject’s application, explaining the grounds for rejection, in the following circumstances:
Where personal data are processed by natural persons exclusively within the scope of activities relating to themselves or their family members living in the same household, provided that such data are not disclosed to third parties and data security obligations are complied with;
Where personal data are processed for purposes such as research, planning, and statistics after being anonymized for official statistical purposes;
Where personal data are processed for artistic, historical, literary, or scientific purposes or within the scope of freedom of expression, provided that such processing does not violate national defense, national security, public security, public order, economic security, privacy, or personal rights, or constitute a crime;
Where personal data are processed within the scope of preventive, protective, and intelligence activities carried out by public institutions and organizations authorized and assigned by law to ensure national defense, national security, public security, public order, or economic security;
Where personal data are processed by judicial authorities or enforcement authorities in connection with investigations, prosecutions, judicial proceedings, or enforcement proceedings.
Pursuant to Article 28/2 of the Law, provided that such processing is compatible with the purpose and fundamental principles of the Law and proportionate, Articles 10, which regulates the Data Controller’s disclosure obligation; 11, which regulates the rights of the relevant person, except for the right to request compensation for damages; and 16, which regulates the obligation to register with the Data Controllers Registry, shall not apply in the following circumstances:
Where processing personal data is necessary for the prevention of a crime or for a criminal investigation;
Where personal data made public by the relevant person are processed;
Where processing personal data is necessary for the performance of inspection or regulatory duties or disciplinary investigations or proceedings by public institutions and organizations or professional organizations having the status of public institutions, based on the authority granted by law;
Where processing personal data is necessary for the protection of the State’s economic and financial interests in relation to budgetary, tax, and financial matters.
This Policy entered into force on the date of its publication.
BIQSLAB reserves the right to amend this Policy in order to provide up-to-date information regarding practices and legal regulations concerning the protection of personal data. If the entire Policy or any of its provisions are updated, such updates shall enter into force on the date of their publication.
BIQSLAB, as the Data Controller, is responsible for implementing this Policy and monitoring, coordinating, and auditing all activities and actions related to the compliance process with the Law.
The applicable legislation concerning the processing and protection of personal data shall take precedence. In the event of any inconsistency between the applicable legislation and this Policy, BIQSLAB acknowledges that the applicable legislation shall prevail.
| TERM | DESCRIPTION |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person. |
| Special Categories of Personal Data | Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. |
| Explicit Consent | Consent relating to a specific matter, based on being informed and expressed freely. The data subject always has the right to withdraw their consent. |
| Data Controller | The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system. |
| Relevant Person / Data Subject | The natural person whose personal data are processed. |
| Contact Person | The person responsible for ensuring communication between the Data Controller and the relevant person or the Personal Data Protection Authority. |
| Processing of Personal Data | Any operation performed on personal data, including obtaining, recording, storing, retaining, altering, reorganizing, disclosing, transferring, taking over, making available, classifying, or preventing the use of such data, whether wholly or partially by automated means or by non-automated means provided that such processing forms part of a data recording system. |
| Data Recording System | A recording system in which personal data are structured and processed according to specific criteria. |
| Anonymization | Rendering personal data incapable of being associated with an identified or identifiable natural person in any way, even when matched with other data. |
| Board | The Personal Data Protection Board. |
| Authority | The Personal Data Protection Authority. |
| Data Processor | The natural or legal person who processes personal data on behalf of the Data Controller based on the authority granted by the Data Controller. |