Personal Data Protection Notice

Home > Corporate > Personal Data Protection Notice
PRIVACY NOTICE AND PERSONAL DATA PROTECTION POLICY UNDER THE TURKISH PERSONAL DATA PROTECTION LAW

ENVAPLAS PLASTİK MAKİNA İMALAT HIRDAVAT NAKLİYE İTHALAT İHRACAT ENERJİ SAN. VE TİC. LTD. (“ENVAPLAS” or the “Company”), acting as the data controller, hereby presents this Privacy Notice to the relevant data subjects in order to fulfil its obligation to inform prior to the processing of personal data, pursuant to Article 10 of the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and in accordance with the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform, published by the Turkish Personal Data Protection Authority. Within the scope of our obligation to inform under the KVKK, this Privacy Notice explains the data collected from you, as visitors/users of the ENVAPLAS website (the “Site”), during the operation of the website at www.envapeyzaj.com and how we use such data.

1- IDENTITY OF THE DATA CONTROLLER

With respect to the personal data you share through the channels described herein, the Data Controller within the meaning of the KVKK is ENVAPLAS PLASTİK MAKİNA İMALAT HIRDAVAT NAKLİYE İTHALAT İHRACAT ENERJİ SAN. VE TİC. LTD., registered with the Ankara Trade Registry under registration number 17386 and MERSIS number 0336104906700001, with its registered address at EOSB, 23100 Organize Sanayi Bölgesi, 96. Sk. No:8, 23200 Elazığ Merkez/Elazığ, Türkiye.

2- GENERAL INFORMATION ABOUT THE LAW AND ITS PURPOSE

The protection of personal data is primarily guaranteed under Article 20 of the Constitution of the Republic of Türkiye, entitled “Privacy of Private Life.” Within this scope, everyone has the right to be informed about personal data relating to them that has been obtained, processed and stored; to access such data; to request its correction or deletion; and to learn whether it is being used in accordance with its intended purposes. Personal data may only be processed in circumstances prescribed by law or with the explicit consent of the individual. As ENVAPLAS, we attach the utmost importance to the lawful protection and processing of personal data in accordance with the KVKK and act with due care in all our planning and activities.

Article 20 of the Constitution provides that the principles and procedures regarding the protection of personal data shall be regulated by law. Accordingly, the Turkish Personal Data Protection Law No. 6698 was published in the Official Gazette No. 29677 dated 7 April 2016. Subsequently, the scope and implementation of the Law have been further developed through the regulations and communiqués issued pursuant to the Law.

The Turkish Personal Data Protection Law No. 6698 was enacted to protect the fundamental rights and freedoms of individuals, particularly the right to privacy, in connection with the processing of personal data; to regulate the obligations, procedures and principles to be followed by natural and legal persons processing personal data; and to establish the legal rights available to natural persons whose personal data is processed.

3- DEFINITIONS

Explicit Consent: Consent relating to a specific matter, based on adequate information and expressed freely.

Anonymisation: The process of rendering personal data incapable of being associated with an identified or identifiable natural person in an irreversible manner. Examples include masking, aggregation and data corruption techniques.

Employee: Natural persons employed by the Company under an employment agreement.

Employee Candidate: Natural persons who have applied for employment with the Company through any means or have otherwise made their CV and related information available for review by the Company.

Natural Persons and Private-Law Legal Entities: Natural persons are individuals who have been born alive and fully and are currently living, as defined under the Turkish Civil Code. Private-law legal entities include commercial companies defined under the Turkish Commercial Code and associations and foundations defined under the Turkish Civil Code.

General Public: A group consisting of all individuals without any specific distinguishing characteristics.

Shareholders: Natural or legal persons holding shares in the Data Controller’s Company.

Business Partner: Parties with whom the Data Controller conducts commercial activities and maintains business relationships.

Employees, Shareholders and Officials of Cooperating Institutions: Natural persons, including employees, shareholders and authorised representatives of institutions with which the Company maintains any type of business relationship, including but not limited to business partners, legal advisers and suppliers.

Affiliates and Subsidiaries: An affiliate refers to a company in which the Data Controller holds an ownership interest. Where the Company holds more than 50% of the voting rights in another company, the relationship constitutes a subsidiary relationship; otherwise, it constitutes an affiliate relationship.

Processing of Personal Data: Any operation performed on personal data, whether wholly or partly by automated means or by non-automated means forming part of a data filing system, including collection, recording, storage, preservation, alteration, reorganisation, disclosure, transfer, acquisition, making available, classification or restriction of use.

Personal Data Subject: The natural person whose personal data is processed, such as customers and employees.

Personal Data: Any information relating to an identified or identifiable natural person. Information relating solely to legal entities does not fall within the scope of the Law. Examples include name and surname, Turkish ID number, email address, residential address, date of birth and credit card number.

Customer: Natural persons who use or have used the products or services offered by the Company, regardless of whether they have a contractual relationship with the Company.

Special Categories of Personal Data: Personal data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, religious denomination or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.

Potential Customer: Natural persons who have expressed an interest in or request to use our products and services, or who may reasonably be considered potential customers in accordance with established commercial practices and principles of good faith.

Intern: Natural persons who have applied for an internship with the Company through any means for the purpose of applying their theoretical professional knowledge in a workplace environment.

Company Shareholder: Natural persons holding shares in the Company.

Company Official: Members of the Company’s board of directors and other authorised natural persons.

Supplier: Parties maintaining a business relationship with the Data Controller under a service agreement and/or agency agreement for the procurement of services within the scope of the Data Controller’s commercial activities.

Group Companies: Companies directly or indirectly controlled by a parent company which, together with that parent company, constitute a group of companies as defined under the Turkish Commercial Code.

Third Party: Natural persons associated with the aforementioned parties for the purposes of ensuring the security of commercial transactions between the Company and such parties, protecting their rights or safeguarding their interests, such as family members and relatives.

Data Processor: A natural or legal person who processes personal data on behalf of the Data Controller based on the authority granted by the Data Controller.

Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.

Authorised Public Institutions and Organisations: Public institutions and organisations authorised under applicable legislation to request information and documents from the Data Controller, as well as those to which data must be transferred in order for the Data Controller to fulfil its legal obligations.

Visitor: Natural persons who enter the Company’s physical premises for various purposes or visit the Company’s websites.

4- ABBREVIATIONS

KVKK: Turkish Personal Data Protection Law No. 6698, dated 24 March 2016 and published in the Official Gazette No. 29677 dated 7 April 2016.

Constitution: Constitution of the Republic of Türkiye No. 2709.

KVK Board: Turkish Personal Data Protection Board.

KVK Authority: Turkish Personal Data Protection Authority.

Policy: The Company’s Personal Data Protection and Processing Policy.

TCO: Turkish Code of Obligations No. 6098.

TPC: Turkish Penal Code No. 5237.

TCC: Turkish Commercial Code No. 6102.

5- DATA CATEGORIES

The Company may record, process or transfer data relating to the following data categories:

Identity: Name and surname, mother’s and father’s name, mother’s maiden name, date and place of birth, marital status, identity card serial/sequence number, Turkish ID number and similar information.

Contact Information: Address number, email address, contact address, registered electronic mail (KEP) address, telephone number and similar information.

Location: Information concerning the location of the person.

Personnel: Payroll information, disciplinary investigation records, employment entry and termination records, asset declaration information, CV information, performance evaluation reports and similar information.

Legal Proceedings: Information contained in correspondence with judicial authorities, information contained in case files and similar information.

Customer Transactions: Call centre records, invoices, promissory notes, cheque information, information contained in counter receipts, order information, request information and similar information.

Physical Premises Security: Entry and exit records of employees and visitors, CCTV records and similar information.

Transaction Security: IP address information, website login and logout information, passwords and passcodes and similar information.

Risk Management: Information processed for the management of commercial, technical and administrative risks.

Finance: Balance sheet information, financial performance information, credit and risk information, asset information and similar information.

Professional Experience: Diploma information, courses attended, in-service training information, certificates, transcript information and similar information.

Visual Records: Visual and CCTV recordings and similar information.

Health Information: Information concerning disability status, blood type, personal health information, information concerning devices and prostheses used and similar information.

Criminal Convictions and Security Measures: Information relating to criminal convictions and security measures.

Biometric Data: Palm data, fingerprint data, retinal scan data, facial recognition data and similar information.

6- WHAT IS PERSONAL DATA?

Personal data means any information relating to an identified or identifiable natural person. In this context, personal data includes not only information that directly identifies an individual, such as name, surname, date and place of birth (“Personal Data”), but also information relating to a person’s physical, family, economic and social characteristics, race, ethnic origin, clothing and appearance, membership of associations, foundations or trade unions, health, sexual life, criminal convictions, security measures and other characteristics (“Special Categories of Personal Data”). A person is considered identified or identifiable where available data can, in any manner, be associated with a natural person so as to identify that person. This includes all circumstances in which data contains specific information reflecting a person’s physical, economic, cultural, social or psychological identity or enables the person to be identified through association with any record, such as an identity, tax or insurance number. Data such as names, telephone numbers, vehicle registration plates, social security numbers, passport numbers, CVs, photographs, image and audio recordings, fingerprints and genetic information constitute personal data because they may make an individual identifiable, even indirectly. Accordingly, all explanations herein cover all of your personal data, including special categories of personal data.

7- HOW DO WE COLLECT YOUR PERSONAL DATA?

We collect your Personal Data for the principal purposes and by the methods described below, as well as through other channels that may be added in the future, by automated or non-automated means and in audio, verbal, written or electronic form.

We may collect your Personal Data through our internet and mobile platforms, including our websites, mobile sites and applications; social media accounts operated on behalf of ENVAPLAS; communication methods including email, SMS and MMS; agreements signed with you or the company you represent within the scope of ENVAPLAS sales and marketing activities; commercial offers; printed and electronic forms; business cards and other documents provided during customer visits; third parties such as ENVAPLAS business contacts, dealers, sales channels, manufacturers and companies from which services or products are procured; and various sources including trade registries.

We process the Personal Data collected through the above methods on the basis of one or more of the following legal grounds:

• Your explicit consent;
• Processing being permitted by applicable laws and regulations in the Republic of Türkiye;
• Processing being necessary to protect the life or physical integrity of you or another person where you are unable to express consent due to actual impossibility;
• Processing being necessary for the performance of a contract concluded with you or your company;
• Processing being necessary for compliance with our legal obligations;
• Your Personal Data having been made public by you;
• Processing being necessary for the establishment, exercise or protection of ENVAPLAS’s legal or contractual rights;
• Processing being necessary for our legitimate interests, provided that such processing does not prejudice your fundamental rights and freedoms.

Processing special categories of personal data without the explicit consent of the data subject is prohibited. Special categories of personal data other than data concerning health and sexual life may be processed without explicit consent where permitted by law. Personal data concerning health and sexual life may be processed without explicit consent only by persons subject to a confidentiality obligation or by authorised institutions and organisations for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of healthcare services and their financing.

As ENVAPLAS, we retain all Personal Data processed by us for the periods required under the KVKK and other applicable legislation and, in any event, for as long as the legitimate purposes stated above continue to exist, by taking all necessary administrative and technical measures.

8- FOR WHAT PURPOSES DO WE PROCESS YOUR PERSONAL DATA?

Depending on its nature, we process the Personal Data we collect for the following general purposes:

(1) Fulfilling agreements entered into by ENVAPLAS; providing and manufacturing products and services; carrying out sales, delivery and installation operations; developing products and services; conducting necessary studies and evaluations; and providing after-sales maintenance and repair services.

(2) Monitoring and fulfilling obligations arising from consumer legislation and responding to consumer applications.

(3) Monitoring and evaluating requests and complaints from customers, consumers and other relevant persons; providing support services; managing consumer satisfaction; and conducting planning, statistical studies and satisfaction surveys.

(4) Conducting quality assessment and improvement activities to provide better and more reliable products and services and ensure sustainability, and auditing suppliers, subcontractors and other business partners.

(5) Conducting advertising and marketing activities relating to ENVAPLAS products and services; providing information about promotions, campaigns, offers, events, new products and services; and carrying out corporate communications.

(6) Conducting marketing and CRM (Customer Relationship Management) activities.

(7) Conducting corporate communications, organising events and invitations, providing information about them and carrying out market research.

(8) Improving digital platforms made available to customers, consumers and business contacts; generating statistics concerning users, visits, behaviour and geographical location; providing personalised content, campaigns and advertisements; and using cookies for these purposes.

(9) Ensuring the legal and commercial security of ENVAPLAS and persons having a business relationship with the Company, including communication operations, physical security of Company premises, evaluation and auditing of business partners, customers and suppliers, and legal compliance processes.

(10) Exercising legal rights and using transaction history as evidence in the event of disputes.

(11) Determining and implementing ENVAPLAS’s commercial, legal and business strategies.

(12) Conducting ENVAPLAS’s human resources and accounting/finance policies.

(13) Planning, auditing and conducting information security processes.

(14) Ensuring compliance with domestic and international legislation, providing information requested by public institutions and organisations, and fulfilling reporting obligations.

The purpose of our policy is to ensure compliance with personal data protection obligations; evaluate the processing, transfer and confidentiality of information obtained through Company activities using a risk-based approach; determine strategies, internal controls, measures, operating rules and responsibilities; and raise awareness among Company employees. It also aims to ensure transparency by informing persons whose personal data is processed by the Company, including customers, potential customers, employees, employee candidates, Company shareholders, Company officials, visitors, employees, shareholders and officials of cooperating institutions and organisations, and third parties.

Your personal data may be collected by the Human Resources Department, General Management and natural or legal persons authorised by ENVAPLAS, through automated and non-automated methods and by verbal, written or electronic means, including email, telephone, websites, agreements, paper forms and records.

Your personal data is processed in accordance with the fundamental principles set out in the Turkish Personal Data Protection Law for purposes including conducting operational activities, business relationships and human resources processes; providing updates; establishing and performing contracts; fulfilling legal obligations; advertising and marketing; conducting surveys and polls; identifying, personalising and improving suitable products, projects and services; providing effective customer service; making relevant notifications; responding to requests; maintaining technical processes; ensuring commercial security; and conducting Company activities. Such data is securely stored in physical or electronic environments for a period appropriate to its processing purpose.

9- TRANSFER OF PERSONAL DATA

We may share your Personal Data with other ENVAPLAS companies located in Türkiye and abroad. ENVAPLAS undertakes to securely retain your personal data and not process it unlawfully.

Where the legal grounds described above exist, we may transfer your personal data to business contacts with whom we cooperate and/or from whom we receive services in Türkiye and abroad, supplier companies, banks, financial institutions, consultancy firms providing support in areas such as law and tax, other related parties where transfer is necessary for the specified purposes, authorised institutions and organisations, and third parties providing storage, archiving, information technology support, including servers, hosting, software and cloud computing, and call centre services.

Where the conditions specified in the Law are met, personal data may be transferred abroad in accordance with the applicable requirements of the KVKK and relevant legislation.

The Company may transfer personal data to the following recipient groups:

• Shareholders
• Business Partners
• Suppliers
• Group Companies
• Authorised Public Institutions and Organisations
• Natural persons or companies providing legal consultancy services

PERSONS WHOSE PERSONAL DATA MAY BE PROCESSED

The Company may record, process or transfer personal data relating to the following categories of persons:

• Employee Candidates
• Employees
• Shareholders/Partners
• Potential Product and Service Customers
• Interns
• Supplier Employees
• Supplier Officials
• Persons Receiving Products or Services
• Visitors

Personal Data that may only be processed subject to explicit consent may, on the basis of such consent, be transferred to Group Companies, business contacts, suppliers, banks, financial institutions, consultancy firms and other relevant or authorised parties in Türkiye and abroad, subject to applicable law.

ENVAPLAS may also transfer data, within legitimate purposes and legal limits, to:

(1) Institutions designated by laws and regulations;
(2) Dealers and other representatives and agencies;
(3) Tax and legal advisers, auditors and other external professional advisers;
(4) Third parties providing products or services to ENVAPLAS, such as information systems providers and customer satisfaction-oriented marketing service providers.

10- PERSONAL DATA RETENTION PERIODS

Personal data retention periods are regulated in detail in the Personal Data Retention and Destruction Policy.

11- DELETION, DESTRUCTION OR ANONYMISATION OF PERSONAL DATA

Although personal data may have been processed lawfully, where the reasons requiring its processing cease to exist, such data shall be deleted, destroyed or anonymised by the Data Controller ex officio or upon the request of the relevant person.

The Data Controller shall delete, destroy or anonymise personal data during the first periodic destruction process following the date on which the obligation to delete, destroy or anonymise the personal data arises.

The procedures relating to these matters are explained in detail in the Personal Data Retention and Destruction Policy.

12- GENERAL (FUNDAMENTAL) PRINCIPLES FOR THE PROCESSING OF PERSONAL DATA

Personal data shall be processed in accordance with the following fundamental principles regulated under Article 4 of the Turkish Personal Data Protection Law:

Compliance with the Law and the Principles of Good Faith

Personal data must be processed in accordance with laws and other legal regulations and in compliance with the principles of good faith.

Accuracy and, Where Necessary, Keeping Data Up to Date

Maintaining personal data accurately and keeping it up to date where necessary is essential for protecting individuals’ fundamental rights and freedoms.

Processing for Specified, Explicit and Legitimate Purposes

Data Controllers must clearly and precisely determine the purpose of data processing, and such purpose must be legitimate. The data processed must be related to and necessary for the business conducted or service provided.

Being Relevant, Limited and Proportionate to the Purposes for Which Data Is Processed

The data processed must be suitable for achieving the specified purposes. Personal data unrelated to or unnecessary for those purposes should not be processed. The principle of proportionality requires a reasonable balance between data processing and the intended purpose.

Retention for the Period Prescribed by Relevant Legislation or Required for the Purpose for Which Data Is Processed

Personal data must be retained only for the period necessary for the purposes for which it is processed. Once applicable statutory or Company retention periods expire, personal data must be deleted, destroyed or anonymised.

13- LEGAL RIGHTS UNDER THE TURKISH PERSONAL DATA PROTECTION LAW

Pursuant to Article 11 of the Turkish Personal Data Protection Law No. 6698 and the Communiqué on the Procedures and Principles of Application to the Data Controller, the Personal Data Subject may apply to our Company and exercise the following rights:

• To learn whether their personal data is being processed;
• To request information if their personal data has been processed;
• To learn the purpose of processing their personal data and whether it is being used in accordance with that purpose;
• To know the third parties to whom their personal data has been transferred in Türkiye or abroad;
• To request correction of personal data where it has been processed incompletely or inaccurately and to request its deletion or destruction under the conditions set out in Article 7 of the KVKK;
• To request notification of correction, deletion or destruction operations to third parties to whom the personal data has been transferred;
• To object to a result arising against the person from analysis of personal data exclusively through automated systems;
• To claim compensation for damages suffered as a result of unlawful processing of personal data.

Requests submitted within this scope shall be concluded as soon as possible depending on the nature of the request and, in any event, no later than thirty days.

14- EXERCISE OF RIGHTS GRANTED UNDER THE LAW

Pursuant to Article 13(1) of the Turkish Personal Data Protection Law, requests relating to the exercise of the rights specified above must be submitted to our Company in writing within the scope of the Communiqué on the Procedures and Principles of Application to the Data Controller, or by using an email address that you have previously notified to our Company and that is registered in our systems.

To exercise the rights specified above, you may submit a petition containing the information necessary to verify your identity and explanations regarding the right or rights you wish to exercise under Article 11 of the Turkish Personal Data Protection Law, together with documents verifying your identity, in person or by post to:

EOSB, 23100 Organize Sanayi Bölgesi, 96. Sk. No:8, 23200 Elazığ Merkez/Elazığ, Türkiye

You may also submit your application by email to the address designated by the Company.

Rights relating to personal data may only be exercised with respect to data belonging to the applicant. Requests concerning data belonging to persons other than the applicant will not be taken into consideration where the required identity verification requirements are not fulfilled.

ENVAPLAS reserves the right to amend this Privacy Notice at any time due to changes arising from the Law, secondary legislation and decisions of the Turkish Personal Data Protection Board. Amendments and the updated text shall become effective as of the date on which they are communicated.

15- COMPLAINT

If your requests submitted to ENVAPLAS are rejected by the Company, if you are dissatisfied with the response provided by the Company, or if no response is provided, you may lodge a complaint with the Turkish Personal Data Protection Board within the periods prescribed under the applicable legislation.

SIGNATURE