Gürok Turizm ve Madencilik A.Ş., which was incorporated as a joint stock company pursuant to the Turkish Commercial Code No. 6102 (hereinafter referred to as "Gürok") and acting as a data controller, aims to fully comply with all kinds of legal regulations regarding the protection and lawful processing of personal data.
The purpose of this Personal Data Storage and Destruction Policy ("the Policy"), which is prepared within the scope of Article 16 of the Law on Protection of Personal Data No. 6698 and Article 5 of the Regulation on the Deletion, Destruction or Anonymization of Personal Data, is to determine the required storage periods and the minimum standards to be regarded in the destruction of personal data which is processed by Gürok and belong to customers purchasing/receiving products and services, employees, employee candidates and other third parties.
This Policy provides the basis for determining the maximum time required for the processing of data by data controller, Gürok, in line with the purpose of processing as well as for deleting, destroying and anonymizing the data.
This Policy will apply to all business units, processes and business relationships with other third parties.
This Policy will apply to all Company executives, employees, consultants, service providers or service providers that may collect, process or access data (including personal data and/or qualified personal data).
This Policy will apply to all personal data and information collected by the Company.
Electronic and non-electronic recording media and/or documents where personal data covered by this Policy are stored are as follows:
The terms in this Policy will have the meanings ascribed to them below.
| Term | Definition |
|---|---|
| Recipient Group | The category of natural or legal persons to whom personal data is transferred by the data controller. |
| Explicit Consent | Consent to a specific subject, based on information and explained with free will. |
| Anonymization | Making the personal data unfeasible to be matched with an identified or identifiable real person's personal data. |
| Data Subject | Real person whose personal data is processed. |
| Data Processor | Persons who process personal data within the organization of the data controller or in accordance with the authorization and instruction received from the data controller except for the person or unit responsible for the technical storage, protection and backup of the data. |
| Destruction | Deleting, destroying or anonymizing personal data. |
| Law or PPD Law | Law No. 6698 on Protection of Personal Data. |
| Storage Media | Any medium where personal data processed by non-automated means are stored provided that they are fully or partially automated or as part of any data recording system. |
| Personal Data | Any information about an identified or identifiable real person. |
| Personal Data Processing Inventory | Inventory created associated to the personal data processing purposes, the data category, the recipient group transferred, and the data subject group in which data officers detail their personal data processing activities in line with their business processes by explaining the maximum time required for the purposes for which the personal data are processed, the personal data foreseen to be transferred to foreign countries and the measures taken regarding data security. |
| Processing of Personal Data | Any action put into practice on the personal data such as the acquisition, recording, storage, retention, modification, reorganization, disclosure, transfer, acquisition, availability, classification or prevention of personal data by fully or partially automated means or by non-automated means provided that they are part of any data recording system. |
| Board | Personal Data Protection Board. |
| Authority | Personal Data Protection Authority. |
| Qualified Personal Data | Information related with individuals' race, ethnicity, political thought, philosophical belief, religion, sect or other beliefs, disguise and outfit, association, foundation or union membership, health status, sexual life, criminal conviction records and security measures as well as their biometric and genetic data. |
| Periodic Destruction | It is the process of ex-officio and recurrently deleting, destroying or anonymizing the personal data in the event that all the conditions specified in the policy requiring the processing, storing and destroying of personal data in the law cease. |
| Company or Gürok | Gürok Turizm ve Madencilik Anonim Şirketi. |
| Data Processor | Real or legal person who processes personal data on his/her behalf based on the authority provided by the data controller. |
| Data Registration System | Registration system in which personal data is processed in accordance with certain criteria. |
| Data Controller | Real or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data registration system. |
| Data Controller Registry Information System (VERBİS) | Information system which can be accessed over the internet that is created and managed by the Authority to be used in applying for and other transactions related to the registry. |
| Regulation | Regulation on the Deletion, Destruction or Anonymization of Personal Data dated 28 October 2017. |
The company defines and updates the relevant storage period for documents and electronic records that should be stored during the personal data storage period pursuant to the Storage and Destruction Period Table