Logo
MEYİS OTOMOTİV
Personal Data Protection Policy

Personal Data Protection Policy

Meyis Automotive Seat Components Industry and Trade Ltd. Co. As the Company, we attach utmost importance to the legal protection and processing of personal data in accordance with Law No. 6698 on the Protection of Personal Data (the "Law") and act with this care in all our planning and operations. As a Company, we take all administrative and technical measures in compliance with the legislation regarding the protection and processing of personal data, which is the foundation of the right to privacy.


With the Personal Data Protection and Processing Notice ("Notice"), we aim to ensure compliance with applicable national and international legislation, particularly Law No. 6698 on the Protection of Personal Data (the "Law") and the European Union General Data Protection Regulation ("GDPR"). Detailed information on the protection and processing of personal data under the GDPR can be found at https://www.meyis.com.tr.


The purpose of the Personal Data Protection and Processing Policy ("Policy") is to protect the fundamental rights and freedoms of individuals, particularly the right to privacy regulated in Article 20 of the Constitution, in the protection and processing of personal data in accordance with the purpose of the Law, and to fulfill our Company's obligations. The purpose of this policy is to inform Personal Data Subjects about the procedures and principles to be followed pursuant to the Law. The aim of this policy is to ensure full compliance with legislation in the protection and processing of Personal Data carried out by our Company and to protect the right of Personal Data Subjects to privacy and data security.


To ensure the security of the personal data of our customers, suppliers, employees, and guests, we share our customers' data only with our trusted business partners, at a minimum level, and implement security measures in accordance with applicable legislation to ensure the safe storage of personal data and to prevent any unlawful access or leakage of this data.


1. DEFINITIONS


Explicit consent: This refers to the declaration of consent regarding a specific subject, based on informed consent, and freely given by data subjects.


Anonymization: This refers to the process of rendering personal data incapable of being associated with an identified or identifiable natural person, even when matched with other data.

Relevant person/data subject: This refers to the natural person whose personal data is being processed.

Personal data: This refers to an identified or identifiable natural person. This refers to any information related to your data.

Special personal data: This refers to data subject to a more stringent protection regime under the Law, which may cause the Data Subject to be victimized or discriminated against in the event of disclosure or loss.

Processing of personal data: This refers to any operation performed on personal data, such as obtaining, recording, storing, preserving, altering, reorganizing, disclosing, transferring, acquiring, making available, classifying, or preventing the use of personal data, whether fully or partially by automatic means, or non-automatic means provided that it is part of any data recording system.

Data recording system: This refers to a recording system in which personal data is structured and processed according to specific criteria.

Data controller: This refers to the natural or legal person responsible for determining the purposes and means of processing personal data and for establishing and managing the data recording system.


2. PERSONAL DATA PROTECTION


Our company, in accordance with the Law, implements appropriate procedures to prevent unlawful processing and access of personal data and to ensure the safeguarding of personal data. We take all necessary technical and administrative measures to ensure the level of security. Our Company respects all legal rights of Personal Data Subjects through the implementation of the Policy and Law, and takes all necessary measures to protect these rights.


Our Company conducts and has the necessary audits carried out to ensure the establishment of data security described above and the regularity and continuity of the measures taken.


Our Company takes all necessary technical and administrative measures, taking into account technological possibilities and implementation costs, to ensure that relevant data controllers and data processors do not disclose their Personal Data to others in violation of the Law and Policy, or use it for purposes other than those intended. In this context, we conduct information and training programs regarding the Law and Policy with our Company employees.


If Personal Data processed by our Company is obtained by others through unlawful means, our Company takes the necessary steps to notify the relevant Personal Data Subject and the Personal Data Protection Board as soon as possible.


If deemed necessary by the Personal Data Protection Board, this may be announced on the Personal Data Protection Board's website or by another method deemed appropriate by the Board.


Our Company considers that Special Personal Data constitutes data that could cause the data subject to victimization or discrimination if learned by others. Therefore, all necessary measures are meticulously taken to protect such personal data processed in accordance with the law.


3. PROCESSING AND TRANSFER OF PERSONAL DATA


Our Company ensures that the processed Personal Data is suitable for the achievement of the specified purposes and avoids processing Personal Data that is not relevant or needed to achieve the purpose. Our Company limits the data processed to only what is necessary to achieve the purpose.


Our Company processes Personal Data in accordance with the procedures and principles stipulated in the Law and this Policy. Our Company processes and uses Personal Data in accordance with relevant legislation and the requirements of the principle of integrity. Our Company clearly and precisely determines the purpose of data processing.


If relevant legislation stipulates a data retention period, our Company complies with these periods; otherwise, it retains Personal Data only for the period necessary for the purpose for which it is processed. The retention periods for processed data are specified in our policies. If there is no valid reason for our Company to retain Personal Data any longer, or upon the request of the person whose data was collected, the data in question will be deleted, destroyed, or anonymized.


Our Company does not process Personal Data without the explicit consent of the data subject. Our Company may process Personal Data without the explicit consent of the data subject if one of the following conditions exists. Our Company may process Personal Data of Personal Data Subjects even without explicit consent, in cases expressly stipulated by law. Our Company may process Personal Data of Personal Data Subjects if it is necessary to fulfill its legal obligations as a data controller.


Our Company may process Personal Data for commercial purposes related to the establishment or performance of a contract.


Our Company may transfer Personal Data and Special Personal Data of Personal Data Owners to third parties specified in this protocol in accordance with the Law, by establishing the necessary confidentiality conditions and taking security measures in accordance with the purposes for which Personal Data is processed.


If the Personal Data Owner has given explicit consent;

If there is a clear regulation in the law stipulating that Personal Data will be transferred;

If it is necessary to protect the life or physical integrity of the Personal Data Owner or another person, and the Personal Data Owner is unable to give their consent due to a physical impossibility, or if their consent is not legally valid;

If the transfer of Personal Data belonging to the parties to a contract is necessary, provided that it is directly related to the establishment or performance of a contract;

If the transfer of Personal Data is necessary for our Company to fulfill its legal obligation;

If the Personal Data has been made public by the Personal Data Owner;

If the transfer of Personal Data is necessary for the establishment, exercise, or protection of a right;

If the transfer of Personal Data is necessary for the legitimate interests of our Company, provided that it does not prejudice the fundamental rights and freedoms of the Personal Data Owner.


Our Company may transfer Personal Data and Special Personal Data of Data Subjects to third parties abroad by taking the necessary security measures in line with the purposes for which we process Personal Data. Our Company may transfer Personal Data to foreign countries declared by the Personal Data Protection Board to have adequate protection, or, if insufficient protection is not provided, to foreign countries where the data controllers in Turkey and the relevant foreign country have undertaken, in writing, to provide adequate protection and where the Personal Data Protection Board has granted its consent.


4. CLASSIFICATION OF PERSONAL DATA, PURPOSES OF PROCESSING AND TRANSFER, AND PERSONS TO WHOM IT WILL BE TRANSFERRED


4.1. Types of Personal Data:


Identity (such as name and surname, mother-father's name, mother's maiden name, date of birth, place of birth, marital status, identity card serial number, Turkish ID number), communication (such as address number, e-mail address, contact address, registered electronic mail address (Keep), telephone number), location (location information of the place where the person is located), personnel (such as payroll information, disciplinary investigation, employment entry and exit document records, asset declaration information, CV information, performance evaluation reports), legal proceedings (such as information in correspondence with judicial authorities, information in the case file), customer transactions (such as call center records, invoices, promissory notes, check information, information on counter receipts, order information, request information), physical location security (such as employee and visitor entry and exit record information, camera recordings), finance (such as balance sheet information, financial performance information, credit and risk information, asset information), professional experience (such as diploma information, courses attended, in-service training information, certificates, transcript information), marketing (such as shopping history information, surveys, cookie records, campaigns). We collect data such as visual and audio recordings (such as visual and audio recordings, camera recordings, and photographs), appearance and dress (information regarding appearance and dress), association membership (such as association membership information), foundation membership (such as foundation membership information), union membership (such as union membership information), health information (such as disability status information, blood type information, personal health information, device and prosthesis information), criminal convictions and security measures (such as information regarding criminal convictions and security measures), and biometric data (such as palm print information, fingerprint information, retina scan information, facial recognition information) for the purposes specified in this protocol.


Identity Information


Data containing information regarding the individual's identity: name and surname, Turkish ID number, ID number, marital status, nationality, parents' name and surname, place and date of birth, gender, and other identification information, including driver's license, identity card, passport, and other documents containing this information, as well as tax number, social security number, signature information, vehicle license plate, and other information.


Contact Information


Phone number, address, email address, fax number, IP address, and other information.


Transaction Security Information


Personal data processed regarding the technical, administrative, legal, and commercial security of both the Personal Data Subject and the Company while conducting the Company's activities.


Financial Information


Personal data processed regarding information, documents, and records showing all financial outcomes arising from the employer-employee relationship established by the Company with the Relevant Person, as well as bank account number, branch code, debit card information, IBAN number, credit card information, financial profile, credit score, asset data, income information, and other information.


Visual and Audio Information


Photographs, camera recordings, audio recordings, and any other data and other information containing such data


Personal Information


All personal data processed to obtain information that will form the basis for protecting the personal rights of individuals who have a working relationship with the Personal Data Subject


Location Information


Information that determines the location of the Data Subject while the Data Subject is using the Company's or its group companies' vehicles within the scope of the activities and operations of the Company, its group companies, or collaborating companies and institutions; GPS location, travel data, and other information


Family Members and Relatives Information


Identity and contact information, as defined above, regarding the Relevant Person's family members (e.g., spouse, mother, father, child), relatives, and other persons who can be reached in an emergency, within the scope of the activities and operations of the Company, its group companies, or collaborating companies and institutions, or to protect the legal and other interests of the Company and the Relevant Person.


Physical Location Security Information


Personal data related to records and documents obtained upon entering the physical location and during the stay at the physical location; Camera recordings, fingerprint records, security checkpoint recordings, and other data


Legal Transaction Information


Data processed for the determination and pursuit of the Company's legal receivables and rights, the fulfillment of its debts, and its legal obligations


Special Personal Information


Data specified in Article 6 of the Law (health data, biometric data, religious affiliation and association membership information, and other information)


Request/Complaint Management Information


Personal data related to the receipt and evaluation of requests or complaints submitted to our Company


Purposes of Processing Personal Data


Your personal data is used for the optimal planning and implementation of our human resources policies, the accurate planning and execution of our commercial partnerships and strategies.


5. RIGHTS OF THE PERSONAL DATA SUBJECT


According to Article 11 of the Law, data subjects have the following rights against the data controller:


To learn whether personal data concerning them has been processed.

To request information if personal data concerning them has been processed.

To learn the purpose of processing personal data and whether it is being used in accordance with its intended purpose.

To know the third parties to whom personal data has been transferred, whether domestically or internationally.

To request correction of personal data if it has been processed incompletely or inaccurately.

To request the deletion or destruction of personal data within the framework of the conditions stipulated in relevant legislation.

To request notification of actions taken as a result of requests for correction, deletion, or destruction to third parties to whom personal data has been transferred.

To object to any consequences detrimental to the data subject arising from the analysis of processed data, exclusively through automated systems.

To request compensation for damages suffered due to unlawful processing of personal data.

We will respond to data subjects who wish to exercise these rights within the limits stipulated in the Law, within a maximum of thirty days, as stipulated by the Law. For third parties to submit an application on your behalf, you must have a special power of attorney issued through a notary public in the name of the applicant.


While your applications are generally processed free of charge, if the Personal Data Protection Board specifies a fee schedule, a fee may be charged according to this schedule. We may request information from the applicant to determine whether they are the Data Subject and may ask the Data Subject questions regarding their application to clarify the matters specified in the application.


To exercise the aforementioned rights, you can contact us via the contact information on our website.


6. EXCEPTIONS


Personal data is processed by individuals solely for activities related to themselves or their family members living in the same residence, provided that it is not disclosed to third parties and that data security obligations are complied with.

Personal data is processed for purposes such as research, planning, and statistics, after being anonymized by official statistics. Processing of personal data for artistic, historical, literary, or scientific purposes, or within the scope of freedom of expression, provided that it does not violate national defense, national security, public safety, public order, economic security, privacy of private life, or personal rights, or constitutes a crime.


Processing of personal data within the scope of preventive, protective, and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public safety, public order, or economic security.


The provisions of this Policy and the Law do not apply if personal data is processed by judicial authorities or enforcement authorities in connection with investigations, prosecutions, trials, or executions.


The processing of personal data is necessary for the prevention of crimes or for criminal investigations.

The processing of personal data made public by the relevant person.

The processing of personal data is necessary for the performance of supervisory or regulatory duties, or for disciplinary investigations or prosecutions, by authorized public institutions and organizations or professional organizations qualified as public institutions, based on the authority granted by law. In cases where personal data processing is necessary to protect the economic and financial interests of the State regarding budget, tax and financial matters, Articles 10, 11 and 16 of the relevant law do not apply.


7. DATA SECURITY [MOU1]


To ensure the security of your personal data, we take reasonable technical and administrative measures to prevent the risks of unauthorized access, accidental data loss, and deliberate deletion or damage to data.


In order to take administrative and technical measures in our company, network security and application security are ensured. A closed system network is used for personal data transfers via the network. Key management is implemented. Security measures are taken within the scope of information technology systems procurement, development, and maintenance. The security of personal data stored in the cloud is ensured. Disciplinary regulations that include data security provisions are in place for employees. Training and awareness campaigns are conducted periodically for employees on data security. An authorization matrix is ​​created for employees. Access logs are kept regularly. Corporate policies on access, information security, usage, storage, and destruction are prepared and implemented. Data masking measures are implemented when necessary. Confidentiality commitments are signed. Authorizations in this area are revoked for employees who change their duties or leave their jobs. Up-to-date anti-virus systems are used. Firewalls are used. Signed contracts include data security provisions. Extra security measures are taken for personal data transferred via paper, and relevant documents are sent in a confidential document format. Personal data security policies and procedures are established. Personal data security issues are reported quickly. Personal data security is monitored. Necessary security measures are taken regarding entry and exit, Physical environments containing personal data are secured against external risks (fire, flood, etc.), The security of environments containing personal data is ensured, Personal data is reduced as much as possible, Personal data is backed up, and the security of backed up personal data is also ensured, User account management and authorization control systems are implemented and monitored, periodic and/or random inspectors are conducted and ordered, Log records are kept in a way that prevents user intervention, Existing risks and threats are identified, Protocols and procedures for the security of special personal data have been determined and implemented, If special personal data is to be sent via electronic mail, it is sent encrypted and using a KEP or corporate mail account, Secure encryption/cryptographic keys are used for special personal data and are managed by different units, Intrusion detection and prevention systems are used, Penetration testing is implemented, Cybersecurity measures have been taken, and their implementation is continuously monitored, Encryption is performed, Special personal data transferred on portable memory, CD, or DVD is transferred encrypted, Data processing service providers are audited at regular intervals regarding data security. Data processing service providers are made aware of data security, and data loss prevention software is used.


We ensure data security by using software and hardware that include virus and similar malware protection systems, firewalls, and intrusion prevention systems.

Within the partnership, we manage access to personal data through a controlled process, based on authorizations by unit/role/application and appropriate to the nature of the data.

In accordance with Article 12 of the Law, we ensure that the necessary audits are conducted to ensure the implementation of the provisions of the Law.

We ensure compliance with the Law on data processing activities through internal policies and procedures.

We subject access to sensitive personal data to stricter measures.

In cases where personal data is accessed externally, such as through outsourcing, we obtain commitments from the external service provider to ensure compliance with the Law.

We take the necessary actions to inform all our employees, especially those authorized to access personal data, about their duties and responsibilities under the Law.