KVKK and Information Text
KVKK and Information Text
COMMERCIAL ELECTRONIC MESSAGE CONSENT
INFORMATION AND APPROVAL TEXT
As Hekagro Solutions Tarım Teknoloji Sanayi Ve Ticaret Anonim Şirketi (the "Company"), we respect and value the privacy of private life. Therefore, we would like to inform you within the scope of the Personal Data Protection Law No. 6698 (hereinafter referred to as "KVKK") and the Law on the Regulation of Electronic Commerce.
Your personal information is collected directly from you electronically and processed into our systems through your visits to our website, the explanations contained in links within SMS or emails sent to you, and forms you provide.
By agreeing to this text, which can be found on our website or via a link in an SMS or email sent to you, your personal data, including your identity and contact information (Name, Surname, Date of Birth, Gender, Email address, Telephone information, Address), will be processed by the Company in accordance with the Personal Data Protection Law (KVKK) and the Law on the Regulation of Electronic Commerce, for the purposes of planning and executing marketing processes for our products and services, conducting customer satisfaction surveys, celebrating special occasions, sending newsletters, and sharing campaign and promotional services with you.
Your personal data will be shared with the companies from which we receive service, by taking the necessary security measures to send SMS and E-mail accordingly.
As data subjects, you have the right to: learn whether your personal data is being processed; request information regarding the processing of your personal data if it has been processed; learn the purpose of the processing of your personal data and whether it is being used in accordance with its purpose; know the third parties to whom your personal data has been transferred, domestically or internationally; request the correction of your personal data if it is incomplete or inaccurate, and request that this correction be notified to the third parties to whom your personal data has been transferred; request the deletion or destruction of your personal data if the reasons requiring its processing have ceased to exist, even if it has been processed in accordance with Law No. 6698 and other relevant laws, and request that this action be notified to the third parties to whom your personal data has been transferred; object to a result that is detrimental to you arising from the analysis of your processed data exclusively through automated systems; and demand compensation for damages if you have suffered harm due to the unlawful processing of your personal data.
You can find details in the Personal Data Processing Policy available at www.hekagro.com. If you submit your requests in writing via mail, in person to our company address, or using our registered electronic mail (KEP) address, secure electronic signature, mobile signature, or the email address you previously provided to the Company, we will process your request as soon as possible, and no later than thirty days, depending on the nature of the request.
Best regards;
HEKAGRO SOLUTIONS AGRICULTURAL TECHNOLOGY
INDUSTRY AND TRADE JOINT STOCK COMPANY
PERSONAL DATA STORAGE AND DESTRUCTION POLICY
HEKAGRO SOLUTIONS AGRICULTURAL TECHNOLOGY
INDUSTRY AND TRADE JOINT STOCK COMPANY
PERSONAL DATA STORAGE AND DESTRUCTION POLICY
ARTICLE 1 - PURPOSE
This personal data storage and destruction policy has been prepared to define the procedures and principles regarding the storage and destruction of personal data processed by HEKAGRO SOLUTIONS TARIM TEKNOLOJİ SANAYİ VE TİCARET ANONİM ŞİRKETİ .
ARTICLE 2 - SCOPE
Personal data of company employees, job candidates, interns, product and service buyers, potential customers, partners, visitors, suppliers and other third parties are within the scope of this policy.
This policy applies to all recording environments and personal data processing activities owned or managed by the company.
ARTICLE 3 - DEFINITIONS
Recipient group : The category of natural or legal persons to whom personal data is transferred by the data controller.
Explicit consent : Consent given freely and based on informed knowledge regarding a specific matter.
Anonymization : The process of rendering personal data in such a way that it cannot be linked to an identified or identifiable natural person, even when combined with other data.
Employee : Company staff
Electronic environment : Environments where personal data can be created, read, modified, and written using electronic devices.
Non-electronic media : All written, printed, visual, and other media that are outside of electronic media.
Service provider : A natural or legal person who provides services to the company under a specific contract.
Data subject : The natural person whose personal data is being processed.
Relevant user : Individuals within the data controller organization, or those acting under the authority and instructions of the data controller, who process personal data, excluding the person or unit technically responsible for the storage, protection, and backup of the data.
Destruction : The deletion, destruction, or anonymization of personal data.
Law : Law No. 6698 on the Protection of Personal Data
Recording medium : Any medium containing personal data processed wholly or partly automatically, or by non-automatic means as part of a data recording system.
Personal data : Any information relating to an identified or identifiable natural person.
Personal Data Processing Inventory : An inventory created by data controllers detailing their personal data processing activities related to their business processes; associating these activities with the purposes and legal basis for processing, data category, recipient group, and data subject group; and specifying the maximum retention period for the purposes for which the personal data is processed, the personal data intended to be transferred to foreign countries, and the measures taken regarding data security.
Processing of personal data : Any operation performed on personal data, such as obtaining, recording, storing, keeping, modifying, reorganizing, disclosing, transferring, acquiring, making available, classifying or preventing the use of data, whether wholly or partly automated or non-automated, provided that it is part of a data recording system.
Board : Personal Data Protection Board
Special categories of personal data : Data relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, membership in associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
Periodic destruction : When all the conditions for processing personal data stipulated in the law cease to exist, the process of deletion, destruction, or anonymization of personal data will be carried out automatically at recurring intervals as specified in the personal data retention and destruction policy.
Policy : Personal Data Storage and Destruction Policy
Company: Hekagro Solutions Agricultural Technology Industry and Trade Inc.
Data processor : A natural or legal person who processes personal data on behalf of the data controller, based on the authorization given by the data controller.
Data recording system : A recording system in which personal data is processed by structuring it according to specific criteria.
Data controller : The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.
Data Controllers Registry Information System : An internet-accessible information system created and managed by the Presidency, which data controllers will use for applications to the Registry and other related transactions.
VERBIS : Data Controllers Registry Information System
Regulation : The Regulation on the Deletion, Destruction or Anonymization of Personal Data, published in the Official Gazette dated October 28, 2017.
ARTICLE 4 - RESPONSIBILITIES AND DUTIES
All company employees and departments provide full and active support to responsible departments regarding the lawful collection, processing, and storage of personal data. All employees and departments support responsible departments in implementing administrative and technical measures taken within the scope of the policy, training department employees, ensuring, raising, and monitoring employee awareness, preventing unlawful access to personal data, and maintaining personal data in accordance with the law.
The distribution of titles, units and job descriptions of those involved in the storage and destruction of personal data is shown in ADDITIONAL TABLE: 1.
ARTICLE 5 - RECORDING MEDIUMS
Personal data is kept securely by the company in accordance with the law in the environments listed in ADDITIONAL TABLE: 2.
ARTICLE 6 - LEGAL REASONS REQUIRING STORAGE
Personal data processed within the Company's operations is retained for the period stipulated in relevant legislation and within the scope of the law. The reasons for such retention are as follows:
- Storing personal data because it is directly related to the establishment and execution of contracts,
- Storing personal data for the purpose of establishing, exercising or protecting a right
- It is mandatory to store personal data for the legitimate interests of the company, provided that it does not harm the fundamental rights and freedoms of individuals.
- Storing personal data for the company to fulfill any legal obligations
- Clearly stipulating the storage of personal data in the legislation
- Explicit consent of data owners is required for storage activities that require explicit consent of data owners.
ARTICLE 7 - PROCESSING PURPOSES REQUIRING STORAGE
The Company may process personal data of the relevant person or third parties specified by the relevant person for various purposes, including, but not limited to, the following:
- Carrying out human resources processes
- Ensuring corporate communication
- Ensuring company security
- Ability to conduct statistical studies
- To be able to carry out work and transactions as a result of signed contracts and protocols
- To ensure the fulfillment of legal obligations as required or mandated by legal regulations.
- To contact real/legal persons who have business relations with the company
- Making legal reports
- Managing call center processes
- To fulfill the burden of proof in legal disputes that may arise in the future.
- Executing/following up on company legal affairs
ARTICLE 8 - LEGAL REASONS REQUIRING DESTRUCTION
Personal data is deleted or destroyed by the company upon the request of the relevant person or ex officio in the event of the following situations:
- Amendment or removal of relevant legislative provisions that form the basis for the processing of personal data
- The purpose requiring the processing or storage of personal data disappears
- In cases where personal data processing is carried out only on the basis of explicit consent, the person concerned may withdraw his/her explicit consent.
- Acceptance by the data controller of the application made by the relevant person for the deletion and destruction of his/her personal data within the framework of his/her rights in accordance with Article 11 of the Law.
- The maximum period requiring personal data to be stored has passed and there are no conditions that justify storing personal data for a longer period of time.
ARTICLE 9 - TECHNICAL MEASURES
The technical measures taken by the Company regarding the personal data it processes are as follows:
- Performs necessary internal controls within the scope of established systems.
- Conducts the processes of information technology risk assessment and business impact analysis within the scope of the established systems.
- It ensures the provision of technical infrastructure and the creation of relevant matrices that will prevent or monitor data leakage outside the company.
- It ensures control of system vulnerabilities by taking penetration testing services regularly and when needed.
- Ensures that employees' access to personal data in information technology units is kept under control.
- Personal data is destroyed in a way that is irreversible and leaves no audit trail.
- Pursuant to Article 12 of the Law, all digital media where personal data is stored are protected by encrypted or cryptographic methods to ensure information security requirements.
ARTICLE 10 - ADMINISTRATIVE MEASURES
The administrative measures taken by the Company regarding the personal data it processes are as follows:
- Internal access to stored personal data is restricted to personnel whose job description requires access. The sensitive nature of the data and its importance are also taken into account when limiting access.
- If the processed personal data is obtained by others through illegal means, this situation is reported to the relevant person and the Board as soon as possible.
- Regarding the sharing of personal data, it signs a framework agreement regarding the protection of personal data and data security with the persons with whom personal data is shared, or ensures data security with provisions added to its existing agreement.
- It employs personnel who are knowledgeable and experienced about the processing of personal data and provides its personnel with the necessary training within the scope of personal data protection legislation and data security.
- It conducts and has conducted necessary audits to ensure the implementation of the provisions of the Law within its own legal entity. It resolves any confidentiality and security vulnerabilities uncovered as a result of audits.
ARTICLE 11 - METHODS OF DELETION OF PERSONAL DATA
Personal data is deleted using the methods specified in ADDITIONAL TABLE: 3.
ARTICLE 12 - METHODS OF DESTRUCTION OF PERSONAL DATA
Personal data is destroyed by the methods specified in ADDITIONAL TABLE: 4.
ARTICLE 13 - STORAGE AND DESTRUCTION PERIODS
When determining the retention period for personal data, the Company shall, first of all, comply with any period stipulated in legal regulations for the retention of such personal data. Regarding personal data processed by the Company within the scope of its activities:
- The retention periods for all personal data within the scope of activities carried out in connection with the processes are listed in the Personal Data Processing Inventory;
- Retention periods based on data categories are determined during registration with VERBIS;
- Retention periods on a process basis are included in ADDITIONAL TABLE: 5 in the Personal Data Retention and Destruction Policy.
ARTICLE 14 - PERIODIC DESTRUCTION PERIOD
The company carries out periodic destruction operations in June and December every year.
ARTICLE 15 - PUBLICATION, STORAGE AND UPDATING OF THE POLICY
The policy is published in two formats: ink-signed (printed) and electronically, and is posted to the public on the company's website. The printed copy is kept within the company. The policy is reviewed and necessary sections are updated as needed.
ARTICLE 16 - ENFORCEMENT
The policy is deemed effective upon publication on the company's website. If a decision is made to revoke it, the old, wet-signed copies of the policy must be cancelled (either by stamping the cancellation stamp or by writing the cancellation) and kept by the company for at least five years.
ADDITIONAL TABLE: 1 Storage and destruction processes task distribution
| TITLE | UNIT OF | RESPONSIBILITY |
| CEO | Hekagro Solutions Agriculture Technology Industry and Trade Inc. | Responsible for employees to comply with the policy. |
| Human Resources Manager | Human Resources | Responsible for executing the policy, publishing it in relevant media and updating it. |
| Finance director | Financial Affairs | Responsible for the execution of policy in accordance with their duties. |
ADDITIONAL TABLE: 2 Personal Data Storage Environments
| Electronic Media | Non-Electronic Media |
| -Servers (Domain, backup, email, database, web, file sharing, etc.)
-Software (Microsoft Office, Outlook, Tiger Logo, Bordro Plus, VERBIS, etc.) -Information security devices (firewall, intrusion detection and prevention, log file, antivirus, etc.) -Personal computers (Desktop, laptop) -Mobile Devices (Phone, Tablet, etc.) -Optical discs (CD, DVD, etc.) -Removable and portable memories (USB etc.) -Printers, scanners, photocopiers |
– Papers
– Written and printed media – Visual records – Manual data recording systems |
ADDITIONAL TABLE: 3 Methods of Deletion of Personal Data
| Data Recording Environment | Deletion Method |
| Servers | For personal data on the servers whose retention period has expired, the system administrator removes the access authorization of the relevant users and deletes them. |
| Electronic media | Among the personal data in the electronic environment, those whose period of storage has expired are made inaccessible and unusable for other employees (relevant users) except the database administrator. |
| Physical environment | Personal data kept in physical environment, for those whose period of storage has expired, are made inaccessible and unusable by all employees except the unit manager responsible for the document archive. In addition, blackening is also applied by drawing/painting/erasing the surface so that it cannot be read. |
| Removable media | Among the personal data kept in flash-based storage media, those that have expired are stored in secure environments with encryption keys, by being encrypted by the system administrator and access authorization is given only to the system administrator. |
ADDITIONAL TABLE: 4 Methods of Destroying Personal Data
| Data Recording Environment | Destruction Method |
| Physical environment | Personal data in paper form, whose storage period has expired, is destroyed irreversibly in document shredders. |
| Optical or magnetic media | Personal data on optical and magnetic media that have expired are physically destroyed by melting, burning, or pulverizing them. Furthermore, magnetic media is subjected to a special device and subjected to a high magnetic field, rendering the data on it unreadable. |
ADDITIONAL TABLE: 5 Storage and Destruction Period Table
| PROCESS | STORAGE PERIOD | DESTRUCTION PERIOD |
| Company Transactions | 10 Years | During the first periodic destruction period following the end of the storage period |
| Contract Processes | 10 years following the termination of the contract | During the first periodic destruction period following the end of the storage period |
| Execution of Communication Activities | 10 years following the end of the activity | During the first periodic destruction period following the end of the storage period |
| Human Resources Processes | 10 years following the end of the employment relationship | During the first periodic destruction period following the end of the storage period |
| Occupational Health and Safety Processes | 10 years following the end of the employment relationship | During the first periodic destruction period following the end of the storage period |
| Responding to personnel court/courthouse requests | 10 years following the end of the employment relationship | During the first periodic destruction period following the end of the storage period |
| Execution of Application Processes of Employee Candidates | 2 years following the application date | During the first periodic destruction period following the end of the storage period |
| Filing of education records | 10 years following the organization of the training | During the first periodic destruction period following the end of the storage period |
| Sales and Marketing Processes | 10 years following the end of the activity | During the first periodic destruction period following the end of the storage period |
| Purchasing Processes | 10 years following the end of the activity | During the first periodic destruction period following the end of the storage period |
| Execution of Accounting Transactions | 10 years following the end of the activity | During the first periodic destruction period following the end of the storage period |
| Banking Transactions | 10 years following the end of the activity | During the first periodic destruction period following the end of the storage period |
| Execution of Stock Control and Logistics Activities | 10 years following the end of the activity | During the first periodic destruction period following the end of the storage period |
| Carrying out customs activities | 10 years following the end of the activity | During the first periodic destruction period following the end of the storage period |
| Planning Domestic and International Travel Organizations | 10 years following the end of the activity | During the first periodic destruction period following the end of the storage period |
| Recording of Meeting Records and Participants | 2 Years following the end of the event | During the first periodic destruction period following the end of the storage period |
| Log Record Tracking Systems | 10 Years | During the first periodic destruction period following the end of the storage period |
| Execution of Hardware and Software Access Processes | 2 Year | During the first periodic destruction period following the end of the storage period |
| Camera Recordings | 1 Year | During the first periodic destruction period following the end of the storage period |
| Vehicle tracking | xnumxyıl | During the first periodic destruction period following the end of the storage period |


