Privacy Policy

“DMS SAVUNMA SANAYİ VE OTOMOTİV TİC. A.Ş.”

PERSONAL DATA PROCESSING AND PROTECTION POLICY

 

TABLE OF CONTENTS

  1. SCOPE……………………………………………………………………………………………………...2
  2. DEFINITIONS AND ABBREVIATIONS………………………………………………………………………….2
  3. OUR POLICY…………………………………………………………………………………….………….3
  1. PERSONAL DATA…………………………………….……………………………………….…………3
  1. General Principles in the Processing of Personal Data………………………………………………......3
  2. Data Processed by the Company….…………………….…………………………………......3
  3. Purposes of Processing Personal Data……………………………………………………………..4
  4. Transfer of Personal Data Within and Outside of Turkey…………………………………………..5
  5. Method of Collecting Personal Data…………………………………………………………...7
  6. Method of Storage and Destruction of Personal Data…………………………………………………7
  7. Security and Auditing of Personal Data………………………………………………………8
  8. Measures We Take…………………………………….………………………………………..8
  9. Rights of the Data Subject…………………………………….……………………………………..9
  1. OTHER PROVISIONS…………………………………….…………………………………………10
  2. ENFORCEMENT……………………………………………………………………………………...10

 

  1. SCOPE

The Personal Data Protection Law No. 6698 (KVKK) entered into force by being published in the Official Gazette dated April 7, 2016, and numbered 29677. Its purpose is to protect the fundamental rights and freedoms of real persons whose personal data are processed, including the privacy of private life, and to determine the obligations of real and legal persons who process personal data.

The purpose of this Policy is; as the data controller, to establish management instructions, procedural requirements, and a technical policy to ensure that the personal data belonging to relevant persons are processed and protected by DMS SAVUNMA SANAYİ VE OTOMOTİV TİC. A.Ş. (“DMS SAVUNMA”) in compliance with the KVKK. At the same time, this policy is applied to and prepared within this scope for all activities carried out regarding the processing and protection of all personal data held by “DMS SAVUNMA”.

  1. DEFINITIONS AND ABBREVIATIONS
  • Personal Data: Any information relating to an identified or identifiable real person.
  • Processing of Personal Data: Any operation performed on data such as obtaining, recording, storing, retaining, altering, re-arranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of personal data, fully or partially by automated means or by non-automated means provided that it forms part of any data recording system.
  • Data Recording System: The recording system where personal data are structured and processed according to specific criteria.
  • Anonymization: Rendering personal data impossible to be associated with an identified or identifiable real person in any way, even by matching with other data.
  • Data Subject: The real person whose personal data is processed.
  • Data Controller: The real or legal person who determines the purposes and means of processing personal data and manages the place where data is kept systematically (VERBİS).
  • Explicit Consent: Consent regarding a specific subject, based on information and expressed with free will.
  • Storage Period: The period during which personal data is stored by the data controller in accordance with the law.
  • Destruction: The process of making personal data irreversibly inaccessible/destroyed by the data controller after the storage period prescribed by law expires.
  • Application Form: The form containing the application to be made by the data subject to the data controller to exercise their rights within the framework of the relevant legislation.
  • Website:The website belonging to DMS SAVUNMA SANAYİ VE OTOMOTİV TİC. A.Ş. (“DMS SAVUNMA”) located at the addresswww.dmsgroup.com.tr.
  • DMS SAVUNMA SANAYİ VE OTOMOTİV TİC. A.Ş.: DMS SAVUNMA, Our Firm, Our Company, Production area.
  • KVKK: Personal Data Protection Law No. 6698.
  • KVKK Board: The Personal Data Protection Board.
  • Authority: The Personal Data Protection Authority.
  • Policy: DMS SAVUNMA Personal Data Protection and Processing Policy.
  • Visitor: Real persons who have entered the physical areas owned by our Company for various purposes or who visit our websites.

 

 

 

  1. OUR POLICY
  1. PERSONAL DATA

Within the framework of KVKK Art. 3/I(d), “personal data” refers to any information relating to an identified or identifiable real person. In this context, anonymous information, anonymized information, and other data that cannot be associated with a specific person are not considered personal data under this Policy.

  1. GENERAL PRINCIPLES IN THE PROCESSING OF PERSONAL DATA

The processing of personal data; within the framework of KVKK Art. 3/I(e), covers any operation performed on personal data such as obtaining, recording, storing, retaining, altering, re-arranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of personal data, fully or partially by automated means or by non-automated means provided that it forms part of any data recording system, and falls under the scope of "data processing".

Personal data are processed by DMS SAVUNMA in accordance with the general principles specified in Article 4 of the KVKK, as listed below:

  1. Compliance with the law and rules of honesty,
  2. Being accurate and, where necessary, up-to-date,
  3. Being processed for specific, explicit, and legitimate purposes,
  4. Being relevant, limited, and proportionate to the purposes for which they are processed,
  5. Being retained for the period prescribed in the relevant legislation or necessary for the purpose for which they are processed.

In this context, DMS SAVUNMA;

As the Data Controller, personal data obtained through any channel in written, verbal, or electronic format within the scope of KVKK and other legislation may be obtained, recorded, stored, deposited, maintained, or modified in the forms provided by the lawmaker in the KVKK.

In addition, DMS SAVUNMA SANAYİ VE OTOMOTİV TİC. A.Ş. notes that according to the second paragraph of Article 5 of the Personal Data Protection Law, personal data shall not be transferred abroad without the explicit consent of the data subject. However, provided that adequate precautions specified in the law are taken, and in the presence of one of the conditions stated in the third paragraph of Article 6, it may be transferred without seeking the explicit consent of the data subject. Personal data may be transferred to foreign countries declared to have adequate protection by the KVK Board (Foreign Country with Adequate Protection) or, in the absence of adequate protection, to foreign countries where the data controllers in Turkey and the respective foreign country commit to adequate protection in writing and have the permission of the KVK Board “Foreign Country Where the Data Controller Committing to Adequate Protection is Located”. Transfer processes operate according to the regulations stipulated in Article 9 of the Personal Data Protection Law.

  1. DATA PROCESSED BY DMS SAVUNMA SANAYİ VE OTOMOTİV TİC. A.Ş.
  • Identity Information: Turkish Identity Number (TCKN), Passport No, name-surname, signature, photograph, place of birth, date of birth.
  • Contact Information: Persons' e-mail, phone number, mobile phone.
  • Personnel Information: Payroll information, disciplinary investigation, employment entry-exit document records, property declaration information, CV information, performance evaluation reports, SGK entry declarations, company title, tax registration and identity number, chamber registration number, reference information.
  • Legal Transaction Information: Information in correspondence with judicial authorities, information in the lawsuit file (enforcement information).
  • Physical Space Security Information: Entry and exit log information of employees and visitors, camera records.
  • Financial Information: Balance sheet information, financial performance information, salary payrolls, IBAN information, payment amount, credit card and debit card information, refund amount information, debt information.
  • Professional Experience Information: Diploma information, attended courses, in-service training information, certificates, transcript information.
  • Visual and Audio Records Information: Voice recording, captured camera footage.
  • Health Information: Blood type information of personnel and information specified in health reports submitted to our company.

 

  1. PURPOSES OF PROCESSING PERSONAL DATA

DMS SAVUNMA may process personal data for the purposes stated below and may retain them for the duration required by these purposes:

  • Execution of Emergency Management Processes: Such as ensuring communication between units and institutions in case of potential emergencies;
  • Fulfillment of Obligations Arising from Employment Contracts and Legislation for Employees: Such as keeping personnel files of our employees as a legal obligation, preventing uninsured employment;
  • Execution of Fringe Benefits and Benefits Processes for Employees: Such as employees benefiting from health services, bonus, premium payments;
  • Execution of Training Activities: Such as conducting training processes provided to personnel;
  • Execution of Access Authorizations: Such as providing access to the internet;
  • Execution of Activities in Compliance with Legislation: Such as complying with legal regulations like the Labor Law, Occupational Health and Safety Law, Law No. 5651, KVKK No. 6698, and other legislations;
  • Execution of Finance and Accounting Affairs: Such as payment of expenses, submission of monthly and annual legal tax returns, payment of employees' wages, all kinds of accounting inputs and outputs;
  • Ensuring Physical Space Security: Such as controlling the entry-exit hours of customers and employees (taken only in common areas);
  • Follow-up and Execution of Legal Affairs: Such as enabling individuals and the Company to protect themselves in potential lawsuits;
  • Execution of Internal Audit/Investigation/Intelligence Activities: Such as ensuring the safety of used vehicles and individuals, implementing decisions to be taken by the company;
  • Execution of Communication Activities: Such as sending e-mails, contacting via telephone;
  • Planning of Human Resources Processes: Evaluation of incoming job applications;
  • Execution of Occupational Health/Safety Activities: Conducting activities in accordance with the Occupational Health and Safety Law No. 6331 and the Social Insurance and General Health Insurance Law No. 5510;
  • Providing Information to Authorized Persons, Institutions, and Organizations: Such as responding to writs/letters from official institutions and courts;
  • Execution of Storage and Archive Activities: Execution of processes for storing and archiving data that the Company is obliged to keep in accordance with the law and for the required period;
  • Execution of Contract Processes: Creation of supplier and sales contracts, receiving fees from real persons receiving service;
  • Execution of Management Activities: Use of data in the management processes of the Company, appointment planning;
  • Evaluation of Job Applications of Employee/Intern Candidates, Conducting Interviews and Meetings: Such as contacting persons listed as references in their CVs;
  • For the Purpose of Fulfilling Tax Obligations

 

  • Cases Where Personal Data May Be Processed Without Explicit Consent in Accordance with KVKK:

In accordance with Article 5 of the KVKK and Article 7 of the Regulation, your Personal Data may be processed without seeking your explicit consent in the following cases:

• Where clearly prescribed by law,

• Where it is mandatory to process personal data to protect the life or bodily integrity of yourself or another person when you are unable to express your consent due to actual impossibility or when your consent is not granted legal validity,

• Provided that it is directly related to the establishment or performance of a contract, where it is necessary to process the Personal Data of the parties to the contract,

• Where it is mandatory to fulfill a legal obligation,

• Where your Personal Data has been made public by yourself,

• Where data processing is mandatory for the establishment, exercise, or protection of a right,

• Provided that it does not harm your fundamental rights and freedoms, where data processing is mandatory for the legitimate interests of DOĞANER MAKİNA.

 

TRANSFER OF PERSONAL DATA

Personal data may be transferred by our company to third parties in Turkey and abroad, and processed and stored on servers or other electronic media located in Turkey and abroad, in accordance with the processing conditions specified in Articles 8 and 9 of the KVKK, in line with our purposes stated in this policy, and by taking necessary security measures. The third parties to whom personal data can be transferred may vary depending on various factors, such as the type and nature of the relationship between the data subject and DOĞANER MAKİNA (customer-company or business relationship, etc.), but generally are as follows:

  1. DMS SAVUNMA SANAYİ VE OTOMOTİV TİC. A.Ş.
  2. Storage institutions, platform owners, data broadcasting institutions, infrastructure providers, and other business partners, suppliers, and subcontractors with whom DMS SAVUNMA works in Turkey and abroad,
  3. Banks and/or institutions authorized for collection for collection purposes, and domestic/foreign organizations worked with for the execution of activities related to these purposes, and other relevant third parties.
  4. Independent Certified Public Accountant (in order to invoice the fees received in return for services and sales provided)
  5. Attorneys from whom Legal Consultancy is received (for the establishment or exercise of a right of the company in potential or existing legal disputes)
  6. Social Security Institution and/or Private Insurance Companies (identity information of employees can be shared with the relevant insurance company or SGK.)
  7. Authorized institutions and organizations to which data must be transferred to fulfill employer obligations in accordance with the Labor Law No. 4857
  8. All Official authorities and institutions within the legitimate interest of the Company,

As a rule, personal data obtained by our Company is not shared abroad. However;

  • The Personal Data Protection Board's Decision dated 31.05.2019 and numbered 2019/157 states; “In case the G-mail e-mail service infrastructure belonging to the Google company is used, since the sent and received e-mails will be kept in data centers located in various parts of the world, in such a case, personal data will be transferred abroad and data controllers must carry out the said application in accordance with the provisions of Article 9 of the Personal Data Protection Law No. 6698 (Law) titled 'Transfer of personal data abroad';

It has been decided that storage services obtained from data controllers/data processors whose 'servers' are located abroad must also be carried out in accordance with the provisions of Article 9 of the Law.” In light of this decision, since sent and received e-mails are kept in data centers located in various parts of the world when using the Gmail e-mail service infrastructure, we inform you that our company provides data transfer within the scope of transfer abroad only to the persons and/or groups specified in our data transfer group in this policy due to the reason in this decision, within the scope of emailing, communicating via whatsapp line, and using foreign-supported programs. Likewise, our company holds no legal responsibility regarding the storage obligations of these foreign-sourced companies.

  1. METHOD OF COLLECTING PERSONAL DATA

Personal data are collected by our company within the framework of the conditions set forth in Art. 5 and Art. 6 of the KVKK through;

  • Information received within the scope of service contracts for supply, sales, and service
  • Information received within the scope of employment contracts
  • Information received within the scope of job applications
  • Closed-circuit camera recordings (CCTV)
  • Information received during face-to-face interviews
  • Information received through cookies used during website visits
  • Information received within the scope of applications
  • Information received within the scope of offers
  • Information received for the exercise of legal rights

It is being collected.

  1. METHOD OF STORAGE AND DESTRUCTION OF PERSONAL DATA

Personal data processed in line with the purposes set forth in this policy will be stored and destroyed in accordance with the KVKK and the Regulation on the Deletion, Destruction, or Anonymization of Personal Data.

Storage periods and destruction procedures are kept limited to the periods specified in the KVKK and other specific laws.

In the event that the purpose of processing personal data ends and the periods specified in the laws expire, personal data are stored solely for the purpose of serving as evidence in potential legal disputes, asserting a right linked to the stored data, establishing a defense for our legal rights, and/or presenting it upon request by authorized official authorities.

In line with this purpose, personal data will not be accessed in any way except for any legal dispute. Data stored regarding legal processes will be destroyed based on the statute of limitations and storage periods.

Personal data whose periods specified in the law are found to have expired will be deleted, destroyed, and/or anonymized by DOĞANER MAKİNA in accordance with the KVKK.

To learn about the measures we take regarding the secure storage and destruction of your personal data and the storage and destruction periods we have determined, you can request our Personal Data Storage and Destruction Policy via an email with the subject line "storage and destruction" sent to the address info@dmsgroup.com.tr.

  1. SECURITY AND AUDITING OF PERSONAL DATA

Within the scope of KVKK Art. 12, DOĞANER MAKİNA as the data controller;

Takes all kinds of necessary technical and administrative measures to ensure the appropriate level of security in order to ensure the lawfulness of personal data, prevent unlawful access to them, and ensure their preservation. For this purpose, necessary training is provided to employees, all necessary declarations and commitments are obtained from employees for the confidentiality and protection of data, the security of personal data inside and outside the company is ensured, and necessary information security measures are applied to prevent unauthorized access to data. The adequacy of the measures taken is checked, new data security systems are obtained and updated according to needs and possibilities, and audits are carried out periodically regarding all the listed aspects.

 

  1. MEASURES WE TAKE

All collected personal data are ensured to be processed in compliance with the principles listed in Article 4 of the KVKK, as well as the conditions specified in Articles 5 and 6. The technical and administrative measures we take include;

 

  • The “Obligation to Inform and Enlighten”, which is under the responsibility of the data controller within the scope of KVKK, is fulfilled through the Clarification Texts we publish both at the company address and on the websites belonging to DMS SAVUNMA.
  • DMS SAVUNMA, as the Data Controller, creates the necessary infrastructure to ensure the provision of “explicit consent” for the acquisition and processing of personal data in accordance with the KVKK.
  • In job applications and recruitment processes, it takes the necessary measures by creating the necessary conditions for the acquisition and preservation of personal data in accordance with the KVKK.
  • Within the scope of KVKK Art. 12, it takes all technical and administrative measures to prevent the unlawful processing of personal data and unlawful access to these data, and to ensure the preservation of personal data in accordance with the KVKK.
  • It takes the necessary intra-company measures, through applications within the Company and externally provided support products, to prevent data leaks.
  • It determines the legal storage periods according to the nature of the data provided in accordance with the relevant legal legislation, develops and implements storage policies suitable for these periods in the Company practice.
  • Personal data processed in accordance with the provisions of the KVKK and other relevant laws are deleted, destroyed, or anonymized ex officio or upon the request of the relevant person in a way that can never be used or retrieved, in the event that the reasons requiring their processing disappear and the periods mentioned in the article titled “Method of Storage and Destruction of Personal Data” of this Policy expire. DMS SAVUNMA introduces limitations in line with the KVKK in intra-company data access authorizations to ensure data security, and carries out destruction work on data deemed necessary to be destroyed.
  • It takes measures to prevent unauthorized access and use of personal data processed, transferred, or received as a result of transfer, by different departments within DMS SAVUNMA and by real or legal persons processing personal data on its behalf based on the authorization granted by DMS SAVUNMA.
  • Even though the necessary technical and administrative measures regarding the processing, transfer, and preservation of personal data have been taken, if unlawful access to personal data by third parties occurs; it takes all technical and administrative measures to prevent damage to the relevant persons in accordance with the relevant legislation on the protection of personal data and the KVK Board decisions.
  • It periodically follows up and audits that the data recording systems used within the company are created and used in accordance with the KVKK and relevant legislation.
  • Network security and application security are provided.
  • Disciplinary regulations containing data security provisions for employees are available.
  • Training and awareness studies on data security are conducted for employees at certain intervals.
  • An authority matrix has been created for employees.
  • Confidentiality commitments are made.
  • The authorizations of employees who have a change of role or leave their jobs in this area are removed.
  • Up-to-date anti-virus systems are used.
  • Firewalls are used.
  • Signed contracts contain data security provisions.
  • Personal data security policies and procedures have been determined.
  • Personal data security issues are reported quickly.
  • Personal data security follow-up is carried out.
  • Necessary security measures are taken regarding entry and exit to physical environments containing personal data.
  • The security of physical environments containing personal data against external risks (fire, flood, etc.) is taken.
  • The security of environments containing personal data is provided.
  • Personal data is minimized as much as possible.
  • Personal data is backed up and the security of backed-up personal data is also ensured.
  • Existing risks and threats have been identified.

 

  1. RIGHTS OF THE DATA SUBJECT

Within the scope of KVKK Art. 11, data subjects may apply to the data controller DMS SAVUNMA regarding themselves to;

a) Learn whether personal data is processed,

b) Request information if personal data has been processed,

c) Learn the purpose of processing personal data and whether they are used in accordance with their purpose,

ç) Know the third parties to whom personal data are transferred in the country or abroad,

d) Request correction of personal data if it is incomplete or incorrectly processed,

e) Request deletion or destruction of personal data within the framework of the conditions stipulated in Article 7,

f) Request notification of the operations carried out pursuant to subparagraphs (d) and (e) to third parties to whom personal data have been transferred,

g) Object to the occurrence of a result against the person himself by analyzing the processed data exclusively through automated systems,

ğ) Request the compensation of the damage in case of damage due to unlawful processing of personal data,

have the rights.

 

If data subjects wish to exercise any of their rights specified above, they must fill out the application form, which is an annex to this Policy, and submit a wet-signed copy of the form together with information and documents that will identify them, by personal application or via a notary public to our Company's notification address.

 

If the Personal Data Protection Board decides that requests can be submitted by other methods than those specified above, how applications can be submitted will be announced separately. DMS SAVUNMA will evaluate and conclude the requests coming duly from the data subjects as soon as possible and in any case within 30 (thirty) days at the latest according to the nature of the request within the framework of KVKK Art. 13.

As a rule, the requests of the data subjects will be concluded free of charge, but if answering the request requires an additional cost, the fee in the tariff determined by the Personal Data Protection Board may be charged within the framework of the relevant legislation.

 

If the answers to the applications exceed 10 (ten) pages, a transaction fee of 5.00 (five) TL will be charged for each page. If the response is requested to be given in a recording medium such as a CD or flash memory, a fee will be requested according to the cost of the requested recording medium. In case of new regulations regarding prices, newly regulated fees will apply.

  1. OTHER PROVISIONS

DMS SAVUNMA reserves the right to make changes to this Personal Data Protection and Privacy Policy at various times for detailing and updating purposes, in light of and not limited to the Regulation articles and other legislation to be issued depending on the KVKK. These updates and details are for the protection of the rights of personal data subjects.

The current version of this policy will be published on the website belonging to DMS SAVUNMA at info@dmsgroup.com.tr and will be kept open to the access of candidate personnel, customers, and visitors from the websites.

  1. ENFORCEMENT

This Policy will enter into force on the date it is published and will continue to remain in force until it is removed from the website.