KVKK
PERSONAL DATA PROTECTION AND PROCESSING POLICY
1.PURPOSE
As EFG ELEKTRİK ENERJİ A.Ş., our priority is to ensure that the personal data of natural persons associated with our Company, including our customers, subscribers and employees, are processed in compliance with the Constitution of the Republic of Türkiye, international conventions on human rights to which our country is a party, particularly the Personal Data Protection Law No. 6698 (“KVKK”), and other applicable legislation, and to ensure that the rights of the relevant persons whose data are processed can be effectively exercised. Therefore, including but not limited to our employees, subscribers, visitors, business partners, customers, dealers, users visiting our website and using our mobile applications, in short, all personal data obtained during our activities, we carry out all operations relating to the processing, storage and transfer of such data in accordance with the EFG ELEKTRİK ENERJİ A.Ş. Personal Data Protection and Processing Policy (“Policy”). The protection of personal data and safeguarding the fundamental rights and freedoms of natural persons whose personal data are collected constitute the fundamental principles of our policy regarding the processing of personal data. Therefore, we conduct all our activities involving the processing of personal data by observing the rights to privacy, confidentiality of communications, freedom of thought and belief, and effective legal remedies. In order to protect personal data, we take all administrative and technical protection measures required by the nature of the relevant data in accordance with applicable legislation and current technology. This Policy explains the methods we follow for the processing, storage, transfer, deletion or anonymization of personal data shared during our commercial, social responsibility and similar activities within the framework of the principles specified in the KVKK.
2.SCOPE
Including but not limited to the personal data of our employees, subscribers, visitors, business contacts, business partners, customers, potential customers, suppliers, dealers and users visiting our website, in short, all personal data obtained during our activities and processed by us fall within the scope of this Policy. Personal data protection applies only to natural persons, and information belonging to legal entities that does not contain information relating to a natural person is excluded from personal data protection. Therefore, this Policy does not apply to data belonging to legal entities. Our Policy applies to all personal data processing activities owned or managed by EFG ELEKTRİK ENERJİ A.Ş. and has been prepared by taking into account the KVKK, other relevant legislation relating to personal data and international standards in this field.
3.DEFINITIONS AND ABBREVIATIONS
This section briefly explains specific terms and expressions, concepts, abbreviations, etc. used in the Policy.
Company Name: EFG ELEKTRİK ENERJİ A.Ş.
Explicit Consent: Consent relating to a specific subject, based on being informed and free will, given in a clear manner that leaves no room for doubt and limited solely to the relevant processing activity.
Anonymization: Rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching them with other data.
Employee: Refers to personnel of EFG ELEKTRİK ENERJİ A.Ş.
Personal Data Owner (Data Subject): The natural person whose personal data are processed.
Personal Data: Any information relating to an identified or identifiable natural person.
Special Categories of Personal Data: Data relating to individuals’ race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, association, foundation or trade union membership, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
Processing of Personal Data: Any operation performed on personal data, such as obtaining, recording, storing, retaining, altering, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, whether wholly or partially by automated means or by non-automated means provided that they form part of a data recording system.
Data Processor: A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller.
Data Controller: A natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.
KVK Board: Personal Data Protection Board.
KVK Authority: Personal Data Protection Authority.
KVKK: Personal Data Protection Law published in the Official Gazette dated 7 April 2016 and numbered 29677.
KEP: Registered Electronic Mail address. It is a system that preserves all kinds of commercial and legal correspondence and document sharing in the form in which they were sent, definitively identifies the recipient, ensures that the content cannot be altered, and makes the content legally valid, secure and conclusive evidence.
Policy: EFG ELEKTRİK ENERJİ A.Ş. Personal Data Protection and Processing Policy.
4.DUTIES AND RESPONSIBILITIES
Company Management is responsible for the overall supervision of determining and operating notification, investigation and sanction mechanisms in cases of non-compliance with the Policy, rules and regulations. The KVKK working group is responsible for the preparation, development, implementation and updating of the Policy. This Policy is evaluated when necessary in terms of its currency and development requirements. The publication of the prepared document on the corporate portal is the responsibility of management.
5.LEGAL OBLIGATIONS
Our legal obligations as a data controller within the scope of the protection and processing of personal data pursuant to the KVKK are listed below:
A. Our obligation to inform
When collecting personal data as a data controller;
- The purposes for which your personal data will be processed,
- Information regarding our identity and, if applicable, the identity of our representative,
- To whom and for what purposes your processed personal data may be transferred,
- Our method of collecting data and its legal basis,
- Rights arising from the law; we have an obligation to inform the Data Subject regarding these matters. As EFG ELEKTRİK ENERJİ A.Ş., we take care to ensure that this Policy, which is publicly available, is clear, understandable and easily accessible.
- Our obligation to ensure data security
As a data controller, we take the administrative and technical measures prescribed by legislation to ensure the security of personal data under our responsibility. Obligations and measures relating to data security are detailed in Section 9 of this Policy.
6.CLASSIFICATION OF PERSONAL DATA
Personal data means any information relating to an identified or identifiable natural person. Personal data protection applies only to natural persons, and information belonging to legal entities that does not contain information relating to a natural person is excluded from personal data protection. Therefore, this Policy does not apply to data belonging to legal entities.
Data relating to individuals’ race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, association, foundation or trade union memberships, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data, are special categories of personal data.
7.PROCESSING OF PERSONAL DATA
We process personal data in accordance with certain principles. We process personal data in accordance with the rules of good faith, transparently and within the framework of our obligation to inform. We take the necessary measures in our data processing procedures to ensure that processed data are accurate and up to date. We also provide the Personal Data Owner with the opportunity to contact us in order to update their data and correct any errors in processed data, if any. We process personal data within the scope of our legitimate purposes, the scope and content of which are clearly defined and which have been determined in order to carry out our activities within the framework of legislation and the ordinary course of commercial life. We process personal data in a manner that is relevant, limited and proportionate to the clearly and precisely defined purposes. We avoid processing personal data that are irrelevant or not required to be processed. Various regulations in the legislation require personal data to be stored for specific periods. Therefore, we retain the personal data we process for the periods prescribed by applicable legislation or required for the purposes of processing personal data and until the end of the relevant service period. Where the retention period prescribed by legislation expires or the purpose of processing ceases to exist, we delete, destroy or anonymize personal data. Our principles and procedures relating to retention periods are detailed in Section 9 of this Policy.
Your Personal Data;
- Your personal data by which we may identify you, such as your name, surname, telephone number, e-mail address, customer number, contract number and user ID assigned to you in relation to your subscription,
- Your voice call recordings kept by sales and customer representatives in accordance with call center standards and your personal data obtained when you contact us via e-mail,
- Your credit card and debit card information, branch code, account number and other banking information,
- Your data obtained through sales, such as request and transaction information through sales channels,
- Your personal data containing usage details such as your usage volume of value-added services, content and personal information provided by you, and other records,
- If you apply for a job, other personal data obtained in this context, including your CV, and if you are an employee of EFG ELEKTRİK ENERJİ A.Ş. or an associated employee, all personal data relating to your employment agreement and suitability for employment,
- Informing you about our new products and services and providing you with the products and services most suitable for you,
- Making offers to you based on the way you use our products and services and informing you about new services,
- Conducting analyses for the purpose of improving our products and services,
- Training and developing our employees,
- Issuing invoices in return for your use of our products and services,
- Responding to any questions and complaints you may have regarding our products or services,
- Analyzing your use of our products and services for the purpose of developing and improving the products and services we provide to you,
- Providing the necessary information in line with requests and inspections by regulatory and supervisory institutions and official authorities,
- Ensuring the consistency of your information,
- Measuring customer satisfaction,
- Including but not limited to the provision of services relating to our products and services, including the execution of customer services and sales operations, management of services, traffic management, analysis of products and services, marketing activities and communications such as determining and measuring campaigns, tariffs, products and strategies, customer services and satisfaction, financial reporting and analysis, legal proceedings, service optimization and similar purposes.
Special categories of personal data are processed by us by taking the administrative and technical measures prescribed by law and by the KVK Board and where explicit consent exists, or in cases where processing is required by legislation. Since special categories of personal data relating to health and sexual life may be processed for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of healthcare services and their financing by persons subject to confidentiality obligations or authorized institutions and organizations, such data are not processed by us except for data relating to our employees. Such data belonging to our employees may be processed by persons prescribed by law.
In exceptional cases arising from the law where explicit consent is not required for the processing of personal data, we may process personal data without obtaining explicit consent.
- TRANSFER OF PERSONAL DATA
As EFG ELEKTRİK ENERJİ A.Ş., we act in compliance with the provisions of the KVKK and the decisions and regulations adopted by the KVK Board regarding the transfer of personal data. Except for exceptional circumstances specified in the legislation, personal data and special categories of personal data are not transferred by us to other natural or legal persons without the explicit consent of the Data Subject. In exceptional circumstances stipulated by the KVKK and other legislation, data may also be transferred without the explicit consent of the Data Subject to authorized administrative or judicial institutions or organizations in the manner and within the limits prescribed by the legislation. In addition, in exceptional circumstances prescribed by the legislation, data may be transferred without requiring explicit consent. As a rule, personal data are not transferred abroad without the explicit consent of the Data Subject.
Personal data may be transferred, including but not limited to, our suppliers, business partners and business contacts, subsidiaries and group companies, legally authorized public institutions and organizations, legally authorized private-law entities and our shareholders, in accordance with the principles and rules explained above.
In order to protect personal data, including but not limited to, we establish an internal technical organization for the processing and storage of personal data in accordance with legislation, establish the technical infrastructure necessary to ensure the security of databases in which your personal data will be stored, monitor and audit the processes of the technical infrastructure created, determine procedures for reporting the technical measures we take and the audit processes, periodically update and renew technical measures, reassess risky situations and develop necessary technological solutions, use software or hardware security products such as antivirus systems and firewalls, and establish security systems in line with technological developments.
In order to protect your personal data, including but not limited to, we establish personal data access policies and procedures covering employees of companies and subsidiaries within our group, inform and train our employees regarding the lawful protection and processing of personal data, record the measures to be taken in cases where personal data are processed unlawfully by our Company Employees in agreements concluded with our employees and/or in the Policies we establish, and audit the personal data processing activities of the data processors with whom we work or the partners of such data processors.
9.RETENTION OF PERSONAL DATA
Personal data are retained for the period prescribed by applicable legislation or required for the purpose for which they are processed. Without prejudice to the retention periods prescribed by legislation, we retain personal data for as long as required by the purpose of processing and for the duration of the continuity of products and services. Where we process personal data for more than one purpose, the data are deleted, destroyed or retained in anonymized form where the purposes of processing cease to exist or where, upon the request of the Data Subject, there is no legal obstacle to deleting the data. The provisions of legislation and decisions of the KVK Board are complied with regarding destruction, deletion or anonymization.
The measures we take regarding the retention of personal data include establishing technical infrastructures and related audit mechanisms for the deletion, destruction and anonymization of personal data, taking the necessary measures for the secure retention of personal data, employing personnel with technical expertise, establishing business continuity and emergency plans against potential risks and developing systems for their implementation, establishing security systems in accordance with technological developments relating to personal data storage environments, informing our employees about technical and administrative risks relating to the retention of personal data and raising awareness, and, where cooperation with third parties is required for the retention of personal data, including provisions in agreements concluded with companies to which personal data are transferred requiring the persons to whom personal data are transferred to take the necessary security measures for the protection and secure retention of transferred personal data.
10.SECURITY OF PERSONAL DATA
Our obligations regarding the security of personal data are to prevent the unlawful processing of personal data, prevent unlawful access to data and ensure that personal data are retained in accordance with the law. In this context, administrative and technical measures are taken according to technological possibilities and implementation costs.
The measures we take to prevent the unlawful processing of personal data are as follows:
– Conducting and having the necessary audits conducted within the Company,
-Training and informing our employees about the lawful processing of personal data,
-Evaluating the activities carried out by our Company in detail for all business units and, as a result of such evaluation, processing personal data specifically within the commercial activities carried out by the relevant units,
-Where cooperation with third parties is undertaken for the purpose of processing personal data, including provisions in agreements concluded with companies processing personal data requiring persons processing personal data to take the necessary security measures,
-In the event of unlawful disclosure of personal data or a data breach, notifying the KVK Board of the situation and carrying out the examinations prescribed by legislation and taking the necessary measures.
The technical and administrative measures we take to prevent unlawful access to personal data are as follows:
-Periodically updating and renewing technical measures,
-Establishing access authorization procedures within our Company,
-Determining procedures for reporting the technical measures we take and audit processes,
– Establishing the data recording systems used within our Company in accordance with legislation and carrying out periodic audits thereof,
-Establishing emergency plans against potential risks and developing systems for their implementation,
-Training and informing our employees regarding access to and authorization for personal data,
-Where cooperation with third parties is undertaken for activities such as the processing and storage of personal data, including provisions in agreements concluded with companies providing access to personal data requiring persons with access to personal data to take the necessary security measures,
-Establishing security systems within the scope of technological developments in order to prevent unlawful access to personal data.
We take administrative and technical measures to prevent the unlawful disclosure of personal data and update these measures in accordance with our relevant procedures. If we determine that personal data have been disclosed without authorization, we establish systems and infrastructures to notify the Data Subject and the KVK Board of such situation. If an unlawful disclosure occurs despite all administrative and technical measures taken, where deemed necessary by the KVK Board, such situation may be announced on the KVK Board’s website or by another method.
11.RIGHTS OF THE PERSONAL DATA OWNER
Within the scope of our obligation to inform, we inform the Personal Data Owner and establish systems and infrastructures relating to such information. We make the necessary technical and administrative arrangements to enable the Personal Data Owner to exercise their rights regarding personal data.
The Personal Data Owner has the following rights regarding their personal data:
-To learn whether personal data are being processed,
-To request information if personal data have been processed,
-To learn the purpose of processing personal data and whether they are being used in accordance with their intended purpose,
-To know the third parties to whom personal data are transferred domestically or abroad,
-To request the correction of personal data if they have been processed incompletely or incorrectly,
-To request the deletion or destruction of personal data if the reasons requiring their processing cease to exist,
-To request that the correction, deletion or destruction operations mentioned above be notified to third parties to whom personal data have been transferred,
-To object to the occurrence of a result against the individual arising from the analysis of processed data exclusively through automated systems,
-To request compensation for damages in the event of suffering damage due to the unlawful processing of personal data.
The Personal Data Owner may submit your requests within the scope of the KVKK and any questions regarding your personal data by writing a petition and sending it to Mevlana Mah. 832. Sk. No:1 Gaziosmanpaşa/İstanbul address (through a Notary Public, etc.) or by sending the relevant form signed with a secure electronic signature to our registered electronic mail address [email protected]. You may also submit your request through the KVKK Information Inquiry section at www.efgelektrik.com.
In the application to be made by the Personal Data Owner in order to exercise the above-mentioned rights and containing explanations regarding the right requested to be exercised, the requested matter must be clear and understandable, the requested matter must relate to the applicant personally or, if acting on behalf of another person, the applicant must be specifically authorized in this regard and such authorization must be documented; furthermore, the application must contain identity and address information and documents verifying the applicant’s identity must be attached to the application. Such requests must be made individually, and requests made by unauthorized third parties regarding personal data will not be taken into consideration.
Requests relating to personal data shall be concluded free of charge as soon as possible depending on their nature and, in any event, within no more than 30 (thirty) days, or, where the conditions specified in the tariff to be published by the KVK Board regarding fees arise, in return for the fee specified in such tariff. Additional information and documents may be requested during the application process or while the application is being evaluated.
Applications relating to personal data shall be rejected with justification in the following written circumstances:
-Processing personal data for purposes such as research, planning and statistics by anonymizing them through official statistics,
-Processing personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that such processing does not violate privacy or personality rights or constitute a criminal offence,
-Processing personal data made public by the Personal Data Owner
-The application not being based on a justified reason
-The application containing a request contrary to applicable legislation
-Failure to comply with the application procedure shall result in rejection with justification.
In order for the response period specified in Article 11 of this Policy to commence, requests must be submitted in writing and with a wet signature or electronically signed and sent via KEP, or through other methods determined by the KVK Board, together with information and documents verifying the applicant’s identity. If the request is accepted, the relevant action shall be taken and notification shall be made in writing or electronically. If the request is rejected, the reason shall be explained and notified to the applicant in writing or electronically. In the event that the application is rejected, the response provided by us is considered insufficient, or no response is provided within the prescribed period, the applicant has the right to lodge a complaint with the KVK Board within 30 (thirty) days from the date on which the applicant learns of the response and, in any event, within 60 (sixty) days from the date of application.
12.PUBLICATION AND RETENTION OF THE DOCUMENT
This Policy is retained in two different media: printed paper and electronic format. The current version of the documents is available on the corporate portal and website.
13.UPDATE PERIOD
This Policy is reviewed at least once a year and is updated by Operations Management where necessary.
14.EFFECTIVE DATE
This Policy enters into force on the date of its adoption by the Executive Board.