Privacy Policy
CONTENTS
• A. PURPOSE AND SCOPE
• B. DEFINITIONS
• C. IMPLEMENTATION OF THE POLICY AND RESPONSIBILITIES
• D. POLICY PRINCIPLES
•
1. BASIC PRINCIPLES ADOPTED BY
2. PERFORMING PERSONAL DATA PROCESSING ACTIVITIES IN ACCORDANCE WITH KVKK
3. PERFORMING PERSONAL DATA TRANSFER IN ACCORDANCE WITH KVKK
4. ENSURING THE SECURITY OF PERSONAL DATA
• a. Administrative Measures to be Taken
• b. Technical Precautions to be Taken
• c. Conducting Audit Activities Regarding the Protection of Personal Data
• D. Precautions in Case of Illegal Disclosure of Personal Data
5. OBLIGATIONS RELATED TO PERSONAL DATA PROCESSING ACTIVITIES
• a. Registration Obligation to the Data Controllers Registry (VERBİS)
• b. Obligation to Inform the Data Owner
• c. Obligation to Collect and Transfer Personal Data in accordance with the Law
• D. Obligation to Ensure the Security of Personal Data
• e. Obligation to Fulfill the Decisions Made by the KVK Board
• f. Obligation to Respond to Data Owner Applications
• E. PUBLISHING AND STORAGE OF THE POLICY
• F. UPDATE OF THE POLICY
A. PURPOSE AND SCOPE
Due to the fact that the legal order is one of the cornerstones of social life, INNDANCE has been complying with general legal rules since its establishment and has been making maximum efforts to protect the rights and interests of people. With INNDANCE Personal Data Processing, Protection and Privacy Policy (“INNDANCE KVK Policy”). INNDANCE determines the basic principles regarding the compliance of its activities with the regulations in the Personal Data Protection Law No. 6698 ("KVK Law") and within this scope. What INNDANCE must fulfill is set out.
By implementing INNDANCE KVK Policy regulations in all our activities, the data security principles adopted by INNDANCE will be made sustainable.
INNDANCE KVK Policy has been prepared as a guide for the implementation of the regulations set forth by the KVK Law and relevant legislation. Personal data of INNDANCE employees, employee candidates, visitors and employees of third parties, institutions or organizations with whom INNDANCE has relations as service providers, and personal data of other third parties are within the scope of this Policy, and all records where personal data owned by INNDANCE or managed by INNDANCE are processed. This Policy applies to activities related to environments and personal data processing.
B. DEFINITIONS
The terms used in the legislation and also in the INNDANCE KVK Policy are listed below.
I. Personal Data: Any kind of data relating to an identified or identifiable natural person
II. Special Personal Data: Data regarding race, ethnic origin, political thought, philosophical belief, religion, sect or other beliefs, appearance, association, foundation or union membership, health, sexual life, criminal conviction and security measures, and biometric and genetic data. .
III. Personal Data Owner/Relevant Person: The real person whose personal data is processed. For example; employees. IV. Explicit Consent: Consent regarding a specific subject, based on prior information and expressed with free will,
V. Processing of personal data: Obtaining, recording, storing, preserving, changing, rearranging, disclosing, transferring, taking over, making available personal data by fully or partially automatic or non-automatic means provided that it is part of any data recording system. Any operation performed on data such as bringing, classifying or preventing its use,
VI. Data processor: Real or legal person who processes personal data on behalf of the data controller, based on the authority given by the data controller,
VII. Anonymization: Making personal data impossible to associate with an identified or identifiable natural person in any way, even by matching it with other data.
VIII. KVK Law: Personal Data Protection Law No. 6698, dated 24 March 2016, published in the Official Gazette No. 29677, dated 7 April 2016.
IX. KVK Board: Personal Data Protection Board.
X. KVK Authority: Personal Data Protection Authority.
C. IMPLEMENTATION OF THE POLICY AND RESPONSIBILITIES
Our legal consultants will be a source of advice and guidance in the implementation of the procedures, standards and training activities prepared in accordance with the INNDANCE KVK Policy within INNDANCE. All personnel, visitors and relevant third parties throughout INNDANCE are obliged to comply with the INNDANCE KVK Policy and cooperate with the Legal Consultancy in preventing risks / dangers.
All personnel of INNDANCE are responsible for ensuring compliance with the INNDANCE KVK Policy.
D. POLICY PRINCIPLES
1. BASIC PRINCIPLES ADOPTED BY INNDANCE
INNDANCE adopts the following basic principles to comply with and maintain compliance with personal data protection legislation:
a. Personal data includes all kinds of information that belongs to a person and allows the person to be identified, and therefore it is the responsibility of the data owner to protect it.It constitutes a superior benefit. Data owner; One should act with the awareness that it is an obligation to pay attention to the right to know which data is processed for what purpose and whether the data is transferred or not.
b. It carries out data processing activities in accordance with the law and the rule of honesty.
c. It must be ensured that the personal data processed are accurate and up-to-date when necessary, and if the data is inaccurate, it must be corrected/updated.
D. Personal data is processed only for specific, explicit and legitimate purposes and to the extent necessary for the purpose of processing. Excessive data should not be processed with the assumption that it will be used in the future, and the rights of the data owner and the purpose of the processing should be taken into consideration.
to. Processed personal data are retained for the period stipulated in the relevant legislation or necessary for the purpose for which they are processed. In particular, the time limit arising from Article 138 of the Turkish Penal Code and Articles 4 and 7 of the KVK Law is respected. INNDANCE deletes, destroys or anonymizes personal data if the period stipulated in the legislation expires or if the reasons requiring the processing of personal data disappear.
2. PERFORMING PERSONAL DATA PROCESSING ACTIVITIES IN ACCORDANCE WITH KVKK
While carrying out their personal data processing activities, they must act in accordance with the data processing conditions specified in Articles 5 and 6 of the KVK Law and the Regulation on the Processing of Personal Health Data, provided that they comply with the basic principles. The following stages are followed in data processing activity:
1- The data owner must be informed. Clarification should be made before obtaining consent (signature) in cases where explicit consent is required to process data, before starting data processing in cases where explicit consent (signature) is not required, and it should be explained which data will be processed and why. If data is processed by taking camera images, written warning signs should be placed where necessary.
2- It should be determined whether the conditions for data processing are present. If the conditions are not met, personal data processing should not be carried out. In the following cases, the existence of data processing conditions is accepted and there is no need to obtain consent:
• It is clearly stipulated by law (for example, it is mandatory to obtain the employee's identity information due to the obligation to notify the Social Security Institution).
• It is necessary to process personal data of the parties to the contract, provided that it is directly related to the establishment or execution of a contract (for example, it is necessary to obtain the name, surname and bank account information of the seller in order to pay the price of the purchased product).
• It is mandatory for the data controller to fulfill its legal obligation, it has been made public by the data subject himself, data processing is mandatory for the establishment, exercise or protection of a right, data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject. Personal data may be processed in such cases.
• EXPRESS CONSENT MUST BE OBTAINED, except in the above cases or when processing "special nature data".
3- It is necessary to limit the amount of data to be processed "as much as necessary" and not to process more data than necessary for each processing purpose.
4- INNDANCE personnel must comply with the rules set forth in the Constitution of the Republic of Turkey, the Turkish Penal Code, the KVK Law and other relevant legislation and the INNDANCE KVK Policy, within the scope of processing personal data. Within the scope of these explanations, at INNDANCE, personal data processing will be carried out within the conditions and purposes specified in Article 5 and Article 6 of the KVK Law and for the purposes stated below;
Member and Business partners data;
• Data processing due to contractual relationship; Personal Data belonging to the Member or Business Partner (in case the business partner is a legal entity, the business partner representative) may be processed for the establishment, implementation and termination of the contract without the need for separate consent. Personal data before and during the contract initiation phase; It may be processed in order to prepare an offer, prepare a purchase form or meet the Personal Data Owner's requests regarding the implementation of the contract.
• Data processing due to INNDANCE's legal obligation or as expressly provided for in the law; Personal data may be processed without obtaining separate consent in order to clearly state the processing in the relevant legislation or to fulfill a legal obligation determined by the legislation. The type and scope of data processing must be necessary for the legally permissible data processing activity and must comply with the relevant legal provisions.
• Processing data in accordance with INNDANCE's legitimate interest; Personal data may be processed without the need for further consent when necessary for a legitimate interest of INNDANCE. Legitimate interests are generally legal (e.g. collecting debts) or economic (e.g. avoiding breach of contract) interests.
Personnel data;
• Processing of Personal Data for business relationshipmesi; Personal Data is processed without further consent if necessary for the establishment, implementation and termination of the employment contract. Personal Data of candidates are processed when starting a business relationship. If the candidate is rejected, the candidate's information is kept for the appropriate data retention period for a later selection phase, and is deleted, destroyed or anonymized at the end of this period.
• Data processing is carried out due to the legal obligation of INNDANCE or as expressly provided for in the law; Personal Data belonging to the employee may be processed without the need to obtain separate consent in order to clearly state the processing in the relevant legislation or to fulfill a legal obligation determined by the legislation.
• Processing of data in accordance with legitimate interest; Personal Data belonging to the Employee may be processed without further consent when necessary for a legitimate interest of INNDANCE (e.g. filing, exercising or defending legal rights). In personal cases where the interests of employees must be protected, personal data is not processed for legitimate interest purposes. Before the data is processed, it is determined whether there are interests that require protection. When employee data is processed based on INNDANCE's legitimate interest, it is examined whether the processing is proportionate. It is checked that INNDANCE's legitimate interest in taking this control measure does not violate a right of the relevant employee that needs to be protected, and it is applied only if it is proportionate.
3. PERFORMING PERSONAL DATA TRANSFER IN ACCORDANCE WITH KVKK
In personal data transfers to be carried out by INNDANCE (actively sharing personal data with third parties or making personal data accessible to third parties), the personal data transfer conditions set out in Articles 8 and 9 of the KVK Law must be complied with. Excluding individuals' race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, association, foundation or union membership, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data. Other data may be transferred in the following cases:
• It is clearly prescribed by law (for example, due to SSI legislation, it is mandatory to notify the employee's identity information to SSI).
• It is necessary to process personal data of the parties to the contract, provided that it is directly related to the establishment or execution of a contract (for example, it is mandatory to transfer the name, surname and account information of the seller to the bank in order to pay for the product purchased).
• It is mandatory for the data controller to fulfill its legal obligation, it has been made public by the data subject himself, data processing is mandatory for the establishment, exercise or protection of a right, data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject. personal data may be transferred (for example, data regarding the medications used by the employee or their diseases, if any, must be transferred to healthcare personnel when necessary).
• Personal data cannot be transferred abroad without the explicit consent of the relevant person.
4. ENSURING THE SECURITY OF PERSONAL DATA
INNDANCE must take all necessary precautions, within the means possible, depending on the nature of the data to be protected, in order to prevent unlawful disclosure and transfer of personal data, unlawful access to personal data, or security deficiencies that may occur in other ways. In this context, administrative and technical measures should be taken, an audit system should be established within INNDANCE, and in case of illegal disclosure of personal data, the process should be implemented in the KVK Law.
a. Administrative Measures Taken to Ensure Lawful Processing and Transfer of Personal Data and to Prevent Unlawful Access to Personal Data are as follows:
• Trains and raises awareness of its employees regarding the protection of personal data.
• In cases where personal data is subject to transfer, records are added to the contracts concluded with the persons to whom personal data are transferred, stating that the party to which personal data is transferred will fulfill its obligations to ensure data security. In this context, it is undertaken that the transferred party will take all necessary measures to protect personal data and ensure the implementation of these measures in their own organizations.
• The processes carried out by the personnel are examined in detail, and the personal data processing activities carried out within the scope of the process are determined for each unit. In this context, the steps to be taken to ensure that the data processing activities carried out comply with the personal data processing conditions stipulated in the KVK Law are determined.
b. To Ensure Lawful Processing and Transfer of Personal Data and to Prevent Illegal Access to Personal DataTechnical Measures taken are as follows:
• Regarding the protection of personal data, technical measures have been taken to the extent technology allows, and the measures taken should be updated and improved in parallel with developments.
• Inspections should be carried out at regular intervals regarding the implementation of the measures taken.
• Software and systems to ensure security are updated.
• Access authority to personal data being processed by personnel is limited to the relevant unit employee in line with the determined processing purpose.
c. Carrying out Audit Activities for the Protection of Personal Data: The compliance, functioning and effectiveness of the technical measures, administrative measures and practices taken by INNDANCE within the scope of protecting and ensuring the security of personal data with the relevant legislation, policies, procedures and instructions are audited by Internal Audit Units. The audit may also be carried out by external audit firms, taking the opinion of the Board of Directors. The results of the audit activities performed are reported to the General Manager and relevant function managers. It is the primary responsibility of process owners to regularly monitor the actions planned regarding the audit results. Activities that will ensure the development and improvement of the measures taken regarding the protection of data, without being limited to the audit results, are carried out by the relevant unit.
D. Precautions to be Taken in Case of Illegal Disclosure of Personal Data; INNDANCE must immediately notify the KVK Board and relevant data owners in case the personal data they process is obtained by unauthorized persons in violation of the law. The INNDANCE Data Breach Notification Procedure must be implemented simultaneously.
5. OBLIGATIONS RELATED TO PERSONAL DATA PROCESSING ACTIVITIES
They must comply with the obligations stipulated by the INNDANCE KVK Law for data controllers.
a. Registration Obligation to the Data Controllers Registry (VERBIS): VERBIS registration is required when the conditions specified in the legislation are met. The information that must be submitted to the Data Controllers Registry in the registration application is listed below:
1. Identity information and addresses of the data controller and his representative, if any,
2. Purpose of processing personal data,
3. Information about data subject groups and categories of personal data processed for these individuals,
4. Person or groups of people to whom personal data can be transferred,
5. Maximum retention period required by the purpose of processing personal data,
6. Measures taken to ensure the security of processed personal data.
b. Obligation to Inform the Data Owner: The information that must be provided to data owners within the scope of the disclosure obligation is listed below:
1. Identity of the data controller and his representative, if any,
2. For what purpose personal data will be processed,
3. To whom and for what purpose the processed personal data can be transferred,
4. Method and legal reason for collecting personal data,
5. Rights of the data owner listed in Article 11 of the KVK Law
c. Obligation to Collect and Transfer Personal Data in Compliance with the Law: It must be explained to the data owner which data is processed for what purpose and whether the data is transferred, and the collected data must be processed in accordance with the law and the rule of honesty. Personal data must be processed only for specific, clear and legitimate purposes and to the extent necessary for the purpose of processing, and must be kept accurate and up to date. If the reason for processing the processed data is no longer present, they must establish the necessary internal systems for deleting, anonymizing or destroying the data.
D. Obligation to Ensure the Security of Personal Data: In order for the data owner to avoid any loss of rights, INNDANCE; All necessary technical and administrative measures must be taken to ensure the appropriate level of security in order to prevent the unlawful processing of personal data, to prevent unlawful access to personal data, and to ensure the preservation of personal data. It is obliged to carry out the necessary inspections or have them carried out within the scope of the operation of the mechanisms to ensure data security.
to. Obligation to Fulfill the Decisions Made by the KVK Board: INNDANCE must act in accordance with the decisions made by the KVK Board, which operates to ensure that personal data is processed in accordance with fundamental rights and freedoms and is the executive body of the KVK Institution.
f. Obligation to Respond to Data Owner Applications: INNDANCE, as the data controller, must finalize the written requests of data owners regarding their personal data as soon as possible and within thirty (30) days at the latest, depending on the nature of the request.
Personal data owners can contact the data controllers and request the following issues regarding themselves:
1. Learning whether personal data is processed or not,
2. Requesting information if personal data has been processed,
3. Learning the purpose of processing personal data and whether they are used for their intended purpose,
4. Personal data at home or abroad
Knowing the third parties to whom it is transferred,
5. Requesting correction of personal data if they are incomplete or incorrectly processed,
6. Requesting the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the KVKK,
7. In case of correction or deletion/destruction of data, requesting notification of the situation to third parties to whom personal data has been transferred,
8. Objecting to the emergence of a result that is unfavorable to the individual by analyzing the processed data exclusively through automatic systems,
9. To request compensation for the damage in case of damage due to illegal processing of personal data.
PUBLISHING AND STORING OF THE E-POLICY
The policy document is published in two different media, with wet signature (printed paper) and electronically, and is disclosed to the public on the website. The printed paper copy is also kept in the file.
F- UPDATE OF THE POLICY
It enters into force from the moment it is approved by the Board of Directors. This Policy is reviewed as needed and necessary sections are updated. The General Manager has been authorized by the Board of Directors to determine the changes to be made within the policy and how they will be put into effect. Changes can be made and put into effect in this Policy with the approval of the General Manager. The implementation rules, which will be drawn up in accordance with this Policy and will specify how the matters specified in this Policy will be implemented on certain subjects, will be added to the relevant regulations. INNDANCE KVK Policy has been published on the website and made available to the public. In case of conflict between the current legislation, especially the KVK Law, and the regulations contained in this Policy, the provisions of the legislation shall apply.
İÇİNDEKİLER
- A. AMAÇ VE KAPSAM
- B. TANIMLAR
- C. POLİTİKANIN UYGULANMASI VE SORUMLULUKLAR
- D. POLİTİKA ESASLARI
-
- TARAFINDAN BENİMSENEN TEMEL İLKELER
- KİŞİSEL VERİ İŞLEME FAALİYETİNİN KVKK’NA UYGUN YERİNE GETİRİLMESİ
- KİŞİSEL VERİ AKTARIMININ KVKK’NA UYGUN YERİNE GETİRİLMESİ
- KİŞİSEL VERİLERİN GÜVENLİĞİNİN SAĞLANMASI
- a. Alınacak İdari Tedbirler
- b. Alınacak Teknik Tedbirler
- c. Kişisel Verilerin Korunmasına ilişkin Denetim Faaliyetleri Yürütmesi
- d. Kişisel Verilerin Kanuni Olmayan Yollarla İfşası Durumunda Tedbirler
- KİŞİSEL VERİ İŞLEME FAALİYETİNE İLİŞKİN YÜKÜMLÜLÜKLER
- a. Veri Sorumluları Sicili (VERBİS) ne Kayıt Yükümlülüğü
- b. Veri Sahibini Aydınlatma Yükümlülüğü
- c. Kişisel Verileri Hukuka Uygun Olarak Toplama ve Aktarma Yükümlülüğü
- d. Kişisel Verilerin Güvenliğini Sağlama Yükümlülüğü
- e. KVK Kurulu Tarafından Verilen Kararları Yerine Getirme Yükümlülüğü
- f. Veri Sahibi Başvurularına Cevap Verme Yükümlülüğü
- E. POLİTİKA’NIN YAYINLANMASI VE SAKLANMASI
- F. POLİTİKA’NIN GÜNCELLENME
A. AMAÇ VE KAPSAM
INNDANCE, hukuk düzeninin toplumsal hayatın temel taşlarından biri olduğu gerçeği nedeniyle, kurulduğu tarihten bu yana genel hukuk kurallarına uymakta ve kişilerin hak ve menfaatini gözetmek için azami gayret göstermektedir. INNDANCE Kişisel Verilerin İşlenmesi, Korunması ve Gizlik Politikası (“ INNDANCE KVK Politikası”) ile . INNDANCE, faaliyetlerinin kişisel verilerin 6698 sayılı Kişisel Verilerin Korunması Kanunu’nda (“KVK Kanunu”) yer alan düzenlemelere uyumuna ilişkin temel prensipler belirlenmekte ve bu kapsamda . INNDANCE’nin yerine getirmesi gerekenler ortaya konulmaktadır.
Tüm faaliyetlerimizde, INNDANCE KVK Politikası düzenlemelerinin uygulanması ile INNDANCE’nin benimsediği veri güvenliği ilkeleri sürdürülebilir kılınmış olacaktır.
INNDANCE KVK Politikası, KVK Kanunu ve ilgili mevzuat ile ortaya konulan düzenlemelerin uygulanması bakımından rehber olarak hazırlanmıştır. INNDANCE çalışanlar, çalışan adayları, ziyaretçiler ve hizmet sağlayıcı olarak ilişkide bulunulan üçüncü kişilerin, kurumların veya kuruluşların çalışanlarına ait kişisel veriler ve diğer üçüncü kişilere ait kişisel veriler bu Politika kapsamında olup INNDANCE’nın sahip olduğu ya da INNDANCE’since yönetilen kişisel verilerin işlendiği tüm kayıt ortamları ve kişisel veri işlenmesine yönelik faaliyetlerde bu Politika uygulanır.
B. TANIMLAR
Mevzuatta ve aynı zamanda INNDANCE KVK Politikası’nda kullanılan terimler aşağıda yer almaktadır.
I. Kişisel Veri : Kimliği belirli veya belirlenebilir gerçek kişiye ilişkin her türlü
II. Özel Nitelikli Kişisel Veri : Irk, etnik köken, siyasi düşünce, felsefi inanç, din, mezhep veya diğer inançlar, kılık kıyafet, dernek vakıf ya da sendika üyeliği, sağlık, cinsel hayat, ceza mahkûmiyeti ve güvenlik tedbirleriyle ilgili veriler ile biyometrik ve genetik veriler.
III. Kişisel Veri Sahibi /İlgili Kişi: Kişisel verisi işlenen gerçek kişi. Örneğin; çalışanlar. IV. Açık Rıza : Belirli bir konuya ilişkin, önceden yapılmış bilgilendirilmeye dayanan ve özgür iradeyle açıklanan rızayı,
V. Kişisel verilerin işlenmesi: Kişisel verilerin tamamen veya kısmen otomatik olan ya da herhangi bir veri kayıt sisteminin parçası olmak kaydıyla otomatik olmayan yollarla elde edilmesi, kaydedilmesi, depolanması, muhafaza edilmesi, değiştirilmesi, yeniden düzenlenmesi, açıklanması, aktarılması, devralınması, elde edilebilir hâle getirilmesi, sınıflandırılması ya da kullanılmasının engellenmesi gibi veriler üzerinde gerçekleştirilen her türlü işlemi,
VI. Veri işleyen: Veri sorumlusunun verdiği yetkiye dayanarak onun adına kişisel verileri işleyen gerçek veya tüzel kişiyi,
VII. Anonim Hale Getirme : Kişisel verinin, başka verilerle eşleştirilerek dahi hiçbir surette kimliği belirli veya belirlenebilir bir gerçek kişiyle ilişkilendirilemeyecek hale getirilmesi.
VIII. KVK Kanunu : 7 Nisan 2016 tarihli ve 29677 sayılı Resmi Gazete’de yayımlanan, 24 Mart 2016 tarihli ve 6698 sayılı Kişisel Verilerin Korunması Kanunu.
IX. KVK Kurulu : Kişisel Verileri Koruma Kurulu.
X. KVK Kurumu : Kişisel Verileri Koruma Kurumu.
C. POLİTİKANIN UYGULANMASI VE SORUMLULUKLAR
INNDANCE KVK Politikası’na uygun hazırlanan prosedür, standart ve eğitim faaliyetlerinin INNDANCE bünyesinde uygulanmasında, hukuk danışmanlarımız tavsiye kaynağı ve rehber olacaktır. INNDANCE genelindeki tüm personel, ziyaretçiler ve ilgili üçüncü kişiler, INNDANCE KVK Politikası’na uymak ve risklerin / tehlikenin önlenmesinde Hukuk Müşavirliği ile iş birliği yapmakla yükümlüdürler.
INNDANCE’nin tüm personelli INNDANCE KVK Politikası’na uyulmasını gözetmekle sorumludur.
D. POLİTİKA ESASLARI
1. INNDANCE TARAFINDAN BENİMSENEN TEMEL İLKELER
INNDANCE, kişisel verilerin korunması mevzuatına uyum sağlanması ve uyumun sürdürülmesi için aşağıda sıralanan temel ilkeler benimsenmektedir:
a. Kişisel veri, kişiye ait ve kişinin belirlenesini sağlayan her türlü bilgiyi içermektedir ve bu sebeple korunması veri sahibi yönünden üstün yarar teşkil etmektedir. Veri sahibinin; hangi verilerinin hangi amaçla işlendiğini, verilerin aktarılıp aktarılmadığını bilme hakkına öncelikle özen gösterilmesinin bir yükümlülük olduğu bilinciyle hareket edilmelidir.
b. Veri işleme faaliyetlerini hukuka ve dürüstlük kuralına uygun olarak yürütür.
c. İşlenen kişisel verilerin doğru ve gerektiğinde güncel olması sağlanmalı ve verilerin hatalı olması halinde bunların düzeltilmesi/ güncellenmesi sağlanmalıdır.
d. Kişisel veriler sadece belirli, açık ve meşru amaçlar için ve işleme amacının gerektirdiği kadar işlenir. İleride kullanılma varsayımıyla fazla veri işlenmemeli, veri sahibinin hakları ile işlemenin amacı birlikte göz önünde bulundurulmalıdır.
e. İşlenen kişisel veriler ilgili mevzuatta öngörülen veya işlendikleri amaç için gerekli olan süre kadar muhafaza edilir. Özellikle Türk Ceza Kanunu’nun 138. maddesi ve KVK Kanunu’nun 4. ve 7. maddelerinden kaynaklanan süre sınırına riayet edilir. INNDANCE, mevzuatta öngörülen sürenin bitimi veya kişisel verilerin işlenmesini gerektiren sebeplerin ortadan kalkması halinde kişisel verileri siler, yok eder veya anonim hale getirir.
2. KİŞİSEL VERİ İŞLEME FAALİYETLERİNİN KVKK’NA UYGUN YERİNE GETİRİLMESİ
Kişisel verilerin işlenmesi faaliyetlerini yürütürken, temel ilkelere uymak kaydıyla, KVK Kanunu’nun 5. ve 6. maddeleri ile Kişisel Sağlık Verilerinin İşlenmesine İlişkin Yönetmelik’te belirlenen veri işleme şartlarına uygun hareket etmelidirler. Veri işleme faaliyetinde sırayla aşağıdaki aşamalar takip edilir;
1- Veri sahibi aydınlatılmalıdır. Aydınlatma, veri işlemek için açık rıza alınması gereken durumlarda rıza ( imza) alınmadan önce, açık rıza (imza) alınması gerekmeyen durumlarda veri işlemeye başlamadan önce yapılmalı ve hangi verilerin neden işleneceği açıklanmalıdır. Kamera görüntüsü alınmak suretiyle veri işlenmesi durumunda, gerekli yerlere yazılı uyarı levhaları konulmalıdır.
2- Veri işlenme şartlarının mevcut olup olmadığının tespiti yapılmalıdır, şartların bulunmaması durumunda kişisel veri işleme faaliyetini gerçekleştirmemelidirler. Şu durumlarda veri işleme şartlarının varlığı kabul edilir ve rıza almaya gerek yoktur:
• Kanunlarda açıkça öngörülmesi ( örneğin SGK’ya bildirim zorunluluğu nedeniyle çalışanın kimlik bilgisinin alınması zorunludur).
• Bir sözleşmenin kurulması veya ifasıyla doğrudan doğruya ilgili olması kaydıyla, sözleşmenin taraflarına ait kişisel verilerin işlenmesinin gerekli olması ( örneğin satın alma yapılan ürünün bedelini ödemek için satıcı kişinin ad soyadı ve banka hesap bilgilerinin alınması zorunludur).
• Veri sorumlusunun hukuki yükümlülüğünü yerine getirebilmesi için zorunlu olması, ilgili kişinin kendisi tarafından alenileştirilmiş olması, bir hakkın tesisi, kullanılması veya korunması için veri işlemenin zorunlu olması, ilgili kişinin temel hak ve özgürlüklerine zarar vermemek kaydıyla, veri sorumlusunun meşru menfaatleri için veri işlenmesinin zorunlu olması hallerinde kişisel veri işlenebilir.
• Yukarıdaki haller dışında veya “özel nitelikli veri” işlenmesi sırasında AÇIK RIZA ALINMALIDIR.
3- İşlenecek veri miktarını “ gerektiği kadarla” sınırlamak ve her işleme amacı için gerektiğinden fazla veri işlememek gereklidir.
4- INNDANCE personeli, kişisel verilerin işlenmesi kapsamında Türkiye Cumhuriyeti Anayasası başta olmak üzere, Türk Ceza Kanunu, KVK Kanunu ve ilgili diğer mevzuat ile INNDANCE KVK Politikası’nda ortaya konulan kurallara uymalıdırlar. Bu açıklamalar kapsamında INNDANCE’de, KVK Kanunu Madde 5 ve Madde 6’da belirtilen kişisel veri işleme şartları ve amaçları dâhilinde ve aşağıda belirtilen amaçlar dahilinde gerçekleştirilecektir;
Üye ve İş ortakları verileri;
• Sözleşmesel ilişki nedeniyle veri işleme; Üye veya İş ortağına (iş ortağının tüzel kişi olması halinde iş ortağı yetkilisine) ait Kişisel Veri ayrıca rıza alınmasına gerek olmaksızın, sözleşmenin kurulması, uygulanması ve sonlandırılması için işlenebilir. Sözleşme öncesinde ve sözleşmeye başlama aşamasında kişisel veriler; teklif hazırlamak, satın alma formu hazırlamak ya da Kişisel Veri Sahibinin sözleşmenin uygulanmasıyla ilgili taleplerini karşılamak amacıyla işlenebilir.
• INNDANCE’nin hukuki yükümlülüğü veya kanunda açıkça öngörülmesi sebebiyle yapılan veri işlemeleri; Kişisel veriler, işlemenin ilgili mevzuatta açıkça belirtilmesi veya mevzuatla belirlenen bir hukuki yükümlülüğün yerine getirilmesi amacıyla, ayrıca rıza alınmadan işlenebilir. Veri işlemlerinin tür ve kapsamı, yasal olarak izin verilen veri işleme faaliyeti için gerekli olmalı ve ilgili yasal hükümlere uygun olmalıdır.
• INNDANCE’nin meşru menfaatine uygun olarak veri işlenmesi; Kişisel veriler, INNDANCE’nin meşru bir menfaati için gerekli olduğunda da ayrıca rıza alınmasına gerek olmaksızın işlenebilir. Meşru menfaatler genellikle yasal (örn. alacakların tahsil edilmesi) ya da ekonomik (örn. sözleşme ihlallerinden kaçınma) menfaatlerdir.
Personel verileri;
• İş ilişkisi için Kişisel Verilerin işlenmesi; Kişisel Veriler, iş sözleşmesinin kurulması, uygulanması ve sonlandırılması için gerekli olması halinde ayrıca rıza alınmadan işlenmektedir. İş ilişkisi başlatılırken adayların Kişisel Verileri işlenmektedir. Eğer aday reddedilirse, adaya ait bilgiler aday daha sonraki bir seçim aşaması için uygun veri saklama süresi kadar muhafaza edilmekte bu sürenin sonunda silinmekte, yok edilmekte veya anonim hale getirilmektedir.
• Kanunda açıkça öngörülmesi veya INNDANCE’nin hukuki yükümlülüğü sebebiyle yapılan veri işlemeleri; Çalışana ait Kişisel Veriler, işlemenin ilgili mevzuatta açıkça belirtilmesi veya mevzuatla belirlenen bir hukuki yükümlülüğün yerine getirilmesi amacıyla ayrıca rıza alınmasına gerek olmaksızın işlenebilir.
• Meşru menfaate uygun olarak verilerin işlenmesi; Çalışana ait Kişisel Veriler, INNDANCE’nin meşru bir menfaatinin gerektiğinde de ayrıca rıza alınmadan işlenebilmektedir (örn. yasal hakların dosyalanması, uygulanması ya da savunulması). Çalışanların menfaatlerinin korunması gerektiği kişisel durumlarda kişisel veriler meşru menfaat amaçları için işleme alınmamaktadır. Veriler işlenmeden önce koruma gerektiren menfaatlerin olup olmadığı belirlenmektedir. Çalışanlara ait verilerin INNDANCE’nin meşru menfaatine dayanarak işlendiğinde, işlemenin ölçülü olup olmadığı incelenmektedir. INNDANCE’nin bu kontrol önlemini almasındaki meşru menfaatinin ilgili çalışanın korunması gereken bir hakkını ihlal etmediği kontrol edilmekte olup ve sadece ölçülü olması halinde uygulanmaktadır.
3. KİŞİSEL VERİ AKTARIMININ KVKK’NA UYGUN YERİNE GETİRİLMESİ
INNDANCE tarafından gerçekleştirilecek kişisel veri aktarımlarında (kişisel verilerin aktif olarak üçüncü kişilerle paylaşılması veya kişisel verilerin üçüncü kişilerin erişime açılması) KVK Kanunu’nun 8. ve 9. maddelerinde düzenlenmiş olan kişisel veri aktarım şartlarına uygun hareket edilmelidir. Kişilerin ırkı, etnik kökeni, siyasi düşüncesi, felsefi inancı, dini, mezhebi veya diğer inançları, kılık ve kıyafeti, dernek, vakıf ya da sendika üyeliği, sağlığı, cinsel hayatı, ceza mahkûmiyeti ve güvenlik tedbirleriyle ilgili verileri ile biyometrik ve genetik verileri hariç olmak üzere diğer veriler aşağıdaki durumlarda aktarılabilir:
• Kanunlarda açıkça öngörülmesi ( örneğin SGK mevzuatı nedeniyle çalışanın kimlik bilgisinin SGK’ya bildirimi zorunludur).
• Bir sözleşmenin kurulması veya ifasıyla doğrudan doğruya ilgili olması kaydıyla, sözleşmenin taraflarına ait kişisel verilerin işlenmesinin gerekli olması ( örneğin satın alması yapılan ürünün bedelini ödemek için satıcı kişinin ad soyadı ve hesap bilgilerinin bankaya bölümüne aktarımı zorunludur).
• Veri sorumlusunun hukuki yükümlülüğünü yerine getirebilmesi için zorunlu olması, ilgili kişinin kendisi tarafından alenileştirilmiş olması, bir hakkın tesisi, kullanılması veya korunması için veri işlemenin zorunlu olması, ilgili kişinin temel hak ve özgürlüklerine zarar vermemek kaydıyla, veri sorumlusunun meşru menfaatleri için veri işlenmesinin zorunlu olması hallerinde kişisel veri aktarılabilir ( örneğin çalışanın kullandığı ilaçlar veya varsa hastalıklarına dair verilerin gerekli durumlarda sağlık personeline aktarımı zorunludur).
• Kişisel veriler, ilgili kişinin açık rızası olmaksızın yurt dışına aktarılamaz.
4. KİŞİSEL VERİLERİN GÜVENLİĞİNİN SAĞLANMASI
INNDANCE kişisel verilerin hukuka aykırı olarak açıklanmasını, aktarılmasını, kişisel verilere hukuka aykırı olarak erişilmesini, veya başka şekillerde meydana gelebilecek güvenlik eksikliklerini önlemek için, imkanlar dahilinde, korunacak verinin niteliğine göre gerekli her türlü tedbiri almalıdırlar. Bu kapsamda idari ve teknik tedbirler alınmalı, INNDANCE bünyesinde denetim sistemi kurulmalı ve kişisel verilerin kanuni olmayan yollarla ifşası durumunda KVK Kanunu’nda süreç işletilmelidir.
a. Kişisel Verilerin Hukuka Uygun İşlenmesini, Aktarılmasını Sağlamak ve Kişisel Verilere Hukuka Aykırı Erişilmesini Önlemek için Alınan İdari Tedbirler şunlardır:
• Kişisel verilerin korunmasına ilişkin olarak çalışanlarını eğitir ve bilinçlendirir.
• Kişisel verilerin aktarıma konu olduğu durumlarda, kişisel verilerin aktarıldığı kişiler ile akdedilmiş sözleşmelere, kişisel verilerin aktarıldığı tarafın veri güvenliğini sağlamaya yönelik yükümlülükleri yerine getireceğine ilişkin kayıtlar eklenir. Bu kapsamda, aktarılan tarafın kişisel verilerin korunması amacıyla gerekli her türlü tedbiri alacağı ve kendi kuruluşlarında bu tedbirlerin uygulanmasını temin edeceği taahhüt altına alınır.
• Personel tarafından gerçekleştirilen süreçler detaylı olarak incelenir, süreç kapsamında yürütülen kişisel veri işleme faaliyetleri her birim özelinde tespit edilir. Bu kapsamda, yürütülen veri işleme faaliyetlerinin KVK Kanunu’nda öngörülen kişisel veri işleme şartlarına uygunluğunun sağlanması için atılması gereken adımlar belirlenir.
b. Kişisel Verilerin Hukuka Uygun İşlenmesini, Aktarılmasını Sağlamak ve Kişisel Verilere Hukuka Aykırı Erişilmesini Önlemek için Alınan Teknik Tedbirler şunlardır:
• Kişisel verilerin korunmasına ilişkin olarak, teknolojinin imkan verdiği ölçüde teknik önlemler alınınmış olup, alınan önlemler gelişmelere paralel olarak güncellenmeli ve iyileştirilmelidir.
• Alınan önlemlerin uygulanmasına yönelik düzenli aralıklarla denetim yapılmalıdır.
• Güvenliği temin edecek yazılım ve sistemleri güncellenir.
• Personeller tarafından işlenmekte olan kişisel verilere erişim yetkisi, belirlenen işleme amacı doğrultusunda ilgili birim çalışanı ile sınırlandırılır.
c. Kişisel Verilerin Korunmasına ilişkin Denetim Faaliyetleri Yürütmesi INNDANCE tarafından kişisel verilerin korunması ve güvenliğinin sağlanması kapsamında alınan teknik tedbirlerin, idari tedbirlerin ve uygulamaların ilgili mevzuata, politika, prosedür ve talimatlara uyumu, işleyişi ve etkinliği İç Denetim Birimleri tarafından denetlenir. Denetim Yönetim Kurulu görüşünü alarak dış kaynaklı denetim firmalarına da yaptırabilir. Gerçekleştirilen denetim faaliyetlerinin sonuçları, Genel Müdür ve ilgili fonksiyon yöneticilerine raporlanır. Denetim sonuçlarına ilişkin planlanan aksiyonların düzenli olarak takibi, süreç sahiplerinin asli sorumluluğundadır. Denetim sonuçları ile sınırlı olmaksızın, verilerin korunmasına ilişkin alınan tedbirlerinin geliştirilmesini ve iyileştirilmesini sağlayacak faaliyetler ilgili birimce yürütülür.
d. Kişisel Verilerin Kanuni Olmayan Yollarla İfşası Durumunda Alınması Gereken Tedbirler ; INNDANCE, işlemekte oldukları kişisel verilerin hukuka aykırı olarak yetkisiz kimseler tarafından elde edilmesi durumunda, vakit kaybetmeksizin durumu KVK Kurulu’na ve ilgili veri sahiplerine bildirmelidirler. Eş zamanlı olarak INNDANCE Veri İhlal Bildirim Prosedürü uygulanmalıdır.
5. KİŞİSEL VERİ İŞLEME FAALİYETİNE İLİŞKİN YÜKÜMLÜLÜKLER
INNDANCE KVK Kanunu’nun veri sorumluları için öngördüğü yükümlülüklere uymalıdırlar.
a. Veri Sorumluları Sicili (VERBİS) ne Kayıt Yükümlülüğü: Mevzuatta belirlenen şartlar oluştuğunda VERBİS kaydının yaptırılması gereklidir. Kayıt başvurusunda Veri Sorumluları Sicili’ne sunulması gereken bilgiler aşağıda yer almaktadır:
1. Veri sorumlusu ve varsa temsilcisinin kimlik bilgileri ve adresleri,
2. Kişisel verilerin işlenme amacı,
3. Veri sahibi kişi grupları ve bu kişilere ait işlenen kişisel veri kategorileri hakkında bilgiler,
4. Kişisel verilerin aktarılabileceği kişi veya kişi grupları,
5. Kişisel verilerin işlenme amacının gerektirdiği azami muhafaza edilme süresi,
6. İşlenen kişisel verilerin güvenliğini sağlamaya yönelik alınan tedbirler.
b. Veri Sahibini Aydınlatma Yükümlülüğü : Aydınlatma yükümlülüğü kapsamında veri sahiplerine sunulması gereken bilgiler aşağıda yer almaktadır:
1. Veri sorumlusunun ve varsa temsilcisinin kimliği,
2. Kişisel verilerin hangi amaçla işleneceği,
3. İşlenen kişisel verilerin kimlere ve hangi amaçla aktarılabileceği,
4. Kişisel veri toplamanın yöntemi ve hukuki sebebi,
5. KVK Kanunu’nun 11. maddesinde sayılan veri sahibinin hakları
c. Kişisel Verileri Hukuka Uygun Olarak Toplama ve Aktarma Yükümlülüğü: Veri sahibine hangi verilerinin hangi amaçla işlendiği ve verilerin aktarılıp aktarılmadığı açıklanmalı, toplanan veriler hukuka ve dürüstlük kuralına uygun olarak işlenmelidir. Kişisel veriler sadece belirli, açık ve meşru amaçlar için ve işleme amacının gerektirdiği kadar işlenmeli ve doğru ve güncel olması sağlanmalıdır. İşlenmiş verinin işleme sebebi ortadan kalkmış ise verilerin silinmesi, anonim hale getirilmesi veya yok edilmesine yönelik gerekli iç sistemlerini kurmalıdırlar.
d. Kişisel Verilerin Güvenliğini Sağlama Yükümlülüğü: Veri sahibinin herhangi bir hak kaybı yaşamaması için INNDANCE; kişisel verilerin hukuka aykırı olarak işlenmesini önlemek, kişisel verilere hukuka aykırı olarak erişilmesini önlemek, kişisel verilerin muhafazasını sağlamak amacıyla uygun güvenlik düzeyini temin etmeye yönelik gerekli her türlü teknik ve idari tedbirleri alınmalıdır. Veri güvenliğini sağlamaya yönelik mekanizmaların işletilmesi kapsamında gerekli denetimleri yapmak veya yaptırmakla yükümlüdür.
e. KVK Kurulu Tarafından Verilen Kararları Yerine Getirme Yükümlülüğü: INNDANCE kişisel verilerin, temel hak ve özgürlüklere uygun şekilde işlenmesini sağlamak adına faaliyette bulunan ve KVK Kurumu’nun icra organı olan KVK Kurulu tarafından verilen kararlara uygun hareket etmelidirler.
f. Veri Sahibi Başvurularına Cevap Verme Yükümlülüğü : INNDANCE veri sorumlusu sıfatıyla, veri sahiplerinin kişisel verilerine ilişkin yazılı taleplerini, talebin niteliğine göre en kısa sürede ve en geç otuz (30) gün içinde sonuçlandırmalıdırlar.
Kişisel veri sahipleri veri sorumlularına başvurarak kendileri ile ilgili aşağıda yer alan konularda talepte bulunabilirler:
1. Kişisel veri işlenip işlenmediğini öğrenme,
2. Kişisel verileri işlenmişse buna ilişkin bilgi talep etme,
3. Kişisel verilerin işlenme amacını ve bunların amacına uygun kullanılıp kullanılmadığını öğrenme,
4. Yurt içinde veya yurt dışında kişisel verilerin aktarıldığı üçüncü kişileri bilme,
5. Kişisel verilerin eksik veya yanlış işlenmiş olması hâlinde bunların düzeltilmesini isteme,
6. KVKK 7. maddede öngörülen şartlar çerçevesinde kişisel verilerin silinmesini veya yok edilmesini isteme,
7. Verilerde düzeltme veya silinme/yok edilme halinde, kişisel verilerin aktarıldığı üçüncü kişilere durumun bildirilmesini isteme,
8. İşlenen verilerin münhasıran otomatik sistemler vasıtasıyla analiz edilmesi suretiyle kişinin kendisi aleyhine bir sonucun ortaya çıkmasına itiraz etme,
9. Kişisel verilerin kanuna aykırı olarak işlenmesi sebebiyle zarara uğraması hâlinde zararın giderilmesini talep etme etmek.
E- POLİTİKA’NIN YAYINLANMASI VE SAKLANMASI
Politika dokümanı, ıslak imzalı (basılı kâğıt) ve elektronik ortamda olmak üzere iki farklı ortamda yayımlanır, internet sayfasında kamuya açıklanır. Basılı kâğıt nüshası da dosyasında saklanır.
F- POLİTİKA’NIN GÜNCELLENME
Yönetim Kurulu tarafından onaylandığı andan itibaren yürürlüğe girer. Bu Politika, ihtiyaç duyuldukça gözden geçirilir ve gerekli olan bölümler güncellenir. Politika içerisinde yapılacak değişiklikler ve ne şekilde yürürlüğe konacağı konusunda da Yönetim Kurulu tarafından Genel Müdüre yetki verilmiştir. Genel Müdür onayıyla işbu Politika içerisinde değişiklik yapılabilecek ve yürürlüğe konabilecektir. İşbu Politika’ya bağlı olarak düzenlenecek, bu Politika’nın içerisinde belirtilen hususların belli konular özelinde ne şekilde icra edileceğini belirtecek uygulama kuralları ilgili yönetmeliklere eklenmek şeklinde düzenlenecektir. INNDANCE KVK Politikası internet sitesinde yayımlanarak kamuoyuna sunulmuştur. Başta KVK Kanunu olmak üzere yürürlükteki mevzuat ile işbu Politika’da yer verilen düzenlemelerin çelişmesi halinde mevzuat hükümleri uygulanır.