Protection of Personal Data

1. PURPOSE AND SCOPE

This Personal Data Processing and Protection Policy (“Policy”) has been prepared with the main aim of ensuring transparency and accountability within the framework of legislation concerning personal data. The goal of this Policy is to inform and enlighten individuals whose personal data is processed by E VE N SERVİS ANONİM ŞİRKETİ (“Company”).

This Policy applies to all real persons whose personal data is processed by the Company.

2. DEFINITIONS

The definitions used in the Policy and which need clarification for the integrity of the text are as follows:

“Explicit Consent”: Consent that is given on a specific issue, based on information and expressed with free will.

“Relevant User”: Persons who process personal data within the organization of the data controller or under its authorization and instruction, excluding those responsible for technical storage, protection, and backup of data.

“Anonymization of Personal Data”: Rendering personal data impossible to link to an identified or identifiable person, even when combined with other data.

“Personal Data”: Any information related to an identified or identifiable real person.

“Processing of Personal Data”: Any operation performed on personal data such as collection, recording, storage, retention, alteration, rearrangement, disclosure, transfer, acquisition, making available, classification, or prevention of use, whether by automatic or non-automatic means as part of a data recording system.

“Destruction of Personal Data”: Deletion, destruction, or anonymization of personal data.

“Deletion of Personal Data”: Making personal data inaccessible and non-reusable for relevant users.

“Board”: Personal Data Protection Board.

“Law on the Protection of Personal Data”: Law No. 6698 on the Protection of Personal Data (KVK Law).

“Sensitive Personal Data”: Data such as race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, clothing, association, foundation or union membership, health, sexual life, criminal conviction and security measures, biometric and genetic data.

“Data Processor”: A real or legal person who processes personal data on behalf of the data controller based on authorization.

“Data Recording System”: A recording system in which personal data is structured according to specific criteria.

“Data Subject or Related Person”: The real person whose personal data is processed.

“Data Controller”: The real or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.

3. IDENTITY OF THE DATA CONTROLLER

Information regarding the identity of the data controller for any personal data processing activity covered by the Policy is provided below:

Data Controller: -

MERSIS No: 0323052809500018

Address: Maslak Mah. Dereboyu 2 Cd Ata Center İş Merkezi No:15 H:31, 34485 Sarıyer/İstanbul

Registered Email (KEP): -

Email Address: info@astonmartinstore.com

4. GENERAL PRINCIPLES IN PROCESSING PERSONAL DATA

Article 4 of the KVK Law outlines the fundamental principles that must be followed in the processing of personal data. These principles are observed and applied carefully by the Company in all data processing activities. The relevant principles and their explanations are listed below:

Lawfulness and Fairness: The Company complies with the general principles of law and the principle of honesty regulated in the Turkish Civil Code No. 4721 while fulfilling its obligations regarding the processing and protection of personal data.

Accuracy and Up-to-Dateness: Ensuring that personal data provides accurate and up-to-date information about individuals is of utmost importance to protect their rights. The Company takes reasonable care to keep personal data accurate and up-to-date.

Specific, Clear and Legitimate Purposes: The purposes for which personal data is processed are crucial in determining the lawfulness of the processing activity. In this context, the KVK Law requires processing for specific, clear, and legitimate purposes. The Company processes personal data for specific, clear, and legitimate purposes as required by its commercial activities.

Relevance, Limitation and Proportionality: The Company processes personal data to the extent necessary to achieve the specified purposes in the context of its commercial activities and avoids unnecessary data processing in accordance with this principle.

Retention for a Limited Period: The Company retains personal data as long as the purpose for processing continues and deletes it when the purpose ceases to exist, in accordance with applicable laws and regulations.

5. LEGAL GROUNDS FOR PROCESSING PERSONAL DATA

Article 5 of the KVK Law lists the legal grounds for processing personal data. If the purposes of processing personal data by a data controller fall within these legal grounds, then the processing is considered lawful. In this context, if the purposes pursued by the Company fall under these legal grounds defined in the KVK Law, the Company processes personal data accordingly.

The legal grounds under the KVK Law are as follows:

  • Explicit consent of the data subject,
  • It is clearly prescribed by law,
  • It is necessary for the protection of the life or physical integrity of the person who is unable to express consent due to actual impossibility or whose consent is not legally valid,
  • It is necessary to process personal data of the parties to a contract, provided that it is directly related to the conclusion or performance of the contract,
  • It is necessary for the data controller to fulfill its legal obligation,
  • The data subject has made the data public,
  • It is necessary for the establishment, exercise or protection of a right,
  • Provided that it does not harm the fundamental rights and freedoms of the data subject, it is necessary for the legitimate interests of the data controller.

6. LEGAL GROUNDS FOR PROCESSING SENSITIVE PERSONAL DATA

The Company may process sensitive personal data under the legal grounds specified in Article 6 of the KVK Law. Sensitive data is not processed for discriminatory purposes or in a manner that may subject individuals to unlawful treatment. The Company also implements additional security measures as required by legislation to protect sensitive personal data.

The legal grounds under Article 6 for processing sensitive personal data are:

  • Explicit consent of the data subject,
  • It is clearly prescribed by law,
  • It is necessary for the protection of the life or physical integrity of the person who is unable to express consent due to actual impossibility or whose consent is not legally valid,
  • It is related to personal data made public by the data subject and is in line with the purpose of disclosure,
  • It is necessary for the establishment, exercise or protection of a right,
  • It is necessary for public health protection, preventive medicine, medical diagnosis, treatment and care services, or the planning, management and financing of health services, by persons or institutions under a confidentiality obligation,
  • It is necessary for the fulfillment of obligations in the areas of employment, occupational health and safety, social security, social services and social assistance,
  • It is limited to members, former members or regular contacts of foundations, associations, or other non-profit entities operating in line with their legislation and purposes, and is not disclosed to third parties.

7. EXPLANATIONS ON PERSONAL DATA CATEGORIZATION

In the clarification texts provided to data subjects, personal data categories are used. These categories are prepared within the framework of the VERBIS system, and sample data types within each category are listed below.

Personal Data Categories

Category Examples
IdentityName, surname, parents’ names, maiden name, birth date/place, marital status, ID number, etc.
ContactAddress, email, communication address, KEP, phone number, etc.
LocationLocation data of where the individual is situated
HRPayroll info, disciplinary records, entry/exit records, asset declarations, CVs, performance reviews, etc.
Legal TransactionsInformation in correspondence with judicial authorities, case file info, etc.
Customer TransactionsCall center recordings, invoices, receipts, order info, requests, etc.
Physical SecurityEntrance-exit records of staff/visitors, CCTV footage, etc.
Transaction SecurityIP addresses, website logins, passwords, etc.
Risk ManagementInformation processed for managing commercial, technical or administrative risks
FinanceBalance sheets, financial performance, credit/risk data, asset info, etc.
Professional ExperienceDiplomas, courses attended, in-service training, certificates, transcripts, etc.
MarketingShopping history, surveys, cookie data, campaign results, etc.
Visual and Audio RecordsImages and sound recordings
OtherData types to be specified by the user

Sensitive Personal Data Categories

Category Examples
Race and EthnicityInformation about race and ethnic background
Political OpinionDetails expressing political views or party membership
Philosophical Belief, Religion, Sect, and Other BeliefsInformation on religious or philosophical beliefs, sect affiliations, etc.
Appearance and ClothingDetails related to attire
Association MembershipInformation about association membership
Foundation MembershipInformation about foundation membership
Union MembershipInformation about union membership
Health DataDisability status, blood type, medical data, use of devices/prosthetics
Sex LifeInformation about sexual life
Criminal Convictions and Security MeasuresCriminal records, security-related data
Biometric DataPalm print, fingerprint, retina scan, facial recognition, etc.
Genetic DataGenetic data

8. RETENTION AND DISPOSAL OF PERSONAL DATA

The retention period for personal data by the Company is calculated by considering the durations specified in the relevant legislation. Even after these durations expire, if there is a continuing purpose for data processing that falls within the legal grounds outlined in the KVK Law, the personal data of individuals may continue to be processed and retained.

If the purposes for processing personal data no longer exist and there are no applicable legal grounds for processing as per the KVK Law, the Company will dispose of the data. Such disposal operations are carried out either ex officio in six-month periods or upon the request of the data subjects, and in accordance with the provisions of the applicable legislation.

Personal data is disposed of by deletion, anonymization, or destruction techniques depending on the environment in which the data is stored. Detailed information on these techniques can be found in the “Guideline on the Deletion, Destruction or Anonymization of Personal Data” published by the Board.

9. RIGHTS OF THE DATA SUBJECT

Under Article 11 of the Personal Data Protection Law (KVK Law), the following rights are granted to data subjects:

  • To learn whether personal data is being processed,
  • If personal data has been processed, to request information about it,
  • To learn the purpose of the data processing and whether the data is being used in accordance with that purpose,
  • To know the third parties, in Turkey or abroad, to whom personal data has been transferred,
  • To request correction of personal data if it is incomplete or incorrectly processed,
  • To request the deletion or destruction of personal data if the reasons requiring its processing no longer exist, even if it was processed in accordance with the law and other relevant legislation, and to request notification of these actions to third parties to whom the data has been transferred,
  • To object to the occurrence of a result against the person by analyzing the processed data exclusively through automated systems,
  • To request compensation for damages in case of loss due to unlawful processing of personal data.

Requests under Article 11 of the KVK Law may be submitted to the data controller in accordance with the "Communiqué on the Principles and Procedures for the Request to Data Controller." You may submit your request via the following addresses:

Address: Köybaşı Cd. No:94, Yeniköy, 34464 Sarıyer/Istanbul

Registered Email (KEP): -

Email Address: info@astonmartinstore.com

Our Company will conclude your requests related to the aforementioned rights free of charge as soon as possible and within a maximum of thirty days from the date of receipt. In order to respond to the applications made by data subjects, the Company may request additional information and documents to verify the identity of the applicant and to clarify the request. Failure to provide the requested information and documents may result in the Company not being able to respond to the request.

10. MEASURES REGARDING THE SECURITY OF PERSONAL DATA

The Company exercises all reasonable care and diligence to ensure the confidentiality and security of the personal data it processes. In accordance with Article 12 of the KVK Law, the Company also takes all necessary technical and administrative measures at a reasonable level to ensure data privacy and security. With these administrative and technical security measures, it aims to prevent unlawful processing of personal data, prevent unlawful access to personal data, and ensure that personal data is stored with an appropriate level of security.

If personal data is processed by another natural or legal person (data processor) on behalf of the Company, the Company will ensure that the necessary measures mentioned above are also taken by such data processors.

If personal data is unlawfully obtained by third parties, the Company will notify the data subjects, the Board, and other relevant public institutions and organizations in accordance with the provisions of the applicable legislation.

When taking measures regarding the security of personal data, the Company takes into account the "Personal Data Security Guidelines (Technical and Administrative Measures)" published by the Board.