KVKK Disclosure

PERSONAL DATA PROTECTION LAW NO. 6698 (“KVKK”)

INFORMATION AND DISCLOSURE NOTICE

KVKK refers to Turkey’s Personal Data Protection Law. In compliance with the Personal Data Protection Law No. 6698 (“Law”) and related regulations, we take utmost care in processing and protecting your personal data. Necessary technical and administrative measures are implemented to prevent unlawful processing of personal data, unauthorized access, and to ensure the safeguarding of personal data as required by applicable legislation.

Due to your visits to our website www.gumusarslan.com, filling out forms containing personal data on our site, or contacting our company, your personal data is processed in accordance with the principles outlined in Article 4 of the Law. You can review our Privacy and Cookie Policy published on our website.

In accordance with Article 10 of the Law and the Communiqué on the Procedures and Principles for Fulfilling the Disclosure Obligation, this disclosure notice is prepared to inform our employees, suppliers, business partners, customers purchasing products or services, potential customers, and third parties visiting our website. Additional disclosure notices tailored to specific groups can be obtained from our authorized departments.

1. DATA CONTROLLER

Your personal data is processed by Gümüş Arslan General Machinery Manufacturing Energy and Heating Systems Industry and Trade Limited Company (“Gümüş Arslan”) as the “Data Controller” as defined in Article 3 of the Personal Data Protection Law No. 6698 (“Law”).

2. PURPOSES OF PROCESSING PERSONAL DATA

Your personal data is processed in accordance with the principles set out in Articles 4, 5, and 6 of the Law for the following purposes:

  • Informing relevant parties about our products within the scope of company activities, sustaining corporate development activities, and conducting promotional and marketing activities.
  • Facilitating communication activities through our website, fulfilling special machine design and production activities, and managing order acceptance, production, and shipment processes for machinery manufacturing and solutions.
  • Maintaining the company’s financial, accounting, administrative, legal, and technical processes, making necessary notifications to relevant public institutions as required by law, and fulfilling legal obligations.
  • Ensuring customer satisfaction and managing customer requests and complaint processes.
  • Planning and executing human resources processes, processing job applications, creating personnel files for employees, and fulfilling financial obligations.
  • Establishing and performing contracts with the company’s customers, potential customers, business partners, suppliers, service providers, employees, consultants, and related third parties.
  • Providing evidence in legal disputes, facilitating communication with real and legal entities in legal relations with the company, ensuring corporate quality, and securing the safety of relevant parties.
  • Managing processes necessary for using our website and filling out forms on our website.
  • Conducting sales transactions, tracking sales, performing banking operations, and processing payments via checks, promissory notes, credit cards, and other commercial payment instruments for products and services.
  • Ensuring the physical security of the company’s buildings and facilities, controlling entry and exit, managing employment contracts, and ensuring continuity and oversight in the company’s interest.
  • Managing product delivery, tracking, shipment processes, customs operations, and foreign trade-related activities.

3. CATEGORIES OF PROCESSED PERSONAL DATA

Identity Information: (For employees, interns, and job applicants: ID number, name, surname, place and date of birth, parents’ names, spouse, children, family relationship information, marital status, gender, and identity details on shared official documents.)

Contact Information: (For customers, suppliers, business partners, employees, interns, job applicants, and related third parties: phone number, fax number, address, email address.)

Personnel Information: (For employees: employment contract, education, diploma, certificate details, SGK registration and termination notices, family allowance form, information on dependents, spouse, children, family identity and registry details, equipment receipt forms, work certificates, resignation, termination, severance and notice pay slips, payroll details, SGK records, service history, resume, leave details, performance evaluation reports, workplace accident details, job application form details, references, military service status, bank account details, IBAN; for job applicants: details on job application forms; for interns: details in internship files.)

Legal Transaction Information: (For parties in legal relations with the company: personal details in correspondence with judicial authorities, mediation, labor courts, other courts, enforcement files, and investigation details.)

Customer, Supplier, Service Provider, Business Partner Transaction Information: (For individuals: name, surname, ID number, tax number, tax office, chamber registration, address, location, email, phone, bank account details, payment details for checks, promissory notes, credit cards, financial details, invoices, delivery notes, product order requests, authorization, signature circulars, marketing, transaction security, risk management details, profession, role, title, visual photo details on shared documents, personal details on official identity documents; for legal entities’ representatives and employees: identity, contact, role, profession, title details, visual and audio recordings, legal and transaction security details.)

Physical Space Security Information: (For customers, potential customers, suppliers, service providers, business partners, legal entity representatives, employees, interns, job applicants, visitors, and third parties: camera recordings in the company’s buildings, parking lots, and facilities; for employees: workplace entry and exit records.)

Transaction Security Information: (For employees: usernames and passwords for software, hardware, and applications, log records, website entry and exit records; for customers: project tracking details.)

Financial Information: (For customers and suppliers: invoices, tax ID number, tax office, bank account number, IBAN, credit card details, checks, promissory notes, mail orders, payments, insurance policies, contract details, asset details, bank and current account details, financial details reported to public institutions; for employees, interns, shareholders: bank account details, IBAN, declarations, other financial details.)

Professional Experience Information: (For employees, interns, job applicants: education, professional courses, work experience, diplomas, professional life, references, in-service training, certificates, professional qualifications, other professional details in forms; for shareholders, customers, business partners, suppliers, service providers, public institution representatives: role, title, profession, registration, expertise, education, diplomas, certificates, qualifications.)

Visual and Audio Records: (For relevant parties: photos on filled forms, diplomas, certificates, shared documents, official records, visual recordings for job applications or company activities as needed.)

Health Information: (For employees and job applicants: health details in job application forms, health reports, general health test results, HES code, infectious disease details, blood type, lab results, personal health, and disability details.)

Criminal Conviction and Security Measures Information: (For employees and shareholders/partners: criminal records, convictions, judicial status details.)

Information obtained through corporate communication channels, personal details obtained via email, letters, or other communication methods.

4. RECIPIENTS AND PURPOSES OF PERSONAL DATA TRANSFER

Within the scope of this disclosure notice, your personal data may be transferred for the purposes listed in Section 2, limited to: company representatives, suppliers, service providers, health institutions and insurance companies for employee health data, banks and financial institutions for financial transactions, software, hardware, IT, and technology companies for the installation, maintenance, and repair of computer systems and programs, and, for sensitive personal data transfers within Turkey, to real or legal entities with explicit consent as permitted by law. In legal disputes, data may be transferred to prosecutors, courts, enforcement offices, customs authorities, tax offices, SGK, and other authorized public institutions as required by law, limited to the conditions and purposes specified in Article 8 of the Law.

5. INTERNATIONAL DATA TRANSFER

In accordance with the principles in Article 4/2 of the KVKK, personal data may be transferred abroad with explicit consent obtained via “Consent Forms” or, in cases specified in Articles 5/2 and 6/3 of the Law, without explicit consent, subject to the rules in Article 9. Transfers will occur only to countries deemed to have adequate protection by the Personal Data Protection Board (“Board”) or, for countries without adequate protection, to data controllers in Turkey and the relevant country that provide written commitments for adequate protection and obtain necessary Board approvals.

Within the scope of Law No. 6698, identity, contact, and professional details of our representatives and employees may be transferred abroad with explicit consent, limited to fulfilling business activities and communication, to customers, suppliers, and relevant entities.

6. METHODS AND LEGAL BASES FOR COLLECTING PERSONAL DATA

Your personal data is collected for the purposes specified, via verbal, written, or electronic means, including communication, human resources, project tracking, and application forms, personnel file creation, contract execution, accounting, financial, and social rights management, procurement, marketing, planning, quality, and corporate development processes, communication channels (phone, fax, email), website visits, and camera systems for internal and external security at company facilities. Data is processed and collected fully or partially automatically or non-automatically as part of a data recording system.

Your personal data is processed based on one or more conditions in Article 5(2) of the Law, including: explicit consent (Article 5/1), explicit legal provisions (Article 5/2(a)), necessity for contract establishment or performance (Article 5/2(c)), mandatory legal obligations (Article 5/2(ç)), necessity for establishing, exercising, or protecting rights (Article 5/2(e)), or legitimate interests of the data controller without harming fundamental rights (Article 5/2(f)). For special categories of data, processing may occur without consent for public health, medical diagnosis, treatment, or healthcare financing by authorized entities (Article 6/3), in compliance with Articles 5 and 6 of the Law and Article 5/1(h) of the Communiqué on Disclosure Obligations.

7. RIGHTS OF THE DATA SUBJECT (APPLICATION RIGHTS)

Under Article 11 of the Personal Data Protection Law No. 6698, you can submit requests regarding your rights as per the Communiqué on the Procedures and Principles for Applications to the Data Controller. Contact Gümüş Arslan General Machinery Manufacturing Energy and Heating Systems Industry and Trade Limited Company (“Gümüş Arslan”) at Dumlupınar Mahallesi Selçuk Caddesi No: 9 Nilüfer Bursa Türkiye, by completing the APPLICATION FORM on our website, sending an email to our corporate email info@gumusarslan.com, our registered electronic mail (KEP) gumusarslangenelmakine@hs01.kep.tr, or via notary.

Requests will be processed as soon as possible, within thirty days at the latest, subject to the processing fee specified in Article 7 of the Communiqué, and responded to in writing or electronically.

GÜMÜŞ ARSLAN GENERAL MACHINERY MANUFACTURING ENERGY AND HEATING SYSTEMS INDUSTRY AND TRADE LIMITED COMPANY

Address: Dumlupınar Mahallesi Selçuk Caddesi No: 9 Nilüfer Bursa Türkiye

Phone/Fax: +90 224 411 23 08 / +90 224 411 23 11

Email: info@gumusarslan.com

KEP: gumusarslangenelmakine@hs01.kep.tr

Website: www.gumusarslan.com

logo-dark