1. Scope
This Personal Data Processing Policy (the “Policy”) covers all departments, units and employees of the organisation, together with the third parties, involved in the processes in which Tecmony processes personal data.
This Policy covers all retention and destruction activities Tecmony applies to personal data.
This Policy applies solely to the destruction and retention of personal data.
Should the Law, the Regulation or other legislation be amended, revised, updated or repealed in whole or in part, the organisation will update and amend the Policy so as to comply with the new provisions.
2. Definitions
- Recipient group
- The group of natural or legal persons to whom personal data is transferred by the data controller.
- Relevant user
- Persons who process personal data within the data controller’s organisation, or in line with the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.
- Destruction
- The erasure, elimination or anonymisation of personal data.
- Law
- Law No. 6698 on the Protection of Personal Data.
- Recording medium
- Any medium containing personal data processed by wholly or partly automated means, or by non-automated means provided that it forms part of a data recording system.
- Personal data inventory
- The inventory in which Tecmony associates the personal data processing activities it carries out in connection with its business processes with the purposes of processing, the data category, the recipient group and the group of data subjects; and in which it details the maximum period necessary for the purposes of processing, the personal data envisaged to be transferred abroad and the measures taken concerning data security.
- Board
- The Personal Data Protection Board.
- Periodic destruction
- The erasure, elimination or anonymisation carried out by Tecmony of its own motion at the intervals stated in this Policy, where all the conditions for processing personal data set out in the Law have ceased to exist.
- Registry
- The Data Controllers Registry maintained by the Presidency.
- Data recording system
- The recording system in which personal data is processed, structured according to specific criteria.
- Data controller
- The natural or legal person who determines the purposes and means of processing personal data and who is responsible for establishing and managing the data recording system.
- Regulation
- The Regulation on the Erasure, Elimination or Anonymisation of Personal Data.
3. Purpose and Scope
This Policy applies to the natural or legal persons responsible for the destruction of personal data under the Regulation issued pursuant to Article 7 of the Law, and sets out the principles to be observed by third parties for whom Tecmony is contractually responsible.
Under the Regulation, Tecmony — as a data controller obliged to register with the Registry — is required to prepare this Policy and to act in accordance with it, in order to retain the personal data in its possession in a manner consistent with the personal data inventory and to destroy that data where necessary.
The following principles apply to the retention and destruction of personal data:
The general principles set out in Article 4 of the Law are observed.
Tecmony acknowledges that the preparation of this Policy does not in itself mean that personal data has been destroyed in accordance with the Regulation, the Law and the applicable legislation.
When retaining, erasing, eliminating or anonymising personal data, Tecmony acts in accordance with the general principles in Article 4 of the Law, the technical and administrative measures under Article 12, the provisions of the applicable legislation and the decisions of the Board.
Tecmony undertakes that, during the destruction of personal data processed by wholly or partly automated means or by non-automated means forming part of a recording system, it will comply with this Policy and with the tools, programs and processes applied under it.
Tecmony takes all the minimum technical and administrative measures required by law to ensure the secure retention of personal data and to prevent its unlawful processing and unlawful access to it. Those technical and administrative measures are described in the technical guides prepared for the methods used in the retention and destruction of personal data.
4. Recording Media
- Computers and servers
- Network devices
- Shared and non-shared disk drives used for storing data on the network
- Mobile telephones and all storage areas within them
- Paper
- Microfiche
- Peripherals such as printers and fingerprint readers
- Magnetic tapes
- Optical discs
- Flash memory
5. Circumstances Requiring the Destruction of Personal Data
In the event of a breach within the scope set out below, a Potential Security Breach is deemed to have occurred and Tecmony operates the relevant security breach processes; the related reports and notifications are shared, where deemed necessary, with Tecmony management, the Board and the data subjects concerned. Tecmony’s breach management processes are applied for the purpose of making those reports and notifications.
Non-compliance with the Law
Unless the exceptions to the conditions for processing personal data set out in Articles 5 and 6 of the Law apply, Tecmony does not retain the personal data of persons from whom it has not obtained explicit consent. Where the purpose of processing data processed under an exception or on the basis of explicit consent ceases to exist, and/or the statutory retention periods expire, Tecmony does not retain that personal data and destroys it.
Cessation of the Conditions for Processing Personal Data
Tecmony is responsible for keeping the conditions for processing data current, and shares that responsibility with all employees who process personal data.
Employees do not continue processing data where the conditions for processing have ceased to exist. Such circumstances are identified by the KVKK Committee upon the recommendation of the relevant business unit, and destruction is carried out in accordance with this Policy.
Tecmony accepts that the conditions for processing data have ceased to exist in the circumstances listed below, which are also set out in the Regulation:
- Amendment or repeal of the provisions of the applicable legislation on which the processing of personal data is based;
- The contract between the parties never having been concluded, being invalid, terminating automatically, being terminated or being rescinded;
- The purpose requiring the processing of personal data ceasing to exist;
- The processing of personal data being contrary to the law or to the rule of good faith;
- Where processing is carried out solely on the basis of explicit consent, the withdrawal of that consent by the data subject;
- Acceptance of an application duly made by the data subject concerning the processing activity within the framework of the rights under subparagraphs (e) and (f) of Article 11 of the Law;
- Where Tecmony rejects an application made to it by the data subject requesting the destruction of their personal data, where the response given is found insufficient, or where no response is given within the period prescribed in the Law: the lodging of a complaint with the Board and the Board finding that request justified;
- The absence of any condition justifying the retention of personal data for a longer period, despite the expiry of the maximum period requiring its retention.
6. Destruction of Personal Data
Personal data may be destroyed in three different ways, explained in detail below: erasure, elimination or anonymisation.
During the destruction of personal data, the KVKK Committee decides in writing on the method to be applied, in line with the information provided by the owners of the information systems and applications in which the personal data is held and depending on the reason for destruction. Pursuant to that written decision, one of the destruction methods in section G) of this Policy is applied in accordance with the Board’s published Guidelines on the Erasure, Elimination and Anonymisation of Personal Data.
Tecmony also prepares technical guides on the methods to be used for the retention and destruction of personal data and ensures their application.
Monitoring the destruction of personal data is the responsibility of the relevant data-owning business unit within Tecmony. The data-owning business unit receives support from other units of Tecmony, with supervision remaining its own.
Erasure of Personal Data
The erasure of personal data processed by wholly or partly automated means is the process of rendering that personal data inaccessible and incapable of being reused in any way by the relevant users.
In the erasure of personal data forming part of a data recording system and processed by non-automated means, the personal data subject to erasure is identified taking the statutory retention periods into account. Tecmony updates its role and authority matrices for its information systems and applications in terms of access and authorisation for personal data, and identifies the relevant users. The access, restoration and reuse rights and methods of the relevant users are determined within this scope.
Where Tecmony Yazılım Bilişim ve Danışmanlık Hizmetleri Limited Şirketi erases personal data, it renders that data inaccessible and incapable of being reused in any way. In doing so, it guarantees that the data is inaccessible and cannot be reused by any user.
Elimination of Personal Data
The elimination of personal data is the process of rendering personal data inaccessible, irretrievable and incapable of being reused by anyone in any way.
Elimination is carried out where Tecmony processes data on physical recording media. Tecmony is obliged to render such data impossible to retrieve.
Anonymisation of Personal Data
By removing or altering all direct and/or indirect identifiers in the relevant data set, Tecmony prevents the identification of the data subject and ensures that the data loses its capacity to distinguish an individual within a group or crowd in a way that could be associated with a natural person.
In anonymising data, Tecmony may use methods such as one-way functions and encryption.
7. Methods and Process for the Destruction of Personal Data
The following methods are applied by Tecmony Yazılım Bilişim ve Danışmanlık Hizmetleri Limited Şirketi for the destruction of personal data.
During destruction, Tecmony selects and applies the appropriate method from those below in accordance with the written decision taken:
Overwriting
The process of rendering earlier data unreadable by writing random data consisting of zeros and ones over magnetic media and rewritable optical media at least seven times by means of software.
Degaussing
The process of rendering the data on magnetic media unreadable by exposing the media to physical change in a high magnetic field.
Physical Destruction
The process of physically destroying optical or magnetic media by melting, pulverising, grinding and similar operations. It may be applied where degaussing or overwriting has failed.
Destruction in the Cloud
The process of destroying all copies of the encryption keys for personal data held on cloud systems, following notification of destruction to the contracted service provider.
Destruction of Personal Data in Peripheral Systems
The destruction to be carried out by applying overwriting, degaussing or physical destruction to the internal unit, where one exists, or otherwise to the entire device, in systems such as printers, fingerprint units and door entry turnstiles that hold personal data. Such destruction must be applied before the devices are subjected to backup, maintenance and similar operations.
8. Retention and Destruction Periods
Periodic Destruction and Statutory Retention Periods
Physical and electronic data whose statutory retention and destruction periods have expired is destroyed periodically. Tecmony carries out destruction of its own motion at six-month intervals.
The statutory retention periods taken as a basis for periodic destruction are determined according to the requirements of the applicable legislation, the provisions of contracts and company policies. Destruction is applied at the first periodic destruction following the point at which the obligation to destroy arises.
All operations relating to destroyed personal data are recorded, and those records are retained for three years.
Destruction upon Request by Data Subjects
Where data subjects apply to Tecmony requesting the destruction of their personal data, Tecmony checks the current status of the conditions for processing that data. Following that check:
- If it is established that all conditions for processing the personal data have ceased to exist, the personal data subject to the request is destroyed within thirty days at the latest, in accordance with the decisions and methods set out in this Policy, and the data subject is informed.
- If it is established that the conditions for processing have ceased to exist and that the personal data subject to the request has been transferred to third parties, Tecmony notifies the third party concerned and ensures that the necessary operations are carried out by that third party within the scope of the Regulation.
- If not all conditions for processing the personal data have ceased to exist, Tecmony may reject the request, explaining its reasons, and notifies the data subject of that rejection in writing or electronically within thirty days at the latest.
The process for the Management of Requests and Complaints from Data Subjects is operated within Tecmony for the purpose of meeting and responding to requests from data subjects.
9. Authorisation in Retention and Destruction Processes
- KVKK Committee: meets once a month, chaired by the Information Security Team Leader. It decides on policies and methods concerning the retention and destruction of personal data in cooperation with the relevant business units, ensures that the Policy and its annexes are kept up to date and, where necessary, works closely with Tecmony’s Process Management and other units to ensure that the Policy is carried out correctly and in compliance with the Law and the Regulation.
- Information technologies: ensures that the relevant destruction and retention processes are carried out in compliance with the Law and the Regulation, in the light of the decisions and methods set out in the Policy.
- Relevant business units: state their opinions and reasoning for determining the policies and methods concerning the retention and destruction of personal data, and follow up the actions carried out under this Policy.
10. Amendments to the Policy
Tecmony shares the updated Policy with its employees by e-mail, in a manner allowing the amendments it has made to be reviewed, and makes it available to its employees over the corporate intranet.
11. Effective Date of the Policy
This Policy entered into force on 10 May 2026.
This is an English translation provided for convenience. In the event of any discrepancy, the Turkish text of the Policy prevails.