Privacy Agreement
GENERAL POLICY ON THE PROCESSING AND PROTECTION OF PERSONAL DATA
1. PURPOSE AND SCOPE OF THE POLICY This General Personal Data Protection Policy ("Policy") sets forth the general principles and guidelines for the processing and protection of personal data processed by Ersoftpos.com (ERSOFT SOFTWARE INFORMATION E-COMMERCE) ("Company") as a data controller, in accordance with the provisions of relevant legislation, primarily the Law No. 6698 on the Protection of Personal Data.
Politika ile Şirketimiz tarafından kişisel verilerin toplanması, saklanması ve aktarılması dahil kişisel veri işleme amaçlarımız ile önemsediğimiz temel ilkeler hakkında, sizleri bilgilendirmeyi amaçladık.
2. DEFINITIONS Explicit Consent Consent given freely and based on informed knowledge regarding a specific matter. Data Subject The natural person whose personal data is processed; the data subject.
Destruction This is the conceptual name for the processes of deleting, destroying, or anonymizing personal data. Law This is the Law No. 6698 on the Protection of Personal Data. Recording Medium Any medium containing personal data processed wholly or partially automatically, or by non-automatic means as part of a data recording system. Personal Data This refers to information relating to an identified or identifiable natural person (such as identity, contact, and financial data) - Information relating to legal entities (e.g., company name, trade registry number, tax number) is not covered by the Law. Processing of Personal Data This is the general term for any operation performed on personal data, such as obtaining, recording, storing, preserving, modifying, reorganizing, disclosing, transferring, acquiring, making available, classifying, or preventing the use of data, whether wholly or partly automated or non-automated, provided that it is part of a data recording system. Anonymization of Personal Data This is the process of rendering personal data in such a way that it cannot be linked to an identified or identifiable natural person, even when combined with other data. Deletion of Personal Data This is the process of making personal data completely inaccessible and unusable for the relevant users. Destruction of Personal Data This is the process of rendering personal data completely inaccessible, irretrievable, and unusable by anyone. Board This refers to the Personal Data Protection Board.
Institution The Personal Data Protection Authority. Special Categories of Personal Data These are the data listed in Article 6, paragraph 1 of the Law, including race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, clothing, membership in associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. Company In this Policy, Ersoftpos.com (ERSOFT SOFTWARE INFORMATION E-COMMERCE) is the company. Data Inventory This is a personal data processing inventory created in accordance with the Regulation, specifying the activities in which personal data is processed, the purposes of the processing activities, the data subject groups, the types and categories of data being processed, the retention periods of personal data, the recipient groups to whom personal data is transferred (domestic and foreign), and the technical and administrative measures taken for data security regarding the processing, including the transfer of personal data.
Data Controller The data controller is the person (natural or legal person) who determines the purposes and means of processing personal data and manages the place where the data is systematically kept (data recording system). Ersoftpos.com (ERSOFT SOFTWARE INFORMATION E-COMMERCE) is a data controller. Regulation This is the Regulation on the Deletion, Destruction or Anonymization of Personal Data. 3. PROCESSING OF PERSONAL DATA IN ACCORDANCE WITH THE GENERAL PRINCIPLES OF THE LAW Our company primarily acts in accordance with the general principles written in Article 4 of the Law when processing Personal Data. Accordingly, Personal Data is processed only;
1. In accordance with the law and the principle of honesty, 2. With the necessary effort to ensure accuracy and, where necessary, up-to-date information, 3. For specific, clear and legitimate purposes, and 4. In a manner that is relevant to these purposes, limited and proportionate. We process Personal Data for the retention periods we determine according to the above basic principles and the purposes listed below. Accordingly, we generally retain them for the period stipulated in the relevant legislation or for the period necessary for the purpose for which they are processed. Our retention periods and methods of destruction of Personal Data are regulated in our Retention and Destruction Policy. 4. PROCESSING OF PERSONAL DATA BASED ON THE DATA PROCESSING CONDITIONS DETERMINED BY LAW Our company processes personal data in accordance with the basic principles mentioned above; • For the processing activities listed in the Personal Data Processing Inventory, which are also listed in the following Article of this Policy, • Our company processes personal data in accordance with the processing conditions (legality grounds) set forth in Article 6 of the Law, which are also listed below. Accordingly, our company processes personal data within the scope of Article 5 of the Law; • Explicitly provided for in the laws, • Inability to obtain the explicit consent of the Data Subject due to factual impossibility, • The processing of personal data belonging to the parties of a contract is necessary, provided that it is directly related to the establishment or performance of the contract, • It is necessary for the Data Controller to fulfill its legal obligations, • The data has been made public by the Data Subject themselves. • The processing of data is necessary for the establishment or protection of a right, • The processing of data is necessary for the legitimate interests of the Data Controller, provided that it does not harm the fundamental rights and freedoms of the Data Subject, and based on one or more of these processing conditions, and • Where necessary, by obtaining the explicit consent of the Data Subject. Accordingly, the basis for the Personal Data processing activity may be only one of the conditions mentioned above, or more than one of these conditions may serve as the basis for the same Personal Data processing activity.
• Our company processes Special Categories of Personal Data only if one of the processing conditions specified in Article 6 of the Law is met. Accordingly: • The explicit consent of the Data Subject, • The processing of Special Categories of Personal Data other than health and sexual life is provided for in the laws, • For personal data relating to health and sexual life, processing is only permitted by persons or authorized institutions and organizations under an obligation of confidentiality for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and managing health services and their financing.
3. GROUPS OF INDIVIDUALS WHOSE DATA IS PROCESSED BY OUR COMPANY, METHODS OF COLLECTING PERSONAL DATA, AND CATEGORIES OF PERSONAL DATA PROCESSED • Data Subjects/Data Subject Groups and Methods of Collecting Personal Data The data subject groups whose personal data we frequently process and our methods of collecting personal data are shown in general terms in the table below. DATA SUBJECT GROUP WHERE AND HOW PERSONAL DATA IS COLLECTED Dealers / Organized Channel Customers / Dealer and Organized Channel Customer Candidates / Partners, Managers and Related Employees of Dealers and Organized Channel Customers / Sales Points • Personal data is generally collected through face-to-face meetings, business cards or electronic email correspondence, online forms, contact forms or messages sent via social media channels, telephone calls, and mobile applications. • Personal data, such as identity and contact information, of sole proprietorship dealers and customers, as well as partners, managers, and relevant employees of corporate dealers and customers, is also collected through documents presented in or attached to contracts, signature circulars, signature declarations, and power of attorney documents. • Personal data of customers at points of sale is collected through requests and complaints they submit to our company verbally, in writing, or electronically. These requests and complaints are generally sent to our dealers via telephone, fax, postal service, email addresses, contact forms filled out on our website www.Ersoftpos.com, or through our social media channels. Employees / Job Applicants / Subcontractor Employees / Supplier Employees • Personal data of our employees is collected through documents requested from them during the onboarding process, resumes, CVs, education and skills documents and records submitted while they are still job applicants, and answers given to questions asked in person or via telephone interviews. In addition, we may collect personal data from resumes submitted through recruitment portals, selection and placement service providers, private employment agencies, and internal sources, applications sent via contact forms on our website www.Ersoftpos.com, and social media platforms (LinkedIn). • Personal data of subcontractor employees is generally collected through information and documents, most of which are necessary, that we request from the relevant subcontractor company. • Personal data of supplier employees and supplier employees who provide their services by being present at our workplaces are collected only in accordance with legal requirements and/or the purpose and scope of the service, by requesting it from the relevant supplier company and, in some cases, from the employee themselves. Raw Material, Goods and Services Suppliers / Supplier Candidates / • This is generally collected through face-to-face meetings, business cards or electronic email correspondence, contact forms, and telephone calls. • Personal data of our sole proprietorship suppliers and corporate suppliers Supplier Partners, Managers and Related Employees / Farmers • Personal data such as identity and contact information of partners, managers and related employees are also collected through documents submitted in the contract or its annexes, signature circulars, signature declarations, power of attorney, etc. • Personal data of our farmers is generally collected directly from them through the forms they fill out and the documents they share that contain their identity and contact information. Consumers • Ersoftpos consumers can submit their requests, complaints, and suggestions to us verbally, in writing, or electronically through requests they make to our dealers, calls they leave on the line 0 554 891 03 05, contact forms on our websites at www.Ersoftpos.com, and emails they send to bilgi@Ersoftpos.com. During this process, their identity, contact, and request/complaint-type personal data are collected. Blogger / Influencer • We may collect the identity, contact, and visual/audio recordings of bloggers and influencers as long as it remains within the scope of social media promotional activities. www.Ersoftpos.com Website Visitors / Members www.Ersoftpos.com • IP (Internet Protocol) addresses and web logs of users visiting our website, whether they are members or not, are recorded, and their use of our website is facilitated through cookies and pixel tags. • One or more cookies may be sent to facilitate visitors' access to the website and personalize their online experience. Cookies do not record personal data such as name, gender, or address of website users. Data subjects visiting our websites have the option to prevent the use of cookies, choose to receive a warning before cookies are used, or disable or delete only certain cookies by changing their browser settings, if their browser allows it. • Personal data may be collected from sources transmitted online to our company through forms filled out during membership registration and purchases made via www.Ersoftpos.com. Ersoftpos Website Visitors • The IP (internet protocol) addresses and web logs of users visiting www.Ersoftpos.com and our websites are kept, and their use of our website is facilitated through cookies and pixel tags. • One or more cookies may be sent to facilitate visitors' access to the website and to personalize their online experience. Cookies do not record personal data such as name, gender, or address of website users. Data Subjects visiting our websites have the option to prevent the use of cookies, to receive a warning before cookies are used, or to disable or delete only certain cookies by changing their browser settings, if their browser allows it.
5.1. Categories of Personal Data Processed The data categories we process for the groups of individuals mentioned above are listed below. The group of individuals whose personal data is processed most intensively within our organization is our employees. • Identity data, • Contact data, • Personal data, • Professional experience and education data, • Financial and transaction data, • Location data of our suppliers' employees (information on the stations visited), • Legal transaction data, • Risk management data, • Visual and audio data, • Physical security data, • Transaction security data, • Customer transaction data, • Marketing data, • Consumer requests and complaints, • Special categories of data including health data, criminal convictions, criminal records, and fingerprint scan records (biometric data). 1. PURPOSES OF PROCESSING PERSONAL DATA Personal data collected by our company may be processed based on one or more of the personal data processing conditions specified in Articles 5/2 and 6/3 of the Law. Therefore, our company first examines whether the personal data processing activities fall within the scope of one of these conditions. If none of these conditions exist, but data processing is necessary, personal data is processed based on the explicit consent of the Data Subject in accordance with Articles 5/1 and 6/2 of the Law.
In this context, our Company generally processes personal data for the following purposes: • To fulfill all obligations and commitments undertaken pursuant to contracts and applicable legislation, to claim rights, and to perform legal and administrative obligations, • To carry out all the Company's purposes and business activities in general, • To respond to complaints, suggestions, and requests regarding our products or services, • To provide effective customer satisfaction service, • To establish necessary communication with customers and consumers and respond to their requests, • To improve the quality of our products and services, • To establish dealership relationships. • Managing dealer relationships, • Managing dealer evaluation processes, • Planning various events and trips for dealers, • Planning and executing marketing, promotion, advertising, customer service, and communication activities, • Evaluating project and sponsorship requests and establishing and managing sponsorship relationships, • Evaluating and responding to sales point requests, complaints, and suggestions, • Establishing and managing relationships with organized channel customers, • Receiving requests and orders, and handling product procurement and distribution. • Tracking and procuring SİNCAP branded products and fixed assets and materials used in the field, • Following up on processes such as evaluation, reporting, feedback and complaints regarding SİNCAP branded products, conducting field research, • Establishing supplier relationships, • Managing supplier relationships, • Managing payment and evaluation processes for suppliers, • Planning events, organizations and travel for suppliers, • Developing the commercial portfolio by registering individuals who are not in the dealer, customer and supplier portfolio and who are contacting the company for the first time as potential customers and suppliers. • Planning and execution of raw material procurement, • Registration of our farmers and ensuring effective and beneficial commercial relations with them, • Planning and management of our company's training, field activities, events and organizations, • Planning and execution of advertising, promotion and campaigns, shooting of videos and commercials, and their publication in all media (including social media), • Organizing competitions and events (including via social media), • Managing SİNCAP websites, improving services offered to users, and enhancing user experience, • Establishing memberships on SİNCAP websites, recording and updating member information, and monitoring related membership processes. • Performing our contractual obligations such as completing the shopping process, preparing orders, packaging, preparing delivery notes, shipping, and delivery, • Performing post-sales operational processes (returns, product inspection), • Planning and conducting survey and analysis studies, • Announcing campaigns and advantages conducted by our company, conducting advertising communication and product promotion, • Developing our business/commercial activities, • Increasing product quality and variety, • Effective planning and execution of marketing, sales, and distribution activities, • Performing all accounting operations, organizing and maintaining all financial records and documents in electronic or physical form, • Maintaining legal ledgers, issuing invoices, e-invoices, and receipts, evaluating and accepting those submitted to our company, • Maintaining current account and debt-credit records, • Fulfilling all our commitments and obligations arising from financial legislation, • Managing all financial processes, including budgeting, planning, and reporting, • Tracking all debts, receivables, and outstanding payments, making payments, accepting payments, accepting and providing collateral, • Executing and monitoring the company's audit, legal, and financial reporting processes, • Planning, conducting, and auditing quality assurance and quality control processes, • Managing selection and placement processes, • Planning and managing human resources processes such as recruitment, placement, performance management, and career planning, • To fulfill all legal and administrative obligations arising from all current labor and social security legislation, primarily the Labor Law, the Social Security and General Health Insurance Law, the Occupational Health and Safety Law, and the Subcontracting Regulation, • To maintain the necessary follow-up and records within the scope of occupational health and safety rules and principles, and to conduct pre-employment medical examinations, • To establish employment contracts with employees, • To manage employment contracts and to fulfill all our obligations, commitments, and responsibilities as an employer. • Planning employee working hours, work and shift schedules, and leave periods, • Planning employee events and internal and external training programs, • Establishing and strengthening internal communication, planning and executing activities deemed necessary to increase corporate commitment, employee loyalty and satisfaction, • Planning and managing reward/discipline/punishment activities for employees, • Continuously and regularly monitoring and fulfilling employee personnel matters (e.g., preparing monthly payrolls, submitting monthly legal declarations, paying and/or allocating wages and benefits, providing social assistance, monitoring overtime and vacations, monitoring disability cases, etc.) • Planning business trips, • Conducting social responsibility activities, • Ensuring the security of our workplaces, • Registering and announcing the management and signing authorities of our company, preparing signature circulars, and obtaining power of attorney documents, • Managing, monitoring, and completing all processes related to the termination of all legal relationships and contracts to which our company is a party, • Fulfilling the requirements of legal proceedings to which our company is a party or which are served upon our company. • Implementing information security processes, fulfilling legal obligations in this context, ensuring the security of our systems and servers, • Implementing processes such as emergency and risk management, • Implementing information security processes, • Conducting storage and archiving activities, • Ensuring the security of data controller operations, • Fulfilling all our obligations arising from legislation, • Providing information to public authorities on matters relating to public health, safety, and order, • Providing information to authorized persons, institutions, and organizations, responding to requests from relevant official and administrative institutions or judicial authorities, and exercising our right of defense. 2. SECURITY OF PERSONAL DATA We are aware of the importance of protecting and securely processing Personal Data. In this regard, our Company takes the necessary technical and administrative measures to protect the Data Subject against unauthorized access to or loss, misuse, disclosure, alteration, or destruction of Personal Data. Generally accepted security technology standards are used when processing personal data. For this purpose, firewalls and anti-virus programs are used to protect against attacks from environments such as the internet. Cabinets containing documents and files with personal data are locked and can only be opened by authorized personnel. Access to personal data processed within the company is limited to relevant employees in accordance with the defined processing purpose. Company employees, especially unit managers, receive training on the protection of personal data and awareness of the law. Despite taking the necessary technical and administrative measures, in the event that Personal Data is damaged or falls into the hands of third parties, the Company undertakes to immediately notify the Data Subjects and the Personal Data Protection Board and to take the necessary measures. Furthermore, our Company has a Data Breach Response Plan prepared in parallel with the legislation. Our Personal Data Processing Inventory and Storage and Destruction Policy list the administrative and technical measures we take when processing Personal Data. The technical and administrative measures taken by our company are detailed below: 7.1. Technical Measures Taken to Ensure the Security of Personal Data • Policies, procedures, and instructions regarding the security of the company's information are in effect. • Our company conducts penetration tests once a year to determine whether the processed Personal Data is stored in compliance with the Law, relevant legislation, and our company's policies on the protection and processing of Personal Data, and to ensure cybersecurity. • Our company has created a technical infrastructure to prevent the leakage of personal data outside the company and any potential misuse by installing firewalls and antivirus programs on all computers within the company. • The most advanced and high-level filtering, log control, and alert systems are used to ensure information security. • In the event of an external attack, this is immediately reported to the Committee chairman or the nearest member in accordance with our Company's Information Security Policies. Upon notification of such a breach, the Committee immediately intervenes with the Information Systems unit to remedy the breach and makes the necessary notification to the Board as soon as possible. Furthermore, every cyber attack that occurs is regularly reported as part of the identification of security vulnerabilities in the system. • To ensure the security of the company's IT systems, equipment, software, and data, hardware measures are taken against environmental threats (such as restricting access to the server room to authorized personnel only, and providing fire extinguishing and air conditioning systems). • Passwords for company computers used by employees are changed at regular intervals. • Access rights for employees with access to personal data within the company are regularly checked, and access to personal data is only permitted for authorized units or employees. • Personal data is reviewed at regular intervals to ensure its secure storage. • When external services are used for access to company computers, other electronic devices, and backup facilities, high-level security measures are taken regarding service providers' access, and confidentiality commitments are always obtained from third-party service providers. • Security cameras are used for monitoring in company buildings. • Individuals' access to company networks is subject to approval.
7.2. Administrative Measures Taken to Ensure the Security of Personal Data • Our company has created an “Ersoftpos Personal Data Processing Inventory” to analyze the personal data processed within our company based on business processes, data processing units, types of personal data processed, and relevant individuals. This inventory shows the personal data processing activities carried out by our company in accordance with its business processes, personal data categories, units processing personal data, purposes and conditions of personal data processing, and the person/institution to whom the data is transferred. • Our company provides its employees with the necessary training on the lawful processing, secure storage, destruction of personal data, and fulfillment of obligations as a data controller, ensuring that employees are aware of Personal Data Protection. • Personal data collected by our company is only accessible to employees who need access to it as part of their job description. Furthermore, the access rights of these employees are not unlimited and are limited in terms of duration and scope depending on the nature of the data they process. The general or specific nature of the data is also considered when determining employees' access rights to personal data. • Files and folders containing personal data are stored in relevant unit cabinets, drawers, and/or archives in a way that prevents unauthorized access; these cabinets and archive rooms are kept locked. The keys/passwords to the cabinets and rooms where personal data is stored are only held by those authorized to access the relevant data, and unauthorized access to these environments is prevented. Health data, which is a sensitive personal data category, is kept in the infirmary safe. • Our company has established an internal Ersoftpos Personal Data Protection Working Group ("Committee") to ensure coordination within the company regarding compliance with personal data protection legislation and to ensure compliance with the Law in this regard. The Committee is generally responsible for ensuring coordination among the company's units, managing and improving the systems established to ensure that activities carried out within the company comply with personal data protection legislation. • Contracts concluded between our company and employees include provisions and protocols stipulating that, except for exceptions mandated by our company's instructions and laws, personal data will not be processed, disclosed, or used. These provisions also state that individuals to whom personal data is transferred will take necessary security measures to protect personal data and ensure compliance with these measures within their own organizations. • We always process personal data in accordance with the general principles outlined in the relevant article of the Law, within the limits and context of the purposes for which it was collected, and retain it for the necessary periods, within the legally permissible circumstances. These periods are determined primarily by considering the statutes of limitations and forfeiture periods stipulated in the legislation, as well as the periods that may be required to exercise our right of defense, along with periods that can be considered reasonable and legitimate in interest according to the commercial/legal relationship between us or the purpose of storing the Personal Data, and where necessary, with the Explicit Consent obtained from the Data Subject. Our company fulfills its obligation to inform and uses information notices prepared according to the Data Subjects and processing purposes. If the processing condition is Explicit Consent, Explicit Consent is obtained from the Data Subject based on the information provided. • Our company conducts/will conduct necessary audits to ensure the implementation of the laws and regulations and the policies it has put into effect regarding the security of personal data. Our Data Breach Response Plan is ready. • When personal data is transferred to third parties, the necessary provisions are added to the contracts the company makes, and commitments regarding confidentiality and the protection of personal data are obtained from the parties. • Our company conducts/commissions necessary audits to ensure the implementation of the policies it has put into effect regarding the security of personal data in accordance with the provisions of the Law and relevant legislation, and reports any risky situations related to privacy or security that arise as a result of these audits to the Company contact person and the Information Security Officer and intervenes. 7.3. Administrative and Technical Measures Taken to Ensure the Security of Special Categories of Personal Data
Our company processes Special Categories of Personal Data only if one of the processing conditions specified in Article 6 of the Law is met. Accordingly: • The explicit consent of the data subject, • The processing of Special Categories of Personal Data other than health and sexual life is provided for in the laws, • For personal data relating to health and sexual life, processing is only permitted by persons or authorized institutions and organizations under an obligation of confidentiality, for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and managing health services and their financing.
Data falling under the category of Special Categories of Personal Data are processed in accordance with the Board's decision dated 31.01.2018 and numbered 2018/10, "Adequate Measures to be Taken by Data Controllers in the Processing of Special Categories of Personal Data," and by taking adequate security measures. In this context, in addition to the technical and administrative measures listed above; Regarding employees involved in the processing of Special Categories of Personal Data; a. Training b. Confidentiality clauses have been added to employment contracts, and confidentiality commitments are also obtained. c. The scope and duration of access rights for users authorized to access data are defined. d. Periodic access controls are carried out. e. The access rights of employees who change roles or leave the company are immediately revoked. In electronic environments where Special Categories of Personal Data are processed, stored and/or accessed; a. Security updates for the environments where data is stored are continuously monitored, necessary security tests are regularly conducted, and the test results are recorded. b. Security tests of the software used to access the data are regularly conducted and recorded. c. In case of remote access to data, a tiered authentication system is provided. In physical environments where special categories of personal data are processed, stored, and/or accessed;
a. Precautions are taken against electrical leaks, fires, floods, and theft. b. Unauthorized entry is prevented. Data is kept in locked drawers and cabinets. Regarding the transfer of special categories of personal data: a. When data needs to be transferred via email, it will be transferred encrypted using the corporate email address. b. If transfer via portable memory, CD, DVD, etc., it will be encrypted using cryptographic methods, and the key will be kept on a different medium. c. If transfer is carried out between servers in different physical locations, a VPN will be established between the servers for data transfer. d. When transfer of special categories of personal data via paper, the document will be sent with a "high confidentiality" level.
3. TRANSFER OF PERSONAL DATA Our company may transfer your personal data to third parties located within the country, in accordance with Article 8 of the Law, based on the fundamental principles stipulated in the Law and limited to the purposes for which we process your personal data. Accordingly, our company may transfer Personal Data within the country, where necessary, to: Courts and enforcement offices, tax offices, notaries, Social Security Institution The relevant directorates within the Ministry of Trade, the Ministry of Economy and Treasury, the Ministry of Agriculture and Forestry, as well as other ministries and directorates, customs offices, organized industrial zone administrations, commodity and trade exchanges, hospitals and healthcare institutions, plaza and facility/building managements, and other authorized public or private institutions and organizations;
• Legal and human resources consultants, accounting and payroll service providers, e-invoicing, archiving, and warehousing service providers, personnel attendance control system (PDKS) service providers, travel agencies, visa consultants, hotels, transportation companies, banks, private employment agencies, insurance and pension companies, training companies, banks, law firms, and other service providers and auxiliaries; • Information technology companies, digital agencies, market research companies, cargo and logistics service providers, outsourcing, hosting, archiving, storage, IT systems and solutions service providers will be able to transfer this information.
Personal data may be transferred to our foreign subsidiaries, dealers and sales teams in the country related to the request we receive, and servers of our IT systems and solutions located abroad, if required by the processing purposes and our operations, within the conditions set forth in Article 9 of the Law. If we rely on the condition of obtaining "explicit consent" under Article 9 of the Law, the transfer will be made after obtaining explicit consent. Personal data may be shared with authorized persons, institutions, and organizations as necessary for legal obligations, our obligations to public order, and the fulfillment of legal and official requests. Necessary technical and administrative measures will be taken to ensure the security of transfers, and protection and confidentiality commitments will be obtained from the parties to whom the data is transferred. 4. OBLIGATION TO DESTROY PERSONAL DATA In the event that all of the purposes and conditions for processing Personal Data, as set forth in Articles 5 and 6 of the Law and also included in this Policy, cease to exist, our Company will destroy the Personal Data automatically or upon a request received from the Data Subject. The retention periods determined according to the purpose of processing Personal Data, our methods of destruction, and the explanations and details regarding the management of destruction requests received from the Data Subject are included in our Personal Data Storage and Destruction Policy and its Annex, prepared by our Company in accordance with the Regulation on the Deletion, Destruction or Anonymization of Personal Data.
5. RIGHTS OF THE DATA SUBJECT AND THE EXERCISE OF THESE RIGHTS Data Subjects have the following rights pursuant to Article 11 of the Law: 1. To learn whether their personal data is being processed, 2. To request information regarding the processing of their personal data, if it has been processed, 3. To learn the purpose of the processing of their personal data and whether it is being used in accordance with that purpose, 4. To know the third parties to whom their personal data has been transferred domestically/internationally, 5. To request the correction of their personal data if it has been processed incompletely/incorrectly, 6. To request the deletion/destruction of their personal data within the framework of the conditions stipulated in the relevant article of the Law, 7. To request that the third parties to whom their personal data has been transferred be notified of the actions taken pursuant to paragraphs (5) and (6) above.
8. Objection to an outcome that is detrimental to you solely due to the analysis of your personal data by automated systems, 9. Demand compensation for damages incurred as a result of the unlawful processing of your personal data. The relevant persons may submit their requests regarding the rights listed above: 1. By sending a signed document and a photocopy of a valid identity document to the following address: KOCATEPE MAH. YÜKSEL CAD. NO:22/14 KIZILAY/ANKARA 2. By applying in person with a valid identity document 3. By sending a registered electronic mail (KEP) address using a secure electronic signature to our KEP address. 4. The relevant person may submit their request by sending an email to bilgi@Ersoftpos.com from the email address they previously provided to us and which is registered in our system. Applications must include: 1. Name, surname, and signature (if the application is in writing), 2. Turkish Republic identity number if the applicant is a Turkish citizen, nationality information and passport number or foreign identity number if the applicant is a foreign national, 3. Residential or business address for notification purposes, 4. Email address, telephone and/or fax number (if any) for notification purposes, and 5. The requests subject to the application must be clearly stated. Information and documents related to the subject should be attached to the application. Our company reserves the right to request information and documents from the applicant to determine whether the applicant is the Data Subject and to ask the Data Subject questions regarding their application in order to clarify the requests and information contained in the application. Requests will be answered and finalized as soon as possible, in any case within 30 days at the latest. This General Policy on the Processing and Protection of Personal Data has been published on our company's website www.Ersoftpos and made public. In case of any conflict between the provisions in this Policy and the relevant legislation in force, primarily the Law, the provisions of the Law and relevant legislation shall apply. Our company reserves the right to unilaterally change the Policy and to update the Policy periodically and publish the current version in parallel with legal regulations, developments in legislation, Board Decisions and Institution guidelines and recommendations.
Best regards
Ersoftpos.com (ERSOFT YAZILIM BİLİŞİM E-TİCARET)
KOCATEPE MAH. YÜKSEL CAD. NO:22/14 KIZILAY ÇANKAYA/ ANKARA
0(312)809 48 82