Skip to content
Ata Dizayn
LEGAL

Personal Data Protection Policy

Ata Dizayn’s corporate Personal Data Protection Policy: the principles, responsibilities, security measures and data subject rights we rely on when processing and protecting personal data. Board-approved text; the Turkish version is authoritative.

Last updated: 2025-12-18

1. PURPOSE

Every individual’s right to request the protection of personal data concerning them is a sacred right arising from the Constitution. As ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ., we regard fulfilling the requirements of this right as one of our most valuable duties. We therefore attach importance to the lawful processing and protection of your personal data.

This Corporate Personal Data Protection Policy has likewise been prepared, as a consequence of the importance we attach to the protection of personal data, to set out the principles we rely on and the procedures we apply when processing and protecting personal data.

2. SCOPE

The Policy covers every operation performed on all personal data managed by ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ., such as the collection, recording, storage, retention, alteration, reorganisation, disclosure, transfer, takeover, making available, classification or prevention of use of data, whether wholly or partly by automated means or by non-automated means provided that the data forms part of a data filing system.

The Policy relates to all processed personal data of the shareholders, officers, customers, employees, supplier officers and employees, and third parties of ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. may amend the Policy for the purposes of compliance with legislation and the decisions of the Personal Data Protection Authority and of better protection of personal data.

3. DEFINITIONS

  • Recipient Group: The category of natural or legal persons to whom personal data is transferred by the data controller.
  • Explicit Consent: Consent relating to a specific matter, based on information and expressed through free will.
  • Anonymisation: Rendering personal data incapable of being associated in any way with an identified or identifiable natural person, even by matching it with other data.
  • Data Subject: The natural person whose personal data is processed.
  • Relevant User: Persons who process personal data within the data controller’s organisation or in line with the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.
  • Destruction: The deletion, destruction or anonymisation of personal data.
  • Law/KVKK: Personal Data Protection Law No. 6698.
  • Recording Medium: Any medium containing personal data processed wholly or partly by automated means, or by non-automated means provided that the data forms part of a data filing system.
  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Data Inventory: The detailed inventory that data controllers create of the personal data processing activities they carry out in connection with their business processes, associated with the purposes of processing, data category, recipient group and data subject group.
  • Processing of Personal Data: Any operation performed on data, such as the collection, recording, storage, alteration or transfer of personal data.
  • Committee: The Personal Data Protection Committee established by ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. to manage the Policy and related processes.
  • Board: The Personal Data Protection Board.
  • Authority: The Personal Data Protection Authority.
  • Special Categories of Personal Data: Data relating to a person’s race, ethnic origin, political opinion, belief, health, sexual life, criminal convictions, and biometric and genetic data.
  • Periodic Destruction: The deletion, destruction or anonymisation operation to be carried out ex officio at the recurring intervals specified in the policy when the conditions for processing no longer exist.
  • Policy: The Personal Data Protection Policy.
  • Data Processor: The natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the data controller.
  • Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.

4. GENERAL PRINCIPLES

At the preparation stage of every new workflow requiring the processing of personal data, ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. reviews the compliance of the data to be processed with the principles below. Workflows found non-compliant are not implemented.

When processing personal data, ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ.;

  • Complies with the law and the rules of good faith.
  • Ensures that personal data is accurate and, where necessary, up to date.
  • Ensures that the purpose of processing is specific, explicit and legitimate.
  • Checks that the data processed is relevant to the purpose of processing, limited to what is necessary and proportionate.
  • Retains data only for as long as prescribed by the relevant legislation or required for the purpose of processing, and destroys it once the purpose of processing no longer exists.

5. DUTIES AND RESPONSIBILITIES

A Personal Data Protection Committee has been established within ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. to manage this Policy and the other related procedures concerning the processing of personal data and to ensure the Policy remains in force. The Committee is chaired by the General Manager and its members consist of department managers. ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. also obtains KVKK consultancy support where necessary to ensure compliance with Personal Data Protection Law No. 6698. The Committee may invite KVKK consultants and professional experts to its meetings where it deems necessary.

The duties and responsibilities of the Committee are as follows:

  • It meets ordinarily every 6 months. Extraordinary meetings may be held where circumstances require (for example in the event of a possible data breach).
  • It discusses matters in the Policy that need to be amended or improved.
  • It identifies matters that can be fulfilled for the lawful processing and protection of personal data.
  • The Committee determines the steps that can be taken to raise KVKK awareness within the company and among business partners.
  • It identifies the risks that may be encountered in the processing and protection of personal data and takes the necessary administrative and technical measures.
  • It maintains contact with the Authority and manages relations.
  • It evaluates requests received from Data Subjects.
  • It monitors periodic destruction processes.
  • It updates the Data Inventory.
  • It makes assignments in relation to the matters listed above.

6. MEASURES TAKEN FOR DATA SECURITY

ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. takes all necessary technical and administrative measures to ensure an appropriate level of security in order to prevent the unlawful processing of personal data, prevent unlawful access to personal data and ensure the retention of personal data.

6.1. Within the Scope of the Technical Measures Recommended by the Personal Data Protection Authority;

Ensuring Cyber Security

  • Priority measures that can be taken to protect information technology systems containing personal data against unauthorised access threats from the internet;
  • Ensuring that access to systems containing personal data is also restricted, granting employees limited access rights, and providing access to the relevant systems by means of a username and password,
  • Additionally, to protect against malicious software, using products such as antivirus and antispam that regularly scan the information system network and detect threats.

Monitoring Personal Data Security

  • In order to prevent information processing systems from being exposed to attacks from both inside and outside, to cybercrime or to malicious software, and to be able to forestall such situations;
  • Checking which software and services are running on the IT networks.
  • Determining whether there has been any intrusion into the IT networks.
  • Keeping records of the transaction activities of all users (such as log records).
  • Reporting security problems as quickly as possible.

Ensuring the Security of Media Containing Personal Data

  • Ensuring the physical security of devices containing personal data (laptops, mobile phones, flash drives, etc.) where personal data security breaches may occur,
  • Sending personal data to be transferred by e-mail or post with adequate measures in place.
  • To ensure personal data security, keeping paper documents containing personal data, servers, backup devices and devices such as CDs, DVDs and USBs in sections/rooms with additional security measures and restricted entry authorisation.
  • Also taking measures such as keeping these areas locked when not in use and keeping entry and exit records.

Storage of Personal Data in the Cloud

  • Managing the risks relating to the processing of personal data by cloud storage service providers.
  • Assessment and approval by the data controller of whether the security measures taken by the cloud storage service provider are also adequate and appropriate.
  • In this context, knowing in detail what personal data is stored in the cloud, backing it up, ensuring synchronisation and applying authentication controls.

Backup of Personal Data

  • Ensuring that backed-up personal data is accessible only by the system administrator.
  • Always keeping data set backups off the network.
  • Taking measures against the use of malicious software on data set backups.
  • Ensuring the physical security of all backups.

Procurement, Development and Maintenance of Information Technology Systems

  • If devices sent to third parties such as manufacturers, vendors or service providers because they have malfunctioned or are due for maintenance contain personal data, ensuring the security of the personal data before these devices are sent for maintenance and repair.
  • Removing and retaining the data storage medium in the devices.
  • Carrying out procedures such as sending only the faulty parts.
  • If external personnel have come for purposes such as maintenance and repair, preventing them from copying personal data and taking it outside the organisation.

In relation to the requirement to implement these Technical Measures, ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. applies the following technical measures;

  • Authorisation Matrix.
  • Authorisation Control.
  • Access Logs.
  • User Account Management.
  • Network Security.
  • Application Security management.
  • Encryption management.
  • Log Records.
  • Data Masking.
  • Backup management.
  • Up-to-date Anti-Virus Systems management.
  • Deletion, Destruction or Anonymisation.

6.2. Within the Scope of the Administrative Measures Recommended by the Personal Data Protection Authority;

Identifying Existing Risks and Threats

  • To ensure the security of personal data, what all the personal data processed by the data controller is,
  • Correctly determining the likelihood of the risks that may arise in relation to the protection of this data and the losses they would cause if they materialised,
  • Measures appropriate to this must be taken.

Employee Training and Awareness Activities

  • Receiving training on matters such as not unlawfully disclosing or sharing personal data.
  • Carrying out awareness activities for employees and creating an environment in which security risks can be identified, thereby ensuring personal data security.
  • Roles and responsibilities regarding personal data security should be defined in job descriptions, and employees should be made aware of their roles and responsibilities in this regard.
  • Acting in accordance with the principle of “Everything Is Forbidden Unless Permitted” when granting access rights to media containing personal data.

Determining Personal Data Security Policies and Procedures; Minimising Personal Data as Far as Possible; Managing Relations with Data Processors

In relation to the requirement to implement these Administrative Measures, ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. applies the following administrative measures;

  • Preparation of a Personal Data Processing Inventory
  • Corporate Policies (Antivirus, E-mail, Physical Security, Backup, etc.)
  • Contracts (Data Controller – Data Controller / Data Controller – Data Processor Confidentiality Undertakings, etc.)
  • Periodic and/or Random Internal Audits
  • Risk Analyses
  • Employment Contract, Disciplinary Regulations (Addition of Provisions Compliant with the Law, etc.)
  • Corporate Communication (Crisis Management, Processes for Informing the Board and the Data Subject, etc.)
  • Training and Awareness Activities (Information Security and the Law)
  • Notification to the Data Controllers’ Registry Information System (VERBİS)

7. RIGHTS OF THE DATA SUBJECT REGARDING PERSONAL DATA

The data subject may, by applying to ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ., make requests on the following matters:

  • To learn whether their personal data is processed,
  • To request information if their personal data has been processed,
  • To learn the purpose of processing their personal data and whether it is used in accordance with that purpose,
  • To learn the third parties to whom their personal data is transferred domestically or abroad,
  • To request the correction of their personal data if it has been processed incompletely or inaccurately, and to request that the operation carried out in this context be notified to the third parties to whom the personal data has been transferred,
  • To request the deletion, destruction or anonymisation of their personal data if the reasons requiring its processing no longer exist, even though it has been processed in accordance with the KVKK and other relevant legal provisions, and to request that the operation carried out in this context be notified to the third parties to whom the personal data has been transferred,
  • To object to the occurrence of a result against them through the analysis of the processed data exclusively by automated systems,
  • To claim compensation for damage in the event that they suffer damage due to the unlawful processing of their personal data.

8. BREACH NOTIFICATIONS

Employees of ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. report to the Committee any work, action or fact they believe violates the provisions of the KVKK and/or the Policy. Following such a breach notification, the Committee convenes where it deems necessary and draws up an action plan regarding the breach.

If the breach has occurred through personal data being obtained by others through unlawful means, the Committee notifies the data subject and the Board of this situation within 72 hours, within the scope of Board decision No. 2019/10 dated 24.01.2019.

9. AMENDMENTS

Amendments to the Policy are prepared by the Committee and submitted for the approval of the Board of Directors of ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ. The updated Policy may be sent to employees by e-mail or published on the website.

10. EFFECTIVE DATE

This version of the Policy entered into force on 18.12.2025 upon approval by the Board of Directors of ATA DİZAYN KALIP TASARIM PLASTİK İMALAT SAN. TİC. LTD. ŞTİ.