Datenschutz und Sicherheit KVKK
Data Privacy and Security (KVKK)
Pahsa Energy LTD. ŞTİ. CLARIFICATION TEXT Regarding the Processing of Personal Data within the Scope of Law No. 6698
Information Text on Protection of Personal Data
Pahsa Energy Trade Limited Company respects your privacy and attaches importance to your personal data security. With this awareness, as Pahsa Energy; It is our priority to process and preserve all personal data of all persons associated with Pahsa Energy, including those who benefit from our products and services, in the best possible way and with care. With full awareness of this responsibility, we process your personal data as Data Controller within the scope of the Personal Data Protection Law No. 6698 (“Law”) and relevant legislation, as explained below and within the limits prescribed by the legislation. In this context, this text has been prepared to inform and enlighten you within the scope of the Personal Data Protection Law No. 6698 (“Law”) and other relevant legislation. Information Law; In the processing of personal data, especially the privacy of private life; It was adopted in order to protect the fundamental rights and freedoms of individuals and to regulate the obligations of real and legal persons processing personal data and the procedures and principles to be followed. For this reason, this text explains our obligation to inform under the Law and "Protection of Personal Data and Permission to Share Personal Data" is presented to the information of individuals. Personal Data: It refers to all kinds of information regarding an identified or identifiable natural person. In the justification, a person's being identified or identifiable is defined as making that person identifiable by associating existing data with a real person in any way.
-
Name surname,
-
TC Identification number,
-
Passport number
-
Address,
-
Telephone,
-
System Entry-Exit Times,
-
The areas/products they visited and the transactions they carried out,
-
Digital data kept in databases or files regarding their locations,
-
Documents such as job applications/resumes, order records, where information about people is kept by HR/sales or other units,
-
Place/Date of Birth,
-
Vehicle License Plate,
-
E-Mail Address / IP Address,
-
Image and Sound Recordings,
-
All similar data that makes a person identifiable,
Special Quality: Personal data of special nature are data that, if learned, may cause discrimination or victimization of the relevant person. Therefore, they need to be protected much more strictly than other personal data. Special categories of personal data may be processed with the express consent of the relevant person or in limited cases listed in the Law.
-
Race,
-
Ethnicity,
-
Political Thought,
-
Philosophical Belief,
-
Religious, Sectarian or other beliefs,
-
Disguise and Outfit,
-
Association, Foundation or Union Membership,
-
Health,
-
Sexual Life,
-
Criminal Conviction/Possession Data,
-
Data Regarding Security Measures,
-
Biometric and Genetic Data
Collection and Processing of Your Personal Data Processing of your personal data; It may vary depending on the service or commercial activity provided by Pahsa Energy; Provided that it is part of any data recording system; It refers to all kinds of operations performed on your personal data, such as obtaining, recording, storing, preserving, changing, rearranging, disclosing, transferring, taking over, making available, classifying or preventing the use of your personal data, whether fully or partially, by automatic or non-automatic means. . Your personal data collected by these methods is processed by Pahsa Energy with your explicit consent and within the framework of KVKK's processing conditions of personal data and special personal data; It is created and updated throughout the cooperation of its suppliers, throughout the period in which its customers receive service, and throughout the employment contract period of its employees. In addition, in accordance with the legal regulations and the commercial interests of Pahsa Energy, personal data is stored and protected throughout the retention period. Your general and special personal data are processed by storing and protecting them, including but not limited to the following purposes.
-
Your name, surname, TR ID number, photograph, passport number or temporary TR ID number, place and date of birth, marital status, gender, registry number, criminal record, driver's license, SRC certificate, Psychotechnic and other identity data by which we can identify you,
-
Professional qualification certificates,
-
Your address, telephone number, e-mail address and other contact data,
-
Data regarding your financial CV, your financial data such as your bank account number, IBAN number, credit card information, billing information,
-
Data we obtain through our sales and rental services,
-
Activity certificate, professional chamber registration, etc. obtained within the scope of the execution of the contract. Provide professional data and the signature circular provided if necessary and signature,
-
Your voice call records kept in accordance with facility security standards and your personal data obtained when you contact us via e-mail, letter or other means,
-
If you visit our facilities and offices, your audio camera recordings,
-
If you use the parking lot, provide your vehicle license plate.
-
If you apply for a job at Pahsa Energy, your other personal data, including the CV provided in this regard, and if you are an employee of Pahsa Energy or a related employee, your data necessary for the creation of your personnel file, your association membership data, your service contract and any personal data regarding your aptitude for the job. , your educational background and certificates,
-
Your other data, including your health data and military service information, obtained in order to determine whether you are competent to fulfill the requirements of the job on a permanent basis,
-
Your data regarding the provision and financing of private health insurance and your Social Security Institution data, blood tests obtained to ensure registration with the BES insurance company, etc. Your health information, beneficiary letter regarding the legal heir and other necessary data,
-
Due to Pahsa Energy legitimate interest in tracking business, through systems that control entry and exit times; In order to ensure workplace safety and fulfill our legal obligations, data regarding the tracking of your vehicle and gasoline usage supplied to you, tracking devices we place on vehicles belonging to the Company, and your information received from suppliers,
-
Our data we collect through the cameras we placed in the workplace building and around our facility, in accordance with Pahsa Energy's legal obligation and legitimate interest to ensure workplace safety,
Our Reasons for Processing Your Data Your personal data;
Providing you with the products and services offered by our company,
Carrying out operational activities,
Recommending products and services to our customers that suit your consumption and purchasing motivation,
Carrying out the necessary work with the relevant business unit and business partners,
Ensuring the rights of real persons by providing human resources management by our company,
Taking the necessary steps to enable our company to make, implement and realize commercial decisions,
It is processed in accordance with Articles 5 and 6 of KVKK No. 6698 for the purposes of ensuring the legal security of the real persons with whom we have established business relationships and our company arising from these relationships, and for similar purposes, but not limited to these.
Your Personal Data may be processed by Pahsa Energy, as the Data Controller, without your explicit consent in the following cases:
It is necessary for the protection of the life or physical integrity of the person or someone else who is unable to express his/her consent due to actual impossibility or whose consent is not given legal validity,
It is necessary to process personal data of the parties to the contract, provided that it is directly related to the performance of the contract,
It is mandatory to fulfill our legal obligations as the data controller,
It has been made public by the person concerned,
Data processing is mandatory for the establishment, exercise or protection of a right,
Provided that it does not harm the fundamental rights and freedoms of the person concerned, it may be used for the purposes specified below, based on any of the conditions where data processing is mandatory for the legitimate interests of the data controller.
Your personal data may be processed for the following purposes:
Communicating with you and others as part of the job,
To carry out and ensure the continuation of our commercial and operational activities,
To send you important information about changes to our terms of service, changes to our electronic services and other administrative information,
To provide quality, training and security improvement (for example, regarding recorded or monitored telephone calls to our contact numbers),
Resolving complaints and processing requests for data access or correction,
To comply with applicable laws and regulatory obligations (including those outside your country of residence), including Counter-Terrorism law, and to respond to requests from government and government authorities (including those outside your country of residence),
To manage our infrastructure and business activities and comply with internal policies and procedures, including those in connection with auditing, finance and accounting, billing and collections, IT systems, data and website hosting, business continuity and records, document and print management,
To determine and defend legal rights; to protect our activities or the activities of our business partners, our rights, privacy, security or property and/or your or others' assets and to exercise available remedies or limit our damages,
Conducting market research and analysis, including satisfaction surveys,
To facilitate the social media sharing function,
To personalize your experience with electronic services by providing you with personalized information and advertisements.
To whom and for what purpose the processed personal data can be transferred
Ensuring the legal and commercial security of your collected personal data, our Company and the people who have business relations with our Company,
Carrying out the necessary work by our business units to benefit you from the products and services offered by our company,
Customizing and recommending the products and services offered by our company according to your tastes, usage habits and needs,
It may be transferred to our business partners, legally authorized public institutions and private individuals for the purposes of determining and implementing our company's commercial and business strategies and ensuring the execution of our company's human resources policies, within the framework of the personal data processing conditions and purposes specified in Articles 8 and 9 of the KVK Law.
Institutions and Organizations shared within the country: Police Department, Turkish Ministry of Commerce, Customs Directorate, TOBB, SGK, Mediator, Expert, Insurance Agency, Banks, Court Files, Legal Consultant, Port Management, Notary Publics, Customers, Supplier Companies, Ministry of Transport, Judicial Authorities, Administrative Authorities, ERP (Enterprise Resource Planning), Warehouses, Airline companies, Air and Sea agencies, Reconciliation Office. Institutions and Organizations shared abroad Consulates, Customers, Business Partners, Insurance Agency, Overseas police, Overseas Customs, Overseas Customs agencies, Mail cloud solution, German Federal Protection Board, Method and Legal Reason for Personal Data Collection Your personal data is collected by our Company , is collected from various institutions and organizations in order to carry out our commercial activities based on different legal reasons. Your personal data collected for this legal reason may be processed and transferred for the purposes specified in articles (b) and (c) of this text, within the scope of the personal data processing conditions and purposes specified in Articles 5 and 6 of the KVK Law. The rights of the Personal Data Owner listed in Article 11 of the KVK Law, if you submit your requests regarding your rights as Personal Data Owners to our Company using the methods set out below in this Information Text, our Company will respond to your request free of charge as soon as possible and within 30 (thirty) days at the latest, depending on the nature of the request. will conclude. However, if a fee is stipulated by the Personal Data Protection Board, the fee in the tariff determined by our Company will be charged. In this context, personal data owners;
Learning whether personal data is processed or not,
Requesting information if personal data has been processed,
Learning the purpose of processing personal data and whether they are used for their intended purpose,
Knowing the third parties to whom personal data is transferred at home or abroad,
Requesting correction of personal data in case personal data has been processed incompletely or incorrectly and requesting that the action taken in this context be notified to third parties to whom personal data has been transferred,
Requesting the deletion or destruction of personal data in case the reasons requiring processing no longer exist, even though it has been processed in accordance with the provisions of the KVK Law and other relevant laws, and requesting that the action taken in this context be notified to third parties to whom personal data has been transferred,
Objecting to the emergence of a result that is unfavorable to the individual by analyzing the processed data exclusively through automatic systems,
In case of damage due to unlawful processing of personal data, they have the right to demand compensation for the damage.
In accordance with the 1st paragraph of Article 13 of KVKK No. 6698, you can submit your request to exercise your above-mentioned rights to our Company in writing or by other methods determined by the Personal Data Protection Board. In this context, the channels and procedures through which you can submit your application in writing to our Company within the scope of Article 11 of the KVK Law are explained below. Data Security Pahsa Energy; It protects your personal data in full compliance with all technical and administrative security measures that must be taken within the framework of information security standards and procedures. These security measures are provided at a level appropriate to possible risks, taking into account technological possibilities. A.Administrative Measures Pahsa Energy; While processing your personal data, it ensures data security with the following administrative measures.
-
The security of our facilities is provided 24/7 by a private security company approved by the governorship.
-
All office sections can be accessed with access authorization.
-
A personal data processing inventory has been prepared.
-
All policies, procedures and instructions for information security and data security have been published.
-
Confidentiality commitments have been received from the relevant parties.
-
Risk analyzes have been made and necessary precautions have been taken.
-
Periodic and random audits are carried out through internal audits.
-
The employment contract and Pahsa Energy ethical rules have been signed by the relevant parties. (ANNEX-2 CODE OF ETHICS AGREEMENT)
-
The disciplinary regulation has been notified to the relevant parties. (ANNEX-3 DISCIPLINARY REGULATION)
-
Corporate communication document has been prepared and put into effect.
-
All Pahsa Energy employees were provided with relevant training.
-
Awareness activities are constantly carried out.
B.Technical Precautions Pahsa Energy; While processing your personal data, it ensures data security with the Technical Measures specified below.
-
Firewall is used for internal and external threats.
-
An up-to-date and licensed Anti-Virus program is used to protect against harmful software.
-
For your personal data held in Pahsa Energy, authorization is made through the Authorization Matrix so that only relevant persons can access and process the data electronically.
-
Authorization checks are carried out periodically by privileged account managers.
-
User accounts are managed by encrypting them in Active Directory.
-
With IP and MAC identification in Pahsa Energy, movements in the network are prevented from unauthorized network access by any device.
-
Guest control application is used for security in wireless networks.
-
Penetration tests are performed once a year.
-
FIREWALL with DDOS feature is used for internal and external attack detection and prevention.
-
Log records in accordance with Law No. 5651 and SIEM solutions that alert the data controller in case of any movement while processing personal data that ensure traceability of all data are used.
-
Data classification and data loss prevention software is used for personal data.
-
To protect important data, daily backups are made automatically through the software.
-
Data that needs to be deleted and destroyed is destroyed with the WIPE method.
Data Controller
Data Controller |
Pahsa Energy Ticaret Limited Şirketi |
Address |
Mimar Sinan Mahallesi, Güney Yan Yol Caddesi No : 32 Gebze/Kocaeli TÜRKİYE |
Phone number |
0 262 654 13 15 |
E mail address |
info@pahsaenerji.com |
Exercise of Rights, Application and Communication
Personal Data Protection Law No. 6698 (“KVKK”) gives personal data owners the right to make certain requests regarding the processing of their personal data in Article 11 of this law. In this context, in accordance with the Communique No. 30356 on the Procedures and Principles of Application to the Data Controller, Pahsa Energy Trade Limited Company is obliged to respond to these requests.
In accordance with the first paragraph of Article 13 of the KVK Law; Applications regarding these rights to our company, which is the data controller, must be submitted to us in writing or by the following methods determined by the Personal Data Protection Board ("Board").
Application Method |
Explanation |
Application Made in Person |
In hand-delivered applications, the person's application is accepted only if his/her identity is confirmed. The Pahsa Energy employee who receives the application, after checking the identity, indicates on the form that the identity has been confirmed. (“Information Request Within the Scope of the Personal Data Protection Law” will be written on the envelope.) |
Application Made with E-Signature or Mobile Signature |
The application is made by the relevant person to the Pahsa Energy [info@pahsaenerji.com] e-mail address with an electronic signature and/or mobile signature. With the electronic signature secure electronic signature application on the submitted application form, it is checked whether the file is signed or not and the application is accepted after identity verification. If the signature cannot be verified with the secure electronic signature application or the form is sent with mobile signature, the relevant person is directed to written channels. (The subject line of the e-mail will be written "Personal Data Protection Law Information Request".) |
Application Sent Through Notary Public |
Applications submitted by the relevant person to the Pahsa Energy registered address via a notary are received by the Pahsa Energy Customer Relations Department. ("Information Request within the Scope of the Personal Data Protection Law" will be written on the notification envelope.) |
-
Your applications submitted to us will be responded to within 30 days from the date your request reaches us, depending on the nature of the request, in accordance with the 2nd paragraph of Article 13 of the KVK Law. Our responses will be delivered to you in writing or electronically in accordance with the provision of Article 13 of the relevant KVK Law.
APPLICATION FORM
-
Contact information of the relevant person
Name |
|
Surname |
|
Phone number |
|
T.R. Identification number |
|
Email |
|
Address |
|
-
State your relationship with the company
☐ Customer ☐ Visitor |
☐ Other (please specify): |
Unit/department with which you are in contact with the company: Subject: |
☐ Former Employee (years worked) ☐ Worker |
☐ I Shared a Job Application/Resume Date: |
-
Please state your request below in accordance with Article 11 of the KVKK.
Request No. |
Demand |
Your choice (Please put an X next to your request) |
1 |
I want to know whether your company processes personal data about me. |
|
2 |
If your company processes personal data about me, I request information about these data processing activities. Personal Data Protection Law article 11/1(c) |
|
3 |
If my personal data is transferred to third parties at home or abroad, I want to know about these third parties. Personal Data Protection Law article 11/1 (d) |
|
4 |
I think my personal data has been processed incompletely or incorrectly and I want it to be corrected. Write the personal data you want to be corrected in the "Your Choice" field and send additional documents showing correct and complementary information. (Photocopy of identity card, residence, etc.) Personal Data Protection Law article 11/1 (d) |