Personal Data Retention and Disposal Policy
LOGIN
1.1. Aim
Personal Data Retention and Disposal Policy (Policy) has been prepared in order to determine the procedures and principles regarding the storage and destruction activities carried out as İnce Smile Oral and Dental Health Polyclinic (Company).
Company; In line with the procedures and principles determined within the scope of the Personal Data Protection Law (KVKK) and relevant legislation, and its own mission, vision and basic principles; Personal data belonging to company employees, employee candidates, service providers, visitors, product or service buyer, potential product or service buyer, supplier employee, supplier official and other third parties It has adopted as a priority to ensure that it is processed in accordance with its Constitution, international conventions, KVKK No. 6698 and other relevant legislation and that the relevant persons use their rights effectively.
Work and transactions regarding the storage and destruction of personal data are carried out in accordance with the policy prepared by the company in this direction.
1.2. Scope
Personal data belonging to company employees, employee candidates, service providers, visitors, product or service buyer, potential product or service buyer, supplier employee, supplier official and other third parties are within the scope of this policy, and all personal data owned or managed by the company are processed. This policy is applied in recording environments and activities related to personal data processing.
1.3. Abbreviations and Definitions
Recipient Group: The natural or legal person category to which personal data is transferred by the data controller
Explicit Consent: Consent on a specific subject, based on information and expressed with free will.
Anonymization: Making personal data impossible to associate with an identified or identifiable natural person under any circumstances, even by matching with other data.
Employee: Company personnel
Electronic Media: Environments where personal data can be created, read, changed and written with electronic devices.
Non-Electronic Media: All written, printed, visual etc. other than electronic media. other environments.
Service Provider: A natural or legal person who provides services within the framework of a specific contract with the Personal Data Protection Authority.
Relevant Person: The natural person whose personal data is processed.
Relevant User: Persons who process personal data within the organization of the data controller or in line with the authorization and instruction received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.
Destruction: Deletion, destruction or anonymization of personal data.
Law: Law on Protection of Personal Data No. 6698.
Recording Media: Any environment where personal data is processed wholly or partially automatically or non-automatically, provided that it is a part of any data recording system.
Personal Data: Any information relating to an identified or identifiable natural person.
Personal Data Processing Inventory: Personal data processing activities carried out by data controllers depending on their business processes; The inventory, which they have created by associating the personal data processing purposes and legal reason, the data category, the transferred recipient group and the data subject group, by explaining the maximum storage period required for the purposes for which the personal data is processed, the personal data to be transferred to foreign countries, and the measures taken regarding data security.
Processing of Personal Data: Obtaining, recording, storing, storing, changing, rearranging, disclosing, transferring, taking over, making available, classifying personal data by fully or partially automatic or non-automatic means provided that it is a part of any data recording system. or any kind of operation performed on the data, such as preventing its use.
Board: Personal Data Protection Board
Sensitive Personal Data: Data about the race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, disguise and dress, membership to associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and biometric data. and genetic data.
Periodic Destruction: The deletion, destruction or anonymization process that will be carried out ex officio at repetitive intervals and specified in the personal data storage and destruction policy, in case all the conditions for processing personal data in the law are no longer valid.
Policy: Personal Data Retention and Disposal Policy
Data Processor: The natural or legal person who processes personal data on behalf of the data controller, based on the authority given by the data controller.
Data Registration System: A registration system in which personal data is processed and structured according to certain criteria.
Data Controller: Processing of personal data