Personal Data Protection

Protecting personal data with transparency, security, and responsibility.

RECYLOOP SÜRDÜRÜLEBİLİR AMBALAJ A. Ş.

PERSONAL DATA PROTECTION
AND

PROCESSING POLICY

Personal Data Protection and Processing Policy

Document Name

Personal Data Protection and Processing Policy

Legal Basis

Personal Data Protection Law No. 6698, the Regulation on the Erasure, Destruction or Anonymization of Personal Data, and other applicable legislation.

Document Scope

This document explains the principles adopted for carrying out personal data processing activities under Personal Data Protection Law No. 6698 and the main policies adopted for compliance with the Law.



RECYLOOP SÜRDÜRÜLEBİLİR AMBALAJ A. Ş.

PERSONAL DATA PROTECTION AND PROCESSING POLICY

I. PURPOSE AND SCOPE OF THE POLICY

This Personal Data Protection and Processing Policy (the Policy) concerns all personal data processed wholly or partly by automated means or by non-automated means provided that they form part of a data recording system, within the scope of Personal Data Protection Law No. 6698 (the Law), the Regulation on the Erasure, Destruction or Anonymization of Personal Data (the Regulation), and the practice guides issued by the Personal Data Protection Authority (the Authority). The main purpose of this Policy is to determine the principles regarding the processing and protection of personal data by RECYLOOP SÜRDÜRÜLEBİLİR AMBALAJ A. Ş.

II. DEFINITIONS

Term

Definition

Explicit Consent

Consent relating to a specific matter, based on information, and declared by free will.

Relevant User

Persons who process personal data within the data controller organization or under the authorization and instruction received from the data controller, excluding the person or unit responsible for technical storage, protection, and backup of the data.

Destruction

The erasure, destruction, or anonymization of personal data.

Law / KVKK

Personal Data Protection Law No. 6698.

Recording Medium

Any medium containing personal data processed wholly or partly by automated means or by non-automated means provided that it forms part of a data recording system.

Personal Data

Any information relating to an identified or identifiable natural person.

Processing of Personal Data

Any operation performed on personal data, including collection, recording, storage, preservation, alteration, reorganization, disclosure, transfer, acquisition, making available, classification, or preventing use, whether wholly or partly by automated means or by non-automated means as part of a data recording system.

Anonymization of Personal Data

Rendering personal data impossible to associate with an identified or identifiable natural person under any circumstances, even by matching it with other data.

Erasure of Personal Data

Making personal data inaccessible and unusable for Relevant Users in any way.

Destruction of Personal Data

The process of making personal data inaccessible, irretrievable, and unusable by anyone in any way.

Authority

The Personal Data Protection Authority.

Board

The Personal Data Protection Board.

Special Category Personal Data

Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, association, foundation or union membership, health, sexual life, criminal convictions and security measures, and biometric and genetic data.

Periodic Destruction

The recurring erasure, destruction, or anonymization process carried out ex officio at intervals specified in the personal data retention and destruction policy when all processing conditions under the Law cease to exist.

Data Subject / Relevant Person

The natural person whose personal data is processed.

Data Controller

The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.

Regulation

The Regulation on the Erasure, Destruction or Anonymization of Personal Data, published in the Official Gazette on 28 October 2017.

III. PRINCIPLES

RECYLOOP SÜRDÜRÜLEBİLİR AMBALAJ A. Ş. acts in accordance with the following principles for ensuring the security, retention, and destruction of personal data:

a. In ensuring the security of personal data and in erasure, destruction, and anonymization processes, the Company fully complies with the principles listed in Article 4 of the Law, the technical and administrative measures required under Article 12 and stated in this Policy, applicable legislation, Board decisions, and this Policy.

b. The Company processes personal data lawfully, fairly, and proportionately, and takes the necessary measures to ensure that personal data is accurate and, where necessary, up to date.

c. Before processing personal data, the Company determines the purpose of processing. Data subjects are informed within the scope of the Law and, where required, their explicit consent is obtained.

d. The Company processes personal data only where an exception under the Law applies or in line with the purpose covered by the explicit consent obtained from the data subject, and always in accordance with the principle of proportionality.

e. The Company takes the necessary measures to retain personal data only for the period prescribed by applicable legislation or required for the purpose for which it is processed. All erasure, destruction, and anonymization operations are recorded, and these records are kept for at least 10 years, except for other legal obligations.

f. If all processing conditions under Articles 5 and 6 of the Law cease to exist, personal data is erased, destroyed, or anonymized by the Company ex officio or upon the request of the relevant person. Requests are finalized within 30 days at the latest, and the relevant person is informed through the communication channel they specified. If the data subject to the request has been transferred to third parties, this is notified to those third parties and the necessary actions are ensured.

IV. PROCESSING OF PERSONAL DATA

For processing activities that are not based on the explicit consent of the data subject, one or more of the following legal grounds must apply. Explicit consent must relate to a specific matter, be based on information, and be declared by free will. Where the following processing conditions exist, personal data may be processed without explicit consent.

a. Expressly Provided by Law

This condition applies where there is an explicit provision in the laws regarding the processing of the data subject's personal data.

b. Impossibility of Obtaining Explicit Consent

Personal data may be processed where it is mandatory to process the data in order to protect the life or bodily integrity of the person or another person, and the person is unable to declare consent due to actual impossibility or whose consent cannot be deemed legally valid.

c. Direct Relation to the Establishment or Performance of a Contract

This condition may apply where processing personal data is necessary and directly related to the establishment or performance of a contract to which the data subject is a party.

d. Fulfillment of the Company's Legal Obligations

Personal data may be processed where processing is mandatory for RECYLOOP SÜRDÜRÜLEBİLİR AMBALAJ A. Ş. to fulfill its legal obligations.

e. Data Made Public by the Data Subject

Where the data subject has made their personal data public, the relevant personal data may be processed limited to the purpose of making it public.

f. Mandatory Processing for the Establishment or Protection of a Right

Personal data may be processed where processing is mandatory for the establishment, exercise, or protection of a right.

g. Mandatory Processing for the Company's Legitimate Interest

Provided that it does not harm the fundamental rights and freedoms of the data subject, personal data may be processed where processing is mandatory for the legitimate interests of the Company.

V. PROCESSING OF SPECIAL CATEGORY PERSONAL DATA

Concept of Special Category Data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, association, foundation or union membership, health, sexual life, criminal convictions and security measures, and biometric and genetic data are special category personal data.

General Rule: Processing special category personal data without the explicit consent of the data subject is prohibited.

Exceptions and Special Cases: Personal data other than health and sexual life listed in the first paragraph may be processed without seeking explicit consent of the data subject where permitted by law.

RECYLOOP SÜRDÜRÜLEBİLİR AMBALAJ A. Ş. obtains the explicit consent of relevant data subjects when processing and retaining special category data.

Board Requirements: In processing special category personal data, adequate measures determined by the Board must also be taken.

VI. REASONS REQUIRING RETENTION AND DESTRUCTION OF PERSONAL DATA

a. Personal data of data subjects is retained securely by RECYLOOP SÜRDÜRÜLEBİLİR AMBALAJ A. Ş. in physical or electronic media, within the limits set by the KVKK and other applicable legislation, primarily for the continuation of commercial activities, fulfillment of legal obligations, planning and execution of employee rights and benefits, management of customer relations, execution of marketing activities, recruitment, and creation of personnel files after recruitment.

b. The reasons requiring retention are as follows:

i. Retention of personal data because it is directly related to the establishment and performance of contracts,

ii. Retention of personal data for the establishment, exercise, or protection of a right,

iii. Retention being mandatory for the legitimate interests of the Company, provided that it does not harm the fundamental rights and freedoms of persons,

iv. Retention of personal data for the Company to fulfill any legal obligation,

v. Retention of personal data being expressly provided for by legislation,

vi. Explicit consent of data subjects for retention activities that require such consent.

c. Under the Regulation, personal data of data subjects is erased, destroyed, or anonymized by the Company ex officio or upon request in the following cases:

i. Amendment or repeal of the relevant legislation provisions forming the basis for processing or retaining personal data,

ii. Elimination of the purpose requiring the processing or retention of personal data,

iii. Elimination of the conditions requiring the processing of personal data under Articles 5 and 6 of the Law,

iv. Withdrawal of consent by the relevant person where processing is based solely on explicit consent,

v. Acceptance by the data controller of the relevant person's request for erasure, destruction, or anonymization of personal data within the scope of the rights under Article 11(e) and 11(f) of the Law,

vi. If the data controller rejects the request, gives an insufficient response, or fails to respond within the period prescribed by the Law, the filing of a complaint with the Board and approval of the request by the Board,

vii. Expiry of the maximum retention period for personal data and absence of any condition justifying longer retention.

VII. RETENTION AND DESTRUCTION PERIODS FOR PERSONAL DATA

The following criteria are used by RECYLOOP SÜRDÜRÜLEBİLİR AMBALAJ A. Ş. in determining the retention and destruction periods of personal data obtained in accordance with the KVKK and other applicable legislation:

a. If a period is prescribed in the legislation for retaining the relevant personal data, that period is observed. After the period expires, the data is processed within the scope of the following clauses.

b. If the statutory retention period expires or if no retention period is prescribed for the relevant data, personal data is classified as personal data or special category personal data under Article 6 of the KVKK. Personal data identified as special category data is destroyed. For other data, compliance with the principles in Article 4 and the exceptions in Articles 5 and 6 of the KVKK is evaluated, reasonable retention periods are determined, and the data is erased, destroyed, or anonymized when those periods expire.

c. The retention, destruction, and periodic destruction periods determined by the Company are included in the Personal Data Processing Inventory in Appendix 2 of this Policy.

d. Personal data whose retention period has expired is destroyed every 6 months in accordance with the destruction periods in Appendix 2 and the procedures set out in this Policy.

e. All operations relating to the erasure, destruction, and anonymization of personal data are recorded, and these records are retained for at least three years, except for other legal obligations.

VIII. PROCEDURES FOR RETENTION AND DESTRUCTION OF PERSONAL DATA

8.1 RECORDING MEDIA

Personal data of data subjects is securely retained by RECYLOOP SÜRDÜRÜLEBİLİR AMBALAJ A. Ş. in electronic and physical media in accordance with applicable legislation, particularly the KVKK.

8.2 TECHNICAL AND ADMINISTRATIVE MEASURES

The administrative and technical measures taken by the Company within the framework of Article 12 of the KVKK to retain personal data securely, prevent unlawful processing and access, and ensure lawful destruction are listed below.

a. Administrative Measures:

i. The Company prepares a Personal Data Processing Inventory.

ii. Internal access to retained personal data is limited to personnel who need access due to their job description. Whether the data is special category data and its level of importance are also considered.

iii. If processed personal data is obtained by others through unlawful means, the Company notifies the relevant person and the Board as soon as possible.

iv. For sharing personal data, the Company signs framework agreements or adds provisions to existing agreements with the persons to whom personal data is shared in order to ensure data protection and data security.

v. The Company signs framework agreements or adds provisions to existing agreements with institutions and organizations that process personal data on behalf of the data controller in order to ensure data security.

vi. The Company employs personnel knowledgeable and experienced in personal data processing and provides necessary training on personal data protection legislation and data security.

vii. The Company takes measures to improve physical security, including keeping paper documents, servers, backup devices, CDs, DVDs, USB devices, and similar media containing personal data in rooms with additional security measures, keeping them locked when not in use, and recording entry and exit logs.

viii. The Company conducts or has conducted the necessary audits to ensure implementation of the Law within its legal entity and remedies confidentiality and security vulnerabilities identified as a result of these audits.

b. Technical Measures:

i. The Company conducts necessary internal controls within the established systems.

ii. The Company carries out information technology risk assessment and business impact analysis processes.

iii. The Company provides the technical infrastructure and related matrices required to prevent or monitor leakage of data outside the organization.

iv. The Company ensures that backups taken against risks such as damage, destruction, theft, or loss of data can be accessed only by the system administrator.

v. The Company ensures that evidence is collected and securely stored in unwanted events such as system failure, malicious software, denial-of-service attacks, missing or incorrect data entry, breaches affecting confidentiality or integrity, and misuse of information systems.

vi. Where devices containing data must be sent to third parties such as service providers due to malfunction or maintenance, the Company ensures, where technically possible, that the data storage medium is removed and kept securely before dispatch, and that only faulty parts are sent.

vii. The Company ensures regular penetration testing and additional tests when needed to check system vulnerabilities.

viii. The Company ensures that access authorizations of employees in information technology units to personal data are kept under control.

ix. The Company regularly keeps records of all user transactions, including log records.

x. Destruction of personal data is carried out in a manner that is irreversible and leaves no audit trail for recovery.

xi. Pursuant to Article 12 of the Law, all digital media where personal data is stored is protected by encryption or cryptographic methods that meet information security requirements.

8.3 DESTRUCTION PROCEDURES FOR PERSONAL DATA

Personal data obtained by RECYLOOP SÜRDÜRÜLEBİLİR AMBALAJ A. Ş. in accordance with the KVKK and other applicable legislation will be destroyed by the Company ex officio or upon the application of the Relevant Person, using the techniques below, when the purposes for processing personal data under the Law and the Regulation cease to exist.

Techniques for Erasure and Destruction of Personal Data:

a. Erasure of Personal Data:

i. Secure Deletion from Software: Data processed wholly or partly by automated means and retained in digital media is deleted from the relevant software using methods that make it inaccessible and unusable for Relevant Users.

ii. Deleting relevant data in cloud systems by issuing deletion commands, removing the user's access rights to files or directories on central servers, deleting database rows through database commands, or deleting data on portable flash media using appropriate software may be considered within this scope.

iii. If deletion of personal data would cause other data in the system to become inaccessible or unusable, personal data will also be deemed erased if it is archived in a way that cannot be associated with the relevant person, provided that it is closed to access by any other institution, organization, or person, and all technical and administrative measures are taken to ensure access only by authorized persons.

iv. Secure Deletion by an Expert: In some cases, the Company may engage an expert to delete personal data on its behalf. In this case, personal data is securely deleted by the expert so that it cannot be accessed or reused by Relevant Users.

v. Masking Personal Data in Paper Media: Personal data may be physically removed from the document or made invisible with permanent ink in a manner that cannot be reversed or read by technological methods, to prevent use outside the relevant purpose or to delete data requested to be erased.

b. Destruction of Personal Data:

i. De-magnetization: This method corrupts data on magnetic media by passing the media through special devices that expose it to high magnetic fields. If destruction by this method is not successful, the process can be completed only by physically destroying the media.

ii. Physical Destruction: Personal data may also be processed by non-automated means as part of a data recording system. Such data is destroyed physically so that it cannot be used afterwards. Data in paper and microfiche media must be destroyed in this way when no other destruction method is possible.

iii. Overwriting: Overwriting is a data destruction method that makes old data unreadable and unrecoverable by writing random data consisting of zeros and ones at least seven times over magnetic media and rewritable optical media through special software.

iv. During the above processes, the Company fully complies with the KVKK, the Regulation, and other applicable legislation for data security and takes all necessary administrative and technical security measures.

IX. ANONYMIZATION OF PERSONAL DATA

The principles and procedures regarding anonymization techniques used by RECYLOOP SÜRDÜRÜLEBİLİR AMBALAJ A. Ş. are listed below.

Methods of Anonymization That Do Not Create Value Irregularity

i. These methods anonymize retained personal data without changing or adding/removing values, by generalizing a personal data group, swapping values, or removing a specific data or sub-data group from the group.

ii. Variable Removal: After collected data is combined into a dataset, variables with a high descriptive degree are removed to anonymize the dataset.

iii. Record Removal: Data rows that contain uniqueness among the data are removed from the records to anonymize the retained data. For example, if there is only one senior manager in a company, that person's data may be removed from records containing seniority, salary, and gender data of employees at the same level.

iv. Regional Suppression: If a single data item is identifying because it creates a rarely visible combination, hiding that relevant data provides anonymization.

v. Lower and Upper Bound Coding: Values in a data group containing predefined categories are combined based on a specific criterion to anonymize the data.

vi. Generalization: Through data aggregation, multiple data points are aggregated and personal data is rendered impossible to associate with any person.

vii. Methods of Anonymization That Create Value Irregularity: Unlike methods that do not create value irregularity, these methods create distortion by changing certain data in personal data groups. When using these methods, deviations must be applied carefully in line with the expected benefit. The intended utility of the data may continue by ensuring that aggregate statistics are not distorted.

viii. Under Article 28 of the KVKK, where personal data is processed for purposes such as research, planning, and statistics by anonymizing it through official statistics, this falls outside the scope of the Law and explicit consent is not required.

X. OTHER MATTERS

a. In the event of any inconsistency between the KVKK and other applicable legislation and this Policy, the KVKK and other applicable legislation shall prevail.

b. This Policy prepared by RECYLOOP SÜRDÜRÜLEBİLİR AMBALAJ A. Ş. entered into force on 25/10/2024. In case of any amendment to the Policy, the effective date and relevant articles will be updated accordingly. The update table is included in Appendix 1.

APPENDIX 1

UPDATE TABLE

Changes made to this Policy are shown in the table below.

UPDATE DATE

SCOPE OF CHANGES

[•]

[•]

APPENDIX 2

RETENTION AND DESTRUCTION PERIODS TABLE

DATA CATEGORY

RETENTION PERIOD

DESTRUCTION PERIOD

IDENTITY

10 YEARS

In the first periodic destruction period following the end of the retention period

CONTACT

10 YEARS

In the first periodic destruction period following the end of the retention period

LOCATION

10 YEARS

In the first periodic destruction period following the end of the retention period

PERSONNEL RECORDS

10 YEARS

In the first periodic destruction period following the end of the retention period

LEGAL TRANSACTION

10 YEARS

In the first periodic destruction period following the end of the retention period

CUSTOMER TRANSACTION

10 YEARS

In the first periodic destruction period following the end of the retention period

PHYSICAL PREMISES SECURITY

2 MONTHS

In the first periodic destruction period following the end of the retention period

TRANSACTION SECURITY

10 YEARS

In the first periodic destruction period following the end of the retention period

RISK MANAGEMENT

10 YEARS

In the first periodic destruction period following the end of the retention period

PROFESSIONAL EXPERIENCE

10 YEARS

In the first periodic destruction period following the end of the retention period

VISUAL AND AUDIO RECORDS

2 MONTHS

In the first periodic destruction period following the end of the retention period

HEALTH INFORMATION

10 YEARS

In the first periodic destruction period following the end of the retention period

CRIMINAL CONVICTIONS AND SECURITY MEASURES

10 YEARS

In the first periodic destruction period following the end of the retention period

BIOMETRIC DATA

10 YEARS

In the first periodic destruction period following the end of the retention period