AGEMAR GLOBAL LOJ. DEN. TUR. PAZ. VE TIC. A.S.
SECTION 1 – PURPOSE OF THE POLICY
The right to the protection of personal data is set out in Article 20 of the Constitution of the Republic of Turkey as follows.
“Everyone has the right to demand respect for his or her private and family life. The privacy of private and family life shall not be violated. (Additional paragraph: 12/9/2010-5982/2)
Everyone has the right to request the protection of personal data concerning him or her. This right includes being informed about personal data concerning oneself, accessing such data, requesting their correction or deletion, and learning whether they are used in accordance with their purposes.
Personal data may be processed only in cases prescribed by law or with the explicit consent of the person concerned.
The principles and procedures regarding the protection of personal data shall be regulated by law.”
Law No. 6698 on the Protection of Personal Data, which aims to protect the fundamental rights and freedoms of individuals during the processing of personal data, was submitted to the Presidency of the Grand National Assembly of Turkey on 18 January 2016 following various amendments to previous drafts, adopted by the General Assembly on 24 March 2016, and entered into force after being published in the Official Gazette dated 7 April 2016 and numbered 29677.
Paragraph (1) of Article 12 of Law No. 6698 on the Protection of Personal Data (the “Law”) provides that the Data Controller is obliged to take all necessary technical and administrative measures to ensure an appropriate level of security in order to:
- prevent the unlawful processing of personal data,
- prevent unlawful access to personal data,
- ensure the preservation of personal data;
and to take all necessary technical and administrative measures to ensure an appropriate level of security for these purposes.
Paragraph (5) further provides that, if processed personal data are obtained by others through unlawful means, the data controller shall notify the relevant person and the Personal Data Protection Board (the “Board”) as soon as possible, and that the Board may, where necessary, announce this situation on its website or by any other method it deems appropriate.
With this Policy, the Company adopts the protection of personal data, which is a constitutional right, as a company policy and undertakes to comply with the Personal Data Protection Law and related legislation and regulations within the scope of its legal and social responsibility.
The purpose of the Personal Data Protection Policy is to raise awareness within the Company regarding the lawful processing and protection of personal data and to establish a sustainable and auditable system to ensure compliance with legislation in all processes.
This Policy explains the principles adopted by the Company in carrying out personal data processing activities and the basic principles for ensuring that such activities comply with the provisions of Law No. 6698 on the Protection of Personal Data (the “Law”), thereby providing the necessary transparency by informing personal data subjects.
SECTION 2 – DEFINITIONS
Certain definitions included in the Personal Data Protection Law and in the Company’s Policy on the Protection and Processing of Personal Data are explained below.
Processing of Personal Data: Any operation performed on personal data, such as obtaining, recording, storing, retaining, modifying, reorganizing, disclosing, transferring, taking over, making available, classifying, or preventing the use of personal data, whether wholly or partly by automatic means or by non-automatic means provided that it is part of a data filing system.
Personal Data Subject: Natural-person customers, employees, employee candidates, suppliers and their employees, partners, and other third-party natural persons within the scope of contracts concluded with the Company whose personal data are processed.
Personal Data: Any information relating to an identified or identifiable natural person.
For example: name and surname, Turkish Republic identity number, e-mail address, residential address, business address, date of birth, place of birth, credit card number, driving licence number, bank account number, passport number, licence number, diploma, and similar information.
Special Categories of Personal Data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, association, foundation or trade union membership, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data, are special categories of personal data.
Data Controller: The person who determines the purposes and means of processing personal data and establishes and manages the data filing system in which data are systematically processed and stored.
Data Processor: A natural or legal person who processes personal data on behalf of the data controller under the authority granted by the data controller.
Explicit Consent: Consent relating to a specific matter, based on information and expressed by free will.
Deletion of Personal Data: The process of making personal data inaccessible and unusable in any way for the relevant users.
Destruction of Personal Data: The process of making personal data inaccessible, irretrievable, and unusable in any way by anyone.
Anonymization: Rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even if matched with other data.
KVKK: The Personal Data Protection Law published in the Official Gazette dated 7 April 2016 and numbered 29677.
KVK Board: The Personal Data Protection Board.
Personal Data Retention and Destruction Policy: The Company’s “Personal Data Retention and Destruction Policy”, which serves as the basis, pursuant to the Regulation on the Deletion, Destruction or Anonymization of Personal Data, for determining the maximum period required for the purposes for which personal data are processed and for carrying out deletion, destruction, and anonymization processes.
Data Controllers Registry: The publicly accessible Data Controllers Registry maintained under the supervision of the Personal Data Protection Board and the Presidency of the Personal Data Protection Authority.
Communique on the Procedures and Principles for Application to the Data Controller: The Communique on the Procedures and Principles for Application to the Data Controller, which entered into force upon publication in the Official Gazette dated 10 March 2018 and numbered 30356.
SECTION 3 – GENERAL PRINCIPLES REGARDING THE PROCESSING OF PERSONAL DATA
The Personal Data Protection Law sets out the following under “General Principles” (Article 4 of the Law):
(1) Personal data may be processed only in accordance with the procedures and principles prescribed in this Law and other laws.
(2) The following principles must be observed in the processing of personal data:
- a) Being processed lawfully and fairly.
- b) Being accurate and, where necessary, up to date.
- c) Being processed for specified, explicit, and legitimate purposes.
ç) Being relevant, limited, and proportionate to the purposes for which they are processed.
- d) Being retained for the period stipulated in the relevant legislation or required for the purpose for which they are processed.
These provisions are included in the Law.
In our Company’s practices, the purposes of processing personal data are clearly set out and included in the data inventory and privacy notices. Data are processed only to the extent limited to purposes connected with business activities.
Necessary measures are taken to ensure that personal data remain accurate and up to date throughout the period in which they are processed.
Our Company retains personal data for the period required for the purpose for which they are processed and for the period prescribed by the legal legislation relevant to the activity.
Where no legal retention period exists, personal data are retained for the period required for the purpose for which they are processed.
SECTION 4 – PROCESSED PERSONAL DATA AND PURPOSES OF PROCESSING
The privacy notices provided to relevant persons include the personal data processed, matched separately by each data category with the processing purpose and legal grounds.
Separate privacy notices have been prepared and implemented for Company customers, employees and employee candidates, consultants, service providers and suppliers, business partners, and visitors in order to inform all relevant persons.
The Data Category headings included in the privacy notices are set out below. The information processed under these categories varies according to business processes and sectors, and different information obtained is processed under the relevant category fields.
Processed data categories:
Identity Information: Information relating to a person’s identity, including name and surname, Turkish Republic identity number, Turkish identity information, tax number, social security number, signature information, vehicle plate number, and information contained in documents such as driving licences, identity cards, and passports.
Contact Information: Telephone number, full address information, e-mail address, internal company contact information (extension number, corporate e-mail address), fax information, and registered electronic mail (KEP) address.
Family Members and Relatives Information: Personal data relating to the personal data subject’s family members (spouse, mother, father, children) and relatives.
Legal Transaction Information: Personal data processed within the scope of determining and following up the Company’s legal receivables and rights, fulfilling its debts, and complying with legal obligations.
Special Categories of Personal Data: Data specified in Article 6 of the Personal Data Protection Law, including employee health data such as blood type, biometric data, disability status, and information on devices and prostheses used.
Financial Information: IBAN, card information, bank name, financial profile, mail order form, credit score, contract information, and tax office number.
Employee Personnel Information: Curriculum vitae (CV), social security number, registry number, position name, department and unit, title, employment start and end dates, insurance entry or retirement allocation number, defence and warning documents/minutes, family-relative data, marriage certificate, spouse and children’s names and surnames, minimum living allowance document, performance evaluation scores, and the name, surname, and telephone number of relatives to be contacted in an emergency.
Information Relating to Criminal Convictions: Information relating to security measures and criminal record information.
Legal Documents: Information in correspondence with judicial authorities and information in case files.
Professional Experience Information: Diploma information, course information, in-service training information, certificates, experience certificates, and licence documents.
Financial Data: Bank account and IBAN number, tax number, bank name, and branch.
Visual Data: Images obtained from camera recordings.
Your personal data obtained and processed in compliance with personal data protection legislation may be transferred to the Company’s physical archives and/or information systems, stored both digitally and physically, and backed up in technological environments outside the Company under the Company’s control with security measures in place.
SECTION 5 – INFORMING AND NOTIFYING THE PERSONAL DATA SUBJECT
One of the most important obligations imposed on data controllers by the Law is the obligation to inform.
This obligation is one of the most important indicators that relevant persons have control and oversight over their personal data.
- The obligation to inform introduced by the relevant article is an obligation for data controllers and, at the same time, a right for natural persons whose personal data are processed.
In accordance with Article 10 of the Personal Data Protection Law, our Company informs personal data subjects at the time personal data are obtained.
In this context, relevant persons are informed of the identity of the data controller, the identity of its representative, if any, the purposes for which personal data will be processed, to whom and for what purposes the processed personal data may be transferred, the method and legal ground for collecting personal data, and the rights of the personal data subject.
The purposes for which personal data will be processed are set out before the personal data processing activity begins.
Pursuant to the first paragraph of Article 5 of the Communique, when fulfilling the obligation to inform, the processing purpose must be specific, explicit, and legitimate.
In the information provided, expressions that are general, vague, or that may create the impression that data could be processed for other possible future purposes are avoided.
The Company does not use personal data outside the activities required by the purpose.
The processing of personal data that are not related to or needed for the achievement of the purpose is avoided.
Purposes are determined on a data-category basis, and the privacy notice states which legal condition under Articles 5 and 6 of the Law the processing of each category is based on, to whom the data may be transferred, and the purposes of transfer.
In accordance with Article 11 of the Personal Data Protection Law, where the personal data subject requests information, the Company provides the necessary information to the relevant person within the prescribed period.
An “Application Response Procedure” has been prepared, and responsible persons have been designated and assigned within the Company, to ensure that responses to applications are provided on time and in accordance with the law.
SECTION 6 – METHOD AND LEGAL GROUND FOR COLLECTING PERSONAL DATA
Personal data are collected from physical and electronic environments in a manner appropriate to our fields of activity, through information processed orally, in writing, on paper, or electronically; visual and audio data obtained through call centre and camera recordings; website applications; information sent by e-mail and KEP; shared financial data; contract information; petitions; legal notifications; correspondence; and information made public by you.
Your personal data are collected and processed on the basis of at least one of the following legal grounds and, where necessary, explicit consent:
Article 5/2-a of the Personal Data Protection Law: “It is expressly provided for by law”,
Article 5/2-c of the Personal Data Protection Law: “Processing of personal data belonging to the parties to a contract is necessary, provided that it is directly related to the establishment or performance of the contract”,
Article 5/2-ç of the Personal Data Protection Law: “It is necessary for the data controller to fulfil its legal obligation”,
Article 5/2-d of the Personal Data Protection Law: “The data have been made public by the person concerned”,
Article 5/2-e of the Personal Data Protection Law: “Data processing is necessary for the establishment, exercise, or protection of a right”,
Article 5/2-f of the Personal Data Protection Law: “Processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the person concerned”,
and, where necessary, on the basis of explicit consent.
Our Company does not collect data without a valid purpose and a valid legal ground or without applying explicit consent where required.
SECTION 7 – PROTECTION OF SPECIAL CATEGORIES OF PERSONAL DATA
Article 6 of the Personal Data Protection Law identifies certain personal data as “special categories” because, if processed unlawfully, they carry the risk of causing victimization or discrimination, and special care must therefore be taken when processing such data.
These data are data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, association, foundation or trade union membership, health, sexual life, criminal convictions and security measures, and biometric and genetic data.
Within the Company, health data and, in certain cases, criminal record documents are retained as special-category data by obtaining explicit consent.
Personnel who may access these special categories of personal data receive confidentiality training, the scope and duration of their access authorizations are determined and periodically audited, and confidentiality agreements are signed.
If the relevant personnel leave employment, their access authorization is immediately revoked.
Physical files containing personal health data kept in employees’ health files are stored in locked areas accessible only by the workplace physician.
All operations performed on special-category data are monitored through transaction logs; security updates for environments containing such data are continuously tracked, and the necessary security tests are conducted regularly.
SECTION 8 – TRANSFER OF PERSONAL DATA
The provisions of Article 8 of the Personal Data Protection Law regarding the transfer of personal data are set out below.
(1) Personal data may not be transferred without the explicit consent of the person concerned.
(2) Personal data may be transferred without seeking the explicit consent of the person concerned if one of the conditions specified in subparagraph (a) of the second paragraph of Article 5 or, provided that adequate measures are taken, in subparagraph (b) of the third paragraph of Article 6 exists.
(3) Provisions in other laws regarding the transfer of personal data are reserved. Data are not transferred abroad without the explicit consent of the person concerned.
Under paragraph 2 of Article 5, personal data may be processed and transferred without seeking the explicit consent of the person concerned where one of the following conditions exists.
- a) It is expressly provided for by law.
- b) It is necessary for the protection of the life or bodily integrity of the person who is unable to express consent due to actual impossibility or whose consent is not legally valid, or of another person.
- c) Processing of personal data belonging to the parties to a contract is necessary, provided that it is directly related to the establishment or performance of the contract.
ç) It is necessary for the data controller to fulfil its legal obligation.
- d) The data have been made public by the person concerned.
- e) Data processing is necessary for the establishment, exercise, or protection of a right.
- f) Processing of data is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the person concerned.
In order to transfer special categories of data, explicit consent of the data subject must be obtained, except for the exceptions set out below pursuant to Article 6 of the Law. Special categories of personal data relating to the health and sexual life of the personal data subject may be transferred without explicit consent only for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and managing health services and their financing, and only by persons under an obligation of confidentiality or by authorized institutions and organizations.
Your personal data may be transferred, for the limited purposes specified in the privacy notices, in accordance with Article 8 of the Personal Data Protection Law, the explicit-consent provision in Article 9, and paragraph 2 of Article 5.
The Company acts in accordance with the provisions of Article 5 of the Law, the provisions of Article 6 regarding the processing of special categories of personal data, the regulations set out in Articles 8 and 9 regarding the transfer of personal data, and the decisions published by the Personal Data Protection Board.
Special-category data are not processed or transferred without obtaining the explicit consent of the data subject.
Your personal data may be transferred, within the scope of the Law and other legislation, to authorized and competent public institutions and organizations for the purpose of fulfilling obligations arising from legislation; to the General Directorate of Security; to supervisory and regulatory authorities for the purpose of providing information in accordance with legislation; to all judicial authorities for use as evidence in legal disputes that may arise between us; to your authorized representatives and attorneys; to banks and financial institutions for financing and payment transactions; to our business partners and group companies for the conduct of our business activities; to company shareholders; to suppliers of goods and services for the conduct of goods, services, and operational processes; and to third parties from whom we receive consultancy, including tax and financial advisers, for the conduct of finance and accounting affairs.
No data transfer abroad is carried out without obtaining the explicit consent of the person concerned.
SECTION 9 – ENSURING THE SECURITY OF PERSONAL DATA
Administrative and Technical Measures Taken to Prevent Unlawful Access to Personal Data and to Store Personal Data in Secure Environments:
The Company has implemented secure infrastructure and security controls that protect the integrity of information and ensure its continuous accessibility. The following technical and administrative measures have been implemented to prevent careless or unauthorized disclosure, access, transfer, or other unlawful access to personal data and to address other risks and threats that may arise.
Technical Measures
The security system protects personal data against all threats while they are held in information systems belonging to individuals.
Among information-security threats, internal threats that may arise from persons working within the organization, whether intentional or unintentional, occupy a very important place.
Taking into account intentional or unintentional threats that may arise from persons working within the organization, the necessary security controls have been implemented in all relevant areas to control access to information and prevent unauthorized access. The Company regularly checks whether employees’ daily activities comply with their authorization profiles.
Access to information systems and user authorization are carried out through security policies based on the access and authorization matrix.
Passwords used by personnel or third parties to access personal data resources are arranged in accordance with the password-setting rules defined for the relevant systems. Complex passwords consisting of combinations of numbers, uppercase letters, lowercase letters, and punctuation marks, which are memorable and do not resemble old passwords, are used.
Through real-time analyses within information-security incident management, risks and threats that may affect the continuity of information systems are continuously monitored.
Risks relating to the prevention of unlawful processing of personal data are identified, technical measures appropriate to these risks are ensured, and technical controls are carried out for the measures taken.
Layered network-security measures have been established against threats that may come from external networks. Layered network-security measures have been established on servers in institutional computer systems against threats that may come from external networks. Antivirus software, firewalls, central management, and control software are used in the Company’s information systems.
A Data Breach Response Plan has been prepared, and an appropriate system and infrastructure have been established, to prevent unlawful acquisition of personal data by others and to notify the relevant person and the Board.
Adequate security measures are taken in physical environments where special categories of personal data are processed, retained, and/or accessed, and unauthorized entry and exit are prevented.
For backup purposes, backups of critical systems are taken periodically and moved to external environments at specified intervals.
The Company takes the necessary measures to ensure that deleted personal data are inaccessible and unusable again by the relevant users.
Administrative Measures:
Employees are trained on the Personal Data Protection Law and other relevant legislation and on taking data-security measures, and confidentiality agreements are signed. A disciplinary procedure containing penal provisions to be applied to employees who fail to comply with security policies and procedures is implemented.
To ensure compliance with the Personal Data Protection Law, data confidentiality, and security measures, data processors and suppliers of goods and services are required to provide undertakings.
Before starting to process personal data, the Company fulfils its obligation to inform the relevant persons and obtain explicit consent where required.
The “Risk and Threats Table”, which addresses intentional or unintentional threats that may arise from persons working within the organization and dangers that may come from external networks, is periodically reviewed by the Data Protection Officer and the measures are updated.
Technical control systems have been established over applications. As data controller, the institution conducts internal systematic periodic audits through the Data Protection Officer.
Audits will be conducted by specialist companies or independent audit firms where deemed necessary.
An “Access and Authorization Procedure” and a “Personal Data Retention and Destruction Policy” have been prepared and implemented to control access to information, prevent unauthorized access, ensure data security, and carry out lawful retention and destruction processes.
SECTION 10 – RETENTION PERIODS FOR PROCESSED PERSONAL DATA
Pursuant to Article 4 of the Law, personal data are retained for the period stipulated in the relevant legislation or required for the purpose for which they are processed, and, if all processing conditions set out in Articles 5 and 6 of the Law cease to exist, they are deleted, destroyed, or anonymized ex officio or upon the request of the data subject.
Where provided for in relevant laws and legislation, the Company retains personal data for the period specified in such laws and legislation.
If no period is prescribed in the legislation regarding how long personal data must be retained, personal data are processed for the period required for the purpose of processing in connection with the services provided by the Company while processing that data, and are then deleted, destroyed, or anonymized.
Where the purpose of processing personal data has ended and the retention periods determined by the relevant legislation and the Company have expired, personal data may be retained, taking legal periods into account, only for the purpose of constituting evidence in possible legal disputes or for asserting the relevant right connected to the personal data or establishing a defence. Personal data are not retained by the Company on the basis of the possibility of future use.
The Regulation on the Deletion, Destruction or Anonymization of Personal Data, which entered into force on 28 October 2017, determines the procedures and principles for deleting, destroying, or anonymizing personal data whose reasons for processing have ceased to exist.
Depending on the processes, the legal retention periods for all personal data processed within the scope of the activities carried out are included on a personal-data basis in the Company’s “Personal Data Retention and Destruction Policy”.
SECTION 11 – OBLIGATION TO DELETE DESTROY AND ANONYMIZE DATA
Article 7 of the Law sets out the principles for the deletion, destruction, and anonymization of personal data. Accordingly, even though personal data have been processed lawfully, if the reasons requiring their processing cease to exist, such data shall be deleted, destroyed, or anonymized by the data controller ex officio or upon the request of the person concerned.
In particular, the following cases are deemed to mean that the conditions for processing personal data have ceased to exist.
Amendment or repeal of the relevant legislative provisions constituting the basis for processing personal data,
The contract between the parties having never been concluded, being invalid, expiring automatically, being terminated, or being rescinded,
The purpose requiring the processing of personal data ceasing to exist,
The processing of personal data being contrary to law or the rule of fairness,
Where personal data are processed solely on the basis of explicit consent, withdrawal of consent by the person concerned,
Acceptance by the data controller of the application made by the person concerned regarding the personal data processing activity within the scope of the rights set out in subparagraphs (e) and (f) of Article 11 of the Law,
Where the data controller rejects the application made by the relevant person requesting deletion or destruction of his or her personal data, the response is found insufficient, or no response is given within the period prescribed by the Law, a complaint is filed with the Board and the Board finds the request appropriate,
Although the maximum period requiring retention of personal data has expired, there is no condition that justifies retaining the personal data for a longer period,
The deletion of personal data is defined as “making the relevant personal data inaccessible and unusable again in any way by the relevant users”.
In this context, where the reasons requiring the processing of data cease to exist and the legal period expires, the data in question are irreversibly deleted from all environments, including backups.
The Data Controller decides which of the techniques for deleting and destroying personal data and anonymizing personal data will be applied.
The personal data subject to deletion are identified. Deletion operations are carried out by previously designated personnel. The authorizations of such personnel are specially arranged. The access authorizations of personnel carrying out deletion operations to restore or reuse the deleted data are removed.
The Data Protection Officer checks that the deletion, destruction, or anonymization of data that must be deleted is carried out in accordance with the law, regulations, and Company policies and procedures, and checks the accuracy of the information records created regarding these operations.
SECTION 12 – RIGHTS OF THE DATA SUBJECT AND EXERCISE OF THESE RIGHTS
AGEMAR GLOBAL LOJ. DEN. TUR. PAZ. VE TIC A.S. (the “Company”) informs personal data subjects of their rights in accordance with Article 10 of the Personal Data Protection Law and guides them on how to exercise these rights. The Company has implemented internal administrative and technical arrangements to evaluate the rights of personal data subjects and to provide them with the necessary information.
Personal data subjects have the following rights pursuant to Article 11 of the Personal Data Protection Law:
- a) To learn whether personal data are processed,
- b) To request information if personal data have been processed,
- c) To learn the purpose of processing personal data and whether they are used in accordance with that purpose,
ç) To know the third parties to whom personal data are transferred in Turkey or abroad,
- d) To request correction if personal data have been processed incompletely or inaccurately,
- e) To request deletion or destruction of personal data within the framework of the conditions set out in Article 7,
- f) To request notification of the operations carried out pursuant to subparagraphs (d) and (e) to third parties to whom personal data have been transferred,
- g) To object to the occurrence of a result against the person himself or herself through analysis of the processed data exclusively by automated systems,
ğ) To request compensation for damage suffered due to the unlawful processing of personal data.
Exercise of the Personal Data Subject’s Rights:
The data subject may exercise the rights specified above in the explanation of Article 11 pursuant to the first paragraph of Article 13 of the Personal Data Protection Law.
Requests may not be made by third parties on behalf of personal data subjects.
For a person other than the personal data subject to make a request, a special power of attorney issued by the personal data subject in favour of the person who will make the application on the matter must be available.
Application to the data controller is regulated under Article 13 of the Law as follows.
ARTICLE 13 – (1) The person concerned shall submit his or her requests regarding the implementation of this Law to the data controller in writing or by other methods to be determined by the Board.
(2) The data controller shall conclude the requests included in the application free of charge as soon as possible and, in any event, within thirty days at the latest, depending on the nature of the request.
However, if the transaction requires an additional cost, the fee in the tariff determined by the Board may be charged.
(3) The data controller shall accept the request or reject it by explaining the reason and shall notify the person concerned of its response in writing or electronically.
If the request included in the application is accepted, the data controller shall fulfil what is required. If the application is caused by the fault of the data controller, the fee charged shall be refunded to the person concerned.
The requests included in your application will be concluded free of charge within thirty (30) days at the latest, depending on the nature of the request. Application methods are included in the privacy notices provided to relevant persons.
The Company may request additional information and documents from the relevant person in order to determine whether the applicant is the personal data subject and may ask the personal data subject questions regarding the matters included in the application.
Pursuant to Article 14 of the Personal Data Protection Law, if the application is rejected, the response is found insufficient, or no response is given to the application within the prescribed period, the personal data subject may file a complaint with the KVK Board within thirty days from the date on which he or she learns of the Company’s response and, in any event, within sixty days from the application date.
SECTION 13 – IMPLEMENTATION OF THE POLICY AND RELATED LEGISLATION
The relevant legal regulations in force regarding the processing and protection of personal data shall primarily apply. In the event of any inconsistency between the legislation in force and the Company Policy, our Company accepts that the legislation in force shall apply.
SECTION 14 – EFFECTIVE DATE
This Policy issued by the data controller is dated …/…/20…. The Policy signed by management is published on the Company’s website, and the Policy is reviewed at least once every year.
Reviewing and updating this Policy is carried out by the Data Protection Officer.

