PERSONAL DATA PROTECTION POLICY
1. INTRODUCTION
The protection of personal data is a right safeguarded under the Personal Data Protection Law No. 6698 (the “LAW”) and paragraph 3 of Article 20 of the Constitution of the Republic of Türkiye, and is protected with great diligence by HUN İÇ MİMARİ DANIŞMANLIK SANAYİ VE TİCARET ANONİM ŞİRKETİ (the “COMPANY”). The Company carries out its data processing activities with the necessary care, within the limitations set forth in the relevant laws and legislation.
The fundamental principles set out in Article 4 of the Law are strictly observed in all data processing activities carried out by the Company.
2. PURPOSE OF THE POLICY
The primary purpose of this Personal Data Protection and Processing Policy (the “Policy”) is to establish the procedures and principles to be followed by persons who process data by virtue of their relationship with HUN İÇ MİMARİ DANIŞMANLIK SANAYİ VE TİCARET ANONİM ŞİRKETİ (the “COMPANY”), and to ensure transparency towards persons whose data are processed, by providing explanations regarding the personal data processing activities lawfully carried out by the Company and the systems adopted for the protection of personal data.
The Company conducts its activities in accordance with the Personal Data Protection Law (“KVKK”) and the relevant legislation concerning the protection and confidentiality of personal data, primarily the Constitution of the Republic of Türkiye and the provisions of the international conventions to which Türkiye is a party. The Company approaches the protection of personal data and of fundamental rights and freedoms with great sensitivity, and places fundamental human rights such as the privacy of private life and freedom of thought at the center of all its activities.
3. SCOPE AND APPLICATION OF THE POLICY
This Policy has been prepared in consideration of the applicable regulations and international standards. The Company shall apply this Policy as a priority in all data processing activities, including processing, transferring and modifying data.
The Company also has separate policies addressing the protection of personal data and information security in relation to specific business activities and processes. Unless this Policy contains additional conditions or requires a higher standard for the protection of personal data, it does not override the data protection requirements set out in such other policies of the Company. This Policy is applied together with such other policies and procedures to the extent applicable.
In the event of a conflict between the provisions of the applicable legislation on the protection and processing of personal data and the provisions of this Policy, the current legislative provisions shall prevail.
This “Policy” covers all personal data processed directly or indirectly within the scope of the “COMPANY’s” activities; such data may belong to employees, company executives, visitors, customers and other third parties. Personal data may be processed by automatic means, or by non-automatic means provided that they form part of a data recording system.
4. DEFINITIONS
The definitions provided below are taken from the Regulation on the Registry of Data Controllers, which entered into force under Law No. 6698.
Explicit Consent: Consent relating to a specific matter, based on being informed, and declared with free will.
Anonymization: Rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even when matched with other data.
GDPR: The General Data Protection Regulation of the European Union.
Destruction (İmha): The erasure, destruction or anonymization of personal data.
Contact Person: The natural person notified by the data controller during registration with the Registry, for the communication to be established with the Authority regarding the obligations, under the Law and the secondary regulations issued based on the Law, of legal persons resident in Türkiye and of the data controller representatives of legal persons not resident in Türkiye.
Data Subject (Relevant Person): The natural person whose personal data are processed.
Law No. 6698: The Personal Data Protection Law No. 6698, published in the Official Gazette No. 29677 dated 7 April 2016.
Personal Data: Any information relating to an identified or identifiable natural person.
Processing of Personal Data: Any operation performed on personal data, wholly or partly by automatic means or, provided that the data form part of a data recording system, by non-automatic means, such as collection, recording, storage, retention, alteration, reorganization, disclosure, transfer, takeover, making available, classification, or prevention of use.
Deletion of Personal Data: Rendering personal data inaccessible and unusable in any way for the relevant users.
Destruction of Personal Data: Rendering personal data inaccessible, irretrievable and unusable by anyone in any way.
Board: The Personal Data Protection Board.
Authority: The Personal Data Protection Authority.
Special Categories of Personal Data: Data relating to a person’s race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
VERBİS (Data Controllers’ Registry Information System): The registry system with which natural and legal persons processing personal data must register before commencing personal data processing, and into which they enter categorical information about the personal data they process.
Data Processor: The natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the data controller.
Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.
Data Recording System: The recording system in which personal data are processed by being structured according to specific criteria.
Regulation: The Regulation on the Deletion, Destruction or Anonymization of Personal Data, published in the Official Gazette dated 28 October 2017.
5. INTERNAL KVKK UNITS
In order to ensure the “COMPANY’s” data security, to maintain continuous compliance with the Law and secondary legislation, and to prevent the unlawful processing of data, this Policy states that a “Personal Data Protection Unit” has been established with at least one member of staff assigned from each department (HR, Sales & Marketing, Foreign Trade, Accounting & Finance), and that a Contact Person has been appointed. In this context, …………… has been appointed as the contact person for the personal data processing activities carried out by the Company.
The KVKK Unit is responsible for preparing the personal data processing inventory, drafting agreements, conducting periodic or random internal audits, informing data subjects, updating the Policy when necessary, monitoring new regulations, providing KVKK awareness training to employees, making the necessary notifications to the Data Controllers’ Registry Information System (VERBİS), and taking and implementing the administrative and technical measures determined by the IT Department.
In the fulfillment of these obligations, the matter is reported in writing to the Board of Directors where the Board of Directors is authorized, or to the General Manager where the General Manager is authorized. The necessary actions are taken in line with the requests of the Units, within the financial and technical means of the “COMPANY”.
6. DUTIES, POWERS AND RESPONSIBILITIES OF THE CONTACT PERSON
The Contact Person is not authorized to represent the data controller within the framework of the provisions of the Law and the Regulation. The Contact Person is responsible for facilitating communication in the process of responding to the requests submitted by data subjects to the data controller.
The Contact Person is responsible for carrying out VERBİS registration procedures on behalf of the Company and for conducting relations with the Board. The Contact Person is also obliged to carry out the necessary actions on behalf of the “COMPANY” by evaluating the legal requests of data subjects together with the KVKK unit representatives in the relevant departments.
The Contact Person contributes to the preparation of the “COMPANY’s” Personal Data Processing, Destruction and Erasure policies and monitors the creation of the personal data inventory. Furthermore, the Contact Person works in cooperation with the KVKK unit representatives and other relevant departments in taking the administrative and technical measures for the protection of personal data.
7. GENERAL PRINCIPLES REGARDING THE PROCESSING OF PERSONAL DATA
Personal data are processed by the “Company” in accordance with the procedures and principles set forth in the Law, and the principles below, set out in Article 4 of the Law, are complied with.
Lawfulness and fairness: Data are processed with due regard to the legislation, international standards and the general principles of law.
Accuracy and being up to date where necessary: The Company ensures that data are kept up to date in all processing activities. Incomplete, erroneous or inaccurate data are destroyed or corrected as soon as possible. The Company checks the accuracy of the data at regular intervals.
Processing for specific, explicit and legitimate purposes: The Company determines the purpose of the processing activity before the data processing takes place. Data are processed only for additional purposes compatible with the initial processing purpose. Compatibility with the initial purpose is determined for each additional purpose according to internationally accepted criteria. The Company informs data subjects about its data processing purposes with due regard to the principle of transparency.
Being relevant, limited and proportionate to the purposes for which they are processed: The Company processes only the amount of data necessary for the processing purpose. Data are obtained by the method most appropriate in terms of data privacy and security. In our processing activities, disproportionate interference with the rights, interests and freedoms of data subjects is avoided.
Retention for the period stipulated in the relevant legislation or required for the purpose for which they are processed: Once the purposes of data processing cease to exist, the data are deleted, destroyed or anonymized as soon as possible.
8. CONDITIONS FOR PROCESSING PERSONAL DATA
Personal data may not be processed by the Company without the explicit consent of the data subject. Articles 5 and 6 of the Law set out the cases in which explicit consent is not required; in such cases, personal data may be processed without explicit consent, limited to the purpose of the activity concerned. These cases are as follows:
Where processing is expressly provided for by law.
Where processing is necessary for the protection of the life or physical integrity of the person who is unable to give consent due to actual impossibility or whose consent is not legally valid, or of another person.
Where processing of the personal data of the parties to a contract is necessary, provided that it is directly related to the conclusion or performance of that contract.
Where processing is necessary for the data controller to fulfill its legal obligations.
Where the data have been made public by the data subject himself/herself.
Where processing is necessary for the establishment, exercise or protection of a right.
Where processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.
9. CONDITIONS FOR PROCESSING SPECIAL CATEGORIES OF PERSONAL DATA
Special categories of personal data are specified in the Law by way of examples; these include data relating to a person’s race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health status, sexual life, criminal convictions and security measures, as well as biometric and genetic data. Such data may only be processed with the explicit consent of the data subject.
Special categories of personal data other than those relating to health and sexual life may be processed without the explicit consent of the data subject only in the cases stipulated by law. Personal data relating to health and sexual life, on the other hand, may be processed without the explicit consent of the data subject only by persons under an obligation of confidentiality, for the purposes of the protection of public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of health services and their financing.
Health-related personal data may be processed by the workplace physician or, in the absence of a workplace physician, by the Human Resources (HR) officer in charge of this matter together with the relevant department manager or supervisor. Adequate measures are taken by the Company during the processing of special categories of personal data. Special categories of personal data are kept under a second lock/encryption in physical environments and, as a minimum security measure, under a second password system in digital environments, and may only be accessed by authorized personnel.
10. METHODS OF COLLECTING PERSONAL DATA
Personal data are collected in connection with the Company’s field of activity and for the fulfillment of the purposes set out in this document, through CVs, application forms, employment contracts, agreements, registration/application forms filled in online, receipt and expense documents, information systems, electronic devices, video and audio recording devices, security camera recordings and similar means, in any verbal, written or electronic form, by automatic or non-automatic methods, via the Company’s relevant departments, officers, website, social media platforms and other channels.
Personal data are also collected through the physical delivery of documents, the physical completion of a document provided by the Company, and calls made to the Company’s other telephone numbers.
Personal data are additionally collected by automatic means via https://hunn.com.tr/iletisim/.
11. DELETION, DESTRUCTION OR ANONYMIZATION OF PERSONAL DATA
Even where personal data have been processed in accordance with the Law and the relevant legislation, the Company deletes, destroys or anonymizes personal data, ex officio or upon the request of the data subject, in accordance with the destruction policy in place, where the reasons requiring their processing cease to exist.
Without prejudice to the provisions of the legislation on the deletion, destruction or anonymization of personal data, where a legal obligation requiring that personal data not be deleted exists, the personal data are deleted, destroyed or anonymized once such obligation ceases to exist.
The relevant department officer is responsible for the processes relating to the deletion, destruction and disposal of personal data.
12. TRANSFER OF PERSONAL DATA TO THIRD PARTIES
Personal data are not transferred to third parties without the explicit consent of the data subject.
Personal data may be transferred without the explicit consent of the data subject in the cases set out in the second paragraph of Article 5 and the third paragraph of Article 6 of the KVKK, provided that adequate measures are taken.
Accordingly, personal data are transferred to the persons and institutions indicated in the table below, limited to the stated purposes.
Persons to Whom Data May Be Transferred | Definition | Purpose of Transfer |
|---|---|---|
Business Partners | Institutions and organizations with which the Company cooperates while operating in its field of activity | Limited to ensuring the fulfillment of the purpose for which the partnership was established |
Shareholders | Shareholders authorized under the relevant legislation to design the strategies and audit activities relating to the Company’s commercial operations | Limited to the design of strategies relating to the Company’s commercial operations and to audit purposes |
Suppliers | Suppliers providing services to the Company within the scope of the Company’s activities | Limited to ensuring the provision of the necessary services |
Company Officers | Members of the board of directors and other authorized persons | Limited to the fulfillment of contractual and legal obligations and to audit purposes |
Legally Authorized Private Law Persons | Private law persons legally authorized to obtain information and documents from the Company, such as law firms, notaries and auditors | Limited to the purpose requested within the scope of the activities carried out by the relevant private law persons |
Legally Authorized Public Institutions and Organizations | Public institutions and organizations authorized to obtain information and documents from the Company | Limited to the purpose of requesting information |
13. TRANSFER OF PERSONAL DATA ABROAD
Personal data may not be transferred abroad without the explicit consent of the data subject.
Personal data may be transferred abroad without the explicit consent of the data subject, provided that one of the conditions set out in the second paragraph of Article 5 and the third paragraph of Article 6 of the KVKK exists and that, in the foreign country to which the personal data will be transferred:
adequate protection exists, or
where adequate protection does not exist, the data controllers in Türkiye and in the relevant foreign country undertake adequate protection in writing and the authorization of the Board has been obtained.
14. OBLIGATION TO INFORM
During the collection of personal data, the person(s) authorized by the “COMPANY” are obliged to inform data subjects of:
the identity of the data controller (the Company) and, if any, of its representative,
the purposes for which the personal data will be processed,
to whom and for what purposes the processed personal data may be transferred,
the method and legal basis of collecting the personal data,
the other rights listed in Article 11 of the Law and in Article 15 of this Policy.
This information is provided to data subjects primarily on the “COMPANY’s” website, through the other application channels and in the media where personal data are processed, in a manner visible and readable by everyone, where necessary in a layered manner by directing to the website.
15. RIGHTS OF THE DATA SUBJECT
If, as personal data subjects, you submit your requests regarding your rights to the Company through the methods set out below in this Policy, the Company will conclude the request free of charge within thirty (30) days at the latest, depending on the nature of the request. However, if a fee is prescribed by the Personal Data Protection Board, the fee in the tariff determined by the Company will be charged. In this context, personal data subjects have the right to:
learn whether their personal data are being processed,
request information in this regard if their personal data have been processed,
learn the purpose of the processing of their personal data and whether they are used in accordance with that purpose,
know the third parties to whom their personal data are transferred, in Türkiye or abroad,
request the rectification of their personal data if they are incomplete or inaccurately processed,
request the deletion or destruction of their personal data under the conditions set out in Article 7,
request that the operations carried out pursuant to items (e) and (f) be notified to the third parties to whom their personal data have been transferred,
object to a result arising against them through the analysis of the processed data exclusively by automated systems,
claim compensation for the damage incurred due to the unlawful processing of their personal data.
Data subjects are given the opportunity to apply to the Company regarding their rights arising from the law and listed in this Policy, through the application form available on the Company’s website. Applications made in accordance with the procedure set out in Article 13 of the Law are responded to by the Company within 30 days at the latest, pursuant to Article 13/2 of the KVKK. The Contact Person is responsible for monitoring and managing the processes relating to data subject applications.
You may submit your applications and requests regarding your personal data, using the Data Subject Application Form:
in person, with a wet-ink signature and a copy of your identity document, to the address Gayrettepe Mah. Yıldız Posta Cad. Akın Sitesi No: 8 İç Kapı No: 13 Beşiktaş / İstanbul,
by signing with a secure electronic signature or mobile signature, to the Company’s KVKK e-mail address “hunn@hunn.com.tr”,
through a notary public,
by applying to the Company in person with a valid identity document.
16. ENSURING DATA SECURITY
The “COMPANY” is obliged to take all necessary technical and administrative measures to ensure an appropriate level of security in order to prevent the unlawful processing of personal data, prevent unlawful access to personal data, and ensure the safekeeping of personal data.
Some of the administrative measures taken are as follows:
Disciplinary regulations containing data security provisions are in place for employees.
Training and awareness activities on data security are carried out for employees at regular intervals.
Confidentiality undertakings are executed.
Executed agreements contain data security provisions.
Additional security measures are taken for personal data transferred on paper, and the relevant documents are sent in classified document format.
The necessary security measures are taken regarding entry to and exit from physical environments containing personal data.
The security of physical environments containing personal data against external risks (fire, flood, etc.) is ensured.
Personal data are minimized as much as possible.
Periodic and/or random internal audits are conducted and commissioned.
Data-processing service providers are audited at regular intervals with regard to data security.
Awareness of data-processing service providers regarding data security is ensured.
Identification of existing risks and threats,
Determination of personal data security policies and procedures, and creation of an inventory,
Personal data minimization efforts,
Management of relationships with data processors.
Some of the technical measures taken are as follows:
Network security and application security are ensured.
A closed network system is used for the transfer of personal data over networks.
Key management is implemented.
Security measures are taken within the scope of the procurement, development and maintenance of information technology systems.
The security of personal data stored in the cloud is ensured.
Data masking is applied where necessary.
The authorizations of employees who change roles or leave the company are revoked.
Up-to-date anti-virus systems are used.
Firewalls are used.
The security of environments containing personal data is ensured.
Personal data are backed up, and the security of the backed-up personal data is also ensured.
User account management and authorization control systems are implemented and monitored.
Where special categories of personal data are to be sent by e-mail, they are always sent in encrypted form, using KEP (registered electronic mail) or a corporate e-mail account.
Intrusion detection and prevention systems are used.
Cybersecurity measures have been taken and their implementation is continuously monitored.
Encryption is applied.
Data loss prevention software is used.
Penetration testing,
Monitoring of personal data security,
Ensuring the security of environments containing personal data,
Procurement, development and maintenance of information technology systems.
In the event that personal data are unlawfully obtained by third parties and data security is compromised, the Company is obliged to notify the data subjects, the Board and the other relevant public institutions and organizations, in accordance with the provisions of the relevant legislation and this Policy.
17. PERSONAL DATA INVENTORY
The Company has created a data inventory containing the details required by the Law regarding the personal data processed within the scope of the KVKK. The Company’s data inventory includes the following details:
the business processes in which the personal data are used,
the category of the personal data,
the personal data processed,
the special categories of personal data processed,
the purpose and legal basis of the processing activity,
the domestic recipients of the personal data,
whether the personal data are transferred abroad,
the retention periods of the personal data.
In the event of a change in the Company’s processing activities, the Personal Data Inventory is updated. The Company notifies the Data Controllers’ Registry of the information contained in the Personal Data Inventory and of any updates. The information to be provided by the Company to data subjects within the framework of the obligation to inform referred to in Article 14 of this Policy is consistent with the information disclosed to the Registry.
18. PERSONAL DATA RETENTION AND DESTRUCTION POLICY
The “COMPANY” stores personal data for periods limited to those specified in the legislation, in a manner appropriate to the purpose of data processing, taking the necessary technical and administrative security measures.
Where the purposes of processing personal data cease to exist, the personal data will be destroyed by the “COMPANY”. Such destruction operations are carried out in accordance with the provisions of the relevant legislation, in six-month periods, ex officio or where the requests received from data subjects are found justified.
Records relating to the destruction of personal data are kept by the “COMPANY” for a period of 3 years. The periods stipulated in specific legislation are reserved; should these periods change due to amendments made to the KVKK and its related legislation, the current periods shall apply.
Destruction processes are carried out and decided upon by the KVKK Units.
19. CONFIDENTIALITY
Employees and executives of the “COMPANY” may not disclose the personal data they have learned to others in violation of the KVKK, the relevant legislation and the provisions of this Policy, and may not use them for purposes other than the processing purpose. This obligation continues after they leave their positions.
20. NOTIFICATION
In the event that it is determined that processed personal data have been obtained by others through unlawful means, the Contact Person informed of the matter notifies the relevant person and senior management as soon as possible. The breach is also notified to the Board by the Contact Person.
21. RIGHTS OF THE DATA SUBJECT, SUBMISSION AND EVALUATION OF APPLICATIONS
Rights of the Data Subject
Data subjects may submit their applications and requests regarding their personal data, using the Data Subject Application Form:
in person, with a wet-ink signature and a copy of the identity document, to the address Gayrettepe Mah. Yıldız Posta Cad. Akın Sitesi No: 8 İç Kapı No: 13 Beşiktaş / İstanbul,
by signing with a secure electronic signature or mobile signature, to the Company’s KVKK e-mail address “hunn@hunn.com.tr”,
through a notary public,
by applying to the Company in person with a valid identity document.
In order for the process to be conducted on behalf of the Company in the most effective manner for data subjects, the right intended to be exercised and the details of the requested operation must be stated clearly and comprehensibly in the request.
The subject of the request must relate to the data subject personally. If an application is made on behalf of another person, the applicant must rely on a specifically documented authority (power of attorney) for the requested operation. Unauthorized applications will not be taken into consideration.
Where the request is submitted to the Company using one of the methods above, it is evaluated within thirty (30) days at the latest from the date on which it is received by the Company, and the data subject is informed accordingly. If the request is accepted, the necessary actions are carried out immediately by the Company in its capacity as data controller. Where the evaluation and decision-making process entails an additional cost, the fee in the tariff determined by the Personal Data Protection Board shall apply.
Evaluation of the Application
Applications are evaluated and concluded as soon as possible and within 30 days at the latest from the date on which the application reaches the Company.
During the evaluation process, additional information and documents may be requested where necessary, and a fee may be charged for the fulfillment of the request where permitted under the relevant legislation.
The Company takes all necessary administrative and technical measures to conclude the applications made by data subjects effectively and in accordance with the law and the principle of good faith.
Rejection of the Application
An application is rejected where:
the application has not been made in accordance with the procedure described above,
the application contains a request contrary to the applicable legislation,
the application is not based on a justified reason or constitutes an abuse of right,
the personal data subject to the application are processed for purposes such as research, planning and statistics, by being anonymized through official statistics,
personal data made public by the data subject himself/herself are processed,
one of the other cases falling within the scope of Article 28 of the KVKK exists.
Where the application is rejected, the Company notifies the data subject of the rejection, explaining its reasons.
Right to Lodge a Complaint
In applications made to the Company, the data subject may exercise the right to lodge a complaint with the Board where the application is rejected, where the data subject considers the response given by the Company insufficient, or where the Company does not respond to the application within 30 days.
The data subject may exercise the right to lodge a complaint within 30 days from the date of learning of the Company’s response and, in any case, within 60 days from the date of the application.
22. ENTRY INTO FORCE
This Policy, issued by the Company, entered into force on 12 August 2026 and has been made available to the public on the Company’s website. In the event of a conflict between the regulations set out in this Policy and the applicable legislation — primarily the Law — and the decisions of the Board, the legislative provisions shall prevail first, followed by the decisions of the Board.
The Company reserves the right to amend this Policy at any time, in parallel with legal regulations and Board decisions. The current version of the Policy is published at https://hunn.com.tr/iletisim/ and may also be shared with the data subject upon request.
Last updated: 11 August 2026
Contact