Our KVKK Policy


Personal Data Retention, Disposal and Anonymization Policy
1. Purpose
At ERY Bilişim A.Ş., since the entry into force of the Turkish Personal Data Protection Law No. 6698 (“KVKK” or the “Law”), we have attached great importance to protecting the personal data of all natural persons with whom we come into contact in any way while carrying out our commercial activities, and to fulfilling in full the requirements set out in KVKK in this regard.
This Personal Data Retention, Disposal and Anonymization Policy (the “Policy”) has been prepared to provide information on the processes by which ERY Bilişim A.Ş. collects, uses, shares, retains and erases, destroys or anonymizes personal data, and on the fundamental principles governing those processes.
This Policy sets out, within the scope of KVKK and the relevant legislation, the principles governing the processing of data subjects' personal data by ERY Bilişim A.Ş.
The Policy covers ERY Bilişim A.Ş. employees, active and prospective customers, visitors and other natural persons who have a relationship with ERY Bilişim A.Ş.
Pursuant to the Regulation, as a data controller under an obligation to register with the Registry, ERY Bilişim A.Ş. is obliged to prepare this Policy and to act in accordance with it, in order to retain the personal data in its possession in line with its personal data processing inventory and, where necessary, to erase, destroy or anonymize that data.
The following principles apply to the retention and disposal of personal data:
The general principles set out in Article 4 of the Law are complied with.
ERY Bilişim A.Ş. acknowledges that the preparation of this Policy does not, in itself, mean that personal data has been erased, destroyed or anonymized in accordance with the Regulation, the Law and the relevant legislation.
When retaining, erasing, destroying or anonymizing personal data, ERY Bilişim A.Ş. acts in accordance with the security measures set out in Article 12 of the Law, the relevant legislation, the decisions of the Personal Data Protection Board and this Policy.
With respect to the processing of the personal data it holds, wholly or partly by automated means or by non-automated means provided that the processing forms part of a data filing system, ERY Bilişim A.Ş. acts in accordance with this Policy, and with the tools, programs and processes to be applied under the Policy, in the erasure, destruction or anonymization of personal data.
2. Scope
This Policy applies to all processes of ERY Bilişim A.Ş.
3. Definitions
Law: Personal Data Protection Law No. 6698.
Regulation: Regulation on the Erasure, Destruction or Anonymization of Personal Data.
Board: Personal Data Protection Board.
Recording Medium: Any medium containing personal data that is processed wholly or partly by automated means, or by non-automated means provided that the processing forms part of a data filing system.
Personal Data Processing Inventory: The inventory that data controllers create and detail by associating the personal data processing activities they carry out, depending on their business processes, with the purposes of processing the personal data, the data category, the recipient group to which the data is transferred and the group of data subjects.
Disposal: The erasure, destruction or anonymization of personal data.
Periodic Disposal: The erasure, destruction or anonymization carried out ex officio, at the recurring intervals specified in the personal data retention and disposal policy, where all of the conditions for processing personal data set out in the Law have ceased to exist.
Registry: The Data Controllers Registry maintained by the Presidency of the Personal Data Protection Authority.
Data Filing System: The filing system in which personal data is structured and processed according to specific criteria.
Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.
Recipient Group: The category of natural or legal persons to whom personal data is transferred by the data controller.
Relevant User: Persons who process personal data within the data controller's organization or in line with the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.
The definitions contained in the Personal Data Protection Policy also apply for the purposes of this Policy.
4. References
This Policy has been prepared on the basis of the following legislation and regulations:
Personal Data Protection Law No. 6698
Regulation on the Erasure, Destruction or Anonymization of Personal Data
Regulation on the Data Controllers Registry
Other relevant legislation and regulations
5. Procedures and Principles for the Protection of Personal Data
5.1. General Principles of Processing
ERY Bilişim A.Ş. processes personal data in accordance with the procedures and principles stipulated in KVKK and other relevant legislation.
In this context, the following principles are observed when personal data is processed:
Compliance with the Law and the Rules of Good Faith
ERY Bilişim A.Ş.'s data processing activities are carried out within the limits required by all relevant legislation, in particular the Constitution and KVKK, and by the rules of good faith.
Being Accurate and, Where Necessary, Up to Date
The necessary measures are taken to ensure that the personal data processed by ERY Bilişim A.Ş. is accurate and up to date, and data subjects are given the necessary means to ensure that the data processed reflects the actual situation.
Processing for Specified, Explicit and Legitimate Purposes
ERY Bilişim A.Ş. processes personal data only for legitimate purposes that have been explicitly and specifically set out. No data processing is carried out outside these purposes.
Accordingly, personal data is processed only to the extent that it is related to, and necessary for, the business relationship established with data subjects.
Being Relevant, Limited and Proportionate to the Purposes of Processing
Personal data is processed, in accordance with KVKK and other relevant legislation, in a manner that is suitable for achieving the specified purposes and is relevant, limited and proportionate to those purposes.
The processing of personal data that is not needed is avoided.
Retention for the Period Stipulated in the Relevant Legislation or Required for the Purpose of Processing
Personal data processed by ERY Bilişim A.Ş. is retained for the period stipulated in the relevant legislation or required for the purpose for which it is processed.
Where the relevant legislation stipulates a specific period for the retention of personal data, that period is observed. Where no such period exists, personal data is retained only for as long as is necessary for the purpose for which it is processed.
ERY Bilişim A.Ş. does not retain personal data on the basis of the possibility that it may be used in the future.
5.2. Conditions for Processing Personal Data
The conditions for processing personal data are regulated under KVKK, and ERY Bilişim A.Ş. processes personal data in accordance with the conditions specified in the Law.
Other than in the exceptions listed in the Law, ERY Bilişim A.Ş. processes personal data by obtaining the explicit consent of data subjects.
Where one of the following conditions specified in the Law exists, however, personal data may be processed without seeking the data subject's explicit consent:
It is expressly provided for by law,
It is necessary to protect the life or physical integrity of a person who is unable to express consent due to actual impossibility, or whose consent is not recognized as legally valid, or of another person,
It is necessary to process the personal data of the parties to a contract, provided that the processing is directly related to the conclusion or performance of that contract,
It is necessary for the data controller to fulfill its legal obligation,
The data has been made public by the data subject,
Data processing is necessary for the establishment, exercise or protection of a right,
Data processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.
Processing of Special Categories of Personal Data
ERY Bilişim A.Ş. exercises the necessary care in processing special categories of personal data, the protection of which is of more critical importance for data subjects.
In this context, special categories of personal data are processed in accordance with the conditions stipulated in the relevant legislation, provided that the adequate measures determined by the Board are taken.
Special categories of personal data other than data concerning health and sexual life may also be processed without the data subject's explicit consent in the cases provided for by law.
Data concerning health and sexual life, on the other hand, may be processed without seeking explicit consent provided that adequate measures are taken and the grounds specified in the relevant legislation exist.
In this context:
Protection of public health,
Preventive medicine,
Medical diagnosis,
Provision of treatment and care services,
Planning and management of healthcare services and their financing
are among the purposes specified.
5.3. Purposes of Processing Personal Data
Your personal data obtained by ERY Bilişim A.Ş. may be processed for the following purposes:
Carrying out human resources operations,
Creating personnel files,
Carrying out payroll operations,
Managing employee contract processes,
Carrying out insurance renewal processes,
Providing healthcare services to employees,
Maintaining blood type lists,
Allocating vehicles, telephones and phone lines to employees as part of the performance of the employment contract,
Carrying out the processes for obtaining powers of attorney and signature circulars,
Conducting compliance assessments within the scope of subcontracting relationships,
Making emergency preparations and carrying out the related operations,
Carrying out occupational health and safety processes,
Carrying out accident and legislation management within the scope of occupational health and safety,
Carrying out service procurement contract processes,
Planning, auditing and implementing information security processes,
Opening and authorizing e-mail accounts for employees,
Keeping internet log records,
Planning and carrying out corporate communication activities,
Planning personnel travel and carrying out advance payment processes,
Carrying out and tracking paperwork,
Making access card and shuttle service registrations for personnel entry,
Carrying out budgeting processes,
Delivering and managing personnel training,
Planning and carrying out in-house training and orientation programs,
Carrying out in-house operations,
Carrying out legal, technical and administrative activities,
Carrying out strategy and planning activities,
Carrying out business partner and supplier management,
Planning and carrying out corporate communication activities and events,
Planning and carrying out in-house training programs,
Carrying out customer relationship management processes.
The categories set out above are provided for information purposes, and other categories may be added where this is necessary for ERY Bilişim A.Ş. to carry out its future commercial and operational activities.
In such cases, ERY Bilişim A.Ş. will continue to inform data subjects by updating the relevant texts.
5.4. Retention of Personal Data
Your personal data is retained securely, in physical or electronic media, for the periods stipulated in the relevant legislation.
5.5. Transfer of Personal Data to Persons in Türkiye
With regard to sharing personal data with third parties, ERY Bilişim A.Ş. acts in accordance with the conditions set out in KVKK, without prejudice to the provisions of other laws.
Accordingly, as a rule, personal data is not transferred to third parties without the data subject's explicit consent.
However, where one of the following conditions specified in KVKK exists, personal data may also be transferred without obtaining the data subject's explicit consent:
It is expressly provided for by law,
It is necessary to protect the life or physical integrity of a person who is unable to express consent due to actual impossibility, or whose consent is not recognized as legally valid, or of another person,
It is necessary to process the personal data of the parties to a contract, provided that the processing is directly related to the conclusion or performance of that contract,
It is necessary for the data controller to fulfill its legal obligation,
The data has been made public by the data subject,
Data processing is necessary for the establishment, exercise or protection of a right,
Data processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.
With regard to special categories of personal data, the conditions specified in the relevant legislation and adequate security measures are likewise complied with.
5.6. Transfer of Personal Data Abroad
Processes relating to the transfer of personal data abroad are carried out in line with Article 9 of KVKK and the provisions of the relevant legislation.
Where the conditions permitting the processing of personal data without the data subject's explicit consent exist, data may also be transferred abroad without seeking the data subject's explicit consent, provided that adequate protection exists in the foreign country to which the personal data will be transferred or that the other transfer conditions stipulated in the relevant legislation are met.
Where the country to which the transfer will be made has not been designated by the Board as one of the countries providing adequate protection, the transfer may be carried out by providing the appropriate safeguards stipulated in the relevant legislation and fulfilling the necessary conditions.
5.7. Your Rights Under Article 11 of the Personal Data Protection Law No. 6698
As personal data subjects, you have the following rights under Article 11 of KVKK:
To learn whether your personal data is processed,
To request information about the processing if your personal data has been processed,
To learn the purpose of the processing of your personal data and whether it is used in accordance with that purpose,
To know the third parties, in Türkiye or abroad, to whom your personal data is transferred,
To request the rectification of your personal data if it has been processed incompletely or inaccurately,
To request the erasure or destruction of your personal data within the framework of the conditions stipulated in Article 7 of the Law,
To request that the operations carried out pursuant to items 5 and 6 above be notified to the third parties to whom your personal data has been transferred,
To object to a result arising to your detriment through the analysis of the processed data exclusively by automated systems,
To claim compensation for the damage you suffer as a result of the unlawful processing of your personal data.
In order to exercise the rights listed above, data subjects may send a wet-ink signed copy of the Data Subject Application Form in Annex 1 to this Policy to the contact addresses of ERY Bilişim A.Ş. by mail, e-mail or registered mail with return receipt.
Detailed information on completing the application form and sending it to ERY Bilişim A.Ş. is set out in the application form in Annex 1.
Applications will be concluded free of charge as soon as possible, depending on the nature of the request, and within thirty (30) days at the latest.
If the application entails an additional cost, the fee in the tariff determined by the Personal Data Protection Board may be charged to the persons concerned.
In the course of concluding applications, ERY Bilişim A.Ş. may request additional information or documents from applicants.
Application E-mail Address: info@erysystem.com
5.8. Measures Taken for Data Security
ERY Bilişim A.Ş. takes the necessary technical and administrative measures to ensure the appropriate level of security required for the protection of personal data.
The main purposes of the measures taken under Article 12 of KVKK are as follows:
To prevent the unlawful processing of personal data,
To prevent unlawful access to personal data,
To ensure the safekeeping of personal data.
5.9. Processing of Video Recordings
In order to ensure the general and commercial security of the company's facilities and premises, ERY Bilişim A.Ş. may capture and process video recordings of visitors, employees and other relevant persons, in accordance with the fundamental principles stipulated in KVKK and set out in this Policy.
The video recordings captured are retained securely, in physical or electronic media, for the period necessary for the purposes of their processing.
In areas where video recording takes place, notices stating that video recording is in progress are visibly displayed in order to inform data subjects.
In carrying out these activities, ERY Bilişim A.Ş. acts in accordance with the obligations stipulated in all relevant legislation on the protection of personal data, in particular KVKK.
No monitoring is carried out in areas where there is a high expectation of privacy.
6. Erasure, Destruction or Anonymization of Personal Data
Personal data processed for the purposes set out in this Policy will be erased, destroyed or anonymized, pursuant to Article 7 of Law No. 6698, when the purposes requiring its processing cease to exist and the retention periods determined under the relevant legislation expire.
6.1. Erasure of Personal Data
The erasure of personal data processed wholly or partly by automated means is the process of rendering that personal data inaccessible to, and non-reusable by, the relevant users in any way.
The data controller explains in its relevant policies and procedures how the conditions required for personal data to be deemed erased are met.
The erasure of personal data that forms part of any data filing system and is processed by non-automated means is carried out using methods that comply with the relevant legislation.
Where ERY Bilişim A.Ş. erases personal data, it is obliged to ensure that the data in question is rendered inaccessible and non-reusable even for authorized users.
If, during the erasure process, personal data that should not be erased would also be affected by the erasure and become inaccessible and/or unusable, the combined application of the following methods may be regarded as erasure:
Archiving the personal data in such a way that it cannot be associated with the data subject,
Closing the personal data to all access,
Taking the necessary technical and administrative measures to ensure that the personal data is accessed only where necessary and only by authorized persons.
The erasure methods to be applied are updated when necessary in line with the relevant legislation.
6.2. Destruction of Personal Data
Destruction is applied where ERY Bilişim A.Ş. processes personal data on physical recording media.
Destruction ensures that the personal data is rendered irretrievable and unusable.
In the destruction process, ERY Bilişim A.Ş. employees and the relevant departments notify the relevant units of the personal data that needs to be destroyed. The disposal is then carried out by taking the necessary technical and administrative measures.
6.3. Anonymization of Personal Data
Anonymization is the process of rendering personal data impossible to associate with an identified or identifiable natural person, even when it is matched with other data.
The anonymization of personal data is the responsibility of the business unit that owns the relevant data.
Where necessary in the anonymization process, the data-owning business unit may obtain support from different departments of ERY Bilişim A.Ş., provided that control remains with that unit.
Methods such as one-way functions and encryption may be used during anonymization.
If there is any doubt as to the adequacy or accuracy of the method to be applied, the opinion of the relevant units must be sought.
7. Methods and Process for the Disposal of Personal Data
The methods that ERY Bilişim A.Ş. may use for the disposal of personal data are defined in this Policy.
The data-owning business unit is responsible for determining and applying the method appropriate to the situation at hand.
Whichever of the following methods is appropriate may be used in the disposal of personal data:
7.1. Overwriting
The process of writing new data onto magnetic media and rewritable optical media by means of software, in such a way that the old data is rendered unreadable.
7.2. Degaussing
The process of exposing magnetic media to a high-strength magnetic field so that it is physically altered and the data on it is rendered unreadable.
7.3. Physical Destruction
The process of physically destroying optical or magnetic media by melting, pulverizing, grinding and similar methods.
It may be used where degaussing or overwriting cannot be applied or has failed.
7.4. Cloud Disposal
The process of destroying all copies of the encryption keys for the personal data, after the necessary notification has been made to the relevant service provider, in order to dispose of personal data held in cloud systems.
7.5. Disposal of Personal Data in Peripheral Systems
The process of disposing of personal data held in printers, fingerprint units, door-entry turnstiles and similar systems.
Whichever of the overwriting, degaussing or physical destruction methods is appropriate is applied to the relevant internal unit, if there is one, or otherwise to the entire device.
Such disposal must be carried out before the devices are subjected to backup, maintenance and similar operations.
8. Retention and Disposal Periods
8.1. Periodic Disposal and Statutory Retention Periods
Physical and digital data whose statutory retention and disposal periods have expired is disposed of periodically.
ERY Bilişim A.Ş. erases, destroys or anonymizes the relevant personal data in the first periodic disposal following the date on which the obligation to erase, destroy or anonymize the personal data arises.
Periodic disposal is carried out for all personal data at 6-month intervals.
Records of the operations relating to erased, destroyed or anonymized data are retained for at least 3 years, without prejudice to other legal obligations.
8.2. Erasure and Destruction Process upon Request by Data Subjects
Where data subjects apply to our company and request the erasure or destruction of their personal data, it is first assessed whether the conditions for processing the personal data exist.
Where all of the conditions for processing the personal data have ceased to exist, the personal data subject to the request is erased, destroyed or anonymized.
Our company concludes the data subject's request within thirty days at the latest and informs the data subject.
If all of the conditions for processing the personal data have ceased to exist and the personal data subject to the request has been transferred to third parties, the data controller notifies the relevant third party of this situation and ensures that the necessary actions are taken by the third party.
If not all of the conditions for processing the personal data have ceased to exist, our company may reject the request by explaining its reasons to the relevant data subject. The rejection is notified to the data subject in writing or electronically within thirty days at the latest.
9. Changes to the Policy
Following official changes to the relevant legislation, this Policy may be updated by ERY Bilişim A.Ş. so that it complies with the legislation.
ERY Bilişim A.Ş. shares the current Policy containing the changes it has made with its employees by e-mail and makes it available to its employees through the corporate website.
10. Entry into Force
This Personal Data Retention, Disposal and Anonymization Policy, prepared by ERY Bilişim A.Ş., entered into force on October 8, 2025.

