Personal Data Protection Policy
ANIA TURİZM YATIRIMLARI A.Ş.
PERSONAL DATA PROTECTION PROCESSING STORAGE AND DESTRUCTION POLICY
CONTENTS
- Introduction
- Purpose
- Scope
- Abbreviations and definitions
- ANİA Turizm Yatırımları A.Ş. Regarding the Processing and Protection of Personal Data. Principles Adopted by
- Compliance with Basic Personal Data Processing Data
- Compliance with Personal Data Processing Conditions
- Compliance with Special Personal Data Processing Conditions
- Responsibility and task distribution
- recording media
- Transfer of Personal Data
- Transfer of Personal Data Domestically
- Transfer of Personal Data Abroad
- Explanations Regarding the Reasons Requiring Storage and Disposal
- Notes on storage
- Reasons requiring destruction
- Rights of Personal Data Owners and Finalization of Their Requests by the Company
- Technical and administrative measures
- Technical measures
- Administrative measures
- Personal data destruction techniques
- Deletion of personal data
- Destruction of personal data
- Anonymization of personal data
- Storage and disposal periods
- Periodic destruction time
- Publication and storage of the Policy
- Policy update period
ANNEX-1: Application form
- INTRODUCTION
- Purpose
The purpose of this document is the Personal Data Storage and Destruction Policy (“Policy”), the Personal Data Protection Law No. 6698 (“KVKK” or “Law”) and the secondary regulation of the Law, which came into force by being published in the Official Gazette dated 28 October 2017. To fulfill our obligations following the Regulation on Deletion, Destruction or Anonymization of Personal Data (“Regulation”) and to inform data owners about the principles of determining the maximum storage period required for the purpose for which their personal data is processed and the deletion, destruction and anonymization processes. It has been prepared by ANİA Turizm Yatırımları A.Ş., the operator of Balmy Foresta, as the data controller (from now on referred to as "ANİA" or "Company").
- Scope
Personal data belonging to the Institution's employees, employee candidates, service providers, visitors and other third parties are within the scope of this Policy, and this Policy applies to all recording environments and personal data processing activities where personal data owned or managed by the Institution is processed.
- Abbreviations and Definitions
Abbreviation |
Definition |
EXPRESS CONSENT |
Consent regarding a specific subject is based on information and expressed with free will. |
GDPR |
European Union General Data Protection Regulation No. 2016/679 repealed Directive No. 95/46/EC on 25.05.2018. |
RELEVANT USER |
Persons who process personal data within the data controller organization or in line with the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data. |
DESTRUCTION |
Deletion, destruction or anonymization of personal data. |
LAW / PDPL |
Personal Data Protection Law No. 6698. |
RECORDING MEDIA |
Any environment where personal data is processed by fully or partially automated or non-automatic means, provided that it is part of any data recording system. |
PERSONAL DATA |
Any information regarding an identified or identifiable natural person. |
TRANSFER OF PERSONAL DATA |
Personal data can be shared with domestic or foreign institutions, organizations, suppliers, etc. in accordance with PDPL and in accordance with Article 5 of this Policy. sharing. |
ANONYMIZING PERSONAL DATA |
Making personal data not associated with an identified or identifiable natural person in any way, even by matching it with other data. |
PROCESSING OF PERSONAL DATA |
Obtaining, recording, storing, preserving, changing, rearranging, disclosing, transferring, taking over, making available, classifying or using personal data by fully or partially automatic or non-automatic means provided that it is part of any data recording system. Any action performed on data, such as blocking. |
DELETION OF PERSONAL DATA |
Deletion of personal data; making personal data inaccessible and unusable in any way for the relevant users. |
DESTRUCTION OF PERSONAL DATA |
The process of making personal data inaccessible, irretrievable and reusable by anyone. |
ORGANISATION |
Personal Data Protection Authority |
AUTOMATIC DATA PROCESSING |
Personal data processing activity carried out by an interconnected and interactive electrical or electronic system that minimizes the need for human intervention or assistance. |
NON-AUTOMATIC DATA PROCESSING |
Personal data processing activity carried out manually, that is, through human intervention or assistance, |
SPECIAL PERSONAL DATA |
Data regarding people's race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, association, foundation or union membership, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data. |
PERIODIC DESTRUCTION |
In case all the conditions for processing personal data specified in the Law are eliminated, the deletion, destruction and anonymization process will be carried out ex officio at recurring intervals and specified in the personal data storage and destruction policy. |
DATA OWNER / RELATED PERSON |
Real person whose personal data is processed |
DATA CONTROLLER |
Natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system |
REGULATION |
Regulation on Deletion, Destruction or Anonymization of Personal Data published in the Official Gazette on 28 October 2017. |
POLICY |
Personal Data Storage and Destruction Policy |
DATA PROCESSOR |
Natural or legal person who processes personal data on behalf of the data controller, based on the authority given by the data controller. |
VERBIS |
Data Controllers Registry Information System |
- PRINCIPLES ADOPTED BY THE COMPANY REGARDING THE PROCESSING AND PROTECTION OF PERSONAL DATA
- Compliance with Basic Personal Data Processing Principles
The following basic principles are adopted by the company within the scope of complying with and maintaining compliance with personal data protection legislation:
- Process personal data in accordance with the law and the rules of honesty
The company carries out its personal data processing activities in accordance with the law and the rule of honesty, in accordance with the personal data protection legislation, especially the Constitution of the Republic of Turkey.
- Ensuring the accuracy and up-to-dateness of personal data processed
While the processing of personal data is carried out by the company, all necessary administrative and technical measures are taken to ensure the accuracy and up-to-dateness of personal data within technical possibilities.
- Processing of personal data for specific, explicit and legitimate purposes
The processing of personal data by the company is carried out for clear and lawful purposes determined before the personal data processing begins.
- Processing personal data in a limited and measured manner in connection with the purpose
Personal data is processed by the company in connection with the data processing conditions and as necessary to provide these services. In this context, the purpose of personal data processing is determined before starting the personal data processing activity, and data processing is not carried out with the assumption that it can be used in the future.
- Keeping personal data for the period stipulated in the relevant legislation or necessary for the purpose for which they are processed.
The company retains personal data for a limited period of time stipulated in the relevant legislation or required by the purpose of data processing. Accordingly, if the period stipulated in the legislation expires or the reasons requiring the processing of personal data disappear, personal data is immediately deleted by the Company.
- Compliance with Personal Data Processing Conditions
The company carries out its personal data processing activities in accordance with the data processing conditions set out in Article 5 of the PDPL. In this context, personal data processing activities are carried out in the presence of the personal data processing conditions listed below:
- Existence of Explicit Consent of the Personal Data Owner
- Personal Data Processing Activity is Clearly Provided for in Laws
- Explicit Consent of the Data Owner Cannot Be Obtained Due to Actual Impossibility and Personal Data Processing is Mandatory
- Personal Data Processing Activity Is Directly Related to the Establishment or Performance of a Contract
- It is mandatory to carry out personal data processing activities in order for the company to fulfill its legal obligations
- Data Processing Is Necessary for the Establishment, Exercise or Protection of a Right
- Data Owner's Publicization of Personal Data
- Personal Data Processing is Necessary for the Legitimate Interests of the Company, Provided That It Does Not Harm the Fundamental Rights and Freedoms of the Data Owner
- Compliance with Special Personal Data Processing Conditions
Special categories of personal data can be processed in the following cases, provided that adequate measures determined by the Company are taken:
- The relevant person must have explicit consent,
- It is clearly stipulated in the law,
- It is necessary for the protection of the life or physical integrity of the person or someone else who is unable to express his/her consent due to actual impossibility or whose consent is not given legal validity,
- Concerning the personal data that the relevant person has made public and being in accordance with the will to make it public,
- It is mandatory for the establishment, use or protection of a right,
- It is necessary for the protection of public health, the execution of preventive medicine, medical diagnosis, treatment and care services, and the planning, management and financing of health services by persons or authorized institutions and organizations under the obligation of confidentiality,
- It is mandatory to fulfill legal obligations in the fields of employment, occupational health and safety, social security, social services and social assistance,
- RESPONSIBILITIES AND DUTIES DISTRIBUTION
Title |
Duty |
General Manager |
Management and supervision of all operational processes within the workplace; ensuring service quality, guest satisfaction, and interdepartmental coordination in line with the Company's operational objectives. Monitoring and overseeing the retention and destruction processes of personal data to ensure that such data are retained and disposed of in accordance with the purposes for which they are processed. |
IT Manager |
Organizing workplace processes in terms of information technology and ensuring their security. Checking the compliance of personal data with the retention period. Carefully evaluating and finalizing the applications of those concerned. Management of periodic personal data destruction process. |
Director of human resources |
Ensuring that human resources processes in the workplace comply with personal data protection legislation. Management of storing processed personal data in accordance with its purpose and proportionately. Carefully monitoring and finalizing applications from relevant parties. Regular management of the personal data destruction process. |
Operations manager |
Checking the compliance of operational processes with personal data protection standards. Management of storing processed personal data in accordance with their purposes. Following up applications from relevant parties and finalizing them effectively. Operational management of periodic personal data destruction process. |
Sales and Marketing Manager |
Ensuring that marketing processes comply with personal data protection standards. Management of storing customer data in a manner appropriate and proportionate to its purpose. Quick handling and finalization of applications from interested parties. Effective implementation of periodic personal data destruction process in the marketing department. |
Rooms Division Manager |
Planning, coordinating, and supervising the hotel's rooms and housekeeping operations in accordance with the Company's operational standards. Managing the processes related to the cleanliness, maintenance, and overall condition of guest rooms and public areas to ensure the highest standards of quality and guest satisfaction. |
Front office manager |
Ensuring that accommodation processes comply with personal data protection standards. Carefully follow up and finalize guest applications. |
Guest Relations Manager |
Ensuring that guest relations processes comply with personal data protection standards. Carefully evaluating and finalizing applications from guests. Checking room reservations in terms of personal data management. Effective implementation of the periodic personal data destruction process in the guest services department. |
Kitchen chef |
Ensuring that kitchen processes comply with personal data protection standards. Evaluating special requests from guests who will receive food service in terms of personal data management. Management of safe storage of personnel-related personal data. Effective implementation of periodic personal data destruction process in the kitchen department. |
Finance director |
Ensuring that financial processes comply with personal data protection standards. Management of secure storage of financial data. Following up and finalizing financial applications from relevant parties. Effective implementation of periodic personal data destruction process in the finance department. |
Reservations Chef |
Ensuring that reservation processes comply with personal data protection standards. Management of secure storage of customer reservation information. Following up and finalizing reservation-related applications from relevant parties. Effective implementation of the periodic personal data destruction process in the reservation department. |
F&B Manager |
Ensuring that food and beverage processes comply with personal data protection standards. Controlling personal data management regarding the menu and special requests. Management of safe storage of personnel-related personal data. Effective implementation of periodic personal data destruction process in the F&B department. |
Quality Manager |
Coordinating the effective implementation of personal data protection processes throughout the Company; monitoring and maintaining the currency of policies, procedures, and records relating to the protection of personal data; ensuring coordination with the relevant departments; monitoring non-conformities and improvement actions; and ensuring the continuous improvement of KVKK compliance practices in accordance with applicable legal requirements. |
Purchasing Manager |
Ensuring that personal data obtained from or shared with suppliers, service providers, and other business partners are processed in compliance with the applicable personal data protection legislation. Monitoring the implementation of personal data protection requirements in contracts, forms, and other documentation used throughout the procurement process, and ensuring that personal data are disclosed only to authorized persons and only to the extent necessary. |
ANIA Personal Data Protection Committee |
Ensuring internal coordination to ensure that all departments comply with KVKK legislation and company data policy. Regularly auditing interdepartmental personal data management processes and improving them when necessary. |
- RECORDING MEDIA
Personal data is stored securely in accordance with the law in the environments listed below.
Electronic media |
Non-electronic media |
- Servers (Cloud Based Systems, Domain, backup, email, database, web, file sharing, etc.) |
- Paper |
- TRANSFER OF PERSONAL DATA
Personal data may be shared by the Company with its affiliates, as well as with our business and solution partners providing services such as tourism, hospitality, travel agency, and tour operator services, where necessary for the provision of our services. We may also share personal data with our social media, advertising, and analytics partners. These partners may combine such information with other information that you have provided to them directly or that they have collected through your use of their services.
Within the framework of national and international legislation provisions, especially KVKK, the Company may transfer the personal data it processes domestically or abroad. It may be subject to transfer procedures. During these transactions, articles 8 and 9 of the KVK Law, Directive 95/46/EC and the provisions of the GDPR, which repeals this directive, are taken into account. The company has fulfilled the conditions stipulated by the above-mentioned laws and directives regarding the transfer of personal data domestically and abroad.
- Transfer of Personal Data Within Türkiye
The company may transfer the data it processes to third parties by obtaining the express consent of the relevant person within the framework of the authority granted by Articles 8 and 9 of the PDPL and this policy. The basic principles listed below are explained in Section 2 of this Policy within the scope of compliance and maintenance of compliance with the personal data protection legislation by the Company.
Personal data that are lawfully collected, stored, and processed by the Company may be shared with the domestic third parties listed below for purposes such as receiving technical support services and ensuring data security, and are processed within the scope of the relevant legal basis and, where required, the explicit consent of the data subject.
Talya Bilişim Ticaret Sanayi A.Ş.
(Its Privacy Policy is available at: https://www.talyabilisim.com.tr/gizlilik-politikasi/)
Provisions in other laws are reserved for the domestic transfer of personal data.
If there is any Data Processor within the scope of this Data Policy, the provisions of Article 8 of the PDPL apply to personal data transfers between the Data Processor and the Company. Data transfer between employees operating in the legal entity and different departments within the legal entity of the company that has the title of data controller is not considered a transfer within the framework of Article 8 of the PDP Law. However, data transfers with those who have separate legal entities operating as cooperation or solution partners with the company are considered as data transfer within the scope of Articles 8 and 9 of the PDP Law and this PDP Policy.
- Transfer of Personal Data Abroad
Pursuant to Article 9 of the Law on the Protection of Personal Data ("KVKK"), the Company may transfer personal data abroad in compliance with the applicable legal requirements for international data transfers where:
- An adequate level of protection exists in the recipient country (countries providing an adequate level of protection are determined and announced by the Personal Data Protection Authority);
- Where an adequate level of protection does not exist, the data controllers in Türkiye and in the recipient foreign country provide a written undertaking to ensure adequate protection, and the approval of the Personal Data Protection Board has been obtained;
- The Company and the receiving third party have executed the Standard Contract announced by the Personal Data Protection Authority;
or where one of the following conditions applies:
- The transfer is necessary for the performance of a contract or for the implementation of pre-contractual measures taken at the request of the data subject;
- The transfer is necessary for the conclusion or performance of a contract concluded in the interest of the data subject;
- The transfer is necessary for reasons of overriding public interest;
- The transfer is necessary for the establishment, exercise, or protection of a legal claim;
- The transfer is necessary to protect the life or physical integrity of the data subject or another person where the data subject is physically or legally incapable of giving consent;
- The transfer is made from a register that is open to the public or to persons having a legitimate interest, provided that the legal conditions for access to such register are fulfilled.
- EXPLANATIONS REGARDING THE REASONS REQUIRING STORAGE AND DISPOSAL
Personal data belonging to data subjects are securely retained by the Company in the physical and electronic environments specified above, particularly for the purposes of ensuring the continuity of its commercial activities, fulfilling its legal obligations, planning and administering employee rights and benefits, and managing customer relationships, in compliance with the Law on the Protection of Personal Data ("KVKK") and other applicable legislation.
- Information on Storage
Personal data processed in accordance with the law and this Policy may be stored under the following conditions.
- Storing personal data because it is directly related to the establishment and execution of contracts,
- Storing personal data for the purpose of establishing, exercising or protecting a right,
- It is mandatory to keep personal data for the legitimate interests of the Company, provided that it does not harm the fundamental rights and freedoms of individuals,
- Storing personal data for the purpose of fulfilling any legal obligations of the Company,
- Storage of personal data is clearly stipulated in the legislation,
- Explicit consent of data owners is required for storage activities that require explicit consent of data owners.
- Reasons Requiring Destruction
In accordance with the Regulation, in the cases listed below, personal data of data owners are deleted, destroyed or anonymized by the Company ex officio or upon request.
- Amendment or fulfillment of the relevant legislation provisions that constitute the basis for the processing or storage of personal data,
- Elimination of the purpose requiring the processing or storage of personal data,
- Elimination of the conditions requiring the processing of personal data in Articles 5 and 6 of the Law,
- To withdraw the consent of the relevant person in cases where the processing of personal data is carried out only on the basis of explicit consent,
- The data controller accepts the application made by the relevant person for the deletion, destruction or anonymization of his personal data within the framework of his rights in paragraphs 2 (e) and (f) of Article 11 of the Law,
- Where the Data Controller rejects the data subject's request for the deletion, destruction, or anonymization of their personal data, where the response provided is deemed insufficient, or where no response is given within the period prescribed by the Law, and the data subject files a complaint with the Personal Data Protection Authority, which subsequently determines that the request is justified.
- Although the maximum period requiring the storage of personal data has passed, there are any conditions that justify storing personal data for a longer period of time.
The Company retains personal data only for as long as necessary to fulfill the purposes for which they are processed and for the minimum retention periods prescribed under the applicable legislation. In this regard, the Company first determines whether the relevant legislation stipulates a specific retention period for the personal data concerned and, where such a period exists, complies with that requirement. Where no statutory retention period is prescribed, personal data are retained for the periods specified in the table above, insofar as necessary for the purposes for which they are processed. Upon the expiry of the applicable retention period, personal data are destroyed in accordance with the Company's periodic destruction schedule or upon the data subject's request, using the applicable destruction methods, namely deletion, destruction, and/or anonymization.
- RIGHTS OF PERSONAL DATA OWNERS AND CONCLUSION OF THEIR REQUESTS BY THE COMPANY
If data owners submit their requests regarding their personal data to the Company in writing or by other methods determined by the KVK Authority, the Company, as the data controller, shall ensure that the request is finalized as soon as possible and within thirty (30) days at the latest, in accordance with Article 13 of the KVK Law, depending on the nature of the request. carries out the necessary processes to ensure Data owners must make their requests regarding their personal data in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller.
Within the scope of ensuring data security, the company may request information to determine whether the applicant is the owner of the personal data subject to the application. Our company may also ask questions to the personal data owner regarding his/her application in order to ensure that the personal data owner's application is finalized in accordance with the request.
Application of the data owner; In cases where there is a possibility of hindering the rights and freedoms of other persons, it requires disproportionate effort, or the information is publicly available, the request may be rejected by the Company by explaining the reason.
Rights of Personal Data Owners In accordance with Article 11 of the KVK Law, you can apply to our Company and request the following issues:
- To learn whether your personal data is being processed or not,
- To request information if your personal data has been processed,
- To learn the purpose of processing your personal data and whether they are used in accordance with their purpose,
- To learn the third parties to whom your personal data is transferred domestically or abroad,
- To request correction of your personal data if it has been processed incompletely or incorrectly, and to request that the action taken in this context be notified to third parties to whom your personal data has been transferred,
- To request the deletion, destruction or anonymization of your personal data in case the reasons requiring processing are eliminated, even though it has been processed in accordance with the provisions of PDPL and other relevant laws, and to request that the action taken in this context be notified to third parties to whom your personal data has been transferred,
- To object to the emergence of a result against you by analyzing your processed data exclusively through automatic systems,
- To request compensation in case you suffer damage due to unlawful processing of your personal data.
- TECHNICAL AND ADMINISTRATIVE MEASURES
Company within the framework of adequate measures determined and announced by the Institution for special personal data in accordance with Article 12 of the Law and the fourth paragraph of Article 6 of the Law, in order to safely store personal data, prevent unlawful processing and access of personal data, and destroy personal data in accordance with the law. Technical and administrative measures are taken by the company.
1. Technical Measures
- Penetration tests are conducted to identify risks, threats, vulnerabilities, and potential security gaps within the Company's information systems, and the necessary corrective measures are implemented accordingly.
- Through the Information Security Incident Management process, real-time monitoring and analysis are carried out to continuously identify and monitor risks and threats that may affect the continuity of the Company's information systems.
- Access to information systems and user authorizations are managed through access control and authorization matrices, as well as corporate Active Directory security policies.
- The necessary physical security measures are implemented to protect the Company's information systems, hardware, software, and data.
- To ensure the security of information systems against environmental threats, both physical safeguards (including access control systems restricting server room access to authorized personnel, 24/7 surveillance systems, physical protection of network edge switches, fire suppression systems, air-conditioning systems, etc.) and logical safeguards (including firewalls, intrusion prevention systems, network access control, anti-malware solutions, etc.) are implemented.
- Risks related to the unlawful processing of personal data are identified, appropriate technical safeguards are implemented to mitigate such risks, and the effectiveness of these safeguards is regularly monitored and tested.
- Internal access procedures have been established, and reporting and analysis activities relating to access to personal data are carried out on a regular basis.
- Access to storage environments containing personal data is logged, and unauthorized access attempts are monitored and controlled.
- The Company takes the necessary measures to ensure that deleted personal data are inaccessible and cannot be recovered or reused by authorized users.
- In the event that personal data are unlawfully obtained by unauthorized third parties, the Company has established an appropriate notification system and infrastructure to inform the relevant data subjects and the Personal Data Protection Authority. Such notifications may be made via the dedicated e-mail address [email protected].
- Security vulnerabilities are continuously monitored, appropriate security patches are applied, and information systems are kept up to date.
- Strong password policies are implemented in electronic environments where personal data are processed.
- Secure logging systems are used in electronic environments where personal data are processed.
- Data backup solutions are implemented to ensure the secure retention of personal data.
- Access to personal data stored in both electronic and non-electronic environments is restricted in accordance with the Company's access control principles.
- Under no circumstances does the Company store personal data on flash drives, USB devices, data banks, or similar portable storage media, and the transfer of personal data to such portable storage devices is strictly prohibited.
- Access rights and authorizations have been defined for users who are permitted to access special categories of personal data processed by employees involved in the relevant processing activities.
- Electronic environments in which special categories of personal data are processed, stored, and/or accessed are protected through cryptographic methods; cryptographic keys are maintained in secure environments; all processing activities are logged; security updates are continuously monitored; necessary security testing is performed on a regular basis or commissioned where appropriate; and test results are properly documented.
- Appropriate physical security measures are implemented for physical environments in which special categories of personal data are processed, stored, and/or accessed, ensuring physical security and preventing unauthorized access.
- Administrative Measures
- Administrative measures taken by the company regarding the personal data it processes are listed below:
- Training is provided to employees to enhance their professional competence in areas including the prevention of unlawful processing of personal data, prevention of unauthorized access to personal data, ensuring the secure retention of personal data, communication techniques, technical knowledge and skills, the provisions of the Civil Servants Law No. 657 (where applicable), and other relevant legislation.
- Employees are required to sign confidentiality agreements covering the activities carried out by the Company.
- A disciplinary procedure has been established for employees who fail to comply with the Company's information security policies and procedures.
- Prior to commencing any personal data processing activities, the Company fulfills its obligation to inform data subjects in accordance with the applicable legislation.
- A Personal Data Processing Inventory has been prepared and is maintained by the Company.
- Periodic and random internal audits are conducted to monitor compliance with personal data protection requirements.
- Employees receive regular information security awareness and training.
- A separate policy has been established regarding the protection and security of special categories of personal data.
- Employees involved in the processing of special categories of personal data receive dedicated training on the security of such data, and confidentiality agreements are executed with those employees.
- PERSONAL DATA DESTRUCTION TECHNIQUES
At the end of the period stipulated in the relevant legislation or the storage period required for the purpose for which they are processed, personal data are destroyed by the Company ex officio or upon the application of the relevant person, using the techniques specified below, in accordance with the relevant legislation.
- Deletion of Personal Data
Data Recording Environment |
Explanation |
Personal Data on Servers |
For personal data on the servers whose retention period has expired, the system administrator removes the access authorization of the relevant users and deletes them. |
Personal Data in Electronic Media |
Among the personal data in the electronic environment, those whose period of storage has expired are made inaccessible and unusable for other employees (relevant users) except the database administrator. |
Personal Data in Physical Environment |
Personal data kept in physical environment, for which the period requiring storage has expired, is destroyed under the control of the unit manager responsible for the document archive. |
- Destruction of Personal Data
Data Recording Environment |
Explanation |
Personal Data in Physical Environment |
Personal data stored on paper that have expired are irreversibly destroyed in paper shredding machines. |
Personal Data Contained in Optical / Magnetic Media |
Personal data stored on optical and magnetic media, for which the applicable retention period has expired, are destroyed by physical methods such as shredding, incineration, pulverization, or other similar means, ensuring that the data become permanently irretrievable. |
- STORAGE AND DISPOSAL PERIOD
Regarding the personal data processed by the company within the scope of its activities;
- Personal data-based retention periods for all personal data within the scope of activities carried out depending on the processes are included in the Personal Data Processing Inventory;
- Process-based retention periods are in the Personal Data Storage and Destruction Policy.
takes place.
For personal data whose storage period has expired, the Company will ex officio delete, destroy or anonymize it.
Data Owner |
Process |
Storage Period |
Destruction Period |
Employees, Interns and Relatives of Employees |
Creating an Employee Personnel File |
Legal Relationship + 10 years |
During the first periodic destruction following the end of the storage period |
Employee and Intern |
Occupational Health and Safety Practices |
Legal Relationship + 10 years |
Saklama süresinin bitimini takip eden ilk periyodik imha süresinde |
Employee and Intern |
Salary payments |
Legal Relationship + 10 years |
Saklama süresinin bitimini takip eden ilk periyodik imha süresinde |
Employee and Intern |
Educational Planning |
Legal Relationship + 10 years |
Saklama süresinin bitimini takip eden ilk periyodik imha süresinde |
Employee Candidate |
Conducting the Job Application Process |
3 years from the completion of the visit |
Saklama süresinin bitimini takip eden ilk periyodik imha süresinde |
Instructor |
Educational Planning |
5 year from completion of training |
Saklama süresinin bitimini takip eden ilk periyodik imha süresinde |
Subcontractor |
Execution of Subcontracted Activities |
Legal Relationship + 10 years |
During the first periodic destruction following the end of the storage period |
Employee Candidate and Visitor |
Tracking of Building Entrances and Exits |
2 years from the completion of the visit |
During the first periodic destruction following the end of the storage period |
Daily Hotel Guests, Supplier Employees, Supplier Officials and Visitors |
Tracking of Building/Institution Entrance and Exit |
2 years from the completion of the visit |
During the first periodic destruction following the end of the storage period |
Employee and Intern |
Detection of Employees' Disciplinary Behaviors |
Legal Relationship + 10 years |
During the first periodic destruction following the end of the storage period |
Person Receiving Product or Service |
Ensuring Institutional Security |
Legal Relationship + 10 years |
During the first periodic destruction following the end of the storage period |
Person Receiving Product or Service |
Camera Recordings |
Legal Relationship + 10 years |
During the first periodic destruction following the end of the storage period |
Visitors, Daily Hotel Guests, Employee Candidates and Interns |
Camera Recordings |
Routine retention period: 14 to 17 days, depending on the storage capacity of the recording device. |
During the first periodic destruction following the end of the storage period |
Person Receiving Product or Service |
Management of Accommodation Service Processes and Provision of Accommodation Services |
Legal Relationship + 10 years |
During the first periodic destruction following the end of the storage period |
Person Receiving Product or Service |
Personal Health Data, Blood Group Information and Allergen Information |
Legal Relationship + 20 years |
During the first periodic destruction following the end of the storage period |
Person Receiving Product or Service |
Sales and Marketing Activities |
Legal Relationship + 10 years |
During the first periodic destruction following the end of the storage period |
Employee, Intern and Person Receiving Products or Services |
Transaction Security Activities |
5 years |
During the first periodic destruction following the end of the storage period |
Employee, Intern and Person Receiving Products or Services |
Log/Recording/Tracking Systems |
5 years |
During the first periodic destruction following the end of the storage period |
Website Visitor |
Website Visits |
2 years |
During the first periodic destruction following the end of the storage period |
Person Receiving Product or Service |
Customer Registration Information |
10 years |
During the first periodic destruction following the end of the storage period |
Supplier Employee and Supplier Official |
Conducting Purchasing Processes |
Legal Relationship + 1 years |
During the first periodic destruction following the end of the storage period |
Internet Network Users |
Log Record Tracking Systems (based on law no. 5651) |
2 years |
During the first periodic destruction following the end of the storage period |
- PERIODIC DESTRUCTION PERIOD
The periodic destruction period has been determined as six (6) months. Within the Company, personal data destruction procedures are carried out at six-month intervals on the dates designated annually by the Company.
PUBLISHING AND STORAGE OF THE POLICY
The policy is published in two different media, with wet signature (printed paper) and electronically, and is disclosed to the public on the website. The printed paper copy is stored at the office headquarters.
- UPDATED PERIOD OF THE POLICY
This Personal Data Policy was updated on 26 June 2026 and shall be reviewed as necessary in light of legal, regulatory, or operational developments. Where required, the relevant sections shall be revised and updated. Any updates to the Policy shall be published on the Company's website.
ANNEX-1 APPLICATION FORM
This form is submitted to ANİA Turizm Yatırımları A.Ş. in accordance with Article 11 of the Law on the Protection of Personal Data. It has been prepared to make it easier for you to exercise your right to receive information by applying to (ANIA). For detailed information about the processing process of your Personal Data and the process after your application with this form, see “ANİA Turizm Yatırımları A.Ş.” published on the balmyforesta.com, balmybeachresort.com and balmyhotels.com websites. Please review the "Policy on Protection, Processing, Storage and Destruction of Personal Data".
- Applicant's Contact Information
The information requested through this form is necessary to accurately identify you, to conduct detailed research regarding your request, and to notify you of the result of your application, and may be processed for this purpose. Therefore, please submit your information accurately and completely. Your requested personal data will not be used in any way other than to fulfill the Purpose.
Name and Surname: |
|
TR ID Number: |
|
Phone Number: |
|
E-Mail Address: |
|
Adresiniz: |
|
|
|
- Applicant's Relationship with ANIA
- Please indicate your relationship with ANIA.
For example: Employee; Shareholder; Company official; Customer; Customer Representative/Employee; Reseller.
................................................................................
- Which unit within ANIA did you communicate with?
................................................................................
- Applicant's Request
Please describe your request in detail below.
...............................................................................................................................
...............................................................................................................................
...............................................................................................................................
...............................................................................................................................
...............................................................................................................................
...............................................................................................................................