USERSDOT TECHNOLOGY AND CONSULTANCY INC.
This policy explains the principles of USERSDOT TECHNOLOGY AND CONSULTANCY INC. (hereinafter referred to as the "Usersdot" or "Company") regarding the processing of personal data that are required to be known by Personal Data Owners.
| Data Controller | Data Controller refers to the natural or legal person who determines the purposes and means of processing personal data, and who is responsible for establishing and managing the data recording system. |
| The Company | The data controller refers to Usersdot Technology and Consultancy Inc. |
| Data Subject / Concerned Individual | The data subject is the individual whose personal data is being processed. |
| Data Processor | The natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the data controller. |
| Personal Data | It refers to any kind of information relating to an identified or identifiable natural person. |
| Sensitive Personal Data | It refers to data regarding individuals’ race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, attire, association, foundation or union membership, health, sexual life, criminal record, and security measures, as well as biometric and genetic data. |
| Processing of Personal Data | It encompasses all kinds of processes carried out on data, whether fully or partially, by automatic or non-automatic means, including obtaining, recording, storing, preserving, altering, rearranging, disclosing, transferring, taking over, making data accessible, classifying, or preventing the use of data. |
| KVKK | It refers to the Law on the Protection of Personal Data No. 6698. |
| Board | It refers to the Personal Data Protection Board. |
| Authority | It refers to the Personal Data Protection Authority. |
| Data Registry System | It refers to the record system where personal data is processed in a structured manner according to specific criteria. |
| Record System | Any environment containing personal data that is processed either wholly or partly by automatic means or by non-automatic means as part of a data recording system. |
| Electronic Environment | The environments in which personal data can be created, read, modified, and written using electronic devices. |
| Non-electronic Environment | It refers to all written, printed, visual, and other formats that exist outside of electronic environments. |
| Explicit Consent | It expresses consent based on information provided on a specific subject and declared with free will. |
| Anonymization of Personal Data | Anonymization of personal data refers to rendering it in a way that it can no longer be associated with an identified or identifiable individual, even when combined with other data. |
The main purpose of this Policy is to make explanations about the systems for the processing and protection of personal data in accordance with the Personal Data Protection Law and the relevant legislation, and in this context, to inform the Personal Data Owners (Relevant Person) whose personal data are processed by the company, especially but not limited to those categorized in detail below.
In this way, it is aimed that Personal Data Owners are aware of the company policy, protect all their rights arising from the legislation regarding Personal Data and use them effectively.
In accordance with Article 12 of the Law, our company takes the necessary measures according to the nature of the data to be protected in order to prevent the unlawful disclosure, access, transfer of personal data or security deficiencies that may occur in other ways. In this context, our Company takes administrative measures to ensure the necessary level of security in accordance with the guidelines published by the Personal Data Protection Board ("Board"), conducts or has audits carried out.
With the law, special importance has been attached to some personal data due to the risk of causing victimization or discrimination when processed unlawfully. These data; race, ethnicity, political opinion, philosophical belief, religion, sect or other beliefs, disguise and dress, association, foundation or union membership, health, sexual life, criminal conviction and security measures, and biometric and genetic data. Special measures are taken and sensitive are taken by the Company in the protection of sensitive personal data processed in accordance with the law, which is determined as "special quality" by the Law and is considered sensitive without being limited to this.
The data controller ensures that the necessary trainings are organized for the business units in order to raise awareness to prevent the unlawful processing of personal data, unlawful access to personal data and to ensure the protection of personal data. Necessary systems are established to raise awareness of company employees on the protection of personal data, and work with consultants if needed.
The following basic principles are adopted by the Company within the scope of ensuring and maintaining compliance with the legislation on the protection of personal data:
Except for the explicit consent of the personal data owner, the basis of the personal data processing activity may be only one of the conditions stated below, or more than one condition may be the basis of the same personal data processing activity.
| Group of Data Subjects | Identification |
|---|---|
| Shareholders and Partners | Real persons who are shareholders/partners of the company |
| Employees | Individuals employed by the company as insured persons |
| Employee Candidates | Individuals who apply to work for the company electronically and/or physically |
| Potential Real Person Customer / Potential Customer’s Employees and Authorized Persons | Real persons, legal persons or employees and/or officials of real persons who have requested to use the Company’s products and/or services electronically or physically, or who have been determined to make a request in accordance with commercial practices and honesty rules |
| Real Person Customer / Customer’s Employees and Authorized Persons | Real persons, employees and/or authorized persons of real or legal persons who use or have used the products and/or services offered by the Company |
| Potential Business Partners Shareholder / Employee / Authorized Person | All real persons, including shareholders, authorized persons, and employees of real and/or legal persons with whom the company plans to establish any kind of business or service relationship (bank, partnership, supplier, contractor, etc.) |
| Business Partners Shareholder / Employee / Authorized Person | All real persons involved in any kind of business or service relationship in which the company is engaged (bank, partnership, supplier, contractor, etc.), including shareholders, authorized persons, and employees of legal entities. |
| Third Party Visitors | Real persons who access the www.usersdot.com website or mobile applications for various purposes that are not included in other categories in which the company processes their data (Website Visitor) |
| Group of Data Subjects | Categorization of Personal Data |
|---|---|
| Shareholders and Partners | Identity Data, Communication Data, Financial Data, Legal Transaction Data, Visual and Auditory Data |
| Employees | Identity Data, Communication Data, Personal Data, Financial Data, Visual and Auditory Data, Health Data, Appearance Data, Criminal and Security Measures Data |
| Employee Candidates | Identity Data, Communication Data, Professional Experience Data, Visual and Auditory Data |
| Potential Real Person Customer / Potential Customer’s Employees and Authorized Persons | Identity Data, Communication Data, Other (Request/Complaint Data) |
| Real Person Customer / Customer’s Employees and Authorized Persons | Identity Data, Communication Data, Financial Data, Customer Transaction Data, Transaction Security Data, Other (Request/Complaint Data) |
| Potential Business Partners Shareholder / Employee / Authorized Person | Identity Data, Communication Data |
| Business Partners Shareholder / Employee / Authorized Person | Identity Data, Communication Data, Other (Request/Complaint Data) |
| Third Party Visitors | Transaction Security Data |
| Processed Personal Data | Processing Purposes of Personal Data |
|---|---|
| Detailed information about the personal data of employees is published within the Company in a manner accessible only to our employees, and they have been duly informed about this matter. You can submit your requests regarding the processed personal data and exercise your rights by using one of the application methods specified in this Policy and also detailed in the Information Texts. You can access and download the Relevant Person Request Form from the Personal Data Protection section on www.usersdot.com. |
| Processed Personal Data | Processing Purposes of Personal Data |
|---|---|
Identity Data Contact Data Financial Data Visual and Auditory Data Legal Transaction Data |
Legal Basis of Compliance
|
| Processed Personal Data | Processing Purposes of Personal Data |
|---|---|
Identity Data Contact Data Professional Experience Data Visual and Audio Data |
Legal Basis of Compliance
|
| Processed Personal Data | Processing Purposes of Personal Data |
|---|---|
Identity Data Contact Data Other Data |
Legal Basis of Compliance
|
| Processed Personal Data | Processing Purposes of Personal Data |
|---|---|
Identity Data Communication Data Transaction Security Data Other Data |
Legal Basis of Compliance
|
| Processed Personal Data | Processing Purposes of Personal Data |
|---|---|
Identity Data Communication Data |
Legal Basis of Compliance
|
| Processed Personal Data | Processing Purposes of Personal Data |
|---|---|
Identity Data Contact Data Transaction Security Data |
Legal Basis of Compliance
|
| Processed Personal Data | Processing Purposes of Personal Data |
|---|---|
Transaction Security Data |
Legal Basis of Compliance
|
The data controller company processes special categories of personal data belonging to company shareholders, officials, and employees. Detailed information about these personal data is published within the company in a manner accessible only to the relevant individuals, who have been duly informed about this matter.
Individuals whose special categories of personal data are processed may, if they wish, submit their requests regarding the processed personal data and exercise their rights using one of the application methods specified in Article XII of this Policy.
All your personal data that you have shared with us are kept confidential in the database of the company and in physical documents in accordance with Article 12 of the Law on the Protection of Personal Data No. 6698.
Personal data processed for existing purposes, in accordance with Articles 8 and 9 of the Law, by specifying the purposes of transfer in detail in the Clarification Texts (real persons and private law legal entities within the scope of the relevant legislation (3. Person Private Institutions) and authorized public institutions and organizations (SGK, İŞ-KUR, Banks within the Banks Association of Turkey, Court of Accounts, Ministry of Finance, Central Bank, etc.).
Some data related to shareholders/partners and employees are directly related to the establishment or performance of a contract within the scope of the purposes of conducting investment processes, conducting management activities, conducting company advertising/promotion processes, provided that data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the person concerned, and stipulated in the fourth paragraph of Article 9 of the Law on the Protection of Personal Data; provided that appropriate assurances are provided and transferred to Investors or Potential Investors abroad.
Some data regarding employees are transferred to Social Network Providers abroad for the purposes of conducting employee satisfaction and loyalty processes, conducting performance evaluation processes, and conducting company advertising/promotion processes, provided that the appropriate safeguards stipulated in the fourth paragraph of Article 9 of the Personal Data Protection Law are provided.
Some of the general data regarding the data subjects are categorized in detail in the Clarification Texts and transferred to Cloud Service Providers abroad for the purposes specified, provided that the appropriate safeguards stipulated in the fourth paragraph of Article 9 of the Personal Data Protection Law, which were adopted after the amendment, are provided.
The Company takes the following measures as a minimum in order to ensure the security of the personal data it processes, to prevent unlawful access and to prevent unlawful data processing.
Pursuant to Article 11 of Law No. 6698, your rights over your personal data that you have shared with us within the scope of the purposes specified in this Personal Data Protection Policy and the methods of processing personal data are as follows. Pursuant to Article 11 of the Law, data owners have the following rights:
Your requests regarding these rights will be evaluated and concluded within 30 (thirty) days if delivered in writing to USERSDOT TECHNOLOGY AND CONSULTING INC.'s address “Ayazağa Mah. Kemerburgaz Cad. Vadi İstanbul Park Sitesi 7A Blok No:7B Kat:2 İç Kapı No:4 Sarıyer/İstanbul” by hand delivery, post, or cargo, or through a notary, or via secure electronic signature and mobile signature to our electronic mail (KEP) address [email protected] or to the company's email address [email protected].
Requests submitted by the data subject must include the following information: name, surname, signature if the application is in writing, TR identity number, nationality if the data subject is a foreigner, passport number or, if any, identity number, and the address of residence or workplace, email address for notification, telephone and fax numbers, and the subject of the request.
You can access and download the request form from the “Personal Data Protection” section on www.usersdot.com.
The relevant groups of persons whose personal data we process have accepted and declared that they know that the accuracy and up-to-date of the personal data received due to the contractual relationship is important for them to exercise their rights on their personal data in terms of KVKK and other relevant legislation, and that the responsibility arising from providing false information will be entirely their own.
Personal data regarding employees, shareholders/partners, employee candidates, real person customers, customer employees or officials, employees/officials of business partners, third party visitors are stored during the legal relationship and for 10 years from the termination of the relationship; Personal data regarding the potential real person customer/employee/official with whom no legal relationship is established, the potential legal person customer's employee/official, the employee or official of potential business partners, employee candidates are stored for a reasonable period of 2 years from the processing of the transaction security data for a maximum of 2 years in terms of the Internet Law No. 5651.
Your personal data processed for the purposes specified in this Personal Data Protection Policy; According to Article 7/f.1 of the Law No. 6698, when the purpose requiring processing disappears and according to Article 17 and Article 138 of the Turkish Penal Code, when the periods determined by the Laws have passed, it will be anonymized and continued to be used by us.
When the storage periods stipulated in the relevant legislation or required by the purpose of processing expire, within the 6-month period stipulated for periodic destruction; anonymizes the personal data it processes by using one or more techniques that are most suitable for business processes and activities, among the anonymization methods specified in the Guide on the Deletion, Destruction or Anonymization of Personal Data published by the Personal Data Protection Board, and continues to use the data in this way.
In this regard, a Storage and Disposal Policy has been established and is being implemented. Details of the main company procedure in this regard can be viewed from the Storage and Disposal Policy on the site.
The Company may make changes or updates to this Policy in accordance with legal regulations and Company Policy. Necessary information is provided to the relevant persons on the website about the new Policy text reflecting all these changes and updates.
This Policy has been updated as Version 2 and the necessary regulations have been complied with within the scope of the Law on the Amendment of the Criminal Procedure Law and Certain Laws published in the Official Gazette dated 12/3/2024 and numbered 32487, which also includes provisions regarding the Law on the Protection of Personal Data No. 6698.