Novatel Communication Solutions Inc. Personal Data Protection and Processing Policy

Novatel Communication Solutions Joint Stock Company (Novatel) This document prepared by contains the personal data protection and processing policy for all natural persons whose personal data is processed.

The purpose of this policy is to be clear about the personal data processing activity carried out in accordance with the law and the methods adopted for the protection of personal data, and to ensure transparency by informing the persons whose personal data is processed by our Company about the methods of protecting personal data security.

PURPOSE AND SCOPE

According to the Constitution of the Republic of Türkiye and the Personal Data Protection Law (KVKK), everyone has the right to request the protection of personal data concerning him/her.

Novatel, within the framework of legal purposes, shows the necessary care regarding the protection of personal data of real persons whose data is processed, especially employee candidates, company shareholders, officials, visitors, employees of institutions we cooperate with, shareholders and officials, people and customers who do business and transactions in our company.

The protection of personal data is a matter that Novatel attaches great importance to and approaches with sensitivity. Therefore, the necessary legal, administrative and technical measures are taken to protect personal data processed in accordance with the relevant legislation.

During the processing of personal data, Novatel

  • Processing personal data in accordance with the law and the rules of honesty,
  • Keeping personal data accurate and updated when necessary,
  • Processing personal data for specific, clear and legitimate purposes,
  • Limited and measured processing of personal data in connection with the purpose for which they are processed,
  • It is bound to retain personal data for the period stipulated in the relevant legislation or for the period required for the purpose for which they are processed.

Within the framework of these principles, Novatel

  • To enlighten and inform personal data owners,
  • Establishing the necessary system for personal data owners to exercise their rights,
  • To take the necessary administrative, technical and legal measures for the protection of personal data,
  • In the transfer of personal data to third parties in line with the requirements of the processing purpose, it acts in accordance with the relevant legislation, international legislation and the regulations of the Personal Data Protection Authority ("Agency").

Novatel acts in accordance with the relevant legislation and the Personal Data Protection Authority regulations in the processing of special personal data, and takes all measures to process special personal data in accordance with the legislation, and demonstrates sensitivity to these data and commitment to the basic principles.

PROCESSED PERSONAL DATA

Novatel, within the scope of the disclosure obligation under the provisions of the KVKK, informs personal data owners that it processes their personal data, the purposes of processing and the retention periods.

Although the data processed in terms of personal data categories is separately provided below, the concept of “personal data” in this Policy is accepted as any direct or indirect information that is processed automatically or kept in a data recording system, even if not automatically, and has the ability to distinguish one individual from another.

Identity Information: Information such as name-surname, Turkish identity number, nationality, mother's name-father's name, place of birth, date of birth, gender and documents containing this information such as driver's license, identity card and passport, as well as tax number, SSI number, signature information, vehicle license plate, etc.

Contact Information: Information such as telephone number, address, e-mail address, fax number, IP address.

Family Members and Relatives Information: Information about the personal data owner's family members (e.g. spouse, mother, father, child), relatives and other persons who can be reached in emergency situations.

Physical Space Security Information: Personal data related to records and documents taken at the entrance to the physical location, during the stay in the physical location, processed partially or fully automatically or non-automatically as part of the data recording system; camera records, fingerprint records and records taken at the security point, etc.

Financial Information: Personal data processed regarding information, documents and records showing all kinds of financial results that clearly belong to an identified or identifiable natural person, as well as data such as bank account number, IBAN number, credit card information, financial profile, asset data, income information, etc.

Audio/Visual Information: Data contained in photographs, camera recordings, sound recordings and documents that are copies of documents containing personal data.

Personal Information: Any personal data processed to obtain information that will form the basis for the establishment of personal rights of real persons in an employment relationship.

Special Personal Data: Data regarding individuals' race, ethnic origin, political views, philosophical beliefs, religion, sect or other beliefs, appearance and dress, membership in associations, foundations or unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.

PROCESSING OF PERSONAL DATA

Novatel carries out processing activities in a manner that is compliant with the Constitution, KVKK and other legal regulations, complies with the law and rules of honesty in the processing of personal data, is accurate and up-to-date, pursues specific, clear and legitimate purposes, and is related to the processing purpose, is limited and proportionate.

Data processing activity carried out by Novatel;

  • It is clearly stated in the laws,
  • If it is necessary for the protection of the life or physical integrity of a person or someone else who is unable to give his consent due to a physical impossibility or whose consent is not legally valid,
  • The processing of personal data of the parties to a contract is necessary, provided that it is directly related to the establishment or performance of a contract,
  • It is mandatory for the data controller to fulfill its legal obligations,
  • It has been made public by the relevant person himself,
  • It is mandatory to fulfill legal obligations in the fields of employment, occupational health and safety, social security, social services and social assistance,
  • Data processing is mandatory for the establishment, exercise or protection of a right,
  • Provided that it does not harm the fundamental rights and freedoms of the person concerned, data processing is mandatory for the legitimate interests of the data controller or, if necessary, directly based on the explicit consent of the data owner.

In terms of special data, the processing activity is limited to the cases stipulated by law, excluding sexual life and health information. Sexual life and health information is processed only for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and their financing.

Novatel, in accordance with the legislation, informs personal data owners and provides the necessary information when personal data owners request information.

  1. Processing in Accordance with Law and Fairness

Novatel acts in accordance with legal regulations, principles, general and honesty rules in the processing of personal data, and does not process personal data for purposes other than those announced to the data owners, with the obligation to enlighten the personal data.

  1. Ensuring Personal Data is Accurate and Up-to-Date

Novatel takes the necessary measures and makes arrangements to ensure that the personal data it processes is as accurate and up-to-date as possible, taking into account the rights and legitimate interests of personal data owners.

  1. Processing in Accordance with Specific, Clear and Legitimate Data Owner's Service Request

Novatel clearly determines the legitimate and lawful purpose of the data owner and processes it as much as is necessary for the commercial activity it carries out and the requested service.

  1. Being Relevant, Limited and Proportionate to the Purpose for Which They Are Processed

Novatel processes the data as much as necessary for the commercial activity and the requested service by clearly determining the legitimate and lawful purpose of the data owner. It avoids processing personal data that is not relevant to the achievement of the purpose or is not needed.

  1. Preservation for the Period Stipulated in the Relevant Legislation or Necessary for the Purpose for which they are Processed

Novatel stores personal data for the period specified in the relevant legislation or necessary for the purpose for which they are processed. If the period expires or the reasons requiring processing disappear, personal data is deleted, destroyed or brought into compliance with legal regulations.

  1. Informing the Personal Data Owner

During the collection of personal data, Novatel clearly informs personal data owners about its identity as the data controller, the purpose for which it will process personal data, to whom and for what purposes it can transfer personal data, the legal basis and collection method for collecting personal data, and the rights of the data owner.

The personal data owner has the right to "request information". The personal data owner is also informed by Novatel about the methods, procedures and principles regarding the use of the right in question.

  1. Taking Care in Processing Special Personal Data

Novatel avoids processing data that is determined to be of a “special nature” and carries the risk of causing discrimination or victimization to individuals when processed unlawfully, especially by not receiving the data, and shows the necessary care and sensitivity in cases where it is necessary not to process it;

If the personal data owner has given his/her explicit consent and the information is mandatory for processing, or if the personal data owner does not have his/her explicit consent;

-Special personal data other than the health and sexual life of the personal data owner, in cases prescribed by law,

- In cases where it is necessary for the protection of the life or physical integrity of the person or someone else who is unable to give his consent due to a physical impossibility or whose consent is not legally valid,

-It processes sexual life and health information in accordance with the Law only for the purpose of protecting public health, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and their financing.

PURPOSES OF PROCESSING PERSONAL DATA

Novatel processes personal data limited to the processing purposes and conditions set forth in the KVKK and other relevant legislation. These purposes and conditions are;

  • Processing of personal data is clearly foreseen in the laws to which Novatel is subject,
  • The processing of personal data by Novatel is directly related to and necessary for the establishment or performance of a contract,
  • Processing of personal data is mandatory for Novatel to fulfill its legal obligations,
  • Provided that personal data has been made public by you; processing of you by Novatel in a limited way for publicization purposes,
  • The processing of your personal data by Novatel is mandatory for the establishment, exercise or protection of the rights of Novatel or you or third parties,
  • It is mandatory to process personal data for Novatel's legitimate interests, provided that it does not harm your fundamental rights and freedoms,
  • If Novatel's personal data processing activity is necessary to protect the life or physical integrity of the personal data owner or someone else, and in this case the personal data owner is unable to express his/her consent due to actual or legal invalidity,
  • In terms of special personal data other than the health and sexual life of the personal data owner, it is mandatory and prescribed by law,
  • It is mandatory to fulfill legal obligations in the fields of employment, occupational health and safety, social security, social services and social assistance,
  • In terms of special personal data regarding the health and sexual life of the personal data owner, individuals or authorized institutions and organizations under the obligation of confidentiality, for the purpose of protecting public health, carrying out preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and their financing. is processed by.

For these purposes and within the scope of the work carried out, Novatel;

  • Planning and execution of corporate and business activities
  • Event (organization) management
  • Management of relationships with business partners, solution partners or suppliers or contractual service providers
  • Novatel, execution of personnel recruitment processes
  • Execution and monitoring of Novatel financial reporting and risk management transactions
  • Novatel, legal requirements and execution and follow-up of legal affairs
  • Carrying out accounting transactions,
  • Planning and execution of corporate communication activities
  • Execution of corporate governance activities
  • Carrying out company and partnership law transactions
  • Request and complaint management
  • Supporting the planning and execution processes of fringe rights and benefits to be provided to Novatel's senior managers and the company.
  • Carrying out work to protect Novatel's reputation
  • Managing investor relations
  • Providing information regarding legislation to authorized institutions
  • Procurement and service acquisition and ensuring service continuity,
  • Creating and tracking visitor records
  • Creating and tracking customer records
  • Keeping records and tracking the work carried out with the corporate partnership
  • It is processed for the purposes of sharing and tracking information with affiliated companies for the purpose of purchasing or providing services in accordance with the contract for the purpose of performing the work and/or providing the service.

If the processing activity carried out for the aforementioned purposes does not meet any of the purposes and conditions listed above, your explicit consent is obtained.

TRANSFER OF PERSONAL DATA

Novatel may transfer the personal data and sensitive personal data of the personal data owner to third parties by taking the necessary security measures in line with legal personal data processing purposes.

  • If the personal data owner has explicit consent,
  • If there is a clear regulation in the law regarding the transfer of personal data,
  • If it is necessary to protect the life or physical integrity of the personal data owner or someone else and the personal data owner is unable to express his/her consent due to actual impossibility or if his/her consent is not given legal validity;
  • If it is necessary to transfer personal data of the parties to the contract, provided that it is directly related to the establishment or performance of a contract,
  • If personal data transfer is mandatory to fulfill a legal obligation,
  • If personal data has been made public by the personal data owner,
  • If personal data transfer is mandatory for the establishment, exercise or protection of a right,
  • If personal data transfer is mandatory for Novatel's legal interests, provided that it does not harm the fundamental rights and freedoms of the personal data owner, your personal data may be transferred to third parties by taking the necessary security measures.

As for your personal data of a special nature, provided that adequate measures are taken, if the transfer is clearly foreseen in the law for your personal data of a special nature other than your sexual life and health information, or if it is mandatory for the fulfillment of legal obligations in the fields of employment, occupational health and safety, social security, social services and social assistance; your sexual life and health information may only be transferred to persons or authorized institutions and organizations that are under a confidentiality obligation for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and their financing.

TRANSFER OF PERSONAL DATA ABROAD

Personal data may only be transferred abroad if at least one of the processing conditions specified in Articles 5 and 6 of the Personal Data Protection Law No. 6698 is present and under the following conditions:

  1. Transfer to Countries with an Adequacy Decision:

Personal data may be transferred to countries that have been determined to have adequate protection by the Personal Data Protection Authority and that have been given an adequacy decision, in accordance with the relevant legislation.

  1. Transfer to Countries Without an Adequacy Decision:
  2. Transfers may be made if one of the following appropriate safeguards is provided and the person concerned has the opportunity to exercise his or her rights and access effective remedies in the country to which the transfer is to be made:
  3. Binding company rules approved by the institution,
  4. Standard contract provisions signed by the parties and published by the Institution,
  5. A commitment letter that has been put into effect with the permission of the institution and provides sufficient protection,

d. Agreements made between public institutions/organizations with the permission of the Institution and that do not have the nature of an international contract.

  1. Transfer in Exceptional Cases

If the above conditions cannot be met, personal data may be transferred abroad only within the scope of exceptional cases listed in Article 9/6 of the Law (for example, with the explicit consent of the relevant person, performance of contract, public interest, protection of life, etc.).

  1. Notification and Responsibility

Standard contracts will be notified to the Authority within five working days after they are signed; data controllers and data processors are responsible for complying with all obligations under this article, including the subsequent transfer of transferred data.

THIRD PARTIES TO WHICH PERSONAL DATA IS TRANSFERRED AND THE PURPOSES OF TRANSFER

Within the scope of the legislation regarding the protection of personal data that it is subject to, Novatel notifies the personal data owner of the groups of persons to whom personal data is transferred. Novatel may transfer the personal data of data owners to the categories of persons listed below.

It may transfer and process personal data to its business partners, suppliers, shareholders, company officials and employees who will perform the work, legally authorized public institutions and organizations, legally authorized private law persons and persons-institutions and organizations authorized to audit, units necessary for the performance of accounting transactions, institutions and organizations to which Novatel must transfer due to the work and businesses it is engaged in, domestic or foreign auxiliary and ancillary service organizations and third parties required by the service or contract received or desired by the data owner.

ISSUES RELATED TO THE PROTECTION OF PERSONAL DATA AND ENSURING SECURITY

Novatel has taken all necessary legal, technical and administrative measures to ensure the appropriate level of security in order to prevent unlawful processing and access of personal data and to ensure the preservation of such data in accordance with the KVKK regulations. It carries out or has carried out the necessary inspections for the protection of personal data. Within the scope of this purpose;

  • Personal data processing activities carried out within Novatel are audited by established technical systems.
  • The technical measures taken are periodically inspected and reported by the internal mechanism.
  • Technically knowledgeable personnel are employed.
  • Technical measures are taken in accordance with the developments in technology, and the measures taken are periodically updated and renewed.
  • Access and authorization technical solutions are implemented in accordance with legal compliance requirements determined on a business unit basis.
  • Access authorizations are limited and authorizations are reviewed regularly.
  • The technical measures taken are periodically reported to the relevant person in accordance with the internal audit mechanism, and the issues that pose a risk are re-evaluated and the necessary technological solutions are produced.
  • Software and hardware including virus protection systems and firewalls are installed.
  • Regular security scans are carried out to detect security vulnerabilities in applications where personal data is collected; The existing gaps are closed.
  • Employees are informed and trained about personal data protection law and the lawful processing of personal data.
  • Novatel determines the internal functioning of a business unit and its activities required to ensure compliance with the personal data processing conditions sought by the KVKK in the personal data processing activities carried out by the business units.
  • In order to ensure legal compliance as required by the business, the relevant working units are informed and application rules are determined; necessary administrative and legal measures are taken to ensure the supervision of these issues and the continuity of the application.
  • Records are included in the contracts and documents between Novatel and its employees, which impose obligations not to process, disclose or use personal data, except for instructions and exceptions provided by law, and periodic audits are carried out in this regard.
  • Employees have been informed that they cannot disclose the personal data they have learned to anyone else in violation of the provisions of KVKK and that they cannot use it for purposes other than processing, and the consequences of these, and the necessary contractual and administrative measures have been taken.

STORING PERSONAL DATA IN A SECURE ENVIRONMENT

Novatel has taken the necessary technical and administrative measures, according to technological possibilities and implementation costs, to store personal data in secure environments and to prevent them from being processed, destroyed, lost, changed or disclosed for unlawful purposes.

  • Systems compatible with technological developments are used to store personal data in secure environments.
  • Personnel specialized in technical matters have been employed.
  • Technical security systems are established for storage areas and the technical measures taken are periodically inspected by the internal audit mechanism, technological solutions are produced when necessary and support is received from solution partners.
  • Programs are used in accordance with the law to ensure that personal data is stored securely.
  • Improper access or access attempts to data storage areas containing personal data are reported to the relevant parties and technological and legal solutions are produced when necessary.
  • Employees are trained to ensure that personal data is stored securely.
  • In case of outsourcing services due to technical requirements for the storage of personal data, the contracts concluded with the relevant companies to which personal data are transferred in accordance with the law contain provisions stating that the necessary security measures will be taken to protect personal data and that these measures will be ensured in their own organizations.

Novatel has taken the necessary measures to prevent personal data processed in accordance with the KVKK regulations from being obtained by others through illegal means. However, if personal data is obtained through illegal means despite all precautions taken, Novatel operates a system that ensures that this situation is reported to the relevant personal data owner, the Institution and the relevant legal units as soon as possible.

Within the scope of the protection of personal data, all technical and administrative measures and precautions listed above have been taken to ensure the protection of data defined as “special nature” by the KVKK, if the collection of data is mandatory and necessary.

PROCESSING OF DATA OBTAINED THROUGH THE WEBSITE AND THE INTERNET

Novatel may record the internet movements and personal data on its own websites using technical means in order to ensure that the data of those who visit these sites, transact and receive services through the website are processed in accordance with the purposes for which they report their data on the sites; to be able to show them customized content and engage in online advertising activities; and to enable them to access the services and information they desire.

RIGHTS OF PERSONAL DATA OWNERS

Novatel guides the personal data owner by informing him of his rights in accordance with the legislation regarding the regulation of personal data; It carries out the necessary administrative and technical arrangements to evaluate the rights of personal data owners and provide the necessary information to personal data owners.

  • Learning whether personal data is processed or not,
  • If your personal data has been processed, request information regarding the processing of your data,
  • Learning the purpose of processing personal data and whether they are used for their intended purpose,
  • Knowing the third parties to whom personal data is transferred at home or abroad,
  • To request correction of personal data if it is processed incompletely or incorrectly by Novatel and to request notification of the transaction made to third parties to whom personal data is transferred,
  • Requesting the deletion or destruction of personal data in case the reasons requiring processing no longer exist, even though it has been processed in accordance with the provisions of KVKK and other relevant laws, and requesting that the transaction carried out in this context be notified to third parties to whom personal data has been transferred,
  • Objecting to the emergence of a result against the person by analyzing the processed data through automatic systems,
  • In case of damage due to unlawful processing of personal data, they have the right to demand compensation for the damage.

RIGHT OF APPLICATION OF PERSONAL DATA OWNERS

Personal data owners can exercise their right to obtain information through Novatel's website, via the e-mail address published on the site, in person with a wet-signed identity document, or by sending it through a notary to the address "Oruçreis Mah. Vadi Cad. İstanbul Ticaret Sarayı Apt. No: 108/301 Esenler/ İstanbul".

In order for third parties to request an application on behalf of personal data owners, there must be a special power of attorney issued by the data owner through a notary public on behalf of the person who will apply, and if the applicant is a guardian, a copy of the decision given by the court must be submitted.

If the personal data owner submits his/her request in accordance with the procedure, Novatel will finalize the relevant request within thirty days at the latest, depending on the nature of the request.

If the personal data owner's application to the data controller is rejected, the response is found insufficient or the application is not responded to within the time limit, the personal data owner may lodge a complaint with the Personal Data Protection Authority within thirty days from the date on which he/she learns of the response and, in any case, within sixty days from the date of application.                  

                                                                                    NOVATEL HABERLEŞME SOLUTIONS INC.

illumination text