Personal Data Retention and Disposal Policy
AS KARE SAĞLIK ÜRÜNLERİ PAZARLAMA DANIŞMANLIK YAZILIM HİZMETLERİ SAN. VE DIŞ TİC. A.Ş. PERSONAL DATA RETENTION AND DESTRUCTION POLICY
Last Updated: [01.08.2026]
Table of Contents
INTRODUCTION
A. PURPOSE AND SCOPE
B. GENERAL PRINCIPLES REGARDING RETENTION AND DESTRUCTION
C. RECORDING MEDIA
D. EXPLANATIONS REGARDING RETENTION AND DESTRUCTION
1. Legal Grounds
2. Processing Purposes
3. Grounds Requiring Destruction
E. MEASURES
F. DESTRUCTION TECHNIQUES
G. RESPONSIBLE UNIT
H. RETENTION AND DESTRUCTION PERIODS
I. PERIODIC DESTRUCTION
J. DEFINITIONS
K. UPDATES
L. EFFECTIVENESS
ANNEX – AS KARE RETENTION AND DESTRUCTION PERIODS TABLE
INTRODUCTION
Your privacy and the security of your personal data are important to AS Kare Sağlık Ürünleri Pazarlama Danışmanlık Yazılım Hizmetleri San. ve Dış Tic. A.Ş. We do not retain your personal data for longer than necessary for the purposes for which it is processed, particularly on the basis of the possibility that it may be used in the future, and we destroy it in accordance with applicable law once the purpose of processing ceases to be valid.
A. PURPOSE AND SCOPE
This Personal Data Retention and Destruction Policy (“Policy”) has been prepared pursuant to the Law No. 6698 on the Protection of Personal Data (“KVKK”) and the Regulation on Deletion, Destruction or Anonymization of Personal Data (“Regulation”), published in the Official Gazette dated 28 October 2017 and entered into force as of 1 January 2018, in order to establish the procedures and principles regarding the retention and destruction activities carried out by our Company, AS Kare Sağlık Ürünleri Pazarlama Danışmanlık Yazılım Hizmetleri San. ve Dış Tic. A.Ş., acting as the data controller (“As Kare,” “Torq Nutrition” or the “Company”).
The purpose of this Policy is to provide information regarding the principles for determining the maximum period necessary for the purposes for which personal data are processed and the processes for deleting, destroying and anonymizing personal data. All activities and procedures concerning the retention and destruction of personal data are carried out by our Company in accordance with this Policy.
This Policy covers personal data belonging to employees, job applicants, employees’ family members, supplier employees and visitors, and applies to all recording media owned or managed by the Company where personal data are processed and to all activities involving the processing of personal data.
B. GENERAL PRINCIPLES REGARDING RETENTION AND DESTRUCTION
The principles set forth in Article 7 of the Regulation are complied with in the preparation and implementation of this Policy and in the processing of personal data.
If all of the conditions for processing personal data set forth in Articles 5 and 6 of the KVKK cease to exist, personal data shall be deleted, destroyed or anonymized ex officio by the data controller or upon the request of the data subject.
The following principles set forth in Article 4 of the KVKK are fully complied with when deleting personal data:
Processing in accordance with the law and the principles of good faith,
Being accurate and, where necessary, up to date,
Being processed for specific, explicit and legitimate purposes,
Being connected with, limited to and proportionate to the purposes for which they are processed,
Being retained for the period stipulated in the relevant legislation or necessary for the purpose for which they are processed.
The technical and administrative measures regulated under Article 12 of the KVKK and additionally recommended by the Board are complied with during the retention and destruction processes carried out by the data controller. Detailed information regarding the technical and administrative measures implemented by As Kare is provided in the Measures section of this Policy.
The data controller acts in accordance with the decisions issued by the Board regarding the retention and destruction of personal data.
All operations relating to the deletion, destruction and anonymization of personal data are recorded, and such records are retained for at least 5 years, without prejudice to other legal obligations. Unless otherwise decided by the Board, the data controller selects the most appropriate method among deletion, destruction or anonymization and applies such methods by taking the security of personal data into consideration.
C. RECORDING MEDIA
Personal data belonging to data subjects are securely retained by As Kare in accordance with the KVKK and other applicable legislation. While establishing its own recording media, As Kare takes the security of personal data into consideration and, when selecting service providers, also considers the security level of the recording media used by the relevant data processors.
Personal data belonging to data subjects are securely retained in the following recording media in accordance with the KVKK and applicable legislation:
Physical files,
Workplace database,
Employees’ personal computers,
Contact forms completed by customers,
Company bank account records,
E-mail accounts,
Order portal,
Integrator systems,
ERP system,
Contracted shipping companies,
Reporting service,
YandexMail, Oniks Soft,
LinkedIn, Kariyer.net and HR Firms,
Instagram,
WhatsApp,
NetGSM, Setrow,
SmartPSS.
D. EXPLANATIONS REGARDING RETENTION AND DESTRUCTION
Our Company retains and destroys personal data belonging to employees, employees’ family members, job applicants, supplier employees and visitors in accordance with the KVKK.
Article 3 of the KVKK defines the concept of processing personal data, while Article 4 stipulates that processed personal data must be connected with, limited to and proportionate to the purpose for which they are processed and must be retained for the period prescribed by the relevant legislation. Article 5, on the other hand, sets forth the conditions for processing personal data.
Accordingly, within the scope of our Company’s activities, personal data are retained for periods appropriate to the purposes of processing and the periods prescribed by the relevant legislation.
1. Legal Grounds
Our Company retains the personal data it processes within the scope of its business activities on the following legal grounds:
Explicit consent,
Legal obligation,
Legitimate interest,
Establishment or performance of a contract.
The retention periods of personal data retained on these legal grounds are determined according to the legal regulations underlying the respective legal grounds.
The legal regulations forming the basis for the retention periods of personal data at our Company are as follows:
Law No. 6698 on the Protection of Personal Data,
Turkish Commercial Code No. 6102,
Turkish Code of Obligations No. 6098,
Law No. 6502 on Consumer Protection,
Law No. 6563 on the Regulation of Electronic Commerce,
Social Insurance and Universal Health Insurance Law No. 5510,
Tax Procedure Law No. 213,
Law No. 5651 on the Regulation of Publications on the Internet and Combating Crimes Committed Through Such Publications,
Occupational Health and Safety Law No. 6331,
Right to Information Law No. 4982,
Law No. 3071 on the Exercise of the Right to Petition,
Labour Law No. 4857,
Veterinary Services, Plant Health, Food and Feed Law No. 5996,
Cosmetics Law No. 5324,
Regulation on Food Supplements,
Turkish Food Codex Regulation on Food Labelling and Consumer Information,
Turkish Food Codex Regulation on Nutrition and Health Claims,
Cosmetics Regulation,
Regulation on Health and Safety Measures to be Taken in Workplace Buildings and Annexes,
Regulation on Archival Services,
Regulation on Promotional Activities for Human Medicinal Products,
Other secondary legislation currently in force pursuant to the above-mentioned legal regulations.
2. Processing Purposes
Our Company retains the personal data it processes within the scope of its business activities for the following purposes:
Evaluating job applications,
Contacting job applicants where the CV is positively evaluated,
Delivery of vehicles to employees,
Making salary, bonus and similar payments to employees,
Obtaining company telephone lines for employees,
Sending documents or marketing materials,
Sending documents such as invoices and packing lists,
Creating current accounts for the procurement of services or products,
Sending e-mails for the purpose of providing information regarding campaigns,
Creating personnel files,
Ensuring shipment,
Opening current accounts for product sales,
Delivering products to the relevant address,
Issuing meal cards,
Ensuring security.
3. Grounds Requiring Destruction
Personal data shall be deleted, destroyed or anonymized by our Company upon the request of the relevant person or ex officio in the following circumstances:
Amendment or repeal of the provisions of the relevant legislation constituting the basis for processing the personal data,
Elimination of the purpose requiring the processing or retention of the personal data,
Withdrawal of explicit consent by the relevant person where personal data are processed solely on the basis of explicit consent,
Acceptance of an application made by the data subject for the deletion or destruction of personal data within the scope of the rights set forth in Article 11 of the KVKK,
Where the application made by the data subject to the data controller requesting the deletion, destruction or anonymization of personal data is rejected, the response is found insufficient, or no response is provided within the period prescribed under the KVKK, and the data subject files a complaint with the Board and the Board decides to accept the data subject’s request,
Expiration of the maximum period for retaining personal data where there is no condition justifying a longer retention period.
E. MEASURES
In order to protect your personal data and prevent unlawful access thereto, our Company takes the necessary administrative and technical measures in accordance with the Personal Data Security Guide published by the Personal Data Protection Authority. Procedures are established within the Company, privacy notices and explicit consent texts are prepared, and the necessary audits are carried out and/or commissioned from external service providers to ensure compliance with the provisions of the KVKK pursuant to Article 12 thereof.
The results of these audits are evaluated within the Company’s internal operations, and necessary activities are carried out to improve the measures taken.
We attach particular importance to taking the necessary measures, to the extent possible and according to the nature of the data to be protected, in order to prevent unlawful disclosure, access, transfer or other security breaches involving personal data. We attach great importance to the security of environments in which personal data are stored, whether such environments are under our control or within the systems of service providers acting as data processors.
The technical and administrative measures taken by our Company to ensure the security of personal data are explained in detail below under two headings.
a. Technical Measures
Network security and application security are ensured,
Key management is implemented,
The security of personal data stored in cloud environments is ensured,
Data loss prevention software is used,
Encryption is applied,
User account management and authorization control systems are implemented and monitored,
Log records are maintained in a manner preventing user intervention,
Up-to-date anti-virus systems are used,
Firewalls are used,
Access authorizations of employees whose duties change or who leave the Company are revoked,
Access logs are regularly maintained,
An authorization matrix is established for employees,
Closed-system networks are used for personal data transfers over networks,
Security measures are taken within the scope of the development and maintenance of information technology systems,
Personal data security issues are reported promptly,
Necessary security measures are taken regarding entry to and exit from physical environments containing personal data,
Physical environments containing personal data are protected against external risks such as fire and flooding,
The security of environments containing personal data is ensured,
Personal data stored in cloud systems are backed up and the security of such backups is ensured,
Penetration testing is conducted,
Cybersecurity measures are implemented and continuously monitored,
Special categories of personal data transferred through portable memory devices, CDs or DVDs are encrypted before transfer.
b. Administrative Measures
Confidentiality undertakings are executed,
Awareness of data processor service providers regarding data security is ensured,
The obligation to inform is fulfilled,
Protocols and procedures regarding the security of special categories of personal data are established and implemented,
Periodic and/or random internal audits are conducted and/or commissioned,
Corporate policies concerning access, information security, use, retention and destruction are prepared and implemented,
Employees receive periodic training and awareness programs regarding data security,
Executed contracts contain data security provisions,
Personal data are minimized to the extent possible,
Data processor service providers are periodically audited with respect to data security.
F. DESTRUCTION TECHNIQUES
At the end of the period prescribed by the relevant legislation or the retention period necessary for the purpose for which personal data are processed, personal data are destroyed by As Kare ex officio or upon the application of the relevant person in accordance with the applicable legislation.
During the destruction process, the recommendations contained in the Guide on Deletion, Destruction or Anonymization of Personal Data published by the Personal Data Protection Authority are taken into consideration and the most appropriate destruction method is selected.
Depending on the type of recording medium targeted by the destruction technique applied by our Company, the responsible unit maintains records concerning the destruction procedure, and such records are retained for 5 years independently of other obligations.
The destruction methods applied by our Company are listed below under the headings of deletion, destruction and anonymization.
a. Deletion of Personal Data
a.1. Deletion Process
During the deletion process, the personal data subject to deletion are first identified. Subsequently, the relevant users for each personal data element are identified by using an access authorization and control matrix or a similar system.
Following the identification of the relevant users’ access, retrieval and reuse authorities and methods, such users’ access, retrieval and reuse authorities and methods concerning the relevant personal data are closed and eliminated.
a.2. Deletion Techniques
Personal Data Stored on Servers: For personal data stored on servers for which the retention period has expired, the system administrator removes the access rights of the relevant users and performs the deletion. Our Company uses Yandex 360 systems. Data stored in the cloud system are deleted by issuing the relevant deletion command, without granting the relevant user the authority to restore deleted data from the cloud system.
Personal Data Stored in Electronic Media: Personal data stored in electronic media for which the retention period has expired are made inaccessible and unusable by employees other than the database administrator (relevant users).
Files Stored on Central Servers: The file is deleted using the deletion command of the operating system, or the relevant user’s access rights to the directory containing the file are removed. When performing this operation, it is ensured that the relevant user is not also a system administrator.
Personal Data Stored in Physical Media: Personal data stored in physical media for which the retention period has expired are made inaccessible and unusable by all employees other than the unit manager responsible for the document archive. Where necessary, redaction is also applied by crossing out, painting over or erasing the relevant information so that it cannot be read.
Personal Data Stored on Portable Media: Personal data stored on flash-based storage media for which the retention period has expired are encrypted by the system administrator, and access authority is granted solely to the system administrator. Encryption keys are securely stored.
Databases: Relevant rows containing personal data are deleted using database commands such as DELETE. When performing this operation, it is ensured that the relevant user is not also a database administrator.
b. Destruction of Personal Data
b.1. Destruction Process
Our Company may destroy personal data that have been processed in accordance with the applicable legislation when the grounds requiring their processing cease to exist, either upon its own decision or at the request of the data subject.
Destruction of personal data means rendering personal data completely inaccessible, irretrievable and unusable by anyone in any manner whatsoever.
b.2. Destruction Techniques
Personal Data Stored in Physical Media: Personal data stored on paper for which the retention period has expired are destroyed irreversibly using paper shredders and/or by burning.
Personal Data Stored on Optical/Magnetic Media: Personal data stored on optical and magnetic media for which the retention period has expired are physically destroyed by melting, burning or reducing the media to powder. Magnetic media may also be rendered unreadable by exposing them to a high-intensity magnetic field using a specialized device.
For the destruction of personal data, all copies containing the relevant data must first be identified, and one or more of the methods below must be used depending on the type of system in which the data are stored:
Local Systems
One or more of the following methods may be used to destroy data stored on such systems:
i) Degaussing: The process of exposing magnetic media to a very high magnetic field using a specialized device, thereby irreversibly corrupting the data stored on the media.
ii) Physical Destruction: The physical destruction of optical and magnetic media by melting, burning, reducing to powder or similar methods. Data are rendered inaccessible by melting, burning, pulverizing or passing optical or magnetic media through a metal shredder. For solid-state drives, if overwriting or degaussing is unsuccessful, the media are physically destroyed.
Environmental Systems
Depending on the type of environment, the following destruction methods may be used:
i) Network devices (switches, routers, etc.): Storage media within such devices are generally fixed. Although these products often have deletion commands, they do not necessarily have a destruction function.
ii) Flash-based media: Flash-based hard drives with compatible interfaces are destroyed using the <block erase> command where supported; where not supported, the destruction method recommended by the manufacturer is used.
iii) Magnetic tape: These are storage media that retain data through microscopic magnetic particles on flexible tape. They are destroyed by degaussing through exposure to strong magnetic fields or by physical destruction methods such as burning or melting.
iv) Magnetic disks and similar units: These are storage media that retain data through microscopic magnetic particles on flexible or fixed surfaces. They are destroyed by degaussing through exposure to strong magnetic fields or by physical destruction methods such as burning or melting.
v) Mobile phones (SIM cards and fixed storage areas): Fixed storage areas in portable smartphones generally have deletion commands but do not have destruction commands. One or more of the appropriate methods specified in this destruction policy are used to destroy the relevant data.
vi) Optical disks: These include data storage media such as CDs and DVDs. They are destroyed through physical destruction methods such as burning, breaking into small pieces or melting.
Physical Media on Paper
Personal data stored on such media are destroyed by physically destroying the original medium because the data are permanently recorded on the physical medium.
During this process, the paper is destroyed using paper destruction or shredding machines into pieces of a size that makes the information incomprehensible, preferably by shredding both horizontally and vertically, so that the pieces cannot be reassembled.
Personal data transferred from the original paper format to electronic media through scanning are destroyed using one or more of the appropriate methods specified in this destruction policy according to the electronic medium on which they are stored.
Cloud Environment
During the storage and use of personal data in such systems, the data must be encrypted using cryptographic methods and, where possible, separate encryption keys must be used for each cloud solution used for personal data.
When use of the cloud system ends, all copies of the encryption keys necessary to render the personal data usable must be destroyed.
Destruction of Personal Data on Defective or Serviced Devices
In addition to the environments described above, the destruction of personal data contained in devices that are defective or sent for maintenance shall be carried out as follows:
i) Before the relevant devices are transferred to third parties such as manufacturers, sellers or service providers for maintenance or repair, the personal data contained therein shall be destroyed using one or more of the appropriate methods specified in this destruction policy.
ii) Where destruction is not possible or appropriate, the storage medium shall be removed and retained, while the other defective components may be sent to manufacturers, sellers or service providers.
iii) Necessary measures shall be taken to prevent personnel arriving from external parties for maintenance or repair purposes from copying personal data and taking such data outside the Company.
c. Anonymization of Personal Data
c.1. Anonymization Process
Anonymization of personal data means rendering personal data incapable of being associated in any manner with an identified or identifiable natural person, even when combined with other data.
Although personal data may have been processed in accordance with the relevant legislation, where the reasons requiring their processing cease to exist, the data controller may anonymize such data upon its own decision or at the request of the data subject.
Anonymization means preventing the identification of the relevant person by removing or changing all direct and/or indirect identifiers in a data set, or eliminating the ability of the person to be distinguished within a group or crowd in a manner that prevents the data from being associated with a natural person.
As a result of anonymization processes carried out by our Company, personal data cannot be associated with data subjects by our Company or third parties, even through techniques such as matching the data with other datasets.
Our Company may apply different anonymization techniques depending on the nature of the relevant data.
c.2. Anonymization Techniques
Anonymization Methods Providing Value Irregularity: Existing values are changed through methods that introduce value irregularity, thereby creating distortion in the values within the dataset. Since the values contained in the records are changed, the benefit intended to be obtained from the dataset must be accurately calculated. Even though the values in the dataset are changed, it may still be possible to benefit from the data by ensuring that overall statistical results are not distorted.
Anonymization Methods Not Providing Value Irregularity: In methods that do not introduce value irregularity, the values in the dataset are not changed, added or removed. Instead, changes are made to the entirety of rows or columns in the dataset. Thus, while the dataset as a whole is modified, the values within the relevant fields retain their original form.
Variable Removal: This anonymization method is achieved by completely removing one or more variables from the table. In such cases, the entire relevant column is removed. This method may be used where the variable is a high-degree identifier, no more appropriate solution exists, the variable contains highly sensitive information that cannot be publicly disclosed, or the variable does not serve analytical purposes.
Record Removal: In this method, anonymity is strengthened by removing a unique row from the dataset, thereby reducing the possibility of making assumptions about the dataset. Generally, the removed records are those that do not share a common value with other records and about which persons familiar with the dataset could easily make predictions.
Regional Suppression: The purpose of regional suppression is to make the dataset more secure and reduce the risk of predictability. Where the combination of values associated with a particular record creates a very rare situation and is highly likely to make the individual distinguishable within the relevant population, the exceptional value is changed to “unknown.”
Generalization: This is the process of converting a relevant personal data value from a specific value into a more general value. It is commonly used when generating cumulative reports and conducting operations based on aggregate figures. The resulting values represent aggregate values or statistics belonging to a group, making access to an actual individual impossible.
Lower and Upper Limit Coding: This method is achieved by defining a category for a particular variable and combining the values falling within that category. Generally, lower or higher values of a particular variable are grouped together and assigned a new identifier.
Global Coding: Global coding is a grouping method used in datasets where lower and upper limit coding cannot be applied, where values are non-numerical or cannot be numerically ordered. It is generally used where grouping certain values would facilitate predictions and assumptions. A common new group is created for the selected values, and all relevant records in the dataset are replaced with this new definition.
Sampling: Under the sampling method, a subset selected from the dataset is described or shared instead of the entire dataset. Since it is unknown whether a person known to be part of the entire dataset is included in the disclosed or shared sample subset, the risk of making accurate predictions about individuals is reduced. Simple statistical methods are used when determining the sample subset.
Micro-Aggregation: Under this method, all records in the dataset are first arranged according to a meaningful order and then divided into subgroups of a specified size. The average value of the relevant variable in each subgroup is then calculated, and the value of that variable for the subgroup is replaced with the average value. Thus, the overall average value of that variable across the dataset remains unchanged.
Data Swapping: Data swapping involves changing the values of a subset of variables between selected pairs of records. This method is primarily used for categorical variables and is based on transforming the database by exchanging variable values between individual records.
Noise Addition: Under this method, additions and subtractions are made to a selected variable to introduce a predetermined degree of distortion. This method is generally applied to datasets containing quantitative values. The distortion is applied equally to each value.
Statistical Methods Strengthening Anonymization: In anonymized datasets, certain values may combine in unique scenarios, creating a possibility of identifying individuals in the records or deriving assumptions regarding their personal data. Therefore, anonymization can be strengthened by using various statistical methods to minimize the uniqueness of records within the dataset. The primary purpose of these methods is to minimize the risk of compromising anonymity while maintaining the benefit obtained from the dataset at an appropriate level.
i) K-Anonymity: The possibility of identifying individuals in anonymized datasets or easily predicting information about a specific individual where indirect identifiers are combined in appropriate combinations has undermined confidence in anonymization processes. Accordingly, statistical methods have been developed to make anonymized datasets more reliable.
K-anonymity is designed to prevent the disclosure of information specific to individuals displaying unique characteristics in certain combinations by ensuring that multiple individuals can be identified through certain fields in a dataset. When multiple records correspond to a combination created by bringing together certain variables in a dataset, the likelihood of identifying the individuals corresponding to that combination is reduced.
ii) L-Diversity: Developed based on the shortcomings of k-anonymity, the l-diversity method takes into account the diversity of sensitive variables corresponding to the same combinations of variables.
iii) T-Closeness: Although the l-diversity method provides diversity in personal data, it may not provide sufficient protection because it does not take into account the content or degree of sensitivity of the personal data. Accordingly, t-closeness refers to the process of calculating the degree of proximity between values within the personal data and anonymizing the dataset by dividing it into subgroups according to these degrees of proximity.
G. RESPONSIBLE UNIT
All units and employees of As Kare actively support the responsible unit in taking technical and administrative measures to ensure data security in all environments where personal data are processed, implementing the technical and administrative measures required under this Policy properly, providing training and increasing awareness among unit employees, monitoring and continuously auditing such measures, preventing unlawful processing of personal data, preventing unlawful access to personal data, and ensuring the lawful retention of personal data.
The responsible unit operating within As Kare and/or the group of companies, or, where necessary, operating under agreements entered into by As Kare with third-party service providers, is responsible for properly carrying out the activities and procedures set forth in this Policy and for the technical storage, protection and backup of data, as well as supervising such activities under its responsibility.
The titles of the persons responsible for the retention and destruction processes of personal data and the distribution of duties relating to these processes are as follows:
TitleDuty
Chairman of the Board of DirectorsResponsible for ensuring that employees act in accordance with the Policy.
Information Technologies DepartmentResponsible for providing the technical solutions required for the implementation of the Policy or obtaining such solutions through external service providers. Also responsible for publishing the Policy in the relevant environments.
Legal CounselResponsible for preparing, developing, implementing and updating the Policy.
Human Resources, Sales Department, Procurement Department and other unitsResponsible for implementing the Policy in accordance with their respective duties.
H. RETENTION AND DESTRUCTION PERIODS
With respect to personal data processed by our Company within the scope of its activities:
Retention periods for each category of personal data processed within activities carried out as part of processes are specified in the Personal Data Processing Inventory,
Retention periods by data category are specified in the VERBIS notification,
Retention periods by process are specified in the Personal Data Retention and Destruction Policy.
Where necessary, the relevant department of the Company updates these retention periods.
For personal data whose retention periods have expired, deletion, destruction or anonymization is carried out ex officio or upon the application of the data subject by the responsible unit.
The table showing the retention periods of personal data processed by our Company in accordance with the KVKK and other applicable legislation is provided in the Retention and Destruction Periods Table attached to this Policy.
I. PERIODIC DESTRUCTION
In addition to the previously determined retention and destruction periods, As Kare has determined the periodic destruction period as 6 months in accordance with the provisions of the KVKK and the Regulation.
Accordingly, periodic destruction operations are carried out throughout the data controller’s organization every June and December.
All operations relating to the deletion, destruction and anonymization of personal data are recorded, and such records are retained for at least 5 years, without prejudice to other legal obligations.
J. DEFINITIONS
The terms used in this Policy are defined as follows:
TermDefinition
As Kare KVK PolicyAs Kare Personal Data Protection Policy.
As Kare Data Subject Application FormThe application form prepared by our Company for data subjects to exercise their rights set forth in Article 11 of the KVKK.
As Kare / Torq Nutrition / CompanyAS Kare Sağlık Ürünleri Pazarlama Danışmanlık Yazılım Hizmetleri San. ve Dış Tic. A.Ş.
As Kare Business PartnersParties with which As Kare establishes business partnerships for various purposes while conducting its commercial activities.
As Kare SuppliersParties providing goods and services to As Kare on a contractual basis.
Explicit ConsentConsent relating to a specific subject, based on being informed and expressed freely.
Recipient GroupCategory of natural or legal persons to whom personal data are transferred by the data controller.
AnonymizationRendering personal data incapable of being associated in any manner with an identified or identifiable natural person, even when combined with other data.
Non-Electronic/Physical EnvironmentAll written, printed and other media outside electronic environments.
Electronic EnvironmentEnvironments in which personal data can be created, read, modified and written using electronic devices.
Responsible UnitThe person or unit within As Kare and/or the group of companies, or providing services under an agreement with third-party service providers of As Kare, responsible for the technical storage, protection and backup of data and for fulfilling the duties specified under this Policy.
Service ProviderA natural or legal person providing services to our Company under a specific agreement.
Relevant UserPersons who process personal data within the organization of the data controller or under the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.
DestructionDeletion, destruction or anonymization of personal data.
Contact PersonThe unit designated by As Kare to provide the necessary coordination within the Company for ensuring, maintaining and sustaining compliance with personal data protection legislation.
Recording MediumAny environment in which personal data processed by fully or partially automated means or by non-automated means as part of a data recording system are stored.
Personal DataAny information relating to an identified or identifiable natural person.
Personal Data Processing InventoryThe inventory created by data controllers by associating their personal data processing activities carried out in connection with business processes with the purposes of processing personal data, data categories, recipient groups and categories of data subjects, and detailing the maximum retention period necessary for the purposes for which personal data are processed, personal data intended to be transferred abroad and measures taken regarding data security.
Data SubjectThe natural person whose personal data are processed.
Processing of Personal DataAny operation performed on personal data, including obtaining, recording, storing, retaining, modifying, reorganizing, disclosing, transferring, acquiring, making available, classifying or preventing the use of personal data by fully or partially automated means or by non-automated means provided that such processing forms part of a data recording system.
Personal Data Protection AuthorityThe Personal Data Protection Authority of Türkiye.
KVKKLaw No. 6698 on the Protection of Personal Data, dated 24 March 2016 and published in the Official Gazette No. 29677 dated 7 April 2016.
Special Categories of Personal DataData relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, association, foundation or trade union membership, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data.
Periodic DestructionThe deletion, destruction or anonymization of personal data to be carried out ex officio at recurring intervals specified in the personal data retention and destruction policy where all conditions for processing personal data under the KVKK have ceased to exist.
Policy / As Kare Personal Data Retention and Destruction PolicyThis “As Kare Personal Data Retention and Destruction Policy,” which sets forth the principles governing personal data retained by As Kare.
Retention and Destruction Periods TableThe table attached to this Policy showing the retention periods of personal data processed in accordance with the KVKK and other applicable legislation.
DeletionThe process of making personal data completely inaccessible and unusable by the relevant users.
Data ProcessorA natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller.
Data Controllers Registry Information System (VERBIS)The information system created and managed by the Presidency of the Personal Data Protection Authority and accessible online, which data controllers use for registration with the Registry and other relevant Registry-related procedures.
Data ControllerThe person who determines the purposes and means of processing personal data and manages the place where the data are systematically stored. Under this Policy, this refers to As Kare.
DestructionThe process of rendering personal data completely inaccessible, irretrievable and unusable by anyone in any manner whatsoever.
RegulationThe Regulation on Deletion, Destruction or Anonymization of Personal Data, published in the Official Gazette on 28 October 2017 and entering into force as of 1 January 2018.
K. UPDATES
This Policy is reviewed as necessary and the relevant sections are updated where required. The date of the latest update to this Policy is stated on its first page.
L. EFFECTIVENESS
This Policy shall be deemed to have entered into force upon its publication on As Kare’s website.
If it is decided to repeal the Policy, previous copies of the Policy shall be cancelled by a decision of the Board of Directors, signed with a cancellation stamp or marked “Cancelled,” and retained by the responsible unit for at least 5 years.
ANNEX – AS KARE RETENTION AND DESTRUCTION PERIODS TABLE
The table below specifies the retention periods, by process, for personal data lawfully processed by As Kare.
The destruction period for personal data is linked to the 6-month periodic destruction periods. Accordingly, the personal data listed below are destroyed during the first periodic destruction period following the expiration of their respective retention periods.
ProcessRetention Period
Recruitment process – Job applicantCVs of positively evaluated applicants are retained for 10 years; CVs of negatively evaluated applicants are destroyed immediately.
Recruitment – Employees and employees’ family membersRetained for 10 years.
Provision of additional benefits to employeesRetained for 10 years.
Provision of additional benefits to employees – Company telephone lineRetained for 10 years.
Provision of additional benefits to employees – Meal cardsRetained for 10 years.
Procurement of goods or servicesRetained for 10 years.
Sale of goods or servicesRetained for 10 years.
Salary paymentsRetained for 10 years.
Sending documents, invitations, POS materials and goods to customersRetained for 10 years.
Marketing and promotional activitiesRetained for 10 years.
Ensuring shipmentRetained for 10 years.
Information regarding payments madeRetained for 10 years.
Sending documents to suppliersRetained for 10 years.
Physical retention of incoming and outgoing company documents, invoices, etc.Retained for 10 years.
Product and invoice deliveryRetained for 10 years.
Ensuring securityRetained for 5 years.

Türkçe


























-140x140.png)
-140x140.jpg)












-140x140.jpg)










































































