KVKK and Security Policy

  INTRODUCTION

1.1.    Purpose of Policy

As Shopiverse Teknoloji ve Yazılım Anonim Şirketi (hereinafter referred to as “Shopiverse” or “Company”), we process sensitive personal data and ensure the security of this data in accordance with the Personal Data Protection Law No. 6698 and the relevant legislation.

The Decision of the Personal Data Protection Board dated 31/01/2018 and numbered 2018/10 regarding this Policy on Processing and Security of Special Quality Personal Data (“Policy”), “Adequate Precautions to be Taken by Data Controllers in Processing of Special Quality Personal Data” (“Policy”) Board Decision”), as the data controller, to determine the measures we take for the processing of sensitive personal data.

This Policy and Shopiverse’s Personal Data Security Policy (“Security Policy”) are complementary to each other, and the Security Policy should be reviewed for matters not mentioned in this Policy.

Shopiverse, as the data controller, will act in accordance with this Policy when processing sensitive personal data in its possession, sharing it with third parties and storing it in data recording environments.

1.2.    Scope of Policy

This Policy covers our activities to ensure the appropriate level of security for the personal data of special nature that we have or may obtain from the following persons:

  • Our company’s employees, employee candidates, former employees and interns,
  • Representatives, proxies and shareholders of our company and group companies,
  • Employees, representatives and attorneys of our business partners,
  • Healthcare professionals with whom we cooperate,
  • Employees, representatives and attorneys of our suppliers,
  • Our customers and potential customers,
  • Employees of public / private institutions and organizations,
  • Members and managers of the associations we cooperate with,
  • Other natural persons.

1.3.    Policy Changes and Updates

Shopiverse, within the framework of this Policy art. It will take the necessary administrative and technical measures in order to process the sensitive personal data of the persons mentioned in Article 2 in accordance with the personal data protection legislation and to ensure the security of this data. In line with the changes in the law or related legislation or the activities of Shopiverse, this Policy may be changed and updated at any time by the relevant units.

 

 

 

  1. PROCESSING OF SPECIAL QUALITY PERSONAL DATA

2.1.    General Principles Regarding the Processing of Private Personal Data

Shopiverse is obliged to comply with the general principles set forth in the KVK Law regarding the processing of personal data. In this context, Shopiverse will act in accordance with the following principles when processing sensitive personal data:

  • Processing personal data in accordance with the law and honesty,
  • Ensuring that personal data is accurate and up-to-date when necessary,
  • Processing personal data for specific, explicit and legitimate purposes,
  • Processing personal data in connection with the purpose for which they are processed, limited and measured,
  • Storage for the period required by the relevant legislation or for the purpose for which they are processed.

2.2.    Conditions for Processing Special Quality Personal Data

Shopiverse is obliged to process sensitive personal data in accordance with the above-mentioned general principles and the conditions set forth in Article 6 of the KVK Law. In this context, Shopiverse will be able to process sensitive personal data based on one of the following conditions:

  • Obtaining the express consent of the person concerned for the processing of sensitive personal data, or
  • Except for personal data related to health and sexual life, the processing of sensitive personal data is stipulated in the law.

2.3.    Transfer of Private Personal Data

Shopiverse may share sensitive personal data with third parties in accordance with the data processing conditions specified in Articles 8 and 9 of the KVK Law. During the transfer of sensitive personal data to third parties, Shopiverse will take the security measures specified in the Board Decision. In this context, Shopiverse collects special quality personal data;

  • In cases where it is transferred by e-mail, it uses an encrypted corporate e-mail address or Registered Electronic Mail (KEP) account,
  • In cases where it transfers between servers in different physical environments, it transfers data by establishing VPN between servers or by sFTP method,
  • In cases where it is transferred on paper, it takes the necessary precautions against the risks such as theft, loss or access by the authorized person and sends the document in the form of “confidential documents”.

2.4.    Retention of Private Personal Data

Shopiverse preserves sensitive personal data in accordance with the general principles and processing conditions detailed above. Regarding the environments where sensitive personal data is stored and/or accessed, Shopiverse will take the security measures specified in the Board Decision. In this context, Shopiverse,

  • preserves sensitive personal data using cryptographic methods and keeps cryptographic keys in secure and different environments,
  • All transactions made on sensitive personal data are securely logged,
  • constantly monitors the security updates of the environments where special quality personal data is located, regularly performs the necessary security tests and records the test results,
  • In cases where sensitive personal data is accessed through a software, user authorizations for this software are made,
  • If remote access to sensitive personal data is required, at least two-stage authentication system is provided.
  • environments where sensitive personal data is processed, stored and/or accessed, and physical environment, electricity leakage, fire, flood, theft, etc. taking precautions against situations. By ensuring the physical security of these environments, unauthorized entries and exits are prevented.

  1. PROCESSING OF SPECIAL QUALIFIED PERSONAL DATA OF EMPLOYEES

Shopiverse takes the following measures specified in the Board Decision for its employees who process sensitive personal data:

  • Necessary training and awareness activities are carried out for the personnel to ensure the security of personal data, not to disclose or share it unlawfully.
  • A confidentiality agreement is signed with the employees.
  • Personnel are authorized to access servers containing personal data, depending on their department and job role. The scope and duration of these authorizations are clearly defined.
  • Periodic authorization checks are carried out.
  • In the event that the employees change their duties or leave the job, their access to data is removed and the inventory given to them is taken back.
  1. PERSONAL DATA SECURITY POLICY

Shopiverse has created the Personal Data Security Policy in accordance with the technical and administrative measures specified in the Personal Data Security Guide published on the Institution’s website in order to ensure the security of all personal data it processes, including sensitive personal data. This Special Quality Personal Data Security Policy includes the technical and administrative measures taken by the Company to ensure the compliance of the processed personal data with the law, to prevent unlawful access and to ensure the appropriate level of security in order to ensure its preservation.