KVKK Policy

PERSONAL DATA PROTECTION AND PROCESSING POLICY

INTRODUCTION

The protection of personal data is among the core priorities of ONVO Anonim Şirketi ("Company"). This Company Personal Data Protection and Processing Policy ("Policy") outlines the principles adopted in conducting personal data processing activities executed by our Company, as well as fundamental compliance principles set forth under Law No. 6698 on the Protection of Personal Data ("KVKK" or "Law"), thereby ensuring necessary transparency by informing data subjects.

With full awareness of our responsibility within this scope, your personal data is processed and protected under the framework of this Policy.

SCOPE AND FIELD OF APPLICATION

Excluding Company employees, this Policy applies to all personal data belonging to the following data subject categories, processed automatically or non-automatically provided that it is part of any data filing system:

  • Real Customers

  • Corporate Customer Shareholders, Officials, and Employees

  • Prospective Customers

  • Company Officials

  • Shareholders

  • Former Employees / Retirees

  • Business Partner Shareholders, Officials, and Employees

  • Supplier Shareholders, Officials, and Employees

  • Employee Candidates and Intern Applicants

  • Prospective Business Partners

  • Prospective Suppliers

  • Family Members

  • Visitors

  • Legally Authorized Persons

  • Other Third Parties

APPLICATION OF THE POLICY AND RELEVANT LEGISLATION

Applicable legal regulations governing the processing and protection of personal data shall take primary precedence. In the event of a conflict between active legislation and this Policy, ONVO ELEKTRONİK A.Ş. accepts that active statutory legislation shall prevail. This Policy concrete-formulates statutory rules within the scope of Company operational practices.

CORE MATTERS REGARDING THE PROTECTION OF PERSONAL DATA

SECURING PERSONAL DATA

In accordance with Article 12 of the Law, ONVO ELEKTRONİK A.Ş. implements necessary precautions commensurate with the nature of data to prevent unlawful disclosure, access, transfer, or security breaches of personal data.

Within this framework, ONVO ELEKTRONİK A.Ş. executes or commissions technical and administrative audits and measures to ensure required security levels in compliance with guidelines published by the Personal Data Protection Board ("Board").

PROTECTION OF SPECIAL CATEGORIES OF PERSONAL DATA

Data of a sensitive nature is granted special statutory protection due to risks of causing discrimination or victimizing individuals if unlawfully processed. These "special categories of" personal data comprise:

  • Race, ethnic origin

  • Political opinions

  • Philosophical beliefs, religion, sect, or other beliefs

  • Clothing and attire

  • Association, foundation, or trade-union memberships

  • Health records

  • Sexual life

  • Criminal convictions and security measures

  • Biometric and genetic data

ONVO ELEKTRONİK A.Ş. diligently applies technical and administrative measures for protecting personal data to special categories of data and conducts necessary internal compliance audits.

AWARENESS AND AUDIT ACTIVITIES ACROSS BUSINESS UNITS

ONVO ELEKTRONİK A.Ş. organizes necessary training programs across business units to raise organizational awareness regarding the prevention of unlawful processing, unauthorized access, and maintaining safe data retention.

Necessary frameworks are established for current and newly onboarding employees to foster personal data protection awareness, collaborating with specialized external advisors when necessary.

PRINCIPLES AND CONDITIONS FOR PROCESSING PERSONAL DATA

PROCESSING IN ACCORDANCE WITH FUNDAMENTAL PRINCIPLES

  • Processing in Lawfulness and Good Faith: Data is processed in good faith without harming fundamental rights and freedoms, strictly limited to what Company business operations necessitate.

  • Ensuring Accuracy and Up-to-Date Status: ONVO ELEKTRONİK A.Ş. establishes mechanisms to maintain data accuracy and currency throughout processing periods.

  • Processing for Specified, Explicit, and Legitimate Purposes: Purposes are explicitly stated and aligned with legitimate business activities.

  • Relevant, Limited, and Proportionate Processing: Data is collected and processed strictly to the extent required for stated operational goals.

  • Retention for Period Stipulated by Legislation or Necessary for Purpose: Data is retained for the duration mandated by legislation or necessary for processing goals, followed by periodic destruction methods (deletion, destruction, or anonymization).

CONDITIONS FOR PROCESSING PERSONAL DATA

Data processing relies on one or more of the following statutory conditions, unless explicit consent is obtained:

  1. Explicit Consent of Data Subject: Given voluntarily, based on informed consent regarding a specific matter.

  2. Explicitly Stipulated by Laws: Statutory provisions directly permitting data processing.

  3. Physical Impossibility: Processing essential to protect life or bodily integrity when the data subject cannot express consent due to physical impossibility.

  4. Execution or Performance of Contract: Direct necessity for establishing or performing a contract to which the data subject is a party.

  5. Fulfillment of Legal Obligations: Mandatory processing for ONVO ELEKTRONİK A.Ş. to fulfill statutory duties.

  6. Data Made Public by Data Subject: Processing strictly limited to the intent of public disclosure made by the owner.

  7. Establishment or Defense of Rights: Mandatory processing for establishing, exercising, or defending legal claims.

  8. Legitimate Interests of Company: Processing necessary for legitimate interests of ONVO ELEKTRONİK A.Ş., provided it does not harm fundamental rights and freedoms.

PROCESSING SPECIAL CATEGORIES OF PERSONAL DATA

Processed under strict administrative/technical measures dictated by the Board under the following conditions:

  • Data Other Than Health and Sexual Life: Processed without consent if explicitly stipulated by laws; otherwise requires explicit consent.

  • Health and Sexual Life Data: Processed without consent strictly by persons bound by confidentiality obligations or authorized institutions for public health protection, preventive medicine, medical diagnosis, treatment, and healthcare services management; otherwise requires explicit consent.

CATEGORIES OF PROCESSED PERSONAL DATA

  • Identity Data: Full name, T.R. ID number, nationality, parents' names, birthplace/date, gender, driver's license, national ID, passport data, tax number.

  • Contact Data: Residence, phone number, address, e-mail, address registration records.

  • Customer Transaction Data: Inquiries, orders, and usage logs of end-users benefiting from Company group products and services.

  • Physical Space Security Data: Entry/exit camera recordings, fingerprint records, and security checkpoint logs.

  • Financial Data: Financial documents, records, and outputs created within the commercial relationship.

  • Transaction Security Data: IP addresses, website logs, credentials, and passwords ensuring IT security.

  • Legal Action and Compliance Data: Records processed for legal claims, debt enforcement, statutory compliance, and Company policies.

  • Audio/Visual Data: Photographs, camera footage, voice recordings, and document copies containing personal data.

  • Candidate Data: Personal records of applicants evaluated for HR recruitment needs.

  • Marketing Data: Usage habits, preferences, and trend analyses of end-consumer products.

  • Contractual Data: Details of corporate suppliers, business partners, commercial contracts, and personnel information.

  • Special Categories of Data: Data concerning race, ethnicity, political views, beliefs, attire, memberships, health, sexual orientation, convictions, biometric/genetic data.

PURPOSES OF PROCESSING PERSONAL DATA

  • A) Human Resources Planning and Execution: Managing job applications, intern selections, and recruitment workflows.

  • B) Legal and Technical Security: Creating employee files, ensuring regulatory compliance, corporate governance, visitor logs, legal tracking, official reporting, archival, information security, asset management, and network security.

  • C) Customization and Promotion of Products/Services: Tailoring marketing campaigns, consumer behavior profiling, data analytics, customer acquisition, and survey planning.

  • D) Service Execution Workflows: Managing order sales, customer relationships, post-sales support, satisfaction activities, and complaint tracking.

  • E) Commercial Operations Management: Finance/accounting, operational efficiency analyses, corporate governance, continuity planning, procurement, internal reporting, and supply chain management.

  • F) Strategic Planning: Strategic business planning, budgeting, financial risk management, and supplier risk evaluations.

DATA TRANSFERS AND RECIPIENT PARTIES

TRANSFER CONDITIONS AND OVERSEAS TRANSFERS

Data may be transferred domestically or internationally in compliance with Articles 8 and 9 of KVKK under statutory exceptions or explicit consent. Overseas transfers occur to countries declared to have Adequate Protection or where data controllers commit to adequate protection in writing with Board authorization.

RECIPIENT CATEGORIES AND TRANSFER PURPOSES

  • Business Partners: Financial institutions, legal consultancies, e-invoice software partners processing data for accounting and legal operations.

  • Suppliers: IT hosting, software maintenance, and cybersecurity service vendors providing operational infrastructure.

  • Group Companies: Shared service partners organizing visits, complaint resolutions, and operational coordination.

  • Audit and Inspection Firms: Authorized firms auditing regulatory compliance and Company procedures.

  • Authorized Public Institutions: Lawfully empowered bodies (Courts, Notaries, Law Enforcement Agencies) upon formal request.

  • Authorized Private Legal Entities: Mediators, independent audit firms operating within statutory boundaries.

RETENTION AND DESTRUCTION METHODS

Personal data is stored for the duration stipulated by applicable legislation or required for processing purposes. Upon expiration of retention limits, data is destroyed during periodic disposal cycles or upon data subject request via:

  1. Deletion: Removing access to personal data.

  2. Destruction: Physical or electronic permanent destruction.

  3. Anonymization: Rendering data irreversibly disassociated from identifiable real persons.

STATUTORY RIGHTS OF DATA SUBJECTS AND APPLICATION PROCEDURES

STATUTORY RIGHTS UNDER ARTICLE 11 OF KVKK

Data subjects hold the right to: obtain information on processing; request details; learn processing purposes; know domestic/foreign third-party recipients; request rectification of inaccurate data; demand deletion/destruction under statutory conditions; request notification of corrections/deletions to third parties; object to results against them arising from automated systems; and demand compensation for unlawful processing damages.

APPLICATION PROCEDURE AND RESPONSE TIMES

Requests regarding statutory rights can be submitted via:

  • Written Application: Signed petition sent to Mimaroba Mah. Emirşah Sok. NO: 8/1 Büyükçekmece, Istanbul / Türkiye.

  • Electronic Application: E-mail sent to kvkk@onvo.com.tr via registered e-mail (KEP), secure digital signature, mobile signature, or previously registered e-mail address.

Applications are reviewed and finalized free of charge within 30 (thirty) days at the latest.

FINAL PROVISIONS

  • Policy Updates: This Policy may be revised due to legislative amendments, operational changes, or technological advancements. Modifications take effect upon publication on the official website.

  • Effective Date: September 2026.

CONTACT INFORMATION

  • Company: ONVO ELEKTRONİK A.Ş.

  • Address: Mimaroba Mah. Emirşah Sok. NO: 8/1 Büyükçekmece, Istanbul / Türkiye

  • E-mail:kvkk@onvo.com.tr

  • Phone: +90 850 886 66 86

T-Soft 360 Logo Powered by T-SOFT E-Commerce