Türkiye Gençlik ve Eğitime Hizmet Vakfı ("TÜRGEV" or "Foundation") fulfills its obligations arising from the Law No. 6698 on the Protection of Personal Data ("Law") regarding the processing, deletion, destruction, anonymization, transfer of personal data, informing the data subject, and ensuring data security within the framework of the principles set forth by the Law.
This Privacy and Personal Data Protection Policy, which is organized in accordance with the Law, is made available to individuals whose personal data is processed ("data subject").
1. Scope and Purpose of the Privacy and Personal Data Protection Policy
This Privacy and Personal Data Protection Policy outlines the following regarding TÜRGEV:
- The methods and legal reasons for collecting personal data,
- Which groups of individuals' personal data are processed (Data Subject Categorization),
- Which category of personal data of data subjects is processed (Data Categories) and example data types,
- For what purposes the relevant personal data is used,
- Technical and administrative measures taken to ensure the security of personal data,
- To whom and for what purposes personal data can be transferred,
- The retention periods of personal data,
- What rights data subjects have over their personal data and how they can exercise these rights
are detailed.
a. Methods and Legal Reasons for Collecting Personal Data
TÜRGEV collects personal data through printed forms, electronic forms, Websites, social media accounts, email, mail, CCTV, cookies, fax, notifications from administrative and judicial authorities, and other communication channels in auditory, electronic, or written form, in accordance with the personal data processing conditions specified in the Law and in line with the legal reasons stated in this Privacy and Personal Data Protection Policy.
b. Data Subject Categorization
TÜRGEV categorizes the data subjects whose personal data it processes as follows, and these groups may expand in light of the processes and legal reasons specified in this policy.
- Scholarship Recipient
- Scholarship Candidate
- Dormitory Student
- Dormitory Student Candidate
- Employee
- Employee Candidate
- Donor
- Visitor
- Online Visitor
- Educator/Business Solution Partner/Supplier
c. Data Categories and Example Data Types
1. Scholarship Recipient and Candidate
- Identity Information: Name-Surname, Gender, Turkish ID Number, Turkish ID Information (Wallet serial number, family order number, etc.), Date of Birth, Place of Birth, Marital Status, Passport Information (for Foreign Nationals), Signature
- Contact Information: Address (home/work), Email, Phone / Mobile Phone
- Financial Information: Bank Account Information, Payment Information (Only obtained from Scholarship Recipients.)
- Visual and Auditory Information: Photograph
- Special Category Personal Data: Criminal Record, Health Report
- Family Members and Relatives Information: Name-Surname, Residence, Degree of Kinship, Occupation, School, Date of Birth, Mobile Phone, Social Security documents, Financial Status Information
- Other: Student certificate, school records, CCTV, other information specified in the Student Application and Registration Guide
2. Dormitory Student and Candidate
- Identity Information: Name-Surname, Gender, Turkish ID Number, Turkish ID Information (Wallet serial number, family order number, etc.), Date of Birth, Place of Birth, Marital Status, Passport Information (for Foreign Nationals), Signature
- Contact Information: Address (home/work), Email, Phone / Mobile Phone
- Visual and Auditory Information: Photograph
- Special Category Personal Data: Criminal Record, Health Report
- Family Members and Relatives Information: Name-Surname, Residence, Degree of Kinship, Occupation, School, Date of Birth, Mobile Phone, Social Security documents, Financial Status Information
- Other: Student certificate, school records, CCTV, other information specified in the Student Application and Registration Guide
3. Donor
- Identity Information: Name-Surname, Gender, Turkish ID Number, Signature
- Contact Information: Address information
- Financial Information: Donation Amount, receipt information, credit card information
4. Visitor
- Identity Information: Name-Surname, Turkish ID Number, Passport Number (for Foreign Nationals)
- Contact Information: Email, Phone / Mobile Phone
- Legal Transaction and Compliance Information: IP address and Log Records
- Other: Vehicle License Plate, CCTV
5. Online Visitor
- Transaction Security Information: Password, Member Number, Mobile Phone
- Legal Transaction and Compliance Information: IP Address and Log Records
6. Business Solution Partner / Supplier
- Identity Information: Name-Surname, Gender, Turkish ID Number, Turkish ID Information (Wallet serial number, family order number, etc.), Date of Birth, Place of Birth, Marital Status, Professional IDs
- Contact Information: Address, Email, Phone / Mobile Phone
- Financial Information: Bank Account Information, Financial Transaction Information, IBAN Number, Payment Information, Copies/Photocopies of Guarantee Letters
- CV and Professional Information: Educational Status, Military Status, Sector Information, Affiliated Organization, Start/End Date of Employment, Title, Insurance Information
- Legal Transaction and Compliance Information: Signature Circular, Activity Information, Power of Attorney
- Special Category Personal Data: Criminal Record, Signature, Health Information
- Other: Vehicle License Plate, CCTV, Photograph
d. Purposes for Which Personal Data is Used
Personal data is used by TÜRGEV for the following purposes;
- To carry out the necessary work by the relevant business units for the realization of activities conducted by the Foundation and to manage related business processes
- To plan and/or execute the activities of conducting effectiveness/productivity and/or appropriateness analyses of Foundation Activities
- To plan and/or execute the activities of ensuring business continuity
- To plan, audit, and execute information security processes
- To monitor the financial and accounting affairs of the Foundation
- To plan and execute the operational processes of the Foundation
- To plan and execute training activities inside and outside the Foundation
- To manage relationships with business partners and/or suppliers
- To track requests and/or complaints
- To monitor the legal affairs of the Foundation and fulfill legal responsibilities
- To plan and execute necessary operational activities to ensure that the Foundation's activities are conducted in accordance with Foundation procedures and/or relevant legislation
- To provide information to authorized institutions as required by legislation
- To plan and execute the audit activities of the Foundation
- To ensure the security of Foundation campuses and/or facilities
- To ensure the security of Foundation operations
- To ensure the security of Foundation campuses and assets
- To ensure the security of Foundation fixed assets and/or resources
- To create visitor records
e. Technical and Administrative Measures Taken to Ensure the Security of Personal Data
TÜRGEV undertakes to take all necessary technical and administrative measures to ensure the confidentiality, integrity, and security of your personal data and to show the necessary care. In this context, it takes necessary precautions to prevent the misuse of personal data, unlawful processing, unauthorized access to data, disclosure, alteration, or destruction of data.
TÜRGEV takes the following technical and administrative measures to prevent unlawful access to the personal data it processes, to prevent unlawful processing of this data, and to ensure the preservation of personal data:
- Anti-Virus
- Firewall
- Access authorization
- Access password management, etc.
An anti-virus application that is periodically updated is installed on all PCs and Servers in TÜRGEV's information technology infrastructure.
Firewall
The Data Center and Disaster Recovery Centers hosting TÜRGEV's servers are protected by firewalls with periodically updated software, and the relevant next-generation firewalls control all personnel's internet connections and provide protection against viruses and similar threats during this control.
User Identifications and Need to Know
The authorizations of TÜRGEV and its employees to the Foundation systems are limited only to the extent necessary by their job descriptions, and in case of any change in authority and duties, the system authorizations are promptly updated.
Information Security Threat and Incident Management
Incidents occurring on TÜRGEV's servers and firewalls are transferred to the "Information Security Threat and Incident Management" system. This system alerts responsible personnel when a security threat occurs and provides the opportunity for a prompt response to the threat.
Penetration Testing
Periodic testing of the servers and computers in TÜRGEV's system is conducted manually by a supplier company. Security vulnerabilities identified as a result of this test are closed, and a verification test is conducted to confirm that the relevant security vulnerabilities have been closed. Additionally, penetration testing is also conducted automatically by the Information Security Threat and Incident Management system.
Training Portal
The Training Portal is actively used to raise awareness among TÜRGEV employees against various information security violations and to minimize the impact of the human factor in information breach incidents. All employees have received online training on Cyber Security and Information Security.
Other
- All fields on the website where personal data is collected are protected by SSL.
- Personal data on paper must be stored in locked cabinets and accessed only by authorized persons.
- Personal data processed through cookies belonging to third parties from whom services are received are deleted from third-party systems if the membership ends.
Other Measures:
- Mail Gateway
- Server room encryption systems
- Physical security
- Private Security
- Camera monitoring systems
- Penetration tests
- Two-level authorization control
- SHA 256 bit encryption
- GEO IP Restrictions
- Email encryption methods
Despite taking necessary information security measures, in the event of damage to personal data or unauthorized access by attacks on platforms operated by TÜRGEV or the TÜRGEV system, TÜRGEV will immediately notify you and the Personal Data Protection Board of this situation and take necessary precautions.
f. To Whom and for What Purpose Personal Data Can Be Transferred
TÜRGEV transfers personal data to third parties only in accordance with the purposes specified in this Privacy and Personal Data Protection Policy and in compliance with Articles 8 and 9 of the Law.
Personal data transfers carried out in this context occur through secure environments and channels provided by the relevant third party. Depending on the content and scope of the service received from third parties; in all cases where the data subject's personal data does not need to be transferred, pseudonymous data is used for the transfer.
The personal data subject to the transfer mentioned above is legally protected by the provisions of our contracts that comply with the Law, considering that the counterparty of the legal relationship is the data controller or data processor, in addition to the technical measures that will ensure their security.
h. Retention Periods of Personal Data
TÜRGEV retains the personal data it processes in accordance with the Law for the periods stipulated in the relevant legislation or required by the purpose of processing. The retention periods in the Personal Data Retention and Destruction Policy are approximately as follows:
j. Rights of the Relevant Person Over Their Personal Data and How They Can Exercise These Rights
The rights of the relevant person under Article 11 of the Law are as follows:
- (1) To learn whether personal data is processed,
- (2) To request information regarding personal data if it has been processed,
- (3) To learn the purpose of processing personal data and whether they are used in accordance with their purpose,
- (4) To know the third parties to whom personal data is transferred, whether domestically or internationally,
- (5) To request the correction of personal data if it is processed incompletely or inaccurately,
- (6) To request the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the KVK Law,
- (7) To request notification of the transactions carried out under (d) and (e) to third parties to whom personal data has been transferred,
- (8) To object to the emergence of a result against the person by analyzing the processed data exclusively through automated systems,
- (9) To request compensation for damages in case of damage due to unlawful processing of personal data.
To exercise your rights over your personal data; you can perform necessary changes, updates, and/or deletions through the "KVKK Application Form" accessible from the TÜRGEV Website, and the official email address TÜRGEV and the official phone line 0 212 532 1996.
2. Conditions for Deletion, Destruction, and Anonymization of Personal Data
TÜRGEV retains the personal data it processes, collected through physical, electronic, Website, Email, and other channels, for the periods stipulated by the relevant laws and/or required by the purpose of processing in accordance with Article 7, 17 of the Law and Article 138 of the Turkish Penal Code. Upon the expiration of these periods, it will delete, destroy, or anonymize the data in accordance with the provisions of the Regulation on Deletion, Destruction, or Anonymization of Personal Data and the Guide on Deletion, Destruction, or Anonymization of Personal Data.
The deletion of personal data by TÜRGEV refers to the process of making personal data inaccessible and unusable in any way for the relevant users.
The destruction of personal data by TÜRGEV refers to the process of making personal data inaccessible, irretrievable, and unusable in any way by anyone.
The anonymization of personal data by TÜRGEV refers to the process of making personal data unidentifiable or untraceable to any identifiable or identifiable real person, even if matched with other data.
TÜRGEV provides detailed explanations of the methods and technical and administrative measures it takes regarding deletion, destruction, and anonymization in accordance with the Regulation on Deletion, Destruction, or Anonymization of Personal Data. In this Policy, the periodic destruction interval stipulated by the Regulation is determined as 6 months.
3. Changes to the Privacy and Personal Data Protection Policy
TÜRGEV may change this Privacy and Personal Data Protection Policy at any time. These changes become effective immediately upon the publication of the revised new Privacy and Personal Data Protection Policy. Necessary information will be provided to you to keep you informed of changes in this Privacy and Personal Data Protection Policy.
Formu doldurduktan sonra [email protected] adresine e-posta ile göndermeniz gerekmektedir.