
TABLE OF CONTENTS
- 1. INTRODUCTION
- 2. PURPOSE
- 3. SCOPE
- 4. DEFINITIONS
- 5. GENERAL PRINCIPLES REGARDING THE PROCESSING OF PERSONAL DATA
- 6. PROCESSING OF PERSONAL DATA
- 7. ENSURING THE SECURITY AND CONFIDENTIALITY OF PERSONAL DATA
- 8. PURPOSES OF PROCESSING PERSONAL DATA AND RETENTION PERIODS
- 9. DELETION, DESTRUCTION, AND ANONYMISATION OF PERSONAL DATA
- 10. THIRD PARTIES TO WHOM PERSONAL DATA IS TRANSFERRED AND THE PURPOSES OF TRANSFER
- 11. INFORMATION OBLIGATION AND DATA SUBJECT RIGHTS
- 12. DATA PROCESSING ACTIVITIES IN SPECIFIC AREAS
1. INTRODUCTION
Under the Constitution of the Republic of Turkey, everyone has the right to request the protection of personal data concerning themselves. This right also encompasses the right to be informed about personal data relating to oneself, to access such data, to request its correction or deletion, and to learn whether it is being used for its intended purpose.
In connection with the exercise of this constitutional right, Law No. 6698 on the Protection of Personal Data ("KVKK") has been enacted to regulate the protection of fundamental rights and freedoms of individuals in the processing of personal data, as well as the obligations of natural and legal persons who process personal data and the procedures they must follow. ENTEGRE PROJE YÖNETİM DANIŞMANLIK MÜHENDİSLİK TİCARET A.Ş. ("Integrated Project Management") exercises the necessary diligence regarding compliance with the KVKK and formalises this commitment through this Personal Data Protection and Processing Policy ("Policy") as a corporate policy.
The subject of the Policy covers the protection by Integrated Project Management of the personal data of Job Applicants, Shareholders of Integrated Project Management, Visitors, Employees of Institutions with which We Cooperate, Customers, and Third Parties (Guarantors, Victims/Beneficiaries). Activities carried out in relation to the protection of the personal data of our employees are managed within the framework of the Integrated Project Management Employee Personal Data Processing Policy, which is prepared in parallel with the principles set out in this Policy.
2. PURPOSE
The purpose of this Policy is to provide explanations regarding the personal data processing activities carried out by Integrated Project Management in compliance with the KVKK, and the principles adopted for the protection of personal data, and to ensure transparency by informing individuals whose personal data is processed by Integrated Project Management, including in particular Job Applicants, Shareholders of Integrated Project Management, Visitors, Employees of Cooperating Institutions, Customers, and Third Parties with rights.
3. SCOPE
Data subjects whose personal data is processed within the scope of this Policy are categorised as follows:
| Category | Description |
|---|---|
| Job Applicants | Natural persons who apply for employment at Integrated Project Management or make their CV and related information accessible to Integrated Project Management by any means |
| Employees of Cooperating Institutions | Employees of institutions that have a business relationship with Integrated Project Management |
| Customers | Natural persons whose personal data is obtained through business relationships arising from the activities carried out by Integrated Project Management, regardless of whether a contractual relationship exists |
| Visitors | Natural persons who have entered the physical premises of Integrated Project Management for various purposes or who visit its websites |
| Third Parties | Natural persons whose personal data is processed within the framework of this Policy, even though they are not defined elsewhere in this Policy |
A separate "Integrated Project Management Employee Personal Data Processing Policy" has been established in relation to the processing of the personal data of employees of Integrated Project Management, whether fully or partially by automated means or by non-automated means forming part of a data filing system.
4. DEFINITIONS
| Term | Definition |
|---|---|
| Explicit consent | Consent that is specific to a subject, based on being informed, and expressed by free will |
| Employee | All natural persons who work for Integrated Project Management in a dependent capacity, for a definite or indefinite term |
| Job Applicant | Natural persons who apply for employment at Integrated Project Management or make their CV and related information accessible to Integrated Project Management by any means |
| Employee Data Subject Application Form | The application form used by employees of Integrated Project Management when exercising their rights as data subjects under Article 11 of the KVKK |
| Relevant User | Persons within the data controller organisation or processing personal data under the authority and instructions received from the data controller, excluding persons or units responsible for the technical storage, protection, and backup of data |
| Personal data | Any information relating to an identified or identifiable natural person |
| Processing of personal data | Any operation performed on personal data such as collection, recording, storage, preservation, alteration, adaptation, disclosure, transfer, acquisition, making available, classification, or prevention of use, whether wholly or partly by automated means or by non-automated means forming part of a data filing system |
| KVKK | Law No. 6698 on the Protection of Personal Data |
| Personal Data Protection Board | The Personal Data Protection Board (KVK Kurulu) |
| Personal Data Protection Authority | The Personal Data Protection Authority (KVK Kurumu) |
| Special categories of personal data | Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, dress and appearance, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data |
| TCK | Turkish Penal Code No. 5237 |
| Data processor | A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller |
| Data subject | The natural person whose personal data is processed, referred to as the "relevant person" in the KVKK |
| Data Subject Application Form | The application form used by data subjects whose personal data is processed within Integrated Project Management when exercising their rights under KVKK Article 11 |
| Erasure of Personal Data | The process of making personal data inaccessible and unusable in any way by relevant users |
| Destruction of Personal Data | The process of making personal data inaccessible, irrecoverable, and unusable in any way by any person |
| Anonymisation of Personal Data | The process of rendering personal data impossible to associate with an identified or identifiable natural person, even when matched with other data |
| Data controller | The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system |
| Visitor | Natural persons who have entered the physical premises of Integrated Project Management for various purposes or who visit its websites |
| Data Controllers Registry | The data controllers registry maintained by the Presidency of the Personal Data Protection Board |
| Data Inventory | The inventory created and detailed by Integrated Project Management that associates its personal data processing activities — carried out in connection with its business processes — with the purposes of processing, the recipient group to whom personal data is transferred, and the relevant data subject group |
5. GENERAL PRINCIPLES REGARDING THE PROCESSING OF PERSONAL DATA
Pursuant to Article 3 of the KVKK, any operation performed on personal data — such as collection, recording, storage, preservation, alteration, adaptation, disclosure, transfer, acquisition, making available, classification, or prevention of use — whether wholly or partly by automated means or by non-automated means forming part of a data filing system, falls within the scope of processing personal data.
The following principles must be observed in the processing of personal data:
Compliance with law and rules of good faith
Integrated Project Management conducts its personal data processing activities in compliance with the Constitution, the KVKK, relevant legislation, and the rules of good faith.
Being accurate and, where necessary, up to date
While conducting personal data processing activities, Integrated Project Management takes all necessary administrative and technical measures to ensure the accuracy and currency of personal data.
Processing for specified, explicit, and legitimate purposes
Integrated Project Management determines the purpose of personal data processing clearly and precisely before commencing any personal data processing activity.
Being relevant, limited, and proportionate to the purposes for which they are processed
Personal data is processed by Integrated Project Management only to the extent necessary for the relevant specified, explicit, and legitimate purposes. Processing activities are not carried out on the assumption that the data may be useful in the future.
Retention for the period stipulated in the relevant legislation or required for the purpose for which they are processed
Integrated Project Management retains personal data only for the period stipulated by the KVKK and relevant legislation, or for the period required by the purposes of the processing activity.
6. PROCESSING OF PERSONAL DATA
Integrated Project Management conducts its personal data and special categories of personal data processing activities in accordance with the conditions for data processing set out in Articles 5 and 6 of the KVKK respectively.
6.1 CONDITIONS FOR PROCESSING PERSONAL DATA
Integrated Project Management may process personal data with the explicit consent of the data subject, or without explicit consent in the circumstances set out in Article 5 of the KVKK, which are listed below:
- It is expressly provided for by law.
- It is mandatory for the protection of the life or physical integrity of the person who is unable to disclose their consent due to actual impossibility or whose consent is not given legal validity, or of another person.
- It is necessary to process the personal data of the parties to a contract, provided that it is directly related to the establishment or performance of a contract.
- It is mandatory for the data controller to fulfil its legal obligation.
- The personal data has been made public by the data subject.
- Data processing is mandatory for the establishment, exercise, or protection of a right.
- Data processing is mandatory for the legitimate interests of Integrated Project Management, provided that the fundamental rights and freedoms of the data subject are not harmed.
6.2 PROCESSING OF SPECIAL CATEGORIES OF PERSONAL DATA
Integrated Project Management processes special categories of personal data, which carry a risk of discrimination if processed unlawfully, in accordance with the data processing conditions set out in Article 6 of the KVKK.
The processing of special categories of personal data without the explicit consent of the data subject is prohibited.
The measures determined by the Personal Data Protection Board for the processing of special categories of personal data are effectively implemented by Integrated Project Management.
6.3 CATEGORISATION OF PERSONAL DATA PROCESSED BY INTEGRATED PROJECT MANAGEMENT
| Personal Data Category | Description | Relevant Data Subject Category |
|---|---|---|
| Identity Data | All information contained in documents such as driving licences, identity cards, and residence permits, including but not limited to name and surname, Turkish ID number, nationality, mother's and father's name, place and date of birth, gender, and social security number | Customers, Third Parties, Suppliers, Visitors, Job Applicants, Employees of Cooperating Institutions |
| Contact Data | Information such as telephone number, address, e-mail, and fax number | Customers, Job Applicants, Visitors, Suppliers |
| Customer Data | Information obtained and produced about the data subject as a result of our commercial activities and the operations carried out by our business units within this framework | Customers |
| Customer Transaction Data | Information such as records relating to the use of our products and services and the customer's instructions and requests necessary for the use of products and services | Customers |
| Transaction Security Data | Personal data processed to ensure technical, administrative, legal, and commercial security during the conduct of the commercial activities of Integrated Project Management | Customers, Visitors, Suppliers |
| Risk Management Data | Personal data processed by methods used in accordance with generally accepted legal, commercial customs, and rules of good faith in order to manage our commercial, technical, and administrative risks | Customers, Visitors, Suppliers, Job Applicants |
| Financial Data | Personal data processed in relation to information, documents, and records showing any financial outcome created according to the type of legal relationship established with the data subject | Customers, Suppliers |
| Job Applicant Data | Personal data processed in relation to persons who have applied to become an employee of Integrated Project Management or who have been considered as a job applicant in line with the human resources needs of Integrated Project Management in accordance with commercial customs and rules of good faith | Job Applicants |
| Legal Transaction and Compliance Data | Personal data processed within the scope of the determination, pursuit, and fulfilment of our legal claims, rights, and obligations | Customers, Job Applicants, Suppliers, Third Parties |
| Audit, Inspection and Compliance Data | Personal data processed within the scope of compliance with the statutory obligations of Integrated Project Management and the policies of Integrated Project Management | Customers, Job Applicants, Visitors, Suppliers |
| Special Categories of Personal Data | As specified in Article 6 of the KVKK: data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, dress and appearance, membership of associations, foundations or trade unions, health, criminal convictions and security measures, as well as biometric and genetic data | Customers, Job Applicants, Third Parties, Employees of Cooperating Institutions |
| Marketing Data | Personal data processed for the purpose of customising the marketing of our products and services in line with the usage habits, preferences, and needs of the data subject, as well as reports and assessments generated as a result of such processing | Customers |
| Request / Complaint Management Data | Personal data relating to the receipt and evaluation of any request or complaint directed to Integrated Project Management | Customers, Job Applicants |
7. ENSURING THE SECURITY AND CONFIDENTIALITY OF PERSONAL DATA
In accordance with Article 12 of the KVKK, Integrated Project Management takes all necessary technical and administrative measures to ensure that the personal data it processes is processed and preserved lawfully and to prevent unlawful access to such personal data.
The unit of Integrated Project Management that assumes the corporate compliance function is responsible for the overall, sufficient, and effective conduct of activities within the framework of the KVKK and this policy, as well as for the relevant internal coordination. In this capacity, that unit is authorised and responsible for:
- Monitoring this policy and, when necessary, submitting it to the Board of Directors for approval for updating,
- Establishing other policies and procedures outside this policy relating to the protection, processing, and destruction of personal data, in coordination with the relevant units of Integrated Project Management,
- Making the necessary assignment of duties for the implementation of policies and procedures and submitting them to senior management for approval,
- Monitoring the implementation of all technical and administrative measures taken pursuant to Article 12 of the KVKK and planning audits thereof,
- Monitoring the processes relating to applications and requests made by data subjects and providing the necessary coordination to resolve any issues that may arise,
- Identifying the matters to be addressed to ensure compliance with the KVKK and relevant legislation and overseeing their implementation,
- Managing relations with the Personal Data Protection Board.
7.1 TECHNICAL MEASURES
All necessary technical security measures have been taken for the purpose of protecting personal data, and a sufficient level of protection against possible risks has been ensured. The main technical measures taken include:
- Periodic authority and access controls are applied to systems within Integrated Project Management that provide access to personal data.
- The technical measures taken are also monitored independently from executive activities within the scope of risk management, internal control, and internal audit processes.
- Personnel with a sufficient level of expertise are employed.
7.2 ADMINISTRATIVE MEASURES
- Employees of Integrated Project Management are trained and made aware of compliance with the KVKK.
- Where personal data transfer is involved, general conditions containing the obligations that must be fulfilled by the transferring parties for the security of personal data pursuant to the KVKK are established and ensured to be signed on a counterparty basis.
- Implementation rules are set on a business unit basis to meet the requirements identified for compliance with the KVKK, and the necessary administrative measures are ensured through internal procedures and training to ensure continuity.
- Provisions are included in contracts and documents governing legal relationships between Integrated Project Management and counterparties, imposing obligations not to process, disclose, or use personal data except in accordance with the instructions of Integrated Project Management and exceptions introduced by law; employee awareness is raised on this matter, and audits are conducted.
7.3 MEASURES IN CASE OF UNLAWFUL DISCLOSURE
An internal procedure has been developed to ensure that, in the event that personal data processed within the requirements of compliance with the KVKK is obtained by others through unlawful means, the relevant data subject and the Personal Data Protection Board are notified as soon as possible.
8. PURPOSES OF PROCESSING PERSONAL DATA AND RETENTION PERIODS
8.1 PURPOSES OF PROCESSING
Personal data is processed within Integrated Project Management for the following purposes:
- Management of relationships and business processes within the scope of agreements with contracted institutions and/or suppliers,
- Conducting processes related to job applicants and concluding employment contracts,
- Planning and execution of the necessary audit activities to ensure that activities are carried out in accordance with the procedures of Integrated Project Management and relevant legislation,
- Conducting internal control processes,
- Meeting the requests of relevant persons,
- Planning and conducting corporate sustainability activities,
- Evaluating customer requests and complaints,
- Conducting processes within the scope of marketing activities,
- Conducting the operational activities, business relationships, and human resources processes of Integrated Project Management,
- Carrying out processes arising from corporate law,
- Ensuring that our products and services are presented to our customers in the most appropriate manner,
- Providing information to authorised institutions and organisations pursuant to obligations arising from relevant legislation,
- Creating and monitoring visitor records.
8.2 RETENTION PERIODS
Integrated Project Management determines whether a specific retention period is stipulated in the relevant legislation for the storage of personal data. In accordance with Article 138 of the Turkish Penal Code and Articles 4 and 7 of the KVKK, it ensures that personal data is retained only for the period stipulated in the relevant legislation, or — where no period is stipulated in the relevant legislation — for the period required by the purpose of personal data processing.
9. DELETION, DESTRUCTION, AND ANONYMISATION OF PERSONAL DATA
Where the purpose for processing personal data has ceased and the retention periods determined by the relevant legislation and/or Integrated Project Management have expired, personal data is erased, destroyed, or anonymised by Integrated Project Management either at the request of the data subject or ex officio. The procedures and principles in this regard have been established within the framework of the provisions of the KVKK and the Regulation on the Deletion, Destruction, or Anonymisation of Personal Data.
9.1 DELETION AND DESTRUCTION TECHNIQUES
Personal data must be deleted and destroyed using methods appropriate to the recording medium.
Physical Destruction
Personal data may also be processed by non-automated means as part of a data filing system. When such data is being erased/destroyed, the system of physically destroying the personal data in a manner that renders it impossible to use subsequently is applied.
Secure Erasure/Destruction from Software
When data processed by wholly or partly automated means and stored in digital environments is being erased/destroyed, methods are used that delete the data from the relevant software in a manner that renders it irrecoverable by specific persons or in any form.
Secure Erasure/Destruction by an Expert
Integrated Project Management may in some cases engage an expert to erase/destroy personal data on its behalf. In such cases, the personal data is securely erased/destroyed by the expert in a manner that renders it irrecoverable.
9.2 ANONYMISATION TECHNIQUES
The anonymisation of personal data refers to the process of rendering personal data impossible to associate with an identified or identifiable natural person, even when matched with other data.
In accordance with Article 28 of the KVKK, anonymised personal data may be processed for purposes such as research, planning, and statistics.
Masking
Data masking is a method of anonymising personal data by removing the key identifying information of the personal data from within the dataset.
Aggregation
Using the data aggregation method, large amounts of data are aggregated so that personal data can no longer be associated with any individual.
Data Derivation
Using the data derivation method, more general content is generated from the content of personal data, ensuring that the personal data can no longer be associated with any individual.
Data Shuffling
Using the data shuffling method, the values within the personal data set are mixed, thereby severing the link between the values and individuals.
10. THIRD PARTIES TO WHOM PERSONAL DATA IS TRANSFERRED AND THE PURPOSES OF TRANSFER
The procedures and principles applicable to personal data transfers are regulated under Articles 8 and 9 of the KVKK. For the purpose of fulfilling the services provided by Integrated Project Management, personal data is processed within the framework of the KVKK and other applicable legislation and may be shared with the infrastructure providers, third parties from whom services are obtained, contracted institutions, business partners, and other third parties of Integrated Project Management. Except for the exceptional circumstances specified in the KVKK, it is not possible to transfer personal data without the explicit consent of the data subject.
10.1 DOMESTIC TRANSFER
In accordance with Article 8 of the KVKK, the domestic transfer of personal data is possible provided that one of the conditions specified in Section 6.1 of this Policy, entitled "Conditions for Processing Personal Data", is met.
10.2 INTERNATIONAL TRANSFER
In accordance with Article 9 of the KVKK, the international transfer of personal data requires, in addition to the conditions applicable to domestic transfers, the existence of one of the following:
- The country to which the transfer is to be made is among the countries declared by the Personal Data Protection Board as having adequate protection.
- Where adequate protection does not exist in the country to which the transfer is to be made, the data controllers in Turkey and the relevant foreign country undertake adequate protection in writing and the Personal Data Protection Board grants its permission accordingly.
10.3 GROUPS OF PERSONS TO WHOM PERSONAL DATA IS TRANSFERRED
| Groups of Persons | Definition | Purpose of Transfer |
|---|---|---|
| Public Institutions and Organisations | Public institutions and organisations that request information and documents from Integrated Project Management in accordance with applicable legislation | Limited to the purposes requested by the relevant public institutions and organisations |
| Private Law Persons | Private law persons with whom Integrated Project Management shares information and documents in accordance with applicable legislation | Limited to the purpose of continuing the services of Integrated Project Management within the framework of applicable legislation and in the areas in which it operates |
11. INFORMATION OBLIGATION AND DATA SUBJECT RIGHTS
11.1 INFORMATION OBLIGATION
In accordance with Article 10 of the KVKK, Integrated Project Management informs data subjects at the time of collection of their personal data. In this context, Integrated Project Management fulfils its information obligation by providing data subjects with the following:
- The title of Integrated Project Management as data controller
- The purposes for which personal data will be processed
- The persons to whom processed personal data may be transferred and for what purpose
- The method and legal basis for collecting personal data
- The rights of the data subject
11.2 RIGHTS OF DATA SUBJECTS
Data subjects may submit their requests regarding the rights enumerated under Section 11.2 of this Policy to Integrated Project Management by the methods specified below or by other methods determined by the Personal Data Protection Board, by completing and signing the Integrated Project Management Data Subject Application Form. Upon submission of such a request, it will be concluded free of charge depending on the nature of the request.
After completing the form available under the "Legal Information" section of the corporate website of Integrated Project Management:
- A wet-signed copy must be delivered in person or through a notary to "Sahrayı Cedit, Halk Sk. Sıddıklar İş Merkezi No:56/4 34734 Kadıköy/İstanbul", or
- After being signed with a "secure electronic signature" within the scope of the Electronic Signature Law No. 5070, the securely electronically signed form must be sent to the e-mail address info@epy.com.tr by registered electronic mail.
Integrated Project Management may request information from the relevant person in order to verify whether the applicant is a data subject.
Pursuant to Article 11 of the KVKK, data subjects have the right to request the following from Integrated Project Management:
- To learn whether their personal data is being processed,
- To request information if their personal data has been processed,
- To learn the purposes of processing their personal data and whether it is being used in accordance with those purposes,
- To learn the third parties to whom their personal data has been transferred domestically or internationally,
- To request correction of their personal data where it has been processed incompletely or inaccurately, and to request that the transaction carried out within this scope be notified to the third parties to whom the personal data has been transferred,
- To request the deletion, destruction, or anonymisation of their personal data where the grounds for processing no longer exist, and to request that the transaction carried out within this scope be notified to the third parties to whom the personal data has been transferred,
- To object to the emergence of a result against themselves by means of analysis of the processed data exclusively through automated systems,
- To request compensation for damage suffered as a result of the unlawful processing of their personal data.
11.3 SITUATIONS OUTSIDE THE SCOPE OF DATA SUBJECT RIGHTS
Pursuant to Article 28 of the KVKK, data subjects cannot assert their rights of application in the following circumstances, as they fall outside the scope of the KVKK:
- Processing of personal data for purposes such as research, planning, and statistics by rendering it anonymous through official statistics.
- Processing of personal data for artistic, historical, literary, or scientific purposes, or within the scope of freedom of expression, provided that it does not violate national defence, national security, public security, public order, economic security, the privacy of private life, or personal rights, or does not constitute a criminal offence.
Pursuant to paragraph 2 of Article 28 of the KVKK, data subjects cannot assert their rights in the following circumstances, with the exception of the right to request compensation for damage:
- Where processing of personal data is necessary for the prevention or investigation of a criminal offence.
- Processing of personal data that has been made public by the data subject themselves.
11.4 RESPONSE PROCEDURE
In accordance with Article 13 of the KVKK, Integrated Project Management concludes the application requests made by data subjects free of charge and as soon as possible, and in any event within a maximum of 30 (thirty) days, depending on the nature of the request. However, where the transaction requires an additional cost, it is possible to charge the fee set out in the tariff determined by the Personal Data Protection Board.
Integrated Project Management may accept the application request of the data subject or, by explaining its justification, reject it on the following grounds:
- Obstructing the rights and freedoms of others
- Requiring disproportionate effort
- The information being publicly available
- Jeopardising the privacy of others
- The existence of one of the circumstances falling outside the scope of the KVKK
The data subject has the right to lodge a complaint with the Personal Data Protection Board within thirty days from the date on which they learn the response of the data controller, and in any case within sixty days from the date of application, in the event that their application is rejected, the response given is found inadequate, or no response is given within the prescribed period.
12. DATA PROCESSING ACTIVITIES IN SPECIFIC AREAS
12.1 CUSTOMER ENTRY AND EXIT RECORDS
Personal data processing activities are carried out for the purpose of monitoring the entry and exit of guests visiting Integrated Project Management.
12.2 WEBSITE VISITORS
The internet activity of persons visiting the website of Integrated Project Management is recorded (via technical means such as cookies) for the purpose of displaying personalised content and conducting online advertising activities. Detailed explanations regarding these activities of Integrated Project Management are set out in the Privacy Policy texts on our website.
Contact
| Data Controller | Entegre Proje Yönetim Danışmanlık Mühendislik Tic. A.Ş. |
| Address | Sahrayı Cedit, Halk Sk. Sıddıklar İş Merkezi No:56/4 34734 Kadıköy/İstanbul |
| info@epy.com.tr | |
| Phone | +90 (216) 355 26 50 |
To exercise your rights under the KVKK, you may download or complete the application form.
Data Subject Application FormPrepared in accordance with Law No. 6698 on the Protection of Personal Data.
Last updated: 31.07.2026
1. INTRODUCTION
Under the Constitution of the Republic of Turkey, everyone has the right to request the protection of their personal data. This right includes the right to be informed about personal data concerning oneself, to access such data, to request its correction or deletion, and to learn whether it is being used in accordance with its intended purposes.
To ensure the exercise of this constitutional right, the Law on the Protection of Personal Data No. 6698 (“KVKK”) was enacted to regulate the protection of individuals’ fundamental rights and freedoms in the processing of personal data, as well as the procedures and principles that natural and legal persons processing personal data must comply with. ENTEGRE PROJE YÖNETİM DANIŞMANLIK MÜHENDİSLİK TİCARET A.Ş. (“Entegre Project Management”) exercises due diligence regarding compliance with the KVKK and has established this compliance as a corporate culture and policy through this Personal Data Protection and Processing Policy (“Policy”).
The scope of this Policy covers the protection by Entegre Project Management of personal data belonging to Job Applicants, Entegre Project Management Shareholders, Visitors, Employees of Organizations We Collaborate With, Customers, and Third Parties (Guarantors, Victims/Right Holders, etc.). Activities related to the protection of our employees’ personal data are managed in accordance with the provisions of the “Policy on the Processing of Personal Data of Entegre Project Management Employees,” which was drafted in line with the principles set forth in this Policy.
2. PURPOSE
The purpose of this Policy is to provide explanations regarding the personal data processing activities conducted by Entegre Project Management in compliance with the Personal Data Protection Law (KVKK) and the principles adopted for the protection of personal data. In this context; the aim is to inform individuals whose personal data is processed by Entegre Project Management—including, but not limited to, Job Applicants, Entegre Project Management Shareholders, Visitors, Employees of Partner Organizations, Customers, and Third Parties with legitimate interests—and to ensure full transparency throughout the process.
3. SCOPE
Within the scope of this Policy, data subjects whose personal data is processed are categorized as follows:
| Category | Descrıptıon |
|---|---|
| Job Applicants | Natural persons who apply for a job at Entegre Project or make their resumes and related information available to Entegre Project through any means |
| Employees of Organizations We Collaborate With | Employees of organizations (suppliers, subcontractors, business partners, etc.) that have a business relationship with Entegre Project Management |
| Customers | Natural persons whose personal data is collected as a result of activities and business relationships conducted by Entegre Project Management, regardless of whether a contractual relationship exists |
| Visitors | Natural persons who have entered Entegre Project Management’s physical facilities for various purposes or who have visited its websites |
| Third Parties | Other natural persons whose personal data is processed under this Policy, even if they are not defined in the categories above (e.g., guarantors, accompanying persons, former employees) |
With regard to the processing of Entegre Project Management employees' personal data—whether fully or partially automated, or processed by non-automated means provided it forms part of a data recording system—the “Policy on the Processing of Entegre Project Management Employees’ Personal Data” has been established separately from this Policy.
4. DEFINITIONS
The definitions used in this Policy are as follows:
| Term | Defınıtıon |
|---|---|
| Explicit consent | Consent that is specific to a particular matter, based on information provided, and freely given |
| Anonymization | The process of rendering personal data incapable of being associated with any identified or identifiable natural person, even when combined with other data |
| Job Applicant | Natural persons who have applied for a job at Entegre Project Management through any means or have made their resume accessible |
| Data Subject | The natural person whose personal data is being processed |
| Relevant User | Persons who process data within the organization of or under the authority of the data controller, excluding the person or unit responsible for the technical storage, protection, and backup of the data |
| Personal data | Any information relating to an identified or identifiable natural person |
| Processing of personal data | Any operation performed on data, such as collection, recording, storage, modification, transfer, or restriction of use |
| Data Subject Request Form | The form that data subjects will use when submitting requests to Entegre Project Management to exercise their rights under Article 11 of the KVKK |
| KVKK / Law | Law No. 6698 on the Protection of Personal Data |
| Board | Refers to the Personal Data Protection Board |
| Authority | Refers to the Personal Data Protection Authority |
| Deletion | Making personal data inaccessible and unusable in any way for the relevant users |
| Turkish Penal Code | Turkish Penal Code No. 5237 |
| Data Inventory | A record detailing the purposes of data processing, the recipient groups to whom data is transferred, and retention periods, in accordance with Entegre Project Management’s business processes |
| Data Processor | A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller |
| Data Controller | A natural or legal person (Entegre Project Management) that determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system |
| Data Controllers Registry (VERBİS) | A publicly accessible registry maintained by the Presidency of the Personal Data Protection Board |
| Destruction | Ensuring that personal data is rendered inaccessible, irrecoverable, and unusable by anyone in any way. |
| Visitor | Natural persons who visit Entegre Project Management’s physical facilities or websites for various purposes. |
5. GENERAL PRINCIPLES REGARDING THE PROCESSING OF PERSONAL DATA
Pursuant to Article 3 of the Personal Data Protection Law (KVKK); any operation performed on personal data—such as the collection, recording, storage, retention, modification, reorganization, disclosure, transfer, acquisition, making available, classification, or restriction of use—whether fully or partially automated or carried out by non-automated means as part of a data recording system, falls within the scope of the processing of personal data.
In the processing of personal data by Entegre Project Management, compliance with the following fundamental principles set forth in Article 4 of the Law is mandatory:
Compliance with the Law and Principles of Good Faith
Entegre Project Management conducts its personal data processing activities in compliance with the Constitution, the Personal Data Protection Law (KVKK), relevant legislation, and the principles of good faith.
Accuracy and, Where Necessary, Timeliness
During the processing of personal data, Entegre Project Management takes all necessary administrative and technical measures to ensure the accuracy and timeliness of the data. In this context, data subjects are given the opportunity to update their information.
Processing for Specific, Clear, and Legitimate Purposes
Entegre Project Management clearly defines the purpose of the data processing activity in a specific, clear, and legitimate manner before commencing such processing.
Processing That Is Relevant, Limited, and Proportionate to the Purpose
Personal data is processed only to the extent necessary to achieve the specified purposes. Data processing is not conducted based on the notion that “it might be needed in the future” (for storage purposes).
Retention for the Period Specified by Applicable Legislation or Necessary for the Purpose of Processing
Entegre Project Management retains personal data for the period specified in applicable legislation, if any, or for the period required by the purpose of processing, if no such period is specified. At the end of this period, the data is deleted, destroyed, or anonymized.
6. PROCESSING OF PERSONAL DATA
Entegre Project Management conducts its processing activities involving personal data and special category personal data in full compliance with the data processing conditions set forth in Articles 5 and 6 of the Personal Data Protection Law (KVKK).
6.1 CONDITIONS FOR THE PROCESSING OF PERSONAL DATA
Entegre Project Management does not process personal data without the explicit consent of the data subject. However, in accordance with Article 5 of the KVKK, the processing of personal data without explicit consent is permitted if one of the following conditions is met:
- Explicit provision in laws: The processing of data is directly provided for in relevant laws.
- Actual impossibility: It is necessary to protect the life or physical integrity of a person who is unable to express consent or whose consent is not legally valid.
- Conclusion or performance of a contract: Where the processing of personal data belonging to the parties is necessary for the conclusion or performance of a contract, provided that such processing is directly related to the contract.
- Legal obligation: Where data processing is necessary for Entegre Project Management to fulfill its legal obligations.
- Disclosure: The data subject has disclosed their personal data to the public themselves.
- Establishment, exercise, or protection of a right: Data processing is necessary for the establishment or protection of a right.
- Legitimate interest: Data processing is necessary for the legitimate interests of Entegre Project Management, provided that it does not infringe upon the data subject’s fundamental rights and freedoms.
6.2 PROCESSING OF SPECIAL CATEGORIES OF PERSONAL DATA
For this data, which carries a risk of discrimination if processed unlawfully, Entegre Project Management acts in accordance with Article 6 of the Personal Data Protection Law (KVKK). Special category personal data (excluding data related to health and sexual life) may be processed without explicit consent in cases provided for by law. Data related to health and sexual life, however, may only be processed by authorized institutions for limited purposes such as the protection of public health, medical diagnosis, and treatment. E Project Management meticulously implements the additional security measures determined by the Board during this process.
6.3 CATEGORIZATION OF PERSONAL DATA PROCESSED BY ENTEGRE PROJECT
| Personal Data Category | Descrıptıon | Category of Data Subject to Whıch the Relevant Personal Data Relates |
|---|---|---|
| Identity Information | First and last name, Turkish ID number, nationality, parents’ names, place of birth, date of birth, gender, and Social Security Number (SGK), as well as all information contained in documents such as driver’s licenses, national ID cards, and residence permits, without being limited to these; | Customers, Third Parties, Suppliers, Visitors, Job Applicants, Employees of Organizations We Collaborate With |
| Contact Information | Information such as phone number, address, email, and fax number | Customer, Job Applicant, Visitor, Supplier |
| Customer Information | Information obtained and generated about the relevant individual as a result of our commercial activities and the operations conducted by our business units within this framework | Customers |
| Customer Transaction Information | Records related to the use of our products and services, as well as information such as instructions and requests necessary for the customer’s use of products and services | Customers |
| Transaction Security Information | Personal data processed to ensure technical, administrative, legal, and commercial security during the conduct of Entegre Project Management's commercial activities | Customers, Visitors, Suppliers |
| Risk Management Information | Personal data processed using methods in accordance with generally accepted legal principles, commercial practices, and the principle of good faith in these areas to enable us to manage our commercial, technical, and administrative risks | Customers, Visitors, Suppliers, Job Applicants |
| Financial Information | Personal data processed in relation to information, documents, and records reflecting any financial outcomes arising from the type of legal relationship established with the data subject | Customers, Suppliers |
| Job Applicant Information | Personal data processed regarding individuals who have applied to become employees of Entegre Project Management, or who have been evaluated as job applicants in accordance with commercial practice and the principle of good faith to meet Entegre Project Management’s human resources needs, or who are in an employment relationship with Entegre Project Management | Job Applicants |
| Legal Proceedings and Compliance Information | Personal data processed in the context of identifying and pursuing our legal claims and rights, and fulfilling our obligations | Customers, Job Applicants, Suppliers, Third Parties |
| Audit, Inspection, and Compliance Information | Personal data processed in the context of Entegre Project Management's legal obligations and compliance with Entegre Project Management policies | Customers, Job Applicants, Visitors, Suppliers |
| Special Category Personal Data | As specified in Article 6 of the Personal Data Protection Law (KVKK); data regarding a person’s race, ethnic origin, political opinions, philosophical beliefs, religion, denomination, or other beliefs, attire and clothing, membership in associations, foundations, or unions, health, criminal convictions, and data related to security measures, as well as biometric and genetic data | Customers, Job Applicants, Third Parties, Employees of Organizations We Collaborate With |
| Marketing Information | Personal data processed to market our products and services by customizing them according to the data subject’s usage habits, preferences, and needs | Customers |
| Request/Complaint Management Information | Personal data related to the receipt and evaluation of any requests or complaints directed to Entegre Project Management | Customers, Job Applicants |
7. ENSURING THE SECURITY AND CONFIDENTIALITY OF PERSONAL DATA
Entegre Project Management, in accordance with Article 12 of the Personal Data Protection Law (KVKK), takes all necessary technical and administrative measures to ensure that the personal data it processes is handled and stored in compliance with the law and to prevent unauthorized access to such data.
The relevant unit at Entegre Project Management, which assumes the role of corporate compliance, is responsible for coordinating the adequate and effective execution of activities under the KVKK as a whole, in accordance with this Policy. Within this scope, the aforementioned unit is responsible for:
- Monitoring the implementation of this Policy, updating it as necessary, and submitting it to the Board of Directors for approval,
- Developing other policies and procedures related to the protection and destruction of personal data in coordination with the relevant units,
- Assigning the necessary responsibilities for the implementation of the policies and procedures and submitting them to senior management for approval,
- To monitor the implementation of technical and administrative measures taken in accordance with Article 12 of the Law and to plan audits thereof,
- To track requests and inquiries from data subjects and coordinate their resolution,
- Identify the necessary requirements for compliance with the Personal Data Protection Law (KVKK) and related legislation and oversee their implementation,
- Is authorized and responsible for managing relations with the Personal Data Protection Board (the Board).
7.1 TECHNICAL MEASURES
All necessary technical security measures have been implemented to protect personal data, ensuring an adequate level of protection against potential risks. The primary measures are as follows:
- Periodic authorization and access controls are applied to systems that provide access to data within the Entegre Project Management framework.
- The technical measures taken are periodically audited as part of risk management, internal control, and internal audit processes, independently of operational activities.
- Personnel with sufficient expertise in data security and information systems are employed.
7.2 ADMINISTRATIVE MEASURES TAKEN
- Training and Awareness: All employees receive regular training and are made aware of KVKK compliance and the protection of personal data.
- Contract Management: In cases involving data transfers, protocols and confidentiality agreements that include data security obligations are signed with the counterparties.
- Corporate Discipline: Implementation rules have been established for each business unit, and the continuity of these rules is ensured through internal company procedures.
- Access Restrictions: Internal authorizations are structured so that employees can access only the data they need based on their job descriptions (need-to-know principle).
7.3 MEASURES TO BE TAKEN IN THE EVENT OF A DATA BREACH
In the event that processed personal data is obtained by others through unlawful means (data breach), a Data Breach Response Plan and internal procedures have been developed to ensure that this situation is reported to the Personal Data Protection Board as soon as possible and no later than 72 hours. If the breach poses a risk to the individuals concerned, data subjects are also notified through appropriate methods.
8. PURPOSES OF PROCESSING PERSONAL DATA AND RETENTION PERIODS
8.1 PURPOSES OF PROCESSING PERSONAL DATA
At Entegre Project Management, personal data is processed within the framework of the conditions for processing personal data specified in Articles 5 and 6 of the Personal Data Protection Law (KVKK), for the purposes listed below:
- Management of Operational Processes: Planning and execution of business operations, our business relationships, contract processes, and human resources processes.
- Contract and Supply Chain Management: Management of relationships and business processes within the scope of contracts entered into with partner organizations and/or suppliers.
- Customer Relations: Ensuring that our products and services are provided to our customers in the most appropriate manner, and evaluating and resolving customer requests and complaints.
- Legal and Regulatory Compliance: Fulfilling obligations arising from corporate law and other relevant legislation; providing information to authorized institutions and organizations as required by law.
- Audit and Security: Conducting audit and internal control processes to ensure that activities are carried out in accordance with Entegre Project Management procedures and applicable laws; maintaining visitor logs and monitoring physical premises security.
- Marketing and Development: Executing processes related to marketing activities and planning corporate sustainability initiatives.
- Human Resources: Conducting processes related to job candidates (application, interview, evaluation) and establishing employment contracts.
8.2 RETENTION PERIODS FOR PERSONAL DATA
Entegre Project Management determines whether relevant legislation specifies a retention period for personal data and acts in accordance with Article 138 of the Turkish Penal Code and Articles 4 and 7 of the Personal Data Protection Law (KVKK).
- If a Retention Period Is Specified by Law: Personal data is retained for the period specified in the relevant law or regulation (e.g., statute of limitations, retention periods for commercial records, etc.).
- If No Retention Period Is Specified by Law: Personal data is retained only for as long as necessary to fulfill the purpose of processing.
9. DELETION, DESTRUCTION, AND ANONYMIZATION OF PERSONAL DATA
When the purpose of processing personal data has ended and the retention periods established by applicable legislation and Entegre Project Management have expired, personal data is deleted, destroyed, or anonymized upon the data subject’s request or by Entegre Project Management on its own initiative.
The procedures and principles regarding this process are carried out in accordance with the provisions of the Personal Data Protection Law (KVKK) and the “Regulation on the Deletion, Destruction, or Anonymization of Personal Data.”
9.1 TECHNIQUES FOR THE DELETION AND DESTRUCTION OF PERSONAL DATA
Personal data must be destroyed using methods appropriate to the storage media on which it is held. While technical details are outlined in the company’s “Personal Data Retention and Destruction Policy”, the primary methods used are as follows:
Physical Destruction
This involves the irreversible destruction of data stored on physical data storage systems—such as paper or optical/magnetic media—using methods like burning, shredding, or melting, ensuring the data cannot be recovered.
Secure Deletion/Destruction via Software
This involves deleting data stored in digital environments using relevant software in such a way that it cannot be recovered by anyone, including authorized users.
Secure Deletion/Destruction by Experts
Entegre Project Management may seek external professional support to ensure data is permanently and irreversibly deleted in situations requiring technical expertise. In such cases, the data is destroyed by experts using secure methods.
9.2 ANONYMIZATION TECHNIQUES
Anonymization is the process of rendering personal data such that it cannot be associated with any identifiable or identifiable natural person under any circumstances, even if matched with other data.
Pursuant to Article 28 of the KVKK, anonymized data may be processed for purposes such as research, planning, and statistics. Since this data falls outside the scope of the KVKK, the data subject’s explicit consent is not required, and the rights outlined in Section 12 of the Policy cannot be asserted with respect to this data. The primary techniques used by Entegre Project Management are as follows:
Masking
This involves removing the key identifying information from personal data (e.g., masking part of a Turkish ID number with asterisks) from the dataset.
Aggregation
This involves removing personal identifiers from the data and converting it into statistical summaries (e.g., recording “total number of customers in Region X” instead of individual names).
Data Derivation
This involves creating a more general representation of the data’s content (e.g., recording only “Age Range” instead of a specific date of birth).
Data Scrambling (Adding Noise)
This involves scrambling the values within the dataset to sever the link between the data and actual individuals.
10. THIRD PARTIES TO WHOM PERSONAL DATA IS TRANSFERRED AND THE PURPOSES OF SUCH TRANSFERS
The procedures and principles to be followed in the transfer of personal data are regulated in Articles 8 and 9 of the KVKK. Entegre Project Management may share personal data with third parties in order to perform its services, primarily in accordance with the provisions of Law No. 1774 on Identity Reporting, Law No. 6502 on the Protection of Consumers, and other relevant legislation.
Personal data may be transferred to third parties under Article 8 of the KVKK without the data subject’s explicit consent, provided that the conditions for data processing specified in Articles 5 and 6 of the KVKK are met. In cases where explicit consent is required, such consent is obtained separately from the data subject. Details regarding the transfer processes are defined in the internal “Data Transfer and Sharing Procedure”.
10.1 DOMESTIC TRANSFER
In accordance with Article 8 of the KVKK, the domestic transfer of personal data is permitted provided that at least one of the conditions specified in Section 6.1 of this Policy (Conditions for the Processing of Personal Data) is met.
10.2 TRANSFER ABROAD
In accordance with Article 9 of the KVKK; for the transfer of personal data abroad, in addition to the conditions for domestic transfer, one of the following criteria must be met:
- Adequacy Decision: The country, sector, or international organization to which the transfer will be made must be among those designated by the Board as “Adequate Protection” as announced by the Board.
- Appropriate Safeguards: In cases where no adequacy decision exists, personal data may be transferred abroad through the signing of standard contracts determined by the Board between data controllers and data processors, the application of Binding Corporate Rules (BCR), or the provision of appropriate safeguards.
- Exceptional Cases: The existence of the data subject’s explicit consent or other exceptional (temporary/one-time) circumstances listed in the Law.
10.3 CATEGORIES OF RECIPIENTS TO WHOM PERSONAL DATA IS TRANSFERRED
Entegre Project Management may transfer personal data covered by this Policy to the following categories of recipients, within the scope of the specified purposes:
| Recipient Groups | Description | Purpose of Transfer |
|---|---|---|
| Authorized Public Institutions and Organizations | Public authorities authorized to request information and documents in accordance with the law (Ministries, BTK, KVKK, etc.). | Compliance with legal obligations and fulfillment of requests from authorized authorities |
| Business Partners and Suppliers | Natural or legal persons from whom Entegre Project Management receives services or with whom it collaborates while conducting its operations | Service provision, infrastructure support, and ensuring the continuity of commercial activities |
11. INFORMATION DISCLOSURE OBLIGATION AND DATA SUBJECT RIGHTS
11.1 OUR COMPANY’S OBLIGATION TO PROVIDE INFORMATION
Entegre Project Management informs data subjects at the time of collecting personal data in accordance with Article 10 of the Personal Data Protection Law (KVKK). Within this scope, the following information is provided through our privacy notices:
- The name of Entegre Project Management as the data controller,
- The purposes for which personal data will be processed,
- To whom and for what purposes the processed data may be transferred,
- The method and legal basis for data collection,
- The data subject’s rights under Article 11 of the KVKK.
11.2 DATA SUBJECTS’ RIGHTS (RIGHT TO SUBMIT A REQUEST)
Pursuant to Article 11 of the KVKK, you may exercise the following rights by submitting a request to Entegre Project Management:
- To learn whether your personal data is being processed,
- To request information regarding such processing if it has occurred,
- To learn the purpose of processing and whether the data is being used in accordance with that purpose,
- To know the third parties to whom your personal data has been transferred, whether within or outside the country,
- To request the correction of your personal data if it has been processed incompletely or incorrectly,
- To request the erasure or destruction of your personal data under Article 7 of the KVKK,
- To request that third parties to whom your data has been transferred be notified of any corrections, erasures, or destruction,
- To object to a decision made solely through automated processing that adversely affects you,
- To request compensation for any damages you may have suffered due to unlawful processing.
11.3 APPLICATION PROCEDURES AND CHANNELS
You may submit your requests by filling out the “Data Subject Request Form” available on our website using the following methods:
- Hand-Signed Request: By sending a signed copy of the form in person or through a notary to the address “Barbaros Mah. Çiğdem Sok. Ağaoğlu My Office No: 1 / 36, 34734 Ataşehir/Istanbul.”
- Electronically Signed Request: By signing the form with a “secure electronic signature” as defined under the Electronic Signature Law No. 5070 and sending it via email to info@epy.com.
Important Note: Entegre Project Management may request additional information or identity verification to confirm that the person submitting the request is the “data subject.”
11.4 RESPONSE TIMEFRAME AND PROCEDURE
Entegre Project Management will process requests free of charge as soon as possible and no later than 30 (thirty) days, depending on the nature of the request. However, if the process incurs additional costs, a fee based on the tariff determined by the Board may be charged.
Data subjects’ requests may not be fulfilled in cases falling under the exceptions listed in Article 28 of the KVKK.
12. DATA PROCESSING ACTIVITIES IN SPECIFIC AREAS
12.1 VISITORS TO PHYSICAL PREMISES (Visitor Entries and Exits)
For visitors to the Entegre Project Management campus, data such as first and last names and entry and exit times are processed to ensure building security and comply with legal obligations. Visual data captured by security cameras in these areas is also recorded for security purposes.
12.2 WEBSITE VISITORS (Cookies)
The cookies used on our website are classified as essential cookies, performance/analytics cookies, and marketing cookies. Except for essential cookies, users’ explicit consent is required for all other cookies, and users may change their cookie preferences at any time. Detailed information is available in the “Cookie Policy” on our website.
Contact
| Fıeld | Informatıon |
|---|---|
| Data Controller | Entegre Project Management Consulting Engineering Inc. |
| Address | Barbaros Mah. Çiğdem Sok. Ağaoğlu My Office No:1 / 36 34746 Ataşehir / Istanbul |
| info@epy.com.tr, entegreprojeyonetim@hs03.kep.tr | |
| Phone | +90 (216) 355 26 50 |
To use your rights under the Personal Data Protection Law, you can download or fill out the application form.
Prepared in accordance with Law No. 6698 on the Protection of Personal Data.
