carbonemit logo

PDPL

We process and protect your personal data securely

1. Introduction

1.1. Purpose of the Policy

Within the scope of Law No. 6698 on the Protection of Personal Data ('Law'), as Marsala Yazılım Inc. ('CarbonEmit' and 'Company'), processing and protection of personal data in accordance with the law is among our top priorities. We follow the same priority in all our planning and business activities. In this context, in accordance with Article 10 of the Law, we hereby submit this Policy on Processing and Protection of Personal Data ('Policy') to your information in order to enlighten you and to inform you of all administrative and technical measures we will implement within the scope of processing and protection of personal data.

1.2. Scope

This Policy sets out the conditions for the processing of personal data and sets out the principles adopted by CarbonEmit in the processing of personal data. In this context, the Policy covers all personal data processing activities carried out by CarbonEmit within the scope of the Law, all personal data processed and the owners of such data.

1.3. Definitions

- Explicit Consent: Consent on a specific subject, based on information and expressed with free will.

- Anonymization: Making the data previously associated with a person impossible to be associated with an identified or identifiable natural person under any circumstances, even by matching with other data.

- Employee Candidate: Natural persons who do not work for CarbonEmit but have the status of employee candidate.

- Personal Data: Any information relating to an identified or identifiable natural person.

- Data Subject: The natural person whose personal data is processed.

- Processing of Personal Data: Any operation performed on personal data such as obtaining, recording, storing, preserving, modifying, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data by fully or partially automatic means or by non-automatic means provided that it is part of any data recording system.

- Law: Law No. 6698 on the Protection of Personal Data published in the Official Gazette dated April 7, 2016 and numbered 29677.

- Special Categories of Personal Data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, clothing, membership to associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data.

- Policy: Marsala Yazılım Inc. Personal Data Processing and Protection Policy

- Company: CarbonEmit or Marsala Yazılım Inc.

- Data Processor: A natural or legal person who processes personal data on behalf of the data controller based on the authorization granted by the data controller.

- Data Controller: The person who determines the purposes and means of processing personal data and manages the place where the data is kept systematically.

- Data Recording System: The recording system where personal data is structured and processed according to certain criteria.

- Business Partners: Persons with whom CarbonEmit has established a partnership within the scope of contractual relations within the framework of its commercial activities.

1.4. Enforcement of the Policy

This Policy, edited by CarbonEmit, entered into force on May 25th and was presented to the public. In case of any conflict between the legislation in force, particularly the Law, and the regulations in this Policy, the provisions of the legislation shall apply. CarbonEmit reserves the right to amend the Policy in line with legal regulations. The current version of the Policy is available on the CarbonEmit website (www. CarbonEmit.com).

2. Information on CarbonEmit's Personal Data Processing Activities

2.1. Data Subjects

Data subjects under the Policy are all natural persons, other than CarbonEmit employees, whose personal data are processed by CarbonEmit. In general, data subjects can be listed as follows:

- Customers: Refers to natural persons who benefit from the products and services offered by CarbonEmit.

- Potential Customers: Natural persons who show interest in the products and services offered by CarbonEmit and have the potential to become customers.

- Employee Candidates: Refers to natural persons who apply for a job by sending a CV to CarbonEmit or by other means.

- Third Parties: Refers to the above categories of data subjects and natural persons other than CarbonEmit employees.

The categories of data subjects described above are provided for general information sharing purposes. The fact that the data subject does not fall within the scope of any of these categories does not eliminate the nature of the data subject as stated in the Law.

2.2. Purposes of Processing Personal Data

2.2.1. Carrying out the necessary work and executing the business processes by the relevant units in order to benefit the relevant persons from the products and services offered by CarbonEmit:

- Planning and execution of sales processes of products and/or services,

- Planning and/or execution of after sales support services activities,

- Planning and execution of customer relationship management processes,

- Follow-up of contract processes and/or legal requests,

- Follow-up of customer requests and/or complaints.

2.2.2. Planning and execution of CarbonEmit human resources policies and processes:

- Planning and execution of talent and career development activities,

- Fulfillment of obligations arising from the employment contract and/or legislation for Company employees,

- Planning and execution of benefits and perks for employees,

- Planning and execution of internal orientation activities,

- Planning and execution of personnel exit procedures,

- Wage management,

- Planning of human resources processes,

- Managing personnel recruitment processes,

- Planning and execution of appointment, promotion and termination processes for the company,

- Planning and execution of employee performance evaluation processes,

- Monitoring and/or supervision of employees' work activities,

- Planning and/or execution of in-house training activities,

- Planning and execution of employee satisfaction and/or engagement processes,

- Planning and execution of the processes of receiving and evaluating suggestions for the improvement of employees' work and/or production processes,

- Planning and/or execution of intern and/or student recruitment, placement and operation processes.

2.2.3. Carrying out the necessary work by the relevant business units for the realization of the commercial activities carried out by CarbonEmit and carrying out the related business processes:

- Event management,

- Planning and execution of business activities,

- Planning and execution of corporate communication activities,

- Planning and execution of supply chain management processes,

- Planning and execution of production and/or operation processes,

- Planning, auditing and execution of information security processes,

- Establishment and management of information technology infrastructure,

- Planning and execution of business partners' authorizations to access information,

- Follow-up of financial and/or accounting affairs,

- Planning and execution of corporate sustainability activities,

- Planning and execution of corporate governance activities,

- Planning and/or execution of business continuity activities,

- Planning and execution of logistics activities.

2.2.4. Planning and execution of the activities necessary to recommend and promote the products and services offered by CarbonEmit to the relevant persons by customizing them according to their tastes, usage habits and needs:

- Identifying and/or evaluating the people to be subject to marketing activities in line with consumer behavior criteria

- Design and/or execution of customized marketing and/or promotional activities

- Design and/or execution of advertising and/or promotion and/or marketing activities in digital and/or other media

- Design and/or execution of activities to be developed on customer acquisition and/or value creation in existing customers in digital and/or other channels

- Planning and/or execution of data analytics activities for marketing purposes

- Planning and execution of marketing processes of products and/or services

- Planning and/or execution of processes to build and/or increase loyalty to the products and/or services offered by the Company

2.2.5. Planning and execution of CarbonEmit's commercial and/or business strategies: Managing relationships with business partners.

2.2.6. Ensuring the legal, technical and commercial business security of CarbonEmit and related persons in business relationship with CarbonEmit:

- Follow-up of legal affairs

- Planning and execution of the necessary operational activities to ensure that the Company's activities are carried out in accordance with Company procedures and/or relevant legislation

- Providing information to authorized institutions due to legislation

- Creation and follow-up of visitor records

- Planning and execution of emergency management processes

- Realization of company and partnership law transactions

- Planning and execution of company audit activities

- Planning and/or execution of occupational health and/or safety processes

- Realization of risk management of credit processes

- Ensuring the security of company premises and/or facilities

- Ensuring the security of company operations

- Planning and/or execution of the Company's financial risk processes

- Ensuring the security of company fixtures and/or resources

2.3. Categories of Personal Data

Personal data categorized as follows are processed by CarbonEmit in accordance with the personal data processing conditions set out in the Law and the relevant legislation:

- Identity data: Information contained in documents such as driver's license, identity card, residence card, passport, lawyer ID, marriage certificate.

- Contact information: Information used to contact the person (e.g. e-mail address, telephone number, mobile phone number, address).

- Location information: Information used to determine the location of the data subject (e.g. location information obtained while driving).

- Customer data: Information about customers who benefit from our products and services (e.g. customer number, occupation information, etc.).

- Customer transaction information: Information regarding any transaction performed by customers who use our products and services.

- Physical location security information: Personal data related to records and documents such as camera recordings, fingerprint records taken at the entrance to the physical space, during the stay in the physical space.

- Transaction security information: Personal data processed to ensure technical, administrative, legal and commercial security while CarbonEmit conducts its business activities.

- Financial information: Personal data processed in relation to information, documents and records showing all kinds of financial results created according to the type of legal relationship CarbonEmit has established with the personal data subject.

- Employee candidate information: Personal data processed in relation to individuals who have applied to become an employee of CarbonEmit or who have been evaluated as an employee candidate in line with human resources needs in accordance with commercial customs and honesty rules or who are in a working relationship with CarbonEmit.

- Legal process and compliance information: Personal data processed within the scope of determination and follow-up of CarbonEmit's legal receivables and rights and performance of its debts and compliance with its legal obligations and company policies.

- Audit and inspection information: Personal data processed within the scope of CarbonEmit's legal obligations and compliance with company policies.

- Special categories of data: Personal data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance, membership to associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data.

- Marketing information: Personal data processed for the marketing of the products and services offered by CarbonEmit by customizing them in line with the usage habits, tastes and needs of the personal data owner, and the reports and evaluations created as a result of this processing.

- Request/complaint management information: Personal data relating to the receipt and evaluation of any requests or complaints addressed to CarbonEmit.

- Reputation management information: Information collected for the purpose of protecting CarbonEmit's business reputation, and information about the evaluation reports and actions taken.

- Incident management information: Personal data processed in order to take necessary legal, technical and administrative measures to protect CarbonEmit's commercial rights and interests and the rights and interests of its customers.

3. Principles and Conditions Regarding the Processing of Personal Data

Regarding the processing of personal data in accordance with Article 4 of the Law, CarbonEmit carries out personal data processing activities in accordance with the law and honesty rules, accurately and, where necessary, up-to-date, for specific, clear and legitimate purposes, in connection with the purpose, in a limited and measured manner. CarbonEmit retains personal data for the period stipulated by law or required by the purpose of personal data processing.

3.1. Principles Regarding the Processing of Personal Data

CarbonEmit informs data subjects in accordance with Article 10 of the PDP Law and processes personal data based on the following principles by requesting consent from data subjects in cases where consent is required.

3.1.1. Processing of Data in Compliance with the Law and Good Faith

CarbonEmit acts in accordance with the principles set forth by legal regulations and the general rule of trust and good faith in the processing of personal data. In accordance with the principle of good faith, CarbonEmit takes into account the interests and reasonable expectations of the data subjects while trying to achieve its data processing objectives.

3.1.2. Ensuring that Personal Data is Accurate and Up-to-Date When Necessary

Keeping personal data accurate and up-to-date is necessary for CarbonEmit to protect the fundamental rights and freedoms of the data subject. CarbonEmit has an active duty of care to ensure that personal data is accurate and, where necessary, up-to-date. For this reason, all communication channels are open for CarbonEmit to keep the data subject's information accurate and up-to-date.

3.1.3. Processing of Data for Specific, Explicit and Legitimate Purposes

CarbonEmit clearly and precisely determines the purpose of processing personal data that is legitimate and lawful. CarbonEmit processes as much personal data as is necessary for and relevant to the commercial activity it carries out.

3.1.4. Data being relevant, limited and proportionate to the purpose for which they are processed

CarbonEmit processes personal data for purposes related to its field of activity and necessary for the conduct of its business. For this reason, it processes personal data in a manner that is conducive to the realization of the specified purposes and avoids the processing of personal data that is not related to the realization of the purpose or is not needed.

3.1.5. Retention of Data for the Period Stipulated in the Relevant Legislation or Required for the Purpose for which they are Processed

CarbonEmit retains personal data only for the period specified in the relevant legislation or for the period required for the purpose for which they are processed. In this context; first of all, it determines whether a period of time is stipulated for the storage of personal data in the relevant legislation, if a period of time is specified, it acts in accordance with this period, and if no period of time is specified, it keeps personal data for the period required for the purpose for which they are processed. Personal data are deleted, destroyed or anonymized by CarbonEmit after the purpose of personal data processing ceases to exist or the period stipulated in the legislation expires.

3.2. Conditions for Processing Personal Data

Your personal data is processed by CarbonEmit in the presence of at least one of the personal data processing conditions set out in Article 5 of the Law.

3.2.1. Explicit consent of the personal data owner

One of the conditions for processing personal data is the explicit consent of the owner. The explicit consent of the personal data owner must be related to a specific subject, based on information and free will. In order for personal data to be processed based on the explicit consent of the personal data owner, explicit consent is obtained from customers, potential customers and visitors through relevant methods.

3.2.2. Personal data processing activities are clearly stipulated by law

The personal data of the data subject may be processed in accordance with the law without the explicit consent of the data subject, if expressly provided for in the law.

3.2.3. Failure to obtain the explicit consent of the person due to actual impossibility

The personal data of the data subject may be processed if it is mandatory to process the personal data of the person who is unable to disclose his/her consent due to actual impossibility or whose consent will not be recognized as valid, in order to protect his/her or another person's life or physical integrity.

3.2.4. The personal data is directly related to the establishment or performance of a contract

Provided that it is directly related to the conclusion or performance of a contract processing of personal data if it is necessary to process personal data belonging to the parties is possible.

3.2.5. CarbonEmit's fulfillment of its legal obligations

Personal data of the data subject may be processed if such processing is necessary for CarbonEmit to fulfill its legal obligations as a data controller.

3.2.6. Publicizing the personal data of the data subject

If the data subject has made his/her personal data public by himself/herself, the relevant personal data may be processed.

3.2.7. Data processing is mandatory for the establishment or protection of a right

Personal data of the data subject may be processed if data processing is necessary for the establishment, exercise or protection of a right.

3.2.8. Data processing is mandatory for CarbonEmit's legitimate interest

Provided that it does not harm the fundamental rights and freedoms of the personal data owner, the personal data of the data owner may be processed if data processing is mandatory for the legitimate interests of CarbonEmit.

3.3. Processing of Special Categories of Personal Data

CarbonEmit complies sensitively with the regulations stipulated in the PDP Law in the processing of personal data determined as 'special categories' by the PDP Law. CarbonEmit processes personal data of special nature in the following cases, provided that adequate measures to be determined by the PDP Board are taken:

- If the personal data owner has explicit consent,

- If the personal data subject does not have explicit consent,

- Sensitive personal data other than the health and sexual life of the personal data owner, in cases stipulated by law,

- Sensitive personal data relating to the health and sexual life of the personal data subject are processed only for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services and financing, by persons or authorized institutions and organizations under the obligation of confidentiality.

4. Transfer of Personal Data

CarbonEmit may transfer the personal data and sensitive personal data of the data subject to domestic or foreign third parties by taking the necessary security measures in line with the lawful personal data processing purposes. In this respect, CarbonEmit acts in accordance with the regulations stipulated in Article 8 of the PDP Law.

4.1. Transfer of personal data to domestic third parties

Your personal data may be transferred by CarbonEmit in the presence of at least one of the data processing conditions specified in Articles 5 and 6 of the Law and explained under Title 3 of this Policy and provided that the basic principles regarding the data processing conditions are complied with.

4.2. Transfer of personal data to third parties abroad

CarbonEmit may transfer the personal data and sensitive personal data of the personal data owner to third parties abroad in the presence of at least one of the data processing conditions described under Title 3 of this Policy and by taking the necessary security measures. CarbonEmit transfers personal data to foreign countries that are declared to have adequate protection by the PDP Board ('Foreign Country with Adequate Protection') or, in the absence of adequate protection, to foreign countries where the data controllers in Turkey and the relevant foreign country undertake in writing to provide adequate protection and where the PDP Board has granted permission ('Foreign Country with Data Controller Undertaking Adequate Protection'). In this respect, CarbonEmit acts in accordance with the regulations stipulated in Article 9 of the PDP Law.

4.3. Third parties to whom personal data are transferred and the purposes of transfer

Within the scope of the general principles of the Law and the data processing conditions in Articles 8 and 9, CarbonEmit may transfer data to the parties categorized below:

- Business Partners: Parties with whom CarbonEmit has established a business partnership while conducting its business activities

- Sharing of personal data limited to the purpose of ensuring the fulfillment of the purposes for which the business partnership was established

- Shareholders: Shareholders authorized to design CarbonEmit's strategy and oversight of its business operations in accordance with the relevant regulatory provisions

- Sharing of personal data limited to the design of strategies for CarbonEmit's business activities and for audit purposes

- Company Authorized Persons: Board members and other authorized persons

- Sharing of personal data limited to designing strategies for CarbonEmit's business activities, ensuring their management at the highest level and for audit purposes

- Legally Authorized Public Institutions and Organizations: Public institutions and organizations legally authorized to receive information and documents from CarbonEmit

- Sharing personal data limited to the purpose of requesting information by the relevant public institutions and organizations

- Legally Authorized Private Law Persons: Private legal persons legally authorized to receive information and documents from CarbonEmit

- Sharing data limited to the purpose requested by the relevant private law persons within their legal authority

5. Rights of the Data Subject and Exercise of Related Rights

5.1. Rights of the personal data subject:

- To find out whether his/her personal data is being processed,

- Request information if their personal data has been processed,

- To learn the purpose of processing personal data and whether they are used for their intended purpose,

- To know the third parties to whom personal data is transferred domestically or abroad,

- To request correction of personal data in case of incomplete or incorrect processing and to request notification of the transaction made within this scope to third parties to whom personal data is transferred,

- Although it has been processed in accordance with the provisions of the PDP Law and other relevant laws, to request the deletion or destruction of personal data in the event that the reasons requiring its processing disappear and to request notification of the transaction made within this scope to third parties to whom personal data is transferred,

- In the event that the processed data is analyzed exclusively through automated systems and a result occurs to the detriment of the person himself/herself, to object to this result,

- In case of damage due to unlawful processing of personal data, to demand compensation for the damage.

- If personal data is not obtained directly from the data subject, CarbonEmit carries out activities to inform data subjects (1) within a reasonable period of time from the acquisition of personal data, (2) if personal data will be used for communication with the data subject, during the first communication, (3) if personal data will be transferred, at the latest during the first transfer of personal data.

5.2. Cases where the personal data subject cannot assert his/her rights:

Pursuant to Article 28 of the PDP Law, personal data subjects cannot assert their rights listed in 5.1 in these matters, as the following cases are excluded from the scope of the PDP Law:

- Processing of personal data by natural persons within the scope of activities related to themselves or their family members living in the same residence, provided that personal data is not disclosed to third parties and data security obligations are complied with,

- Processing of personal data for purposes such as research, planning and statistics by anonymizing them with official statistics,

- Processing of personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that such processing does not violate national defense, national security, public security, public order, economic security, privacy or personal rights or constitute a crime,

- Processing of personal data within the scope of preventive, protective and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public security, public order or economic security,

- Processing of personal data by judicial authorities or enforcement authorities in relation to investigation, prosecution, trial or execution procedures.

- Pursuant to Article 28.2 of the PDP Law; in the cases listed below, personal data owners cannot assert their other rights listed in 5.1, except for the right to claim compensation for the damage:

- Processing of personal data is necessary for the prevention of crime or criminal investigation,

- Processing of personal data made public by the personal data subject himself/herself,

- Personal data processing is necessary for the execution of supervisory or regulatory duties and disciplinary investigation or prosecution by the authorized and authorized public institutions and organizations and professional organizations in the nature of public institutions based on the authority granted by law,

- Processing of personal data is necessary for the protection of the economic and financial interests of the State in relation to budgetary, tax and fiscal matters.

6. Deletion, Destruction, Anonymization of Personal Data

As regulated in Article 138 of the Turkish Penal Code and Article 7 of the PDP Law, personal data shall be deleted, destroyed or anonymized upon the decision of CarbonEmit or upon the request of the personal data owner, in the event that the reasons requiring its processing disappear, although it has been processed in accordance with the provisions of the relevant law, as regulated in Article 138 of the Turkish Penal Code and Article 7 of the PDP Law. In this context, CarbonEmit has taken the necessary technical and administrative measures within the Company to fulfill its relevant obligation; has developed the necessary operating mechanisms in this regard; and trains, assigns and raises awareness of the relevant business units to act in accordance with these obligations.