Skip to content

HDS Policies and Procedures

PERSONAL DATA PROTECTION AND PROCESSING POLICY

1. DEFINITIONS

KVKK / Law: Law No. 6698 on the Protection of Personal Data.

GDPR / Law: General Data Protection Regulation.

Data Processor: A natural or legal person who processes personal data on behalf of the data controller based on the authorization granted by the data controller.

Data Controller: The person who determines the purposes and means of processing personal data and manages the place where the data are systematically kept (data recording system).

Company: HDS Seyahat ve Otel İşletmeleri Anonim Şirketi.

Data Subject: Employees, customers, business partners, shareholders, authorized representatives, potential customers, job candidates, interns, visitors, suppliers, employees of institutions with which the Company cooperates, third parties, and all other natural persons whose personal data are processed by the Company and its affiliated subsidiaries, without limitation to those listed herein.

Explicit Consent: Consent relating to a specific matter, based on being informed and freely given.

Personal Data: Any information relating to an identified or identifiable natural person.

Special Categories of Personal Data: Data relating to a person's race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and clothing, membership of an association, foundation or trade union, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.

Processing of Personal Data: Any operation performed on personal data, such as obtaining, recording, storing, retaining, changing, rearranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of personal data, whether wholly or partly by automated means or by non-automated means provided that the operation forms part of a data recording system.

Anonymization of Personal Data: Rendering personal data incapable of being associated, by any means whatsoever, with an identified or identifiable natural person, even by matching the data with other data.

Deletion of Personal Data: Rendering personal data inaccessible and unusable again for the relevant users.

Destruction of Personal Data: The process of rendering personal data inaccessible, irretrievable and unusable by anyone, by any means.

KVK Board / Board: Personal Data Protection Board.

KVK Authority / Authority: Personal Data Protection Authority.

2. PURPOSE

The primary purpose of this Personal Data Protection and Processing Policy (the “Policy”) is to explain the systems adopted by the Company for the lawful processing and protection of personal data, to determine the procedures and principles to be followed by persons processing data due to their relationship with the Company, and to ensure transparency towards data subjects.

The Company conducts its activities in compliance with the Constitution of the Republic of Türkiye, the provisions of international conventions to which Türkiye is a party, the Law on the Protection of Personal Data (“KVKK” and/or the “Law”) and relevant legislation concerning the protection and confidentiality of personal data. The Company approaches the protection and privacy of personal data with due care and places fundamental human rights, such as privacy of private life and freedom of thought, at the center of all its activities.

3. SCOPE AND APPLICATION

This Policy has been prepared taking into consideration applicable regulations and international standards. The Company shall apply this Policy as a priority in all data processing activities, including processing, transferring and changing data.

The Company also has different policies addressing the protection of personal data and information security in relation to specific business activities and processes. Unless they contain additional requirements or require a higher standard for the protection of personal data, this Policy does not invalidate the data protection requirements in those other policies. This Policy shall be applied together with such other policies and procedures to the extent appropriate. Unless expressly stated otherwise, all matters regulated under KVKK shall also apply under the GDPR.

In the event of a conflict between the applicable legislation on the protection and processing of personal data and this Policy, the current provisions of applicable legislation shall prevail.

4. PROCESSING OF PERSONAL DATA

a. Principles Applied in the Processing of Personal Data

The Company's policies and procedures are implemented in parallel with the processing principles set out in KVKK and relevant legislation. The Company recognizes that these principles are vital to the exercise of data subjects' rights and their control over their data and therefore places them at the center of all processing activities. Our principles are as follows:

·        Personal data are processed lawfully, fairly and transparently.

·        Personal data are processed only for specified, explicit and legitimate purposes.

·        Personal data are relevant, limited and proportionate to the purposes for which they are processed.

·        Personal data are accurate and, where necessary, kept up to date.

·        Personal data are retained only for the period prescribed by applicable legislation or necessary for the purposes for which they are processed.

·        Personal data are processed in a manner ensuring appropriate security.

·        The Company demonstrates compliance with the other principles under KVKK.

The Company relies on the legal grounds for processing provided under KVKK in its data processing activities and takes into account the reasonable expectations of data subjects in accordance with the principle of fairness. The Company uses clear and understandable language in its communications with data subjects and remains readily accessible.

Before processing data, the Company determines the purpose of the processing activity. Data are processed only for additional purposes compatible with the original processing purpose. Compatibility for each additional purpose is determined according to internationally accepted criteria. The Company informs data subjects about processing purposes in accordance with the transparency principle.

The Company processes only the amount of data necessary for the processing purpose. Data are obtained by methods most appropriate for data privacy and security. In its processing activities, the Company avoids disproportionate interference with the rights, interests and freedoms of data subjects.

The Company ensures that data remain up to date in all processing activities. Incomplete, inaccurate or incorrect data are deleted or corrected as soon as possible, and the Company checks data currency at regular intervals.

When the purposes of processing cease to exist, data are deleted, destroyed or anonymized as soon as possible.

The Company applies data security as a fundamental principle and takes the necessary administrative and technical measures by following best practices.

The Company observes the principle of accountability in all processing activities.

b. Purposes of the Company's Processing of Personal Data

·        Conducting recruitment and placement processes for employees, interns and students

·        Conducting job candidate application processes

·        Conducting assignment processes

·        Planning human resources processes

·        Conducting retention and archiving activities

·        Conducting / supervising business activities

·        Conducting communication activities

·        Fulfilling employment contract and statutory obligations for employees

·        Conducting contractual processes

·        Implementing remuneration policy

·        Conducting occupational health and safety activities

·        Providing information to authorized persons, institutions and organizations

·        Conducting employee fringe benefit and benefit processes

·        Conducting employee satisfaction and engagement processes

·        Conducting activities in compliance with legislation

·        Conducting training activities

·        Conducting talent / career development activities

·        Organization and event management

·        Ensuring physical premises security

·        Conducting information security processes

·        Managing access authorizations

·        Providing after-sales support services for goods / services

·        Conducting goods / services sales processes

·        Conducting customer relationship management processes

·        Conducting goods / services production and operational processes

·        Conducting activities aimed at customer satisfaction

·        Conducting goods / services procurement processes

·        Ensuring the security of data controller operations

·        Conducting supply chain management processes

·        Conducting finance and accounting activities

·        Tracking requests / complaints

·        Conducting management activities

·        Conducting audit / ethics activities

c. Legal Grounds for the Company's Processing of Personal Data

When processing personal data, the Company relies on one of the legal grounds for processing set out in Article 5 of KVKK. The conditions for processing personal data, i.e. the circumstances constituting lawfulness, are exhaustively listed in the Law and cannot be expanded. The Company relies on the following legal grounds:

·        The existence of the explicit consent of the data subject

·        Processing being necessary for the establishment or performance of a contract, directly related to the parties to that contract

·        Processing being mandatory for the data controller to fulfill its legal obligation

·        Processing being expressly prescribed by law

·        Processing being mandatory due to workplace occupational medicine / preventive occupational health services

·        Processing being necessary for the establishment, exercise or protection of a right

·        Processing being necessary for the legitimate interests of the data controller, provided that the fundamental rights and freedoms of the data subject are not harmed

Where another legal ground exists, the Company does not rely on explicit consent as the legal ground.

d. Legal Grounds for Processing Special Categories of Personal Data

Special categories of personal data are data which, if disclosed, may expose a person to discrimination, such as data concerning religion, race, beliefs, health and sexual life. Special categories of personal data may not be processed without one of the limited legal grounds specified in Article 6 of KVKK.

When processing special categories of personal data, the Company relies on the following legal grounds:

·        The explicit consent of the data subject

·        Explicitly prescribed by law

·        Being necessary to protect the life or physical integrity of a person who is unable to express consent due to actual impossibility or whose consent is not legally valid, or of another person

·        Relating to personal data made public by the data subject and being consistent with the data subject's intention to make them public

·        Being necessary for the establishment, exercise or protection of a right

·        Being necessary for persons under a duty of confidentiality or authorized institutions and organizations for purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning, managing and financing health services

·        Being necessary to fulfill legal obligations in the fields of employment, occupational health and safety, social security, social services and social assistance

·        Being processed by foundations, associations and other non-profit organizations established for political, philosophical, religious or trade-union purposes, within the scope of their applicable legislation and purposes, limited to their fields of activity and not disclosed to third parties, in relation to their current or former members and persons who have regular contact with them

Where another legal ground exists, the Company does not rely on explicit consent as the legal ground.

5. INFORMATION OBLIGATION

In accordance with KVKK and the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Information Obligation, the Company is obliged to inform data subjects. If personal data are obtained directly from the data subject, the Company or persons authorized by it shall inform the data subject at the time the data are obtained. If personal data are not obtained from the data subject, the information obligation shall be fulfilled within a reasonable period, at the time of the first communication if the data will be used for communication with the data subject, and no later than the time of the first transfer if the data will be transferred.

At a minimum, the Company informs data subjects about the Company's legal entity and address information, the purposes for which personal data will be processed, to whom and for what purposes the processed data may be transferred, the method and legal ground for collecting personal data, and the rights listed in Article 11 of KVKK.

When the purpose of personal data processing changes, the information obligation shall be fulfilled separately for the new purpose before the processing activity.

6. DATA SECURITY

As the data controller, the Company is obliged to prevent unlawful processing of and access to personal data and to ensure their preservation. Accordingly, the Company has taken all technical and administrative measures relating to data security, including additional measures required for the protection of special categories of personal data. The measures are listed below.

Technical Measures

·        Authorization and Access Controls

·        Network Security and Firewall Use

·        Data Encryption

·        Antivirus and Antimalware Software

·        Logging and Monitoring

·        Backup

·        Penetration Testing

·        Data Masking

·        Malware Prevention

·        E-mail Security and Use of a Mail Gateway

·        Data Masking

·        Mobile Device Security (MDM)

·        Two-Factor Authentication (2FA/MFA)

Administrative Measures

·        Personnel Training and Awareness

·        Confidentiality and Undertaking Documents

·        Data Inventory and Recording System

·        Internal Policies and Procedures

·        Data Breach Management Process

·        Data Retention and Destruction Policy

·        Audit and Internal Control

·        Service Provider Agreements

·        Maintaining and Monitoring Log Records

·        Access Authorization and Control

7. TRANSFER OF PERSONAL DATA

a. Domestic Transfer

The Company transfers personal data to third parties based on the data processing conditions set out in Articles 5 and 6 of KVKK. The Company takes all necessary security measures in its data transfer activities. The recipient groups to which the Company transfers data are:

·        Suppliers

·        Authorized Institutions and Organizations

·        Customers

·        Organizations of which the Company is a member

b. International Transfer

Pursuant to Article 9 of KVKK, the Company transfers data abroad by satisfying one of the following conditions:

·        If one of the conditions in Articles 5 or 6 of KVKK exists and an adequacy decision exists concerning the country, sectors within the country or international organization to which the transfer will be made, the Company transfers personal data abroad.

·        If there is no adequacy decision, the Company transfers personal data abroad if one of the appropriate safeguards below is provided by the parties, provided that the data subject is able to exercise their rights and seek effective legal remedies in the country to which the transfer is made.

·        Where an agreement that is not in the nature of an international treaty exists between public institutions and organizations abroad or international organizations and public institutions and organizations in Türkiye or public professional organizations, and the Board permits the transfer.

·        Binding corporate rules approved by the Board containing provisions on personal data protection that companies within a group of undertakings engaged in common economic activity are required to comply with.

·        Standard contractual clauses announced by the Board containing matters such as data categories, purposes of transfer, recipients and recipient groups, technical and administrative measures to be taken by the data recipient, and additional measures for special categories of personal data.

·        A written undertaking containing provisions ensuring adequate protection, where the Board permits the transfer.

If there is no adequacy decision and none of the other appropriate safeguards under Article 9 of KVKK can be provided, the Company transfers personal data abroad, on an occasional basis, only where one of the following circumstances exists:

·        The data subject, having been informed about possible risks, gives explicit consent to the transfer.

·        The transfer is necessary for the performance of a contract between the data subject and the data controller or for the implementation of pre-contractual measures taken at the request of the data subject.

·        The transfer is necessary for the conclusion or performance of a contract to be concluded between the data controller and another natural or legal person for the benefit of the data subject.

·        The transfer is necessary for an important public interest.

·        The transfer of personal data is necessary for the establishment, exercise or protection of a right.

·        The transfer is necessary to protect the life or physical integrity of a person who is unable to express consent due to actual impossibility or whose consent is not legally valid, or of another person.

·        The transfer is made from a register which is open to the public or to persons with a legitimate interest, provided that the conditions required under applicable legislation for access to the register are met and the person with a legitimate interest requests the transfer.

8. PERSONAL DATA INVENTORY

The Company has created a data inventory containing the details required by the Law concerning personal data processed under KVKK. The Company's data inventory includes:

·        Business processes in which personal data are used

·        Category of personal data

·        Personal data processed

·        Special categories of personal data processed

·        Purpose and legal ground of the processing activity

·        Domestic recipients of personal data

·        Whether personal data are transferred abroad

·        Retention periods of personal data

The Personal Data Inventory is updated when there is a change in the Company's processing activities. The Company reports the information contained in the Personal Data Inventory and any updates, if applicable, to the Data Controllers Registry. The information provided by the Company to the data subject under the information obligation referred to in Article 5 of this Policy is consistent with the information disclosed in the Registry.

9. ROLES AND RESPONSIBILITIES

The Quality Department is responsible for notifying relevant persons whose data are processed, such as customers, subcontractors and suppliers, of this Policy.

The Human Resources, Information Technology and Quality Departments are responsible for updating this Policy. The Information Technology Department makes the necessary improvements by taking into account the needs of the Company's information technology systems. The relevant departments are responsible for implementing the Policy.

The relevant departments are authorized to approve updates to this Policy.

The relevant departments are responsible for informing parties processing data on behalf of the Company, such as employees and suppliers, about this Policy and for ensuring through regular controls that such data processors implement the Policy.

The relevant department is responsible for applying sanctions in cases of violations arising from non-compliance with this Policy.

10. DELETION, DESTRUCTION AND ANONYMIZATION OF PERSONAL DATA

·        In accordance with Article 7 of KVKK and other relevant legislation, if the grounds for processing personal data cease to exist, personal data shall be deleted, destroyed or anonymized upon the Company's decision, periodic review and/or the request of the data subject.

·        The Company shall not retain personal data longer than necessary in connection with the reason for obtaining the personal data. When the grounds for processing cease to exist, the Company deletes, destroys or anonymizes the personal data during the first periodic destruction process following the date on which the obligation to do so arises.

·        The Company has prepared a Personal Data Retention and Destruction Policy to determine the procedures and principles in this regard. This Retention and Destruction Policy has been prepared in accordance with the Personal Data Inventory specified in Article 8 of this Policy.

·        In deleting, destroying or anonymizing personal data, the Company acts in accordance with the principles set out in Section 4/a of this Policy, the technical and administrative measures set out in Article 6, the Retention and Destruction Policy, applicable legislation and Board decisions.

·        Personal data shall be destroyed securely and by the most appropriate method in accordance with KVKK, applicable legislation and the Company's Retention and Destruction Policy. Upon the request of the data subject, the Company selects the appropriate method and explains the reason for its selection.

11. PERSONAL DATA PROCESSING ACTIVITIES CARRIED OUT AT THE COMPANY'S SERVICE PREMISES

The Company carries out personal data processing activities at its service premises in order to ensure security in accordance with KVKK and other applicable legislation. For security purposes, security camera monitoring is conducted in corridors and entrances/exits and in stores at the Company's premises. The system used for guest entry has been determined in accordance with the Company's relevant policies and procedures.

Access to records concerning security measures recorded and stored in digital environments is provided to departments subject to confidentiality obligations, the Company's management team and managers directly reporting to management.

12. RIGHTS OF THE DATA SUBJECT AND EXERCISE OF RIGHTS

Natural persons whose personal data are processed by the Company may exercise the following rights by applying to the Company at Time Plaza 2, Doğuyaka Mah. Termessos Bulvarı No:29/101-104 Muratpaşa/Antalya/Türkiye or by e-mail at kvkk@hds-turkiye.com in relation to the processing of their personal data:

a. Rights of the Data Subject

·        Learn whether personal data are being processed

·        If personal data have been processed, request information about the nature of the processed data and learn to whom they have been disclosed

·        Learn the purpose of processing personal data and whether they are used in accordance with that purpose

·        Know the third parties to whom personal data are transferred domestically or abroad and request that the relevant action be notified to those third parties

·        Request correction of personal data if they are incomplete or incorrectly processed and request that this correction be notified to third parties

·        Request deletion or destruction of personal data when the reasons requiring their processing cease to exist, even though they have been processed in accordance with applicable law

·        Object to the emergence of a result against the person as a result of the processing of data

·        Request compensation for damages if the person suffers damage due to unlawful processing of personal data

b. Exercise of Rights

Applications and requests concerning personal data may be submitted through the Data Subject Application Form by:

1. Sending it with a wet signature and a copy of an identity document to Time Plaza 2, Doğuyaka Mah. Termessos Bulvarı No:29/101-104 Muratpaşa/Antalya/Türkiye.

2. Signing it with a secure electronic signature or mobile signature and sending it to kvkk@hds-turkiye.com.

3. Signing it with a secure electronic signature or mobile signature and sending it via Registered Electronic Mail (KEP) to the Company's KEP address: hds@hs01.kep.tr.

4. Applying in person with a valid identity document.

Under the legal requirements concerning the procedures and principles for applications to the data controller, applicants must state their first and last name, signature if the application is made in writing, Turkish Republic identification number if they are a Turkish citizen, nationality and passport (or identity) number if they are a foreign national, address of residence or business address for notification purposes, e-mail address and fax number, if any, for notification, and the subject of the request. Documents verifying identity and information and documents relating to the subject of the request must also be attached.

For the process to be handled as effectively as possible, the right the applicant wishes to exercise and the details of the requested action must be stated clearly and understandably.

The subject of the request must concern the applicant. If an application is made on behalf of another person, the applicant must have specifically documented authority (power of attorney) to request the relevant action. Unauthorized applications shall not be considered.

c. Evaluation of the Application

·        Applications are evaluated and a response is provided as soon as possible and no later than 30 days from the date the application reaches the Company.

·        Additional information and documents may be requested where necessary during the evaluation; where permitted by applicable legislation, a fee may be charged for fulfilling the request.

·        The Company takes all necessary administrative and technical measures to conclude applications made by data subjects effectively, lawfully and in accordance with the principle of good faith.

d. Rejection of the Application

An application shall be rejected where:

·        The application is not made in accordance with the procedure stated above

·        The application contains a request contrary to applicable legislation

·        The application is not based on a justified reason or constitutes an abuse of a right

·        The personal data concerned are processed for purposes such as research, planning and statistics by anonymization as part of official statistics

·        The personal data have been made public by the data subject

·        One of the other circumstances falling within the scope of Article 28 of KVKK exists

If an application is rejected, the Company shall notify the data subject of the rejection and explain the reason.

e. Right to Complain

If an application made to the Company is rejected, the response given by the Company is found insufficient, or the Company does not respond within 30 days, the data subject has the right to lodge a complaint with the Board. The data subject may exercise the right to complain within 30 days from the date on which they learn of the Company's response and, in any event, within 60 days from the date of the application.

13. PUBLICATION AND EFFECTIVE DATE OF THE POLICY

This Policy enters into force on 23/05/2025.

The current version of this Policy is published at HDS Policy and Procedures: https://hdsseyahat365.sharepoint.com/:f:/s/hdsturkiye/EvIrRjB7k_VEnvQi-vczjiQBAt0F0gYHuUl0m1iurpY3KA?e=O7pQLF

14. UPDATING THE POLICY

This Policy shall be updated when a need for revision arises. The Company reviews the need for revisions once a year.

Old versions of this Policy that have been repealed shall be retained by the Company for 10 years. Policies whose retention period has expired shall be destroyed by the Company upon preparation of a record.