TR
Policy on the processing of sensitive personal data

This Policy on the Processing of Sensitive Personal Data (“Policy”) sets forth the principles regarding the processing of sensitive personal data by Aş Han Yemek Gıda ve Turizm Sanayi Ticaret A.Ş., TRZ Gıda Turizm Yatırım A.Ş., and Çiftçi Ziraat Sanayi ve Ticaret A.Ş (‘’AŞ HAN Grup veya Grup şirketler’’) to establish the principles governing the processing of special category personal data and to set forth the technical and administrative measures necessary to ensure the lawful processing, protection, and security of such data.

This policy includes all special category personal data processing activities carried out by the Group Companies and is implemented in accordance with the provisions of relevant legislation.

Definitions

The terms used in this Policy have the following meanings:

Personal Data: Any information relating to an identified or identifiable natural person;

Sensitive Personal Data: Data listed in Article 6 of the Personal Data Protection Law No. 6698, including information regarding a person’s race, ethnic origin, political opinions, philosophical beliefs, religion, denomination, or other beliefs, attire and clothing, membership in associations, foundations, or trade unions, health information, data regarding sexual life, information related to criminal convictions and security measures, as well as biometric and genetic data,

Processing of Special Category Personal Data: Any operation performed on special category personal data—including the collection, recording, storage, retention, alteration, updating, reorganization, disclosure, transfer, acquisition, making available, classification, or restriction of use—whether carried out wholly or partially by automated means or by non-automated means as part of a data filing system,

Data Controller: A natural or legal person who determines the purposes and methods of processing personal data and is responsible for the establishment and management of the data recording system,

Data Processor: A natural or legal person who processes personal data on behalf of the data controller within the scope of the authority granted by the data controller,

Data Subject: A natural person whose personal data is being processed,

Data Record System: A record system in which personal data is processed by structuring them according to specific criteria,

Board: The Personal Data Protection Board,

Authority: The Personal Data Protection Authority,

Law (PDPL): The Personal Data Protection Law No. 6698,

Decision on Special Category Personal Data: Refers to the decisions published by the Personal Data Protection Board regarding the technical and administrative measures to be taken in the processing of special category personal data, as well as any amendments thereto.

Data Practices Regarding Employees

For employees involved in the processing of special category personal data:

  • Regular training is provided for employees about the Law, its associated regulations, and special category personal data security.

  • Confidentiality rules are enforced, and confidentiality agreements are signed with employees.

  • The scope and duration of access permissions for users authorized to access data are clearly defined.

  • Authorization reviews are conducted periodically.

  • The access permissions of employees who change roles or leave the company are immediately revoked, and in such cases, the equipment assigned to them by the Data Controller is returned.

Technical and Administrative Security Measures

Our Group Companies implement risk-based technical and administrative security measures to ensure the confidentiality, integrity, and availability of special-category personal data.

Measures Taken in Electronic Environments

When processing or storing special-category personal data in electronic systems, the following security measures are implemented:

  • Data is encrypted using up-to-date cryptographic methods and stored securely.

  • Cryptographic keys are stored separately from encrypted data in secure environments.

  • All access and transaction activities related to the data are logged and monitored regularly.

  • Security patches for server, application, and network systems are applied regularly.

  • Vulnerability scans, penetration tests, and other security controls for information systems are conducted at specific intervals or outsourced to authorized organizations.

  • Role-based authorization is implemented in the used software, and user access rights are reviewed regularly.

  • Multi-factor authentication (MFA) is implemented for systems requiring remote access.

  • Regular backups, antivirus software, firewalls, and intrusion detection systems are used.

Measures Taken in Physical Environments

In areas where special-category personal data is physically stored, the following measures are implemented:

  • Physical security measures to prevent unauthorized access are implemented.

  • Appropriate protection systems are in place against risks such as fire, flooding, power outages, theft, and similar incidents.

  • Document archives and data storage areas are accessible only to authorized personnel.

  • Physical entries and exits are logged and monitored as necessary.

Data Transfer Security

To ensure data security when the transfer of special-category personal data is necessary, the following measures are implemented:

  • For data transfers conducted via email, the data is transmitted in encrypted form; whenever possible, the corporate email infrastructure or the Registered Electronic Mail (KEP) system is used.

  • For transfers conducted using portable memory devices, external hard drives, CDs, DVDs, or similar physical storage media, data is encrypted using strong cryptographic methods, and the encryption keys are stored separately from the transferred data in secure environments.

  • For data transfers between servers or information systems located in different locations, the confidentiality and integrity of the transfer are ensured by using secure communication protocols such as VPN, SFTP, TLS, or similar protocols.

  • For data transfers conducted via physical documents, administrative and physical security measures are taken to minimize the risks of document loss, theft, or unauthorized viewing. In this context, documents deemed necessary are marked according to their classification level and sent using secure delivery methods.

  • Only individuals with access rights within the scope of their duties and authority are assigned to data transfer processes; transfers are logged as necessary to ensure traceability.

Transfer of Special Category Personal Data

The processing and transfer of special category personal data is permitted in the following cases:

  • Where the data subject has given explicit consent,

  • Where expressly provided for by law,

  • Where it is necessary to protect the life or physical integrity of the individual—or of another person—in cases where the individual is unable to express consent due to practical impossibility or where their consent is not legally valid,

  • Where it relates to personal data that the data subject has made public and is consistent with their intention to make such data public,

  • Where it is necessary for the establishment, exercise, or protection of a right,

  • It is necessary for persons subject to a duty of confidentiality or by authorized institutions and organizations for the protection of public health, the provision of preventive medicine, medical diagnosis, treatment, and care services, as well as the planning, management, and financing of health services,

  • It is necessary for the fulfillment of legal obligations in the fields of employment, occupational health and safety, social security, social services, and social assistance.

  • For foundations, associations, and other non-profit organizations or entities established for political, philosophical, religious, or union-related purposes, provided that such processing is in accordance with the applicable legislation and their purposes, is limited to their areas of activity, and is not disclosed to third parties; and provided that it is directed toward their current or former members and affiliates, or individuals who are in regular contact with these organizations or entities.

Updating the Policy

This Policy is reviewed and updated as needed in light of changes in applicable legislation, decisions of the Personal Data Protection Board, judicial precedents, and changes in administrative practices. The updated policy takes effect as of the date it enters into force.