KVKK INFORMATION NOTICE
- Our Potential Product or Service Buyers,
- Persons/Representatives Receiving Products or Services,
- Employees of Our Suppliers,
- Authorized Representatives of Our Suppliers
Scope of the Information Notice
This Information Notice covers:- Purpose of Processing Personal Data
- Methods and Legal Grounds for Collecting Personal Data
- Categories of Data Subjects and Processed Personal Data
- Business Processes and Purposes for Using Personal Data
- Security Measures Taken for Personal Data
- Transfer of Personal Data
- Retention Periods and Destruction Methods of Personal Data
- Rights of the Data Subject
- It is explicitly prescribed by law
- It is directly related to the conclusion or performance of a contract
- It is necessary for our Company as the data controller to fulfill its legal obligation
- You have made your data public
- It is necessary for the establishment, exercise or protection of a right
- Provided not to harm your fundamental rights and freedoms, it is necessary for the legitimate interests of our Company, and where such grounds do not exist, based on your explicit consent
- Our Potential Product or Service Buyers,
- Persons/Representatives Receiving Products or Services,
- Employees of Our Suppliers,
- Authorized Representatives of Our Suppliers
Scope of the Information Notice
Rapitek processes, stores, and transfers only those personal data it considers necessary in addition to the mandatory information it must obtain due to the authorities of its Customers and their representatives, to provide the best service and product it aims to deliver, as permitted by legal regulations. Accordingly, personal data are processed for the provision of our products and services, for necessary operations in this context, for contacting you regarding our products and services with your explicit consent, for marketing activities, for customer acquisition efforts and for sharing offers related to our products and services, for carrying out the necessary reporting and investigations required within company activities, and similar purposes.Methods and Legal Grounds for Collecting Personal Data
Your personal data may be collected by all verbal, written or electronic means, through technical and other methods, for the purpose of fulfilling the obligations arising from the law in a complete and accurate manner and for carrying out commercial activities, as specified in this Information Notice, and may be processed by our company or by data processors assigned by our company. In accordance with Articles 5 and 6 of Law No. 6698, your Personal Data may be processed in cases where:Categories of Data Subjects and Processed Personal Data
a. Identity |
Potential Product or Service Buyer (Website Visitors) Persons/Representatives Receiving Products or Services (Registered Members) Supplier Employees Supplier Representatives |
Personal Data |
b. Contact |
Potential Product or Service Buyer (Website Visitors) Persons/Representatives Receiving Products or Services (Registered Members) Supplier Employees Supplier Representatives |
Personal Data |
c. Legal Transaction |
Persons/Representatives Receiving Products or Services (Registered Members) Supplier Employees Supplier Representatives |
|
d. Customer Transaction |
Persons/Representatives Receiving Products or Services (Registered Members) Supplier Employees Supplier Representatives |
Personal Data |
e. Transaction Security |
Persons/Representatives Receiving Products or Services (Registered Members) Supplier Employees Supplier Representatives |
Personal Data |
f. Finance |
Persons/Representatives Receiving Products or Services (Registered Members) Supplier Employees Supplier Representatives |
Personal Data |
g. Marketing |
Persons/Representatives Receiving Products or Services (Registered Members) Supplier Employees Supplier Representatives |
Personal Data |
h. Visual and Audio Records |
Persons/Representatives Receiving Products or Services (Registered Members) Supplier Employees Supplier Representatives |
Personal Data |
Business Processes and Purposes for Using Personal Data
POTENTIAL PRODUCT OR SERVICE BUYERS (WEBSITE VISITORS)
- Execution of Information Security Processes
- Management of Access Rights
- Follow-up and Execution of Legal Affairs
- Execution of Product/Service Sales Processes
- Execution of After-Sales Support Services
- Execution of Communication Activities
- Responding to Information Requests
- Execution of Marketing and Analysis Activities
- Execution of Product and Service Marketing Processes
- Execution of Customer Relationship Management and Satisfaction Processes
- Execution of Strategic Marketing Activities
- Execution of Storage and Archiving Activities
- Execution of Risk Management Processes
- Tracking of Requests and Complaints
- Ensuring the Operational Security of the Data Controller
- Execution of Product and Service Marketing Processes
PERSONS/REPRESENTATIVES RECEIVING PRODUCTS OR SERVICES (REGISTERED MEMBERS)
- Execution of Information Security Processes
- Management of Access Rights
- Execution of Activities in Compliance with Legislation
- Execution of Financial and Accounting Processes
- Follow-up and Execution of Legal Affairs
- Execution of Communication Activities
- Execution of Product/Service Procurement Processes
- Execution of Product/Service Sales Processes
- Execution of After-Sales Support Services
- Execution of Product, Service, Production and Operation Processes
- Management of Customer Relationship Processes
- Execution of Customer Satisfaction Activities
- Execution of Marketing and Analysis Activities
- Execution of Advertising, Campaign and Promotion Processes
- Execution of Risk Management Processes
- Execution of Storage and Archiving Activities
- Execution of Contract Processes
- Tracking of Requests and Complaints
- Execution of Product and Service Marketing Processes
- Ensuring the Security of Data Controller Operations
- Providing Information to Authorized Persons, Institutions, and Organizations
- Execution of Management Activities
SUPPLIER EMPLOYEES
- Execution of Finance, Accounting and Procurement Activities
- Management of Access Rights
- Execution of Information Security Processes
- Execution of Activities in Compliance with Legislation
- Execution of Storage and Archiving Activities
- Follow-up and Execution of Legal Affairs
- Execution/Inspection of Business Activities
- Execution of Product/Service Procurement Processes
- Execution of Product/Service Sales Processes
- Execution of After-Sales Support Services
- Execution of Product, Service, Production and Operation Processes
- Execution of Supply Chain Management Processes
- Execution of Communication Activities
- Execution of Contract Processes
- Execution of Information Security Processes
- Providing Information to Authorized Persons, Institutions, and Organizations
SUPPLIER REPRESENTATIVES
- Execution of Finance, Accounting and Procurement Activities
- Management of Access Rights
- Execution of Information Security Processes
- Execution of Activities in Compliance with Legislation
- Execution of Storage and Archiving Activities
- Follow-up and Execution of Legal Affairs
- Execution/Inspection of Business Activities
- Execution of Product/Service Procurement Processes
- Execution of Product/Service Sales Processes
- Execution of After-Sales Support Services
- Execution of Product, Service, Production and Operation Processes
- Execution of Supply Chain Management Processes
- Execution of Communication Activities
- Execution of Contract Processes
- Execution of Information Security Processes
- Providing Information to Authorized Persons, Institutions, and Organizations
Security Measures Taken for Personal Data
As Rapitek, we attach utmost importance to taking the measures determined within the framework of Law No. 6698, relevant legislation, and decisions of the Personal Data Protection Board during the processing of your personal data. Rapitek takes necessary administrative and technical measures to prevent unauthorized access to personal data, illegal processing, disclosure, alteration or destruction of personal data due to risks arising within or outside the company. The following measures are taken by Rapitek while processing personal data:- Authorization Matrix
- Authorization Control
- Access Logs
- User Account Management
- Network Security
- Application Security
- Penetration Testing
- Intrusion Detection and Prevention Systems
- Log Records
- Data Loss Prevention Software
- Backups
- Firewall
- Updated Anti-Virus Systems
- Deletion, Destruction or Anonymization
Transfer of Personal Data
Our company may transfer your personal data, collected for the above-mentioned data processing purposes, to relevant parties within the framework of the data processing conditions and purposes specified in Articles 8 and 9 of the KVKK, for the same purposes and due to legal obligations. Our company may share your personal data with domestic and foreign affiliates or partnerships that may be formed, initiatives; public institutions and organizations authorized by law to request such data; domestic or foreign institutions, suppliers, authorized dealers, distributors, and business partners with whom we cooperate, provided that sufficient confidentiality and security are ensured for the purpose of providing higher value-added products and services and improving our service quality. The nature of these transfers and the parties with whom data is shared may vary depending on the type and nature of the relationship between the data subject and Rapitek Bilişim Teknolojileri A.Ş., the purpose of the transfer, and the relevant legal basis. These parties generally include:- Business units within Rapitek for coordination, cooperation, and efficiency
- Research companies for purposes such as customer satisfaction
- Companies providing services for the execution of marketing activities
- Banks and payment institutions enabling the execution of financial transactions
- Natural persons or private law legal entities
- Domestic/foreign companies providing cloud technology services, law offices and legal support institutions
- Our business partners
- Authorized public institutions and organizations
- Our suppliers
Retention Periods and Destruction Methods of Personal Data
The retention principles for your personal data are as follows:- If a retention period is specified for the data in the relevant legislation relating to company activities, the data is kept for at least that period.
- If no period is specified in the relevant legislation, it is retained for a period determined in accordance with the purposes specified and in line with the principles of Law No. 6698.
Rights of the Data Subject
In accordance with Article 11 of Law No. 6698, data subjects whose data are processed may, at any time, exercise their rights listed below by applying to us:- To learn whether personal data is processed,
- If personal data is processed, to request information about this,
- To learn the purpose of processing personal data and whether they are used in accordance with this purpose,
- To know the third parties to whom personal data is transferred domestically or abroad,
- To request correction of personal data if it is incomplete or incorrectly processed,
- To request the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the Law,
- To request that transactions made pursuant to subparagraphs (d) and (e) of Article 11 be notified to third parties to whom personal data has been transferred,
- To object to the emergence of a result against oneself by analyzing the processed data exclusively through automated systems,
- To demand compensation for the damage arising from the unlawful processing of personal data
Kind regards,
RAPİTEK BİLİŞİM TEKNOLOJİLERİ A.Ş.