1. Purpose
This Personal Data and Information Security Policy defines the fundamental principles and procedures required to protect corporate information and personal data processed by Grindballs Bilya Çelik Sanayi Ticaret Anonim Şirketi (“GRINDBALLS”).
2. Scope
The Policy applies to all GRINDBALLS employees, suppliers and parties with access to GRINDBALLS information systems.
3. Authority and Responsibilities
- Employees: must perform business processes in accordance with this Policy.
- Suppliers: must comply in all work carried out with GRINDBALLS.
- Senior management: must ensure that activities remain compliant.
- Information Technology personnel: must manage and configure systems according to this Policy.
4. Definitions
Supplier: an external service provider. IS: Information Systems.
5. Personal Data and Information Security
GRINDBALLS treats corporate information and personal data belonging to itself or its stakeholders, whether processed through information systems or in physical form, as highly valuable assets and protects the systems and physical areas containing them continuously against threats.
Every employee shares responsibility for ensuring that information, including personal data processed by GRINDBALLS or its suppliers, is used only by authorised persons and for its intended purpose; kept complete and accurate; available when required; and deleted, destroyed or anonymised at the proper time and in the proper manner under Turkish Personal Data Protection Law No. 6698 (“KVKK”), the Regulation on the Deletion, Destruction or Anonymisation of Personal Data and company policies.
The Policy aims to prevent material and non-material damage and legal penalties arising from security vulnerabilities and to reduce their effects. All employees, business partners and partner personnel with access to systems, personal data or corporate information must follow this Policy and all related procedures and instructions.
Management expects departments to operate in accordance with KVKK; keep processing inventories and VERBIS records current; follow corporate security procedures; process data only for statutory or lawful company purposes; continue risk assessments; and report personal or corporate data breaches without delay.
The Information Technology Directorate owns the security policies and procedures and is responsible for their correct application. Department managers implement measures and monitor compliance in their units. GRINDBALLS commits to applicable information-security and privacy requirements and continual improvement.
6. References and Legal Basis
Turkish Personal Data Protection Law No. 6698 and related regulations.
7. Related Documents
Personal Data and Information Security Policy.