1. Purpose
Grindballs Bilya Çelik Sanayi Ticaret Anonim Şirketi (“Grindballs” or the “Company”), located at Dilovası OSB Mahallesi, D-2029 Sokak No: 1/1, Dilovası, Kocaeli, collects and processes personal data to provide its services in accordance with Turkish Personal Data Protection Law No. 6698 (“KVKK”) and related legislation. This Policy explains the purposes, conditions and principles of processing; domestic and international transfers; retention and disposal; data-subject rights; and Grindballs’ obligations.
2. Scope
The Policy applies to personal data concerning representatives, proxies and shareholders of the Company and group companies; employees, representatives and proxies of business partners and suppliers; customers and prospects; employees, candidates, interns, applicants and their references; public- and private-sector personnel; employees’ family members; legally authorised persons; visitors; and other third parties.
3. Authority and Responsibilities
- Employees: comply with this Policy and applicable law in all business activities.
- Suppliers: comply in all services provided to Grindballs.
- Senior management: ensures that Grindballs activities remain compliant.
4. Definitions
Personal data means any information relating to an identified or identifiable natural person. Special-category personal data includes data on race, ethnic origin, political opinion, philosophical belief, religion, appearance, association/foundation/trade-union membership, health, sexual life, criminal convictions and security measures, and biometric or genetic data. A data subject is a natural person whose data Grindballs processes. Processing covers every operation performed on data, automatically, partly automatically, or non-automatically as part of a filing system. Explicit consent is freely given, informed consent relating to a specific matter. Anonymisation makes data impossible to associate with an identified or identifiable person even when matched with other data. Data controller determines purposes and means; a processor processes data on the controller’s authority.
5. Processing Conditions and Exceptions
Ordinary personal data may be processed with explicit consent or without consent where expressly provided by law; necessary to protect life or physical integrity where consent cannot validly be given; directly necessary to establish or perform a contract; necessary for a controller’s legal obligation; made public by the data subject; necessary to establish, exercise or protect a right; or necessary for legitimate interests without harming fundamental rights and freedoms.
Special-category data is not processed without explicit consent unless permitted by law. Health and sexual-life data may be processed without consent by persons under a confidentiality duty or authorised bodies for public health, preventive medicine, diagnosis, treatment and care, or planning and management of health services and financing.
6. Personal Data Categories
- Identity: identity/passport numbers, name, signature, photograph, birth details, age, identity-card serial number and driving-licence copies.
- Contact: email, telephone, mobile and social-media accounts.
- Location: location, home and workplace addresses.
- Personnel: payroll, disciplinary, entry/exit, asset declaration, CV, performance, social-security, company title, tax, chamber registration and reference data.
- Legal transactions: judicial correspondence, litigation and enforcement data.
- Physical security: employee/visitor access logs and camera recordings.
- Transaction security: IP addresses and access logs.
- Finance: balance-sheet, performance, credit, risk, asset, payroll, IBAN, payment, card, refund and debt data.
- Professional experience: diplomas, courses, training, certificates and transcripts.
- Marketing: cookie records.
- Visual/audio: audio and camera records.
- Health: blood group, health reports, disability and other health information.
- Convictions/security measures: criminal-record and security-measure data.
- Family members: names and telephone details.
- Incident records: hazards, incidents and workplace accidents.
- Customer/prospect: profession, education, hobbies and interests.
- Requests/complaints: personal data arising from product or service requests, complaints and applications.
- Psychometric: measurements of knowledge, skill, behaviour and personal characteristics.
7. Collection Methods
Data may be collected through email, SMS, business cards, telephone, fax, CCTV, physical forms, the website, post, cargo or courier services, face-to-face meetings and other physical or electronic environments.
8. Processing Purposes
Customers, Prospects and Business or Solution Partners
Purposes include purchasing and supplier evaluation; sales; after-sales support; organisation and event management; marketing analysis and visitor routes; social-responsibility and civil-society activities; contracts; strategic and legal review; request and complaint handling; supply-chain and investment management; customer reporting and relationship management; satisfaction activities; visitor registration; and physical security.
Workplace CCTV
Entry areas are monitored to protect life and property, ensure workplace security and support disciplinary or legal processes under Occupational Health and Safety Law No. 6331, Labour Law No. 4857 and secondary legislation. Warning notices identify monitored areas. Cameras are positioned proportionately within the employer’s legitimate interest.
Candidates and Interns
Data is processed to evaluate applications, conduct interviews, contact references, assess suitability for a role, place successful candidates and, where appropriate, contact unsuccessful candidates about later opportunities.
Employees
Purposes include emergency and information-security management; employment and statutory obligations; employee benefits; audit and ethics; training and access rights; compliance with labour, occupational-safety and internet laws; finance and accounting; internal investigations; communications; occupational health and safety; recording assigned telephone lines, cards and vehicles; business continuity; legal matters; business operations and oversight; logistics; travel and assignments; sharing necessary driver data with vehicle providers; recording fuel and toll use of allocated vehicles; reporting to authorised persons and bodies; and corporate governance.
Contractors
Contractor data is processed to establish and retain personnel files, comply with law, respond to workplace inspections, maintain occupational-health-and-safety records, share necessary information with workplace physicians and medical staff, and protect workplace, employee, life and property security through access and proportionate electronic-monitoring methods.
9. Legal Grounds
Legal grounds include explicit consent under Articles 5/1 and 6/2 of KVKK; express statutory provision under Article 5/2(a); contractual necessity under 5/2(c); legal obligation under 5/2(ç), including access logging under Law No. 5651; establishment, exercise or protection of rights under 5/2(e), including retention for limitation periods; legitimate interests under 5/2(f); and, under Article 6/3, lawful processing of special-category data by persons under confidentiality duties or authorised bodies, such as workplace physicians handling health reports.
10. Transfer of Personal Data
Under Articles 8 and 9 of KVKK and for the purposes above, data may be transferred to employees, domestic or international business partners, suppliers, shareholders, authorised public bodies, legally authorised persons, group companies and natural persons or private-law legal entities. Examples include sharing customer data with lawyers for debt collection; providing access logs to authorities under Law No. 5651; using third parties for efficiency, recruitment and sustainability; and using Microsoft Office, cloud, SAP and backup systems whose databases may be abroad. Data may also be transferred to providers required to supply products and services.
International transfers occur where the data subject explicitly consents; the destination provides adequate protection; or, where it does not, the parties give a written adequate-protection undertaking approved by the Personal Data Protection Board, subject to the law in force.
11. Retention and Disposal
Data is retained and disposed of under KVKK, the Regulation on the Deletion, Destruction or Anonymisation of Personal Data and the Grindballs Retention and Disposal Policy. Information on measures and periods may be requested from kvkk@faydasicok.com.
12. Security
Grindballs applies appropriate technical and administrative measures to ensure lawful processing, prevent unlawful access and protect stored data. It implements a Personal Data Security Policy and additional controls for special-category personal data through its Special-Category Personal Data Processing and Security Policy, following these policies and generally accepted good practices.
13. Your Rights and Application
Under Article 11 of KVKK you may learn whether data is processed; request information; learn the purpose and appropriate use; learn recipients in Türkiye or abroad; request correction and notification to recipients; request deletion or destruction where grounds cease and notification to recipients; object to adverse results from exclusively automated analysis; and claim compensation for unlawful processing.
Applications may be made under the Communiqué on Applications to the Data Controller, with identity documents, in person or through a notary to Dilovası OSB Mahallesi, D-2029 Sokak No: 1/1, Dilovası, Kocaeli, marked “Information Request under the Personal Data Protection Law”, or through KEP with a secure electronic signature to kvkk@faydasicok.com. Applications are answered as soon as possible and within thirty days. They are generally free, but Board-tariff costs may be charged. Rejections are reasoned.
Grindballs Bilya Çelik Sanayi Ticaret Anonim Şirketi
Head Office: Dilovası O.S.B. 2. Kısım, D-2029 Sokak No:1, Dilovası / Kocaeli / Türkiye
Telephone: +90 262 502 11 11
Email: info@grindballs.com
Website: grindballs.com