SANPARK KVKK POLICY
SECTION ONE – INTRODUCTION
1.1. Introduction
1.2. Purpose of the Policy
1.3. Scope of the Policy
1.4. Definitions
SECTION TWO – PROTECTION OF PERSONAL DATA
2.1. Security of Personal Data
2.2. Audit
2.3. Confidentiality
2.4. Unauthorized Disclosure of Personal Data
2.5. Protection of the Legal Rights of Personal Data Subjects
2.6. Protection of Special Categories of Personal Data
SECTION THREE – PROCESSING AND TRANSFER OF PERSONAL DATA
3.1. General Principles in the Processing of Personal Data
3.2. Conditions for Processing Personal Data
3.3. Conditions for Processing Special Categories of Personal Data
3.4. Conditions for Transferring Personal Data
SECTION FOUR – CLASSIFICATION OF PERSONAL DATA, PURPOSES OF PROCESSING AND TRANSFER, PERSONS TO WHOM IT IS TRANSFERRED
4.1. Classification of Personal Data
4.2. Purposes of Processing Personal Data
4.3. Purposes of Transferring Personal Data
4.4. Persons to Whom Personal Data May Be Transferred
SECTION FIVE – METHOD AND LEGAL BASIS FOR COLLECTING PERSONAL DATA, DELETION, DESTRUCTION AND ANONYMIZATION, AND RETENTION PERIOD
5.1 Method and Legal Basis for Collecting Personal Data
5.2. Deletion, Destruction or Anonymization of Personal Data
5.3. Retention Period of Personal Data
SECTION SIX – INFORMING THE PERSONAL DATA SUBJECT, RIGHTS OF THE PERSONAL DATA SUBJECT UNDER THE PERSONAL DATA PROTECTION LAW
6.1. Informing the Personal Data Subject
6.2. Rights of the Personal Data Subject Under the Personal Data Protection Law
6.3. Cases Where the Policy and the Law Shall Not Apply Fully or Partially
SECTION SEVEN – CLASSIFICATION OF PERSONAL DATA SUBJECTS AND MATCHING WITH PERSONAL DATA
7.1. Classification of Personal Data Subjects
7.2. Matching Personal Data with Personal Data Subjects
SECTION ONE – INTRODUCTION
1.1. Introduction
As SANPARK OTOPARK SİSTEMLERİ A.Ş. (the “Company” or “SANPARK”), we attach utmost importance to the lawful protection and processing of Personal Data pursuant to the Personal Data Protection Law No. 6698 (the “Law”), and we act with this care in all our planning and activities. With this awareness, SANPARK takes all administrative and technical measures for the protection and processing of Personal Data.
1.2. Purpose of the Policy
The purpose of the Personal Data Protection and Processing Policy (the “Policy”) is to inform Personal Data Subjects about the procedures and principles that our Company will comply with under the Law, and about our Company’s obligations, while protecting the fundamental rights and freedoms of individuals, primarily the privacy of private life regulated under Article 20 of the Constitution, to the maximum extent in accordance with the purpose of the Law. SANPARK processes, as Data Controller, the personal data of its employees who communicate on its own behalf or as representatives, company employees, and other natural persons who establish a relationship by applying for employment or through any other purpose or channel, in a lawful manner. Another purpose of this Policy is to provide information about the processing activities carried out by SANPARK and the relevant personal data systems, thereby ensuring transparency regarding personal data. In this context, SANPARK explains in detail within this Policy the processing of personal data under the Law, the data subjects whose data are processed, and the rights of these persons, together with the use of cookies and similar technologies.
1.3. Scope of the Policy
This Policy has been prepared for Company Shareholders, Company Business Partners, Company Officials, Employee Candidates, Visitors, Company Customers, Potential Customers and Third Parties, provided that they are natural persons, and shall apply within the scope of these persons. The Company informs these Personal Data Subjects about the Law by publishing this Policy on its website. This Policy shall not apply to legal entities, regardless of their capacity. For our Company employees, the “Policy on the Processing of Personal Data for Employees” shall apply. This Policy shall apply to the above-mentioned relevant persons where our Company processes their Personal Data wholly or partly by automatic means, or by non-automatic means provided that such processing is part of any data recording system. If the data does not fall within the scope of “Personal Data” as defined below, or if the Personal Data processing activity carried out by our Company is not performed by the means described above, this Policy shall not apply.
1.4. Definitions
The terms used in the implementation of this Policy shall have the meanings set out below:
Explicit Consent
Consent that relates to a specific matter, is based on information, and is expressed with free will.
Anonymization
Rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even by matching it with other data.
Employee Candidate
Natural persons who have applied for a job at our Company by any means or who have made their résumé and related information available for review by our Company.
Contact Person
The natural person notified to the Registry by the data controller during registration for communication with the Authority regarding the obligations of legal entities resident in Türkiye and representatives of non-resident legal entity data controllers under the Law and secondary regulations issued based on this Law.
Processing of Personal Data
Any operation performed on Personal Data, such as obtaining, recording, storing, preserving, modifying, rearranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of Personal Data, wholly or partly by automatic means or by non-automatic means provided that it is part of any data recording system.
Personal Data Protection Board
The Personal Data Protection Board.
Personal Data Subject / Relevant Person
Refers to the Company Shareholders, Company Business Partners, Company Officials, Employee Candidates, Visitors, Company Customers, Potential Customers and Third Parties whose Personal Data are processed.
Personal Data Processing Inventory
The inventory created by data controllers by associating the personal data processing activities carried out depending on their business processes with personal data processing purposes, data category, transferred recipient group and data subject group, and by detailing the maximum retention period required for the purposes for which personal data are processed, personal data intended to be transferred abroad, and the measures taken regarding data security.
Personal Data Retention and Destruction Rules
The rules used by data controllers as a basis for determining the maximum period required for the purpose for which personal data are processed, and for deletion, destruction and anonymization processes.
It is monitored through the personal data inventory.
Personal Data
Any information relating to an identified or identifiable natural person.
Person Receiving Products or Services
Natural persons who use or have used the products and services offered by our Company, regardless of whether they have any contractual relationship with our Company.
Special Categories of Personal Data:
Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and clothing, association, foundation or trade union membership, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data, are special categories of personal data.
Potential Product or Service Recipient
Natural persons who have requested or shown interest in using our products and services, or who are assessed, in accordance with commercial practice and the rules of good faith, as potentially having such an interest.
Company / Our Company
SANPARK OTOPARK SİSTEMLERİ A.Ş.
Shareholder / Partner
Natural person shareholders of SANPARK OTOPARK SİSTEMLERİ A.Ş.
Company Official
Members of the board of directors and other authorized natural persons of SANPARK OTOPARK SİSTEMLERİ A.Ş.
Other Person
Other persons who are not covered by the SANPARK Personal Data Protection and Processing Policy prepared for Company Employees and who do not fall into any Personal Data Subject category in this Policy.
Data Category
A class of personal data belonging to a data subject group or groups, grouped according to the common characteristics of personal data.
Data Subject Group:
The category of relevant persons whose personal data are processed by data controllers.
Data Controllers Registry Information System (VERBIS)
The information system created and managed by the Presidency, accessible via the internet, which data controllers use for applications to the Registry and other related Registry transactions.
Data Processor
A natural or legal person who processes Personal Data on behalf of the data controller based on the authority granted by the data controller.
Data Recording System
A recording system in which Personal Data are structured and processed according to specific criteria.
Data Controller
The person who determines the purposes and means of processing Personal Data and manages the place where the data are systematically kept (data recording system).
Visitor
All natural persons who enter the physical premises owned by our Company for various purposes or visit our websites for any purpose.
Procedure for the Management of Requests from Data Subjects
The procedure prepared within SANPARK detailing the process to be used in responding to requests that may be received from data subjects under the Law.
SECTION TWO – PROTECTION OF PERSONAL DATA
- Security of Personal Data
Our Company takes all necessary technical and administrative measures to ensure an appropriate level of security in order to prevent the unlawful processing of and access to Personal Data, and to ensure the preservation of Personal Data in accordance with the Law.
- Audit
Our Company carries out and has carried out the necessary audits to ensure the establishment, regularity and continuity of the data security and measures described above. Our Company periodically has penetration tests performed. It reviews the test results and takes the necessary actions to close vulnerabilities.
- Confidentiality
Our Company takes all necessary technical and administrative measures, according to technological possibilities and implementation costs, to ensure that relevant data controllers and data processors do not disclose the Personal Data they possess to others contrary to the provisions of the Law and the Policy, and do not use them for purposes other than processing. In this context, information and training activities regarding the Law and the Policy have been completed for our Company employees and their sustainability is ensured.
- Unauthorized Disclosure of Personal Data
If Personal Data processed by our Company are obtained by others through unlawful means, our Company carries out the necessary procedures to notify the relevant Personal Data Subject and the Personal Data Protection Board as soon as possible. If deemed necessary by the Personal Data Protection Board, this situation may be announced on the website of the Board or by another method deemed appropriate by the Board.
- Protection of the Legal Rights of Personal Data Subjects
Our Company observes all legal rights of Personal Data Subjects in relation to the implementation of the Policy and the Law and takes all necessary measures to protect these rights.
- Protection of Special Categories of Personal Data
Our Company carefully takes the adequate measures determined by the Personal Data Protection Board within the framework of the Policy on the Processing and Protection of Special Categories of Personal Data.
SECTION THREE – PROCESSING AND TRANSFER OF PERSONAL DATA
- General Principles in the Processing of Personal Data
Personal Data are processed by our Company in accordance with the procedures and principles set forth in the Law and this Policy. While processing Personal Data, our Company complies with the following principles.
- Being Lawful and Compliant with the Rules of Good Faith
- Being Accurate and, Where Necessary, Up to Date
- Being Processed for Specific, Explicit and Legitimate Purposes
- Being Relevant, Limited and Proportionate to the Purposes for Which They Are Processed
- Being Retained for the Period Stipulated in the Relevant Legislation or Required for the Purpose for Which They Are Processed
- Conditions for Processing Personal Data
Personal data are processed within SANPARK through explicit consent obtained from data subjects or in light of activities that may be carried out without explicit consent pursuant to Articles 5 and 6 of the Law, and such data are processed only within the framework of the purposes exemplified in the “Purposes of Processing Personal Data” section of this Policy. Our Company may process Personal Data without seeking the explicit consent of the data subject if one of the following conditions exists.
- It is expressly provided for by laws (Tax, Social Security Legislation, etc.).
- It is mandatory for the protection of the life or physical integrity of the person who is unable to express consent due to actual impossibility, or whose consent is not legally valid, or of another person.
- It is necessary to process personal data of the parties to a contract, provided that it is directly related to the establishment or performance of a contract (employment contract and similar contracts).
- It is mandatory for the data controller to fulfill its legal obligation (financial audit).
- The data have been made public by the relevant person himself/herself.
- Data processing is mandatory for the establishment, exercise or protection of a right (e.g., obligations during the warranty period).
- Data processing is mandatory for the legitimate interests of the data controller, provided that it is interpreted narrowly.
- Conditions for Processing Special Categories of Personal Data
Our Company does not process Special Categories of Personal Data without the explicit consent of the relevant person. However, Personal Data other than health and sexual life data may be processed without explicit consent of the relevant person in cases provided for by law. Personal Data relating to health and sexual life are processed by our Company without seeking the explicit consent of the relevant person only for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and planning and management of healthcare services and their financing, under conditions where we are subject to a confidentiality obligation. Our Company carries out the necessary procedures to ensure that the adequate measures determined by the Board are taken in the processing of Special Categories of Personal Data.
- Conditions for Transferring Personal Data
Our Company may transfer Personal Data and Special Categories of Personal Data of Personal Data Subjects to third parties in accordance with the Law by establishing the necessary confidentiality conditions and taking security measures in line with the purposes of processing Personal Data. Our Company acts in accordance with the regulations stipulated in the Law during the transfer of Personal Data. In this context, our Company may transfer Personal Data in line with legitimate and lawful Personal Data processing purposes, based on and limited to one or more of the Personal Data processing conditions specified in Article 5 of the Law, as listed below:
- If the Personal Data subject has explicit consent;
- If there is an explicit provision in the laws regarding the transfer of Personal Data,
- If it is mandatory for the protection of the life or physical integrity of the Personal Data subject or another person, and the Personal Data subject is unable to express consent due to actual impossibility or whose consent is not legally valid,
- If the transfer of Personal Data of the parties to a contract is necessary, provided that it is directly related to the establishment or performance of a contract,
- If the transfer of Personal Data is mandatory for our Company to fulfill its legal obligation,
- If Personal Data have been made public by the Personal Data subject,
- If the transfer of Personal Data is mandatory for the establishment, exercise or protection of a right,
- If the transfer of Personal Data is mandatory for the legitimate interests of our Company, provided that it does not harm the fundamental rights and freedoms of the Personal Data subject.
- Conditions for Transferring Personal Data Abroad
Our Company may transfer Personal Data of Personal Data Subjects to third parties abroad by taking the necessary security measures in line with the purposes of processing Personal Data. Personal Data may be transferred by our Company to foreign countries declared by the Personal Data Protection Board to have adequate protection, or, in the absence of adequate protection, to foreign countries where the data controllers in Türkiye and in the relevant foreign country undertake adequate protection in writing and where the permission of the Personal Data Protection Board has been obtained. However, in our current practice, there is no transfer of personal data to any foreign country.
SECTION FOUR – CLASSIFICATION OF PERSONAL DATA, PURPOSES OF PROCESSING AND TRANSFER, PERSONS TO WHOM IT MAY BE TRANSFERRED
- Classification of Personal Data
- Identity Data
These are data containing information about a person’s identity: name-surname, Turkish Republic identity number, marital status, nationality information, mother’s/father’s name and surname, place and date of birth, gender, résumé information, factory and registration number of employees, title deed and other official registry information and other identity information, driver’s license, identity card, passport and similar documents containing such information, tax number, SSI number, signature information, vehicle license plate and similar information.
- Contact Data
Telephone number, address, e-mail address, fax number, IP address and similar information.
- Financial Data
Personal data processed regarding any information, documents and records showing all financial results arising within the scope of the employer-employee relationship established by the Company with the Relevant Person, as well as bank account number, branch code, bank card information, IBAN number, credit card information, financial profile, credit score, asset data, income information and similar information.
- Human Resources Data
These are data obtained by the Company within the personnel file. Candidate résumé, license plate, education information, department, employee résumé, work experience information, title, SSI number, disciplinary records, philosophical belief, religion, sect and other beliefs, child information, military service information, association memberships, family information, employment start date, criminal record information, duty, clothing size information, personnel data, employment termination date, diploma information, professional information, vehicle information, travel information, race, ethnic origin, political opinion, professional certificate, signature circular and similar information.
- Digital Data
Photographs and camera recordings, voice recordings, and all other data in which these data are included, and similar information.
- Health Data
These are data processed within the scope of special categories of data. Health reports, disability status, illness information, health documents, sexual life and similar information.
- Third-Party Data
These are data mostly obtained for sole proprietorships. MERSIS number, tax certificate number, expert registry number, tax number, expert degree, sole proprietorship name and title, business number, signature circular, stamp information, expert code and similar information.
- Biometric Data
These are data processed within the scope of special categories of data. Palm information, retina scan information, facial scan information, fingerprint data and similar information.
- Purposes of Processing Personal Data
In order to fulfill the obligation to inform under Article 10 of the Law, our Company provides data subjects with information regarding the purposes for which Personal Data will be processed, and to whom and for what purposes the processed data may be transferred. Your personal data are processed, limited to the following purposes, within the scope of the personal data processing conditions specified in Articles 5 and 6 of the Law: planning and implementing our human resources policies in the best possible manner; properly planning and executing our commercial partnerships and strategies; ensuring the legal, commercial and physical security of our Company and our business partners; ensuring the corporate operation of our Company; carrying out activities to enable you to benefit from the products and services offered by our Company in the best possible way; customizing and recommending the products and services offered by our Company according to your demands, needs and wishes; ensuring data security at the highest level; creating databases; improving the services offered on our Company website; contacting persons who submit requests and complaints to our Company; and resolving errors occurring on our Company website.
- Purposes of Transferring Personal Data
Your Personal Data are transferred, limited to the following purposes, within the scope of the conditions specified in Articles 8 and 9 of the Law: planning and implementing our human resources policies in the best possible manner; properly planning and executing our commercial partnerships and strategies; ensuring the legal, commercial and physical security of our Company and our business partners; ensuring the corporate operation of our Company; carrying out activities to enable you to benefit from the products and services offered by our Company in the best possible way; customizing and recommending the products and services offered by our Company according to your demands, needs and wishes; ensuring data security at the highest level; creating databases; improving the services offered on our Company website; contacting persons who submit requests and complaints to our Company; and resolving errors occurring on our Company website.
- Persons to Whom Personal Data May Be Transferred
Your Personal Data may be transferred to our shareholders, business partners, suppliers, affiliates, companies and institutions with which we cooperate, companies from which outsourced services are received in order to fulfill our contractual or legal obligations, and authorized institutions and organizations. The nature of these transfers and the parties with whom sharing is made vary depending on the type and nature of the relationship between the data subject and SANPARK, the purpose of the transfer and the relevant legal basis, and these parties are generally as follows:
- Legal authorities such as law offices and institutions from which support is received for legal-purpose activities,
- Natural persons or private law legal entities,
- Our shareholders,
- Business units within SANPARK for coordination, cooperation and efficiency,
- Authorized public institutions and organizations,
- Banks that enable financial transactions to be carried out,
- Supplier companies,
- Healthcare institutions or hospitals in the event of a work accident,
- Relevant institutions for capacity reports,
SECTION FIVE – METHOD AND LEGAL BASIS FOR COLLECTING PERSONAL DATA, DELETION, DESTRUCTION AND ANONYMIZATION, AND RETENTION PERIOD
5.1 Method and Legal Basis for Collecting Personal Data
For the purpose of monitoring compliance with Article 1, which regulates the purpose of the Law, and Article 2, which regulates the scope of the Law, Personal Data are collected by all kinds of verbal, written and electronic means; through technical and other methods; through our Company website; within the framework of legal grounds based on legislation, contracts, requests and demands in order to achieve the purposes set out in the Policy and to fulfill legal responsibilities completely and accurately. They are processed by our Company or by data processors appointed by our Company.
5.2. Deletion, Destruction or Anonymization of Personal Data
Without prejudice to the provisions contained in other laws regarding the deletion, destruction or anonymization of Personal Data, our Company deletes, destroys or anonymizes Personal Data ex officio or upon the request of the data subject in accordance with the Personal Data Retention and Destruction rules, when the reasons requiring their processing cease to exist, even though they have been processed in accordance with this Law and other laws.
Deletion of personal data is the process of making personal data inaccessible and unusable in any way for relevant users. With the deletion of personal data, such data are destroyed in a way that they can no longer be used or recovered. Accordingly, data are erased from the documents, files, CDs, diskettes, hard disks and similar media on which they are recorded in a way that cannot be recovered.
Destruction of data means the destruction of materials suitable for data storage, such as documents, files, CDs, diskettes and hard disks, on which data are recorded, in a manner that the information cannot be recovered or used again.
Anonymization means removing or changing all direct and/or indirect identifiers in a data set, thereby preventing the identification of the relevant person or causing the distinctive characteristic of being identifiable within a group/crowd to be lost in a way that cannot be associated with a natural person. Anonymization of data means rendering Personal Data incapable of being associated with an identified or identifiable natural person, even if matched with other data.
5.3. Retention Period of Personal Data
Our Company retains Personal Data for the periods stipulated in laws and other legislation. If no period is regulated in laws and other legislation regarding how long Personal Data must be retained, Personal Data are processed until the purpose of processing the Personal Data in the relevant activity carried out by our Company at the time of processing is fulfilled, and then such Personal Data are deleted, destroyed or anonymized in accordance with the Personal Data Retention and Destruction rules.
SECTION SIX – INFORMING THE PERSONAL DATA SUBJECT, RIGHTS OF THE PERSONAL DATA SUBJECT UNDER THE PERSONAL DATA PROTECTION LAW
- Informing the Personal Data Subject
Our Company informs Personal Data Subjects at the time personal data are obtained, in accordance with Article 10 of the Personal Data Protection Law. In this context, it provides information, if any, about the identity of the Contact Person, the purpose for which personal data will be processed, to whom and for what purpose processed personal data may be transferred, the method and legal basis for collecting personal data, and the rights held by the Personal Data Subject.
- Rights of the Personal Data Subject Under the Personal Data Protection Law
Our Company informs you of your rights pursuant to Article 10 of the Law; provides guidance on how to exercise these rights; and implements the necessary internal procedures, administrative and technical arrangements for all of these. Pursuant to Article 11 of the Law, our Company explains to persons whose personal data are obtained that they have the rights to:
- learn whether personal data are processed,
- request information if personal data have been processed,
- learn the purpose of processing personal data and whether they are used in accordance with their purpose,
- know the third parties to whom personal data are transferred domestically or abroad,
- request correction of personal data if they are incomplete or incorrectly processed,
- request deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the Law,
- request notification of the transactions carried out pursuant to subparagraphs (d) and (e) of the Article of the Law to third parties to whom personal data have been transferred,
- object to the occurrence of a result against the person himself/herself by analyzing the processed data exclusively through automated systems,
- request compensation for damages in case of damage due to unlawful processing of personal data.
You may submit your requests regarding the implementation of the Law to our Company at kvkk@sanmak.com.tr in writing, with secure electronic signature, or by following the procedures set out in the application form through other methods to be determined by the Personal Data Protection Board (the “Board”), using the Personal Data Protection Law Data Subject Request Form. Our Company concludes the requests included in the application free of charge as soon as possible and no later than thirty days, depending on the nature of the request. However, if the relevant transaction requires an additional cost, the fee in the tariff determined by the Board may be charged.
Our Company may accept the request or reject it by explaining the reason; it notifies the relevant person of its response in writing or electronically. If the request in the application is accepted, our Company fulfills the requirement.
If the application arises from an error of our Company, the fee collected shall be refunded to the data subject.
In cases where the application is rejected, the response is found insufficient, or no response is given within the prescribed period, the data subject has the right to lodge a complaint with the Board within thirty days from the date he/she learns of the response, and in any case within sixty days from the date of application.
- Cases Where the Policy and the Law Shall Not Apply Fully or Partially
This Policy and the provisions of the Law shall not apply in the following cases:
- Processing of personal data by natural persons within the scope of activities related entirely to themselves or their family members living in the same household, provided that the data are not disclosed to third parties and obligations regarding data security are complied with.
- Processing of personal data for purposes such as research, planning and statistics by anonymizing them with official statistics.
- Processing of personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that it does not violate national defense, national security, public security, public order, economic security, the privacy of private life or personal rights, or constitute a crime.
- Processing of personal data within the scope of preventive, protective and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public security, public order or economic security.
- Processing of personal data by judicial authorities or enforcement authorities in relation to investigation, prosecution, trial or execution proceedings.
Provided that it is compatible with and proportionate to the purpose and basic principles of this Policy and the Law, Article 10 regulating the data controller’s obligation to inform, Article 11 regulating the rights of the relevant person except for the right to request compensation for damages, and Article 16 regulating the obligation to register with the Data Controllers Registry shall not apply in the following cases:
- Personal data processing is necessary for the prevention of crime or for a criminal investigation.
- Processing of personal data made public by the relevant person himself/herself.
- Personal data processing is necessary for the execution of supervisory or regulatory duties and disciplinary investigation or prosecution by authorized and competent public institutions and organizations and professional organizations having the status of public institutions, based on the authority granted by law.
- Personal data processing is necessary for the protection of the economic and financial interests of the State regarding budget, tax and financial matters.
SECTION SEVEN – CLASSIFICATION OF PERSONAL DATA SUBJECTS AND MATCHING WITH PERSONAL DATA
- Classification of Personal Data Subjects Only natural persons may benefit from the protection of this Policy and the Law; Personal Data Subjects within this scope are grouped as follows:
Employee Candidate
Natural persons who have applied for a job at our Company by any means or who have made their résumé and related information available for review by our Company.
Employee
Persons who are currently employed, formerly employed, or retired from our Company.
Shareholder / Partner
Persons who are shareholders/partners of our Company.
Parent / Guardian / Representative
Person acting by proxy.
Potential Product or Service Recipient
Natural persons who have requested or shown interest in using our products and services, or who are assessed, in accordance with commercial practice and the rules of good faith, as potentially having such an interest.
Intern
Persons serving as interns in our Company.
Visitor
All natural persons who enter the physical premises owned by our Company for various purposes or visit our websites for any purpose.
Person Receiving Products or Services
Natural persons who use or have used the products and services offered by our Company, regardless of whether they have any contractual relationship with our Company.
Supplier Official
Authorized persons of supplier companies that provide support to our Company.
Supplier Employee
Employees of supplier companies that provide support to our Company.
Other
Other persons who do not fall into any personal data subject category.
7.2 Matching Personal Data with Personal Data Subjects
The matching of the classified Personal Data defined and scoped above with the classified Personal Data Subjects is presented below.
Identity Data
Employee Candidate, Employee, Shareholder/Partner, Potential Product and Service Recipient, Intern, Supplier Employee, Supplier Official, Person Receiving Products or Services, Visitor
Contact Data
Employee Candidate, Employee, Shareholder/Partner, Potential Product and Service Recipient, Intern, Supplier Employee, Supplier Official, Person Receiving Products or Services
Financial Data
Employee Candidate, Employee, Person Receiving Products or Services, Supplier Official
Human Resources Data
Employee Candidate, Employee, Shareholder/Partner, Intern
Digital Data
Employee Candidate, Employee, Shareholder/Partner, Potential Product and Service Recipient, Intern, Supplier Employee, Supplier Official, Person Receiving Products or Services, Visitor
Health Data
Employee, Intern
Biometric Data
Employee