DORA MAKİNE INDUSTRY AND TRADE LTD. CO. PERSONAL DATA PROTECTION AND PROCESSING POLICY
1. Purpose of the Policy
Dora Makine Industry and Trade Ltd. Co. (“Dora Makine” or the “Company”) has prepared this policy in full compliance with the Personal Data Protection Law No. 6698 (“PDPL”) and secondary regulations. This policy regulates, in a clear, transparent, and accessible manner, the methods of processing personal data collected in the capacity of data controller, the legal grounds relied upon, sharing procedures, and the rights of data subjects.
2. Scope
This policy applies to all natural persons sharing data with Dora Makine.
- Customers and potential customers
- Suppliers and business partners
- Job applicants and current employees
- Visitors
- Stakeholders in the chemical, stone, pharmaceutical, and paper industries
3. Identity of the Data Controller
Title: Dora Makine Industry and Trade Ltd. Co.
Address: Naldöken, 1237/1. St. No:13, 35050 Bornova/İzmir
E-mail: info@doramakine.com.tr
4. Categories of Personal Data Processed
In accordance with Articles 5 and 6 of the PDPL, the following data are processed:
- Identity Information: Name, surname, ID number, date of birth
- Contact Information: Address, phone, e-mail
- Financial Data: IBAN, bank account details, invoice records
- Employment Data: Resume, references, education status
- Visual/Audio Data: CCTV recordings (factory visits)
- Cookie Data: IP address, session details, analytics and marketing cookies
5. Purposes of Processing Personal Data
We aim to protect the rights of data subjects while enhancing our efficiency and customer satisfaction. The main purposes of processing are:
- Execution of sales and after-sales services
- Design of customized mixers and vibrating screens for customers
- Supply chain and logistics planning
- Fulfillment of financial and accounting obligations
- Management of human resources processes
- Improvement of website user experience
- Compliance with legal obligations and ISO 9001 quality standards
6. Collection Methods and Legal Grounds
Data are collected through web forms, e-mail, contracts, cookies, physical forms, and CCTV systems.
- PDPL Art. 5/2-c: Mandatory for the establishment or performance of a contract
- PDPL Art. 5/2-f: Legitimate interests
- PDPL Art. 5/2-ç: Legal obligations
In cases requiring explicit consent, written or electronic consent is obtained in accordance with PDPL Art. 5/1.
7. Domestic and International Transfers
Personal data may be transferred to:
- Suppliers, audit firms, logistics partners
- Public authorities (Tax Administration, Social Security Institution, etc.)
- Overseas cloud service providers with adequate protection (Microsoft 365, Google Workspace) in line with PDPL Art. 9. Necessary commitments and agreements are signed before transfer to ensure security.
8. Retention Periods
Data are retained for the maximum periods stipulated in relevant legislation:
- Invoices and financial records: 10 years (Tax Procedure Law, Turkish Commercial Code)
- Employee personnel files: 10 years after termination of employment
- Job application data: 2 years
- CCTV recordings: 30 days
- Cookie data: Duration set in the browser
9. Rights of Data Subjects
Within the scope of PDPL Art. 11, data subjects have the right to:
- Learn whether their personal data are processed
- Request information if processed
- Learn the purpose of processing and whether it is used in line with that purpose
- Know third parties to whom the data are transferred
- Request correction of incomplete/incorrect data
- Request deletion or destruction of data
- Request notification of corrections/deletions to third parties
- Object to decisions based on automated systems
- Claim compensation for damages caused by unlawful processing
10. Exercising of Rights
Applications can be made via the following methods and will be concluded free of charge within 30 business days:
- Secure e-mail with electronic signature: info@doramakine.com.tr
- Wet-signed written application (to the Dora Makine address)
- Application via Registered Electronic Mail (REM/KEP)
11. Data Security Measures
Within the scope of ISO 27001-compliant Information Security Management System:
- Network firewalls, antivirus, IDS/IPS solutions
- Data Loss Prevention (DLP) software
- Authorization matrix and role-based access controls
- Regular backups and disaster recovery tests
- KVKK and cybersecurity training for employees
12. Cookie Policy
Our website uses essential, analytical, and advertising cookies. You can manage your cookie preferences from your browser settings or the “Cookie Preferences” panel. For more details, please review our Cookie Policy page.
13. Enforcement and Updates of the Policy
This policy entered into force on April 26, 2025. Updates will be made in line with legislative changes or operational needs, and the new version will become effective as of its publication on our website.