Attorney Ceyhun Emre Babacan emblem LL.M. AVUKAT / ATTORNEY Ceyhun Emre BABACAN HUKUK BÜROSU / LAW OFFICE

Corporate Page

Personal Data Protection and Privacy Policy

1. Introduction This Personal Data Protection and Privacy Policy ("Policy") has been prepared by Att. Ceyhun Emre Babacan, acting in the capacity of data controller, in order to…

1. Introduction

This Personal Data Protection and Privacy Policy ("Policy") has been prepared by Att. Ceyhun Emre Babacan, acting in the capacity of data controller, in order to explain the principles regarding the processing of personal data within the scope of the Personal Data Protection Law No. 6698 ("KVKK"), relevant secondary legislation, and to the extent applicable, the European Union General Data Protection Regulation ("GDPR").

This Policy provides information regarding the purposes for which the personal data of clients, consulteds, business partners, employees, employee candidates, suppliers, website visitors, e-newsletter subscribers, and other third parties are processed, to whom they are transferred, how they are protected, and the rights of the data subjects. "Personal data" refers to any information relating to an identified or identifiable natural person.

2. Legal Grounds for Processing Personal Data

Personal data is processed based on at least one of the following legal grounds pursuant to Articles 5 and 6 of the KVKK:

  • It is clearly prescribed by law
  • It is mandatory for the protection of the life or physical integrity of the person who is unable to express their consent due to actual impossibility
  • It is directly related to the establishment or performance of a contract
  • It is mandatory for the data controller to fulfill their legal obligation
  • It has been made public by the data subject themselves
  • Data processing is mandatory for the establishment, exercise, or protection of a right
  • Data processing is mandatory for the legitimate interests of the data controller
  • Having the explicit consent of the data subject

As a rule, special categories of personal data are processed with explicit consent. Exceptional circumstances provided for in the law are reserved.

3. Method of Collecting and Processing Personal Data

Personal data may be collected through electronic environments, website, e-mail, software, online forms, physical documents, telephone calls, verbal communication, and similar methods, by automatic or non-automatic means.

In addition, device and usage data may be processed during the use of the website through cookies, log records, and similar technologies.

The collected data categories generally include:

  • Identity and contact information
  • Transaction and customer data
  • Legal transaction and case file information
  • Financial and billing information
  • Employee and candidate information
  • Device and usage data
  • Visual and auditory records
  • Special categories of personal data when necessary

4. Purposes of Processing Personal Data

Personal data may be processed for the following purposes:

  • Providing and executing legal services
  • Managing client and consultant relations
  • Preparing, establishing, and performing contract processes
  • Executing finance, accounting, and billing processes
  • Providing communication activities
  • Fulfilling legal obligations
  • Executing litigation, execution, and dispute resolution processes
  • Ensuring information security processes
  • Protecting system and network security
  • Developing and improving the website and digital platforms
  • Analyzing user experience through cookies
  • Conducting events, seminars, and information activities
  • Executing human resources and recruitment processes
  • Meeting requests from official institutions and organizations
  • Executing internal audit, reporting, and operational processes
  • Increasing service quality within the scope of legitimate interest

5. Transfer of Personal Data

Personal data may be transferred to the following persons and institutions in accordance with Articles 8 and 9 of the KVKK:

  • Authorized public institutions and organizations
  • Tax offices, financial authorities, and regulatory bodies
  • Banks and financial institutions
  • Business partners, consultants, and service providers
  • Technical infrastructure and IT service providers
  • Suppliers and external service providers
  • Attorneys, experts, and collaborating professionals
  • Group companies and affiliates
  • Domestic and international business partners

6. International Data Transfer

Personal data may be transferred abroad within the framework of obtaining explicit consent, transfer to countries with adequate protection, appropriate safeguards determined under the KVKK, and appropriate security mechanisms under the GDPR.

Data may be considered transferred abroad due to electronic mail infrastructures, cloud systems, and third-party software.

7. Retention and Security of Personal Data

Personal data is retained in accordance with the law and honesty rules, for specific, clear, and legitimate purposes, relevant, limited, and proportionate to the purpose of processing, and for the required period.

Within the scope of data security:

  • Technical and administrative measures are implemented to prevent unauthorized access
  • Access privileges are restricted
  • Log records and system monitoring processes are conducted
  • Technologies such as encryption and firewalls are used
  • Regular backups are performed
  • KVKK awareness training is provided to employees
  • Physical files are kept in secure areas

Personal data whose retention period has expired or whose processing purpose has ceased to exist is deleted, destroyed, or anonymized in accordance with the KVKK. In the event of a data breach, data subjects and authorized bodies are informed in accordance with the legislation.

8. Rights of the Data Subject

Data subjects have the following rights under the KVKK and GDPR:

  • To learn whether their personal data is being processed
  • To request information if processed
  • To learn the purpose of processing
  • To know the third parties to whom they are transferred domestically or abroad
  • To request correction of incomplete or incorrect data
  • To request deletion or destruction of data
  • To request notification of these operations to third parties
  • To object to a result against them by analyzing via automated systems
  • To demand compensation of damages in case of unlawful processing
  • To use data portability and restriction of processing rights under the GDPR

Applications may be submitted to the data controller in writing or electronically and will be finalized within 30 days at the latest.

9. Policy Changes

This Policy may be modified in line with legislative changes or updates in corporate processes. The updated version takes effect on the date it is published on the website.

10. Contact

Contact with the data controller:

Att. Ceyhun Emre Babacan
Address: Merkez Mah. Akar Cad. iTower No:3/60 Şişli/Istanbul
E-mail: info@ceyhunemrebabacan.av.tr
Phone: +90 533 516 08 90
Web: ceyhunemrebabacan.av.tr

Related legal documents

Attorney Ceyhun Emre Babacan emblem LL.M. AVUKAT / ATTORNEY Ceyhun Emre BABACAN HUKUK BÜROSU / LAW OFFICE
HomeArticlesAbout UsPractice AreasContact