Personal Data Retention and Destruction Policy
Detailed information on the retention periods, destruction methods, and our policy regarding personal data.
Detailed information on the retention periods, destruction methods, and our policy regarding personal data.
This is an English translation for information purposes only. The legally binding version is the Turkish text.
This policy has been prepared by Yaşam Diyet for the purpose of determining the procedures and principles regarding the retention, destruction, and recording of personal data processed within the scope of the Turkish Personal Data Protection Law No. 6698 (KVKK) and the relevant legislation. This policy covers all personal data processed by us in our capacity as data controller.
Personal data are retained for the periods specified in the Turkish Personal Data Protection Law No. 6698 (KVKK) and other relevant laws. Client information is retained for a period of 10 (ten) years in accordance with the Turkish Criminal Code and the relevant healthcare legislation. Following the termination of the contractual relationship, data are retained throughout the statutory periods and, upon the expiry of these periods, are subjected to periodic destruction processes.
In the process of retaining and destroying personal data, the Yaşam Diyet management as data controller, employees acting as data processors, system administrators, and external service providers take part. All stakeholders are obliged to take the necessary measures to ensure the protection and security of personal data in line with their duties and responsibilities.
The necessary technical and administrative measures are taken to prevent the unlawful processing of and access to personal data and to prevent the loss of data. These measures include encryption methods, access control mechanisms, firewalls, up-to-date antivirus software, confidentiality agreements with employees, and regular information security training.
Where the statutory periods have expired and the conditions for destruction have been met, personal data are destroyed by means of physical destruction (shredding paper documents, incineration, or grinding with special machines), secure erasure (software-based deletion from databases), and secure destruction (de-magnetizing magnetic media with special devices or physically fragmenting them).
Pursuant to the Turkish Personal Data Protection Law No. 6698 (KVKK) and the relevant regulations, whether the conditions requiring the destruction of personal data have arisen is regularly audited, and periodic destruction processes are carried out in 6 (six)-month intervals. During the periodic destruction process, all personal data whose retention period has expired are destroyed by the methods specified in the relevant regulation.
This policy is regularly reviewed and updated in line with legislative amendments and corporate needs. The effectiveness of the processes covered by the policy is audited at least once a year through internal audit mechanisms, and action plans are drawn up for identified areas of improvement.
For your questions, comments, and requests regarding the retention and destruction of your personal data, you may contact us via the e-mail address bilgi@yasamdiyet.com or by telephone at +90 505 069 61 65.