Personal Data Protection & Processing Policy
BURTECH KİMYA SANAYİ VE TİCARET LİMİTED ŞİRKETİ · Обновлено: 2026-08-23
Courtesy translation. In case of discrepancy, the Turkish text prevails.
Audience: all natural persons whose personal data is processed within https://www.burtech.com.tr and its connected systems ("the Platform") operated by BURTECH KİMYA SANAYİ VE TİCARET LİMİTED ŞİRKETİ — customers, visitors, dealers and dealer applicants, and employees of suppliers and partners.
1. INTRODUCTION
BURTECH KİMYA SANAYİ VE TİCARET LİMİTED ŞİRKETİ manufactures, wholesales, retails, imports and exports chemical and technical products. In its relationships with customers, dealers, suppliers, partners, employees and other data subjects, the Company is committed to acting in line with Turkish Personal Data Protection Law No. 6698 ("KVKK") and related legislation.
Purpose. To align the procedures required by KVKK with the Platform's organisation and business processes and apply them effectively, through administrative and technical measures, internal procedures and awareness training.
Scope. All personal data obtained by wholly or partly automated means, or by non-automated means as part of a data filing system, within the Platform's business processes.
Basis. KVKK, together with Law No. 6563 (e-commerce), Law No. 6102 (commercial code), Law No. 6502 (consumer protection), Law No. 213 (tax procedure), Law No. 5651 and Law No. 5237. Where legislation and this Policy conflict, legislation prevails.
2. PROTECTION OF PERSONAL DATA
2.1. Security. The Company takes the measures required by Article 12 of KVKK, appropriate to the nature of the data, and follows the guidance published by the Authority, carrying out audits accordingly.
2.2. Special categories. The Company's principle is not to collect special categories of personal data. Where processing is unavoidable, it takes place under Article 6 of KVKK with the adequate measures determined by the Board.
2.3. Awareness. Training is provided and repeated in line with practical findings and legislative changes.
3. PROCESSING
3.1. Principles (Art. 4): lawfulness and fairness; accuracy and, where necessary, being up to date; specified, explicit and legitimate purposes; relevance, limitation and proportionality; retention only for the period required.
3.2. Conditions (Art. 5): explicit consent, or one of: express provision in law; actual impossibility; direct connection with the conclusion or performance of a contract; compliance with a legal obligation; data made public by the data subject; necessity for the establishment, exercise or protection of a right; legitimate interest without prejudice to fundamental rights.
3.3. Disclosure. Data subjects are informed through the KVKK Privacy Notice before their data is obtained.
3.4. Transfers (Arts. 8–9). Transfers take place under one or more of the conditions in Article 5, with the necessary security measures, and are governed by data-processing agreements with the recipients. Recipient groups are listed in Section 5 of the KVKK Privacy Notice. As a rule, no data is transferred abroad; where unavoidable, transfers comply with Article 9.
4. DATA INVENTORY
Data categories, processing purposes, data subject groups, recipients and retention periods are kept in the Company's Personal Data Processing Inventory, maintained per business process (orders, payment, delivery, dealership applications, dealer portal, support, log management) and reviewed regularly.
5. TECHNICAL AND ADMINISTRATIVE MEASURES
Administrative: maintaining the processing inventory; applying the retention and destruction policy; confidentiality undertakings; agreements with data processors; awareness training; access rights aligned with job definitions; disciplinary procedures.
Technical: SSL/TLS encrypted transport; irreversible password hashing; role-based access control and role-scoped session tokens; API rate limiting; security and transaction logging; regular encrypted backups; up-to-date software and security patches; processing of payment data on a PCI-DSS compliant payment-institution infrastructure so card data never enters Company systems.
If personal data is nevertheless unlawfully obtained by third parties, the Company notifies the Board and the affected individuals as soon as possible under Article 12/5.
6. RETENTION AND DESTRUCTION
Data is retained for the period required by the processing purpose and by legislation; the full table is published in Section 6 of the KVKK Privacy Notice. At the end of the period, data is deleted, destroyed or anonymised — during periodic destruction cycles (every 6 months) or upon a data subject's application.
7. RIGHTS OF DATA SUBJECTS
7.1. The rights listed in Article 11 of KVKK (information, purpose, recipients, correction, erasure, notification to third parties, objection to automated decisions, compensation).
7.2. Exercised via the Data Subject Application Form, submitted in person, by notary, or from an e-mail address registered in our systems.
7.3. Applications are concluded free of charge within 30 days at the latest; where the process entails a cost, the Board's tariff may apply.
7.4. The Company may reject a request, stating its reasons, in the cases listed in Article 28 of KVKK.
7.5. Data subjects may complain to the Board within 30 days of learning the answer and in any case within 60 days of the application.
7.6. The Company may request identity-verifying information and ask clarifying questions.
8. IMPLEMENTATION
The Policy is approved and put into force by Company management, with technical implementation through the Personal Data Retention and Destruction Policy. Management is responsible for execution, updating, monitoring and audit.
9. ENTRY INTO FORCE
The Policy is in force as of its publication date. Changes are published on the Platform and take effect on the date announced.
Last updated: 23.08.2026 · Contact: info@burtech.com.tr
Вопросы по этому документу: info@burtech.com.tr · 0850 244 18 80
