PRIVACY POLICY
Talya Informatics Trade and Industry Ltd. Sti. (“TALYA”, “Company”), we attach importance to the protection of your personal data and private information. For this reason, in accordance with the Law on Protection of Personal Data No. 6698 (“KVK Law”), by using, recording, storing, updating, transferring and/or classifying your personal data within the framework described below, depending on business purposes, by our Company, as Data Controller. We show all the necessary effort and care in processing.
In this context, in accordance with the Laws and Regulations issued by our Company to protect the fundamental rights and freedoms of individuals, especially the privacy of private life, and to protect personal data, in order to prevent unlawful processing of your personal data, to prevent unlawful access and to ensure its preservation, we try to ensure the appropriate level of security. All technical and administrative measures are taken.
The target audience of this text is all real persons and our employees whose personal data are processed on our websites and in our corporate processes. As TALYA, our online software (“Web-Based Software”), desktop software (“Desktop”), websites (“Site”, “Sites”) and mobile applications (“Mobile Application”, “Mobile Application”), which serve over the internet via web-based and cloud We provide services through “Applications”). This Illumination Text covers all of the software, sites and applications in question.
Our Web-based Software: Elektraweb, Elektrawebmini, Elektraweb SPA, ElektraOtelimWebde
Desktop: Medisoft, Elektra
Our Websites: www.talyabilisim.com.tr, www.medisoft.com.tr, isafe.com.tr, www.elektraotel.com, www.elektraweb.com, spasatis.com, sparezervasyon.com
Our Mobile Applications: Medisoft Mobil, Medisoft Mobil Pro, e-Wallet Mobile, Elektra Pos Restaurant Manager
Personal information processed on our Software, Applications, Sites and Mobile Applications are processed in accordance with the legislation on the protection of personal data. Regarding our web-based, desktop and mobile applications, we are in the status of “data controller” only for those who open a user account and/or download mobile applications and use our websites, and this Privacy Policy is only valid for the processing of data belonging to these individuals.
Our Customers who process and save data using our web-based, desktop and mobile applications are data controllers independently of us. In these cases, since we are only in the status of “data processor” as the Company, we recommend that you consult our Customers’ own privacy policies, clarification text and similar documents that process your personal data when necessary.
On the other hand, we do not give any guarantee regarding the data security and data protection practices and policies of third party websites linked within our Sites. In this regard, we recommend that you review the data security and data protection policies of the relevant data controller separately.
TALYA BİLİŞİM (or the “Organization*) is in the status of “Data Controller” and is obliged to fulfill the obligations arising from the law against all real persons with whom it contacts and processes personal data, especially employees, employee candidates, customers, suppliers, supplier employees and visitors. . TALYA BİLİŞİM fulfills these obligations with the administrative measures it has taken through the compliance and control tools it has taken, and the technical measures at the appropriate and measured level.
TALYA BİLİŞİM processes your personal data as the “Data Controller” defined in Article 3 of the Personal Data Protection Law No. 6698, and the contact information is below:
Title : Talya Bilişim Ticaret ve Sanayi Ltd. Sti..
Address : Akdeniz University Antalya Technopolis, R&D 3 Building, Dumlupınar Boulevard, No:758/3 Campus ANTALYA
Our web addresses: www.talyabilisim.com.tr, www.medisoft.com.tr, isafe.com.tr, www.elektraotel.com, www.elektraweb.com, spasatis.com, sparezervasyon.com
Phone : + 90 (242) 227 91 00
You can send it to the correspondence address or [email protected] via e-mail
On ri za: for a given subject, which is based on informed consent and free will described
Anonymization: Making personal data incapable of being associated with an identified or identifiable natural person in any way, even by matching with other data.
Relevant person i: Natural person whose personal data is processed
Personal data: Any information relating to an identified or identifiable natural person.
Employee who touches personal data: Employees who process personal data of relevant persons on behalf of the organization as per their job description
Processing of personal data: Obtaining, recording, storing, preserving, changing, rearranging, disclosing, transferring, taking over, making available personal data by fully or partially automatic or non-automatic means provided that it is a part of any data recording system, all kinds of operations carried out on the data, such as classification or prevention of its use.
Committee: Internal Committee formed within the organization in accordance with the “Directive on the Duties and Responsibilities of the KVK Committee”, which has duties such as monitoring all personal data processes carried out by the organization, its units and employees, controlling whether the policies are followed, and executing personal data processes on behalf of the organization.
Board: Personal Data Protection Board
Institution: Personal Data Protection Authority
KVK: Personal Data Protection Law No. 6698
Private Personal Data: Data about the race, ethnic origin, political thought, philosophical belief, religion, sect or other beliefs, costume and clothing, membership to associations, foundations or trade unions, health, sexual life, criminal convictions and security measures. biometric and genetic data
Data processor: The natural or legal person who processes personal data on behalf of the data controller, based on the authority given by the data controller.
Data registration system: The registration system in which personal data is processed and structured according to certain criteria.
Data controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.
Joint data controller: The other data controller with whom the organization shares personal data within the scope of its commercial and corporate activities, and carries out processing activities on personal data jointly during this sharing.
Independent data controller: The other data controller that the organization shares personal data for once within the scope of its commercial and corporate activities.
Personal data belonging to the persons concerned in our organization, completely and directly related to the activities of the organization and the commercial, business or legal relationship with the person concerned;
TALYA BİLİŞİM processes the data of the persons concerned in general and intensively within the scope of this Privacy Policy and other administrative and technical measures. In the processing of personal data belonging to real persons outside these categories, the data processing policies of the organization, especially this Privacy Policy, will be complied with. The categories of natural persons whose personal data are being processed are as follows:
Personal data of organization employees, employee candidates and interns,
and similar laws, regulations and communiqués.
In this context, the organization includes the categories of employees’ identity, communication, personnel, finance, professional experience, physical space security, legal action, transaction security, risk management, audio-visual records and other information, belief, association membership, foundation membership, health information, criminal convictions. It processes special quality data such as security measures and security measures.
Identity, personal, contact, family information, finance, education, vocational information, shared with us by online employment platforms and/or talent agents, which job applicants share with us voluntarily through tools such as CVs, letters of intent or forwarded to be shared with all relevant organizations at their own request. We process personal data such as experience, habits and special data that they share with their own will, such as association and foundation memberships that they record in their resumes.
The personal data of the customer and supplier real persons, representatives of the customer and supplier institutions and real persons with whom the organization has relations while carrying out its commercial activities,
and similar laws, regulations and communiqués. The organization processes the personal data of real persons and representatives of customers and suppliers in the categories of identity, communication, finance, legal action and other information.
Personal data of auditors, consultants and public employees who carry out control and audit duties in order to carry out commercial and manufacturing activities of the organization and to ensure its sustainability and quality,
and similar laws, regulations and communiqués.
In this context, the organization processes the personal data of auditors, consultants and public officials in the categories of identity, communication and personnel.
We process the personal data of users who use our own web-based, desktop and mobile applications on their own behalf or corporately in the categories of identity, personnel, communication, location.
In addition, a trial account is created for people who want to try applications and software, and their personal data in the categories of identity, personnel and communication are processed.
Personal data of visitors in order to ensure information and facility security,
We process it within the scope of our legitimate interests.
In this context, personal data of visitors in categories such as Identity, Transaction Security, Physical Space Security are processed.
In accordance with our legitimate interests, your personal data in categories such as transaction security and identity belonging to users who visit our websites and register as members are processed through forms and “cookies”. For more information about cookies, we ask you to refer to our “Cookies Policy” .
Apart from the advertisements on our sites, we may inform our users, trial users, customers and potential customers about new products or services by e-mail, social media or telephone with their consent. The persons concerned may object to such promotional, advertising and promotional communications at any time. In addition, those who do not want to receive such e-mails and SMS messages can block the messages, use the cancellation option or request to be deleted from the lists by contacting us.
We also have a newsletter to inform those interested in our products and/or services. Each newsletter contains a link from our newsletter where you can unsubscribe. Those who want to cancel the subscription can do so through their account settings. Limited to this scope, we process the personal data of our potential customers in the categories of identity, personnel and communication.
Identity, communication and personal data of the representatives of our dealers who take part in sales, marketing and after-sales support services of our products and services
and similar laws, regulations and communiqués.
The Organization accepts that, within the scope of the Law, the data subject has the right to obtain consent before the data is processed, and that it has the right to determine the fate of the data after the data is processed.
In this sense, the relevant persons apply to the Contact Person;
ç) To know the third parties to whom personal data is transferred in the country or abroad,
ğ) In case you suffer damage due to unlawful processing of personal data, it can exercise its right to demand the compensation of the damage.
However, individuals do not have a right to anonymized data within the Company. Personal data may be shared with relevant institutions and organizations in case of legal authority by a judicial or public authority as a requirement of the business and contractual relationship.
Requests within the scope of the enumerated rights are made by filling in the Institution Application Form completely and submitting it to the Contact Person with your wet signature, registered letter with return receipt, and copies of your identity card (only the front page for the identity card). You can take a look at the Personal Data Applications Clarification Text regarding the application process .
9. BASIC RULES TO BE FOLLOWED IN PROCESSING PERSONAL DATA
TALYA BİLİŞİM units and employees will pay attention to the following basic rules, on which the Privacy Policy and other corporate policies are built, while processing the personal data of the persons concerned.
TALYA BİLİŞİM makes use of domestic and international service and product suppliers in order to carry out production-oriented and commercial activities and to carry out the activities that require expertise as an institution, and according to their job descriptions, activities and the nature of the service they provide, they are “data processor”, “data controller” or ” These suppliers, who are considered to be the “joint data controllers”, may transfer personal data to their business partners or authorized institutions and organizations.
Personal data is shared with the following parties for the following purposes:
It will be shared with the following parties residing abroad for the purpose of providing service via cloud, instant message or online communication channels, which are widely and inevitably used today. In this context,
You can find the privacy policies of each service provider at the following links:
The organization can carry out the necessary internal and external audits on the protection of personal data.
Applications made by the relevant persons are answered by the Committee within 30 days at the latest, by taking the opinion of the relevant unit.
When the organization is notified of any violation of personal data, the KVK Board is notified without delay and within 72 hours at the latest from the date of learning of this situation. It also informs the relevant parties and persons in the same way.
This policy document is updated when the organization’s personal data processing conditions, tools, purposes and scope change and the parties to which personal data are shared change. Updates made in each item are kept in a separate table.