RETENTION AND DISPOSAL POLICY

1. INTRODUCTION AND THE PURPOSE AND SCOPE OF THE POLICY

The Law on the Protection of Personal Data No. 6698 (“LPPD”) aims to protect fundamental rights and freedoms, the privacy of private life, and the information security of individuals during the processing of personal data. With the amendment made to Article 20 of the Constitution in 2010, the protection of personal data was accepted as a constitutional right, and in 2016, the LPPD came into force.

Pursuant to Article 16 of the LPPD, data controllers who are obliged to register with the Data Controllers' Registry (VERBİS) are required to prepare a Personal Data Retention and Disposal Policy in accordance with their personal data processing inventory.

In this context, Altus Organizasyon Tanıtım Turizm Oto Kiralama Hizmetleri A.Ş. (“Altus” or the “Company”) processes personal data across a wide range of services such as congress, organization, media, live broadcasting, advertising production, ticketing and accommodation services, graphic and printing activities, subcontractor employment, and short-term employment practices.

This policy regulates the procedures and principles regarding the storage, protection, disposal, and anonymization of personal data obtained by Altus throughout its business processes.

This Policy covers:

  • Employees,
  • Subcontractors and short-term employees,
  • Suppliers and business partners,
  • Organization and congress participants,
  • Visitors,
  • Customer institution representatives,
  • Data from hotels, airlines, and other intermediaries,

and includes the rules regarding the storage and disposal of all personal data belonging to these groups of individuals in electronic and physical environments.

2. DEFINITIONS

Within the scope of this policy:

  • Law/LPPD: Law on the Protection of Personal Data No. 6698.
  • Board: Personal Data Protection Board.
  • VERBİS: Data Controllers' Registry Information System.
  • Explicit Consent: Consent that is based on information and expressed with free will regarding a specific subject.
  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Special Categories of Personal Data: Sensitive data such as health, biometric, religious, political, criminal conviction, and trade union membership.
  • Disposal: The deletion, destruction, or anonymization of personal data.
  • Periodic Disposal: The ex officio disposal of data whose retention period has expired at specified intervals.
  • Electronic Recording Medium: Servers, computers, portable memories, software, e-mails, camera recordings.
  • Non-Electronic Recording Medium: Paper forms, printed documents, name badges, printed materials.
  • Data Processor: Subcontractors, business partners, or service providers who process data on behalf of Altus.

3. FUNDAMENTAL PRINCIPLES

Altus complies with the principles set forth in Article 4 of the LPPD in the processing of personal data:

  • Compliance with the law and honesty rules
  • Being accurate and up-to-date when necessary
  • Processing for specific, explicit, and legitimate purposes
  • Being relevant, limited, and proportionate to the purpose for which they are processed
  • Being retained for the period required

4. RECORDING MEDIA

Within Altus, personal data is stored in the following electronic and physical media:

Electronic Media

  • Company servers (live broadcast recordings, video archives, congress software)
  • Portable memories, hard disks, backup units
  • In-house software (ticketing, congress registration software, accounting)
  • E-mail systems and WhatsApp correspondence
  • Camera recording systems
  • CD/DVD archives, video storage servers

Non-Electronic Media

  • Paper forms (participant lists, health reports, SSI documents)
  • Printed name badges, invitations, congress materials
  • Printing graphics and production outputs
  • Employee personnel files
  • Signed contracts (artists, subcontractors, hotels, airline companies)

5. REASONS REQUIRING RETENTION

  • Fulfillment of legal obligations (Tax Procedure Law, Labor Law, SSI, Code of Obligations, etc.)
  • Execution of contract processes (with employees, subcontractors, suppliers, artists, hotels, airlines)
  • Resolution of legal disputes
  • Performance of activities and fulfillment of customer requests
  • Recording of live broadcasts, congresses, and organizations
  • Protection of employee rights and occupational safety
  • Sustainability of commercial activities

6. DATA BY DEPARTMENT

6.1 Graphics Department

  • Data: Name, surname, T.R. identity no, blood type, date of birth, photograph, job information.
  • Purpose: Name badge printing, invitations, printed materials.
  • Retention Period: Duration of the organization + 2 years.
  • Transfer: To badge printing suppliers, business partners.

6.2 Media Department

  • Data: Audio-visual recordings, live broadcast videos, promotional videos.
  • Purpose: Live broadcast service, editing, production of commercials.
  • Retention Period: Institution's request + 10 years.
  • Note: Recordings made for the Presidency and state institutions are stored on encrypted servers, and their external transfer is prohibited.

6.3 Congress Department

  • Data: T.R. identity no, name-surname, date of birth, professional information, phone, e-mail, health reports, SSI documents, photograph, video recordings.
  • Purpose: Congress registration tracking, RSVP services, security control, travel allowances, artist contracts.
  • Retention Period: Duration of the organization + 10 years.
  • Transfer: To public institutions, security units, hotels, software companies.

6.4 Ticketing Department

  • Data: T.R. identity no, name-surname, date of birth, Miles&Smiles code, passport, phone, e-mail, credit card information, IBAN.
  • Purpose: Flight ticket, hotel reservation, transfer.
  • Retention Period: Contract period + 10 years.
  • Transfer: To airline companies, hotels, reservation platforms.

6.5 Employees and Subcontractors

  • Data: Identity, contact, personnel, financial, health reports, criminal record, audio-visual recordings.
  • Purpose: Recruitment, personnel files, occupational safety, equipment assignment.
  • Retention Period: Employment contract + 10 years.

6.6 Visitors

  • Data: Name-surname, T.R. identity no, license plate, camera recording.
  • Purpose: Physical space security, keeping visitor records.
  • Retention Period: 2 years (camera 3 months).

7. TECHNICAL AND ADMINISTRATIVE MEASURES

  • Data security procedures and confidentiality undertakings
  • Employee and subcontractor training
  • Access authorization matrix
  • Server and database security
  • Backup systems
  • Antivirus and firewalls
  • Physical security measures (camera, card access)
  • Data protection provisions in subcontractor and supplier contracts
  • Notification to the LPPD within 72 hours in case of a data breach

8. RETENTION AND DISPOSAL PERIODS TABLE

ACTIVITY / DATA CATEGORYRETENTION PERIODDISPOSAL PERIOD
Organization Participant ListsOrganization + 2 yearsFirst periodic disposal
Live Broadcast and Video Recordings10 years (at the institution's request)First periodic disposal
Employee Personnel FilesEmployment contract + 10 yearsFirst periodic disposal
Subcontractor DocumentsContract + 10 yearsFirst periodic disposal
Flight Ticket and Reservation Records10 yearsFirst periodic disposal
Camera Recordings (Office/Organization)2 monthsFirst periodic disposal
Visitor Records2 yearsFirst periodic disposal
Financial and Accounting Documents10 years (as per Tax Procedure Law)First periodic disposal

9. DISPOSAL METHODS

  • Deletion: Removing access from systems, encryption, closing user authorization.
  • Destruction: Paper shredders, magnetic destruction, physical destruction.
  • Anonymization: Making the data impossible to associate with an identity.

10. PERIODIC DISPOSAL

Altus performs periodic disposal operations twice a year, in June and December.

11. UPDATES

The policy is updated according to legislative changes and Board decisions. Updates are recorded.

12. PUBLICATION AND ENFORCEMENT

This policy is kept in wet-signed and electronic form. It is published on Altus's website. It enters into force as of the date of signature.

BİZİ TAKİP EDİN

Altus Organizasyon © 2012 All Rights Reserved. Terms of Use and Confidentiality KVKK Text