The Law on the Protection of Personal Data (LPPD)
LPPD Policy
MASTERLINE PVC AND ALUMINUM STRUCTURAL ELEMENTS INDUSTRY AND TRADE INC.
PERSONAL DATA PROTECTION AND PROCESSING POLICY
INTRODUCTION
MASTERLINE PVC and Aluminum Structural Elements Industry and Trade Inc. ("COMPANY") attaches great importance to the protection of personal data in its operations and considers it among its top priorities in all business processes. This Personal Data Protection and Processing Policy ("Policy") is the main regulation developed to ensure that the procedures and principles set out in the Law on the Protection of Personal Data No. 6698 ("Law") are harmonized with the organization and operational processes of our Company. In line with this Policy, our Company processes and protects personal data with a high level of responsibility and awareness, ensuring the necessary transparency by informing the data subjects.
Purpose
The purpose of this Policy is to ensure the effective implementation of the procedures and principles stipulated in the Law and relevant regulations by harmonizing them with the organizational and operational processes of MASTERLINE. Our Company adopts all necessary administrative and technical measures for the processing and protection of personal data with this Policy, establishes internal procedures, raises awareness, and provides the necessary training to ensure consciousness. All necessary measures are taken and appropriate and effective control mechanisms are established for shareholders, officials, employees, and suppliers to ensure compliance with the Law.
Scope
This Policy covers all personal data obtained in the business processes of our Company through automated means or non-automated means provided that they are part of any data recording system.
Legal Basis
This Policy is based on the Law and related legislation. Personal data are processed to fulfill legal obligations arising from various regulations such as the Law on the Protection of Consumers No. 6502, the Identity Notification Law No. 1774, the Labor Law No. 4857, the Occupational Health and Safety Law No. 6331, the Social Insurance and General Health Insurance Law No. 5510, the Unemployment Insurance Law No. 4447, the Turkish Commercial Code No. 6102, the Tax Procedure Law No. 213, and other relevant regulations.
In the event of a conflict between the applicable legislation and this Policy, the provisions of the legislation shall apply. Regulations set forth in the legislation are reflected in the practices of MASTERLINE.
Definitions
Explicit Consent: Consent that is given for a specific issue, based on information and expressed with free will.
Application Form: The form prepared in accordance with the Law No. 6698 and the Communiqué on the Principles and Procedures of Application to the Data Controller, to be submitted by the data subject to exercise their rights.
Relevant User: Persons who process personal data within the data controller’s organization or in line with authorization and instructions received from the data controller, excluding those responsible for technical storage, protection, and backup.
Destruction: Deletion, destruction, or anonymization of personal data.
Data Recording Environment: Any environment in which personal data processed wholly or partially by automated means, or by non-automated means provided that they are part of a data recording system, is kept.
Personal Data: Any information relating to an identified or identifiable natural person.
Processing of Personal Data: Any operation performed on personal data such as collection, recording, storage, retention, alteration, rearrangement, disclosure, transfer, acquisition, making available, classification, or preventing use.
Anonymization of Personal Data: Making personal data impossible to associate with an identified or identifiable person, even by linking with other data.
Data Subject: The natural person whose personal data is processed.
Deletion of Personal Data: Making personal data inaccessible and unusable for relevant users.
Destruction of Personal Data: Making personal data inaccessible, unrecoverable, and unusable by anyone.
Board: Personal Data Protection Board.
Authority: Personal Data Protection Authority.
Sensitive Personal Data: Data relating to race, ethnicity, political opinion, philosophical belief, religion, sect or other beliefs, clothing, membership in associations, foundations or unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
Periodic Destruction: The process of deletion, destruction, or anonymization carried out at recurring intervals specified in the personal data retention and destruction policy when all processing conditions no longer apply.
Data Processor: Natural or legal person who processes personal data on behalf of the data controller based on their authorization.
Data Recording System: The system in which personal data is processed based on specific criteria.
Data Controller: The person or entity who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.
Data Representative: The real person appointed to fulfill the obligations of the data controller under the Law.
Regulation: Regulation on the Deletion, Destruction or Anonymization of Personal Data published in the Official Gazette on 28 October 2017.
PROTECTION OF PERSONAL DATA
Ensuring Personal Data Security
Our Company takes the necessary precautions based on the nature of personal data to prevent unlawful disclosure, access, transfer, or any other security breach in accordance with Article 12 of the Law. The Company adheres to the guidelines published by the Personal Data Protection Authority to maintain adequate data security levels and conducts relevant audits.
Protection of Sensitive Personal Data
Sensitive personal data, including race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, clothing, membership in associations, foundations or unions, health, sexual life, criminal convictions, security measures, and biometric and genetic data are handled with particular care and are subject to specific controls and audits.
Promoting Awareness of Data Protection and Processing
The Company provides training to stakeholders to ensure lawful processing, secure storage, and appropriate use of personal data. Processes are established to enhance awareness and responsibility, and expert support is utilized when necessary. Training programs are updated based on feedback and legislative changes.
PROCESSING OF PERSONAL DATA
3.1. Processing in Compliance with Legislation
Personal data shall be processed in accordance with the principles outlined below:
Lawfulness and Fairness: Personal data are processed in a lawful and fair manner without violating the fundamental rights and freedoms of individuals.
Accuracy and Being Up to Date: Necessary measures are taken to ensure that the personal data processed are accurate and up-to-date.
Specific, Clear and Legitimate Purposes: Personal data are processed only for specified, explicit, and legitimate purposes.
Relevance, Limited and Proportional to the Purpose: Data are collected only to the extent required by the purpose and processed in a limited and proportional manner.
Storage for the Required Period: Personal data are stored for the period required by the purpose of processing or as stipulated in the relevant legislation. Once the purpose ceases to exist, the data are deleted, destroyed or anonymized through appropriate methods.
3.2. Legal Grounds for Processing Personal Data
Personal data may be processed if the data subject has given explicit consent or if at least one of the conditions listed below is present:
Explicit Consent of the Data Subject: The data subject’s explicit consent is obtained after providing information and ensuring voluntary expression of will.
Situations Where Consent is Not Required:
It is expressly permitted by law.
It is necessary to protect the life or physical integrity of the data subject or another person where the data subject is physically or legally incapable of giving consent.
It is necessary for the performance or establishment of a contract to which the data subject is a party.
It is required to fulfill the legal obligation of the Company.
The data subject has made the data public.
It is required for the establishment, exercise, or protection of a right.
It is necessary for the legitimate interests of the Company, provided that it does not harm the fundamental rights and freedoms of the data subject.
3.3. Processing of Sensitive Personal Data
Sensitive personal data shall not be processed without the explicit consent of the data subject. However, sensitive personal data other than those relating to health and sexual life may be processed without explicit consent in cases stipulated by law. Sensitive personal data relating to health and sexual life may only be processed by persons under the obligation of confidentiality or authorized institutions and organizations for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, planning and management of health services, and financing.
The Company takes all necessary measures determined by the Board for the protection of sensitive personal data. In this context, the Company implements additional technical and administrative measures, regularly conducts audits, and raises awareness among employees through training programs.
3.4. Purposes of Processing Personal Data
Personal data are processed by the Company for the following purposes:
Fulfillment of legal obligations,
Performance of human resources processes,
Execution and development of business operations,
Management of employee rights and benefits,
Protection of the Company’s legal and commercial security,
Establishment and performance of contracts,
Ensuring workplace security,
Planning and execution of corporate communication and marketing activities,
Compliance with internal policies and procedures,
Planning and execution of audit and ethical processes,
Planning and execution of risk management processes,
Conducting financial and accounting operations.
3.5. Retention Period of Personal Data
Personal data are stored for the duration required by the relevant legislation or for the period necessary for the purposes for which they are processed. Upon expiration of these periods, the data are deleted, destroyed, or anonymized in accordance with the procedures set out in the relevant regulations.
3.6. Transfer of Personal Data
Personal data may be transferred to third parties domestically or internationally for the purposes specified in this Policy, in compliance with the conditions specified in Articles 8 and 9 of the Law. The Company ensures that all necessary administrative and technical measures are taken to protect the data during such transfers.
Transfers may occur to:
Business partners,
Suppliers,
Legally authorized public institutions and organizations,
Legally authorized private individuals,
Third parties within the scope of the purposes specified in this Policy.
3.7. Rights of Data Subjects
In accordance with Article 11 of the Law, data subjects have the following rights:
To learn whether their personal data are being processed,
To request information if their personal data have been processed,
To learn the purpose of processing and whether data are used in accordance with their purpose,
To know the third parties to whom personal data are transferred domestically or abroad,
To request rectification of personal data if it is incomplete or inaccurate,
To request the deletion or destruction of personal data within the framework of the conditions set out in Article 7 of the Law,
To request notification of operations carried out under subparagraphs (e) and (f) to third parties to whom data have been transferred,
To object to the occurrence of a result against themselves by analyzing processed data exclusively through automated systems,
To claim compensation for damages in case of unlawful processing of personal data.
Requests to exercise these rights can be submitted using the Application Form available on the Company’s website. Applications must include the data subject’s name, surname, signature (if written), Turkish ID number (or passport number for foreigners), residence or business address, email address, and subject of the request. The Company responds to applications within thirty (30) days.
3.8. Deletion, Destruction, or Anonymization of Personal Data
When the purpose for which personal data were processed no longer exists and/or the retention periods stipulated by law or the Company have expired, personal data are deleted, destroyed, or anonymized. These processes are carried out in accordance with the Company’s Personal Data Retention and Destruction Policy and relevant regulations.
3.9. Updates to the Policy
The Company reserves the right to update or amend this Policy at any time to comply with legislative changes or internal needs. The updated Policy is published on the Company’s official website and made accessible to relevant parties.
Information Security Policy
INFORMATION SECURITY SCOPE
This policy covers all units using the Information Technologies infrastructure, users who access information systems as third parties, and service, software, or hardware providers offering technical support to information systems.
Information Security aims to ensure the continuity of Information Systems to protect the reputation, reliability, and information assets of our Company and to continue business activities with minimal interruption. It also aims to increase the awareness, consciousness, and compliance levels of employees regarding security requirements, ensure compliance with third parties, and actively implement up-to-date technical security controls. Our company is managed with a risk-based approach.
OUR INFORMATION SECURITY OBJECTIVES
To document, certify, and continuously improve our Information Security Management System in accordance with the requirements of ISO 27001,
To act in line with the Company's Vision and Mission,
To reduce the impact of information security risks related to business continuity and ensure business continuity,
To protect and enhance the Company’s reputation against adverse effects based on information security,
To ensure the confidentiality, integrity, and accessibility of all information stored physically and electronically by fully complying with legal requirements, customer demands, operational and contractual conditions,
To raise awareness among users and employees about information security, minimize risks, and ensure they understand their responsibilities,
To define, assess, and improve the security requirements of the electronic infrastructure we provide services on, follow technological developments, and ensure service continuity,
To ensure an acceptable level of security for access to the system from outside the company,
To identify the information security requirements of parties, customers, and suppliers and ensure their compliance with the information security management system,
To protect the confidentiality of critical data such as strategic objectives, design, production, sales, supply-related data, as well as information of customers and employees related to our Products and Services,
To promptly detect and respond to situations that are contrary to Information Security, and to manage these activities in an integrated manner with other management systems we implement.
Masterline PVC and Aluminum Structural Elements Industry and Trade Inc.
Cookie Policy
PRIVACY AND COOKIE POLICY
This Privacy and Cookie Policy ("Policy") has been prepared by Masterline Pvc Building Components Industry and Trade Inc. (“Company”) regarding the processing of personal data of visitors ("visitor") who access and use the website operated by the Company ("www.masterline.com.tr") in accordance with the Law on the Protection of Personal Data No. 6698 (“Law”).
Cookies are small text files that store small amounts of information. They are stored on your device or network server via browsers by the websites you visit. When a website is loaded into your browser, cookies are stored on your device. Cookies help ensure the proper functioning of the website, enhance its security, and provide a better user experience. Session and local storage areas are also used for similar purposes. Our website does not use cookies; however, session and local storage functionalities are in use.
Cookies are used on our website to ensure that visitors can benefit from it efficiently. If you prefer not to use cookies, they can be deleted or blocked via browser settings. However, this may negatively affect the performance of our website. Unless the visitor changes the cookie settings in their browser, the use of cookies on this site is deemed to have been accepted.
1. Purpose of Processing Personal Data
Personal data obtained as a result of visiting our website is processed by our Company in accordance with Articles 5 and 6 of the Law for the following purposes:
To carry out the necessary operations for the execution of the commercial activities conducted by our Company and to realize the related business processes,
To carry out the necessary efforts to allow relevant persons to benefit from the products and services offered by our Company and to execute the relevant business processes,
To customize and promote the products and services offered by our Company according to the preferences, usage habits, and needs of relevant persons.
2. Parties to Whom Personal Data May Be Transferred and Purpose of Transfer
Personal data obtained through your visit to our website may be transferred to our business partners, suppliers, legally authorized public institutions, and private individuals in line with the purposes of processing and under the conditions and purposes set out in Articles 8 and 9 of the Law.
3. Method of Collecting Personal Data
Cookies are small text files stored on your device or network server by browsers on the websites you visit. Upon visiting our website, cookies may also be placed on domains such as google.com, facebook.com, twitter.com, instagram.com, linkedin.com, and youtube.com, with the visitor’s permission.
4. Purpose of Using Cookies
Our website uses first-party and third-party cookies. First-party cookies are mostly necessary for the proper functioning of the website and do not store your personal data. Third-party cookies are used to improve the performance, interaction, and security of our website, for advertising, and to provide a better overall service. These cookies help speed up your future interactions with our site. These cookies serve the following purposes:
Statistics: These cookies store information such as the number of visitors to the website, the number of unique visitors, the pages visited, the source of the visit, etc. These metrics help us analyze the performance of our website.
Marketing: These cookies are used to personalize the advertisements shown to you and make them more relevant. They also help track the effectiveness of advertising campaigns. The information stored in these cookies may be used by third-party providers to show ads on other websites in your browser.
Functional: These cookies help support non-essential functionalities on our website, such as embedding videos or sharing content on social media platforms.
Preferences: These cookies help remember your settings and browsing preferences, such as language choice, to enhance your experience during future visits.
The technical types of cookies used on our website are shown in the table below:
Cookie Type Description
Session Cookies Temporary cookies used during a visitor’s session, deleted once the browser is closed. Ensure proper functioning during the visit.
Persistent Cookies Improve functionality and provide faster and better service by remembering user preferences, stored in your device.
Technical Cookies Ensure the operation of the website and identify non-functional pages or areas.
Authentication Cookies Prevent the need to re-enter passwords on every page by recognizing users who log in.
Flash Cookies Used to activate media content such as images or sound.
Customization Cookies Remember user preferences like language across different pages of the site.
Analytical Cookies Monitor analytics such as visitor numbers, page views, scroll behaviors, and timestamps.
The main purposes for using cookies on our website are as follows:
To improve the services offered by enhancing the functionality and performance of the website,
To enhance the website and offer new features while personalizing existing ones according to user preferences,
To ensure the legal and commercial security of the website, the user, and our Company.
5. Controlling Cookie Preferences
Different browsers offer various methods to block and delete cookies used by websites. These settings must be changed in the browser to control or delete cookies. You can find more information on how to manage and delete cookies at www.allaboutcookies.org. Visitors can customize their cookie preferences by changing browser settings.
6. Rights of Data Subjects
Requests under Article 11 of the Law, which regulates the rights of data subjects, can be submitted to our Company via the Application Form available on our website at www.masterline.com.tr. Requests will be resolved as soon as possible and at the latest within thirty days, free of charge. However, if the process requires additional costs, fees may be charged according to the tariff set by the Personal Data Protection Board.
7. Enforcement of the Policy
This Policy enters into force on the date of publication. If the entire Policy or specific articles are updated, the effective date of the Policy will be revised accordingly.
Visitor Clarification Text
INFORMATION NOTICE ON THE PROCESSING OF VISITORS' PERSONAL DATA
Personal data of visitors may be processed by Masterline Pvc Building Components Industry and Trade Inc. (“Company”) for the purposes and legal reasons specified below.
Recording visitor information in the visitor logbook upon entry to our Company premises,
Ensuring the safety and security of the Company’s employees and visitors,
Camera recordings are taken of individuals (employees and visitors) via security cameras located at operational areas, emergency exits, and building/department entrance-exit points, in order to detect incidents such as theft, disputes, or unauthorized access.
Your personal data will be retained only for as long as necessary in accordance with the applicable laws or the purpose for which it is processed.
Protection of Personal Data and Data Controller
Your personal data will be processed in accordance with the Personal Data Protection Law No. 6698 (KVKK), regulations of the Personal Data Protection Authority, and other relevant legislation. As the Data Controller, Masterline Pvc Building Components Industry and Trade Inc. takes all necessary technical and administrative measures to ensure appropriate security to prevent unlawful processing, unauthorized access, and to maintain the confidentiality and integrity of your personal data.
As the Data Controller, Masterline may process your personal data in accordance with the applicable legislation and for the purposes explained below.
Purposes of Processing Personal Data
Your personal data may be processed by our Company in compliance with legal obligations and for the following purposes:
Recording visitor information in the visitor logbook upon entry to our Company premises,
Ensuring the safety and security of the Company’s employees and visitors,
Monitoring the premises through surveillance cameras placed at building or department entrances and exits, and other critical locations to detect incidents such as theft, disputes, or unauthorized access.
Your personal data will be retained for five years from the date of processing, in line with the legal requirements and the purpose for which it was processed.
Transfer of Processed Personal Data
Your personal data may be transferred, limited to the purposes listed above, to:
Shareholders, board of directors,
Business partners, suppliers, customers,
Authorized public institutions and private legal entities,
Auditors, consultants, lawyers,
Individuals or entities we have contracted with for services or cooperation,
In accordance with the conditions and purposes of data processing as specified in Articles 8 and 9 of Law No. 6698, and to fulfill legal obligations and ensure Company security.
Method and Legal Basis for Collecting Personal Data
Your personal data is collected by our Company based on the legal reasons stated above. The data may be collected:
In written or electronic form within our Company premises,
Based on name-surname or license plate information,
Verbally, or
Through closed-circuit camera systems located in our buildings.
The mentioned data is processed and may be transferred in accordance with Articles 5 and 6 of Law No. 6698 and for the purposes stated above.
Your Rights Regarding the Processing of Personal Data
In accordance with Article 11 of the Personal Data Protection Law (KVKK), you may contact our Company to:
Learn whether your personal data has been processed,
Request information if your personal data has been processed,
Learn the purpose of processing and whether it is being used in accordance with its purpose,
Know the third parties to whom personal data has been transferred domestically or abroad,
Request correction if the data is incomplete or inaccurately processed,
Request deletion or destruction of personal data under the conditions defined in the Law,
Request notification of the actions taken pursuant to the above requests to third parties to whom the data was transferred,
Object to the occurrence of a result against yourself through the exclusive analysis of processed data via automated systems,
Request compensation for any damages incurred due to unlawful processing of personal data.
Pursuant to Article 13, Paragraph 1 of the KVKK, you may submit your request to exercise the above rights in writing or through other methods determined by the Personal Data Protection Authority. For detailed information, please refer to the Data Subject Rights and Application Form available on our website at www.masterline.com.tr.

