Personal Data Protection & GDPR Compliance Policy
ATABAŞ GLOBAL DIŞ TİCARET A.Ş. · Data protection as a governance discipline
This Policy sets out the data protection compliance framework of ATABAŞ GLOBAL DIŞ TİCARET A.Ş. It defines how the Company governs personal data under the Turkish Personal Data Protection Law No. 6698 (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR): the principles we follow, the responsibilities we assign, the safeguards we maintain, and the procedures through which data subjects can exercise their rights. It operates at governance level and is read together with our Privacy Policy, which explains day to day data handling.
Compliance Snapshot
- Data ControllerATABAŞ GLOBAL DIŞ TİCARET A.Ş.
- Registered AddressSkyland İstanbul B Blok, Kat: 27, D: 389-390-391, 34485 Sarıyer, İstanbul, Türkiye
- Trade Registry / MERSISİstanbul 227479-5 · 0836081381100001
- Primary FrameworkKVKK (Law No. 6698) and secondary legislation
- Extended FrameworkGDPR, where EU related processing applies
- Supervisory Authority (TR)Personal Data Protection Authority (KVKK Kurumu)
- Request Channel[email protected] · +90 212 801 64 60
- Response TargetWithin 30 days (KVKK) / one month (GDPR)
- Related PagesPrivacy Policy, Cookie Policy, Legal Notice
Why this policy exists
Data protection at ATABAŞ GLOBAL is a governance commitment, not a formality. This Policy makes that commitment explicit and auditable.
ATABAŞ GLOBAL DIŞ TİCARET A.Ş. acts as data controller for the personal data it processes in its corporate, commercial and digital activities. This Policy applies to all personal data processed by the Company regardless of format or medium, and to all employees, managers, and — through contractual obligations — the service providers and processors acting on the Company's behalf.
The Policy covers data belonging to website visitors, business contacts, customer and supplier representatives, inquiry senders, and any other individuals whose personal data reaches the Company in the course of lawful business. It defines the standards that every processing activity must satisfy before it takes place and while it continues.
Where the GDPR applies — for example, where processing relates to individuals in the European Union in connection with our commercial activity — the Company applies the corresponding GDPR requirements alongside KVKK. Where the two frameworks differ, the stricter applicable standard is followed.
Principles governing every processing activity
KVKK Article 4 and GDPR Article 5 define the principles below. Each one is a binding internal standard at ATABAŞ GLOBAL.
Personal data is processed lawfully, fairly and in a transparent manner, on a valid legal basis, with individuals informed through appropriate notices.
Data is collected for specified, explicit and legitimate purposes and is not further processed in a manner incompatible with those purposes.
Processing is limited to data that is adequate, relevant and necessary for the purpose. Data that is not needed is not collected.
Personal data is kept accurate and, where necessary, up to date. Inaccurate data is corrected or erased without undue delay.
Data is retained only as long as required by the processing purpose or by the legislation that mandates its retention, and is then deleted, destroyed or anonymized.
Appropriate technical and organizational measures protect the data, and the Company is able to demonstrate compliance with all of these principles.
Conditions under which we process personal data
Every processing activity is mapped to a legal basis under KVKK Articles 5–6 and, where applicable, GDPR Article 6.
| Legal Basis | KVKK Reference | GDPR Reference | Typical Application at ATABAŞ GLOBAL |
|---|---|---|---|
| Explicit consent | Art. 5/1 | Art. 6/1(a) | Newsletters, optional cookies, marketing communications where consent is required. |
| Performance of a contract | Art. 5/2(c) | Art. 6/1(b) | Orders, supplier onboarding, commercial correspondence leading to a transaction. |
| Legal obligation | Art. 5/2(ç) | Art. 6/1(c) | Tax, accounting, customs, sanctions screening and record keeping duties. |
| Establishment or protection of a right | Art. 5/2(e) | Art. 6/1(f) | Managing claims, disputes and contractual evidence. |
| Legitimate interests | Art. 5/2(f) | Art. 6/1(f) | Website security, fraud prevention, corporate administration — always balanced against individual rights. |
Roles and responsibilities
Compliance is assigned, not assumed. Responsibility for data protection is embedded in defined roles.
Approves this Policy, allocates the resources required for compliance, and treats data protection as part of corporate governance and risk management.
Coordinates data subject requests, maintains processing records, monitors legislative changes, and manages relations with the Personal Data Protection Authority where required.
Every employee handles personal data only for authorized purposes under confidentiality duties; processors act solely on documented instructions under data processing terms.
Your rights under KVKK Article 11 and the GDPR
Data subjects may exercise the rights below free of charge, subject to the conditions in the applicable law.
| Right | What it allows | Framework |
|---|---|---|
| Learn and access | To learn whether personal data is processed, request information about the processing, and obtain a copy where the law provides. | KVKK Art. 11/a-b · GDPR Art. 15 |
| Purpose and recipients | To learn the purpose of processing, whether data is used consistently with it, and the third parties to whom data is transferred in Türkiye or abroad. | KVKK Art. 11/c-ç · GDPR Art. 15 |
| Rectification | To request correction of incomplete or inaccurate data, and notification of that correction to recipients. | KVKK Art. 11/d · GDPR Art. 16 |
| Erasure / destruction | To request deletion or destruction where the grounds for processing no longer exist, and notification of that action to recipients. | KVKK Art. 11/e-f · GDPR Art. 17 |
| Objection | To object to a result produced exclusively by automated analysis, and to processing based on legitimate interests or direct marketing where the GDPR applies. | KVKK Art. 11/g · GDPR Art. 21-22 |
| Compensation | To claim compensation for damage arising from unlawful processing of personal data. | KVKK Art. 11/ğ · GDPR Art. 82 |
| Restriction and portability | Where the GDPR applies, to request restriction of processing and portability of data provided by the data subject. | GDPR Art. 18, 20 |
| Withdraw consent | To withdraw consent at any time where processing relies on consent, without affecting earlier lawful processing. | KVKK Art. 3 · GDPR Art. 7/3 |
How a data subject request is handled
A defined procedure ensures every request receives a lawful, documented and timely response.
Cross border transfers under lawful safeguards
As an international trading company, ATABAŞ GLOBAL transfers personal data abroad only where a lawful transfer mechanism exists.
Personal data is transferred outside Türkiye only under the conditions of KVKK Article 9 — including explicit consent, adequacy decisions, appropriate safeguards such as standard contractual undertakings approved under Turkish law, or other mechanisms recognized by the legislation in force. Where the GDPR applies, transfers outside the EU/EEA rely on the mechanisms of GDPR Chapter V, such as adequacy decisions or standard contractual clauses.
The specific mechanism depends on the jurisdictions involved, the service model and the nature of the processing. Transfers are limited to what the commercial or operational purpose genuinely requires.
Protecting data and responding when something goes wrong
Security measures are proportionate to the risk, and incident response is a defined obligation, not an improvisation.
Access controls, secure system configuration, provider oversight and protection of data against unauthorized access, alteration or loss, in line with KVKK Article 12 and GDPR Article 32.
Confidentiality duties, need to know access, staff awareness, documented procedures and periodic review of retention and destruction practices.
If personal data is obtained unlawfully, the Company notifies the affected data subjects and the Personal Data Protection Authority as soon as possible under KVKK Article 12/5, and applies the 72 hour notification discipline of GDPR Articles 33–34 where the GDPR applies.
Review, training and continuous compliance
Compliance is maintained through repetition and review, not a one time declaration.
This Policy is reviewed periodically and updated when legislation, guidance of the Personal Data Protection Authority, business activities or systems change.
Personnel handling personal data are made aware of their obligations under KVKK, the GDPR where relevant, and this Policy.
Processing purposes, legal bases, retention logic and request handling are documented so that compliance can be demonstrated, not merely asserted.
Data protection questions, answered clearly
Precise answers about how ATABAŞ GLOBAL governs personal data protection.
Who is the data controller?
ATABAŞ GLOBAL DIŞ TİCARET ANONİM ŞİRKETİ, registered at the İstanbul Trade Registry under number 227479-5 (MERSIS 0836081381100001), with its registered address at Huzur Mahallesi, Azerbaycan Caddesi, Skyland İstanbul B Blok No: 4B, Kat: 27, Daire: 389-390-391, 34485 Sarıyer, İstanbul, Türkiye.
Which laws apply to my data?
KVKK (Law No. 6698) and its secondary legislation apply as the primary framework. Where processing relates to individuals in the European Union in connection with our activities, the GDPR applies alongside KVKK, and the stricter applicable standard is followed.
How do I exercise my KVKK or GDPR rights?
Send a written request to [email protected] or to the registered address, identifying the right you wish to exercise. After identity verification, you will receive a response free of charge within 30 days under KVKK, or within one month where the GDPR applies.
What happens if I am not satisfied with the response?
You may lodge a complaint with the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) under KVKK Article 14, or with the competent supervisory authority in your EU member state where the GDPR applies.
Does ATABAŞ GLOBAL transfer my data abroad?
Only where an international business purpose genuinely requires it and a lawful transfer mechanism under KVKK Article 9 or GDPR Chapter V is in place.
How is this Policy different from the Privacy Policy?
The Privacy Policy explains in practical terms what data is collected and how it is used. This Policy sets the governance framework behind that practice: the principles, legal bases, responsibilities, security discipline, breach response and rights procedures the Company commits to under KVKK and the GDPR.
Exercise your data protection rights
Submit a written request to [email protected] or contact ATABAŞ GLOBAL through the official channels on the website
Data protection, done as governance — documented, assigned and demonstrable.

