Skip to main content Scroll Top

Personal Data Protection & GDPR Compliance Policy

Personal Data Protection · KVKK · GDPR · Compliance Governance

Personal Data Protection & GDPR Compliance Policy

ATABAŞ GLOBAL DIŞ TİCARET A.Ş. · Data protection as a governance discipline

This Policy sets out the data protection compliance framework of ATABAŞ GLOBAL DIŞ TİCARET A.Ş. It defines how the Company governs personal data under the Turkish Personal Data Protection Law No. 6698 (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR): the principles we follow, the responsibilities we assign, the safeguards we maintain, and the procedures through which data subjects can exercise their rights. It operates at governance level and is read together with our Privacy Policy, which explains day to day data handling.

KVKKLaw No. 6698
GDPREU 2016/679
DefinedAccountability
30 DaysRequest Response Target

Compliance Snapshot

  • Data ControllerATABAŞ GLOBAL DIŞ TİCARET A.Ş.
  • Registered AddressSkyland İstanbul B Blok, Kat: 27, D: 389-390-391, 34485 Sarıyer, İstanbul, Türkiye
  • Trade Registry / MERSISİstanbul 227479-5 · 0836081381100001
  • Primary FrameworkKVKK (Law No. 6698) and secondary legislation
  • Extended FrameworkGDPR, where EU related processing applies
  • Supervisory Authority (TR)Personal Data Protection Authority (KVKK Kurumu)
  • Request Channel[email protected] · +90 212 801 64 60
  • Response TargetWithin 30 days (KVKK) / one month (GDPR)
  • Related PagesPrivacy Policy, Cookie Policy, Legal Notice
Purpose and Scope

Why this policy exists

Data protection at ATABAŞ GLOBAL is a governance commitment, not a formality. This Policy makes that commitment explicit and auditable.

ATABAŞ GLOBAL DIŞ TİCARET A.Ş. acts as data controller for the personal data it processes in its corporate, commercial and digital activities. This Policy applies to all personal data processed by the Company regardless of format or medium, and to all employees, managers, and — through contractual obligations — the service providers and processors acting on the Company's behalf.

The Policy covers data belonging to website visitors, business contacts, customer and supplier representatives, inquiry senders, and any other individuals whose personal data reaches the Company in the course of lawful business. It defines the standards that every processing activity must satisfy before it takes place and while it continues.

Where the GDPR applies — for example, where processing relates to individuals in the European Union in connection with our commercial activity — the Company applies the corresponding GDPR requirements alongside KVKK. Where the two frameworks differ, the stricter applicable standard is followed.

Core Principles

Principles governing every processing activity

KVKK Article 4 and GDPR Article 5 define the principles below. Each one is a binding internal standard at ATABAŞ GLOBAL.

Principle 01
Lawfulness, fairness and transparency

Personal data is processed lawfully, fairly and in a transparent manner, on a valid legal basis, with individuals informed through appropriate notices.

Principle 02
Purpose limitation

Data is collected for specified, explicit and legitimate purposes and is not further processed in a manner incompatible with those purposes.

Principle 03
Data minimization

Processing is limited to data that is adequate, relevant and necessary for the purpose. Data that is not needed is not collected.

Principle 04
Accuracy

Personal data is kept accurate and, where necessary, up to date. Inaccurate data is corrected or erased without undue delay.

Principle 05
Storage limitation

Data is retained only as long as required by the processing purpose or by the legislation that mandates its retention, and is then deleted, destroyed or anonymized.

Principle 06
Integrity, confidentiality and accountability

Appropriate technical and organizational measures protect the data, and the Company is able to demonstrate compliance with all of these principles.

Legal Bases

Conditions under which we process personal data

Every processing activity is mapped to a legal basis under KVKK Articles 5–6 and, where applicable, GDPR Article 6.

Legal BasisKVKK ReferenceGDPR ReferenceTypical Application at ATABAŞ GLOBAL
Explicit consentArt. 5/1Art. 6/1(a)Newsletters, optional cookies, marketing communications where consent is required.
Performance of a contractArt. 5/2(c)Art. 6/1(b)Orders, supplier onboarding, commercial correspondence leading to a transaction.
Legal obligationArt. 5/2(ç)Art. 6/1(c)Tax, accounting, customs, sanctions screening and record keeping duties.
Establishment or protection of a rightArt. 5/2(e)Art. 6/1(f)Managing claims, disputes and contractual evidence.
Legitimate interestsArt. 5/2(f)Art. 6/1(f)Website security, fraud prevention, corporate administration — always balanced against individual rights.
Special categories: ATABAŞ GLOBAL does not seek special category (sensitive) personal data in its ordinary business. If such data were ever required, it would be processed only under the strict conditions of KVKK Article 6 and GDPR Article 9.
Accountability

Roles and responsibilities

Compliance is assigned, not assumed. Responsibility for data protection is embedded in defined roles.

Role 01
Management

Approves this Policy, allocates the resources required for compliance, and treats data protection as part of corporate governance and risk management.

Role 02
Data protection coordination

Coordinates data subject requests, maintains processing records, monitors legislative changes, and manages relations with the Personal Data Protection Authority where required.

Role 03
All personnel and processors

Every employee handles personal data only for authorized purposes under confidentiality duties; processors act solely on documented instructions under data processing terms.

Processor management: Service providers that process personal data on behalf of ATABAŞ GLOBAL are selected with care, bound by contractual data protection obligations, and expected to apply security measures consistent with this Policy.
Data Subject Rights

Your rights under KVKK Article 11 and the GDPR

Data subjects may exercise the rights below free of charge, subject to the conditions in the applicable law.

RightWhat it allowsFramework
Learn and accessTo learn whether personal data is processed, request information about the processing, and obtain a copy where the law provides.KVKK Art. 11/a-b · GDPR Art. 15
Purpose and recipientsTo learn the purpose of processing, whether data is used consistently with it, and the third parties to whom data is transferred in Türkiye or abroad.KVKK Art. 11/c-ç · GDPR Art. 15
RectificationTo request correction of incomplete or inaccurate data, and notification of that correction to recipients.KVKK Art. 11/d · GDPR Art. 16
Erasure / destructionTo request deletion or destruction where the grounds for processing no longer exist, and notification of that action to recipients.KVKK Art. 11/e-f · GDPR Art. 17
ObjectionTo object to a result produced exclusively by automated analysis, and to processing based on legitimate interests or direct marketing where the GDPR applies.KVKK Art. 11/g · GDPR Art. 21-22
CompensationTo claim compensation for damage arising from unlawful processing of personal data.KVKK Art. 11/ğ · GDPR Art. 82
Restriction and portabilityWhere the GDPR applies, to request restriction of processing and portability of data provided by the data subject.GDPR Art. 18, 20
Withdraw consentTo withdraw consent at any time where processing relies on consent, without affecting earlier lawful processing.KVKK Art. 3 · GDPR Art. 7/3
Request Procedure

How a data subject request is handled

A defined procedure ensures every request receives a lawful, documented and timely response.

01
Submit the request
Send your request in writing to [email protected] or to the registered address (Huzur Mahallesi, Azerbaycan Caddesi, Skyland İstanbul B Blok No: 4B, Kat: 27, Daire: 389-390-391, 34485 Sarıyer, İstanbul), identifying the right you wish to exercise, in line with the KVKK Communiqué on Application Procedures.
02
Identity verification
To protect personal data, we may request information reasonably necessary to verify that the requester is the data subject or a duly authorized representative.
03
Assessment and response
The request is assessed against the applicable legal framework and answered free of charge as soon as possible and at the latest within 30 days under KVKK, or within one month under the GDPR where it applies.
04
Escalation route
If a data subject considers the response unsatisfactory, a complaint may be lodged with the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) under KVKK Article 14, or with the competent EU supervisory authority where the GDPR applies.
International Transfers

Cross border transfers under lawful safeguards

As an international trading company, ATABAŞ GLOBAL transfers personal data abroad only where a lawful transfer mechanism exists.

Personal data is transferred outside Türkiye only under the conditions of KVKK Article 9 — including explicit consent, adequacy decisions, appropriate safeguards such as standard contractual undertakings approved under Turkish law, or other mechanisms recognized by the legislation in force. Where the GDPR applies, transfers outside the EU/EEA rely on the mechanisms of GDPR Chapter V, such as adequacy decisions or standard contractual clauses.

The specific mechanism depends on the jurisdictions involved, the service model and the nature of the processing. Transfers are limited to what the commercial or operational purpose genuinely requires.

Security and Breach Management

Protecting data and responding when something goes wrong

Security measures are proportionate to the risk, and incident response is a defined obligation, not an improvisation.

Safeguard 01
Technical measures

Access controls, secure system configuration, provider oversight and protection of data against unauthorized access, alteration or loss, in line with KVKK Article 12 and GDPR Article 32.

Safeguard 02
Organizational measures

Confidentiality duties, need to know access, staff awareness, documented procedures and periodic review of retention and destruction practices.

Safeguard 03
Breach response

If personal data is obtained unlawfully, the Company notifies the affected data subjects and the Personal Data Protection Authority as soon as possible under KVKK Article 12/5, and applies the 72 hour notification discipline of GDPR Articles 33–34 where the GDPR applies.

Realistic standard: No system can be guaranteed risk free. The Company's obligation is to maintain reasonable, appropriate and demonstrable safeguards, and to respond to incidents lawfully and without delay.
Governance

Review, training and continuous compliance

Compliance is maintained through repetition and review, not a one time declaration.

Discipline 01
Policy review

This Policy is reviewed periodically and updated when legislation, guidance of the Personal Data Protection Authority, business activities or systems change.

Discipline 02
Awareness

Personnel handling personal data are made aware of their obligations under KVKK, the GDPR where relevant, and this Policy.

Discipline 03
Records and evidence

Processing purposes, legal bases, retention logic and request handling are documented so that compliance can be demonstrated, not merely asserted.

Frequently Asked Questions

Data protection questions, answered clearly

Precise answers about how ATABAŞ GLOBAL governs personal data protection.

Who is the data controller?

ATABAŞ GLOBAL DIŞ TİCARET ANONİM ŞİRKETİ, registered at the İstanbul Trade Registry under number 227479-5 (MERSIS 0836081381100001), with its registered address at Huzur Mahallesi, Azerbaycan Caddesi, Skyland İstanbul B Blok No: 4B, Kat: 27, Daire: 389-390-391, 34485 Sarıyer, İstanbul, Türkiye.

Which laws apply to my data?

KVKK (Law No. 6698) and its secondary legislation apply as the primary framework. Where processing relates to individuals in the European Union in connection with our activities, the GDPR applies alongside KVKK, and the stricter applicable standard is followed.

How do I exercise my KVKK or GDPR rights?

Send a written request to [email protected] or to the registered address, identifying the right you wish to exercise. After identity verification, you will receive a response free of charge within 30 days under KVKK, or within one month where the GDPR applies.

What happens if I am not satisfied with the response?

You may lodge a complaint with the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) under KVKK Article 14, or with the competent supervisory authority in your EU member state where the GDPR applies.

Does ATABAŞ GLOBAL transfer my data abroad?

Only where an international business purpose genuinely requires it and a lawful transfer mechanism under KVKK Article 9 or GDPR Chapter V is in place.

How is this Policy different from the Privacy Policy?

The Privacy Policy explains in practical terms what data is collected and how it is used. This Policy sets the governance framework behind that practice: the principles, legal bases, responsibilities, security discipline, breach response and rights procedures the Company commits to under KVKK and the GDPR.

Exercise your data protection rights

Submit a written request to [email protected] or contact ATABAŞ GLOBAL through the official channels on the website

Data protection, done as governance — documented, assigned and demonstrable.

Privacy Preferences
When you visit our website, it may store information through your browser from specific services, usually in form of cookies. Here you can change your privacy preferences. Please note that blocking some types of cookies may impact your experience on our website and the services we offer.