Data Retention and Destruction Policy
Last Updated: December 2024
AHMED EMİR EROĞLU - Nexlead Technology
Address: SANCAK MAH. TAŞER SK. C2-23 NO: 38 İÇ KAPI NO: 9 SELÇUKLU / KONYA
Phone: 0850 308 16 81
Email: info@nexlead.com.tr
1. Purpose of the Policy
This policy has been prepared to regulate the secure storage of personal data processed by Nexlead Technology ("Company") for legal periods, its preservation in accordance with business purposes, and its secure destruction when the legal period or purpose expires.
2. Scope
This policy covers all personal data collected, processed, stored and destroyed within the scope of the Company's activities. Company employees, business partners and third parties processing data are obliged to comply with the provisions of this policy.
3. Data Retention Periods
Personal data is stored in accordance with KVKK (Turkish GDPR), Tax Procedure Law, Turkish Commercial Code, other relevant legislation and Company internal procedures within the following principles:
- Personal data is stored for the minimum period specified in the relevant legal regulations.
- Data whose retention period has expired will be destroyed if not required for processing purposes.
- Customer and employee data is retained until contracts are fulfilled and legal obligations are completed.
- In case of court, prosecutor's office, official institution requests or legal disputes, relevant data is retained until the legal process is completed.
4. Data Storage Methods
Data is stored securely in physical and digital environments:
- Digital data is protected in access-controlled, encrypted and backed-up systems.
- Physical documents are kept in secure archive areas.
- The security of storage environments is regularly audited.
5. Data Destruction Process
The destruction of personal data is carried out in accordance with the nature of the data, retention period and legal requirements:
- Digital data is deleted or destroyed in an irretrievable manner.
- Physical data is destroyed by non-recyclable methods (e.g., shredding with destruction machines).
- The destruction process is documented by recording.
6. Authority and Responsibilities
- The data controller at Nexlead Technology is responsible for ensuring that data retention and destruction processes are carried out in compliance with legislation.
- All personnel processing data are obliged to take necessary measures for the security of personal data.
- The security of tools and methods used in data retention and destruction processes is regularly audited.
7. Policy Updates
This policy is updated in line with legal changes, technological developments and company needs. The updated policy is published at https://nexlead.com.tr and announced to all relevant parties.
As Nexlead Technology, we act meticulously in ensuring the security of personal data, storing it in compliance with legal legislation and destroying it on time.