PRIVACY NOTICE

Data Controller: CAGS TOBACCO TOBACCO AND TOBACCO PRODUCTS INDUSTRY AND TRADE JOINT STOCK COMPANY.
Fulya Mah. Büyükdere Cad. Torun Center A Blok No: 74a İç Kapı No: 19 Şişli/İstanbul

As CAGS TOBACCO TOBACCO AND TOBACCO PRODUCTS ("CAGS" or "Company"), in accordance with the Law on Protection of Personal Data No. 6698 ("KVKK") and related legislation, we have prepared this privacy notice to inform individuals, including visitors, customers, potential service recipients, job applicants, employees, business partners, platform users, and other individuals, about the personal data we process within the scope of our activities for the purposes of the Company.

What Data Do We Collect and What Is the Purpose of Data Collection?
We collect the following data within the scope of our company activities:
Identity Information
Contact Information
Identity Verification, Security, and Tracking Information
Financial Information
Employment Information
Education Information
Other Data
Data Category: Identity Information
Description: Data related to the identification of individuals.
Source: We collect identity information from our job applicants, employees, customers, potential service recipients, platform users, business partners, and visitors.
Content: Name, surname, gender, Turkish identification number, social security registration number, nationality, marital status, date of birth, place of birth, passport number, driver's license number, vehicle registration information, identity card/identification copy, driver's license copy, passport copy, etc.
Purpose of Data Collection: We collect the identity information of our job applicants for the purpose of conducting human resources activities related to the applied position.
We collect the identity information of our employees in accordance with our obligations arising from employment, social security, tax regulations, etc.

We collect the identity information of our customers to fulfill our legal obligations, provide support services, fulfill commercial requirements and legal obligations, and for advertising and marketing purposes, audit processes, and security purposes.
We collect the identity information of our platform users to fulfill our legal obligations.
We collect the identity information of our visitors for the purpose of ensuring security during building entry and exit and for future service relationships.
We collect the identity information of our business partners to fulfill our legal obligations, provide support services, issue invoices, carry out audit processes, monitor joint projects, and fulfill our obligations under contracts.
Legal Basis for Data Collection: The primary reason for collecting this data is compliance with relevant legislation.
Furthermore, we collect identity information based on the contractual relationship between us and the relevant individuals.
Sometimes, we collect identity information based on our legitimate interests and the principles adopted by our Company.
Data Collection Method: We collect data through printed forms and sometimes directly through company-shared electronic areas and electronic devices.
Data Category: Education Information
Description: Information necessary for the smooth provision of services within the scope of contractual relationship.
Source: We collect education data from our employees and job applicants.
Content: Position/title information, diplomas and certificates, work history and details, resume, educational background, social security employment entry declaration, social security employment exit declaration, blood type, criminal record, other health reports, photographs, insurance data, military service status, etc.
Purpose of Data Collection: We collect the education information of our employees and job applicants to fulfill our legal obligations, provide support services, fulfill commercial requirements and legal obligations, and for advertising and marketing purposes, audit processes, and security purposes.
Legal Basis for Data Collection: The primary reason for collecting this data is compliance with relevant legislation.
Furthermore, we collect education information based on the contractual relationship between us and the relevant individuals.
Data Collection Method: We collect data through printed forms and sometimes directly through company-shared electronic areas and electronic devices.
Data Category: Contact Information
Description: Personal data that enables communication with individuals.
Source: We collect contact information from our job applicants, employees, customers, potential service recipients, platform users, business partners, and visitors.
Content: Email address, residence address, mailing address, workplace address, workplace name and title, home phone number, mobile phone number, other phone and fax numbers, etc.
Purpose of Data Collection: We collect the contact information of our job applicants for the purpose of conducting human resources activities related to the applied position.
We collect the contact information of our employees in accordance with our obligations arising from employment, social security, tax regulations, etc.
We collect the contact information of our customers to fulfill our legal obligations, provide support services, fulfill commercial requirements and legal obligations, and for advertising and marketing purposes, audit processes, and security purposes.
We collect the contact information of our platform users to fulfill our legal obligations.
We collect the contact information of our visitors for the purpose of ensuring security during building entry and exit and for future service relationships.
We collect the contact information of our business partners to fulfill our legal obligations, provide support services, issue invoices, carry out audit processes, monitor joint projects, and fulfill our obligations under contracts.
Legal Basis for Data Collection: The primary reason for collecting this data is compliance with relevant legislation.
Furthermore, we collect contact information based on the contractual relationship between us and the relevant individuals.
Sometimes, we collect contact information based on our legitimate interests and the principles adopted by our Company.
Data Collection Method: We collect data through printed forms and sometimes directly through company-shared electronic areas and electronic devices.
Data Category: Financial Information
Description: Data such as bank account information, credit card information, invoice information, etc. Source: We collect financial information from our employees and customers.
Content: Bank account information, bank card information, credit card information, signature circulars, income information, asset information, payroll information, minimum income deduction information, information about disability tax liability, records related to salary garnishment, etc.
Purpose of Data Collection: We collect the financial information of our employees to fulfill our obligations arising from employment, social security, tax regulations, etc.
We collect the financial information of our customers to fulfill our legal obligations, provide support services, fulfill commercial requirements and legal obligations, and for advertising and marketing purposes, audit processes, and security purposes.

Legal Basis for Data Collection: The main reason for collecting the data is the obligations stated in the relevant legislation.
Additionally, we collect financial information due to the contractual relationship we have with the individuals.
At times, we also collect financial information for purposes such as including our employees in campaigns or promotions provided by banks or other financial institutions we collaborate with, based on our legitimate interests and Company principles.
Data Collection Method: We collect the data through printed forms and sometimes directly through company internal shared spaces and electronic devices.
Data Category: Personal Data
Description: These are the necessary information for the smooth continuation of the employment relationship.
Collected From: We collect employee data from job applicants and employees.
Content: Position/title information, diplomas and certificates, work history and details, curriculum vitae, education status, Social Security Institution (SGK) entry declaration, SGK departure declaration, blood type, entry health report, criminal record, disability report, former prisoner report, administrative and annual leave information, other health reports, photograph, insurance data, military service status, and similar data.
Purpose of Data Collection: We collect communication information of job applicants in order to carry out human resources activities related to the applied position.
We collect employees' personal data within the scope of our service agreement with them, our obligations arising from labor and social security, tax laws, and our legitimate interests.
Legal Basis for Data Collection: The main reason for collecting these data is the obligations stated in the relevant legislation.
Additionally, we collect personal information due to the contractual relationship we have with the individuals
At times, we collect these data based on our legitimate interests and Company principles, for example, to place employees in suitable positions.
Data Collection Method: We collect the data through printed forms and sometimes directly through company internal shared spaces and electronic devices.
Data Category: Other Data
Description: These are other data collected within the scope of our company activities. Collected From: We collect this data from our visitors.
Content: Visited person, purpose of the visit, date and time of the visit, and similar data. Purpose of Data Collection: Information related to visitors' visits is collected in order to identify potential service recipients.

Additionally, we collect this data for security reasons.
Legal Basis for Data Collection: The main reason for collecting these data is the obligations stated in the relevant legislation.
At times, we collect these data based on our legitimate interests and Company principles, for example, to improve the quality of the provided service or for security purposes.
Data Collection Method: We collect the data through printed forms and sometimes directly through company internal shared spaces and electronic devices.
Do We Transfer Your Personal Data to Third Parties?
Due to legal regulations in our country, identity information, contact information, and many other personal data mentioned above are shared with authorized entities explicitly stated in the legislation periodically or upon the requests of authorized authorities.
Additionally, they are shared with authorized individuals or institutions in case of a court order or upon the request of an administratively authorized institution explicitly stated in the law.
Apart from that, your personal data is limitedly shared with Business Partners and Suppliers (Financial Advisors, Logistics Companies, International Transfer Companies), official institutions (service providers, etc.) in order to perform the service and fulfill contractual obligations.
Do We Transfer Your Personal Data Abroad?
Your personal data can be transferred abroad only if one of the following conditions is met: With your explicit consent,
If one of the conditions stipulated in the Law on the Protection of Personal Data (KVKK) is met and sufficient protection exists in the country where the data will be transferred,
If one of the conditions stipulated in the KVKK is met, and although sufficient protection does not exist in the country where the data will be transferred, sufficient protection is committed by the relevant country and approval is obtained from the Personal Data Protection Board.
For example, if the service is provided through a foreign company, the information needs to be transferred abroad for the performance of the contract. Therefore, if consent is not given to such transfer, it will be impossible to perform the service mentioned in the contract.
How Long Are Your Personal Data Retained?
The retention periods of your personal data are as follows:
If there is a period specified by law or relevant legislation for the retention of data, the data must be retained for at least this period. Considering the possibilities such as a delayed request for a court order, a request from an authorized administrative authority or the occurrence of a dispute in which we may be involved, the retention periods of your data are determined by adding 6 months to 1 year to the periods prescribed by the legislation, and the data is deleted at the end of the determined period.
If there is no period specified in the legislation for the retention of the data processed, your data will be retained for the duration determined in accordance with the nature of our relationship and the period specified in the contract made with you. After the end of this relationship or the expiration of the period specified in the contract, your data will be deleted, destroyed, or anonymized without the need for any request from you.
If you request the deletion of your data before the retention period specified in the legislation, your request cannot be fulfilled.
If you request the deletion of your data that is not subject to a retention period and no longer serves a processing purpose, your data will be deleted within a maximum of 6 months.
What Are Your Rights Regarding Your Personal Data?
Regarding your personal data, you have the following rights:
To learn whether your personal data is processed or not,
If your personal data is processed, to request information regarding this,
To learn the purpose of processing your personal data and whether it is used in accordance with its purpose,
To know the third parties to whom your personal data is transferred domestically or abroad,
If your personal data is incomplete or inaccurate, to request its correction,
To request the deletion or destruction of your personal data within the framework of the conditions stipulated in the KVKK, and if the data is corrected or deleted, to request that these operations be notified to the third parties to whom your personal data is transferred,
In case an unfavorable result arises for you as a result of the analysis of processed data solely through automated systems, to object to this result,
In case your personal data is processed unlawfully and causes you to suffer damages, to request compensation for such damages.
How Can You Exercise Your Rights?
The Data Subject can submit their personal data-related requests: By sending a signed and written petition or CAGS PDPA Application Form, along with a photocopy of their ID, to the email address info@cagstobacco.com,
By personally applying to the Company with a valid ID document, and sending a signed written petition or CAGS PDPA Application Form to the address Fulya Mahallesi, Büyükdere Caddesi, Torun Center A Blok No: 74A İç Kapı No: 19 Şişli / İSTANBUL, along with a photocopy of their ID,
By sending an email to info@cagstobacco.com from the previously notified and registered email address in the Company's system.
According to the Communiqué on the Procedures and Principles of Application to the Data Controller, it is obligatory for the Data Subject's request to include their name, surname, signature if the request is written, T.R. identity number (passport number if the person making the application is a foreigner), the address of the residence or workplace for notification purposes, the registered electronic mail address if any, telephone and fax numbers, and information regarding the subject of the request.

The request should explicitly and clearly indicate the requested matter. Information and documents related to the request should be attached to the application.
If the request is made on behalf of someone else, the applicant must be specifically authorized in this regard and this authorization must be documented (special power of attorney). In addition, the application must include the applicant's identification and address information and be accompanied by identity verification documents.
Requests made by unauthorized third parties will not be taken into consideration.
How Long Does It Take to Respond to Your Requests Regarding the Processing of Your Personal Data?
Your requests regarding your personal data will be evaluated, and a response will be provided within a maximum of 30 days from the date of receipt. If your request is rejected, the reasoned rejection will be sent to the address specified in your application through electronic mail or postal services, or by any other means chosen from the options in the Data Subject Application Form.