About this translation: This document is an English translation provided for information purposes only. H2O Organizasyon's legal obligations arise under Turkish law, and the binding text is the Turkish original. In the event of any discrepancy between the two versions, the Turkish text shall prevail.
Section 1Purpose and scope
This policy determines how long personal data processed by H2O Organizasyon ve İnsan Kaynakları Limited Şirketi will be retained, by what method it will be destroyed at the end of that period, and how the process will be supervised.
It derives from Article 7 of Law No. 6698 on the Protection of Personal Data and from the Regulation on the Deletion, Destruction or Anonymisation of Personal Data.
This document covers personal data collected through the h2o-organizasyon.com website and the communication channels connected with it. Data processes concerning staff working in field operations, suppliers and contracted clients fall outside the scope of this document and are managed separately in their own right.
Why do we publish this document? The obligation to prepare a retention and destruction policy is provided principally for data controllers who are required to register with VERBİS. Even though we are not subject to that registration requirement, we prepare and publish this document: putting in writing, in an auditable form, how long data will be kept is both a discipline for us and a safeguard for you.
Section 2Definitions
- Personal data
- Any information relating to an identified or identifiable natural person.
- Data subject
- The natural person whose personal data is processed — on this site, usually you, the visitor.
- Data controller
- The party that determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system — here, H2O.
- Data processor
- The party that processes data on the controller's behalf under authority given by the controller — such as the hosting provider.
- Destruction
- The collective term for the deletion, destruction or anonymisation of personal data.
- Deletion
- Rendering data inaccessible and unusable in any way by the relevant users.
- Erasure
- Rendering data inaccessible, irretrievable and unusable in any way by anyone.
- Anonymisation
- Rendering data such that it can in no way be associated with an identified or identifiable natural person, even if matched with other data.
- Periodic destruction
- The destruction of data whose retention period has expired, carried out at the intervals stated in this policy and on the controller's own initiative.
Section 3Recording media
Personal data is held on the media below. Each medium is protected with security measures appropriate to the data it holds.
| Medium | Data held | Format |
|---|---|---|
| Web server Hosted in Türkiye | Server access logs (IP, time, requested address, browser information) | Electronic — text file |
| Corporate email accounts | Form submissions, incoming and outgoing correspondence, attachments | Electronic |
| Mobile devices | WhatsApp correspondence, contact list entries | Electronic |
| The visitor's own browser | Record of cookie preference | Electronic — local storage |
| Google Analytics infrastructure | Visit statistics (where consent has been given) | Electronic — held by a third party |
| Office filing | Wet-signed KVKK applications and response correspondence | Physical — paper |
Section 4Grounds requiring retention
Legal grounds
- Law No. 6698 (KVKK) — the period necessary for the purpose of processing
- Law No. 6098, Turkish Code of Obligations — the ten-year general limitation period under Article 146
- Law No. 6102, Turkish Commercial Code — periods relating to the retention of commercial books and documents
- Law No. 213, Tax Procedure Law — five-year retention of documents relating to the taxable event
- Law No. 5651 — retention of traffic data for the period prescribed by law
- Law No. 6563 on the Regulation of Electronic Commerce — retention of consent records
Grounds arising from the purposes of processing
- Conducting the quotation process and establishing the contractual relationship
- Maintaining client relationships and being able to access past correspondence
- Ensuring information security and detecting misuse
- Establishing, exercising or protecting a right in any dispute
- Providing information to authorised institutions and bodies
Section 5Grounds requiring destruction
Personal data is destroyed in the following cases:
- The purpose requiring its processing ceases to exist
- The legal ground on which the processing rests ceases to exist
- The retention period prescribed by legislation expires
- Where processing rests solely on explicit consent, the data subject withdraws that consent
- The data subject's request for deletion or erasure is accepted
- Following the rejection of a deletion/erasure request, the Board finds in the data subject's favour
- It is established that the processing was unlawful from the outset
Section 6Retention and destruction periods
The table below shows the retention period for each type of data and when destruction takes place after that period ends.
| Type of data | Retention period | Start of the period | Time of destruction |
|---|---|---|---|
| Quote requests that do not proceed | 2 years | Date of last correspondence | The first periodic destruction thereafter |
| Records of discussions that become a contract | 10 years | End of the contract | The first periodic destruction thereafter |
| Email and WhatsApp correspondence | 2 years (10 years if a commercial relationship exists) | Date of last correspondence | The first periodic destruction thereafter |
| Server access logs | 1 year | Creation of the record | Automatic rotational deletion |
| Analytics data | 14 months | Collection of the data | Automatic deletion by Google Analytics |
| Record of cookie preference | 12 months | Saving of the preference | Lapses by itself on expiry of the period |
| KVKK applications and responses | 3 years | Giving of the response | The first periodic destruction thereafter |
| Tax and accounting documents | 5 years | Close of the relevant taxation period | The first periodic destruction thereafter |
Where data is subject to more than one period, the longest of them applies. Where there is an ongoing dispute, investigation or audit, the data concerned is retained until that process is complete, even if the period has expired.
Section 7Methods of destruction
Deletion
Data in electronic media is rendered inaccessible and unusable by the relevant users. For email records this is achieved by deleting the message and also emptying the trash; in file systems, by permanently removing the file.
Erasure
Physical documents are shredded irreversibly in a document shredder. Electronic storage media taken out of use (disks, memory cards) are physically destroyed or wiped by overwriting.
Anonymisation
For data whose statistical value is to be preserved, the fields that make a person identifiable are removed irreversibly. Anonymised data is no longer personal data and may therefore be retained indefinitely; care is taken, however, to ensure that the anonymisation is genuinely irreversible.
Data held by third parties
For data held by our service providers acting as data processors, an instruction to destroy is sent to the provider concerned and confirmation that destruction has taken place is obtained. For services with their own automatic retention periods, such as Google Analytics, the shortest possible period is selected and destruction is left to the platform's own mechanism.
Section 8Periodic destruction
Personal data whose retention period has expired is destroyed on our own initiative, without any request from the data subject. Under the Regulation, the periodic destruction interval may not exceed six months.
- Periodic destruction interval
- 6 months
- Destruction periods
- The first half of June and December each year
- Responsible
- The personal data contact person designated on behalf of the data controller
- Record
- Every destruction operation is recorded with its date and scope; the records are kept for at least 3 years
Destruction requests made on the application of a data subject do not wait for periodic destruction: the request is concluded within thirty days at the latest. If the request is accepted, the data is destroyed without delay and, where applicable, the third parties to whom it was transferred are informed. If the request is rejected, the reasons are explained in writing.
Section 9Technical measures
- All traffic between the website and the visitor is encrypted with TLS 1.2 or above
- Access to the server is made only with an encrypted key and is limited to authorised persons
- Browser security headers are enabled; content-type confusion and framing attacks are prevented
- Backup folders and configuration files are closed to access over the web
- Server and software components are updated regularly
- Server logs are deleted automatically on a rotational basis at the end of the set period
- There is no database, user account or payment infrastructure on the site; the attack surface is deliberately kept narrow
- Strong passwords and multi-factor authentication are used on corporate email accounts
Section 10Administrative measures
- Access to personal data is limited to those who genuinely need it to do their job
- Employees with access rights are under a written obligation of confidentiality
- Contracts are made with service providers acting as data processors, requiring that data be processed only on instruction
- The data collected is kept to the minimum needed for the purpose (data minimisation)
- Employees are briefed on the protection of personal data
- Access rights are removed without delay on a change of duties or departure
- The steps to be followed in the event of a data breach are determined in advance
Section 11Responsibility and allocation of duties
H2O Organizasyon ve İnsan Kaynakları Limited Şirketi, in its capacity as data controller, is responsible for the implementation of this policy. In practice, duties are allocated as follows:
| Duty | Responsible |
|---|---|
| Preparing, reviewing and updating the policy | Company management |
| Carrying out periodic destruction on time and recording it | Personal data contact person |
| Handling and responding to data subject applications | Personal data contact person |
| Implementing and maintaining technical measures | The authorised person / service provider giving IT support |
| Concluding and supervising contracts with data processors | Company management |
| Notifying the Board and the data subjects in the event of a breach | Company management |
Section 12Updating the policy
This policy is reviewed at least once a year. It is also updated when the legislation changes, when a new data processing activity begins, or when the service providers used change.
The current version is always published on this page; the last updated date and version number at the top of the page indicate the change. Previous versions of the policy can be shared on request.
You can send your questions about this policy to info@h2o-organizasyon.com.
