PERSONAL DATA PROTECTION PRIVACY NOTICE
This Privacy Notice has been prepared by the Data Controller to inform you regarding which of your personal data is processed; for what purposes and by which methods it is processed; with whom it is shared; and the duration of its retention. This disclosure is provided within the scope of Article 10 of the Law on the Protection of Personal Data No. 6698 (KVKK).
As MESÇİ MEŞRUBAT GIDA İNŞAAT NAKLİYAT SANAYİ VE TİCARET LİMİTED ŞİRKETİ (the “Company”), we hereby present this Privacy Notice—covering all data categories and subject groups—to the public and relevant data subjects in accordance with Article 10 of the Law.
ARTICLE 1: DATA CONTROLLER
Your personal data may be processed by MESÇİ MEŞRUBAT GIDA İNŞAAT NAKLİYAT SANAYİ VE TİCARET LİMİTED ŞİRKETİ in its capacity as the Data Controller. The Data Controller refers to the legal or natural person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data filing system.
You may contact the Data Controller through the following channels:
Email: info@mescigrup.com.tr
Phone: 0850 888 00 63
Address: Asya Mahallesi Akçakale Caddesi Mesçi İş Merkezi No:265 Eyyübiye/Şanlıurfa
ARTICLE 2: PROCESSED DATA AND PURPOSES OF PROCESSING
The categories of personal data processed by our Company and their respective purposes are listed below:
Identity Data (Name-Surname, Parents’ Names, Date/Place of Birth, Marital Status, National ID No, etc.):
Execution of emergency management, information security, and recruitment/placement processes.
Fulfillment of employment contract obligations and statutory requirements.
Management of finance, accounting, audit, and internal investigation activities.
Operation of marketing, sales, and customer relationship management (CRM) workflows.
Maintenance of visitor records and management of organizational events.
Contact Data (Address, Email, Telephone No, etc.):
Execution of communication activities, audit/ethics operations, and physical space security.
Management of advertising, campaigns, promotions, and performance evaluation processes.
Location Data (Geographical coordinates, location information, etc.):
Ensuring physical space security and managing emergency/assignment processes.
Personnel Files (Payroll, recruitment documents, asset declarations, CVs, etc.):
Fulfillment of legal obligations arising from employment contracts and management of requests/complaints.
Legal Proceedings (Correspondence with judicial authorities, case file details, etc.):
Tracking and execution of legal affairs and internal investigations.
Customer Transactions (Invoices, promissory notes, checks, order details, etc.):
Execution of financial operations and customer satisfaction activities.
Physical Space Security (Entry/exit logs, CCTV recordings, etc.):
Ensuring workplace safety and occupational health and security (OHS) compliance.
Digital Security (IP addresses, website login/logout logs, passwords, etc.):
Maintenance of business operations and audit processes.
Risk Management (Data processed for commercial, technical, and administrative risks):
Managing corporate risk and assignment workflows.
Financial Data (Balance sheets, financial performance data, etc.):
Compliance with statutory regulations and execution of compensation policies.
Professional Experience (Diplomas, certifications, in-service training records):
Management of training activities, assignments, and contract processes.
Marketing Data (Purchase history, surveys, cookies, campaign data):
Conducting marketing analysis and performance evaluation.
Audio/Visual Records (Photos, voice recordings):
Ensuring physical security and managing archiving/storage activities.
Associations & Unions (Membership information):
Providing required information to authorized public institutions.
Health Data (Personal health records, medical reports, blood type):
Management of OHS activities and emergency processes.
Criminal Records (Criminal convictions and security measures):
Fulfillment of regulatory reporting and security protocols.
ARTICLE 3: PARTIES TO WHOM DATA MAY BE TRANSFERRED
Personal data may be transferred to authorized public institutions, natural persons, or private legal entities for the purpose of fulfilling legal obligations and executing business operations within the framework of the law.
ARTICLE 4: METHODS AND LEGAL GROUNDS FOR DATA COLLECTION
Personal data is collected based on the following legal grounds:
Explicit Consent, Contractual Necessity, and Statutory Requirements: For Identity, Personnel, Contact, Professional Experience, and Financial data of employees.
Legal Obligations and Legitimate Interests: For Health, Union, and Association data.
Legitimate Interests of the Data Controller: For Criminal Record, Physical Security, and Marketing/Financial data of customers.
Contractual Execution and Legal Compliance: For Customer Transaction data.
ARTICLE 5: RETENTION PERIODS
Personal data is retained for the following periods based on category, after which it is destroyed/anonymized:
Identity, Contact, Legal, Financial, Professional, Marketing, Health, Criminal Records: 5 Years
Location, Personnel, Physical Security, Audio/Visual, Union/Association: 3 Years
Digital Security, Risk Management: 5 Years
ARTICLE 6: RIGHTS OF THE DATA SUBJECT
Under the KVKK, you have the right to:
Learn whether your data is being processed.
Request information if your data has been processed.
Learn the purpose of processing and whether it is used accordingly.
Know the third parties to whom data is transferred (onshore/offshore).
Request correction of incomplete or inaccurate data.
Request the erasure or destruction of data.
Object to results derived exclusively from automated systems.
Claim compensation for damages arising from unlawful processing.
ARTICLE 7: APPLICATION PROCESS
You may exercise your rights by completing the Data Subject Application Form or by submitting a written request through the following methods:
In Person or via Mail: Asya Mahallesi Akçakale Caddesi Mesçi İş Merkezi No:265 Eyyübiye/Şanlıurfa
Via Email: info@mescigrup.com.tr (with a signed and scanned copy of the request).
Your application will be finalized within thirty (30) days at the latest, depending on the nature of the request.

