Logo

Ruba Yapı

Personal Data Protection Policy

Ruba Yapı A.Ş. ("Company") attaches the utmost importance to the protection and processing of personal data within the scope of Law No. 6698 on Protection of Personal Data ("Law") and acts with this sensitivity in all its activities.

This Personal Data Protection and Processing Disclosure Text ("Disclosure Text") aims to ensure compliance with national and international legislation, especially the Law and General Data Protection Regulation (GDPR) of the European Union.

For detailed information, please visit https://www.rubayapi.com.

The purpose of the policy is to protect the fundamental rights and freedoms of individuals, especially the right to privacy as regulated in Article 20 of the Constitution, in the processes of protecting and processing personal data and to ensure that our Company fulfills its legal obligations in this regard.


1. DEFINITIONS

  • Explicit Consent: Informed, freely given consent based on information about a specific subject.
  • Anonymization: Rendering personal data unable to be associated with an identifiable person.
  • Data Subject: The real person whose personal data is processed.
  • Personal Data: Any information relating to an identified or identifiable real person.
  • Special Categories of Personal Data: Data requiring special protection that may lead to discrimination or harm if disclosed.
  • Data Processing: Any operation performed on data (collection, storage, transfer, deletion, etc.).
  • Data Controller: The real or legal person determining the purposes and means of processing personal data.

2. PROTECTION OF PERSONAL DATA

Ruba Yapı A.Ş. takes all necessary technical and administrative measures to prevent the unlawful processing, access, or use of personal data.

Regular audits are conducted, and awareness training is provided to employees.

In case of unlawful acquisition of personal data, notification is made to the Personal Data Protection Board and the relevant person as soon as possible.

Special categories of personal data are protected under stricter security measures.


3. PROCESSING AND TRANSFER OF PERSONAL DATA

Ruba Yapı A.Ş. processes personal data only for specific, explicit, and legitimate purposes; collects data to the extent necessary for the purpose and does not process more data than necessary.

In cases where there is no legal retention period, data is stored for the period required by the purpose, then deleted, destroyed, or anonymized.

Data processing without explicit consent is only carried out in cases permitted by the Law (e.g., legal obligation, contractual necessity, legitimate interest).

Data transfer is carried out in compliance with the Law only by taking necessary security measures.


4. TYPES OF PERSONAL DATA AND PROCESSING PURPOSES

Collected data: Identity, contact, location, personnel, legal transaction, customer transaction, security, financial, professional, marketing, visual/audio, membership, health, biometric, etc.

Processing Purposes:

  • Execution of human resources processes
  • Planning of commercial relationships
  • Fulfillment of legal obligations
  • Protection of Company security and assets

5. RIGHTS OF THE DATA SUBJECT

Pursuant to Article 11 of Law No. 6698, data subjects;

  • Have the right to learn whether their personal data is processed,
  • Request information,
  • Learn whether it is used for its purpose,
  • Know the third parties to whom it is transferred,
  • Request correction of incomplete or inaccurate data,
  • Request deletion or destruction,
  • Object to the result of the analysis by automated systems,
  • Have the right to claim compensation in case of damage.

Applications are responded to within 30 days.

Applications can be made through the communication channels available at https://www.rubayapi.com.

6. EXCEPTIONS

Personal data may be excluded from this Policy only in cases of individual use, art, press, science, or freedom of expression, provided that it does not violate the privacy of private life or public security.


7. DATA SECURITY

Ruba Yapı A.Ş. takes technical and administrative measures to prevent unauthorized access, loss, or damage of personal data:

  • Network and application security
  • Encryption and secure key management
  • Access authorization control
  • Privacy commitments
  • Backup, auditing, and record-keeping
  • Firewall, antivirus, unauthorized entry prevention systems
  • Secure destruction of data whose retention period has expired
  • Employees and service providers are informed and committed to data privacy obligations.