Dedeman Intranet Portal — Privacy Policy (Privacy Notice on the Protection and Processing of Personal Data)
Unofficial courtesy translation. The Turkish version of this document is the sole legally binding text; in case of any discrepancy, the Turkish original prevails. This translation is a DRAFT pending review by the Legal department.
DRAFT — Subject to the approval of the Data Protection Officer and the Legal department. Fields shown in square brackets will be completed by the relevant departments before entry into force.
1. Introduction and Purpose
This document has been prepared to explain how your personal data is processed when you use the Dedeman Intranet Portal (an internal web application intended for employees and authorized users).
This document serves two functions together:
- Privacy Policy — It sets out, in general terms, the principles under which the personal data of persons using the Portal is protected and processed.
- Privacy Notice — Pursuant to Article 10 of the Turkish Personal Data Protection Law No. 6698 (the “Law” or “PDPL”), it fulfills the data controller’s obligation to inform you (the duty to disclose) before processing your personal data.
Scope of this document (an important limitation): This document provides a privacy notice with respect to the personal data processed by Dedeman in its capacity as data controller. For certain user types (employees of hotels operating under the Dedeman brand pursuant to a franchise agreement — “franchise operations” — as well as business partners and contractors), the data controller capacity may not lie entirely with Dedeman. In such cases, this document constitutes a privacy notice only for the processing operations for which Dedeman is responsible; with respect to processing operations where that capacity lies with another party, the privacy notice of the relevant party shall govern. The details of the allocation of responsibility are set out in Section 12 of this document.
The meaning of certain concepts used in this document:
- Data controller: The person or organization that determines why and how personal data will be processed and is responsible for the establishment and management of the data filing system. Within the scope of this document, the data controller is the Dedeman entity identified below (“Dedeman” or the “Company”).
- Data subject: The natural person whose personal data is processed. For the purposes of this document, and to the extent of the data processed by Dedeman in its capacity as data controller, this scope includes the employees using the Portal, authorized franchise hotel employees, as well as business partners and contractors. In this document, the term “you” refers to the data subject within this limitation.
The purpose of this document is to explain to you, in a clear, comprehensible, and transparent manner, in which categories, for which purposes, on which legal grounds your data is processed, to whom it may be transferred, for how long it is retained, and which rights you hold in this respect.
2. Identity of the Data Controller
Your personal data is processed, in its capacity as data controller, by the organization whose details are set out below:
| Information | Content |
|---|---|
| Trade name | [Full trade name of the data controller] |
| Address | [Full address / registered head office address] |
| Trade registry / Central Registry System (MERSİS) number | [MERSİS number] |
| Data Controllers’ Registry Information System (VERBİS) registration number | [VERBİS registration number] |
| Website | [Corporate website] |
Data Protection Officer / Point of Contact:
You may direct any question, request, or application regarding the processing of your personal data to the Data Protection Officer function designated for this matter within the Company.
- Email: [Personal data protection application email address — the live corporate address of the Data Protection Officer]
- [Postal address / application unit]
The term Data Protection Officer refers to the role/unit within the Company responsible for monitoring the processes relating to the protection of personal data and for responding to data subject applications.
3. Definitions
The key concepts used in this document and their plain-language explanations are set out below:
- Personal data: Any information relating to an identified or identifiable natural person (for example, name and surname, email address, user account, session record).
- Special categories of personal data: Data that, by its nature, is more sensitive and afforded stronger legal protection. These are data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, dress and appearance, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
- Processing (processing of personal data): Any operation performed on data, such as obtaining, recording, storing, altering, transferring, classifying, using, or deleting personal data.
- Data controller: The person/organization that determines the purposes and means of processing personal data and is responsible for the data filing system.
- Data processor: The natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the controller (for example, companies providing technical services or cloud infrastructure).
- Data subject: The natural person whose personal data is processed.
- Privacy notice (disclosure): The data controller’s act of informing the data subject, before processing personal data, of the purposes and legal grounds for which the data is processed, the parties to whom it may be transferred, and the rights the data subject holds. This document contains such a privacy notice.
- Explicit consent: Consent relating to a specific matter, based on information, and declared with free will.
4. Categories of Personal Data Processed
During your use of the Portal, your personal data may be processed in the following categories. The actual scope of the data may vary depending on your user type (employee, franchise hotel employee, business partner/contractor) and the operations you perform on the Portal. These categories apply with respect to the data processed by Dedeman in its capacity as data controller (see Sections 1 and 12).
| Data category | Example data |
|---|---|
| Identity information | Name, surname, user/account identity, position/title information |
| Contact information | Corporate email address, [if any] corporate telephone/extension number |
| Personnel / employee information | The hotel/unit at which you work, department, role, and authorization information (to the extent required for Portal access) |
| User transaction and usage data | Content you view on the Portal, operations you perform, requests, form inputs, and preferences |
| Transaction security / system records (logs) | Login/logout records, authentication records, internet protocol address, device/browser information, access and activity logs, security audit trails |
Note regarding special categories of personal data: In the ordinary course of operations, the Portal does not aim to collect special categories of personal data. Should any processing of special categories of personal data become necessary, such processing shall be carried out solely on the basis of at least one of the processing conditions set out in Article 6 of the Law as in force since 1 June 2024 (limited conditions, including explicit consent) and with the additional security measures prescribed by the Board for special categories of data. In the processing of special categories of data, the processing conditions under Article 5 applicable to general personal data (for example, contract, legitimate interest) do not apply; such data may be processed only under the conditions of Article 6 (see Section 6).
5. Purposes of Processing Personal Data
Your personal data is processed for the following purposes:
- Providing access to the Portal and authentication — Enabling you to log in securely with your corporate identity (Single Corporate Sign-On) and verifying your identity (including Multi-Factor Authentication).
- Ensuring information and system security — Preventing unauthorized access, detecting misuse, investigating security incidents, and protecting the integrity of the system.
- Corporate communication and information sharing — Providing announcements, internal content, and information intended for employees.
- Providing services and content — Delivering the applications and content offered through the Portal to users with the correct role and authorization.
- Authorization and access management — Defining and managing appropriate access levels according to user type.
- Compliance with obligations — Fulfilling obligations arising from legislation, contracts, and corporate policies.
- Maintaining and improving service quality — Monitoring the proper functioning of the Portal, remedying errors, and carrying out improvement efforts.
6. Legal Grounds for Processing
Your personal data is processed on the basis of one or more of the processing conditions set out in Article 5 of the Law for general personal data and in Article 6 of the Law for special categories of personal data. These two regimes are separate: conditions under Article 5 such as contract, legitimate interest, and legal obligation apply only to general personal data; special categories of data cannot be processed on the basis of these conditions and may be processed solely under the conditions of Article 6.
The tables below match the processing purposes with the legal grounds. The matching in the table is illustrative; for each processing operation, the conditions set out in Article 5 (and, where necessary, Article 6) of the Law that are applicable to the situation shall be taken as the basis.
(1) General personal data — Article 5 of the Law
| Legal ground (Art. 5) | Relevant processing |
|---|---|
| Expressly provided for in laws | Processing of data in cases where the legislation expressly requires it |
| Processing of data of a person who is unable to give consent due to actual impossibility | Processing in cases where it is mandatory for the protection of the life or physical integrity of the data subject or another person, where the data subject is actually unable to give consent (not ordinary in the Portal context; applicable if relied upon in the future) |
| Being directly related to the conclusion or performance of a contract | Provision of Portal access and services within the scope of an employment/work relationship or a service/business partnership agreement |
| Fulfillment of the data controller’s legal obligation | Meeting obligations arising from legislation and, where necessary, maintaining system records |
| Having been made public by the data subject | Processing, in a manner consistent with the purpose of disclosure, of data that has been made public solely by the data subject (not ordinary in the Portal context; applicable if relied upon in the future) |
| Being mandatory for the establishment, exercise, or protection of a right | Use of necessary records in cases of legal dispute or audit |
| Being mandatory for the legitimate interest of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject | Ensuring information security, preventing unauthorized access, recording/monitoring for security purposes, and maintaining service quality |
(2) Special categories of personal data — Article 6 of the Law
| Legal ground (Art. 6/2) | Relevant processing |
|---|---|
| Explicit consent; or, without seeking explicit consent, the limited conditions set out in the second paragraph of Article 6 of the Law (for example: being expressly provided for in laws; inability to give consent due to actual impossibility; the data subject having made the data public; necessity for the establishment/exercise/protection of a right; obligations in the fields of employment, occupational health and safety, and social security; protection of public health; activities of foundations/associations/trade unions) and, in any case, the additional security measures prescribed by the Board | In its ordinary course, the Portal does not aim to process special categories of data (see Section 4). Should such processing become necessary, it shall rely solely on one of the limited conditions in this column; grounds under Article 5 such as contract/legitimate interest are not used for this category. |
Where processing is based on explicit consent, your consent shall be obtained separately and explicitly; you have the right to withdraw the explicit consent you have given at any time.
7. Method of Collecting Personal Data
Your personal data is collected by the following methods, through automated or partially automated means:
- Via corporate account and session: When you log in to the Portal with your Microsoft 365 / Entra corporate identity, your identity and session information is processed.
- Via automated system records: Session, access, and security records (logs) are automatically generated during your use of the Portal and the infrastructure.
- Via user inputs: Through the forms you complete, the requests you submit, and the operations you perform on the Portal.
8. Transfer of Personal Data
Your personal data may be transferred only for the realization of the purposes specified in this document and in compliance with the conditions set out in Articles 8 (domestic transfer) and 9 (transfer abroad) of the Law.
8.1. Domestic Transfer (Art. 8)
Your personal data may be transferred, to the extent necessary and on the basis of the relevant legal grounds, to the following categories of recipients:
- Relevant organizations / authorized units within the group — for the purposes of access management and corporate operations,
- Technical service and infrastructure providers (data processors) — for the purposes of operating, hosting, maintaining, and securing the Portal,
- Authorized public institutions and organizations — only in cases and within the limits required by legislation.
Contracts aimed at ensuring data security pursuant to Article 12 of the Law are concluded with the providers from whom services are received in the capacity of data processor.
8.2. Transfer Abroad (Art. 9)
Cloud computing (remote server services provided over the internet) is used in the authentication and content infrastructure of the Portal. Depending on the nature of the cloud infrastructure used, the operation of this infrastructure may involve the transfer of data to servers located abroad or access from abroad.
Where such a transfer occurs, it is carried out on the basis of the current regime set out in Article 9 of the Law. This regime is tiered, and the transfer is carried out according to whichever of the following grounds is applicable:
- Adequacy decision — Where the Personal Data Protection Board has issued an adequacy decision regarding the country, the sectors within the country, or the international organizations to which the transfer will be made, the transfer is carried out on the basis of that decision.
- Appropriate safeguards — Where there is no adequacy decision, the transfer may be carried out if one of the appropriate safeguards set out in the Law is provided by the parties (for example, the standard contract announced by the Board, binding corporate rules, a written undertaking, and the Board’s authorization). For transfers carried out on the basis of a standard contract, the obligation to notify the Board within five business days of the signing of the contract is fulfilled.
- Incidental cases — In the absence of the foregoing, the transfer may be carried out only where the incidental (exceptional) cases set out in Article 9 of the Law exist.
Any potential transfer to or access from abroad arising from the use of cloud services is in all cases carried out within the framework set out above and with the safeguards prescribed by the Law.
9. Retention Periods and Disposal
Your personal data is retained for as long as necessary for the purpose for which it is processed and for the statutory retention periods prescribed by the relevant legislation. When the purpose requiring retention ceases to exist and the statutory periods expire, your data is erased, destroyed, or anonymized pursuant to Article 7 of the Law.
- Retention and disposal processes are carried out in accordance with the Company’s Personal Data Retention and Disposal Policy.
- Disposal operations are carried out within the designated periodic disposal periods.
- In the event of termination of the employment/work relationship: When your work relationship ends, your Portal access is closed, and your access/session records and other personal data continue to be processed within the framework of the principles above; they are retained only to the extent that the purpose requiring their processing and the statutory retention periods continue, and are disposed of upon expiry of the period. No indefinite retention is carried out.
- Specific retention periods applied on the basis of data categories: [retention periods by data category — placeholder; reference to the Personal Data Retention and Disposal Policy]. This field shall be completed by the Data Protection Officer before entry into force, on the basis of the relevant Policy.
10. Data Security Measures
In order to prevent the unlawful processing of your personal data and unlawful access to your data, and to ensure the secure storage of the data, the Company takes appropriate administrative and technical measures pursuant to Article 12 of the Law. These measures include, in particular, the following:
Technical measures:
- Strengthening access through secure login with corporate identity (Single Corporate Sign-On) and Multi-Factor Authentication,
- Role- and authorization-based access control; ensuring that only authorized persons can access the relevant data,
- Keeping and monitoring system records (logs) and detecting security incidents,
- Applying appropriate protection methods (for example, encryption/access restrictions) at the transfer and storage stages,
- Up-to-date and secure infrastructure with regular security reviews.
Administrative measures:
- Defining access authorizations to the extent necessary (the principle of least privilege) and reviewing them regularly,
- Concluding contracts with data processors aimed at ensuring data security,
- Informing employees and authorized users about the protection of personal data,
- Use bound by rules consistent with the Terms of Use (Acceptable Use).
11. System Records and Monitoring
System records (logs) are kept to ensure the secure operation of the Portal and the infrastructure. These records may contain information such as login/logout, authentication, access, and security-related events.
- Purpose: System records are kept and used solely for the purposes of ensuring information security, preventing unauthorized access, investigating security incidents, remedying errors, and meeting legal obligations.
- Legal basis and balancing: These recording and monitoring operations are based primarily on the data controller’s legitimate interest (and the provisions of the relevant legislation). These operations are carried out by balancing them against the fundamental rights and freedoms of the data subject and observing proportionality.
- Proportionality: Monitoring is carried out in a manner limited and proportionate to these purposes; it does not aim to continuously and personally monitor the content of your personal communications.
- Consistency: This section is consistent with the monitoring and recording provisions of the Terms of Use (Acceptable Use) relating to the Portal. In the event of a conflict between the two documents, this document shall prevail in any assessment relating to the protection of personal data.
12. Business Partners, Contractors, and Franchise Operations — Distinction Between Data Controller / Data Processor
Different user types may use the Portal, and the role (capacity) in processing data may differ with respect to these persons. In any case, this document constitutes a privacy notice only for the data processed by Dedeman in its capacity as data controller (see Section 1):
- Employees and head office users: With respect to the personal data of these persons arising from their use of the Portal, the organization identified in Section 2 of this document acts in the capacity of data controller.
- Franchise hotel employees: With respect to franchise hotel employees who use the Portal to the extent access is granted, the data controller/data processor relationship is determined according to the relevant franchise arrangement. The specific allocation of roles is clarified by [the franchise data responsibility arrangement — placeholder]. With respect to processing operations for which responsibility does not lie with Dedeman, this document does not constitute a privacy notice; the privacy notice of the relevant party shall govern.
- Business partners and contractors: Business partners and contractors who use the Portal with controlled and limited access, through external identities that are provisioned for a fixed term and subject to regular access reviews, act, as a rule, within the framework of their own responsibility with respect to the data they collect in their own processes. The validity period and termination of these external identities is a corporate policy parameter; [access validity period and termination principles — determined by Head Office Information Technology / Human Resources policy]. The automatic expiry of such external identities upon the end of the term is not technically guaranteed; termination is ensured through regular access reviews and the relevant lifecycle processes.
Parties providing technical services on behalf of and at the instruction of the Company (for example, hosting/infrastructure providers) act in the capacity of data processor. With these parties, data processor agreements aimed at ensuring data security and at processing data only in accordance with the instructions given are concluded pursuant to Article 12 of the Law.
13. Rights of the Data Subject
Pursuant to Article 11 of the Law, you have the following rights with respect to your personal data, which you may exercise by applying to the data controller:
- To learn whether your personal data is being processed,
- To request information regarding your personal data if it has been processed,
- To learn the purpose of processing your personal data and whether it is used in accordance with that purpose,
- To know the third parties to whom your personal data is transferred domestically or abroad,
- To request the correction of your personal data in the event that it has been processed incompletely or inaccurately,
- To request the erasure or destruction of your personal data within the framework of the conditions set out in Article 7 of the Law,
- To request that the operations carried out pursuant to rights (5) and (6) be notified to the third parties to whom your personal data has been transferred,
- To object to the emergence of a result against you due to the analysis of your processed data exclusively by automated systems,
- To request the remedy of the damage in the event that you suffer damage due to the unlawful processing of your personal data.
In addition, in processing based on explicit consent, you have the right to withdraw your consent at any time (see Section 6). The withdrawal of consent does not affect the lawfulness of processing carried out up to the moment of withdrawal.
Regarding automated decision-making and profiling: The Portal does not aim to carry out any decision-making (profiling) regarding users exclusively by automated systems that produces legal consequences against the person or significantly affects the person in a similar manner. Should such processing become necessary, that processing shall be separately explained in this document, and your right to object under item 8 above is reserved.
14. Application Procedure
To exercise the rights listed in Section 13 above, you may submit your requests to the data controller in writing, pursuant to Article 13 of the Law, or by the other methods determined by the Personal Data Protection Board.
Application channels:
- Email: [Personal data protection application email address — the live corporate address of the Data Protection Officer],
- Written application / post: [application postal address — placeholder],
- [Other application channels, if any — placeholder].
What your application must contain: Name and surname, your signature if the application is in writing, information verifying your identity, the subject of your request, and, if any, the contact address at which you wish to be reached.
Response time: Your applications shall be concluded as soon as possible and within thirty (30) days at the latest, depending on the nature of the request. In the event that the operation also requires a cost, the fee in the tariff determined by the Personal Data Protection Board may be charged.
In the event that you are not satisfied with the outcome of your application or do not receive a response within the statutory period, your right to file a complaint with the Personal Data Protection Board is reserved.
15. Cookies and Similar Technologies
The Portal uses cookies and similar technologies in order to function properly and securely. A cookie is a small data file stored on your device through your browser.
- Mandatory (technical) cookies: These are mandatory for the Portal’s core functions, such as keeping your session open and maintaining secure login and authentication. Without these cookies, the Portal cannot operate securely; therefore, they may not be able to be disabled.
- Preference/functional cookies (if any): These may be used to remember user preferences (for example, language selection). [If such cookies are used, their scope and management — placeholder].
Because the Portal’s front-door authentication and content infrastructure operates in integration with corporate identity and content services (for example, Microsoft 365 / Entra and connected cloud components), session/identity cookies belonging to these services may also be used during the secure login and authentication flow. These cookies also serve the purpose of security and session continuity. [The specific scope and provider of the session/identity cookies used — a placeholder to be clarified with the confirmation of Head Office Information Technology].
Because the Portal is an internal application, cookies primarily serve the purpose of security and session continuity; no monitoring for marketing/advertising purposes is carried out. You may manage your cookie preferences through your browser settings; however, blocking mandatory cookies may prevent you from using the Portal.
16. Changes and Updates
This document may be updated from time to time in line with changes in legislation, updates made to the Portal, or corporate needs.
- The current document is always made accessible through the Portal.
- Significant changes are notified to users by appropriate methods (for example, a Portal announcement).
- The most current version of the document and its effective date are stated in the “Entry into Force” section below.
17. Contact
For your questions, opinions, and applications regarding the protection of your personal data, you may reach the following points of contact:
- Data Protection Officer (personal data protection function): [The live corporate application address of the Data Protection Officer]
- Legal department / relevant unit: [Legal / relevant unit contact — placeholder]
18. Entry into Force
| Information | Content |
|---|---|
| Document name | Dedeman Intranet Portal — Privacy Policy (Privacy Notice on the Protection and Processing of Personal Data) |
| Version | v1.0 — DRAFT |
| Status | Subject to the approval of the Data Protection Officer and the Legal department |
| Effective date | 1 April 2026 |
| Prepared by / owner | [Data Protection Officer / Legal department — placeholder] |
Preconditions for entry into force (must be completed before entry into force):
- The data controller identity information (trade name, address, MERSİS, VERBİS, website) is completed; the VERBİS registration obligation is confirmed.
- The personal data protection application address is clarified; the planned role-based mailbox (
kvkk@dedeman.com) is published as the primary channel only after active forwarding is confirmed. - The Legitimate Interest Balancing Assessment (Balancing Test) for monitoring/recording based on legitimate interest is completed (see Sections 6 and 11).
- The specific basis for the transfer abroad (adequacy decision / appropriate safeguard / incidental case) is clarified by verifying the actual data-residency status of the cloud infrastructure used (see 8.2).
- The specific retention periods by data category are completed on the basis of the Personal Data Retention and Disposal Policy (see Section 9).
This document becomes effective when it is approved by the authorized departments, the above preconditions are completed, and the effective date is determined. Until approval, it is of DRAFT nature, and the fields in square brackets will be completed by the relevant departments.