Dedeman Intranet Portal — Terms of Use (Acceptable Use Agreement)
Unofficial courtesy translation. The Turkish version of this document is the sole legally binding text; in case of any discrepancy, the Turkish original prevails. This translation is a DRAFT pending review by the Legal department.
DRAFT — Subject to review and approval by the Legal department. The bracketed fields ([…]) in this text are placeholders to be verified and completed by the relevant units (Legal · Information Technology · Human Resources · Data Protection Officer) prior to entry into force.
1. Purpose and Scope
1.1. These Terms of Use (the “Terms”) govern the rights and obligations of all users who access and use the Dedeman Intranet Portal (the “Portal”), together with the principles concerning the secure, lawful use of the Portal in a manner respectful of corporate values.
1.2. These Terms cover employees working at hotels operated by Dedeman and at its head office (central) units, employees of franchise hotels (independently operated establishments bound by a licence to use the brand) who have been granted access, as well as business partners and contractors (external persons or organizations that have undertaken, by contract, to perform a specific job or service for Dedeman) who have been granted controlled access.
1.3. The Portal is an internal platform that supports corporate communication, information sharing, employee services, and access to connected corporate services. The Portal is used solely for corporate purposes and in accordance with these Terms.
2. Definitions
The terms used in these Terms shall have the following meanings:
| Term | Description |
|---|---|
| Portal | The Dedeman Intranet Portal; the entirety of the front end (the web application the user accesses) made available to employees and authorized users, together with the underlying content infrastructure. |
| User | Any natural person who has been granted access to the Portal and uses it. |
| Corporate Account | The digital account through which the User’s identity is authenticated, defined via the corporate identity system (corporate identity account). |
| Single Sign-On with a Single Corporate Identity | A method enabling sign-in to multiple corporate systems with a single corporate identity, eliminating the need to enter a separate password for each system. |
| Multi-Step Authentication | Confirmation of identity through a second verification step in addition to the password (for example, an approval received on a phone). |
| Confidential Information | Any and all information, documents, and data of a corporate, commercial, financial, operational, or personal nature that is not publicly available. |
| Business Partner | An external person or organization that provides services within the framework of a contractual relationship with Dedeman and is granted controlled/restricted access, together with the employees they authorize. |
| Contractor | An external person or organization that undertakes, by contract, to perform a specific job or service for Dedeman and is granted controlled/restricted access for the duration of the assignment. |
| Personal Data | Any information relating to an identified or identifiable natural person. |
| Data Controller | The person or organization that determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system. |
| Information Classification | The categorization of information according to its level of confidentiality and sensitivity, and the determination of the applicable sharing and protection rules for each category. |
| Connected Services | Other corporate systems and services accessed through the Portal or with the corporate identity, including the corporate learning platform. |
3. Acceptance and Entry into Force
3.1. By accessing and using the Portal, the User declares that they have read and understood these Terms and accept being bound by them.
3.2. Upon first access to the Portal, the User’s confirmation that they have seen and accepted these Terms is obtained; this confirmation is recorded together with the date and the user’s identity. Persons who do not accept the Terms may not use the Portal.
3.3. These Terms are to be construed as a whole together with the applicable employment contract, service contract, corporate policies, and the legislation in force, and supplement them.
4. Access and Account Security
4.1. Access to the Portal is provided through the corporate identity system via single sign-on with a single corporate identity and multi-step authentication. The authentication steps are necessary for the security of both the User and the organization.
4.2. Access is defined according to role and authorization level:
- Dedeman hotel employee: The account is created within the scope of the recruitment and onboarding process conducted by Human Resources; the approval workflow is subject to the relevant internal procedure.
- Franchise hotel employee: Access is granted through the contact authorized by the relevant franchise establishment and in coordination with Human Resources.
- Head office (central) employee: The account is created within the scope of the recruitment and onboarding process conducted by Human Resources.
- Business Partner / Contractor: Access is controlled and restricted; the relevant account is defined in coordination with Human Resources and through the Dedeman contact. Such accounts are defined for a fixed term and reviewed at regular intervals [period — to be determined by Legal and Information Technology].
4.3. The Corporate Account is personal. The User shall not share their account and credentials with anyone, shall not sign in on behalf of another person, and shall not use another person’s account.
4.4. The User is obliged to keep their password, the information relating to the second verification step, and their devices confidential and to protect them against unauthorized access. Password renewal is performed through the corporate identity system’s self-service password reset feature to the extent that this feature is enabled; where this feature is not enabled, password renewal is requested through the Information Technology contact.
4.5. When the User has finished their work on shared or unattended devices, they shall sign out and lock their device against unauthorized access.
4.6. Where the User suspects that their account has been used without authorization or that its security has been compromised, they shall report the situation without delay to the relevant information security or Information Technology contact.
5. Acceptable Use
5.1. The Portal is used solely for carrying out corporate duties and achieving corporate objectives.
5.2. The User uses the Portal in a manner consistent with the principles of corporate courtesy, respect, and integrity.
5.3. The User uses Portal resources in a measured and reasonable manner; they refrain from conduct that would adversely affect the continuity of the systems and other users’ ability to benefit from the service.
5.4. The User uses the information they access through the Portal only within the scope of their role and authorization, and only to the extent they need to know.
6. Prohibited Use
The User may not use the Portal for the purposes and in the manners exemplified below:
6.1. Producing, sharing, storing, or transmitting content contrary to the law, morality, or corporate policies.
6.2. Engaging in words, images, or conduct that are harassing, discriminatory, demeaning, threatening, or that violate personal rights.
6.3. Spreading malware (malicious code); performing operations that would damage or disrupt systems, data, or the network.
6.4. Extracting, copying, reproducing, or exporting data without authorization, or sharing it with unauthorized persons or organizations.
6.5. Attempting to circumvent security measures, bypass access limits, escalate privileges, or impersonate other users.
6.6. Using the Portal or the resources on it for personal commercial gain or for activities outside corporate purposes.
6.7. Engaging in uses that infringe copyright, trademark, or other intellectual property rights.
7. Information Security Obligations
7.1. The User acts in accordance with the confidentiality level of the information they access (information classification); they share confidential and limited-distribution information only with authorized persons and through secure methods.
7.2. The User takes care to ensure that the devices through which they access the Portal are up to date and protected; they comply with corporate security requirements and device usage rules.
7.3. The User does not leave confidential information in environments accessible to unauthorized persons; they pay attention to the security of printouts, screens, and portable media.
7.4. When the User notices a security incident, a suspected data breach, or an unusual situation, they report it without delay to the relevant security or Information Technology contact. This notification initiates the organization’s incident response process; where a data breach is involved, the notification obligations prescribed by the relevant legislation (including, in the case of personal data breaches, notifications to be made to the Personal Data Protection Board and to the affected persons) are fulfilled by the organization.
8. Protection of Personal Data
8.1. The processing of personal data is carried out in accordance with the Turkish Personal Data Protection Law No. 6698 (the “Law”) and the relevant legislation, as well as the corporate privacy policies.
8.2. Detailed information regarding the purposes of processing, the legal bases, the principles of transfer, the retention periods, and the rights of the data subject in respect of personal data processed through the Portal is provided to the User by means of the privacy notice prepared pursuant to Article 10 of the Law. The privacy notice is made accessible through the Portal together with these Terms.
8.3. The User processes the personal data they access by reason of their role only for the determined purposes, in a lawful manner, to the extent they need to know, and by taking the necessary security measures.
8.4. The retention and destruction of personal data is carried out in accordance with the organization’s Personal Data Retention and Destruction Policy and the periodic destruction schedule; retention periods are subject to the relevant legislation and the principles set out in that policy.
8.5. In the processing of personal data relating to franchise hotel employees, business partners, and contractors, the manner in which the status of data controller is allocated among the parties is determined within the framework of the relevant contract and legislation. As a rule, with respect to the data of a franchise establishment’s employee, the relevant establishment is the data controller for its own employees; Dedeman may hold the status of data controller within the scope relating to the brand and shared systems. The data subject may submit an application concerning processing that pertains to them to the establishment where they work and, where necessary, to Dedeman’s Data Protection Officer.
8.6. Rights of the data subject (Article 11 of the Law). With respect to their personal data, the User has the right to:
- learn whether their personal data is processed,
- request information if it has been processed,
- learn the purpose of processing and whether it is used in accordance with its purpose,
- know the third parties to whom it is transferred domestically or abroad,
- request its rectification if it has been processed incompletely or incorrectly,
- request its erasure or destruction within the conditions set out in the legislation,
- request that rectification, erasure, and destruction operations be notified to the third parties to whom the data has been transferred,
- object to a result arising against them as a consequence of analysis carried out exclusively by automated systems,
- request compensation for the damage in the event they suffer damage due to unlawful processing.
8.7. Application procedure. The data subject may submit an application concerning the above rights through the channels specified in the organization’s privacy notice and Privacy Policy. Applications are concluded within the period prescribed by the legislation (as a rule, within thirty days at the latest). The point of contact for applications, requests, and questions relating to the protection of personal data is set out in the communication section in Article 19 of these Terms.
9. Confidentiality and Trade Secrets
9.1. The User protects the corporate, commercial, and third-party confidential information they access through the Portal; they do not share it with unauthorized persons and do not use it for purposes other than their role.
9.2. Information in the nature of trade secrets, as well as information of competitive, financial, or operational value, is protected with particular care.
9.3. The confidentiality obligation continues for a reasonable period after the termination of the User’s Portal access or of their relationship with the organization, in accordance with the nature of the information concerned and the requirements of the legislation.
10. Intellectual Property
10.1. The content, design, software, trademarks, logos, text, images, and other materials contained in the Portal belong to Dedeman or to the relevant rights holders, and their intellectual property rights are protected.
10.2. The User uses these materials only within the scope of their role and authorization; they may not reproduce, distribute, modify, or use them for purposes outside the organization without the rights holder’s permission.
10.3. Rights relating to content produced by the User in the Portal within the scope of their role are assessed within the framework of the provisions of the contract and the legislation.
11. Content and Communication Rules
11.1. The User is responsible for the content they share through the Portal; they take care to ensure that the information they share is accurate, lawful, and aligned with the purpose of their role.
11.2. Corporate communication is conducted in a respectful, constructive, and inclusive language; discriminatory, hurtful, or expressions contrary to corporate values are avoided.
11.3. When sharing content or personal data belonging to others, the User shows respect for the rights of the persons concerned and the requirements of confidentiality.
12. Workplace System Records and Auditing
12.1. In order to ensure the security, continuity, and lawful use of the Portal, system records (access and transaction logs) may be kept and audits conducted in a manner that is compliant with the legislation and proportionate.
12.2. These records and audits are subject to the following principles:
- Purpose: they are carried out solely for legitimate corporate purposes such as information security, the continuity of systems, the prevention of misuse, and ensuring compliance with obligations.
- Legal basis: the processing of records is based on the legitimate interest of the data controller and the provisions of the relevant legislation; in processing based on legitimate interest, the necessary balancing-of-interests assessment is carried out.
- Scope: the records kept are limited to system records such as sign-in/sign-out, access, and transaction information; the content of communications is not monitored beyond the limits of proportionality and the legislation.
- Retention and access: records are kept for the period set out in the organization’s retention and destruction policy and are accessible only by authorized persons, as required by their role.
12.3. The User is informed in advance, by means of the organization’s privacy notice, that system records are kept and that these records may be processed for the above purposes. In every case where personal data is processed, the principles in the Law and the organization’s privacy policies, and the principles of proportionality and purpose limitation, are observed.
13. Third-Party Links and Services
13.1. The Portal may contain redirections to connected systems and services accessed with the corporate identity. The connected corporate learning platform is accessed with the corporate identity; a User who has signed in to the Portal with their corporate identity passes to this service with their corporate identity without signing in again. For direct access to the service, sign-in with the corporate identity and multi-step authentication are applied.
13.2. Connected services may have their own terms of use and privacy arrangements; when using these services, the User also complies with the relevant arrangements.
13.3. Where links external to the organization are present, the content and security of those links are the responsibility of the relevant third parties; the User uses such links with care.
14. Duration of Access and Termination
14.1. Portal access is valid for as long as the User’s role, authorization, or contractual relationship continues.
14.2. In the event of the termination of the role, authorization, or contract, Portal access is also terminated. For employee accounts, the disabling of access is carried out upon Human Resources initiating the offboarding process.
14.3. Business partner and contractor accounts are defined for a fixed term and reviewed at regular intervals [period — to be determined by Legal and Information Technology]. Where the need continues, access is renewed in accordance with the procedure; otherwise, access is disabled at the end of the term. For business partner and contractor accounts, the termination of access is triggered by Human Resources and implemented by Information Technology.
14.4. The termination of access does not extinguish the User’s confidentiality and information protection obligations arising under these Terms.
15. Course of Action in the Event of a Breach
15.1. Upon detection of a use contrary to these Terms, Portal access may be temporarily suspended or restricted in order to protect the security and lawfulness of the organization.
15.2. Breaches are assessed within the framework of the relevant internal processes, corporate policies, and the legislation in force, under the supervision of Human Resources and, where necessary, the Legal department. The User is given the opportunity to explain the situation and to object.
15.3. The purpose of these Terms is to maintain a trust-based and healthy usage relationship between the User and the organization; proportionality and fair assessment are taken as the basis in every step to be applied.
16. Service Continuity
16.1. The organization makes reasonable efforts to provide the Portal in a secure, continuous, and functional manner.
16.2. Temporary interruptions in access to the Portal may occur due to maintenance, updates, technical faults, or reasons beyond the organization’s reasonable control. Planned maintenance and updates are announced in advance, as far as possible, through appropriate corporate communication channels, and care is taken to minimize the impact.
16.3. Disruptions that may occur in the Portal service due to unforeseeable extraordinary circumstances beyond the organization’s reasonable control (force majeure; for example, natural disaster, fire, epidemic, large-scale infrastructure or communication outages) are assessed to the extent that they affect the obligations under these Terms.
17. Amendments
17.1. These Terms may be updated in line with corporate, legal, or technical requirements.
17.2. Significant changes are announced to the User through appropriate corporate communication channels.
17.3. Continued use of the Portal after the changes enter into force constitutes acceptance of the updated Terms.
18. Miscellaneous Provisions
18.1. Entirety. These Terms, together with the relevant employment or service contracts, corporate policies, and the privacy notice, constitute the entirety of the parties’ agreement concerning the use of the Portal and supplement them.
18.2. Severability. The invalidity or unenforceability of any provision of these Terms does not affect the validity and enforceability of the other provisions; the invalid provision is construed by means of the valid arrangement closest to its purpose.
18.3. Assignment. The User may not assign the rights and obligations arising under these Terms to third parties without Dedeman’s written consent.
19. Governing Law
19.1. These Terms are governed by the legislation of the Republic of Türkiye and are construed in accordance with that legislation.
19.2. In disputes that may arise under these Terms, the legislation in force and the organization’s relevant internal regulations are taken as the basis.
20. Contact
For questions, requests, and notifications relating to these Terms and the use of the Portal, the following corporate points of contact may be addressed:
| Subject | Point of Contact |
|---|---|
| Access, account, and technical support | Information Technology Unit — [Information Technology contact address] |
| Account creation, role, and employment processes | Human Resources Unit — [Human Resources contact address] |
| Legal matters and contractual questions | Legal Unit — [Legal contact address] |
| Protection of personal data | Data Protection Officer — [Data Protection Officer application address] |
21. Entry into Force
21.1. These Terms enter into force on 1 April 2026.
21.2. Version: Version 1.0 — DRAFT
21.3. This document takes its final form following the review and approval of the Legal department.