Arnes Pack Arnes Pack
  • Company
    • About Us
    • Certifications
    • Careers
  • Products
    Paper Cups
    Paper Cups
    Hot Cold
    Ice Cream Bowls
    Ice Cream Bowls
    Paper Bowls
    Paper Bowls
    Salad Bowls
    Salad Bowls
    Popcorn
    Popcorn
    Take-away Boxes
    Take-away Boxes
    Wall Type Single Wall Single Wall Double Wall Double Wall
  • Sustainability
  • Sectors
  • Gallery
  • Product Catalog
  • Contact
    • Türkçe
    • English

Type at least 2 characters. Press Esc to close.

Arnes Pack
Company
  • About Us
  • Certifications
  • Careers
Products
  • Paper Cups
  • Ice Cream Bowls
  • Paper Bowls
  • Salad Bowls
  • Popcorn
  • Take-away Boxes
Sustainability Sectors Gallery Product Catalog Contact
Türkçe English
Home › Personal Data Protection (KVKK)

Personal Data Protection (KVKK)

Our policy on the processing, storage and destruction of personal data under Turkish Law No. 6698 on the Protection of Personal Data.

Effective: June 2020
Contents
  • PERSONAL DATA COLLECTION, RETENTION, DESTRUCTION AND ANONYMISATION POLICY
  • A. SCOPE
  • B. DEFINITIONS
  • C. PURPOSE AND PRINCIPLES
  • D. RECORDING MEDIA
  • E. CIRCUMSTANCES REQUIRING THE RETENTION AND DESTRUCTION OF PERSONAL DATA
  • F. DESTRUCTION OF PERSONAL DATA
  • G. METHODS AND PROCESS FOR DESTROYING PERSONAL DATA
  • H. RETENTION AND DESTRUCTION PERIODS FOR PERSONAL DATA
  • I. EFFECTIVE DATE OF THE POLICY

This is a courtesy English translation. Arnes Pack's personal data policy is issued under Turkish Law No. 6698 on the Protection of Personal Data (KVKK), and the Turkish text remains the legally binding version. In the event of any discrepancy, the Turkish original prevails.

Personal data lawfully obtained in connection with the service relationship, commercial activity, communication, organisation, social activity and similar dealings established with ARNES AMBALAJ SANAYİ VE TİCARET A.Ş., together with the personal data of all persons connected with the company — including those who benefit from the products and services procured within the scope of its commercial activity — are collected, processed and retained in accordance with Law No. 6698 on the Protection of Personal Data.

Acting as a “data controller” under the Law on the Protection of Personal Data, our company diligently fulfils its legal responsibilities regarding the processing, storage and destruction of all personal data in accordance with that Law.

1 - Purpose of processing your personal data

Our company processes your personal data for the following purposes:

  • Planning and carrying out human resources processes,
  • Creating personnel records files,
  • Drawing up and performing service contracts,
  • Administering employees' insurance processes,
  • Following up employees' health processes,
  • Supplying and assigning telephones and other electronic devices to employees within the scope of the service relationship,
  • Managing occupational health and safety processes,
  • Planning the use of internet systems and electronic mail services,
  • Ensuring corporate communication,
  • Providing services such as travel and accommodation within the scope of the service relationship,
  • Planning and delivering vocational training, personnel training, business development and orientation programmes,
  • Ensuring workplace and occupational safety and monitoring entries to and exits from the workplace and working schedules,
  • Carrying out the activities of the company's management and decision-making bodies,
  • Within the scope of sustaining commercial activity: procuring goods and services, managing and monitoring commercial processes, performing the work and employment contracts, carrying out sales, marketing and accounting activities, and managing legal processes relating to the workplace.

Within the scope of its commercial activities, our company may collect personal data — in the manner permitted by the relevant legislation, by automated or non-automated means — at its headquarters and affiliated offices or at group companies, on the companies' websites or social media accounts, verbally, in writing, visually or digitally. The data collected will be retained and may be updated for as long as you benefit from the products and services offered by the company or its group companies.

In addition, personal data shared may be processed when call centres are contacted, web pages are used or websites are visited in order to use the products and services offered by our company or our group companies, or when you take part in training sessions, seminars or events organised by our company or its group companies.

Personal data collected by our company will be processed in accordance with Articles 5 and 6 of the Law on the Protection of Personal Data for the purposes of meeting the requirements of the products and services used; enabling evaluations of preference, satisfaction or complaints regarding those products and services and delivering a better service; ensuring the legal and commercial security of the natural and legal persons in a business relationship with our company and our group companies; determining business strategy; and implementing human resources policy.

2 - Methods of collecting personal data

In accordance with the conditions for collecting and processing personal data set out in the Law on the Protection of Personal Data, personal data are collected on the legal grounds stated above through channels such as statements by employees and relevant persons, personal business cards or CVs, websites, human resources systems, application forms, Social Security Institution and tax office records, documents and forms issued by joint health and safety units and occupational health and safety units, documents relating to orders for goods and services, and electronic correspondence. They are securely retained, processed and may be transferred, physically or in electronic environments, for the duration of the legal relationship or commercial activity.

3 - To whom and for what purpose processed personal data may be transferred

Personal data collected by our company may be transferred, in accordance with Articles 8 and 9 of the Law on the Protection of Personal Data, to group companies, company shareholders, legally authorised public institutions and private persons, suppliers and business partners, for the purposes of meeting the requirements of the products and services used; enabling evaluations of preference, satisfaction or complaints regarding those products and services and delivering a better service; ensuring the legal and commercial security of the natural or legal persons in a business relationship with our company; determining business strategy; and implementing human resources policy.

4 - Transfer of data abroad

In line with the principles set out in the relevant articles of the KVKK, and on the basis of explicit consent, our company may transfer personal data to persons or companies resident abroad under the conditions described above — limited to what its legitimate commercial activities require and in accordance with the principles and rules to be determined by the Personal Data Protection Board — for the purposes of commercial activities with an international dimension, import and export transactions, and the planning and delivery of conferences, fairs, panels, training meetings, seminars and similar events. As a rule, special categories of personal data are not transferred abroad; where such a transfer is unavoidable, a limited transfer may be made with the measures prescribed by law in place.

5 - Rights of the data subject listed in Article 11 of the KVKK

Under the Law on the Protection of Personal Data, data subjects have the right to:

  • a) learn whether their personal data are being processed;
  • b) request information if their personal data have been processed;
  • c) learn the purpose of processing and whether the data are used in accordance with that purpose;
  • d) know the third parties in Turkey or abroad to whom their personal data are transferred;
  • e) request that their personal data be corrected if processed incompletely or inaccurately;
  • f) request the erasure or destruction of their personal data under the conditions set out in Article 7;
  • g) request that any action taken under points (e) and (f) be notified to the third parties to whom the personal data have been transferred;
  • h) object to a result arising against them from the analysis of processed data exclusively by automated systems;
  • i) claim compensation for damage suffered as a result of the unlawful processing of their personal data.

Where a data subject notifies our company of complaints and requests concerning the rights listed above — in person or through a notary public at our company's headquarters address, together with a document evidencing their identity, or by other means to be determined by the Personal Data Protection Board — our company will conclude the application within 30 days.

6 - Keeping personal data up to date

Personal data collected by our company must be accurate and up to date. Any change to your personal data should therefore be notified to our company within a reasonable period.

7 - Application by the data subject

Any request, complaint or application concerning the protection of personal data will be acted upon within 30 days once submitted in writing to:

ARNES Ambalaj Sanayi ve Ticaret A.Ş.

İkitelli Organize Sanayi Bölgesi, Çevre Sanayi Sitesi, 15. Blok No: 1/A, Başakşehir / İstanbul, Türkiye

PERSONAL DATA COLLECTION, RETENTION, DESTRUCTION AND ANONYMISATION POLICY

A. SCOPE

1. This Data Security and Personal Data Retention and Destruction Policy (the “Policy”) covers all departments and employees of our company involved in any process in which personal data are processed.

2. This Policy covers all retention and destruction processes that the company applies in relation to personal data.

B. DEFINITIONS

Law
Law No. 6698 on the Protection of Personal Data.
Regulation
The Regulation on the Erasure, Destruction or Anonymisation of Personal Data.
Communiqué
The Communiqué on the Procedures and Principles of Application to the Data Controller, published in the Official Gazette by the Personal Data Protection Authority on 10.03.2018.
Board
The Personal Data Protection Board.
Recording medium
Any medium containing personal data processed wholly or partly by automated means, or by non-automated means provided that it forms part of a data filing system.
Personal data processing inventory
The inventory in which data controllers set out the personal data processing activities they carry out in connection with their business processes — linked to the purposes of processing, the data category, the recipient group and the group of data subjects — detailing the maximum period necessary for the purposes for which the personal data are processed, the personal data envisaged to be transferred to foreign countries, and the measures taken in respect of data security.
Destruction
The erasure, destruction or anonymisation of personal data.
Periodic destruction
The erasure, destruction or anonymisation carried out ex officio at recurring intervals specified in the personal data retention and destruction policy, where all of the conditions for processing personal data set out in the Law cease to exist.
Registry
The Data Controllers' Registry maintained by the Presidency of the Personal Data Protection Authority.
Data filing system
A filing system in which personal data are processed, structured according to specific criteria.
Data controller
The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.
Recipient group
The category of natural or legal persons to whom personal data are transferred by the data controller.
Relevant user
Persons who process personal data within the data controller's organisation, or in line with the authorisation and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data.
Company
The data controller legal entity that establishes and will apply this Policy.

C. PURPOSE AND PRINCIPLES

This Policy sets out the duties, powers and responsibilities of the personnel authorised and charged with the collection, retention, erasure, destruction or anonymisation of personal data and with ensuring data security, together with the principles of application, within the framework of the Regulation issued under Article 7 of the Law.

Under the relevant legislation, our company — which is subject to the obligation to register with the Data Controllers' Registry — is required, as a data controller, to prepare a Policy for storing the personal data in its custody appropriately in the personal data inventory and for erasing, destroying or anonymising them where necessary, and to act in accordance with that Policy. The purpose of this Policy is to ensure data security.

Our company undertakes to ensure data security by establishing procedures and operations compliant with the Law, the Regulation and the relevant legislation in the collection, retention and destruction of personal data.

The following principles are observed in the collection, retention and destruction of personal data and in ensuring data security.

  • a. In collecting, retaining, erasing, destroying and anonymising personal data, we will act in accordance with the principles listed in Article 4 of the Law, the technical and administrative measures required under Article 12, the provisions of the relevant legislation, Board decisions and this Policy.
  • b. All operations relating to the collection, retention, erasure, destruction and anonymisation of personal data will be recorded, and those records will be retained for as long as the legislation requires.
  • c. Unless the Board decides otherwise, we select whichever of the erasure, destruction or anonymisation methods is appropriate when acting ex officio. Where the data subject so requests, however, the method will be selected with the reasons explained.
  • d. Where all of the conditions for processing personal data set out in Articles 5 and 6 of the Law cease to exist, personal data will be erased, destroyed or anonymised by us ex officio or at the data subject's request. Where the data subject applies to our company on this matter:
  • i. Requests submitted will be concluded within 30 (thirty) days at the latest and the data subject will be informed.
  • ii. Where the data in question have been transferred to third parties, this will be notified to those third parties and the necessary action will be secured on their part.

D. RECORDING MEDIA

Personal data held in the media listed below, and in any further media that may arise, fall within the scope of this Policy.

  • 1. Computers and servers used at the company's headquarters and branches
  • 2. Network devices
  • 3. Shared and non-shared disk drives used for storing data on the network
  • 4. Cloud systems
  • 5. Mobile telephones and all storage areas within them
  • 6. Microfiche
  • 7. Peripherals such as printers and fingerprint readers
  • 8. Magnetic tapes
  • 9. Optical discs
  • 10. Flash memory
  • 11. All written and printed documents, papers and ledgers

E. CIRCUMSTANCES REQUIRING THE RETENTION AND DESTRUCTION OF PERSONAL DATA

Personal data belonging to data subjects are securely retained in the physical or electronic media listed above, within the limits set out in the KVKK and other relevant legislation, in particular for the purposes of (i) sustaining commercial activities, (ii) fulfilling legal obligations, (iii) planning and providing employee rights and benefits, and (iv) managing customer relations.

The company takes all technical and administrative measures relating to the secure retention of personal data and to preventing their unlawful processing and access.

The grounds requiring retention are as follows:

  • a. Retention of personal data because they are directly related to the establishment and performance of contracts,
  • b. Retention of personal data for the establishment, exercise or protection of a right,
  • c. Retention of personal data being necessary for the company's legitimate interests, provided that this does not harm the fundamental rights and freedoms of individuals,
  • d. Retention of personal data for the purpose of the company fulfilling any legal obligation,
  • e. Retention of personal data being expressly prescribed by legislation,
  • f. The existence of the data subjects' explicit consent in respect of retention activities that require such consent.

Where a breach occurs within the scope described below, the necessary action is taken by the company.

a. Unlawfulness

Our company undertakes not to process personal data in a manner contrary to the form prescribed by the Law and the relevant legislation.

Unless the exceptions set out in Articles 5 and 6 of the Law apply, our company does not retain the personal data of persons whose explicit consent it has not obtained.

Where our company retains special categories of personal data, it processes them in accordance with the relevant legislation.

b. Cessation of the conditions for processing

Our company is responsible for keeping the conditions for processing current, and shares that responsibility with all of its employees.

Employees may not continue processing data where the conditions for processing have ceased to exist.

Where the conditions for processing cease to exist, the IT Department within our company is required to remove the recording media in accordance with this Policy.

Our company accepts that the conditions for processing have ceased to exist in the circumstances listed below and set out in the Regulation.

  • i. Amendment or repeal of the provisions of the relevant legislation forming the basis for processing the personal data;
  • ii. The contract between the parties never having been established, the contract being invalid, the contract terminating automatically, or the contract being terminated or rescinded;
  • iii. The purpose requiring the processing of the personal data ceasing to exist;
  • iv. Processing of the personal data being contrary to the law or to the rule of good faith;
  • v. Where processing is based solely on explicit consent, the data subject withdrawing that consent;
  • vi. Acceptance by the data controller of a duly made application by the data subject concerning the processing activity within the framework of the rights under points (e) and (f) of Article 11 of the Law;
  • vii. Where the data controller rejects an application for the erasure or destruction of personal data made by the data subject, gives an answer found to be insufficient, or fails to answer within the period prescribed by the Law: a complaint being made to the Board and that request being upheld by the Board;
  • viii. The absence of any condition justifying longer retention despite the expiry of the maximum period requiring the retention of the personal data.

F. DESTRUCTION OF PERSONAL DATA

Personal data may be destroyed in three different ways: erasure, destruction or anonymisation. The purpose of destruction is to make it impossible to reach the natural person by means of the remaining data.

Our company takes all technical and administrative measures relating to the lawful erasure, destruction and anonymisation of personal data.

a. Erasure of personal data

Erasure of personal data processed wholly or partly by automated means means rendering those personal data in no way accessible or usable by the relevant users.

Personal data processed by non-automated means that form part of a data filing system will be erased in the ways set out below.

Anonymisation of unnecessary personal data on paper that has been transferred to an electronic environment by scanning or digitisation will be carried out where the data are processed wholly or by automated means.

Where the company erases personal data, it will render them in no way accessible or reusable.

If, during erasure, personal data that should not be erased are also affected and become inaccessible and/or unusable, providing the following methods together will also be regarded as erasure:

  • i. Archiving the personal data in a way that cannot be associated with the data subject;
  • ii. Closing the personal data to all forms of communication;
  • iii. Taking all necessary technical and administrative measures to ensure that the personal data are accessed only by authorised persons and only where necessary.

b. Destruction of personal data

Destruction is carried out where the company processes data in physical recording media. The company will render such data impossible to retrieve. All technical and administrative measures will be taken during and after these operations.

c. Anonymisation of personal data

Anonymisation means rendering personal data — where they are processed wholly or partly by automated means — incapable of being associated with an identified or identifiable natural person, even where they are matched with other data.

Anonymisation of personal data is the duty of the relevant unit. The units charged with this may receive help and support from other departments, provided that they carry out the supervision themselves.

G. METHODS AND PROCESS FOR DESTROYING PERSONAL DATA

The methods to be used for the destruction of personal data are determined by this Policy. The business unit owning the data determines and applies the method within this Policy that is appropriate to the situation.

Whichever of the following methods is appropriate is selected and applied during the destruction of personal data.

a. Erasure of personal data

  • i. Secure erasure from software: When data processed wholly or partly by automated means and held in digital environments are erased, methods are used to delete the data from the relevant software in such a way that they become in no way accessible or reusable by the relevant users. Examples include issuing a delete command for the relevant data in a cloud system; removing the relevant user's access rights to a file or to the directory containing the file on the central server; deleting the relevant rows in databases with database commands; or erasing data held on portable media such as flash storage using suitable software. However, where the erasure of personal data would result in other data also becoming inaccessible and unusable within the system, personal data will also be regarded as erased if they are archived in a way that cannot be associated with the data subject, provided that the following conditions are met:
  • They are closed to access by any other institution, organisation or person;
  • All necessary technical and administrative measures are taken to ensure that the personal data are accessed only by authorised persons.
  • ii. Secure erasure by an expert: In certain cases the company may engage an expert to erase personal data on its behalf. In that case the personal data are securely erased by that expert in such a way that they become in no way accessible or reusable by the relevant users.
  • iii. Redaction of personal data held on paper: A method used to prevent the use of personal data for purposes other than intended, or to erase data whose erasure has been requested, by physically cutting the relevant personal data out of the document, or by rendering them invisible and covered using permanent ink in a way that cannot be reversed or read by technological means.

b. Destruction of personal data

  • i. Degaussing: A method in which magnetic media are subjected to physical change in a high magnetic field so that the data on them are corrupted and rendered unreadable.
  • ii. Physical destruction: Personal data may also be processed by non-automated means, provided that they form part of a data filing system. This is the physical destruction of such data so that they cannot subsequently be used. Written papers, ledgers and microfiche in particular may be destroyed in this way.
  • iii. Overwriting: A data destruction method that makes it impossible to read or recover the old data by writing random data consisting of 0s and 1s at least 8 times over magnetic media and rewritable optical media using special software.
  • iv. Cloud destruction: The destruction of all copies of the encryption keys for personal data held in cloud systems, following notification of destruction to the contracted service provider.
  • v. Destruction of personal data in peripheral systems: Devices containing personal data within systems such as printers, fingerprint units and door entry turnstiles are destroyed by applying overwriting, degaussing or physical destruction. These destruction operations are carried out before the devices are subjected to backup, maintenance and similar processes.

H. RETENTION AND DESTRUCTION PERIODS FOR PERSONAL DATA

In determining the retention and destruction periods for personal data obtained by our company in accordance with the KVKK and the provisions of other relevant legislation, the criteria set out below are applied in order:

  • a. If a period for retaining the personal data in question is prescribed by legislation, that period is observed. Once that period expires, the data are dealt with under paragraph (b).
  • b. Where the period prescribed by legislation for retaining the personal data in question has expired, or where the relevant legislation prescribes no period for retaining that data, then in order:
  • i. Personal data are classified as personal data and special categories of personal data, based on the definition in Article 6 of the KVKK. All personal data identified as belonging to a special category are destroyed. The method applied to destroy such data is determined according to the nature of the data and the degree of importance of retaining them for the company.
  • ii. The compliance of retention with the principles set out in Article 4 of the KVKK is examined — for example, whether the company has a legitimate purpose in retaining the data. Data identified as capable of conflicting with the principles in Article 4 of the KVKK are erased, destroyed or anonymised.
  • iii. It is determined which of the exceptions set out in Articles 5 and 6 of the KVKK the retention of the data may fall under. Reasonable periods for retaining the data are determined within the framework of the exceptions identified. Upon expiry of those periods, the data are erased, destroyed or anonymised.

The retention, destruction and periodic destruction periods determined by our company are set out in the “Data Retention and Destruction Periods Table” annexed to this Policy.

Personal data whose retention period has expired are destroyed at six-monthly intervals in accordance with the procedures set out in this Policy, within the framework of the destruction periods annexed to it.

All operations relating to the erasure, destruction and anonymisation of personal data are recorded, and those records are retained for at least three years, save for other legal obligations.

I. EFFECTIVE DATE OF THE POLICY

This Policy entered into force in June 2020.

Data controller

ARNES Ambalaj Sanayi ve Ticaret A.Ş.

Correspondence address

İkitelli Organize Sanayi Bölgesi, Çevre Sanayi Sitesi, 15. Blok No: 1/A, Başakşehir / İstanbul, Türkiye

E-mail address
arnes@arnespack.com.tr
Wholesale Quote

B2B quote request

Add the products you are interested in; our sales team will reply within 1 business day.

Products *
No products added yet.
100.000 units
50.000 1M 2,5M 5M+
Pattern
Delivery Region
Your data is used only to deliver your quote.

Follow us on social media for the latest from Arnes Pack

Arnes Pack

a cup of happiness for the planet.

BRCGS FSC® SEDEX BSCI ISO 9001

Contact

Selimpaşa Mah. 5006 Sk. No:22
34590 Silivri / İstanbul

+90 212 723 55 10

arnes@arnespack.com.tr

Products

  • Paper Cups
  • Ice Cream Bowls
  • Paper Bowls
  • Salad Bowls
  • Popcorn
  • Take-away Boxes

Company

  • About Us
  • Sectors
  • Certifications
  • Careers

Newsletter

Stay tuned for our sustainability and innovation updates.

Thank you ✿
© 2026 Arnes Ambalaj San. Tic. A.Ş.
KVKK Policy Privacy Policy Cookie Policy Information Society Services
Piksel Agency This page used 0.4 g CO₂.