Personal Data Protection and Processing Policy
Last updated: March 2026This policy has been prepared by Bizicon BiliΕim ve DanΔ±ΕmanlΔ±k Hizmetleri ("361") as data controller to determine the general principles, legal grounds, security measures and transfer rules for the processing of personal data in accordance with the Turkish Personal Data Protection Law No. 6698 ("KVKK") and related legislation.
1. Purpose
The purpose of this policy is to define the principles to be followed in 361's personal data processing activities, the legal standards to be applied and the measures to protect the rights of data subjects. The policy is binding for all departments and employees of 361.
2. Scope
This policy covers all personal data processed by 361 and all related activities. Data subjects within the scope of the policy are:
- Customers and customer employees
- Prospective customers and visitors
- Website users
- Business partners, suppliers and collaborating third parties
- Employees, interns and job applicants
- Visitors
3. Data Processing Principles
361 complies with the following fundamental principles set out in Article 4 of the KVKK when processing personal data:
3.1 Processing in Compliance with Law and Good Faith
Personal data is processed lawfully and in good faith. No processing is carried out that exceeds data subjects' expectations or surprises them.
3.2 Accuracy and, Where Necessary, Up-to-Dateness
361 takes the necessary measures to ensure that the personal data it processes is accurate and up to date. Utmost care is taken to correct inaccurate or incomplete data.
3.3 Processing for Specific, Explicit and Legitimate Purposes
Personal data is processed in line with clearly defined legitimate purposes. The purpose of data collection is explicitly communicated to data subjects.
3.4 Being Relevant, Limited and Proportionate to the Purpose of Processing
Personal data is processed only to the extent necessary to achieve the defined purposes. No data is collected beyond the purpose.
3.5 Retention for the Period Envisaged in Legislation or Required for the Purpose of Processing
Personal data is retained for as long as the purpose of processing requires. At the end of the period, data is destroyed under our Retention and Destruction Policy.
4. Legal Grounds
Personal data is processed on the basis of the legal grounds specified in Articles 5 and 6 of the KVKK:
4.1 Explicit Consent
Consent given by the data subject in relation to a specific matter, based on information and with free will. Marketing communications, cookie usage and similar activities rely on this ground.
4.2 Explicitly Provided for by Law
Data processing is mandatory in cases explicitly provided for by legislation such as the Commercial Code, Tax Procedure Law and Labor Law.
4.3 Being Directly Related to the Establishment or Performance of a Contract
Data processing in POC applications, contract negotiations and service delivery processes relies on this ground.
4.4 Fulfillment of a Legal Obligation
Fulfillment of legal reporting and notification obligations to public authorities.
4.5 Legitimate Interest Without Prejudice to Fundamental Rights and Freedoms
Data processing in line with legitimate interests such as website security, performance analysis, fraud prevention and improvement of service quality.
5. Data Security Measures
361 applies the following technical and administrative measures to ensure the security of personal data in accordance with Article 12 of the KVKK and the Regulation on the Registry of Data Controllers:
5.1 Technical Measures
- Continuous auditing within the scope of ISO 27001 Information Security Management System certification
- Security in AI processes with ISO 42001 AI Management System certification
- Data transmission security with SSL/TLS encryption protocols
- Data storage security with AES-256 encryption
- Multi-factor authentication (MFA) systems
- Access control lists and role-based authorization
- Penetration tests and vulnerability scans (periodic)
- Firewall, IDS/IPS and WAF applications
- Data masking and encryption techniques
- Automatic backup and disaster recovery plans
5.2 Administrative Measures
- Regular KVKK and information security training for employees
- Confidentiality agreements and undertakings
- Confidentiality and data processing agreements with third-party data processors
- Department-based data access authorization policies
- Incident response plans and breach notification procedures
- Regular internal audits and compliance checks
6. Data Transfer
Personal data is transferred in accordance with the conditions specified in Articles 8 and 9 of the KVKK:
6.1 Domestic Transfer
- To authorized public institutions where legally required
- To suppliers and business partners collaborated with for service delivery (as data processors, under confidentiality agreements)
- To lawyers, consultants and courts in legal disputes
- To independent audit firms within the scope of audit activities
6.2 International Transfer
International data transfer is carried out only in the following cases:
- Transfer to countries declared by the Personal Data Protection Board to have adequate protection
- Where adequate protection does not exist, the data controllers' written undertaking of adequate protection and the Board's authorization
- Within the scope of explicit consent (with transfer risks notified to the relevant data subject)
361 AI Platform users are offered a data location preference, including the option to keep data in TΓΌrkiye.
7. Right of Application
Under Article 11 of the KVKK, data subjects may apply to 361 to exercise the following rights:
- Learn whether their personal data is being processed
- Request information about the processing if it has been processed
- Learn the purpose of processing and whether it is used in accordance with that purpose
- Know the third parties to whom data is transferred domestically or abroad
- Request correction if data is incomplete or inaccurate
- Request deletion or destruction within the framework of Article 7 of the KVKK
- Request that correction, deletion and destruction operations be notified to third parties to whom data has been transferred
- Object to a result arising against them through analysis by automated systems
- Request compensation for damages arising from unlawful processing
Application Methods
You can apply with the Data Subject Application Form or through our contact page using the following methods:
- Email: info@361.com.tr (subject: "KVKK Application")
- Written application: Originn Office, KazΔ±m Dirik Mh. 296/2 St. No:33, 35100 Bornova/Δ°zmir, TΓΌrkiye
- REM (KEP): Via registered electronic mail with secure electronic signature or mobile signature
Applications are concluded free of charge within 30 days at the latest.
8. Related Policies
Our other policies on personal data protection:
- KVKK Information Notice
- Personal Data Retention and Destruction Policy
- Privacy Policy
- Cookie Policy
- AI Policy
9. Amendments
This policy may be updated in line with changes in legislation and company practices. The current text is always published on this page.
10. Contact
For questions regarding the protection and processing of personal data:
Bizicon BiliΕim ve DanΔ±ΕmanlΔ±k Hizmetleri
Address: Originn Office, KazΔ±m Dirik Mh. 296/2 St. No:33, 35100 Bornova/Δ°zmir, TΓΌrkiye
Email: info@361.com.tr
Phone: +90 (850) 255 15 82
Web: 361.com.tr