Skip to content
Skip to content
361
  • One platform, unified intelligenceData, processes, people and AI work on the same enterprise model.20+ years100+ customers200+ modules What is 361?Understand the platform simply ArchitectureLayers, security and scale CapabilitiesAI, automation, data and experience DeploymentCloud, on-prem and air-gap IntegrationsConnect your existing systems Trust CenterEvidence for IT and procurement OneBoxOne inbox, unified work experience Liquid PlatformAdapts to your organization Local AIOn-prem, air-gap and data sovereignty Your DataNo lock-in, portable by design Developer CenterAPI, MCP, webhooks and tools
  • Start with the business outcomeSelect ready modules and adapt them to your organization.Explore 200+ modules → AI SolutionsEnterprise AI use cases Module CatalogSearchable business modules Autonomous EnterpriseFrom manual to autonomous Maturity ModelThe S0-S4 ladder and where 361 stands Works WithAlongside your existing tools ComparisonsEvaluate alternatives transparently Is 361 for You?Find your best starting point
  • A fast path for every roleChoose your need and get the right content and next step.Open Solution Builder → ExecutivesValue, risk and transformation IT & SecurityArchitecture, compliance and review Business TeamsGrowth, efficiency and visibility Customer ExperienceSales, service and continuous journeys DevelopersAPI, webhooks, MCP and tools PartnersProgram, economics and application Solution BuilderYour path in four questions
  • Video CenterProduct tours and explainers InsightsAI and transformation guides Download CenterPresentations, guides and technical content AcademyRole-based learning paths GlossaryTechnical terms in plain language FAQFrequently asked questions What is 361?A plain-language introduction What's NewMonthly product progress ROI CalculatorModel value with your numbers Maturity TestAssess your AI readiness IT Review PackTechnical evaluation evidence
  • AboutOur vision, approach and 20+ years of experience TeamThe experts behind the platform ReferencesTrusted by 100+ customers Success StoriesMeasurable customer outcomes CareersJoin the 361 team ContactTalk directly with our team CorporateMission, certifications and governance Why Now?The category thesis and timing EventsLive sessions and meetings PricingModel and cost drivers Book a DemoA 30-minute live product tour
TR
ExploreChoose your role or the job you want to accomplish. ExecutiveValue and transformation IT / SecurityArchitecture and compliance Business TeamOutcomes and efficiency Customer ExperienceSales and service DeveloperAPIs and tools PartnerProgram and economics What is 361?ArchitectureCapabilitiesIntegrationsDeploymentTrust CenterOneBoxLiquid PlatformLocal AIYour DataDeveloper Center AI Solutions200+ ModulesAutonomous EnterpriseMaturity ModelWorks WithComparisonsIs 361 for You? Solution BuilderExecutiveIT / SecurityBusiness TeamsCustomer ExperienceDevelopersPartners Video CenterBlogDownloadsAcademyGlossaryFAQWhat is 361?What's NewROI CalculatorMaturity TestIT Review Pack AboutTeamSuccess StoriesReferencesEventsCareersContactCorporateWhy Now?PricingBook a DemoFree POC 20+ years100+ customers200+ modules

Personal Data Retention and Destruction Policy

Last updated: March 2026

This policy has been prepared by Bizicon Bilişim ve Danışmanlık Hizmetleri ("361") as data controller, in accordance with Article 7 and 17 of the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the Regulation on the Deletion, Destruction or Anonymization of Personal Data.

In this articleIn this article1. Purpose2. Scope3. Definitions4. Retention Principles5. Retention Periods6. Destruction Methods7. Periodic DestructionProcess8. Responsibilities
11 sections — jump to what you need.

1. Purpose

The purpose of this policy is to regulate the procedures and principles for determining the retention periods of personal data processed by 361, and for the deletion, destruction or anonymization of such data upon expiry of those periods.

The policy aims to ensure that personal data is retained for the periods determined in accordance with applicable legislation and securely destroyed at the end of those periods.

2. Scope

This policy covers all categories of personal data processed by 361 and all departments, systems, processes and data processors handling such data. It covers data belonging to the following data subjects:

  • Customers and customer employees
  • Prospective customers and visitors
  • Website users
  • Business partners and suppliers
  • Company employees and interns
  • Job applicants

3. Definitions

  • Explicit Consent: Consent relating to a specific matter, based on information and declared with free will.
  • Anonymization: Rendering personal data impossible to associate with an identified or identifiable natural person, even by matching with other data.
  • Data Subject: The natural person whose personal data is processed.
  • Destruction: Deletion, destruction or anonymization of personal data.
  • Recording Medium: Any medium containing personal data processed wholly or partly by automated means, or by non-automated means as part of a data filing system.
  • Periodic Destruction: Deletion, destruction or anonymization of data ex officio, taking into account the periodic intervals specified in the Regulation, when the retention period expires.
  • Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.
  • Regulation: Regulation on the Deletion, Destruction or Anonymization of Personal Data (Official Gazette: 28.10.2017, No. 30224).

4. Retention Principles

The following principles are observed in the retention of personal data:

  • Proportionality: Data is retained in a manner related, limited and proportionate to the purpose of processing.
  • Accuracy and Currency: Necessary measures are taken to ensure retained data is accurate and up to date.
  • Specific, Explicit and Legitimate Purpose: Data is retained in line with the purposes specified at the time of collection.
  • Data Minimization: Only necessary data is retained; unnecessary data is destroyed immediately.
  • Storage Limitation: Data is retained only as long as required by law or contract and destroyed at the end of that period.

5. Retention Periods

Personal data is retained for the periods required by the purpose of processing and applicable legislation. The main retention periods are set out below:

5.1 Customer Data

Customer contract and invoice information is retained for 10 years under the Turkish Commercial Code and Tax Procedure Law. Customer contact data is retained for the duration of the contract and for 5 years after its termination.

5.2 Marketing and Communication Data

Data processed for marketing purposes is retained until consent is withdrawn or for 2 years from the last interaction date. Electronic message permission records are retained for the validity period of the permission.

5.3 Website and Digital Trace Data

IP addresses, browser information and session data are retained for a maximum of 2 years. For cookie data, see our Cookie Policy.

5.4 Contract and Legal Transaction Data

Data relating to legal disputes is retained for the duration of litigation limitation periods (generally 10 years). Records required by legal obligations are retained for the periods prescribed by the relevant legislation.

5.5 Employee Data

Employee personnel files are retained for 10 years under the Labor Law and Social Insurance Law. Payroll and salary records are retained for 10 years; occupational health and safety records for the periods required by legislation.

6. Destruction Methods

Personal data whose retention period has expired is destroyed using the methods specified in the Regulation:

6.1 Deletion Methods

  • Database Deletion: Permanent deletion of the relevant rows from database records containing personal data.
  • File System Deletion: Permanent deletion of files containing personal data at the operating system level (using secure delete algorithms).
  • Cloud Service Deletion: Deletion of data stored in cloud environments within the secure deletion protocols of the relevant service provider.

6.2 Physical Destruction Methods

  • Physical Destruction: Destruction of paper documents using a cross-cut shredder.
  • Magnetic Degaussing: Rendering data on magnetic media unreadable by degaussing.
  • Software Overwriting: Overwriting data on electronic media at least 3 times with different patterns.

6.3 Anonymization Methods

  • Variable Masking: Anonymization of variables by masking according to a specific pattern.
  • General Variable Masking: Anonymization of variables at subgroup level.
  • Noise Addition: Concealing real values by adding random values to the data.
  • K-Nearest Neighbor: Anonymization of data using a specific k-value.

7. Periodic Destruction Process

361 applies the following process for the periodic review and destruction of personal data:

7.1 Periodic Review Intervals

Systems containing personal data are reviewed periodically every 6 months. During these reviews, data whose retention period has expired is identified and the destruction process is initiated.

7.2 Destruction Procedure

  • The necessity of destruction is determined by the relevant department head.
  • Data to be destroyed is identified in line with the Data Inventory and Retention Period Plan.
  • The list of data to be destroyed is approved by the KVKK Officer.
  • Destruction is carried out using the determined method.
  • The destruction is documented with a Destruction Record.
  • The record is reported to the KVKK Officer and Senior Management.

8. Responsibilities

Responsibilities in the retention and destruction of personal data are as follows:

  • KVKK Officer: Supervises implementation of the policy, coordinates periodic reviews, examines destruction reports.
  • IT Department: Performs technical deletion and destruction operations, applies destruction at database level.
  • HR Department: Responsible for retention and destruction of employee data.
  • Sales and Marketing Department: Responsible for retention and destruction of customer and prospective customer data.
  • Finance Department: Responsible for retention and destruction of financial records as required by law.

9. Related Policies

Our other policies on personal data protection:

  • KVKK Information Notice
  • Personal Data Protection and Processing Policy
  • Privacy Policy
  • Cookie Policy
  • Data Subject Application Form

10. Amendments

This policy may be updated in line with changes in legislation and company practices. The current text is always published on this page.

11. Contact

For questions regarding the retention and destruction of personal data, you can reach us via our contact page or the details below:

Bizicon Bilişim ve Danışmanlık Hizmetleri
Address: Originn Office, Kazım Dirik Mh. 296/2 St. No:33, 35100 Bornova/İzmir, Türkiye
Email: info@361.com.tr
Phone: +90 (850) 255 15 82
Web: 361.com.tr

20+ yearsenterprise software experience 100+ customersrun business processes on 361 200+ modulesready business capabilities Explore the evidence →
361361

Unify your organization's data, processes, people and AI capabilities on one platform.

Start POC

Platform

What is 361?ArchitectureCapabilitiesIntegrationsTrust Center

Solutions

AI SolutionsModule CatalogIndustriesComparisonsPricing

Resources

Video CenterBlogDownloadsAcademyFAQ

Company

AboutSuccess StoriesPartner CenterCareersContact
ISO 9001ISO 27001ISO 22301ISO 42001 LegalPrivacyCookie Preferences
2026 © 361 Derece Bilişim · All rights reserved