Personal Data Retention and Destruction Policy
Last updated: March 2026This policy has been prepared by Bizicon Bilişim ve Danışmanlık Hizmetleri ("361") as data controller, in accordance with Article 7 and 17 of the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the Regulation on the Deletion, Destruction or Anonymization of Personal Data.
1. Purpose
The purpose of this policy is to regulate the procedures and principles for determining the retention periods of personal data processed by 361, and for the deletion, destruction or anonymization of such data upon expiry of those periods.
The policy aims to ensure that personal data is retained for the periods determined in accordance with applicable legislation and securely destroyed at the end of those periods.
2. Scope
This policy covers all categories of personal data processed by 361 and all departments, systems, processes and data processors handling such data. It covers data belonging to the following data subjects:
- Customers and customer employees
- Prospective customers and visitors
- Website users
- Business partners and suppliers
- Company employees and interns
- Job applicants
3. Definitions
- Explicit Consent: Consent relating to a specific matter, based on information and declared with free will.
- Anonymization: Rendering personal data impossible to associate with an identified or identifiable natural person, even by matching with other data.
- Data Subject: The natural person whose personal data is processed.
- Destruction: Deletion, destruction or anonymization of personal data.
- Recording Medium: Any medium containing personal data processed wholly or partly by automated means, or by non-automated means as part of a data filing system.
- Periodic Destruction: Deletion, destruction or anonymization of data ex officio, taking into account the periodic intervals specified in the Regulation, when the retention period expires.
- Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.
- Regulation: Regulation on the Deletion, Destruction or Anonymization of Personal Data (Official Gazette: 28.10.2017, No. 30224).
4. Retention Principles
The following principles are observed in the retention of personal data:
- Proportionality: Data is retained in a manner related, limited and proportionate to the purpose of processing.
- Accuracy and Currency: Necessary measures are taken to ensure retained data is accurate and up to date.
- Specific, Explicit and Legitimate Purpose: Data is retained in line with the purposes specified at the time of collection.
- Data Minimization: Only necessary data is retained; unnecessary data is destroyed immediately.
- Storage Limitation: Data is retained only as long as required by law or contract and destroyed at the end of that period.
5. Retention Periods
Personal data is retained for the periods required by the purpose of processing and applicable legislation. The main retention periods are set out below:
5.1 Customer Data
Customer contract and invoice information is retained for 10 years under the Turkish Commercial Code and Tax Procedure Law. Customer contact data is retained for the duration of the contract and for 5 years after its termination.
5.2 Marketing and Communication Data
Data processed for marketing purposes is retained until consent is withdrawn or for 2 years from the last interaction date. Electronic message permission records are retained for the validity period of the permission.
5.3 Website and Digital Trace Data
IP addresses, browser information and session data are retained for a maximum of 2 years. For cookie data, see our Cookie Policy.
5.4 Contract and Legal Transaction Data
Data relating to legal disputes is retained for the duration of litigation limitation periods (generally 10 years). Records required by legal obligations are retained for the periods prescribed by the relevant legislation.
5.5 Employee Data
Employee personnel files are retained for 10 years under the Labor Law and Social Insurance Law. Payroll and salary records are retained for 10 years; occupational health and safety records for the periods required by legislation.
6. Destruction Methods
Personal data whose retention period has expired is destroyed using the methods specified in the Regulation:
6.1 Deletion Methods
- Database Deletion: Permanent deletion of the relevant rows from database records containing personal data.
- File System Deletion: Permanent deletion of files containing personal data at the operating system level (using secure delete algorithms).
- Cloud Service Deletion: Deletion of data stored in cloud environments within the secure deletion protocols of the relevant service provider.
6.2 Physical Destruction Methods
- Physical Destruction: Destruction of paper documents using a cross-cut shredder.
- Magnetic Degaussing: Rendering data on magnetic media unreadable by degaussing.
- Software Overwriting: Overwriting data on electronic media at least 3 times with different patterns.
6.3 Anonymization Methods
- Variable Masking: Anonymization of variables by masking according to a specific pattern.
- General Variable Masking: Anonymization of variables at subgroup level.
- Noise Addition: Concealing real values by adding random values to the data.
- K-Nearest Neighbor: Anonymization of data using a specific k-value.
7. Periodic Destruction Process
361 applies the following process for the periodic review and destruction of personal data:
7.1 Periodic Review Intervals
Systems containing personal data are reviewed periodically every 6 months. During these reviews, data whose retention period has expired is identified and the destruction process is initiated.
7.2 Destruction Procedure
- The necessity of destruction is determined by the relevant department head.
- Data to be destroyed is identified in line with the Data Inventory and Retention Period Plan.
- The list of data to be destroyed is approved by the KVKK Officer.
- Destruction is carried out using the determined method.
- The destruction is documented with a Destruction Record.
- The record is reported to the KVKK Officer and Senior Management.
8. Responsibilities
Responsibilities in the retention and destruction of personal data are as follows:
- KVKK Officer: Supervises implementation of the policy, coordinates periodic reviews, examines destruction reports.
- IT Department: Performs technical deletion and destruction operations, applies destruction at database level.
- HR Department: Responsible for retention and destruction of employee data.
- Sales and Marketing Department: Responsible for retention and destruction of customer and prospective customer data.
- Finance Department: Responsible for retention and destruction of financial records as required by law.
9. Related Policies
Our other policies on personal data protection:
- KVKK Information Notice
- Personal Data Protection and Processing Policy
- Privacy Policy
- Cookie Policy
- Data Subject Application Form
10. Amendments
This policy may be updated in line with changes in legislation and company practices. The current text is always published on this page.
11. Contact
For questions regarding the retention and destruction of personal data, you can reach us via our contact page or the details below:
Bizicon Bilişim ve Danışmanlık Hizmetleri
Address: Originn Office, Kazım Dirik Mh. 296/2 St. No:33, 35100 Bornova/İzmir, Türkiye
Email: info@361.com.tr
Phone: +90 (850) 255 15 82
Web: 361.com.tr