Legal
Personal Data Retention, Destruction and Anonymisation Policy
Last updated 01.10.2026
Document No: 9
AKAHAN TURİZM PAZ. TAR. GID. İNŞ. SAN. VE TİC. LTD. ŞTİ.
1. Purpose and scope
This Personal Data Retention and Destruction Policy ("Policy") has been prepared to set out the procedures and principles for the work and operations relating to the retention and destruction activities carried out by Akahan Turizm Paz. Tar. Gıd. İnş. San. ve Tic. Ltd. Şti. ("Company").
As a Company, our basic principle is that the personal data of our customers, employees, job applicants, service providers, visitors and other third parties are processed in accordance with the Constitution of the Republic of Türkiye, international conventions, Law No. 6698 on the Protection of Personal Data ("Law") and other relevant legislation. In this context, ensuring that data subjects do not suffer any loss of rights and are able to exercise their rights effectively has been set as a priority.
This Policy has been prepared in accordance with the Law, the Regulation on the Erasure, Destruction or Anonymisation of Personal Data, which entered into force upon publication in Official Gazette No. 30224 dated 28.10.2017 ("Regulation"), and other provisions of legislation.
2. Definitions
| Recipient Group | The category of natural or legal persons to whom personal data are transferred by the data controller. |
|---|---|
| Explicit Consent | Consent relating to a specific matter, based on information and expressed with free will. |
| Anonymisation | Rendering personal data incapable of being associated in any way with an identified or identifiable natural person, even when matched with other data. |
| Employee | Company personnel. |
| Electronic Environment | Environments in which personal data can be created, read, modified and written by means of electronic devices. |
| Non-Electronic Environment | All written, printed, visual and other environments other than electronic environments. |
| Service Provider | A natural or legal person who provides services to the data controller within the framework of a specific contract. |
| Data Subject | The natural person whose personal data are processed. |
| Relevant User | Persons who process personal data within the data controller's organisation or in accordance with the authority and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data. |
| Destruction | The erasure, destruction or anonymisation of personal data. |
| Law | Law No. 6698 on the Protection of Personal Data. |
| Recording Medium | Any medium containing personal data processed wholly or partly by automated means, or by non-automated means provided that they form part of a data filing system. |
| Personal Data | Any information relating to an identified or identifiable natural person. |
| Personal Data Processing Inventory | The inventory created by data controllers detailing the personal data processing activities they carry out in connection with their business processes, by associating them with the purposes and legal grounds of processing, the data category, the recipient groups to whom data are transferred and the group of data subjects. |
| Processing of Personal Data | Any operation performed on personal data, such as obtaining, recording, storing, retaining, modifying, reorganising, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, wholly or partly by automated means, or by non-automated means provided that they form part of a data filing system. |
| Board | The Personal Data Protection Board. |
| Special Category Personal Data | Data relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of an association, foundation or trade union, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data. |
| Periodic Destruction | Where all the conditions for processing personal data set out in the Law have ceased to exist, the erasure, destruction or anonymisation process specified in this Policy that is carried out ex officio at recurring intervals. |
| Policy | The Personal Data Retention and Destruction Policy. |
| Data Processor | A natural or legal person who processes personal data on behalf of the data controller on the basis of the authority granted by the data controller. |
| Data Filing System | A recording system in which personal data are structured and processed according to specific criteria. |
| Data Controller | The natural or legal person who determines the purposes and means of processing personal data and who is responsible for establishing and managing the data filing system. |
| VERBİS | Data Controllers' Registry Information System. The information system, accessible over the internet, created and managed by the Presidency, which data controllers use to apply to the Registry and for other Registry-related procedures. |
| Regulation | The Regulation on the Erasure, Destruction or Anonymisation of Personal Data published in the Official Gazette dated 28 October 2017. |
3. Recording media
The table below shows the media in which personal data retained by the Company are recorded. Retained personal data are kept in the most appropriate recording medium according to their nature and legal status.
| Data Recording Medium | Description |
|---|---|
| Electronic media | Servers (backup, email, file sharing, etc.), information security devices (firewall, antivirus, etc.), company computers (desktop, laptop, etc.), company mobile devices, optical discs, removable memory devices. |
| Non-electronic media | Paper, manual data recording systems (notebooks, customer tracking files, employee personnel files, etc.), written, printed and visual media. |
4. Responsibilities and division of duties
Pursuant to subparagraph (f) of Article 6 of the Regulation, the titles, duties and units of the persons involved in the processes of retention and destruction of personal data must be specified. In this context, in order to prevent the unlawful processing of and access to personal data and to ensure their lawful retention, the titles and job descriptions of the persons responsible for managing data security, retention and destruction processes and for taking technical and administrative measures are set out below.
| Title | Job description |
|---|---|
| Personal Data Manager | Responsible for directing all planning, analysis, research and risk identification work in projects carried out in the process of compliance with the Law; managing the processes to be carried out under the Law, the Personal Data Processing and Protection Policy, this Policy and other policies and procedures; and deciding on requests received from data subjects. |
| Personal Data Protection Specialist (technical and administrative) | Responsible for examining the requests of data subjects and reporting them to the Personal Data Manager for evaluation; carrying out the actions relating to requests that have been decided upon; conducting and auditing retention and destruction processes; and reporting on these audits. |
| Human Resources and Legal Affairs Officer | Responsible, in line with the job description, for implementing the policies and for audits relating to the protection, retention and destruction of personal data. |
5. Explanations regarding retention and destruction
Within the Company, personal data belonging to persons to whom services are provided and to Company personnel are processed in accordance with the matters set out in the Law, retained in the recording media specified in this Policy and destroyed in the manner specified in this Policy.
Personal data are retained on the basis of one or more of the processing conditions set out in Articles 5 and 6 of the Law. Personal data retained for as long as those conditions remain valid are erased, destroyed or anonymised when the processing conditions cease to exist or upon the data subject's application to the Company, after the Company's other legal obligations have been checked.
5.1. Legal grounds requiring retention
Personal data processed within the framework of the Company's activities are kept for the period stipulated in the relevant legislation. In this context, the relevant regulations, primarily the following legislation, are taken as a basis:
- Law No. 1618 on Travel Agencies and the Association of Travel Agencies and its related regulations.
- Labour Law No. 4857.
- Law No. 5510 on Social Insurance and General Health Insurance.
- Unemployment Insurance Law No. 4447.
- Law No. 6331 on Occupational Health and Safety.
- Turkish Commercial Code No. 6102.
- Tax Procedure Law No. 213.
- Law No. 6502 on Consumer Protection.
- Law No. 1774 on Identity Notification.
- Regulation on Archive Services.
- The need to fulfil legal and regulatory requirements arising or that may arise from other relevant legislation and secondary regulations, and to take the necessary measures in this context.
5.2. Processing purposes requiring retention
The Company retains the personal data it processes within the framework of its activities for the following purposes:
- Fulfilment of obligations arising from employment contracts and legislation for employees
- Conduct of fringe benefit and entitlement processes for employees
- Conduct of activities in accordance with legislation
- Conduct and supervision of business activities
- Conduct of occupational health and safety activities
- Conduct of goods and services sales processes
- Conduct of after-sales support services for goods and services
- Conduct of customer relationship management processes
- Conduct of activities aimed at customer satisfaction
- Conduct of advertising, campaign and promotion processes
- Conduct of supply chain management processes
- Provision of information to authorised persons, institutions and organisations
- Conduct of performance evaluation processes
- Conduct of retention and archiving activities
- Follow-up of requests and complaints
5.3. Reasons requiring destruction
In the following cases:
- Amendment or repeal of the provisions of the relevant legislation on which their processing is based,
- Disappearance of the purpose requiring their processing or retention,
- Withdrawal of explicit consent by the data subject in cases where the processing of personal data is based solely on explicit consent,
- Acceptance by the Company of an application made by the data subject, within the framework of their rights under Article 11 of the Law, for the erasure and destruction of their personal data,
- Where the Company rejects an application made by the data subject requesting the erasure, destruction or anonymisation of their personal data, finds its response insufficient or fails to respond within the period stipulated in the Law, the data subject's filing of a complaint with the Board and the Board's approval of this request,
- Expiry of the maximum period requiring the retention of personal data and the absence of any condition justifying retention for a longer period,
- Expiry of the retention periods set out in the relevant legislation,
personal data are erased, destroyed or anonymised upon the request of the data subject or ex officio.
6. Technical and administrative measures taken for secure retention and the prevention of unlawful processing
The Company takes the necessary technical and administrative measures, appropriate to the nature of the relevant personal data and the environment in which they are kept, to ensure the secure retention of personal data and to prevent their unlawful processing and access. In addition, pursuant to Article 12 and the fourth paragraph of Article 6 of the Law, additional technical and administrative measures are taken for special category personal data within the framework of the adequate measures determined and announced by the Board.
These measures include, but are not limited to, those listed below.
6.1. Technical measures
- Network security and application security are ensured.
- Security measures are taken within the scope of the procurement, development and maintenance of information technology systems.
- An authorisation matrix has been created for employees.
- The authorisations of employees who change roles or leave the company are removed in this area.
- Up-to-date antivirus systems are used.
- Firewalls are used.
- The necessary security measures are taken regarding entry to and exit from physical environments containing personal data.
- Personal data are backed up and the security of the backed-up personal data is also ensured.
- A user account management and authorisation control system is implemented and monitored.
- Cyber security measures have been taken and their implementation is continuously monitored.
- Encryption is used.
6.2. Administrative measures
- There are disciplinary regulations for employees that include data security provisions.
- Training and awareness activities on data security are carried out for employees at regular intervals.
- Corporate policies on access, information security, use, retention and destruction have been prepared and put into practice.
- Confidentiality undertakings are made.
- The contracts signed contain data security provisions.
- Personal data security policies and procedures have been established.
- Personal data security issues are reported promptly.
- Personal data security is monitored.
- The security of physical environments containing personal data against external risks (fire, flood, etc.) is ensured.
- The security of environments containing personal data is ensured.
- Personal data are reduced as far as possible.
- Existing risks and threats have been identified.
- Protocols and procedures for the security of special category personal data have been established and are implemented.
- Awareness of data security among data processing service providers is ensured.
7. Personal data destruction techniques
The Company erases, destroys or anonymises the personal data it retains in accordance with the Law, other legislation and the Personal Data Processing and Protection Policy, when the reasons requiring their processing cease to exist, upon the request of the data subject or ex officio within the periods specified in this Policy.
7.1. Erasure methods
| Erasure methods for personal data kept in physical media | |
|---|---|
| Blacking out | Personal data in physical media are erased using the blacking-out method. Blacking out is carried out by cutting out the personal data on the relevant document where possible and, where this is not possible, by making them invisible using permanent ink in a way that cannot be reversed or read with technological solutions. |
| Erasure methods for personal data on servers | |
| Erasure by removing access rights | For personal data on servers whose required retention period has expired, the system administrator removes the access rights of the relevant users and the erasure is carried out. |
7.2. Destruction methods
| Destruction methods for personal data kept in physical/printed media | |
|---|---|
| Physical destruction | Documents kept in printed form are destroyed with document shredders in such a way that they cannot be put back together. |
| Destruction methods for personal data kept in local digital media and on servers | |
| Physical destruction | The physical destruction of optical and magnetic media containing personal data, such as by melting, burning or pulverising. |
| Degaussing | Exposing magnetic media to a strong magnetic field so that the data on them are corrupted and rendered unreadable. |
| Overwriting | Random data consisting of 0s and 1s are written at least seven times over magnetic media and rewritable optical media, preventing the old data from being read and recovered. |
| Destruction by removing access rights | For personal data on servers whose required retention period has expired, the access rights of the relevant users are removed and destruction is carried out in such a way that the data can never be accessed again. |
7.3. Anonymisation methods
The Company renders personal data incapable of being associated with an identified or identifiable natural person, even through the use of appropriate techniques. Personal data are anonymised using the methods in the table below.
| Anonymisation methods for personal data kept in physical/printed media | |
|---|---|
| Removing variables | Removing one or more of the direct identifiers contained in the personal data of the data subject that would serve to identify the data subject. |
| Regional suppression | In a data table in which personal data are held collectively in anonymous form, deleting information that may be distinctive in relation to data that constitute an exception. |
| Generalisation | Bringing together the personal data of many persons and removing distinguishing information to turn them into statistical data. |
| Top and bottom coding / global coding | For a given variable, ranges for that variable are defined and categorised; values falling within the same category are combined. |
| Micro-aggregation | The records in the data set are arranged in a meaningful order and divided into subsets; the value of the relevant variable in each subset is replaced with the average value. |
| Data swapping and perturbation | The direct or indirect identifiers in personal data are mixed with or perturbed by other values, breaking their link with the data subject. |
| Anonymisation methods for personal data kept in digital media, on servers and in cloud environments | |
| Masking | Making personal data unintelligible in order to prevent access by unauthorised persons (encryption, use of symbols, blurring, scrambling, invalidation). The data format is not changed; only the values are changed irreversibly. |
8. Personal data retention and destruction periods
With regard to the personal data processed by the Company within the scope of its activities:
- retention periods on a personal data basis for all personal data within the scope of activities carried out in connection with processes are set out in the Personal Data Processing Inventory,
- retention periods on a data category basis are set out in the VERBİS registration,
- retention periods on a process basis are set out in this Policy.
The Company updates these retention periods where necessary.
8.1. Retention and destruction periods
| Process | Retention period | Destruction period |
|---|---|---|
| Employee personnel file | 10 years | At the first periodic destruction following the end of the retention period |
| File of persons purchasing goods/services | 10 years | At the first periodic destruction following the end of the retention period |
| Job applicant file | Until the position applied for is filled | At the first periodic destruction following the end of the retention period |
| Supplier file | 10 years | At the first periodic destruction following the end of the retention period |
| Website reservation requests (payment completed) | 5 years from the end date of the event | Automatically anonymised when the period expires |
| Website reservation requests (other) | 1 year from the end date of the event | Automatically anonymised when the period expires |
| Reservation system transaction security records (IP address hash and submission time) | 48 hours at most | Automatically erased; not included in backups |
| Reservation system database backups (on the server) | 8 weeks | Automatically erased |
| Reservation system database backups (off the server, encrypted) | 1 year | At the first periodic destruction following the end of the retention period |
| Website contact form messages | 2 years from the reply; for those that become a commercial relationship, 10 years from the end of the relationship | At the first periodic destruction following the end of the retention period |
| Server access logs (at the hosting provider) | The period determined by the hosting provider | Erased by the provider |
In reservation request records, anonymisation is carried out by erasing the first name and surname, the names of those staying together, the email address, the telephone number, the organisation, the customer note, internal notes, the payment link and the descriptions in the transaction history, and by replacing the request number with a random value that cannot be associated with the person. Dates, room type, number of guests, amount, request status and the record of acceptance of the terms remain. Anonymisation and erasure run automatically every day in the reservation system.
Reservation request notification emails sent within the Company do not contain personal data and are therefore not subject to a separate retention period.
8.2. Data destruction periods
The Company erases, destroys or anonymises the personal data for which it is responsible under the Law, the relevant legislation, the Personal Data Processing and Protection Policy, its other policies and this Policy at the first periodic destruction following the date on which the obligation to erase, destroy or anonymise arises.
When a data subject applies to the Company pursuant to Article 13 of the Law requesting the erasure or destruction of their personal data:
- If all the conditions for processing the personal data have ceased to exist, the Company erases, destroys or anonymises the personal data subject to the request using the appropriate destruction method within thirty days of the date of receipt of the request, stating its reasons. For the request to be deemed received, the data subject must have made the application in accordance with the Personal Data Processing and Protection Policy and the application procedure.
- If not all the conditions for processing the personal data have ceased to exist, the request may be rejected with reasons pursuant to the third paragraph of Article 13 of the Law; the rejection is notified to the data subject in writing or electronically within thirty days at the latest.
In all cases, the Company informs the data subject of the action taken.
9. Periodic destruction period
Where all the conditions for processing personal data set out in the Law have ceased to exist, the Company erases, destroys or anonymises the personal data whose processing conditions have ceased to exist through an operation carried out ex officio at the recurring intervals specified in this Policy.
Periodic destruction processes start for the first time on 1 January 2027 and are repeated every six months.
10. Publication, retention and updating of the Policy
The Policy is published in two different media, with a wet signature (printed paper) and electronically, and is disclosed to the public on the Company's website. The printed paper copy is kept on file by the Company management or the Personal Data Manager.
The Policy is reviewed as needed and the necessary sections are updated.
11. Compliance and amendments
The Company has the right to amend this Policy as required by legislation or by company policy.
This Policy was published on 1 October 2026.
In the event of any inconsistency, the Turkish text prevails.