Note: This page is an English translation provided for the convenience of international applicants. The Turkish text is the binding version. As the policy itself states: in the event of any discrepancy between the Turkish text and any translation, the Turkish text prevails.

Caferilik İnancını Tanıtma, Araştırma ve Eğitim Derneği — Personal Data Retention and Destruction Policy

Document Name: Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği Personal Data Retention and Destruction Policy

Target Audience: All natural persons whose personal data is processed by Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği

Prepared / Approved by: Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği Personal Data Protection Committee

Version: v. 0.1

Effective Date: 6 June 2025

Where the Policy has been prepared in Turkish, and a discrepancy arises between that Turkish version and any translated version, the Turkish text shall be taken into account.

© Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği, 2026. This document may not be reproduced or distributed without the written permission of Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği.

1. Introduction

The protection of personal data is of great importance to Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği (the "Association"), which shows the utmost sensitivity on this matter. Accordingly, processing personal data in a manner consistent with individuals' expectations and in compliance with the law is one of our Association's fundamental cornerstones.

In this respect, our Association retains and destroys the personal data it obtains during its activities in accordance with the general principles and arrangements set out in this Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği Personal Data Retention and Destruction Policy (the "Policy"), which has been prepared in compliance with the Constitution above all, Law No. 6698 on the Protection of Personal Data (the "Law"), the Regulation on the Deletion, Destruction, or Anonymisation of Personal Data (the "Regulation"), and other applicable legislation.

2. Purpose and Scope of the Policy

Through this Policy, our Association aims to set out the Association's general principles concerning the retention and destruction of the personal data of natural persons subject to its data processing activities under the Law, and to fulfil the obligations set out in the relevant legislation on these matters.

This Policy covers all personal data subject to our Association's data processing activities under the Law. In addition, unless otherwise stated in this Policy, the documents referenced by this Policy cover both their printed and electronic copies.

3. Definitions

Unless the context requires otherwise, in this Policy:

4. Recording Media Governed by the Policy

Our Association retains all personal data subject to its data processing activities under the Law, in media containing personal data processed wholly or partly by automated means, or by non-automated means provided that they form part of a data recording system.

5. Reasons Requiring the Retention and Destruction of Personal Data

Our Association bases its personal data processing activities on the following principles:

In line with the principles mentioned above, our Association retains and uses personal data based on the personal data processing purposes set out in the relevant articles of the Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği Personal Data Protection and Processing Policy and the Caferilik İnancını Tanıtma, Araştırma Ve Eğitim Derneği Employees' Personal Data Protection and Processing Policy, and on the conditions for processing personal data set out in Articles 5 and 6 of the Law below, and destroys personal data ex officio or upon the request of the Data Subject once all of these conditions cease to exist.

(a) Explicit Consent of the Data Subject

One of the conditions for processing personal data is the explicit consent of the data subject. The Data Subject's explicit consent must be declared in relation to a specific matter, based on being informed, and with free will.

(b) Being Expressly Provided for by Law

The data subject's personal data may be lawfully processed without obtaining explicit consent where this is expressly provided for by law.

(c) Impossibility of Obtaining the Data Subject's Explicit Consent Due to Actual Impossibility

Where it is mandatory to process the personal data of a person who is unable to declare consent due to actual impossibility, or whose consent is not legally valid, in order to protect the life or bodily integrity of that person or of another person, the data subject's personal data may be processed.

(d) Direct Connection to the Establishment or Performance of a Contract

Provided that it is directly related to the establishment or performance of a contract, the processing of personal data belonging to the parties to the contract may be permitted where it is necessary.

(e) Legal Obligation

Where data processing is mandatory for our Association to fulfil its legal obligations, the Data Subject's data may be processed.

(f) The Data Subject Having Made Their Own Personal Data Public

Where the data subject has made their own personal data public, the relevant personal data may be processed to the extent limited to the purpose of that disclosure.

(g) Data Processing Being Mandatory for Our Association's Legitimate Interest

Provided that it does not harm the data subject's fundamental rights and freedoms, where data processing is mandatory for our Association's legitimate interests, the data subject's personal data may be processed.

Accordingly, the basis of a personal data processing activity may be only one of the conditions listed above, or more than one of these conditions may together form the basis of the same personal data processing activity.

6. Methods Applied for the Destruction of Personal Data, and the Technical and Administrative Measures Taken for the Lawful Destruction of Personal Data

Where all of the conditions for processing personal data set out in Articles 5 and 6 of the Law cease to exist, our Association deletes, destroys, or anonymises personal data using the methods below. Our Association exercises utmost care and diligence in the destruction of personal data. In this context, our Association takes the necessary technical and administrative measures, according to technological possibilities and the cost of implementation, in accordance with Article 12 of the Law, the provisions of the Regulation, the general principles stated above, this Policy, and Board decisions. All operations carried out within the scope of destruction are recorded by our Association, and such records are kept for at least three years, except for other legal obligations. Unless otherwise decided by the Board, our Association selects, ex officio, whichever of the Deletion, Destruction, or Anonymisation methods is appropriate according to technological possibilities and the cost of implementation, and explains the rationale for the method chosen upon the Data Subject's request.

(a) Methods of Deleting Personal Data

The Deletion of personal data is the process of rendering personal data inaccessible and unusable in any way whatsoever for relevant users. Our Association takes all necessary technical and administrative measures, according to technological possibilities and the cost of implementation, to ensure that deleted personal data is inaccessible and unusable for relevant users.

In this context, our Association applies the following methods for the Deletion of personal data: personal data held in databases is classified by field and its retention period is determined accordingly. System fields are periodically checked (weekly/monthly) and data that needs to be deleted is reported to the relevant managers. Data will be deleted by system administrators, and the record will be closed once deleted.

(b) Methods of Destroying Personal Data

The destruction of personal data is the process of rendering personal data inaccessible, irretrievable, and unusable by anyone, in any way whatsoever. Our Association takes all necessary technical and administrative measures related to the destruction of personal data, according to technological possibilities and the cost of implementation.

In this context, our Association applies the following methods for the Destruction of personal data:

Electronic/Magnetic Media: For personal data on electronic/magnetic media whose required retention period has ended, physical destruction methods such as melting, incinerating, or pulverising are applied. In addition, magnetic media is passed through a special device and exposed to a high-value magnetic field so that the data on it is rendered unreadable.

(c) Methods of Anonymising Personal Data

The Anonymisation of personal data is rendering personal data incapable of being associated with an identified or identifiable natural person under any circumstances, even when matched with other data. For personal data to be considered anonymised, it must be rendered incapable of being associated with an identified or identifiable natural person even through the use of techniques appropriate to the recording medium and the relevant field of activity — such as reversal or matching with other data — by our Association, the recipient, or recipient groups. Our Association takes all necessary technical and administrative measures related to the Anonymisation of personal data, according to technological possibilities and the cost of implementation.

7. Technical and Administrative Measures Taken for the Secure Storage of Personal Data and to Prevent Unlawful Processing and Access

Our Association exercises the utmost care and diligence regarding the secure storage of personal data and the prevention of its unlawful processing and access, and takes the necessary technical and administrative measures, according to technological possibilities and the cost of implementation, in accordance with Article 12 of the Law, the provisions of the Regulation, the general principles stated above, this Policy, and Board decisions, including the following:

8. Titles, Units, and Job Descriptions of Those Involved in the Personal Data Retention and Destruction Processes

Our Association informs and trains the persons involved in the processes of retaining and destroying personal data on personal data protection law and the lawful processing of personal data. In this context, our Association's employees and persons who learn personal data due to their duties retain and destroy such information in compliance with the Law and other applicable legislation. This obligation continues even after the persons concerned leave their duties.

9. Retention and Destruction Periods

Our Association retains and destroys personal data only for the period stipulated in the applicable legislation it is obliged to comply with, or for the period required for the purpose for which it is processed. In this context, our Association retains and destroys personal data for the maximum periods specified in the Retention and Destruction Periods Table in Annex-1 [EK-1].

Where a Data Subject applies to our Association and requests the destruction of their personal data, our Association will:

(a) If all of the conditions for processing the personal data have ceased to exist: Conclude the Data Subject's request within thirty days at the latest and inform the Data Subject; and if the personal data subject to the request has been transferred to third parties, notify this to the third party and ensure that the necessary actions are taken by the third party.

(b) If not all of the conditions for processing the personal data have ceased to exist, the Data Subject's request may be rejected by explaining the justification pursuant to the third paragraph of Article 13 of the Law, and the rejection response will be notified to the Data Subject in writing or electronically within thirty days at the latest.

10. Periodic Destruction Periods

Our Association destroys personal data at the first periodic destruction process following the date on which the obligation to destroy the personal data arises. In this context, whenever the obligation to destroy personal data arises, our Association subjects the personal data to the destruction process. This period does not, under any circumstances, exceed the maximum periodic destruction period specified in Article 11 of the Regulation.

11. Entry into Force

This Policy entered into force on 6 June 2025. The Policy may be updated from time to time in order to comply with changing conditions and legislation. The current Policy will enter into force on the date it is published on the Association's notice board.

In the event of any conflict between this Policy and the provisions of the Law and the Regulation, the provisions of the Law and the Regulation shall prevail.

Version: saklama-v1