Privacy policy
Back to Platform1. Purpose and scope
The purpose of this policy is to inform about the personal data processing activities conducted by Leak Sonar and the practices related to the protection of personal data, thereby ensuring transparency by informing individuals whose personal data are processed by our company, including our customers, potential customers, job applicants, company stakeholders, company officials, visitors, employees of companies or institutions we collaborate with, their stakeholders and officials, as well as third parties.
In line with this purpose, the scope of this policy includes all personal data processed through automatic or non-automatic means, whether belonging to our customers, potential customers, job applicants, company stakeholders, company officials, visitors, employees of companies or institutions we collaborate with, their stakeholders and officials, and third parties, provided that they are part of any data recording system.
2. Responsible parties
LEAK SONAR Top Management, relevant Department Managers, and all employees are responsible for the implementation of this procedure.
3. Implementation
3.1 Introduction
Data protection is one of the top priorities for Leak Sonar ("Company" or "Leak Sonar"). The most important aspect of data protection is the management of personal data, which is governed by this Policy, concerning the protection and processing of personal data of our customers, potential customers, job applicants, company stakeholders, company officials, visitors, employees of companies or institutions we collaborate with, their stakeholders and officials, and third parties. The management of personal data of our employees is carried out in parallel with the principles outlined in this Policy through the Leak Sonar Personal Data Protection and Processing Policy.
According to the laws, everyone has the right to demand the protection of their personal data. Leak Sonar takes the necessary care to protect the personal data of its customers, potential customers, job applicants, company stakeholders, company officials, visitors, employees of companies or institutions we collaborate with, their stakeholders and officials, and third parties, as stipulated in this Policy.
Necessary administrative and technical measures are taken by Leak Sonar at the highest level for the protection of personal data processed in accordance with national and international legal regulations.
Detailed explanations regarding the fundamental principles of personal data processing are provided below:
- Processing personal data in accordance with the law and principles of integrity,
- Keeping personal data accurate and up-to-date when necessary,
- Processing personal data for specific, clear, and legitimate purposes,
- Processing personal data in a manner that is relevant, limited, and proportionate to the purposes for which they are processed,
- Storing personal data for the period prescribed by the relevant legislation or for the time necessary for the purposes for which they are processed,
- Informing and educating data subjects about their personal data,
- Establishing a system necessary for data subjects to exercise their rights,
- Taking necessary measures for the protection of personal data,
- Complying with the relevant legislation and Personal Data Protection Board regulations when transferring personal data to third parties in accordance with the purposes of processing,
- Showing necessary sensitivity in processing and protecting personal data of special nature.
3.2 Implementation of the policy and relevant legislation
The applicable legal regulations regarding the processing and protection of personal data will primarily govern the implementation. In the event of any inconsistency between the current legislation and the Policy, our company acknowledges that the provisions of the current legislation will prevail. The Policy has been formulated by concretizing the rules set forth by relevant legislation within the scope of Leak Sonar practices.
3.3 The implementation of policy
The Policy, organized by our company, is dated February 29, 2024. In case of the renewal of the entire Policy or specific sections thereof, the effective date of the Policy will be updated.
The Policy will be published on our company’s website (www.leaksonar.io).
3.4 Provision regarding the protection of personal data
3.4.1 Ensuring the security of personal data
3.4.1.1 Technical and administrative measures
A. Our company takes organizational measures and technical precautions to ensure the lawful processing of personal data.
The main technical precautions taken by our company to ensure the lawful processing of personal data are listed below:
- Network security and application security are ensured.
- Security measures are taken within the scope of procurement, development, and maintenance of information technology systems.
- The security of personal data stored in the cloud is ensured.
- An authorization matrix is created for employees.
- Access logs are regularly maintained.
- Data masking measures are implemented when necessary.
- Current anti-virus systems are utilized.
- Security firewalls are employed.
- Personal data is backed up, and the security of backed-up personal data is ensured.
- User account management and authorization control systems are implemented, and their tracking is conducted.
- Log records are maintained without user intervention.
- If special category personal data is to be sent via email, it is always sent encrypted and using a secure email protocol or corporate email account.
- Secure encryption/cryptographic keys are used for special category personal data and managed by different units.
- Intrusion detection and prevention systems are utilized.
- Penetration testing is conducted.
- Cybersecurity measures are taken and their implementation is continuously monitored.
- Encryption is applied.
- Data loss prevention software is used.
B. The main organizational measures taken by our company to ensure the lawful processing of personal data are listed below:
- Our company has appointed a Data Protection Officer and formed a Privacy team, which includes the Data Protection Officer.
- Employees are informed about and trained on the law regarding the protection of personal data and the lawful processing of personal data.
- All activities conducted by our company are analyzed in detail across all departments.
- Personal data processing activities are identified on a case-by-case basis.
- Awareness is created in relevant departments and implementation rules are established.
- Contracts and documents governing legal relationships include confidentiality obligations.
- Discipline regulations containing data security provisions are in place for employees.
- Corporate policies regarding access, information security, use, storage, and disposal are implemented.
- Privacy commitments are made.
- Signed contracts contain data security provisions.
- Issues related to personal data security are reported promptly.
- Security measures are taken regarding access to physical environments containing personal data.
- Internal periodic and/or random audits are conducted.
- Existing risks and threats have been identified.
3.4.1.2 Audit of measures taken for the protection of personal data
Our company conducts or commissions necessary audits within its own structure in accordance with Article 12 of the Personal Data Protection Law. The results of these audits are reported to relevant departments, and activities are undertaken to improve the measures taken.
3.4.2 Respecting the rights of data subjects; establishing channels for transmitting these rights to our company and evaluating data subjects’ requests
Our company operates the necessary channels, internal processes, and administrative and technical regulations in accordance with Article 13 of the Personal Data Protection Law to evaluate the rights of data subjects and to provide the necessary information to them.
Data subjects have the following rights:
- Learning whether personal data is being processed,
- Requesting information if personal data has been processed,
- Learning the purpose of processing personal data and whether they are being used in accordance with this purpose,
- Knowing the third parties to whom personal data are transferred domestically or abroad,
- Requesting correction of personal data in case they are incomplete or incorrect,
- Requesting deletion or destruction of personal data where legal conditions are met,
- Objecting to outcomes based solely on automated processing,
- Requesting compensation for damages caused by unlawful processing.
3.4.3 Protection of special categories of personal data
Special categories of personal data include race, ethnic origin, political opinion, philosophical belief, religion, sect, other beliefs, appearance and clothing, association/foundation/union membership, health, sexual life, criminal conviction and security measure data, biometric data, and genetic data.
Our company applies enhanced technical and administrative measures for these data and conducts necessary audits.
3.4.4 Awareness and audit of personal data protection and processing in business units
Our company organizes and repeats necessary training sessions for business units and business partners to increase awareness and prevent unlawful processing/access.
Processing of personal data
Our company processes personal data in accordance with Article 20 of the Constitution and Article 4 of Law No. 6698, in compliance with legal regulations, honesty principles, and principles of accuracy, currency, specificity, clarity, and legitimacy.
Compliance of personal data with principles stated in legislation
- Compliance with legality and honesty,
- Ensuring data is accurate and up-to-date when necessary,
- Processing for specified, clear, and legitimate purposes,
- Processing in a limited and proportionate manner,
- Retaining data for the legally required or purpose-required period.
Processing personal data based on one or more conditions in article 5 of law no. 6698
Our company processes personal data based on legal grounds including explicit consent where required, legal obligations, contract necessity, protection of rights, legitimate interest, and other lawful bases under Article 5.
Informing and notifying the data subject
Our company informs data subjects under Article 10 regarding identity of data controller, purpose, transfer parties, collection method, legal basis, and rights.
Processing of special category personal data
Our company processes special category personal data in accordance with Article 6 of the KVKK and under strict legal conditions, with explicit consent where necessary and with adequate safeguards.
Transfer of personal data
Our company may transfer personal data to third parties in line with Articles 8 and 9 of KVKK, by taking necessary technical and administrative security measures and only for lawful and legitimate purposes.
Transfer of personal data abroad
Our company may transfer personal data abroad to countries with adequate protection or with required legal safeguards/permissions under KVKK Article 9.
Categorization of personal data, purposes, and retention periods
Personal data is categorized, processed, retained, and disposed of in accordance with KVKK principles, legal obligations, and company retention requirements.
Third parties to whom personal data may be transferred
Personal data may be transferred to:
- Leak Sonar business partners/distributors,
- Leak Sonar suppliers,
- Leak Sonar affiliates,
- Leak Sonar shareholders,
- Hosting companies providing services.
Processing conditions for personal data and special category personal data
Explicit consent is one legal basis. Depending on the situation, processing may also rely on legal obligation, contract necessity, legitimate interest, legal claims, public disclosure by the data subject, and similar legal grounds.
Processing of special category personal data is carried out in line with kvkk, with explicit consent or where laws expressly allow and with strict safeguards.
Processing at building/facility entrances and internet access for visitors
Our company may process visitor entry/exit data and internet access logs for security purposes and in line with applicable legislation, including Law No. 5651.
Erasure, destruction, and anonymization of personal data
When the legal basis or purpose for processing personal data ceases, our company erases, destroys, or anonymizes personal data in accordance with KVKK Article 7 and Turkish Penal Code Article 138.
Techniques include physical destruction, secure software deletion, secure deletion by experts, and anonymization methods that prevent identification.
Rights of data subjects
Data subjects may exercise rights under KVKK, including:
- Access,
- Information request,
- Purpose and transfer learning,
- Correction,
- Deletion/destruction,
- Objection to automated decisions,
- Compensation claims.
Exceptions
Certain rights may be limited in cases specified under KVKK Article 28.
Application method
Data subjects may submit applications via the Personal Data Application Form at www.leaksonar.io and by signed email to [email protected].
Complaint right
If requests are rejected, insufficiently answered, or unanswered in due time, data subjects may complain to the Personal Data Protection Board within legal periods under Article 14.
Response to applications
Our company responds as soon as possible and within thirty days, free of charge unless additional costs apply per official tariff.
Our company may request additional verification information and may reject applications where legal exception grounds apply.