Personal Data Protection and Processing Policy (KVK Policy)
1. PURPOSE and SCOPE
The protection of personal data and ensuring privacy has been adopted as a corporate culture for Whitebit Kripto Varlık Alım Satım Platformu Anonim Şirketi (hereinafter referred to as "WhiteBIT TR" or "Company").
The Company exercises the utmost care and effort to process and protect personal data belonging to real persons within the scope of its activities in accordance with applicable legal norms and universal legal principles. Within the scope of crypto asset trading, exchange, transfer, and necessary storage activities; the Company processes personal data as the data controller in the context of remote identity verification, customer identification (KYC), transaction monitoring (transaction monitoring), sanctions list screening, risk classification, use of blockchain analysis tools, and fraud prevention activities.
This KVK Policy applies to the personal data of relevant persons other than our employees, which our Company processes as the Data Controller, either fully or partially automatically, or by non-automated means provided that it is part of a data recording system. The KVK Policy demonstrates how the principles and fundamentals established by the relevant legislation are applied in the Company's personal data protection processes. This Policy describes the Company's general policy and processes regarding the processing and protection of personal data; the disclosure obligation under Article 10 of the KVK Law is fulfilled by providing relevant disclosure texts to the individuals concerned based on specific processes.
The relevant legislation, secondary regulations, and universal legal principles in force in this area will primarily apply to the protection and lawful processing of personal data. In the event of any conflict between our KVK Policy and the relevant regulations in force, the regulations in force shall prevail.
We may make updates to this Policy as necessary, so please ensure that you have access to our current Policy when you use our services.
2. DEFINITIONS
| ABBREVIATION | DEFINITION |
|---|---|
| "Explicit Consent" | Consent that is specific to a particular matter, informed, and freely given. |
| “AML CFT” | Prevention of money laundering and countering the financing of terrorism |
| “Information Obligation” | The Company's obligation to provide information to the Relevant Persons during the collection of personal data by the Data Controller or persons authorized by them, in accordance with Article 10 of the KVK Law and the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Disclosure Obligation. |
| “Blockchain Wallet Address” | The account address where users' crypto asset balances are held |
| "Data Subject," "Data Owner" | Natural persons whose personal data is processed by the Company or by persons/institutions authorized on behalf of the Company. |
| “Destruction” | The deletion, destruction, or anonymization of personal data. |
| “Personal Data” | Any information relating to an identified or identifiable natural person. |
| "Anonymization of Personal Data" | The process of rendering personal data incapable of being associated with an identified or identifiable natural person, even when combined with other data. |
| “Processing of Personal Data” | Any operation performed on personal data, such as obtaining, recording, storing, preserving, modifying, reorganizing, disclosing, transferring, acquiring, making available, classifying, or preventing the use of such data, whether fully or partially automated or non-automated, provided that it is part of a data recording system. |
| “Erasure of Personal Data” | The process of rendering personal data inaccessible and unusable for the relevant users. |
| "Destruction of Personal Data" | The process of rendering personal data inaccessible, irrecoverable, and unusable by anyone in any way. |
| “Crypto Asset” | Intangible assets that can be created and stored electronically using distributed ledger technology or similar technology, distributed over digital networks, and capable of representing value or rights. |
| “Board” | Personal Data Protection Board |
| “Authority” | Personal Data Protection Authority |
| “Law”, “KVK Law” | Law No. 6698 on the Protection of Personal Data |
| “KVK Policy” | The Personal Data Protection and Processing Policy adopted by the Company. |
| “KYC” | The customer identification process |
| “Special Category Personal Data” | Data related to a person's race, ethnic origin, political opinion, philosophical belief, religion, denomination or other beliefs, attire, membership in associations, foundations or unions, health, sex life, criminal convictions and security measures, as well as biometric and genetic data. |
| “Company” | Whitebit Kripto Varlık Alım Satım Platformu Anonim Şirketi |
| “VERBİS”, “Register” | The Data Controllers Registry Information System maintained by the Presidency of the Personal Data Protection Authority. |
| “Data Processor” | A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller. |
| “Data Controller” | A natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system. |
| "Remote Identity Verification" | Customer identification procedures carried out between the Company and the customer without meeting in person, using technological tools. |
3. GENERAL PRINCIPLES IN THE PROCESSING OF PERSONAL DATA
The Company complies with the "General Principles" that must be adhered to when processing personal data as listed in Article 4 of the Personal Data Protection Law:
1. Processing in Compliance with the Law and Rules of Good Faith
The company manages personal data processing activities in accordance with legal norms, universal legal principles, and rules of fairness; informs relevant individuals as necessary to ensure the transparency of processes; and takes into account the interests and reasonable expectations of relevant individuals in these processes. In this context, it prevents the emergence of consequences that are unexpected and unreasonable for the relevant individual.
2. Ensuring that Personal Data is Accurate and, Where Necessary, Kept Up to Date
Personal data is generally processed based on the relevant individuals' statements and as stated, and it is assumed that the personal data is accurate as stated. The Company exercises reasonable care and attention to ensure that personal data within its legal entity is accurate and up-to-date and does not contain incorrect information. If the data subject informs the Company of any changes in the personal data processed, the Company ensures that the necessary administrative and technical mechanisms are in place to update the personal data in the relevant database.
3. Processing for Specific, Clear, and Legitimate Purposes
The Company clearly and explicitly states its legitimate and lawful data processing purposes before commencing personal data processing activities and processes personal data in connection with the Company's products and services and only to the extent necessary for them.
4. Relevance, Limitation, and Proportionality
Personal data is processed by the Company in a manner that is relevant, limited, and proportionate to the purposes determined by the Company and disclosed to the data subject. The Company ensures that the processing is proportionate to the purpose to be achieved, taking into account the need to strike a reasonable balance between the purpose of the data processing activity and the processing itself.
5. Retention for the Period Required by the Relevant Legislation or Necessary for the Purpose of Processing
The Company retains personal data for the period required by legislation or for the purpose of processing. However, when the period specified by legislation ends or when the purposes of processing cease to exist, the Company deletes, destroys, or anonymizes personal data. As the Data Controller, the Company has determined the retention periods, destruction periods, and technical and administrative measures to be implemented in the retention of personal data in its Personal Data Retention and Destruction Policy and is aware that it is responsible for ensuring that personal data is retained in accordance with these principles.
These principles apply regardless of whether the Company has processed personal data based on explicit consent or in accordance with other data processing conditions. In this regard, the Company processes personal data in accordance with data processing conditions and general principles and also fulfills its obligation to inform the relevant persons.
4. INFORMATION REGARDING THE PROCESSING OF PERSONAL DATA
The Company informs the data subjects about the categories of personal data it processes, the groups of data subjects whose data is processed, the purposes of processing personal data, the legal conditions on which the processing of personal data is based, the channels through which personal data is collected, the recipient groups to which it is transferred, the retention periods and destruction processes for expired personal data, and the security measures it has taken to ensure the security of personal data throughout all these processes. All this information is published publicly and updated on the VERBİS (verbis.kvkk.gov.tr) registry information system on the Institution's website and is updated on the relevant platform.
1. PERSONAL DATA CATEGORIES
The Company has categorized the personal data it processes in order to comply with legal regulations and to properly manage personal data processing and protection processes.
All personal data categories are fundamentally organized under two main categories: "Personal Data" and "Special Category Personal Data."
All personal data categories processed within our company and their definitions are as follows:
| PERSONAL DATA CATEGORY | DEFINITION |
|---|---|
| Identity Data | First name, last name, mother's and father's names, mother's maiden name, date of birth, place of birth, marital status, ID card serial number, Turkish ID number, signature, etc. |
| Contact Data | Address number, email address, contact address, registered electronic mail address (KEP), phone number, etc. |
| Personal Data | Payroll information, disciplinary investigation, employment entry-exit document records, property declaration information, resume information, performance evaluation reports, etc. |
| Legal Transaction Data | Information in correspondence with judicial authorities, information in court files, etc. |
| Customer Transaction Data | Call center records, invoice, promissory note, check information, information on cashier receipts, order information, request information, etc. |
| Physical Premises Security | Employee and visitor entry/exit records, camera recordings, etc. |
| Transaction Security Data | IP address information, website entry and exit information, password and PIN information, Blockchain wallet address, Crypto asset transfer history, Transaction hash information, Risk scores, Suspicious transaction assessment notes |
| Risk Management Data | Information processed for managing commercial, technical, and administrative risks, AML risk classification, sanctions list screening results, PEP control records, blockchain analysis reports |
| Financial Data | Bank, IBAN, balance sheet information, financial performance information, credit and risk information, asset information, etc. |
| Professional Experience Data | Diploma information, courses attended, professional training information, certificates, transcript information, etc. |
| Marketing | Purchase history information, surveys, cookie records, information obtained through campaign activities, etc. |
| Visual and Audio Recordings | Photographs, videos, visual and audio recordings, etc. |
| SPECIAL CATEGORY OF PERSONAL DATA | DEFINITION |
| Criminal Convictions and Security Measures | Information related to criminal convictions, information related to security measures, etc. |
| Health Information | Information related to disability status, blood type information, personal health information, information on devices and prostheses used, etc. |
| Philosophical Beliefs, Religion, Denomination, and Other Beliefs | Information about religious affiliation, information about philosophical beliefs, information about sect affiliation, information about other beliefs, etc. |
| Biometric Data | Palm print information, fingerprint information, retina scan information, facial recognition information, etc. |
2. PERSONAL DATA PROCESSED PERSON GROUPS
The relevant groups of persons whose personal data is processed within our company and their definitions are publicly disclosed and published on the VERBİS (verbis.kvkk.gov.tr) address on the Institution's website.
3. PURPOSES OF PROCESSING PERSONAL DATA
The Company processes personal data in accordance with the "General Principles for Processing Personal Data" set forth in Article 4 of the Law and as described above, and in a manner that is appropriate and limited to at least one of the personal data processing conditions specified in Articles 5 and 6 of the Law. The Company informs the relevant groups of individuals separately about the categories and purposes of data processing in the relevant information texts, in accordance with Article 10 of the Law and secondary legislation. The Company's purposes for processing personal data are declared in the Data Controllers Information System (VERBİS) and are publicly accessible in the system (link: verbis.kvkk.gov.tr).
4. CONDITIONS FOR PROCESSING PERSONAL DATA
The Company processes personal data with the explicit consent of the relevant person or in accordance with one or more of the other data processing conditions, if any. If the processed personal data is special category personal data, the conditions specified in the "Processing of Special Category Personal Data" section of this Policy apply.
- Existence of the Data Subject's Explicit Consent
This data processing condition applies when the data subject has given their explicit consent, based on information provided, freely and for a specific purpose. The explicit consent obtained from the data subject is retained by the Company in a verifiable manner for the period required under the Personal Data Protection legislation. Personal data may be processed without the explicit consent of the data subject if any of the personal data processing conditions listed below apply.
- Explicit Provision in Laws
If the relevant law contains an explicit provision regarding the processing of that personal data, this data processing condition applies. For example, personal data is processed for the purposes of fulfilling legal obligations under the provisions of the Personal Data Protection Law, the Consumer Protection Law, the Turkish Code of Obligations, the Turkish Commercial Code, the Tax Procedure Law, the Capital Markets Law, and other relevant legislation.
- Failure to Obtain the Data Subject's Explicit Consent Due to Practical Impossibility
If it is impossible to obtain the consent of a person who is unable to express their consent or whose consent is not legally valid, and if the processing of their personal data is necessary to protect their life or physical integrity or that of another person, the data of the person concerned shall be processed based on this data processing condition.
- Directly Related to the Establishment or Performance of a Contract
If the processing of personal data is necessary and directly related to the establishment or performance of a contract to which the data subject is a party, the data may be processed based on this data processing condition.
- Necessary for the Data Controller to Fulfill Its Legal Obligations
If the processing of personal data is necessary for our company to fulfill its legal obligations arising from legislation or contracts, the processing is based on this data processing condition. Personal data is processed within the scope of legal obligations such as fulfilling customer identity verification obligations, detecting suspicious transactions under MASAK legislation, preventing fraud and market manipulation, complying with CMB regulations, verifying transactions on the blockchain, and ensuring cyber and system security.
- Personal Data Made Public by the Data Subject
Personal data made public by the data subject themselves is processed only for the purpose of making it public.
- Necessity of Data Processing for the Establishment, Exercise, or Defense of a Legal Claim
If data processing is necessary for the establishment, exercise, or defense of a legal claim, the data subject's personal data is processed based on this data processing condition.
- Data Processing Necessary for the Legitimate Interests of the Data Controller
Provided that it does not harm the fundamental rights and freedoms of the data subject, if data processing is necessary for the legitimate interests of the Company, processing is carried out based on this data processing condition.
5. CONDITIONS FOR PROCESSING SPECIAL CATEGORIES OF PERSONAL DATA
The Company processes special category personal data by complying with the additional measures announced by the Personal Data Protection Board, taking all necessary administrative and technical measures, and if one of the following data processing conditions exists:
Pursuant to Article 6/3 of the Personal Data Protection Law, the processing of special category personal data is prohibited. However, the processing of such data is permitted if:
- a) The explicit consent of the data subject,
- b) It is expressly provided for by law,
- c) It is necessary to protect the life or physical integrity of the data subject or another person, where the data subject is unable to give consent due to actual impossibility or where consent is not legally valid,
- d) It relates to personal data that the data subject has made public and is consistent with their intention to make it public,
- e) It is necessary for the establishment, exercise, or protection of a right,
- f) Necessary for the protection of public health, preventive medicine, medical diagnosis, treatment, and care services, as well as the planning, management, and financing of health services by persons or authorized institutions and organizations subject to confidentiality obligations,
- g) It is necessary for the fulfillment of legal obligations in the areas of employment, occupational health and safety, social security, social services, and social assistance,
- h) It is possible for foundations, associations, and other non-profit organizations or entities established for political, philosophical, religious, or trade union purposes, provided that it is in accordance with the legislation to which they are subject and their purposes, is limited to their field of activity, and is not disclosed to third parties; if it is directed at their current or former members and associates or persons who are in regular contact with these organizations and entities.
The company has separately and in detail regulated and published the "Policy on the Processing and Protection of Special Category Personal Data" regarding the processing of special category personal data.
6. CHANNELS FOR COLLECTING PERSONAL DATA
The Company obtains personal data from physical and electronic environments in accordance with legal regulations and the purposes set out in this Policy, based on the conditions for processing. These environments and channels through which personal data is obtained are as follows:
| PHYSICAL DATA COLLECTION | ELECTRONIC DATA COLLECTION |
|---|---|
| Physical Mail | |
| Printed Forms | Website |
| Software and Applications Used | |
| IT Devices | |
| Corporate Social Media Accounts | |
| Communication Platform |
These channels may vary depending on the development and change of business processes and technological developments. In accordance with the principle of transparency, these changes will be presented in updates to the Policy.
7. TRANSFER OF PERSONAL DATA
The Company transfers personal data and special category personal data to third parties in accordance with the provisions of Articles 8 and 9 of the Law, based on lawful personal data processing purposes and by taking all necessary administrative and technical measures.
1. DOMESTIC TRANSFER
The company acts in accordance with the law in its data transfer activities. It only transfers data to third parties to the extent required by the service. It instructs the "Transfer Recipients" groups, which are "data processors," on data security in an appropriate manner through data transfer agreements.
| RECIPIENT GROUPS | EXAMPLE OF TRANSFER PURPOSE |
|---|---|
| Authorized Public Institutions and Organizations | Transferred for the purpose of fulfilling our legal obligations and making the necessary notifications within this framework. |
| Natural persons or private legal entities | Transferred for the purposes of following up and conducting legal affairs, obtaining consultancy services, and conducting activities in accordance with the legislation. |
| Supplier (Product/Service Provider) Companies, Agents | Transferred for the purposes of product/service supply, ensuring business continuity, and establishing and fulfilling contracts. |
| Customer Companies/Business Partners | Transferred for the purposes of executing contract processes, selling products/services, and ensuring the continuity of commercial activities. |
| Bank | Transferred for the purpose of conducting financial and accounting processes. |
| Insurance Companies | Transferred for the purpose of providing individual retirement or health insurance on behalf of employees. |
| OSGB | Transferred to relevant persons for the purpose of conducting occupational health and safety activities. |
2. INTERNATIONAL TRANSFER
The company may transfer personal data abroad only in accordance with the provisions of Article 9 of the Personal Data Protection Law and by taking the necessary administrative and technical measures. This transfer is possible if one of the following conditions is met:
- Personal data may be transferred abroad by our Company if one of the conditions specified in Articles 5 and 6 is met and if there is an adequacy decision regarding the country to which the transfer will be made, the sectors within that country, or international organizations.
- If no adequacy decision exists, personal data may be transferred abroad by our Company if one of the conditions specified in Articles 5 and 6 is met, provided that the relevant person has the opportunity to exercise their rights and seek effective legal remedies in the country to which the transfer will be made, and one of the appropriate safeguards specified below is provided by the parties:
- The existence of an agreement, not constituting an international agreement, between public institutions and organizations abroad or international organizations and public institutions and organizations in Turkey or professional organizations with the nature of public institutions, and the permission of the Board for the transfer.
- The existence of binding corporate rules containing provisions on the protection of personal data, approved by the Board, which companies within a group of undertakings engaged in joint economic activities are obliged to comply with.
- The existence of a standard contract announced by the Board, containing matters such as data categories, purposes of data transfer, recipients and recipient groups, technical and administrative measures to be taken by the data recipient, and additional measures taken for special categories of personal data.
- The existence of a written commitment containing provisions that provide adequate protection and the Board's permission for the transfer. If either of these two conditions is not met, personal data may only be transferred abroad with the explicit consent of the data subject.
- In the absence of an adequacy decision and if any of the appropriate safeguards mentioned above cannot be provided, our Company may transfer personal data abroad only if one of the following conditions exists, provided that it is incidental:
- The data subject's explicit consent to the transfer, provided that they have been informed of the potential risks.
- The transfer is necessary for the performance of a contract between the data subject and the data controller or for the implementation of pre-contractual measures taken at the request of the data subject.
- The transfer is necessary for the establishment or performance of a contract to be concluded between the data controller and another natural or legal person for the benefit of the data subject.
- The transfer is necessary for an overriding public interest.
- The transfer of personal data is necessary for the establishment, exercise, or defense of a legal claim.
- The transfer of personal data is necessary to protect the life or physical integrity of the person who is unable to express their consent due to actual impossibility or whose consent is not legally valid, or of another person.
- Transfer from a register open to the public or to persons with a legitimate interest, provided that the conditions required by the relevant legislation for access to the register are met and the person with a legitimate interest requests it.
Examples of recipient groups and purposes of sharing to which personal data is transferred are as follows:
| RECIPIENT GROUPS | TRANSFER PURPOSE EXAMPLE |
|---|---|
| Supplier (Product/Service Provider) Companies, Agents | Transfer is made for the purpose of product/service supply and ensuring business continuity. |
| Global Affiliates and Business Partners (cloud computing service providers, remote identity verification service providers, blockchain analysis companies) | The transfer is made for the purpose of carrying out business continuity activities, managing joint economic activities, and ensuring coordination. |
The recipient groups to which personal data is transferred and the categories of personal data transferred abroad may vary. These changes and updates are publicly announced and published on the VERBİS (verbis.kvkk.gov.tr) website, which is accessible on the Institution's website.
Personal data may be shared with cloud computing service providers, remote identity verification service providers, blockchain analysis companies, and global affiliates.
8. STORAGE AND DISPOSAL OF PERSONAL DATA
As the Data Controller, the Company has determined the storage periods, destruction periods, and technical and administrative measures to be implemented in the storage of personal data in the "Personal Data Storage and Destruction Policy"; it has declared these periods separately for each personal data category in VERBİS. The Company is aware that it is responsible for ensuring that personal data is stored in accordance with these principles.
In accordance with the Personal Data Protection Law, personal data is retained for the period specified in the relevant legislation or for as long as necessary for the purpose for which it is processed. These periods are specified, and after the expiration of this period, the relevant personal data is deleted, destroyed, or anonymized for analytical purposes at the end of the periodic destruction periods specified in the relevant Policy, in accordance with the "Regulation on the Deletion, Destruction, or Anonymization of Personal Data." You may request further information via the contact details provided in this KVK Policy.
5. SECURITY MEASURES RELATED TO PERSONAL DATA
The Company takes technical and administrative measures, within the scope of technological capabilities and considering the cost of implementation, to ensure that personal data is processed in accordance with the law. The technical and administrative measures taken to protect personal data are applied with care and additional measures for special categories of personal data, and the necessary audits are periodically carried out at the highest level within the Company. These security measures are also specified in VERBİS.
The Company takes all appropriate security measures to ensure that personal data is processed only for specified purposes and to reduce risks such as malicious use, unauthorized access, transfer, destruction, or alteration of personal data. These security measures also include other precautions taken in matters such as not transferring personal data to countries that do not provide an adequate level of data protection.
The personal data processed by the Company is confidential, and the Company complies with this confidentiality. Only persons authorized by the Company may access personal data. In this context, software compliance with standards, careful selection of third parties, and compliance with the KVK Policy within the Company are ensured.
Despite the Company taking the necessary data security measures, if personal data is damaged or falls into the hands of unauthorized third parties as a result of attacks on platforms operated by the Company or the Company's system, the Company takes immediate action to remedy the breach and minimizes the damage to the person concerned. The Company shall immediately notify the relevant persons and the Board of Directors of this situation and take the necessary measures. The rules and procedures regarding personal data breaches are set out in the "Personal Data Breach Management Policy."
Similarly, a Personal Data Protection Committee has been established, which meets at least twice a year and evaluates the implementation of current developments in personal data by the Company and any data breaches (if any).
6. INFORMATION OBLIGATION
The Company informs the relevant persons in accordance with Article 10 of the Personal Data Protection Law and the provisions of the "Communiqué on the Procedures and Principles to be Followed in Fulfilling the Disclosure Obligation" about the identity of the data controller, the methods used to collect their personal data, the legal basis and purposes of the processing, the purposes and recipients of the transfer of personal data, and the rights of the data subjects regarding the processing of their personal data.
7. RIGHTS OF DATA SUBJECTS
According to the Constitution of the Republic of Turkey, everyone has the right to request the protection of their personal data. In this context, the rights of the relevant person over their personal data are listed in Article 11 of the KVK Law as follows:
- The right to learn whether their personal data has been processed,
- To request information regarding the processing of their personal data,
- To learn the purpose of the processing of their personal data and whether it is being used in accordance with that purpose,
- To know the third parties to whom their personal data has been transferred within or outside the country,
- To request the correction of their personal data if it has been processed incompletely or incorrectly,
- Requesting the deletion or destruction of your personal data within the framework of the conditions set forth in Article 7 of the KVK Law,
- Requesting that the third parties to whom your personal data has been transferred be notified of such deletion, destruction, or correction,
- To object to a result detrimental to the data subject arising from the analysis of processed data exclusively through automated systems,
- To request compensation for damages incurred due to the processing of their personal data in violation of the KVK Law.
The relevant person may submit their requests within the scope of the above-mentioned rights in writing to the Company's registered electronic mail (KEP) address, using a secure electronic signature, mobile signature, or the electronic mail address previously notified by the relevant person to the Company and registered in the Company's system. The relevant person may use the "Data Subject Application Form" available on the Company's website for their application. The application must include:
- Name, surname, and signature if the request is in writing,
- Turkish Republic identity number for Turkish citizens, nationality, passport number, or identity number (if available) for foreigners,
- Residence or workplace address for notification purposes,
- If available, the email address, phone number, and fax number for notification purposes,
- The subject of the request, and
In addition, information and documents related to the subject must be attached to the application. Applications will only be considered if they are in Turkish. In order for third parties to apply on behalf of the persons concerned, there must be a special power of attorney drawn up by a notary on behalf of the person who will apply on behalf of the person concerned.
Requests regarding the rights of the relevant persons listed above must be submitted to the Company in accordance with the application procedures specified in this KVK Policy; In any case, if the request is submitted to the Company in accordance with the application procedures set forth in the "Communication on the Procedures and Principles for Applying to the Data Controller," the Company will respond to this request free of charge as soon as possible and no later than 30 (thirty) days from the date of application, depending on the nature of the request. However, if the process involves additional costs, the Company may charge the fee specified in the tariff determined by the Board.
For written requests, the date the document is delivered to the data controller or their representative is the date of the request. For requests made by other methods, the date the request reaches the data controller is the date of the request.
8. RELEVANT DOCUMENTS
The Company specifies the principles it has established for the protection of personal data in its policies and publishes these policies in public forums to the extent relevant. All company policies and regulations prepared in this regard form a whole and complement each other. In this way, the Company aims to ensure transparency and accountability by informing the relevant persons about personal data processing activities.
The other related documents referred to in this Policy are as follows:
- Special Category Personal Data Protection Policy
- Personal Data Retention and Breach Policy
- Personal Data Breach Management Policy
- Data Subject (Data Owner) Application Form
9. TRAINING AND AWARENESS
The company is responsible for ensuring that all relevant employees, particularly those in the risk and compliance unit and the information technology unit, have sufficient knowledge about the protection and processing of personal data. To this end, comprehensive training is provided to all relevant personnel at least once a year. In addition, new employees undergo orientation on the relevant procedures before starting their duties.
The company organizes the necessary training on the processes of protecting and processing personal data. Training content is updated periodically in line with changes in legislation.
The effectiveness of the training is measured through tests. Training records, participant lists, and evaluation results are kept regularly.
10. EFFECTIVENESS AND CHANGES
This policy is reviewed at least once a year for possible updates. In the event of updates due to changes in legislation, sectoral developments, or new needs arising in company operations, the revised version is submitted to the board of directors for approval and implementation. Update proposals are evaluated by the Compliance Unit, approved by the Information Security Unit, and submitted to senior management for approval after obtaining the opinion of the Legal Unit. Version control is performed for approved updates, and change logs are kept. Current policies and procedures are communicated to relevant personnel and archived in the central system. These changes take effect on the date the revised new Policy is published.
11. OUR INFORMATION AND COMMUNICATION
If you have any questions about the KVK Policy or our approach to the processing and protection of your personal data, or if you wish to exercise any of the rights specified in the KVK Law, you can obtain information by using any of the following methods:
Information Regarding the Data Controller
Data Controller Title: Whitebit Kripto Varlık Alım Satım Platformu Anonim Şirketi
Data Controller Address: Fulya Mahallesi, Büyükdere Caddesi, Torun Center, A Blok, No:74 A, İç Kapı No:31, Şişli, Istanbul
Data Controller's Website Address: www.whitebit-tr.com
Data Controller's Email Address: support@whitebit-tr.com