Personal Data Protection Policy

Last Update: June 12, 2020

As United Parcel Service, Inc., we, together with our subsidiaries and affiliates (hereinafter shall be referred to as “UPS” collectively), respect your privacy concerns.

This Privacy Notice reveals which types of information we collect about consumers, how we can use such information, and with whom we can share them. This Privacy Notice also explains the measures taken by us for personal data protection purposes. Furthermore, it explains how you can (i) request from us to access or to change your personal data kept by us, (ii) withdraw any consents you have already granted to us, (iii) reject our submission of certain communication messages to you, and (iv) request from us to respond to your questions about our confidentiality practices. This Privacy Notice is not applicable to The UPS Store or other retail sales points. This Privacy Notice is not applicable to any subsidiary or affiliate of United Parcel Service, Inc. that have their own privacy notices, including The UPS Store or other retail sales points.

Our confidentiality practices may vary between different countries or regions where we may be required to make some adjustments depending on the local practices and legal requirements.

In order to visit the specified section, click on one of the following links:

Policy, Scope and Objective

The Board of Directors and the management of UPS Hızlı Kargo Taşımacılığı A.Ş. (hereinafter shall be referred to as “UPS”) undertake to comply with the Constitution of Republic of Türkiye with respect to personal data protection as well as the principles and rules stipulated by the Law no. 6698 on Protection of Personal Data (LPPD) and other legislation, and to protect the rights and freedoms of individuals whose data are processed by UPS. To that end, the Board of Directors has adopted a written personal data protection policy and system that will be implemented and developed.

Scope
The provisions of the policy cover all the information systems and sub-information, contracts, and peripheral and physical areas, included in the processes of personal data processing in the fields of activity and scope of business of UPS, as well as the systems developed and arrangements made for them. This policy is applicable to all UPS units, the company personnel providing support services, the visitors, third parties, trainees, and contracted employees.

Objectives of the Personal Data Protection Policy and System
The objective of the Personal Data Protection Policy and system is to ensure that UPS establishes and fulfils its own standards in management of personal data, to determine and support organizational targets and obligations, establish control mechanisms that are in compliance with the acceptable risk level of UPS, fulfil any requirements imposed on UPS pursuant to the international conventions, the Constitution, laws, agreements and occupational rules in the field of personal data protection, and to protect, to the greatest extent possible, the interests of individuals.

UPS shall comply with the legislation on personal data protection as well as the data protection principles. The data protection principles adopted by UPS include the following:

  1. Processing personal data only when explicitly required for legitimate corporate objectives,
  2. Processing personal data for these objectives to the minimum extent required and avoiding processing any data more than what is required,
  3. Providing explicit information to individuals about by whom and how their personal data are used,
  4. Processing only relevant and appropriate personal data,
  5. Processing personal data in accordance with the equity and law,
  6. Taking inventory of the categories of personal data processed by UPS,
  7. Ensuring that the personal data are accurate and, if necessary, up-to-date,
  8. Retaining personal data only for a period required by legal regulations, or the legal obligations or legitimate corporate interests of UPS,
  9. Respecting the rights of data subjects with respect to their personal data, including the right of access,
  10. Keeping all the personal data secure,
  11. Transferring personal data to abroad only when sufficient protection is ensured,
  12. Applying the exceptions allowed by the legislation,
  13. Establishing and implementing the personal data protection system for application of the policy,
  14. When necessary, determining the internal and external stakeholders that are party to the personal data protection system, and to what extent they are included in the personal data protection system of UPS,
  15. Determining the officer(s) with special authorizations and responsibilities in relation to the personal data protection system.

Notifications
UPS informs the Personal Data Protection Board (“PDP Board”) about the fact that it is a data controller and about which categories of personal data it processes in such capacity. UPS determines all the categories of personal data processed by it in the personal data inventory.

Notification is made pursuant to the procedures and methods to be determined by the PDP Board, and UPS keeps a copy of such notification.

When necessary, notifications are repeated periodically.

In order to detect any potential changes that may arise in the notification made to the PDP Board, UPS’ data processing operations and any changes in the same are reviewed on an annual basis, and when necessary, the PDP Board is informed accordingly.

UPS’ disciplinary regulations shall be applicable to any act breaching this policy, committed by any UPS department, company officer providing support services, trainees, and contracted employees, and if such breach constitutes an offense or misdemeanour, the relevant authorities shall be notified of the situation as soon as possible.

The solution partners of UPS that have or may potentially have access to personal data and all third parties working with UPS are invited to read and comply with this policy. No third party may have access to the personal data processed by UPS without executing a written confidentiality agreement that imposes obligations as strict as at least those of UPS with respect to protection of personal data and includes UPS’ inspection right in this respect.

Definitions

Explicit consent refers to the consent in relation to a specific matter, which is given upon being informed and of one’s own free will.

Anonymization means rendering it impossible for personal data to be associated in any manner, even by being matched with other data, with a natural person who is identified or identifiable.

Data subject (relevant person) means the natural person whose personal data are processed.

Personal data means any kind of information about an identified or identifiable natural person.

Special category of personal data means data relating to race, ethnic origin, political opinion, philosophic belief, religion, sect or other beliefs, appearance, membership to associations, foundations or unions, health, sexual life, criminal convictions and security measures as well as biometric and genetic data of people.

Processing of personal data means any operation performed on the data, such as obtaining, recording, storage, preservation, alteration, reorganization, disclosure, transfer, takeover, making available or classifying, or precluding the use of the personal data, by fully or partly automated means, or by non-automated means provided that they are part of a data recording system.

LPPD is the Law No. 6698 on Protection of Personal Data.

PDP Board refers to the Personal Data Protection Board.

PDP Authority refers to the Personal Data Protection Authority.

Data Processor means a natural or legal person who processes personal data on behalf of and based on the authority granted by the data controller.

Data recording system refers to a recording system where personal data are processed by being structured according to certain criteria.

Data controller means a natural or legal person who determines the aims and tools for/with which personal data will be processed and who is responsible for the establishment and management of the data recording system.

Duties and Responsibilities

Pursuant to LPPD, UPS is the data controller. All the personnel, mainly those in the Senior Management and those acting as managers and auditors, are responsible for development and promotion of accurate practices in processing of personal data within UPS as well as all the other obligations in this respect as specified in their individual job definitions. The PDP Committee has been established as the unit in charge of management of personal data protection system, and ensuring and documentation of compliance with the LPPD and other applicable legislation, and reports to the Board of Directors within this scope.

PDP Committee
The members of PDP Committee are appointed by the board of directors, based on their specialization and experiences in the legislation on personal data protection and the relevant practices, and they directly report to the Board of Directors.

Duties and Responsibilities of PDP Committee
The Committee shall inform the Board of Directors about the legislation on Personal Data Protection and the relevant developments. The Committee is responsible for ensuring that UPS’ policies and procedures are up-to-date and the data processing inspections are carried out in line with the relevant schedule, and that these are in compliance with the applicable legislation. The Committee acts in cooperation with all the relevant personnel in personal data protection matters.

The main duties and responsibilities of the Committee are listed below:

The PDP Committee has authority to inspect all the systems of UPS related to collection, processing and retention of personal data. During performance of its duties, the PDP Committee may request cooperation, including access to the systems and records, from all the personnel. If such cooperation is not ensured, the Committee reports the situation to the Board of Directors.

All the UPS personnel that process personal data are obliged to act in accordance with the legislation on Protection of Personal Data.

The Human Resources department is responsible for making the necessary notifications and provision of the necessary training required to ensure that all the personnel have the knowledge and necessary awareness about their responsibilities with respect to protection of personal data.

UPS’ personnel are obliged to ensure that all the personal data that are provided by them to UPS or relate to them are accurate and up-to-date.

Data Protection Principles

All personal data protection operations shall be carried out in accordance with the following data protection principles. UPS’ policies and procedures aim at ensuring compliance with these principles:

The personal data are processed transparently and in accordance with the law and the principle of honesty. Accordingly, UPS includes information disclosure texts/privacy notices in the data collection channels and the relevant media, in relation to the personal data processing operations it performs. UPS determines the media where these texts/notices, which include explicit and comprehensible information about which data of whom are processed for which purposes, will be published and announced. These texts/notices include the following:

Personal data can only be processed for specific, clear and legitimate purposes. The reasons/purposes for processing of personal data are determined in the inventory of personal data, and such data may not be used for any purposes other than those specified, without any other legal justification or explicit consent of the data subject.

In the event that any condition arises requiring use of any particular personal data for the purposes other than those specified in the inventory of personal data, the relevant personnel/department shall notify the PDP Committee of this situation. The PDP Committee inspects whether or not the new purpose is appropriate, and if necessary, ensures that the data subject is informed about the new purpose and the new data processing operation./p>

Personal data should be appropriate and relevant, and be processed in a way limited to the specified purpose.

UPS is obliged to ensure that personal data that are not evidently necessary for the purpose of the processing are not collected and processed.

Periodically, UPS inspects whether or not the data processed are appropriate and relevant based on the inventory of personal data.

UPS inspects whether or not all the data processing methods are appropriate and relevant, through an internal/external audit to be performed/procured to be performed annually.

UPS is responsible for ceasing the data processing operations related to the personal data that are detected to be not appropriate or relevant, or to be in excess of what is required with regard to the purpose of the processing, and for safe destruction of the data already processed, in accordance with the retention and destruction procedure.

Personal data should be accurate and up-to-date.

Accuracy and up-to-datedness of the data retained for a long period should be reviewed. The head of the Human Resources department is responsible for provision of training to all the personnel about collection and retention of personal data accurately and in an up-to-date manner. The sole responsibility for the accuracy and up-to-datedness of the data kept in relation to personnel rests with the relevant personnel.

The relevant department of UPS shall be responsible for correcting and updating the personal data processed in relation to personnel/customers and other data subjects.

The PDP Committee may instruct the relevant department to review the accuracy or up-to-datedness of specific data upon an assessment to be performed by it in relation to the type, retention period and quantity of data processed, based on the data inventory.

Personal data shall be processed only when necessary for the purpose of the data processing. In the event that the personal data are retained for a period exceeding the required time due to Back-up and similar requirements, such personal data should be encrypted or anonymized/masked for protection of the rights and freedoms of the individuals in the case of data security vulnerabilities. Processing of personal data after expiry of the terms specified in accordance with the Retention and Destruction Policy shall be subject to the written approval of the PDP Committee.

Rights of Data Subjects

Data subjects shall have the following rights in relation to the data processing operations performed at and the records kept by UPS:

To be informed of whether or not their personal data are processed, and if their personal data are processed, to request information thereon,

To learn the purpose of processing of their personal data and whether or not the same is used for the intended purpose,

To be informed about third parties, both in Türkiye and overseas, to whom their personal data are transferred,

To request correction of their personal data processed in an incomplete or erroneous manner,

To request deletion or destruction of their personal data in absence of a legal reason or basis requiring the processing thereof in compliance with LPPD or this policy,

To demand that the correction or deletion procedures performed upon their request be communicated to third parties to whom their personal data are transferred,

To object to any result to their detriment arising from analysis of the processed data solely through automatic systems,

To request recovery of damages in the case they incur any loss due to unlawful processing of their personal data.

Data subjects may request to have access to their personal data and exercise the aforementioned rights. Such requests shall be responded to within 30 days. The procedures for receipt, forwarding and finalization of the requests shall be carried out in accordance with the Request Management Procedure.

Data subjects may personally deliver their requests to our head office by filling in the PDPL Application Form, or send them, via notary public or registered letter with return receipt, to the address “MERKEZ MAHALLESİ, AYAZMA CAD. PAPIRUS PLAZA, B Blok, NO: 37/44, 34406, KAĞITHANE-ISTANBUL” with confirmation of identity, or send them by e-mail to the following registered e-mail address: upskargo@hs03.kep.tr.

You can access the data subject application form here.

All the UPS’ personnel, no matter what their job definition involves, is obliged to provide guidance to the data subjects on the accurate means of application in relation to the data subject’s requests for access that were submitted to them. UPS’ personnel should be informed and trained about the required course of action upon receipt of requests filed by data subjects.

When a data subject grants their consent on specific data processing operations, after being duly informed thereon and by acting of their own free will, revealing their desire for processing of the data that belong to them, as shown by written/verbal statements or explicit affirmative conduct, UPS deems this as an explicit consent. Explicit consent shall always be taken in writing for special categories of personal data. Data subject is entitled to withdraw their explicit consent at any time.

Explicit consent may be taken through the signing of the explicit consent form template by the data subject or inclusion of the content of this template in the contract to be executed with, or in the electronic form to be filed by the data subject. Explicit consent related to the personal data routinely processed, which pertain to the personnel, prospective personnel and customers, is taken through the relevant contract or forms.

In the case that the data processing operation based on the explicit consent will be performed continuously or repeatedly, the relevant department shall keep a single list of the persons whose explicit consents have been taken. The relevant department shall be responsible for keeping this list accurate and up-to-date. The relevant department shall keep the explicit consent forms or other evidential items related to the data processing operation based on explicit consent.

Data Security

Each personnel is responsible for ensuring that the personal data that are processed by UPS and are under their responsibility are kept in a secure manner.

Security of personal data shall be ensured in accordance with the PDP Policy of UPS and the auxiliary documents thereof.

UPS shall report any data security incidents related to personal data to the PDP Board and the data subject as soon as possible.

Data Sharing

8.1 Sharing of personal data with third parties is allowed only when it is done in compliance with the law and the equity. Accordingly, in order for personal data to be shared, fulfilment of at least one of the following requirements is sought:

Personal data can only be transferred to abroad provided only that the aforementioned requirements are met, the target country has adequate protection, and the data subject grants explicit consent on such transfer. For transferring personal data to abroad, the list of countries that have adequate protection as determined by the PDP Board shall be taken into consideration. Regarding transfer of personal data to abroad, the PDP Board provides any necessary permissions and notifications pursuant to the LPPD and the applicable legislation.

In the case that there is a regular data-sharing relation without any legal reason or obligation, a Letter of Undertaking on LPPD is signed with the relevant party to determine the conditions of such data sharing. The Letter of Undertaking on LPPD shall include, at minimum, the following:

Personal Data Processing Operations Performed by UPS

Purposes of Processing of Personal Data
The purposes of processing of data within scope of the personal data processing operations performed by UPS under the Data Controllers’ Registry Information System are as follows:

Data Subject Categories and Description:

Personal Data Categories and Description:

Categories of Parties With Which Data are Shared:

Management of Records

Upon expiry of the period of retention required for the purposes of processing, or upon justified demand of the data subject, the personal data shall be anonymized or deleted or destroyed, in accordance with the Retention and Destruction Policy, in a way that the natural person who is the data subject cannot be identified.

Personal data may not be retained for a period exceeding the time required for the purposes of processing thereof. Classification of the records containing personal data and the relevant retention periods shall be determined pursuant to the Retention and Destruction Policy.

How Can You Contact Us?

In the event that you have any question about or comments on this Privacy Notice or you want us to update the information belonging to you, or your preferences, please contact us via e-mail by using the email application.

Contact Us By Email

UPS Company Head Office
Contact Person: Global Privacy Officer
55 Glenlake Parkway, NE
Atlanta, GA 30328
United States of America

UPS Türkiye Head Office
Contact Person: Global Privacy Officer
MERKEZ MAHALLESİ, AYAZMA CAD. PAPIRUS PLAZA, B Blok, NO: 37/48, 34406, KAĞITHANE-ISTANBUL Türkiye

Respectfully; UPS HIZLI KARGO TAŞIMACILIĞI A.Ş.
Telephone: 0850 255 00 66