SOYKP İş Merkezi İşletmeciliği AŞ and SOMAYA İş Merkezi İşletmeciliği AŞ
Address: Levent Mah. Cömert Sok. No:1/C D:40 34330 Beşiktaş İstanbul
Data protection enquiries: info@swissoffices.com
Website sales and quotation requests are assessed by our common sales team acting for both companies. We propose suitable offices and services according to your requirements and preferred location.
For job applicants, the relevant company is the company conducting recruitment; for employees, it is the employer named in the employment contract. The common sales process does not make employee or applicant records generally accessible to both companies.
Each company is a data controller for the processing activities whose purposes and means it determines. In these texts, “Company” means the company identified in the documents for your particular transaction and process.
Personal Data Protection and Processing Policy · Version 1.0 · Effective on publication.
1. Purpose
This policy sets the principles for lawful processing, protection, retention, disclosure, erasure, destruction and anonymisation of personal data in SwissOffices activities under KVKK, its secondary legislation, Personal Data Protection Board decisions and other applicable law. Data protection is part of corporate governance and information security; appropriate administrative and technical safeguards are applied.
2. Scope
The policy covers automated and partly automated processing and non-automated processing within a filing system. Data subjects include current/prospective customers; corporate customers’ owners, officers, representatives, contacts and employees; users of office and meeting-room services; visitors; callers to customer companies; senders and persons named in mail, parcels and legal notices; employees, applicants and interns; supplier/adviser/service-provider personnel; website visitors; and other individuals whose data are processed in legal or commercial relationships.
3. Definitions
Explicit consent is freely given, informed and specific consent. A data subject is an individual whose data are processed. Personal data are any information about an identified or identifiable individual. A controller determines processing purposes and means and is responsible for establishing and managing the filing system; a processor processes on its behalf and authority. Recipient groups are categories of people or organisations receiving data. Anonymisation makes identification impossible even by matching other data. Special-category data are those defined in Article 6 KVKK. The processing inventory connects activities with purposes, data categories, recipients, data subjects, retention periods, legal grounds and security measures. “Board” and “Authority” refer respectively to the Turkish Personal Data Protection Board and Authority.
4. Principles
Under Article 4, data are processed lawfully and fairly, considering reasonable expectations; kept accurate and up to date where necessary, with means to request corrections; processed for specific, explicit and legitimate purposes identified beforehand; relevant, limited and proportionate to those purposes; and retained only for the statutory or necessary period. Unnecessary collection is avoided, particularly in call answering, mail handling and scanning. When retention grounds end, data are erased, destroyed or anonymised.
5. Data categories
Depending on the activity, categories may include identity, contact, customer transactions, finance, legal processes, professional/work experience, personnel, transaction security, physical security, images, calls/communications, marketing preferences, and enquiry/complaint/support records. Special-category data are not intended to be collected unless required by the activity.
6. Processing purposes
Purposes may include providing virtual and serviced offices and business/registered addresses; enquiries and quotations; establishing/performing contracts; customer communication and relationships; office/meeting-room reservations; answering calls and forwarding messages for customers; receiving customers’ mail, parcels and legal notices; scanning and sending documents on customer instructions; accounting, invoicing, payments and collections; physical security and visitor access; website operation/security; complaints; legal duties and protection of rights; disputes; IT/security; HR; supplier relationships; and marketing where permissions exist. Activity-specific detail is set out in the inventory and relevant notices.
7. Legal grounds
Processing requires an applicable KVKK condition: express provision in law; necessity to protect life or physical integrity where the individual cannot give legally valid consent; necessity directly related to establishing/performing a contract with the data subject; compliance with a legal obligation; data made public by the individual; necessity to establish, exercise or protect a right; or necessity for legitimate interests without harming fundamental rights and freedoms. If none applies and explicit consent is legally appropriate, consent may be requested. Consent is not a default substitute for another applicable ground.
8. Special-category data
Routine collection is not intended in core services. Such information may nevertheless arise in personnel and occupational health/safety, legal files, powers of attorney/official documents, customers’ mail, documents scanned on request or information callers volunteer. Processing is limited to its purpose and an applicable Article 6 condition, with additional safeguards appropriate to the data. Staff must not request or, where avoidable, record unnecessary health, conviction, biometric or similar information, especially when answering calls.
9. Information notices
At collection, Article 10 information covers the controller’s identity, purposes, recipients and disclosure purposes, collection method and legal grounds, and Article 11 rights. Separate or layered notices may address customers, prospects, website visitors, CCTV/visitors, employees, applicants and, where necessary, call answering. Providing information does not depend on consent; notices and consent procedures are separate.
10. Controller and processor roles
SwissOffices generally acts as controller for its own customers and corporate contacts, contracts, billing and collections, employees, physical security, visitors, website and business/legal records. Depending on the actual activity, it may act as processor under a customer’s instructions when answering calls, recording/forwarding messages, receiving mail/parcels/notices or scanning and sending document contents. In those cases, documented customer instructions and agreed processing terms apply. Controller responsibility for separate operational, security or legal records is assessed independently.
11. Call answering
Data minimisation applies: normally only name, contact details, company/person called, date/time and a short message are collected. Unnecessary sensitive information volunteered by callers should not be recorded. Recording call audio is a separate processing activity: purpose, necessity, proportionality, legal basis, retention and notice must be established before introduction.
12. Mail, parcels and legal notices
Records are limited to necessary recipient/sender, delivery date, tracking/reference number, receiving person and customer notification. Sealed items are normally not opened unless expressly agreed with the customer or required by the service. Opening, scanning and sending contents must follow customer instructions. Copies should not be retained unnecessarily and appropriate deletion processes apply once delivery is complete.
13. Disclosures
Disclosures must be necessary and satisfy Article 8. Depending on the activity, recipients may include customer companies, banks/payment providers, accountants, IT and telephony/communication providers, security providers, building/site management, postal/courier services, notaries, lawyers, competent public bodies, courts and enforcement offices. Necessity is assessed before disclosure.
14. Suppliers and processors
Providers with access to data are assessed for data-security suitability. Where necessary, contracts or protocols address the processing subject/duration, categories, purposes, obligations, confidentiality, security, sub-processors, breaches, rights requests, return/disposal at service end, and international transfers.
15. Retention and disposal
Data are kept for the statutory or necessary period, considering legal obligations, contracts, limitation periods, possible disputes, purpose and proportionality. When all processing grounds end, data are erased, destroyed or anonymised on the controller’s initiative or a valid request. Where registration in the Data Controllers Registry is required, a separate retention/disposal policy is prepared under the applicable regulation.
16. Security
Under Article 12, measures aim to prevent unlawful processing and access and preserve data. Administrative measures, as appropriate, include inventories, allocation of duties, limited access, staff training, confidentiality duties, supplier risk assessments, processor contracts, rights-request and breach-response processes, retention/disposal and compliance review. Technical measures may include access controls, individual accounts, strong passwords, logging, firewalls/network security, malware protection, updates, backups, encryption, secure transmission, archive controls and monitoring.
17. CCTV and physical security
Cameras may cover necessary, proportionate areas for the safety of premises, staff, customers and visitors. Monitoring is purpose-limited, avoids areas with high privacy expectations and unnecessary coverage, permits access only to authorised persons, retains footage proportionately and requires suitable notice. CCTV does not record audio. Footage is ordinarily kept for 15 days.
18. Website and cookies
Website processing is explained in the relevant notice. Non-essential analytics, advertising and similar records are assessed according to their nature and legal ground. Consent-dependent records do not operate before a choice. Types, purposes, providers, duration and grounds are detailed in the Cookie Policy.
19. Marketing communications
KVKK and electronic-commerce rules are considered together. Requesting information or a quotation does not automatically permit unrelated advertising. Where required, marketing data-processing consent and commercial communication permission are obtained separately, and permission/refusal preferences are managed.
20. Data subject rights
Under Article 11 of Turkish Personal Data Protection Law No. 6698 (“KVKK”), you may learn whether your data are processed; request information about processing; learn its purpose and whether data are used accordingly; learn the recipients in Türkiye or abroad; request correction of incomplete or inaccurate data; request erasure or destruction when the legal conditions are met; request notification of correction, erasure or destruction to recipients; object to an adverse result arising solely from automated analysis; and seek compensation for damage caused by unlawful processing.
You may submit a signed written request to Levent Mah. Cömert Sok. No:1/C D:40 34330 Beşiktaş İstanbul; use a secure electronic signature or mobile signature; email info@swissoffices.com from an email address previously notified to and recorded by the relevant company; or use another method permitted by the applicable legislation.
Your request must include your full name, signature for written requests, Turkish identity number for Turkish citizens or nationality and passport number or other identity number for foreign nationals, address for service, any notification email address, telephone and fax number, the subject of the request and relevant supporting information. Do not provide documents unnecessary to identify you and assess the request.
Requests are answered as soon as possible and within 30 days. They are normally free; a charge under the Board’s tariff may apply where a response requires an additional cost. See Your rights and requests.
21. Personal data breaches
Incident-response processes address accidental or unlawful loss, alteration, disclosure, unauthorised access or unavailability. Suspected breaches are promptly reported to the responsible internal person/unit and assessed by nature, data categories, people affected, potential consequences and remedial measures. Notifications to the Authority and affected individuals are made where KVKK and Board requirements apply. Where acting as processor, SwissOffices informs the controller as soon as possible under contract and law.
22. Staff duties
Staff may use data only for their duties, must not share them without authority or for other purposes, must avoid excessive collection and sharing access credentials, must report suspicious/security incidents and protect customer confidentiality during and after employment. Staff handling calls, mail and notices receive specific instruction on these risks.
23. Inventory and registry
An inventory is prepared where Data Controllers Registry registration is required and may also be kept voluntarily to support compliance. It is reviewed when processing, systems, software, suppliers, international transfers, categories or purposes change.
24. Training and review
Appropriate periodic information/training supports awareness of data security, call answering, mail/notices, scanning/transmission, visitors/CCTV, rights requests, breaches and phishing. Processes are reviewed as needed against law and this policy.
25. Effective date and updates
This policy takes effect on website publication. Publication and subsequent version dates are displayed. It is reviewed when legislation, Board decisions, business activities, processing, technology or providers change, or otherwise as needed. The current version is published on the website. The management of each controller company is responsible for implementation and currency; internal duties are allocated separately.