SOYKP İş Merkezi İşletmeciliği AŞ and SOMAYA İş Merkezi İşletmeciliği AŞ
Address: Levent Mah. Cömert Sok. No:1/C D:40 34330 Beşiktaş İstanbul
Data protection enquiries: info@swissoffices.com
Website sales and quotation requests are assessed by our common sales team acting for both companies. We propose suitable offices and services according to your requirements and preferred location.
For job applicants, the relevant company is the company conducting recruitment; for employees, it is the employer named in the employment contract. The common sales process does not make employee or applicant records generally accessible to both companies.
Each company is a data controller for the processing activities whose purposes and means it determines. In these texts, “Company” means the company identified in the documents for your particular transaction and process.
Personal Data Retention and Disposal Policy · Version 1.0 · Effective on publication.
1. Purpose
This policy sets rules for retaining personal data and erasing, destroying or anonymising them when processing grounds end. It follows KVKK, the Regulation on Erasure, Destruction or Anonymisation of Personal Data, Board decisions and other applicable rules, and is implemented consistently with the processing inventory.
2. Scope
It covers automated/partly automated processing and non-automated processing within a filing system for current and prospective customers, corporate representatives/contacts/employees, callers, persons named in mail/parcels/notices, visitors, employees, applicants/interns, suppliers/service-provider personnel, website visitors and other third parties. Where SwissOffices is a processor, customer contracts and processing arrangements also apply.
3. Legal framework
The policy takes account of Articles 4–12 KVKK, the erasure/destruction/anonymisation and Data Controllers Registry regulations, Board decisions and other legislation applicable to SwissOffices.
4. Definitions
Personal data, data subjects, controllers, processors, recipient groups, special-category data, the processing inventory and Board have the meanings described in the Processing Policy. Electronic media allow creation, reading, alteration and storage using devices/software; non-electronic media include written, printed and visual records. Relevant users process data within the organisation or under the controller’s authority, excluding those solely responsible for technical storage, protection and backups. Disposal means erasure, destruction or anonymisation. Erasure makes data inaccessible and unusable to relevant users. Destruction makes data inaccessible, irretrievable and unusable by anyone. Anonymisation prevents identification even by combining other data. Periodic disposal is recurring disposal once all processing conditions cease.
5. Record media
Electronic media may include CRM, email, accounting/finance applications, websites/admin panels/forms, hosting/servers, telephony, computers/mobile devices, shared files, cloud storage, backups, CCTV, access/transaction logs, security systems, electronic contract/document archives and providers’ systems. Physical media may include customer and supplier contracts, customer documents, mail/delivery records, personnel, accounting, legal and visitor files, archives and cabinets. The policy and inventory are updated as necessary when media change.
6. Retention principles
Retention must be lawful and fair, accurate/current where necessary, tied to specific legitimate purposes, relevant, limited and proportionate, and no longer than legally required or necessary. Expired or unnecessary data are disposed of unless another legal ground applies. Data serving several purposes may remain until all purposes and legal retention grounds end. Relevant data may be separately kept for a current or reasonably foreseeable dispute only for the time necessary to establish, exercise or protect rights.
7. Reasons for retention
Reasons include establishing/performing office-service contracts; contractual duties; mail/delivery and call/message services; invoicing, accounting, payments and collections; tax/commercial record duties; personnel, payroll, social security and health/safety; physical/information security; disputes and protection of rights; rights requests; competent-authority requests; system operation/security; and other statutory obligations.
8. Reasons for disposal
Disposal applies where governing rules change or are repealed, purposes cease, Article 5/6 conditions cease, consent is withdrawn for consent-only processing without another ground, an erasure/destruction/anonymisation request is accepted, the Board orders disposal, a statutory or maximum retention period expires, or the legal/operational justification ends.
9. Determining periods
Periods consider legislation, purpose, contractual duration, sector practice, data sensitivity, retention risks, limitation and forfeiture periods, possible disputes, minimisation and proportionality. A specific statutory period takes precedence.
10. Retention schedule
These are general maximum periods based on the current operating model and processing inventory. A longer or shorter mandatory statutory period takes precedence.
| Data / process | Data subject | Retention | Starting point / explanation |
|---|---|---|---|
| Prospect information and quotation requests | Prospect / company representative | 1 year | From last contact or end of quotation process. |
| Unsuccessful quotations and sales discussions | Prospect / company representative | 1 year | From quotation expiry or last discussion. |
| Virtual/serviced-office contracts and annexes | Customer / corporate representative | 10 years | From termination of the contractual relationship. |
| Identity, representation and authority documents | Corporate officer / representative | 10 years | From end of the customer relationship, unless a specific legal reason requires longer. |
| Invoices, payments, collections and accounts | Customer / representative / supplier | Applicable financial/commercial period; generally 10 years | From end of the accounting period of the document/transaction, as required by law. |
| Customer enquiries and complaints | Customer / representative | 3 years | From resolution; relevant records may be kept for a resulting dispute. |
| Short call messages and caller details | Caller | 3 months | From forwarding the message to the customer company. |
| Operational delivery/forwarding records for customer calls | Caller / customer | 1 year | From forwarding the call or message. |
| Telephone audio recordings | Caller | Normally not recorded | Purpose and duration must be separately determined before recording. |
| Sealed mail, parcel and legal-notice delivery records | Customer / sender / third party | 3 years | From delivery/forwarding to the customer; longer as necessary for a dispute. |
| Electronic copies of opened/scanned mail, parcels or notices | Individuals named in the document | Maximum 30 days after forwarding | Unless the customer separately requests longer retention and a legal ground exists. |
| Physical documents received for customers | Individuals named in the document | Time needed for delivery | Storage ends on delivery; delivery records may be retained separately. |
| Meeting-room / tour reservations | Customer / visitor / prospect | 1 year | From reservation or visit. |
| Visitor entry/exit records | Visitor | 1 year | From visit. |
| CCTV footage | Visitor / employee / customer / supplier | 15 days | From recording; relevant footage may be preserved separately for an incident/dispute. |
| Website contact and information forms | Website visitor / prospect | 1 year | From resolution or last contact. |
| Essential cookies | Website visitor | Record-specific period | See Cookie Policy. |
| Analytics / marketing cookies | Website visitor | Record-specific period | Subject to the individual’s choice and Cookie Policy. |
| Website and information-system logs | User / visitor / employee | 2 years or the applicable statutory period | From creation of the log. |
| Commercial communication permission/refusal records | Customer / prospect | Period required by electronic-commerce law | From permission/refusal or end of the communication relationship, as applicable. |
| Supplier contracts and commercial records | Supplier representative / employee | 10 years | From end of the commercial relationship. |
| Personnel files and employment records | Employee | 10 years from end of employment | Longer periods under specific legislation apply to relevant records. |
| CVs and applications of unsuccessful applicants | Job applicant | 1 year | From end of the application process. |
| Occupational health and safety records | Employee | Applicable occupational health/safety period | As required by the relevant legislation. |
| Litigation, enforcement and dispute files | Relevant individuals | 10 years after final conclusion or applicable limitation period | From final conclusion of the proceedings. |
| KVKK requests and responses | Data subject | 3 years | From resolution of the request. |
| Personal data breach records | Affected individuals | 10 years | From incident closure; a longer legal need is assessed according to the incident. |
| Access authorisation and account records | Employee / user | 2 years after authority ends | From account closure or termination of access rights. |
10.1. Mail and scanning
Customer mail contents are not kept to build a permanent SwissOffices archive. Documents are opened only under instruction, copies are sent securely, successful delivery is checked, and copies are disposed of within the schedule unless another duty or legal ground applies. Operational proof of delivery is separate and may have a longer period.
10.2. Call answering
Messages are not retained to build permanent customer/caller profiles. Following forwarding, they are disposed of at the end of the short retention period when operational follow-up is no longer needed.
11. Erasure
Electronic erasure may remove user permissions, files/records from active systems and applications, emails/documents, accounts or database records; controls prevent renewed access by relevant users. For physical records whose whole destruction is unnecessary, redaction, masking, cutting or irreversible removal of the relevant fields may be used.
12. Destruction
Physical records may be shredded or securely destroyed under controlled services with contractual confidentiality/security duties. Electronic methods may include secure erasure, irreversible overwriting, destruction of encryption keys, physical destruction of media or other appropriate secure methods. For cloud systems, active records and access are removed, provider secure-erasure methods applied, and confirmation/records obtained where necessary.
13. Anonymisation
Where a purpose can continue without personal data, anonymisation may be used. Identification must be prevented even when SwissOffices or third parties match other data. Methods may include masking, aggregation, generalisation, variable removal, grouping, top/bottom coding and statistical techniques; re-identification risk is assessed. A technique is not treated as anonymisation merely because it has been applied.
14. Backups
Data erased from active systems must not be reused from backups for ordinary operations. Backup access is limited; data disappear through the backup cycle; restoring a backup must not reactivate records already due for deletion.
15. Periodic disposal
Once all processing grounds cease, SwissOffices disposes of data on its own initiative. Periodic disposal occurs every six months, in January and July, and is recorded. Between the disposal obligation arising and the scheduled disposal, data may not be used outside the retention purpose. CCTV is removed through its ordinary 15-day cycle; January/July scheduling does not extend that period.
16. Disposal on request
If all conditions cease, the requested data are erased, destroyed or anonymised and the person is informed within the statutory period. If retention remains necessary because of law, an ongoing contract, legal duties, protection of rights or another valid condition, the request may be refused with reasons. Processing is then limited to that continuing ground.
17. Data with recipients
Where disposal is required for previously disclosed data, recipients are informed as applicable and necessary KVKK actions are taken. Processor/provider contracts may require return, erasure, destruction or anonymisation on service/purpose ending and confirmation where needed.
18. Processing for customers
Retention/disposal normally follows the controller customer’s instructions and contract. Calls, messages, mail/notices and document scanning/transmission are not retained longer than instructions require. Separate operational records needed to evidence services, ensure security, bill or protect SwissOffices rights may have controller-defined periods.
19. Security
Appropriate administrative measures include inventories, duty allocation, need-based access, confidentiality commitments, staff training, archive restrictions, supplier/processor security contracts, period reviews, disposal tracking, breach management, removing access on role changes/departure and restricting sensitive-data access. Technical measures may include individual accounts, access controls, strong passwords, logs, encryption, malware protection, firewalls, updates, backups, secure transmission, monitoring and media controls. Disposal follows KVKK principles and security requirements.
20. Effective date
This policy takes effect on website publication; publication and version dates are displayed. Each controller company’s management is responsible for implementation and currency, with internal duties allocated separately. Staff must follow this policy and related procedures in their work.