NAVLUNGO LOGISTICS AND TECHNOLOGY INC.

PERSONAL DATA PROTECTION AND PROCESSING POLICY

CONTENTS

  1. DEFINITIONS

  2. PURPOSE

  3. SCOPE

  4. IMPLEMENTATION OF THE POLICY

  5. PRINCIPLES FOR PROCESSING PERSONAL DATA

    • 5.1 Compliance with the Law and Rules of Honesty

    • 5.2 Being Accurate and Up-to-Date When Necessary

    • 5.3 Specificity and Transparency

    • 5.4 Being Relevant, Limited and Proportionate to the Purpose for which they are Processed

    • 5.5 Limited Period

    • 5.6 Consent of the Data Subject

  6. PROTECTION OF SPECIAL CATEGORIES OF PERSONAL DATA

  7. PURPOSES OF PROCESSING PERSONAL DATA

  8. TRANSFER OF PERSONAL DATA

    • 8.1 Transfer of Personal Data Domestically

    • 8.2 Transfer of Personal Data Abroad

  9. RIGHTS OF THE DATA SUBJECT AND EXERCISE OF THESE RIGHTS

    • 9.1 Rights of the Personal Data Subject

    • 9.2 Circumstances in which the Personal Data Subject Cannot Assert Their Rights

    • 9.3 Exercise of the Rights of the Personal Data Subject

    • 9.4 Evaluation of the Application by Navlungo

  10. Deletion, Destruction or Anonymization of Personal Data

    • 10.1 Determination of Maximum Periods and Destruction

    • 10.2 Measures Taken Regarding Secure Storage and Destruction of Personal Data

    • 10.3 Periodic Destruction

  11. Entry into Force and Review

DEFINITIONS

| Explicit Consent | Consent regarding a specific subject, based on information and declared with free will. | | :---- | :---- | | Navlungo / Company | Navlungo Lojistik Ve Teknoloji A.Ş. | | Destruction | Deletion, destruction or anonymization of personal data. | | Personal Data | Any information relating to an identified or identifiable natural person. | | Anonymization of Personal Data | Making personal data impossible to be associated with an identified or identifiable natural person under any circumstances, even by matching it with other data. | | Processing of Personal Data | Any operation performed on data such as obtaining, recording, storing, preserving, altering, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data by fully or partially automated means or non-automated means provided that it is part of any data recording system. | | Deletion of Personal Data | Deletion of personal data; making personal data completely inaccessible and non-reusable for the relevant users. | | Destruction of Personal Data | The process of making personal data inaccessible, non-retrievable and non-reusable in any way by anyone. | | PPD Board / Board | Personal Data Protection Board | | KVKK | Law on the Protection of Personal Data No. 6698 published in the Official Gazette dated April 7, 2016 and numbered 29677 | | Special Category Personal Data | Data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and dressing, membership of association, foundation or trade-union, health, sexual life, criminal conviction and security measures, and biometric and genetic data. | | Periodic Destruction | The process of deletion, destruction or anonymization to be carried out ex officio at repeating intervals in case all of the conditions for processing personal data specified in the Law disappear. | | Data Processor | The person who processes personal data within the organization of the data controller or in line with the authority and instructions received from the data controller, excluding the person or unit responsible for technically storing, protecting and backing up the data. | | Data Subject/ Relevant Person(s) | The natural person whose personal data is processed, such as, but not limited to, Company’s employees, customers, business partners, shareholders, officials, potential customers, candidate employees, interns, visitors, suppliers, employees of institutions worked in cooperation, third parties and other persons with whom the Company has a commercial relationship. | | Data Controller | The natural or legal person who determines the purposes and authorization of processing personal data and is responsible for the establishment and management of the data recording system. |

1. PURPOSE

The purpose of this policy is to regulate the methods and principles to be followed by Navlungo, in its capacity as carrier or charterer, to ensure the processing and protection of personal data belonging to its existing customers and their employees, potential customers, business partners, shareholders, company directors, company officials, employees and employee candidates, employees and officials of institutions in cooperation, and related third parties.

2. SCOPE

This policy is applied to all activities managed by the Company and carried out for the processing and protection of personal data.

This policy relates to all processed personal data of our partners, officials, customers in their capacity as carrier or charterer, and our customers' employees, partners, officials, employees of institutions with which we cooperate, shareholders, officials, and third parties.

3. IMPLEMENTATION OF THE POLICY

This Policy has been created by organizing Company practices according to the rules set forth by the relevant legislation. In case of conflict between the provisions of the legislation and the provisions of the Policy, the provisions of the current legislation shall apply.

Our Company, in its capacity as data controller;

  1. To prevent unlawful processing of personal data,

  2. To prevent unlawful access to personal data,

  3. To ensure the preservation of personal data,

is obliged to take all kinds of necessary technical and administrative measures to ensure the appropriate level of security for the purpose.

4. PRINCIPLES FOR PROCESSING PERSONAL DATA

The data used in our Company's processes are classified as personal data and special category personal data as stipulated in the law, processed according to the following principles, securely preserved, and transferred to third parties.

4.1. Compliance with the Law and Rules of Honesty

Our Company acts in accordance with the principles brought by legal regulations and the rule of general trust and honesty in the processing of personal data. In this context, Navlungo takes into account the requirements of proportionality in the processing of personal data and does not use personal data beyond what is required for the purpose.

4.2. Being Accurate and Up-to-Date When Necessary

Our Company keeps personal data fully and accurately and updates them when necessary. The Company makes the necessary arrangements to identify the correction, modification, update or deletion of the data in question if the personal data is incorrect or not up-to-date.

4.3. Specificity and Transparency

The Company processes personal data for specific, explicit, and legitimate purposes and does not process data for other purposes other than the data collection and processing purposes made transparent to the relevant person. The legitimacy of the purpose means that the data processed by the Company is related to and necessary for the work it does or the service it offers.

4.4. Being Relevant, Limited and Proportionate to the Purpose for which they are Processed

Personal data processed by the Company are processed only in a way that is consistent with the specified purpose and by making a reasonable limitation in this context. While personal data will not be collected for potential future data processing purposes, these data are not used, processedized or transferred in any way that is not suitable for the purpose of obtaining personal data.

Pursuant to the "minimum" data principle, personal data are kept limited and proportionate to the purpose of obtaining them, and data that are not required within this scope are not kept.

4.5. Limited Period

If the main purpose requiring the processing of personal data disappears and these data are no longer needed, the personal data in question are deleted, destroyed or anonymized. If times are stipulated in the laws for keeping the data, these data are preserved in accordance with the periods stipulated in the relevant legislation; after the expiration of the period stipulated in the legislation, these data are controlled at regular intervals by our Company in accordance with Article 10 of this Policy, and deleted, destroyed or anonymized from the systems/devices where the data is stored or from physical environments where they are located.

4.6. Consent of the Data Subject

Our Company fully and properly informs/enlightens the data subject regarding the processing of personal data. Where necessary, it obtains the consent of the data subject regarding the processing in question, and offers the option to withdraw the consent given at any time or make requests regarding their data. Our Company handles the personal data of the relevant person within the other principles specified in this Policy after the data subject withdraws their consent.

5. PROTECTION OF SPECIAL CATEGORIES OF PERSONAL DATA

Special category personal data are processed in the following cases, provided that adequate measures to be determined by the PPD Board are taken:

  • If there is explicit consent of the personal data subject or

  • If there is no explicit consent of the personal data subject;

    • It is clearly foreseen in the Laws that our company carries out the relevant activity regarding the processing of your personal data,

    • It is mandatory for Navlungo to carry out personal data processing activities to protect the life or physical integrity of the personal data subject or someone else, and in this case, the personal data subject is unable to express their consent due to actual or legal invalidity,

    • Provided that your personal data has been made public by you; it is processed by Navlungo in a manner limited to the purpose of making it public,

    • It is mandatory for Navlungo to process your personal data for the establishment, exercise or protection of the rights of our Company, you or third parties,

    • It is necessary for the protection of public health, preventive medicine, medical diagnosis, treatment and care services, and the planning, management and financing of healthcare services by persons under the obligation of confidentiality or authorized institutions and organizations,

    • It is mandatory for our Company to fulfill its legal obligations in the fields of employment, occupational health and safety, social security, social services and social relief.

6. PURPOSES OF PROCESSING PERSONAL DATA

Our Company enlightens the relevant persons during the acquisition of personal data, in accordance with Article 10 of the KVKK. In this context, our Company provides illumination about the purpose for which the personal data will be processed, to whom and for what purpose the processed personal data can be transferred, the method of collecting personal data and its legal reason, and the rights of the designees under Article 11 of the KVKK.

Our Company processes personal data limited to the purposes and conditions within the personal data processing conditions specified in paragraph 2 of Article 5 and paragraph 3 of Article 6 of the KVKK. These purposes and conditions;

  • It is clearly foreseen in the Laws that our company carries out the relevant activity regarding the processing of your personal data,

  • The processing of your personal data by our Company is directly related to and necessary for the establishment or performance of a contract,

  • It is mandatory for our Company to process your personal data in order to fulfill its legal obligation,

  • Provided that your personal data has been made public by you; it is processed by Navlungo in a manner limited to the purpose of making it public,

  • It is mandatory for Navlungo to process your personal data for the establishment, exercise or protection of the rights of our Company, you or third parties,

  • Provided that it does not harm your fundamental rights and freedoms, it is mandatory to carry out personal data processing activities for the legitimate interests of the Company,

  • It is mandatory to carry out personal data processing activities by Navlungo to protect the life or bodily integrity of the personal data subject or someone else, and in this
    case, the personal data subject is unable to express their consent due to physical or legal invalidity.

If the processing activity carried out for the mentioned purposes does not meet any of the conditions provided under the KVKK, your explicit consent will be requested by the Company regarding the relevant processing.

7. TRANSFER OF PERSONAL DATA

7.1 Transfer of Personal Data Domestically

Our Company is responsible for acting in accordance with the decisions and relevant regulations taken by the PPD Board and provided for in the KVKK regarding the transfer of personal data.

Personal data and special category data of the designees cannot be transferred by the Company to other natural or legal persons without the explicit consent of the relevant person. However, in cases required by the KVKK and other Laws, the data may be transferred to the authorized administrative or judicial institution or organization in accordance with the methods and limits provided for in the legislation, even without the explicit consent of the data subject. In addition, the transfer is possible without the consent of the relevant person in the cases provided for in Articles 5 and 6 of the Law. The Company may transfer personal data to third parties in Turkey in accordance with the conditions provided in the Law and other relevant legislation and taking all security measures specified in the legislation, unless otherwise regulated in the existing contract signed with the data subject person and in the Law or other relevant legislation.

7.2. Transfer of Personal Data Abroad

The Company may transfer personal data to third parties in Turkey, as well as abroad (including outsourcing to be processed or stored abroad), in accordance with the conditions provided in the Law and other relevant legislation as mentioned above and taking all security measures specified in the legislation, unless otherwise regulated in the existing contract signed with the data subject person and in the Law or other relevant legislation. In exceptional cases where explicit consent is not sought for the transfer of personal data specified in the KVKK, in addition to the non-consent processing and transfer conditions, the condition of having an adequacy decision regarding the country, international organization or sectors within this country to which the data will be transferred, given by the Personal Data Protection Board, is sought.

The Personal Data Protection Board will determine whether adequate protection is provided; and in the absence of an adequacy decision;

  • The existence of an agreement made between public institutions or organizations or international organizations abroad and public institutions or organizations or professional organizations with public institution status in Turkey, and the existence of the permission of the Personal Data Protection Board,

  • The existence of binding corporate rules binding on the data controllers or data processors in Turkey and in the relevant foreign country within the group of undertakings engaged in joint economic activity, approved by the Personal Data Protection Board,

  • The existence of a standard contract published by the Personal Data Protection Board concluded between data controllers or data processors both in Turkey and in the relevant foreign country,

  • Data controllers both in Turkey and in the relevant foreign country must commit in writing to adequate protection and have the permission of the Personal Data Protection Board.

If any of these cannot be provided, it may transfer personal data abroad, on an occasional basis, provided that it is limited to the cases listed in the KVKK.

8. RIGHTS OF THE DATA SUBJECT AND EXERCISE OF THESE RIGHTS

8.1. Rights of the Personal Data Subject

Personal data subjects have the following rights:

  • To learn whether personal data is processed,

  • To request information if personal data has been processed,

  • To learn the purpose of processing personal data and whether they are used in accordance with their purpose,

  • To know the third parties to whom personal data is transferred domestically or abroad,

  • To request correction of personal data if they are incomplete or incorrectly processed and
    to request notification of the transaction made within this scope to the third parties to whom the personal data has been transferred,

  • To request deletion or destruction of personal data in the event that the reasons requiring its processing disappear, despite being processed in accordance with the provisions of the KVKK and other relevant laws, and to request notification of the transaction made within this scope to the third parties to whom the personal data has been transferred,

  • To object to the occurrence of a result against the person himself/herself by analyzing the processed data exclusively through automated systems,

  • To request indemnification of the damage in case of damage due to unlawful processing of personal data.

8.2. Circumstances in which the Personal Data Subject Cannot Assert Their Rights

Since the following situations are excluded from the scope of KVKK pursuant to Article 28 of the KVKK, personal data subjects cannot assert their above-mentioned rights in these matters:

  • Processing of personal data for purposes such as research, planning, and statistics by anonymizing it with official statistics.

  • Processing of personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that they do not violate national defense, national security, public safety, public order, economic security, privacy of private life or personal rights or constitute a crime.

  • Processing of personal data within the scope of preventive, protective, and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public safety, public order or economic security.

  • Processing of personal data by judicial authorities or execution authorities in relation to investigation, prosecution, trial or execution procedures.

Pursuant to Article 28/2 of the KVKK; in the cases listed below, personal data subjects cannot assert their other rights listed above, except for the right to request indemnification of the damage:

  • Processing of personal data is necessary for the prevention of crime or for criminal investigation.

  • Processing of personal data made public by the personal data subject himself/herself.

  • Processing of personal data is necessary for the execution of auditing or regulation duties and for disciplinary investigation or prosecution by authorized and authorized public institutions and organizations and professional organizations with public institution status, based on the authority given by the law.

  • Processing of personal data is necessary for the protection of the economic and financial interests of the State regarding budget, tax, and financial matters.

8.3. Exercise of the Rights of the Personal Data Subject

Requests regarding the use of the rights specified above must be made in accordance with the following procedure.

  • The application must be made in Turkish.

  • The application must be submitted to the Data Controller in writing or by using the registered electronic mail (KEP) address, secure electronic signature, mobile signature or the electronic mail address previously notified to the Data Controller by the relevant person and registered in the Data Controller's system, or via a software or application developed for application purposes.

  • The application can be submitted in person or by registered post with return receipt to the Company’s address: Sanayi Mah. Teknopark Bul. No:1/10C Ic Kapi No:Z36 Pendik/ Istanbul.

  • In the application;
    a) Name, surname, and signature if the application is in writing,
    b) T.C. identification number for citizens of the Republic of Turkey, nationality, passport number or identification number if any for foreigners,
    c) Residential or business address subject to notification,
    d) Electronic mail address subject to notification if any, telephone, and fax number,
    e) Subject of request,

must be present.

  • Information and documents related to the subject must be added to the application.

If the transaction requested by the personal data subject requires an additional cost, the fee in the tariff determined by the Board may be charged. If the response to the application is given on a recording medium such as CD, flash memory, the fee that may be requested by the Data Controller cannot exceed the cost of the recording medium. If the application is due to the error of the Data Controller, the fee charged is returned to the relevant person.

8.4. Evaluation of the Application by Navlungo

The Data Controller receiving the application will finalize the requests in the application as soon as possible according to the nature of the request and within 30 (thirty) days at the latest. The Company may request information from the relevant person to determine whether the applicant is the personal data subject. Navlungo may ask questions with the personal data subject regarding their application to clarify the issues in the application.

Navlungo will accept the application or reject it by explaining its reasoning.

If the request of the Relevant Person is accepted, the necessity of the request is fulfilled by the Data Controller as soon as possible and the Relevant Person is informed.

The Data Controller will notify its response to the Relevant Person in writing or electronically.

In order for third parties to make request applications on behalf of personal data subjects, there must be a special power of attorney issued by the data subject on behalf of the person who will apply, through a notary public.

9. Deletion, Destruction or Anonymization of Personal Data

9.1. Determination of Maximum Periods and Destruction

The Company takes into account the procedures and principles of the Regulation on Deletion, Destruction or Anonymization of Personal Data when determining the maximum periods required for the purpose of processing personal data.
a) How long is necessary as the general custom of the sector in which the Company operates for the purpose of processing in relation to the relevant data category,
b) How long the legal relationship established with the relevant person that makes processing of personal data necessary in the relevant data category will continue,
c) How long the legitimate interest to be obtained by the Company based on the processing purpose of the relevant data category will be valid in accordance with the law and rules of honesty,
d) How long the risks, costs, and responsibilities to be created by storing the relevant data category based on its processing purpose will continue legally,
e) Whether the maximum period to be determined is suitable for keeping the relevant data category accurate and up-to-date,
f) How long the Company has to store the personal data in the relevant data category due to its legal obligations,
g) How long the prescription period determined for asserting a right dependent on the personal data in the relevant personal data category is, are taken into account.

All transactions regarding the deletion, destruction, and anonymization of personal data are recorded and the records in question are stored for at least three years, excluding other legal obligations.

9.2. Measures Taken Regarding Secure Storage and Destruction of Personal Data

Navlungo is obliged to take technical and administrative measures for secure storage of personal data, prevention of unlawful processing, and access, and lawful destruction of personal data, as well as to announce these measures to the relevant persons and ensure their implementation.

9.3. Periodic Destruction

The Company undertakes that, in parallel with the Personal Data Processing Inventory, it will periodically check the personal data it keeps in its digital and physical environments not to exceed 6 months, and delete, destroy or anonymize the data in question when the processing purpose is completed.
In this context, for customers with and without explicit consent, the legal period begins as of the date when the existing commercial relationship between the customer and the Company ends, and after the legal period expires, the deletion process is carried out on the first periodic deletion date.
For employees with and without explicit consent, the legal period starts from the moment the employment contract ends, and after the legal period expires, the deletion process is carried out in the first periodic deletion period.

10. Entry into Force and Review

This Policy document enters into force upon approved by the Navlungo Board of Directors. This Policy is reviewed at least once a year and in cases when necessary, and updated if there are necessary changes.

In case of conflict between the legislation in force regarding the protection and processing of personal data and Navlungo KVK Policy, the legislation in force shall apply.

PERSONAL DATA STORAGE AND DESTRUCTION POLICY

Table of Contents

  1. DEFINITIONS

  2. PURPOSE

  3. SCOPE

  4. IMPLEMENTATION OF THE POLICY

  5. DELETION, DESTRUCTION OR ANONYMIZATION OF PERSONAL DATA

  6. ENTRY INTO FORCE AND REVIEW

1. DEFINITIONS

| Explicit Consent | Consent regarding a specific subject, based on information and declared with free will. | | :---- | :---- | | Navlungo / Company | Navlungo Lojistik ve Teknoloji A.Ş. | | Destruction | Deletion, destruction or anonymization of personal data. | | Personal Data | Any information relating to an identified or identifiable natural person. | | Anonymization of Personal Data | Making personal data impossible to be associated with an identified or identifiable natural person under any circumstances, even by matching it with other data. | | Processing of Personal Data | Any operation performed on data such as obtaining, recording, storing, preserving, altering, reorganizing, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data by fully or partially automated means or non-automated means provided that it is part of any data recording system. | | Deletion of Personal Data | Deletion of personal data; making personal data completely inaccessible and non-reusable for the relevant users. | | Destruction of Personal Data | The process of making personal data inaccessible, non-retrievable and non-reusable in any way by anyone. | | PPD Board / Board | Personal Data Protection Board | | KVKK | Law on the Protection of Personal Data No. 6698 published in the Official Gazette dated April 7, 2016 and numbered 29677 | | Special Category Personal Data | Data relating to race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and dressing, membership of association, foundation or trade-union, health, sexual life, criminal conviction and security measures, and biometric and genetic data. | | Periodic Destruction | The process of deletion, destruction or anonymization to be carried out ex officio at repeating intervals in case all of the conditions for processing personal data specified in the Law disappear. | | Data Processor | The person who processes personal data within the organization of the data controller or in line with the authority and instructions received from the data controller, excluding the person or unit responsible for technically storing, protecting and backing up the data. | | Data Subject/ Relevant Person(s) | The natural person whose personal data is processed, such as, but not limited to, Navlungo’s employees, customers, business partners, shareholders, officials, potential customers, candidate employees, interns, visitors, suppliers, employees of institutions worked in cooperation, third parties and other persons with whom Navlungo has a commercial relationship. | | Data Controller | The natural or legal person who determines the purposes and authorization of processing personal data and is responsible for the establishment and management of the data recording system. |

2. PURPOSE

The purpose of this policy is to regulate the methods and principles to be followed by the Company; for the storage and destruction of personal data belonging to company directors, company shareholders, company officials, employees and employee candidates, employees and officials of institutions with which it cooperates, customers and customer employees with the capacity of carrier or transport, and related third parties.

3. SCOPE

This policy is applied to all activities managed by Navlungo and carried out for the storage and destruction of all processed personal data.

This policy relates to all processed personal data of our partners, officials, customers in their capacity as carrier or charterer, and our customers' employees, partners, officials, employees of institutions with which we cooperate, shareholders, officials, visitors, and third parties.

4. IMPLEMENTATION OF THE POLICY

This Policy has been created by organizing Navlungo practices according to the rules set forth by the relevant legislation. In case of conflict between the provisions of the legislation and the provisions of the Policy, the provisions of the current legislation shall apply.

Our Company, in its capacity as data controller;

  1. To prevent unlawful processing of personal data,

  2. To prevent unlawful access to personal data,

  3. To ensure the preservation of personal data,

  4. To ensure destruction of personal data in accordance with the legislation,

is obliged to take all kinds of necessary technical and administrative measures to ensure the appropriate level of security for the purpose.

5. DELETION, DESTRUCTION OR ANONYMIZATION OF PERSONAL DATA

5.1. Determination of Maximum Periods and Destruction

The Company takes into account the procedures and principles of the Regulation on Deletion, Destruction or Anonymization of Personal Data when determining the maximum periods required for the purpose of processing personal data.
a) How long is necessary as the general custom of the sector in which the Company operates for the purpose of processing in relation to the relevant data category,
b) How long the legal relationship established with the relevant person that makes processing of personal data necessary in the relevant data category will continue,
c) How long the legitimate interest to be obtained by the Company based on the processing purpose of the relevant data category will be valid in accordance with the law and rules of honesty,
d) How long the risks, costs, and responsibilities to be created by storing the relevant data category based on its processing purpose will continue legally,
e) Whether the maximum period to be determined is suitable for keeping the relevant data category accurate and up-to-date,
f) How long the Company has to store the personal data in the relevant data category due to its legal obligations,
g) How long the prescription period determined for asserting a right dependent on the personal data in the relevant personal data category is, are taken into account.

All transactions regarding the deletion, destruction, and anonymization of personal data are recorded and the records in question are stored for at least three years, excluding other legal obligations.

5.2. Measures Taken Regarding Secure Storage and Destruction of Personal Data

Navlungo is obliged to take technical and administrative measures for secure storage of personal data, prevention of unlawful processing, and access, and lawful destruction of personal data, as well as to announce these measures to the relevant persons and ensure their implementation.

5.3. Periodic Destruction

Navlungo gas committed that, in parallel with the Personal Data Processing Inventory, it will periodically check the personal data it keeps in its digital and physical environments not to exceed 6 months, and delete, destroy or anonymize the data in question when the processing purpose is completed.
In this context, for customers with and without explicit consent, the legal period begins as of the date when the existing commercial relationship between the customer and Navlungo ends, and after the legal period expires, the deletion process is carried out on the first periodic deletion date.
For employees with and without explicit consent, the legal period starts from the moment the employment contract ends, and after the legal period expires, the deletion process is carried out in the first periodic deletion period.

5.4. Deletion Methods

| Deletion Methods for Personal Data Kept in Printed Environments | | | ----- | :---- | | Blackout | Personal data found in printed media are deleted using the blackout method. The blackout process is carried out by cutting the personal data on the relevant document where possible, and by using permanent ink to make it invisible in cases where it is not possible, in a way that cannot be undone and cannot be read by technological solutions. | | Deletion Methods for Personal Data Kept in Cloud and Local Digital Environments | | | Secure deletion from software | Personal data kept in cloud environment or local digital environments are deleted with a digital command so that they can never be recovered. Data deleted in this way cannot be accessed again. |

5.5. Destruction Methods

In Navlungo Lojistik Ve Teknoloji A.Ş., the following methods are generally applied regarding destruction methods.

| Destruction Methods for Personal Data Kept in Printed Environments | | | ----- | :---- | | Physical Destruction | Documents kept in printed environments are destroyed with paper shredders [Shredder] so that they cannot be put together again. | | Destruction Methods for Personal Data Kept in Local Digital Media | | | Physical Destruction | It is the physical destruction process such as melting, burning or powdering the optical and magnetic media containing personal data. It is ensured that the data is rendered inaccessible by operations such as melting, burning, powdering or passing optical or magnetic media through a metal grinder. | | De-magnetizing (degauss) | It is the process of corrupting the data on the magnetic media unreadably by exposing the magnetic media to high magnetic field. | | Overwriting | Random data consisting of 0s and 1s are written at least seven times on magnetic media and rewritable optical media, preventing older data from being read and restored. | | Destruction Methods for Personal Data Kept in Cloud Environment | | | Secure deletion from software | Personal data kept in the cloud environment are deleted with a digital command in a way that they cannot be recovered again, and when the cloud computing service relationship ends, all copies of encryption keys necessary to make personal data usable are destroyed. Data deleted in this way cannot be accessed again. |

5.6. Anonymization Methods

In Navlungo Lojistik Ve Teknoloji A.Ş., the following methods are generally applied regarding anonymization methods.

| Removing variables | It is the removal of one or more of the direct identifiers in the personal data belonging to the relevant person that will serve to identify the relevant person in any way. This method can be used for anonymizing personal data, as well as for deleting this information if there is information within the personal data that does not fit the data processing purpose. | | :---: | :---- | | Regional hiding | It is the deletion of information that may be distinctive regarding the data in an exceptional situation within the data table where personal data is collectively located anonymously. | | Generalization | It is the process of bringing together the personal data of many people and converting them into statistical data by removing distinguishing information. | | Lower and upper limit coding / Global coding | For a certain variable, intervals belonging to that variable are defined and categorized. If the variable does not contain a numerical value, then similar data within the variable are categorized. Values falling within the same category are combined. | | Micro-aggregation | With this method, all records in the data set are first arranged in a meaningful order and then the whole set is divided into a certain number of subsets. Then, by averaging the value of each subset belonging to the determined variable, the value of that subset belonging to that variable is replaced with the average value. In this way, since indirect identifiers within the data will be broken, it is made difficult to associate the data with the relevant person. | | Data shuffling and perturbation | Direct or indirect identifiers within personal data are mixed or corrupted with other values to break their relationship with the relevant person and ensure they lose their identifier qualities. |

5.7. Storage Periods

In Navlungo Lojistik Ve Teknoloji A.Ş., the periods listed in ANNEX-1 are generally applied regarding storage periods.

6. ENTRY INTO FORCE AND REVIEW

This Policy document enters into force upon approved by the Board of Directors of Navlungo Lojistik Ve Teknoloji A.Ş. This Policy is reviewed at least once a year and in cases when necessary, and updated if there are necessary changes.

In case of conflict between the legislation in force regarding the protection and processing of personal data and the Company’s KVK Policy, the legislation in force shall apply.

ANNEX-1:

| DATA SUBJECT | DATA CATEGORY | DATA STORAGE PERIOD | | :---- | :---- | :---- | | Employee / Intern / Shareholder / Board of Directors Member | Identity Data, Contact Data, Education Information | 10 Years | | Employee / Intern | Employee Personal Files | 10 Years | | Employee / Intern | Health etc. data collected in accordance with the Occupational Health and Safety Legislation | 15 Years | | Customer and Natural Person Employee | Identity Data/ Contact Data | 10 Years | | Supplier and Natural Person Employee | Identity Data/ Contact Data | 10 Years | | Candidate Employee | Data in resume such as identity, education | 1 Month | | Employee / Intern / Customer / Supplier | Digital Data (Log/Record/Tracking Systems) | 2 Years | | Customer / Supplier / Other | Customer Transaction Information | 10 Years | | Shareholder / Employee / Intern / Customer / Supplier | Financial Data | 10 Years | | Customer/Other natural persons from whom service is received-provided and/or legal entity employees | Company Core Data | 10 Years | | Employee | Human Resources Data | 10 Years | | Employee / Intern | Audio and Video Recordings | 3 Years | | Employee / Intern / Supplier Employee | Physical Space Security | 1 Month |

*          In the event that a longer period is regulated pursuant to the legislation or a longer period is envisaged for prescription, forfeiture periods, storage periods, etc. pursuant to the legislation, the periods in the provisions of the legislation are accepted as the maximum storage period.

PERSONAL DATA PROTECTION AND PROCESSING POLICY

/