New: 2026 GİB e-Archive updates now live on Argist — details ›
Home About Us Cash Book Service Management Customer Management Staff Management Sales Management Quote Management Inventory Management Subscription Management Leave Management E-Commerce Customer Portal Pricing Blog Contact

KVKK Policy

Last updated: March 7, 2026
Under Law No. 6698 on the Protection of Personal Data ("KVKK") — Turkey's personal data protection law — this policy explains the purposes and methods by which Argist Teknoloji Arge ve Yazılım, acting as data controller, processes personal data, and the rights you have over your data.

Who are we?

Argist Teknoloji Arge ve Yazılım
Website: argist.com

Personal Data Processing and Protection Policy

1. Purpose of the Policy

Our company, aware of the importance of the confidentiality and security of personal data obtained under Law No. 6698 on the Protection of Personal Data ("KVKK") and other applicable legislation, aims to properly fulfill the requirements of compliance with the relevant legislation in its capacity as data controller as defined in the Law on the Protection of Personal Data, and to establish a data protection and processing policy in line with international standards.

Our company's Personal Data Protection Policy ("Policy") sets out the principles of lawfulness, fairness and transparency adopted by our company in the protection and processing of personal data. The Policy also provides information on the purposes for which our company processes personal data, the method of collecting personal data, its legal basis and purpose, to whom and for what purposes the data may be transferred, and the rights of data subjects and the means of exercising them.

2. Purpose, Scope and Definitions

2.1 Purpose

This Personal Data Processing and Protection Policy ("Policy") is the main policy text setting out the principles that Argist Teknoloji Arge ve Yazılım ("Argist") will observe while fulfilling its obligations under Law No. 6698 on the Protection of Personal Data ("KVKK") and other applicable legislation.

2.2 Scope

This Policy covers Personal Data collected, processed by, or shared with Argist in the course of Argist's activities — including data relating to Argist's employees, job candidates, business partners, customers, potential customers, suppliers, service recipients, visitors, and website visitors — and is binding on Argist, its departments and its employees.

2.3 Definitions

For the purposes of this Policy:

  • Recipient group: the category of natural or legal persons to whom the data controller transfers personal data;
  • Relevant user: persons who process personal data within the data controller's organization, or on the basis of authorization and instructions received from the data controller, excluding the person or unit responsible for the technical storage, protection and backup of the data;
  • Destruction: the erasure, destruction or anonymization of personal data;
  • Law: Law No. 6698 on the Protection of Personal Data;
  • Recording medium: any medium containing personal data that is processed wholly or partly by automated means, or by non-automated means provided that it forms part of a data filing system;
  • Personal data: any information relating to an identified or identifiable natural person;
  • Data subject: the natural person whose personal data is processed;
  • Processing of personal data: any operation performed on personal data — wholly or partly by automated means, or by non-automated means provided it forms part of a data filing system — such as collection, recording, storage, retention, alteration, rearrangement, disclosure, transfer, acquisition, making retrievable, classification, or preventing its use;
  • Personal data processing inventory: the inventory in which data controllers detail, in connection with their business processes, the personal data processing activities they carry out — associating the purposes of processing, the data category, the transferred recipient group and the group of data subjects — together with the maximum period required for the purposes for which the data is processed, personal data envisaged to be transferred abroad, and the data security measures taken;
  • Board: the Personal Data Protection Board;
  • Explicit Consent: freely given consent based on information, relating to a specific matter;
  • Special categories of personal data: data relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other belief, appearance and dress, membership of an association, foundation or trade union, health, sexual life, criminal conviction and security measures, as well as biometric and genetic data;
  • Periodic destruction: the erasure, destruction or anonymization process carried out ex officio, at the recurring intervals specified in the personal data retention and destruction policy, once all of the conditions for processing personal data set out in the Law cease to apply;
  • Policy: this Policy, which data controllers rely on as the basis for determining the maximum period required for the purposes for which personal data is processed, and for the erasure, destruction and anonymization process;
  • Registry: the registry of data controllers kept by the Presidency of the Personal Data Protection Authority;
  • Data processor: the natural or legal person who processes personal data on behalf of the data controller, based on authority granted by the data controller;
  • Data filing system: the recording system in which personal data is structured and processed according to specific criteria;
  • Data controller: the natural or legal person who determines the purposes and means of processing personal data, and who is responsible for establishing and managing the data filing system.

Terms not defined in this Policy shall have the meaning given to them in the Law.

3. Processing of Personal Data

3.1 Principles

Argist acts in accordance with the following principles in all activities relating to the collection and processing of Personal Data:

3.1.1 Compliance with the law and the rules of good faith

Personal Data will be collected and processed in compliance with the law and the rules of good faith.

3.1.2 Being accurate and, where necessary, kept up to date

Where necessary for the purpose of collecting and processing Personal Data, Argist will:

  • Take the reasonable measures necessary to keep Personal Data complete, accurate and up to date,
  • Update Personal Data where data subjects notify changes to their Personal Data, and take the reasonable measures necessary to update, correct, or erase incomplete or inaccurate data.

3.1.3 Being processed for specified, explicit and legitimate purposes

Argist undertakes to collect and process Personal Data only to the extent necessary and connected with the business purpose for which it is collected. Except where legally permitted or required, Personal Data will not be collected and/or processed in advance for purposes expected to arise in the future. Except where the processing of Personal Data is legally required or permitted, Personal Data will only be processed in line with the legitimate purposes explicitly specified prior to collection, and in accordance with the consent obtained or, where required, with Explicit Consent.

Prior to any data collection activity by Argist, where the data subject's Explicit Consent is required in accordance with the data collection method and this Policy, a consent form or an online medium through which consent is obtained will be used.

Where Personal Data is processed by third parties acting as Data Processors on behalf of Argist, such third parties must undertake in advance, in writing, by contract or otherwise, to act in compliance with the obligations set out in this Policy.

3.1.4 Being retained for the period stipulated by applicable legislation or required by the purpose of processing

Personal Data is retained for the maximum period appropriate to the purposes for which it is processed; this period may be extended where necessary to comply with obligations set out in legislation or to protect legitimate business interests.

Personal Data that is no longer needed once the legally, administratively or commercially required periods have elapsed will be erased, anonymized or destroyed in accordance with applicable legislation and Argist's Personal Data Retention and Destruction Policy ("Destruction Policy").

Argist is responsible for the Destruction, in compliance with legislation, of all Personal Data held in its physical and electronic data filing systems once the purpose for which the data was collected ceases to exist and the legal retention periods have expired.

All operations relating to the erasure, destruction and anonymization of Personal Data will be recorded, and such records will be retained for at least three (3) years, save for other legal obligations.

3.2 Data Collection and Processing

Argist will collect and process Personal Data in accordance with the following legal conditions.

Method of Collecting Personal Data

  • Obtaining personal data relating to natural persons, and to the shareholders, board members, authorized signatories and employees of legal persons, in the course of any commercial transaction, negotiation, project preparation and delivery, and performance of contracts carried out by our company in pursuing its commercial activities,
  • Obtaining general and special categories of personal data during interviews conducted with job candidates in order to meet our company's staffing needs,
  • Obtaining general and special categories of personal data upon the signing of an employment contract with an employee and during the performance of that contract,
  • Obtaining data through security camera recordings and completed visitor forms in order to ensure secure entry and exit,
  • Obtaining data through visits to our company's office buildings and premises, and through visits to our website and/or other social and digital channels, in order to benefit from our products and services,
  • Your personal data may also be obtained through your participation in trade fairs, events, seminars, organizations, project meetings and training activities organized by our company.

Personal data may be collected verbally, in writing, or electronically, through automated or non-automated methods and similar means. Your collected personal data may be processed and transferred, in order to provide you with better service, within the scope of the personal data processing conditions and purposes set out in Articles 5 and 6 of the KVKK.

3.3 Consent

Argist will process a data subject's Personal Data only after informing them, in accordance with applicable legislation and this Policy, of the collection and/or processing of their Personal Data, and after obtaining their freely given Explicit Consent in writing or in electronic form. Where Personal Health Data is processed, Explicit Consent is obtained in writing. Explicit Consent statements obtained are documented and retained in physical or electronic form.

Personal Data may be processed without the data subject's consent where any of the following circumstances set out in the KVKK apply:

  • It is expressly provided for by law.
  • It is mandatory for the protection of the life or physical integrity of the data subject or of another person, where that person is unable to disclose consent due to actual impossibility or where their consent is not legally valid.
  • Processing the Personal Data of the parties to a contract is necessary, provided that it is directly related to the establishment or performance of that contract.
  • It is mandatory for the Data Controller to fulfill a legal obligation.
  • The data has been made public by the data subject themselves.
  • Data processing is mandatory for the establishment, exercise, or protection of a right.
  • Processing is mandatory for the Data Controller's legitimate interests, provided this does not harm the data subject's fundamental rights and freedoms.

3.4 Special Categories of Personal Data

Special categories of Personal Data may only be processed with the data subject's Explicit Consent, or, save for data relating to health and sexual life, in cases expressly provided for by law. Personal Data relating to health and sexual life may only be processed, without the data subject's Explicit Consent, by persons under an obligation of confidentiality, for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of healthcare services and their financing. The processing of special categories of Personal Data is carried out in accordance with the decisions of the Personal Data Protection Board.

4. Transfer of Personal Data

4.1 Personal Data may only be transferred to third parties located in Turkey where the data subject has given Explicit Consent to the transfer, or where one of the circumstances listed in Section 3.3, in which Explicit Consent is not required, exists.

4.2 In addition to the conditions set out in Section 4.1, the transfer of Personal Data to third parties located abroad requires that the foreign country to which the Personal Data is transferred provide an adequate level of protection, or, where the foreign country does not provide adequate protection, that Argist and the relevant data controllers in that foreign country undertake in writing to ensure adequate protection and that the Board's approval is obtained.

5. Rights and Obligations

5.1 Rights of the Data Subject

Natural persons whose Personal Data is collected or processed by Argist have the right to apply to the Data Controller under the KVKK.

By exercising this right of application, the data subject may submit the following requests, in writing or by email, to Argist or its representatives, using the contact details provided at the end of this Policy:

  • To learn whether Personal Data is being processed,
  • To request information if Personal Data has been processed,
  • To learn the purpose of processing Personal Data and whether it is used in accordance with that purpose,
  • To know the third parties, in Turkey or abroad, to whom Personal Data is transferred,
  • To request correction of Personal Data if it has been processed incompletely or incorrectly,
  • To request the erasure or destruction of Personal Data within the framework of the Law,
  • To request that the operations described above be notified to the third parties to whom Personal Data has been transferred,
  • To object to a result arising to the detriment of the person themselves through the exclusive analysis of processed Personal Data by automated systems,
  • To request compensation for damages suffered as a result of unlawful processing of Personal Data.

5.2 Obligations of the Data Controller

5.2.1 Obligation to Inform

When collecting Personal Data, Argist will provide data subjects with an informative, clear and understandable notice regarding the process of processing their Personal Data and the purposes of that processing, and will ensure they are informed of their rights relating to their Personal Data.

The notice provided to data subjects will contain, at a minimum, the following elements:

  • The identity of the Data Controller and, if any, its representative,
  • The purpose, method and legal basis of the processing,
  • To whom and for what purposes Personal Data may be transferred,
  • The method and legal basis of personal data collection,
  • The other rights listed in Article 11 of the KVKK.

Argist fulfills its obligation to inform under the KVKK through the website at argist.com.

5.2.2 Obligations Relating to Data Security

Within the scope determined by applicable legislation, Argist takes the necessary measures to prevent data from being used for malicious purposes, destroyed, lost, unlawfully altered, or unlawfully obtained. In line with the Personal Data Protection Policy, Argist takes reasonable, legislation-compliant measures to implement an effective system of safeguards, including:

  • Preventing unauthorized persons from accessing the data processing system in order to use or process Personal Data (access control),
  • Ensuring that persons authorized to use a data processing system access only the data covered by their access authorization, and preventing Personal Data from being read, copied, altered or deleted by unauthorized persons during processing, use, and after storage (access control, need-to-know principle),
  • Preventing Personal Data from being read, copied, altered or deleted by unauthorized persons during electronic transfer or transmission, or while being recorded to a storage medium, and ensuring it is possible to detect and audit by whom Personal Data was transferred using data transmission tools (transmission control),
  • Ensuring the ability to check and determine whether Personal Data has been accessed, altered, or deleted from the data processing system, and by whom such operations were carried out (input control),
  • Ensuring that Personal Data processed on behalf of others is processed strictly in accordance with the instructions of the Data Controller (job control),
  • Ensuring measures are taken against the accidental destruction or loss of Personal Data (availability control),
  • Ensuring that Personal Data collected for different purposes can be processed separately.

If Personal Data being processed is unlawfully obtained by others, Argist will notify the relevant data subject and the Board of this as soon as possible.

Argist carries out, or arranges for, the audits necessary to ensure Personal Data security.

5.2.3 Cloud Computing

Argist evaluates whether the security measures taken by the Cloud Storage Service Provider are sufficient and appropriate. In this context, the personal data stored in the cloud is known in detail, backed up, and kept synchronized, and two-factor authentication is applied for remote access to this personal data where necessary.

When the cloud computing service relationship ends, all copies of encryption keys that could be used to render the personal data usable will be destroyed.

5.2.4 Registration with the Registry of Data Controllers

In accordance with the Regulation on the Registry of Data Controllers, Argist will fulfill its relevant obligation by registering with the Registry of Data Controllers established by the Presidency of the Personal Data Protection Authority. In this context, the following information will be made available to the public:

  • The name and address of the Data Controller and, if any, the Data Controller's representative and contact person, and its Registered Electronic Mail (KEP) address, if obtained,
  • The purposes for which Personal Data may be processed,
  • The group or groups of persons to whom Personal Data relates, and the data categories belonging to those persons,
  • The recipients and recipient groups to which Personal Data may be transferred,
  • Personal Data envisaged to be transferred abroad,
  • The registration date and the date on which the registration ends,
  • The measures taken regarding Personal Data security, and the maximum period required for the purposes for which the data is processed.

5.2.5 Awareness and Training

Argist is obliged to ensure that its employees, distribution channels, and third parties bound by mutual responsibilities defined by the Law are adequately informed and trained on the processing of personal data, within the framework of this Policy, local legislation and guidelines.

Argist takes the measures necessary to ensure that persons involved in processing Personal Data learn the requirements of local data protection legislation and this Policy; these measures include holding awareness sessions and providing training. Training and awareness activities are carried out through:

  • e-learning,
  • in-person sessions,
  • internal company bulletins,
  • other methods suitable for building and maintaining a high level of awareness on data protection matters.

These training and awareness activities are carried out in coordination with the HR Department.

6. Methods Applied to the Erasure, Destruction and Anonymization of Personal Data

Argist will erase, destroy and/or anonymize personal data within its organization using the methods set out below.

6.1.1 Software-as-a-Service Cloud Solutions (such as Office 365, etc.)

Argist will delete data on the cloud system by issuing a deletion command. While carrying out this operation, particular attention is paid to ensuring that the relevant user does not have the authority to recover deleted data on the cloud system.

6.1.2 Personal Data on Paper

Argist will erase personal data on paper using the redaction method. Redaction is carried out by cutting the personal data out of the relevant document where possible, or, where this is not possible, by rendering it unreadable and irreversible using fixed ink so that it cannot be recovered with technological solutions.

6.1.3 Office Files on a Central Server

Argist will delete the file using the operating system's deletion command, or will remove the relevant user's access rights to the file or the directory containing it. While carrying out this operation, Argist ensures that the relevant user is not also the system administrator.

6.1.4 Personal Data on Removable Media

Argist stores personal data on flash-based storage media in encrypted form and will delete it using software suitable for such media.

6.1.5 Databases

Argist will delete the relevant rows containing personal data using database commands (such as DELETE, etc.). While carrying out this operation, Argist ensures that the relevant user is not also the database administrator.

7. Periods for the Ex Officio Erasure, Destruction or Anonymization of Personal Data

Argist erases, destroys or anonymizes personal data at the first periodic destruction process following the date on which the obligation to erase, destroy or anonymize the data arises.

The periodic destruction process is carried out by Argist within 180 days following the date on which the obligation to erase, destroy or anonymize personal data arises. In mandatory circumstances, this period may be extended by up to a further 30 days.

8. Departmental Personal Data Protection Officer

To ensure full compliance with the Law and other applicable legislation in the processing of personal data, to determine and deliver departmental training needs, to keep departmental personal data inventories up to date, and to help internalize the work carried out under Argist's Personal Data Protection Policy, Argist has appointed, on the recommendation of the relevant manager, one person in each department as the "Departmental Personal Data Protection Officer."

9. Amendments to the Policy and Effective Date

The provisions of this Policy may be amended by Argist where deemed necessary — within the scope of, and not limited to, the articles of any Regulation issued pursuant to the KVKK and other applicable legislation, or for other reasons — by publishing the amendments on the website in accordance with legislative requirements. If any of these provisions is amended, the relevant amendment enters into force on the date it is published on the website.

Data Controller: Argist Teknoloji Arge ve Yazılım

Contact information

Have questions?

For any questions about this policy, reach us at [email protected] or call 0850 346 91 94.