CLOSED-CIRCUIT TELEVISION (CCTV) SYSTEM PRIVACY NOTICE

Last Updated: 28.07.2026

This Privacy Notice constitutes the detailed second layer of the Camera Information Sign (the summary layer of the layered privacy notice) displayed at the entrances and common areas of our premises and has been prepared pursuant to Article 10 of the Turkish Personal Data Protection Law No. 6698 (“KVKK”).

The following companies operating within the same building and using the shared CCTV system act as JOINT DATA CONTROLLERS for the purposes of this Privacy Notice.

Data Controllers

Company MERSIS / Contact Information Address
SAN Bilgisayar Ticaret Turizm İthalat ve İhracat A.Ş. MERSIS: 0742042956600027

KEP: san.bilgisayar@hs01.kep.tr

E-mail / Tel: info@santsg.com / +90 850 777 07 29

Pınarbaşı Mahallesi, Hürriyet Cad. Akdeniz Üniversitesi Antalya Teknokent Ar-Ge 5 No:3 F İç Kapı No:2, Konyaaltı / Antalya / Türkiye
Paximum Turizm Ticaret ve Taahhüt A.Ş. MERSIS: 0723042093800001

KEP: paximum@hs01.kep.tr

E-mail / Tel: invoice@paximum.com / +90 850 777 07 29

Pınarbaşı Mahallesi, Hürriyet Cad. Akdeniz Üniversitesi Antalya Teknokent Ar-Ge 5 No:3 F İç Kapı No:2, Konyaaltı / Antalya / Türkiye

As both companies operate under the SAN COMPANIES group within the same building and use a common CCTV system, they act as Joint Data Controllers for the purposes described in this Privacy Notice.

Definitions

Personal Data
Any information relating to an identified or identifiable natural person.

Special Categories of Personal Data
Personal data specified under Article 6 of the KVKK, including but not limited to data relating to health, sexual life, racial or ethnic origin, religion, criminal convictions, biometric data and genetic data.

Processing of Personal Data
Any operation performed on personal data such as collection, recording, storage, preservation, transfer or any other processing activity.

Data Subject
The natural person whose personal data is processed (you).

Data Controller
The natural or legal person determining the purposes and means of processing personal data and responsible for establishing and managing the data recording system.

Information Obligation
The obligation of the Data Controller to inform the data subject, at the time personal data is obtained, regarding its identity, purposes of processing, recipients of data transfers, collection method, legal basis and the rights set forth under Article 11 of the KVKK.

 

Data Subjects and Processed Personal Data

Data Subjects:
Employees, interns, managers, visitors, suppliers and business partner representatives entering or present within our premises who are captured by the CCTV system.

Processed Personal Data:
Visual recordings (security camera footage).

NO AUDIO RECORDINGS ARE MADE.

CCTV Coverage Areas and Principle of Proportionality

The CCTV cameras are installed in the following areas:

  • Inside the building: Entrances, corridors, common areas and office rooms for the protection of computers, servers and technical equipment due to the nature of software development activities.
  • Kitchen: Solely for fire prevention and physical security purposes.
  • Outside the building and parking area.

NO CAMERAS ARE INSTALLED in areas where privacy is essential, including but not limited to restrooms, resting rooms and prayer rooms.

Principle of Proportionality and Data Minimization

The number, angle and positioning of the cameras are limited strictly to the areas and assets requiring protection (such as computers, servers, technical equipment, entrances/exits and parking areas).

The CCTV system is not intended for continuous employee surveillance, individual monitoring, performance evaluation, productivity assessment or attendance monitoring.

The cameras record only our own premises and parking areas. Public spaces and neighboring properties are not monitored.

The street on which the building is located is monitored independently by the Antalya Teknokent Administration acting as a separate Data Controller, and therefore falls outside the scope of this Privacy Notice.

Purpose of Processing, Legal Basis, Transfer of Personal Data and Collection Method

  1. Purpose of Processing and Legal Basis

Your CCTV recordings are processed for the following purposes:

  • Maintaining entrance and exit records;
  • Ensuring the security of the premises, individuals within the premises and company assets (including computers, servers and technical equipment);
  • Ensuring occupational health and safety and preventing workplace accidents;
  • Protecting workplace security;
  • Assisting in the detection and prevention of criminal acts.

The above processing activities are based on Article 5/2(f) of the KVKK, which permits processing where it is necessary for the legitimate interests of the Data Controller, provided that such processing does not violate the fundamental rights and freedoms of the data subject.

Processing is carried out in accordance with the principle of proportionality following a legitimate interest balancing assessment.

Where incidents affecting business security occur (such as theft, damage to company assets or occupational health and safety incidents), or in the event of a legal dispute, CCTV recordings may also be processed as evidence for administrative and legal proceedings pursuant to Article 5/2(e) of the KVKK, which permits processing where necessary for the establishment, exercise or protection of a legal right.

Such use is limited exclusively to specific security incidents and is not intended for routine employee performance or attendance monitoring.

  1. Recipients of Personal Data and Purposes of Transfer

Your CCTV recordings may be transferred, without requiring explicit consent or further information, to competent public authorities where required under Article 28/1 of the KVKK.

Apart from such cases, recordings may only be shared:

  • where a security incident or legal dispute has occurred; and
  • upon the written request of competent judicial, administrative or law enforcement authorities.

Your personal data is not transferred abroad.

iii. Method of Collection

Your CCTV recordings are collected automatically through the security camera system by means of live monitoring and recording.

The Network Video Recorder (NVR) is physically located within our premises.

Recordings are not stored in cloud environments or on servers located outside Türkiye.

Access Control and Security Measures

Live camera feeds and recorded footage are accessible only to authorized Information Technologies personnel.

Appropriate technical and organizational security measures are implemented, including:

  • Access authorization matrices,
  • Physical security of the recording equipment,
  • Access logging,
  • Technical and administrative safeguards.

No audio recording is performed.

Retention Period

CCTV recordings are retained for 7 (seven) days, limited to the minimum period necessary for the purposes stated above.

At the end of this period, recordings are automatically overwritten and permanently deleted by the system.

Where recordings are required as evidence in connection with a security incident or legal dispute, they shall be retained only until the relevant legal or administrative process has been concluded.

Your Rights Under Article 11 of the KVKK

Data subjects may exercise their statutory rights by submitting a request to the Data Controller.

Under the KVKK, you have the right to:

  1. a) learn whether your personal data is processed;
  2. b) request information if your personal data has been processed;
  3. c) learn the purpose of processing and whether it is used in accordance with such purpose;
  4. d) know the third parties to whom personal data has been transferred domestically or abroad;
  5. e) request correction of incomplete or inaccurate personal data;
  6. f) request deletion or destruction of personal data pursuant to Article 7 of the KVKK;
  7. g) request notification of the actions taken under items (e) and (f) to third parties to whom the data has been transferred;
  8. h) object to any outcome arising against you through the exclusive analysis of processed data by automated systems;
  9. i) request compensation for damages arising from unlawful processing of personal data.

Application Procedure and Complaint to the Personal Data Protection Board

You may submit your requests:

  • in writing to our company address:

Pınarbaşı Mahallesi, Hürriyet Cad. Akdeniz Üniversitesi Antalya Teknokent Ar-Ge 5 No:3 F İç Kapı No:2, Konyaaltı / Antalya / Türkiye

  • through the relevant company’s registered electronic mail (KEP) address using a secure electronic signature or mobile signature; or
  • via the e-mail address registered in our systems (info@santsg.com).

Your application should include:

  • your full name and surname (and signature for written applications);
  • Turkish Identification Number (or nationality and passport number for foreign nationals);
  • address for notification;
  • e-mail address and/or telephone number, if applicable;
  • the subject of your request.

Any documents supporting your request should be attached to your application.

The Data Controller reserves the right to verify your identity. A representative authorized by the Joint Data Controllers may also verify your identity where necessary.

Further information regarding application procedures can be found in the Communiqué on the Procedures and Principles of Application to the Data Controller published by the Turkish Personal Data Protection Authority.

Applications shall be finalized free of charge within thirty (30) days in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller. If the request requires additional costs, the fee determined by the Personal Data Protection Board may be charged.

If your application is rejected, the response is deemed insufficient, or no response is provided within the statutory period, you may lodge a complaint with the Turkish Personal Data Protection Board within 30 days from the date you become aware of the response, and in any event within 60 days from the date of your application.