MTE Group — GDPR PRIVACY NOTICE
Effective Date: [DD/MM/YYYY]
This Privacy Notice has been prepared by MTE Group, acting as the Data Controller, in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”). It explains how your personal data is collected, processed, protected, and your rights regarding such processing. This notice applies to all communication channels, including our website.
1. Identity of the Data Controller
- Company Name: MTE Group
- Address: Altunizade, Kısıklı Cd. No: 36, 34662 Üsküdar / Istanbul, Türkiye
- Phone: +90 (212) 324 50 50
- Email: contact@mtegroup.com.tr
2. Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Special Category Personal Data: Personal data revealing health information, biometric data, genetic data, or other sensitive information requiring enhanced protection.
- Data Controller: The natural or legal person that determines the purposes and means of processing personal data.
- Data Processor: A natural or legal person processing personal data on behalf of the Data Controller.
- Data Subject: Any identified or identifiable individual whose personal data is processed.
3. Categories of Personal Data, Sources and Collection Methods
3.1 Categories of Personal Data
| Category | Examples | Purpose |
|---|---|---|
| Identity Data | Full name, national identification number, date of birth | Identity verification and legal compliance |
| Contact Data | Address, email address, telephone number | Communication and customer support |
| Financial Data | IBAN, bank account details, invoicing information | Payment processing and accounting |
| Technical / Internet Data | IP address, device information, cookie data | Website analytics, security, and service improvement |
| Transaction / Activity Data | Order history, support requests, transaction records | Service delivery, reporting, and customer support |
| Image & Signature Data | Photographs and signature images | Identity verification and document authentication |
| Other Data | Reference information and service feedback | Additional information where necessary |
3.2 Sources and Collection Methods
- Information Provided Directly by You: Website forms (contact, quotation, registration), email correspondence, telephone conversations, and contractual documentation.
- Automatically Collected Information: Server logs, cookies, analytics technologies, and technical monitoring tools.
- Third-Party Sources: Business partners, suppliers, public authorities, and authorized data providers where legally permitted.
Personal data is processed only for specified purposes, in a proportionate manner, and for no longer than necessary.
4. Purposes and Legal Bases for Processing
4.1 Purposes of Processing
- Providing requested products and services
- Customer support and communication
- Billing, payment processing, and financial administration
- Compliance with legal and regulatory obligations
- System security and fraud prevention
- Analytics, reporting, and business process improvement
- Marketing and promotional communications (where consent has been obtained)
- Internal auditing, compliance, and legal management
4.2 Legal Bases
Personal data may be processed based on one or more of the following legal grounds:
- Your explicit consent
- The performance or execution of a contract
- Compliance with a legal obligation
- The legitimate interests of the Data Controller, provided such interests do not override your fundamental rights and freedoms
- Compliance with applicable legal requirements
Where required by GDPR, particularly for marketing activities, personal data will only be processed based on your explicit consent.
5. Data Sharing and International Transfers
5.1 Data Sharing
Your personal data may be shared, where necessary and subject to appropriate safeguards, with:
- Group companies and affiliates
- Service providers (cloud services, email providers, SMS providers, hosting companies, data centers, etc.)
- Courier and logistics companies
- Government authorities, courts, and regulatory bodies where legally required
- Third parties involved in delivering business services
- International service providers where applicable
Appropriate contractual, technical, and organizational safeguards are implemented before any data transfer takes place.
5.2 International Data Transfers
If personal data is transferred outside your jurisdiction:
- The level of data protection in the recipient country will be assessed.
- Standard Contractual Clauses (SCCs) or equivalent safeguards will be implemented where required.
- All transfers will comply with GDPR and applicable data protection legislation.
6. Data Retention and Disposal
- Personal data is retained only for as long as necessary to fulfill the relevant purposes.
- Applicable statutory retention periods are observed.
- Upon expiration of the retention period, personal data is securely deleted, destroyed, or anonymized.
- Disposal processes are carried out using secure and appropriate methods.
7. Your Rights Under GDPR
Under the GDPR, you have the right to:
- Know whether your personal data is being processed.
- Request access to your personal data.
- Obtain information about the purposes of processing.
- Know the recipients with whom your data has been shared.
- Request correction of inaccurate or incomplete personal data.
- Request erasure, anonymization, or restriction of processing where applicable.
- Request notification of such actions to third parties where required.
- Object to decisions based solely on automated processing.
- Seek compensation where unlawful processing causes damage.
Requests relating to your GDPR rights may be submitted to MTE Group in writing or electronically. Requests will be evaluated following identity verification and answered within the periods required under applicable law.
8. Consent (Where Applicable)
Certain processing activities, particularly those relating to marketing and promotional communications, require your explicit consent.
- Consent will be obtained separately.
- Consent must be freely given, specific, informed, and unambiguous.
- You may withdraw your consent at any time.
- Records of consent and withdrawal are securely maintained.
9. Security Measures
MTE Group implements appropriate technical and organizational measures to protect personal data, including:
- Access control and authorization systems
- Encryption and secure communication protocols (TLS / SSL)
- Physical security measures for facilities and servers
- Backup and disaster recovery procedures
- System monitoring, logging, and regular updates
- Employee awareness and training
- Risk assessment and security management processes
10. Changes to this Privacy Notice
MTE Group reserves the right to amend or update this Privacy Notice at any time. Any revised version becomes effective upon publication on the website. Where legally required, affected individuals will be appropriately informed of significant changes.
11. Governing Law and Jurisdiction
This Privacy Notice shall be governed by the laws of the Republic of Türkiye. Any disputes arising from this Notice shall fall under the exclusive jurisdiction of the courts of Istanbul (Üsküdar), Türkiye.