Legal
Data Protection Notice
Last updated: 10.08.2026
Identity of the Data Controller
This Data Protection Notice is issued pursuant to Article 10 of Law No. 6698 on the Protection of Personal Data (the KVKK or the Law). It explains how Teriş Kimyevi Maddeler Ticaret ve Sanayi A.Ş. (Teris or the Company), acting as data controller, processes personal data.
- Legal name: Teriş Kimyevi Maddeler Ticaret ve Sanayi A.Ş.
- Registered address: Çayıryolu Sokak, Üçgen Plaza No:7 Kat:12, 34752 İçerenköy, Ataşehir / Istanbul, Türkiye
- Telephone: +90 216 577 62 62
- E-mail: info@teris.com.tr
- Website: www.teris.com.tr
- Additional operating locations: Tacirler Bonded Warehouse, Hastane Mah. 29 Mayıs Cad. No:40 Hadımköy / Istanbul; Warehouse, Maltepe Cad. No:10 Topkapı / Istanbul
Established in 1961 and part of Tacirler Holding, the Company operates in the import, distribution and supply-chain financing of plastic raw materials (polymers). Data protection is an integral part of our corporate governance framework.
Categories of Personal Data Processed
Depending on the nature of the relationship between the data subject and the Company, the following categories of personal data may be processed:
- Identity data: name, surname, job title, position, the legal entity represented, and details appearing on signature circulars.
- Contact data: business address, e-mail address, landline and mobile telephone numbers, and fax number.
- Customer transaction data: requests for quotation (RFQ), order records, shipment and delivery records, waybill and invoice details, product and volume data, and correspondence.
- Financial data: current account movements, payment and collection records, bank account and IBAN details, collateral, cheque and promissory note information, and data underlying credit and risk limit assessments.
- Transaction security data: IP address, server and application log records, session information, cookie records, and website access and traffic data.
- Legal process data: contracts, formal notices, information relating to litigation and enforcement files, and correspondence with public authorities.
- Marketing data: commercial electronic message consents, communication preferences, and records of participation in events and trade fairs.
- Personnel and candidate data: educational background, professional experience, language skills, references and other information voluntarily provided in career application forms.
- Physical premises security data: entry and exit records generated during site visits.
The Company does not request special categories of personal data and asks data subjects to refrain from submitting such data through forms or correspondence.
Purposes of Processing
Personal data is processed in accordance with the general principles set out in Article 4 and the processing conditions set out in Articles 5 and 6 of the Law, for the following purposes:
- Managing requests for quotation (RFQ) and preparing and issuing commercial offers.
- Receiving and tracking orders and planning and executing shipment and delivery operations.
- Administering import operations, customs clearance, bonded warehousing and the associated documentary flow.
- Maintaining current accounts and carrying out invoicing, collection and reconciliation.
- Performing credit, risk, collateral and limit assessments for supply-chain financing services.
- Negotiating, concluding, performing and terminating contracts.
- Responding to information requests and complaints received through the website or other channels.
- Conducting recruitment, evaluating career applications and maintaining a candidate pool.
- Ensuring information and system security, preventing unauthorised access and maintaining audit trails.
- Fulfilling legal obligations under tax, commercial, customs, foreign exchange and capital markets legislation, and reporting to competent authorities.
- Exercising rights of defence in disputes and pursuing the recovery of receivables.
- Where explicit consent has been obtained, sending commercial electronic messages.
Method of Collection and Legal Grounds
Personal data is collected through the contact, quotation and career forms on the website, e-mail and telephone correspondence, meetings, trade fairs, contractual and order documentation, logistics processes, documents transmitted by banks and customs brokers, and publicly available sources such as the trade registry gazette, by wholly or partly automated means or by non-automated means forming part of a data filing system.
Processing is based on the following legal grounds set out in Article 5(2) of the Law:
- Processing is expressly permitted by law: record-keeping and documentation obligations under the Turkish Commercial Code, the Tax Procedure Law, the Customs Law and related secondary legislation.
- Processing is directly related to the conclusion or performance of a contract: quotation, ordering, shipment, invoicing and collection processes.
- Processing is mandatory for the data controller to fulfil a legal obligation: responding to requests from competent public authorities.
- Processing is mandatory for the establishment, exercise or protection of a right: dispute resolution and debt recovery.
- Processing is mandatory for the legitimate interests of the data controller, provided that the fundamental rights and freedoms of the data subject are not harmed: information security, risk management, continuity of the commercial relationship and corporate communication.
Processing that does not fall within any of the above grounds is carried out solely on the basis of explicit consent. This applies to commercial electronic messages, the activation of non-essential analytics cookies and the retention of career applications in the candidate pool after the recruitment process has ended. Consent may be withdrawn at any time; withdrawal does not affect the lawfulness of prior processing.
Transfer of Personal Data
Personal data may be transferred within Türkiye to the following recipients, limited to and proportionate with the purposes of processing, under Article 8 of the Law:
- Public institutions, regulatory authorities and judicial bodies legally authorised to receive such data.
- Customs brokerage firms engaged in import and customs clearance procedures.
- Logistics, transport, bonded warehousing and storage service providers.
- Banks, financial institutions, insurers and trade credit insurance providers.
- Independent audit firms, certified public accountants and legal advisers.
- Information technology infrastructure, hosting and software service providers.
- Group companies within Tacirler Holding, strictly limited to joint management, audit and reporting purposes.
Cross-border transfers are made primarily to the foreign manufacturers and suppliers whose products the Company imports or distributes, in the context of order placement, shipment and technical support, and are limited to the name, title and business contact details of the relevant individuals. Such transfers are carried out in accordance with Article 9 of the Law: to countries deemed to provide adequate protection, subject to appropriate safeguards such as written undertakings or standard contractual clauses, or otherwise on the basis of explicit consent.
Retention Periods
Personal data is retained for as long as necessary for the purposes for which it was collected, taking into account the minimum periods prescribed by legislation. Once the purpose of processing ceases to exist, data is deleted, destroyed or anonymised under the Personal Data Retention and Destruction Policy of the Company.
- Commercial books, invoices, waybills and customs declarations: ten years, under the Turkish Commercial Code and the Tax Procedure Law.
- Contracts and related records: for the ten-year statutory limitation period following termination.
- Contact and quotation requests: two years from conclusion of the request.
- Career applications: one year from evaluation where explicit consent has been given; otherwise destroyed at the end of the process.
- Internet traffic and system logs: for the periods prescribed by legislation.
Data Security Measures
In accordance with Article 12 of the Law, the Company implements administrative and technical measures designed to provide an appropriate level of security.
Administrative measures include a personal data inventory, a retention and destruction policy, regular employee awareness training, confidentiality undertakings, written agreements with data processors, access rights restricted according to job descriptions, and periodic internal audits.
Technical measures include encryption in transit (TLS), firewalls and intrusion detection, patch and version management, strong authentication, session and cross-site request forgery protections, backup and disaster recovery arrangements, log monitoring, and vulnerability scanning.
Rights of the Data Subject under Article 11 of the KVKK
By applying to the Company, data subjects may exercise the following rights:
- To learn whether their personal data is being processed.
- To request information if their personal data has been processed.
- To learn the purpose of processing and whether the data is used in accordance with that purpose.
- To know the third parties, in Türkiye or abroad, to whom their personal data has been transferred.
- To request the rectification of personal data that is incomplete or inaccurate.
- To request the erasure or destruction of personal data under the conditions set out in Article 7 of the Law.
- To request that rectification, erasure and destruction be notified to third parties to whom the data has been transferred.
- To object to any adverse outcome resulting from the analysis of personal data exclusively by automated means.
- To claim compensation for damage suffered as a result of unlawful processing of their personal data.
How to Submit an Application
Requests may be submitted in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller. The application must state the name, surname and signature of the applicant, the Turkish identity number for Turkish citizens, the address for notification, any e-mail address or telephone number for notification, and the subject matter of the request.
- Written application: a wet-signed petition delivered in person or through a notary public to Çayıryolu Sokak, Üçgen Plaza No:7 Kat:12, 34752 İçerenköy, Ataşehir / Istanbul.
- Electronic application: submission to info@teris.com.tr using a secure electronic or mobile signature, or from an e-mail address already registered in our systems; submissions may also be made through our registered electronic mail address.
Requests are concluded free of charge as soon as possible and in any event within thirty days of receipt. Where the request entails additional cost, a fee may be charged under the tariff set by the Personal Data Protection Board. If the application is rejected, the response is insufficient or no response is given in time, the data subject may complain to the Board.
Entry into Force and Updates
This Notice may be updated in light of legislative amendments, decisions of the Personal Data Protection Board and changes in the business processes of the Company. The current version takes effect on the date it is published at www.teris.com.tr.
For any questions: info@teris.com.tr