Personal Data Retention and Disposal Policy
Last updated: 11 September 2026
1. Purpose and Scope
This policy sets out the procedures and principles for retaining and disposing of personal data processed by GNR Oyuncak Gıda Sanayi Ticaret Limited Şirketi under Law No. 6698 on the Protection of Personal Data and the Regulation on the Deletion, Destruction or Anonymisation of Personal Data.
The policy covers all natural persons whose personal data are processed, including customers, visitors, supplier employees and job applicants.
2. Definitions
| Deletion | Making personal data inaccessible and unusable in any way by relevant users |
| Destruction | Making personal data inaccessible, irrecoverable and unusable in any way by anyone |
| Anonymisation | Making personal data impossible to associate with an identified or identifiable natural person, even when matched with other data |
| Periodic disposal | Deleting, destroying or anonymising personal data on the organisation's own initiative at the recurring intervals specified in the policy once the conditions for processing no longer exist |
3. Storage Environments
| Electronic environments | Non-electronic environments |
|---|---|
| E-commerce platform (Shopify), email servers, accounting and electronic invoicing software, cloud storage, backup environments and office computers | Printed invoices and dispatch notes, printed forms, written contracts and archive cabinets |
4. Legal Grounds Requiring Retention
- Law No. 6502 on the Protection of Consumers
- Law No. 6563 on the Regulation of Electronic Commerce
- Tax Procedure Law No. 213
- Turkish Commercial Code No. 6102
- Turkish Code of Obligations No. 6098
- Law No. 6698 on the Protection of Personal Data
5. Retention Periods
| Data / process | Retention period | Disposal timing |
|---|---|---|
| Order, invoice and accounting records | 5 years from the end of the year to which they relate under Tax Procedure Law No. 213 | At the first periodic disposal after the period expires |
| Contracts and commercial records | 10 years under Turkish Commercial Code No. 6102 | At the first periodic disposal after the period expires |
| Membership and customer account information | For the duration of the account and for 10 years under the Turkish Code of Obligations No. 6098 after it ends | At the first periodic disposal after the period expires |
| Request, complaint and support records | 3 years | At the first periodic disposal after the period expires |
| Commercial electronic message consent records | 3 years after consent is withdrawn under the Regulation on Commercial Electronic Messages | At the first periodic disposal after the period expires |
| Internet access and transaction log records | 2 years | At the first periodic disposal after the period expires |
| Camera recordings | 14 days (automatically overwritten by the recording device) | Automatically at the end of the period |
6. Disposal Methods
Deletion
- Making the database record inaccessible to relevant users
- Removing access permissions in cloud and server environments
- Redacting data on paper
Destruction
- Irreversibly shredding paper documents in a document shredder
- Physically destroying storage media (disks, USB drives) or overwriting them with secure software
Anonymisation
- Removing identifying fields and using masking and aggregation techniques so the data cannot be associated with a natural person
7. Periodic Disposal Schedule
Periodic disposal schedule, responsible persons and recording method: Periodic disposal is carried out every June and December, no more than six months apart, and documented in a record.. The schedule is determined with regard to the maximum periods under applicable legislation.
Disposal requested by a data subject is completed within 30 days of receipt of the request.
8. Technical and Organisational Measures
Measures actually implemented concerning access control, secure communications, backups, records, training and data processor agreements: Admin access is restricted to authorised persons; card data is processed by a PCI DSS-compliant payment provider; Shopify is PCI DSS Level 1 compliant; corporate email uses SPF and DKIM; confidentiality obligations and data-processing terms are used with staff and service providers..
9. Responsibilities and Allocation of Duties
| Company name | Responsibility |
|---|---|
| Company Owner and Manager | Implementing and updating the policy |
| Accounting Officer | Carrying out and documenting periodic disposal |
| E-commerce Officer | Implementing technical measures |
10. Entry into Force and Updates
This policy entered into force on 11 September 2026. It is updated when legislation changes or as needed; the current version is published on this page.
11. Contact
For questions and requests about the policy: kvkk@romansonofficial.com · gnroyuncak@hs01.kep.tr · Mahmutbey Mahallesi, 2412. Sokak, C Plaza, Kat: 8, No: 89, Bağcılar / İstanbul
