İME DC Sağlık Ürünleri Sanayi Ve Ticaret Limited Şirketi



PERSONAL DATA PROTECTION POLICIES


Document Date: 1 June 2026


TABLE OF CONTENTS

PERSONAL DATA PROTECTION POLICIES …………………………………………………

  1. DATA PRIVACY COMMITMENT………………………………………………………………………..
  2. PURPOSE OF THE POLICY ……………………………………………………………………………………
  3. SCOPE OF THE POLICY ……………………………………………………………………………….
  4. DEFINITIONS ……………………………………………………………………………………………………..
  5. PRINCIPLES OF PERSONAL DATA PROCESSING ………………………………………………………….
  6. PROCESSING OF PERSONAL DATA………………………………………………………………….
  7. PROCESSING OF SPECIAL CATEGORIES OF PERSONAL DATA …………………………………..
  8. DELETION, DESTRUCTION AND ANONYMIZATION OF PERSONAL DATA……………………………………………………………….
  9. TRANSFER OF PERSONAL DATA AND PROCESSING OF PERSONAL DATA BY THIRD PARTIES ……………………………………………………………………..
  10. THE COMPANY’S OBLIGATION TO INFORM AND THE RIGHTS OF THE DATA SUBJECT……….
  11. DATA MANAGEMENT, SECURITY AND MEASURES TAKEN FOR THE PROTECTION OF PERSONAL DATA………………………………………………………………..
  12. TRAINING ………………………………………………………………………………………………………….
  13. AUDIT ………………………………………………………………………………………………………
  14. BREACHES …………………………………………………………………………………………………….
  15. RESPONSIBILITIES………………………………………………………………………………………
  16. AMENDMENTS TO THE POLICY…………………………………………….
  17.  LANGUAGE ……………………………………………………….


PERSONAL DATA PROTECTION POLICY


1) DATA PRIVACY COMMITMENT

İME DC Sağlık Ürünleri Sanayi Ve Ticaret Limited Şirketi (the ‘Company’) undertakes to act in accordance with this Policy and with the procedures to be implemented under the Policy with respect to the Personal Data held within its organization.


2) PURPOSE OF THE POLICY

The purpose of this Policy is to set out the principles regarding the methods and processes for the protection of personal data within the scope of the Turkish Personal Data Protection Law No. 6698 (‘KVKK’) in relation to the Company’s activities.


3) SCOPE OF THE POLICY

The Company’s core field of activity is medical devices and healthcare products. This Policy covers all activities relating to the Personal Data on which the Company carries out any type of processing activity for the continuation of its operations, and applies to such activities.

This Policy may be amended from time to time where the KVKK Regulations so require or where the Company’s Data Controller Representative or its management deems it necessary, provided that legal obligations are observed.


4) DEFINITIONS

The terms used in this Policy have the following meanings;

“Explicit Consent” refers to the consent that Personal Data Subjects declare of their own free will, based on being informed about the processing of their data and without it being tied to any condition.

“Anonymization” refers to rendering Personal Data incapable of being associated in any way with an identified or identifiable natural person, even when matched with other data.

 “Anonymized Data” refers to data that cannot in any way be associated with a natural person.

“Personal Data” refers to any information relating to an identified or identifiable natural person.

“Personal Data Processing” refers to any operation performed on data, such as the obtaining, recording, storage, retention, alteration, reorganization, disclosure, transfer, taking over, making available, classification or prevention of the use of Personal Data, wholly or partially by automated means or by non-automated means provided that they form part of a data recording system.

“Board” refers to the Personal Data Protection Board.

Authority” refers to the Personal Data Protection Authority.

“KVKK” refers to the Turkish Personal Data Protection Law No. 6698.

“KVKK Regulations/Provisions” refers to the Turkish Personal Data Protection Law No. 6698 and other relevant legislation on the protection of Personal Data, the binding decisions, principle decisions, rulings and instructions issued by regulatory and supervisory authorities, courts and other official bodies, the applicable international agreements on the protection of data, and all other relevant legislation.

KVKK Procedures” refers to the procedures setting out the obligations with which the Company, its employees and the Data Controller Representative must comply under this Policy.

“Special Categories of Personal Data” refers to data relating to individuals’ race, ethnic origin, political opinion, philosophical belief, religion, religious sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as their biometric and genetic data.

“Deletion or Erasure” is the process of rendering Personal Data inaccessible and non-reusable in any way for the relevant users.

 “Personal Data Inventory” refers to the inventory containing information on the Company’s Personal Data Processing activities, such as Personal Data Processing processes and methods, Personal Data Processing purposes, data category, the third parties to whom Personal Data are transferred, and similar information.

“Data Processor” refers to the natural or legal person who processes Personal Data on behalf of the Data Controller, based on the authority granted by the Data Controller.

“Data Subject” refers to the natural person to whom the Personal Data belong.

“Data Controller” refers to the natural or legal person who processes Personal Data by determining the purposes and means of processing, and who is responsible for establishing and managing the data recording system.

“Data Controller Representative” refers to the Company employee who conducts the Company’s relations with the Authority.

Destruction” refers to the destruction of personal data, rendering them inaccessible, irretrievable and unusable by anyone in any way.


5) PRINCIPLES OF PERSONAL DATA PROCESSING

5.1. Processing of Personal Data in Compliance with the Law and the Rules of Good Faith

Personal Data are processed by the Company in compliance with the law and the rules of good faith and on the basis of proportionality. What is meant by the principle of proportionality is the processing of only as much personal data as is necessary for the company’s activities, for as long as necessary.

5.2. Taking the Necessary Measures to Ensure that Personal Data Are Accurate and, Where Necessary, Up to Date

The Company takes all necessary measures to ensure that Personal Data are complete, accurate and up to date, and updates the relevant Personal Data where the Data Subject requests a change to their Personal Data.

5.3. Processing of Personal Data for Specified, Legitimate and Explicit Purposes

Before Personal Data are Processed, the Company determines the purposes for which the Personal Data will be processed. In this context, the Data Subject is informed within the scope of the KVKK Regulations and, where required, their Explicit Consent is obtained.

5.4. Personal Data Being Relevant, Limited and Proportionate to the Purposes for Which They Are Processed

The Company processes Personal Data only in cases where explicit consent is not required under the KVKK Regulations and/or, in cases where obtaining explicit consent is required, in line with the purpose covered by the Explicit Consent obtained from the Data Subject, and in accordance with the principle of proportionality.

5.5. Retaining Personal Data Only for as Long as Necessary and Deleting Them Thereafter

5.5.1. The Company retains Personal Data, in accordance with the purpose of their processing, only for as long as necessary for the company’s activities. Where the Company wishes to retain Personal Data for a period longer than that stipulated in the KVKK Regulations or required by the purpose of Personal Data Processing, the Company acts in accordance with the obligations set out in the KVKK Regulations.

5.5.2. After the period required by the purpose of Personal Data Processing has ended, Personal Data are Deleted, Destroyed or Anonymized. In such a case, it is also ensured that the third parties to whom the Company has transferred Personal Data Delete, Destroy or Anonymize the Personal Data.

5.5.3. The Data Controller Representative is responsible for operating the Deletion, Destruction and Anonymization processes. The procedure required in this respect is established by the Data Controller Representative.


6) PROCESSING OF PERSONAL DATA

Within the scope of the Company’s activities, personal data may be processed for the purpose of carrying out commercial activities and providing services, including but not limited to the purposes listed below;

  • Carrying out the activities,
  • Providing services under the contract and within the framework of service standards, and fulfilling contractual requirements,
  • Fulfilling legal obligations as required or mandated by legislation
  • Evaluating job applications and providing employment. Personal data contained in CVs, diplomas and other similar documents shared by any means during the process of the applications you make as a Candidate Employee may be processed, stored and transferred under this Policy for the purpose of evaluating the job application. Where employment is provided, employees’ personal data are processed, stored and transferred in accordance with the obligations under the Labor Law No. 4857 and other applicable legislation,
  • Maintaining contact with persons who have a business relationship with the Company,
  • Marketing,
  • Receiving and placing advertisements,
  • Legal and financial reporting,
  • Invoicing.

Personal Data may be processed by the Company only within the scope of the procedures and principles set out below.

6.1. Explicit Consent

In cases where obtaining explicit consent is required for the processing of Personal Data under the KVKK Regulations;

6.1.1. Personal Data are processed after the Data Subjects have been informed within the framework of the fulfillment of the Obligation to Inform, and provided that the Data Subjects give their Explicit Consent.

6.1.2. Within the framework of the Obligation to Inform, Data Subjects are notified of their rights before Explicit Consent is obtained.

6.1.3. The Explicit Consent of Data Subjects is obtained through methods compliant with the KVKK Regulations. Explicit Consents are retained by the Company in a demonstrable manner for the period required under the KVKK Regulations.

6.1.4. The Data Controller Representative ensures that the Obligation to Inform is fulfilled with respect to all Personal Data Processing processes and that, where necessary, Explicit Consent is obtained and retained. All department employees Processing Personal Data are obliged to comply with the instructions of the Data Controller Representative and with this Policy.

6.2. Processing of Personal Data Without Obtaining Explicit Consent

6.2.1 In cases where the Processing of Personal Data without obtaining Explicit Consent is envisaged under the KVKK Regulations (in the cases listed in the laws, including but not limited to Article 5.2 and Article 6.3 of KVKK), the Company may process Personal Data without obtaining the Data Subject’s Explicit Consent. Where Personal Data are processed in this manner, the Company Processes the Personal Data within the limits drawn by the KVKK Regulations and in compliance with the Obligation to Inform. In this context:

6.2.1.1. Personal Data may be processed by the Company without Explicit Consent where this is necessary for the protection of the life or physical integrity of the Data Subject who is unable to give consent due to actual impossibility or whose consent is not granted legal validity, and/or of a person other than the Data Subject.

6.2.1.2. Provided that the condition of being directly related to the conclusion, application, performance or termination of a contract is met, Personal Data belonging to the parties to the contract may be processed by the Company without the Explicit Consent of the Data Subjects. In this sense, personal data collected by the Company under all contracts necessary for the continuation of its activities, such as the service contracts, employment contracts, lease contracts and the like to which the Company is a party, are processed, stored, deleted and destroyed within the framework of this Policy without explicit consent.

6.2.1.3. Where the Processing of Personal Data is mandatory for the Company to fulfill its legal obligations, Personal Data may be processed by the Company without the Explicit Consent of the Data Subjects.

6.2.1.4. Personal Data that have been made public by the Data Subject may be processed by the Company without obtaining Explicit Consent.

6.2.1.5. Where processing Personal Data without obtaining Explicit Consent is the only possible way for the establishment, exercise or protection of a right, Personal Data may be processed by the Company without Explicit Consent, with the knowledge of the Data Controller Representative.

6.2.1.6. Provided that this does not harm the fundamental rights and freedoms of the Data Subjects, Personal Data may be processed by the Company without Explicit Consent where data processing is mandatory for the legitimate interests of the Company.


7) PROCESSING OF SPECIAL CATEGORIES OF PERSONAL DATA

7.1. Special Categories of Personal Data may be processed only where the Data Subject’s Explicit Consent exists or, with respect to Special Categories of Personal Data other than data relating to sexual life and personal health, where processing is expressly required by law.

7.2. Except for the special categories of personal data required to be obtained as a legal requirement due to the employment contracts to which it is a party or which are transferred to it, the Company does not collect, store or in any way process special categories of personal data.

7.3. Personal Data relating to health and sexual life may be processed without obtaining Explicit Consent only for the purposes of the protection of public health, preventive medicine, medical diagnosis, the conduct of treatment and care services, and the planning and management of healthcare services and their financing. Accordingly, until otherwise provided in the KVKK Regulations, personal health data and data relating to sexual life may be processed only within the scope of Explicit Consent or by the Company physician, who is under an obligation of confidentiality.

7.4. When Special Categories of Personal Data are Processed, the measures determined by the Board are taken.

7.5. In every case requiring the Processing of Special Categories of Personal Data, the Data Controller Representative is informed by the relevant employee.

7.6. Where it is not clear whether a piece of data constitutes Special Categories of Personal Data, the relevant department obtains the opinion of the Data Controller Representative.


8) STORAGE, DELETION, DESTRUCTION AND ANONYMIZATION OF PERSONAL DATA

8.1. When the legitimate purpose for the Processing of Personal Data ceases to exist, the relevant Personal Data are Deleted, Destroyed or Anonymized. Situations in which Personal Data must be Deleted, Destroyed or Anonymized are monitored by the Data Controller Representative.

8.2.     CVs submitted to the Company by any means are deleted within 1 year at the latest where no response is given.

8.3.   Personal data shared with the Company through the contact screen indicated at the imedc.com.tr address are deleted within three months at the latest.

8.4.    Personal data obtained by the Company through the employment contracts to which it is a party are destroyed upon the expiry of the retention obligation arising from the employment contract.

8.5. The Company does not store Personal Data merely in view of the possibility of their future use. The above provisions also apply to personal data that the company has not collected itself but that have been transferred to the company for similar purposes.


9) TRANSFER OF PERSONAL DATA AND PROCESSING OF PERSONAL DATA BY THIRD PARTIES

The Company may transfer Personal Data to a third natural or legal person (the “Contractor”) in compliance with the KVKK Regulations. In this case, the Company ensures that the third parties to whom it transfers Personal Data also comply with this Policy. In this context, the necessary protective provisions are added to the contracts concluded with the third party. The clause to be added to the contracts concluded with third parties to whom any Personal Data transfer is made is obtained from the Data Controller Representative. Each employee is obliged to follow the process set out in this Policy where a Personal Data transfer is to be made. Where the third party to whom Personal Data are transferred requests a change to the clause provided by the Data Controller Representative, the situation is immediately reported by the employee to the Data Controller Representative.

Personal data may be transferred, including but not limited to those listed below;

  • To suppliers,
  • To business partners and business contacts,
  • To legally authorized public institutions and organizations,
  • To legally authorized private-law persons,
  • To shareholders, in accordance with the principles and rules set out in this Policy.

9.1. Transfer of Personal Data to Third Parties Located in Türkiye

9.1.1. Personal Data may be transferred by the Company to third parties located in Türkiye, without Explicit Consent in the cases specified by the KVKK Provisions and, in cases where Explicit Consent is required, provided that the Data Subject’s Explicit Consent is obtained, for the purpose of the continuation of its activities or the fulfillment of its obligations.

9.1.2. The Company is responsible for ensuring that the transfer of Personal Data to third parties located in Türkiye complies with the KVKK Regulations.

9.2. Transfer of Personal Data to Third Parties Located Abroad

9.2.1. Due to its e-mail system, the Company may transfer personal data abroad within the framework of this Policy and the provisions of the legislation.

9.2.2. Personal Data may be transferred by the Company to third parties located abroad, without Explicit Consent in the cases specified by the KVKK Provisions and, in cases where Explicit Consent is required, provided that the Data Subject’s Explicit Consent is obtained.

9.2.3. Where Personal Data are transferred without obtaining Explicit Consent in accordance with the KVKK Regulations, one of the following conditions must additionally be present with respect to the foreign country to which they will be transferred:

9.2.3.1 The foreign country to which the Personal Data are transferred has the status of a country with adequate protection as determined by the Board (for the list, please follow the Board’s current list),

9.2.3.2 Where the foreign country to which the transfer will take place is not included in the Board’s list of safe countries, the Company and the Data Controllers in the relevant country provide a written undertaking that adequate protection will be ensured and obtain authorization from the Board.

9.2.4. The Company is responsible for ensuring that the transfer of Personal Data to third parties abroad complies with the KVKK Regulations.

9.2.5. The Company may receive services from service providers such as Google, Hotmail and Outlook for electronic communication purposes. In this context, the personal data that may be contained in the company’s electronic communications are stored on the servers of the service providers, and are retained, transferred and processed within the scope of the data protection policies of the companies concerned.


10) THE COMPANY’S OBLIGATION TO INFORM AND THE RIGHTS OF THE DATA SUBJECT

10.1. In accordance with Article 10 of KVKK, the Company informs Data Subjects regarding the Processing of Personal Data. In this context, the Company fulfills the Obligation to Inform through the Privacy Notice it prepares at the time Personal Data are obtained. The notification to be made to Data Subjects within the scope of the Obligation to Inform includes, in order, the following elements:

  • The identity of the Data Controller and of its representative, if any,
  • The purposes for which Personal Data will be processed,
  • To whom and for what purposes the processed Personal Data may be transferred,
  • The method and legal basis of collecting Personal Data,

The data subject may obtain information on the following matters by completing the Application Form and sending it to the info@imedc.com.tr address specified in the Company’s Privacy Notice;

  • To learn whether their personal data are processed,
  • To request information in this regard if their personal data have been processed,
  • To learn the purpose of the processing of their personal data and whether they are used in accordance with that purpose,
  • To know the third parties to whom their personal data are transferred, within the country or abroad,
  • To request the rectification of their personal data if they have been processed incompletely or inaccurately
  • To request the deletion or destruction of their personal data in the event that the reasons requiring their processing cease to exist,
  • To request that the rectification, deletion or destruction operations referred to above be notified to the third parties to whom their personal data have been transferred,
  • To object to the emergence of a result to their detriment through the analysis of the processed data exclusively by means of automated systems,
  • To request compensation for the damage in the event that they suffer damage due to the unlawful processing of their personal data

10.2. Where the Data Subject requests information regarding their personal data processed pursuant to the KVKK Provisions, the Company provides the necessary information within 30 (thirty) days at the latest after verifying the Data Subject’s identity. The Company reserves the right to reject the application, including but not limited to the grounds listed below;

  • The inability to verify that the person requesting information is the relevant data subject,
  • The processing of personal data for purposes such as research, planning and statistics, by being anonymized through official statistics,
  • The processing of personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that this does not violate the privacy of private life or personality rights and does not constitute a criminal offense,
  • The processing of personal data made public by the Personal Data Subject,
  • The application not being based on a justified ground,
  • The application containing a request contrary to the relevant legislation,
  • Non-compliance with the application procedure; in such cases, the application is rejected with the grounds for non-acceptance being explained.

10.3. Where the application is rejected, the response given to the application is found insufficient, or no response is given within the prescribed period; the applicant has the right to lodge a complaint with the KVKK Board within 30 (thirty) days from the date on which they learn of the response and, in any case, within 60 (sixty) days from the date of the application.

10.4. The fulfillment of the required Obligation to Inform before Personal Data are Processed is carried out by the employee following the relevant process and by the Data Controller Representative.

10.5. Where the Data Processor is a third party other than the Company, it must be undertaken by the third party, through a written contract concluded before Personal Data Processing begins, that the third party will act in accordance with the obligations set out above. In cases where third parties transfer Personal Data to the Company, the clause to be added to the contracts is obtained from the Data Controller Representative. Each employee is obliged to follow the process set out in this Policy where a Personal Data transfer is made to the Company by a third party. Where the third party transferring the Personal Data requests a change to the clause provided by the Data Controller Representative, the situation is immediately reported by the employee to the Data Controller Representative.


11) DATA MANAGEMENT, SECURITY AND MEASURES TAKEN FOR THE PROTECTION OF PERSONAL DATA

11.1. The Company appoints a Data Controller Representative in order to fulfill its obligations under the KVKK Regulations, to ensure and supervise the implementation of the KVKK Procedures necessary for the implementation of this Policy, and to make recommendations regarding their operation.

In order to ensure personal data security, the Company takes administrative and technical measures within the scope of the relevant guidance of the KVKK Authority on the subject.

11.1.1. Administrative Measures

  • The Company establishes Policies and procedures covering the entire data processing process, carries out periodic work to identify existing risks and threats, and ensures transparency in the data processing process.
  • Company employees are informed and trained on the protection of Personal Data and their processing in compliance with the law.
  • It reduces the personal data processed and stored as much as possible and, where possible, uses the data by anonymizing them.
  • It manages its relations with the natural and legal persons who process personal data pursuant to their job description within the Company or their business relationship with the Company. In this context, Company employees may access Personal Data only within the authority defined for them and in accordance with the relevant KVKK Procedure. Any access or processing carried out by an employee in excess of their authority is unlawful and constitutes grounds for termination of the employment contract for just cause. Every person to whom a Company device is allocated is responsible for the security of the devices allocated for their use. Every Company employee or person working within the Company is responsible for the security of the physical and electronic files/data within their own area of responsibility. If a department within the Company Processes Special Categories of Personal Data, that department is informed about the importance, security and confidentiality of the Personal Data they process, and the relevant department acts in accordance with the instructions of the Data Controller Representative. Access authorization for Special Categories of Personal Data is granted only to a limited number of employees, and their list and monitoring are maintained by the Data Controller Representative. Where there are security measures required, or additionally to be required, for the security of Personal Data under the KVKK Regulations, all employees are obliged to comply with the additional security measures and to ensure the continuity of these security measures. All employees involved in the relevant process are jointly and severally responsible, in proportion to their fault, for the protection of Personal Data in accordance with this Policy and the KVKK Procedures. Company employees have been informed that their obligations regarding the security and confidentiality of Personal Data will continue after the end of the employment relationship, and undertakings have been obtained from the relevant Company employees to comply with these rules.

11.1.2. Technical Measures

  • The Company ensures the cybersecurity of all personal data it processes and stores within its organization. IT personnel knowledgeable in technical matters relating to Personal Data Processing activities are employed.
  • The Company monitors the cybersecurity of all personal data it processes and stores within its organization, and carries out maintenance and audits at periodic intervals. Personal Data Processing activities are audited by the Company through technical systems, in accordance with technological possibilities and the cost of implementation.
  • The Company does not use a cloud storage system for the personal data it processes and stores within its organization.
  • The Company procures information technology systems and receives development and maintenance services from the companies providing this service. Software and hardware including virus protection systems and firewalls are installed at the Company, in line with technological developments, so that Personal Data are stored in secure environments. The Company has a security policy containing the technical measures for the protection of Personal Data.
  • Backup programs are used at the Company to prevent Personal Data from being lost or damaged, and an adequate level of security measures is taken.


12) TRAINING

The Company provides its employees with the necessary training on the protection of Personal Data within the scope of the Policy and the KVKK Regulations, and keeps records of such training.


13) AUDIT

The Company has the right to audit, regularly, at any time, ex officio and without any prior notice, whether all of the Company’s employees, departments and contractors act in compliance with this Policy and the KVKK Regulations, and carries out the necessary routine audits in this context. The Data Controller Representative establishes a KVKK Procedure for these audits and ensures the implementation of the said procedure.


14) BREACHES

14.1 Each employee of the Company reports to the Data Controller Representative any work, transaction or act that they consider to be contrary to the procedures and principles set out in the KVKK Regulations and under this Policy. In this context, the Data Controller Representative establishes an action plan for the relevant breach in accordance with this Policy and the KVKK Procedures.

14.2. As a result of the notifications made, the Data Controller Representative prepares the notification of the breach to be made to the Data Subject or to the Authority, taking into account the provisions of the legislation in force on the matter, in particular the KVKK Regulations. The Data Controller Representative conducts the correspondence and communication with the Authority.


15) PROCESS MANAGEMENT

Process management regarding the Protection of Personal Data within the Company is ensured by the employees, departments and the Data Controller Representative. In this context, the Data Controller Representative who will ensure the implementation of the Policy and manage the Personal Data Protection process is appointed by a decision of the Company management, and changes in this respect are likewise made in the same manner.


16) AMENDMENTS TO THE POLICY

The Company shares the updated Policy text with Data Subjects by e-mail, in a manner allowing the changes made to the Policy to be reviewed, and/or makes it available in a visible manner at the workplace and/or accessible through a website that may be established in the future.


17) LANGUAGE

This Policy may be prepared and published in both Turkish and English. In the event of any discrepancy, inconsistency, conflict or difference in interpretation between the Turkish and English texts, the Turkish text shall prevail and govern.


This Policy was approved on 1 June 2026 by the board of directors of İME DC Sağlık Ürünleri Sanayi Ve Ticaret Limited Şirketi and entered into force.