Skip to content
TCR Lojistik

PHONE
+90 532 295 88 25

EMAIL
info@tcrlojistik.com

ADDRESS
Yeşilbayır Mah., Hadımköy, 34555 Arnavutköy / Istanbul, Türkiye

Request a Quote

Policy on the Protection and Processing of Personal Data

This policy sets out our corporate approach to the protection of personal data and the principles and processes we apply.

LAST UPDATED: 28 SEPTEMBER 2026

01 Purpose and Scope

The purpose of this policy is to set out the principles and rules we follow in the personal data processing activities we carry out as data controller under the Personal Data Protection Law No. 6698 and the related legislation.

The policy covers the personal data of our customers, prospective customers, job applicants, the representatives of our suppliers and business partners, and natural persons who visit our website. Data processing relating to our employees is governed by separate internal rules.

DATA CONTROLLER / COMPANY DETAILS

Company
TCR Lojistik
Address
Yeşilbayır Mah., Hadımköy, 34555 Arnavutköy / Istanbul, Türkiye
Website
tcr.swisslounge.com.tr

02 Definitions

  • Personal data: Any information relating to an identified or identifiable natural person.
  • Data subject: The natural person whose personal data is processed.
  • Data controller: The person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data filing system.
  • Data processor: The person who processes personal data on behalf of the data controller, on the basis of the authority granted by the controller.
  • Explicit consent: Consent relating to a specific subject, based on information and expressed of free will.
  • Destruction: The deletion, destruction or anonymisation of personal data.

03 Our Processing Principles (KVKK Art. 4)

When processing personal data we follow these general principles:

  • Lawfulness and fairness,
  • Accuracy and, where necessary, being kept up to date,
  • Processing for specific, explicit and legitimate purposes,
  • Being relevant, limited and proportionate to the purposes of processing,
  • Retention for the period laid down in the relevant legislation or required for the purpose of processing.

We follow a data minimisation approach: our forms ask only for the fields needed to assess the request, and no unnecessary data is collected.

04 Conditions for Processing (KVKK Art. 5 and 6)

Personal data is not processed without the explicit consent of the data subject. However, where one of the conditions listed in the second paragraph of Article 5 of the KVKK exists, processing may take place without explicit consent. Chief among these conditions are: express provision in law; direct relation to the establishment or performance of a contract; fulfilment of the data controller's legal obligation; the establishment or protection of a right; and the legitimate interests of the data controller.

As a rule, special categories of personal data are not processed. Our processes are designed so that no special-category data needs to be collected.

05 Categories of Data Processed

The main categories of data processed in the course of our activities are:

  • Identity: name, surname.
  • Contact: email, telephone, address, company details.
  • Customer transactions: request and quote records, correspondence.
  • Transaction security: IP address, log records, cookie identifiers.
  • Professional experience: information provided in job applications.

The data processed through the website is listed item by item in the Privacy Notice.

06 Transfer Policy

Personal data is transferred only to the extent required by the purpose of processing and in line with the conditions in Articles 8 and 9 of the KVKK. Agreements containing confidentiality and data security obligations are concluded with the parties to whom data is transferred.

No transfer abroad is made unless the conditions required by the Law are met. In this context, third-party analytics and marketing tools are activated only after the visitor's explicit consent has been obtained.

07 Retention and Destruction

Personal data is kept for as long as required for the purpose for which it is processed and for the limitation periods laid down in legislation. Data whose retention period has expired is deleted, destroyed or anonymised as part of periodic destruction processes.

The retention periods for data collected through the website are stated in the relevant article of the Privacy Notice.

08 Technical and Organisational Measures

Technical measures: encrypted connection (HTTPS), access authorisation, two-step verification in the administration panel, irreversible storage of passwords, encryption of sensitive settings, security headers, form security (CSRF protection, bot filtering, rate limiting), regular backups and log monitoring.

Organisational measures: limiting access to data by job description, confidentiality undertakings, raising staff awareness, agreements with suppliers containing data security obligations, and regular review of processes.

09 Data Subject Applications

You can submit requests under Article 11 of the KVKK, in line with the Communiqué on the Procedures and Principles of Application to the Data Controller, through the following channels:

  • In writing, with a wet-ink signature, delivered in person or through a notary to the address given in the company details,
  • Through a registered electronic mail (KEP) address, a secure electronic signature or a mobile signature,
  • To the email address given in the company details, using an email address you have previously notified to us and which is registered in our systems.

Your application must contain your name and surname, your signature if the application is in writing, your Turkish ID number (passport number for foreign nationals), your address for service, your email address and telephone number if any, and the subject of your request.

Your request will be concluded free of charge as soon as possible according to its nature, and within thirty days at the latest. If the process involves an additional cost, the fee set out in the tariff determined by the Personal Data Protection Board may be charged.

10 Entry into Force and Updates

This policy enters into force on the date it is published on our website. It is reviewed in line with changes in legislation or updates to our processes; the current version is always published on this page.

Where there is a difference between this policy and the Privacy Notice, the Privacy Notice prevails with regard to data processing carried out through the website.