Personal Data Protection and Processing Policy

ROYAL PHARMA PHARMACEUTICALS, COSMETICS, FOOD AND INDUSTRY INC.

PERSONAL DATA PROTECTION AND PROCESSING POLICY

Prepared for ROYAL PHARMA PHARMACEUTICALS, COSMETICS, FOOD AND INDUSTRY INC. All rights reserved. It may not be reproduced, distributed, or used without permission.

1. INTRODUCTION

As the data controller, ROYAL PHARMA PHARMACEUTICALS, COSMETICS, FOOD AND INDUSTRY INC. attaches great importance to the protection of its registrants and employees, and to the safeguarding of the personal data of other natural persons with whom it is in a relationship. Ensuring that personal data are stored and protected in the manner prescribed by law and in accordance with applicable regulations is of critical importance; ROYAL PHARMA hereby demonstrates that it has adopted this as a corporate policy.

This Policy sets out the principles that must be complied with by ROYAL PHARMA while fulfilling its obligations regarding the storage of personal data under the Data Protection Regulations, and determines the procedures to be followed by the Company in relation to personal data processing. For the effective implementation of the Data Protection Regulations, ROYAL PHARMA makes the necessary arrangements for the storage and protection of personal data and establishes the required strategy and system accordingly.

As the data controller with respect to the personal data within its organization, ROYAL PHARMA declares that it will act in accordance with this Policy and the procedures based on this Policy.

2. PURPOSE AND SCOPE OF THE POLICY

The purpose of this Policy is to provide explanations regarding ROYAL PHARMA’s ongoing personal data processing activities in compliance with the Data Protection Regulations and the systems used for the protection of personal data, and to set out the governing principles for such activities. The aim of this Policy—together with other policies that regulate ROYAL PHARMA’s practices in this area—is to ensure that the relevant processes are managed and that personal data are processed and protected lawfully.

This Policy applies to personal data processed by ROYAL PHARMA relating primarily to Company Stakeholders, Company Authorized Persons, the stakeholders/authorized persons/employees of the Company’s Business Partners, Suppliers, Job Applicants, Visitors, Customers, Potential Customers, and Third Parties; and it is intended to be implemented by the aforementioned natural persons.

ROYAL PHARMA reserves the right to amend this Policy where required by the Data Protection Regulations or in cases where changes occur in the purposes of storing and transferring personal data and/or in collection methods.

3. IMPLEMENTATION OF THE POLICY AND DATA PROTECTION REGULATIONS

In the processes of recording and protecting personal data, the Data Protection Regulations shall primarily apply; in the event of any inconsistency between the Regulations and this Policy, the Data Protection Regulations shall prevail.

The update table is provided in Annex 1.

4. DEFINITIONS

Personal Data: Any information relating to an identified or identifiable natural person (within the scope of this Policy, the term “Personal Data” also includes “Special Categories of Personal Data” to the extent applicable).

Special Categories of Personal Data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data.

Processing of Personal Data: Any operation performed on data such as obtaining, recording, storing, retaining, altering, reorganizing, disclosing, transferring, taking over, making available, classifying, or preventing the use of personal data, wholly or partly by automatic means or, provided that it forms part of any data recording system, by non-automatic means.

DP Law (KVKK): The Personal Data Protection Law No. 6698.

Data Protection Regulations: The Personal Data Protection Law No. 6698 and the regulations, communiqués and related legislation on personal data protection; decisions of the Personal Data Protection Board; court decisions; applicable international agreements on data protection and any other legislation.

Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.

Data Processor: The natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the data controller.

Data Subject: The natural person whose personal data are processed by ROYAL PHARMA or on behalf of ROYAL PHARMA.

Third Party: Natural persons whose personal data are processed within the scope of the Policy, unless defined otherwise herein.

Data Recording System: The recording system in which personal data are processed by being structured according to specific criteria.

Explicit Consent: Consent that is specific to a particular subject, based on being informed, and expressed with free will.

Anonymization: Rendering personal data incapable of being associated with an identified or identifiable natural person in any way, even by matching with other data.

Application Form: The form prepared in accordance with Law No. 6698 and the Communiqué on the Procedures and Principles of Application to the Data Controller issued by the Personal Data Protection Authority, which contains the application to be made by the relevant person (Data Subject) to the data controller for exercising data subject rights.

Company Stakeholder: Natural persons who are stakeholders of the Company.

Natural Person Business Partner of the Company: Natural persons with whom the Company has any kind of business relationship.

Stakeholder, Authorized Person, Employee of Business Partners: All natural persons involved in any business relationship with the Company, including their stakeholders, participants and employees (such as members and registrants, where applicable).

Company Authorized Person: Members of the Company’s board of directors and other authorized natural persons.

Job Applicant: Natural persons who have applied for a job with the Company through any means or who have submitted their CV and related information for the Company’s review.

Customer: Natural persons who use or have used the products and services offered by the Company, whether or not they have any contractual relationship with the Company.

Potential Customer: Natural persons who request or show interest in using the Company’s products and services, or who may have such interest, assessed in accordance with commercial practices and good faith principles.

Visitor: Natural persons who enter the Company’s physical premises for various purposes or who visit the Company’s websites for any purpose.

Board: The Personal Data Protection Board.

Policy: The policy on the erasure and protection of personal data.

5. EFFECTIVE DATE OF THE POLICY

This Policy, which was prepared by the Company and became effective on 20/11/2025, is published on the Company’s website ( www.shayen.com ) and made available to Data Subjects and relevant persons.

6. PRINCIPLES TO BE APPLIED IN THE PROCESSING OF PERSONAL DATA

6.1. Processing personal data in compliance with the law and the principles of good faith

ROYAL PHARMA acts in accordance with the law and the principles of good faith while processing personal data; takes into account the rules of proportionality and necessity; and processes personal data to the extent appropriate for the characteristics of the processing activity.

6.2. Keeping personal data accurate and up to date

Keeping personal data accurate and up to date is necessary for the protection of the fundamental rights and freedoms of the relevant person. ROYAL PHARMA ensures that personal data are accurate and updated, and takes the necessary backup measures accordingly. In this context, where the person requests a change regarding their personal data and/or personal system, the relevant personal data are updated.

6.3. Processing personal data for specific, explicit, and legitimate purposes

ROYAL PHARMA determines its personal data processing purposes that are legitimate and lawful clearly and precisely; processes personal data in connection with and to the extent necessary for the commercial activities it carries out and the products and services it offers; and sets out the purposes for which personal data will be processed before the processing activity begins. Accordingly, the data subject is informed under the Data Protection Regulations and, where required, the explicit consent of the data subject is obtained.

6.4. Processing personal data in a manner that is relevant, limited, and proportionate to the purposes for which they are processed

ROYAL PHARMA processes personal data in a manner suitable for achieving the specified purposes and refrains from processing personal data that are not relevant to or not required for the realization of the purpose. In this context, no personal data processing activity is carried out to meet potential needs that may arise later. ROYAL PHARMA processes personal data only in the limited circumstances set out under the Data Protection Regulations (DP Law Article 5/2 and 6/3) or for the purposes within the scope of explicit consent obtained from the data subject (DP Law Article 5/1 and 6/2), and in compliance with the principle of proportionality.

6.5. Retaining personal data for the period stipulated in the Data Protection Regulations or required for the purpose for which they are processed

ROYAL PHARMA retains personal data only for the period stipulated in the Data Protection Regulations or required for the purpose for which they are processed. In this context, ROYAL PHARMA first determines whether a retention period is stipulated under the Data Protection Regulations; if such a period is stipulated, it acts in compliance with that period; if no period is stipulated, it retains personal data for the period necessary for the purpose for which they are processed. Upon expiry of the period or where the reasons requiring processing cease to exist, personal data are erased, destroyed, or anonymized in accordance with the obligations under the Data Protection Regulations, depending on the nature of the data and the purpose of use.

7. PROCESSING OF PERSONAL DATA AND SPECIAL CATEGORIES OF PERSONAL DATA BASED ON AND LIMITED TO THE CONDITIONS SET OUT IN THE DATA PROTECTION REGULATIONS

7.1. Processing of Personal Data

Pursuant to the Data Protection Regulations, ROYAL PHARMA processes personal data based on one or more of the conditions set out in Articles 5 and 6 of the DP Law; informs data subjects in accordance with Article 10 of the DP Law; and provides the necessary information upon the data subjects’ requests.

7.1.1. Explicit Consent

One of the conditions for processing personal data is the explicit consent of the data subject. In cases where explicit consent must be obtained after the fulfillment of the obligation to inform, personal data are processed if the data subject provides explicit consent. Before obtaining explicit consent within the scope of the obligation to inform, the rights of the data subject are communicated to them.

7.1.2. Processing of Personal Data Without Obtaining Explicit Consent

Where the Data Protection Regulations allow processing without obtaining explicit consent (DP Law Article 5/2 and 6/3), ROYAL PHARMA may process personal data without obtaining the explicit consent of the data subject. In such case, the Company processes personal data within the limits set by the Data Protection Regulations. The legal ground for a processing activity may be one of the conditions listed below, or more than one of these conditions may constitute the legal ground for the same processing activity.

7.1.2.1. Where it is explicitly stipulated in the law, the personal data of the data subject may be processed lawfully.

7.1.2.2. Personal data may be processed by ROYAL PHARMA without explicit consent where it is mandatory for the protection of the life or physical integrity of the data subject or another person, and where the data subject is unable to declare consent due to factual impossibility or where legal validity is not granted to their consent.

7.1.2.3. Provided that it is directly related to the establishment, performance, fulfillment, or termination of a contract, personal data of the parties to the contract may be processed by ROYAL PHARMA without their explicit consent.

7.1.2.4. As the data controller, ROYAL PHARMA may process personal data without explicit consent where processing is mandatory for the fulfillment of its legal obligations.

7.1.2.5. Personal data that have been made public by the data subject may be processed by ROYAL PHARMA without explicit consent.

7.1.2.6. Personal data may be processed without explicit consent if processing is the only possible way to establish, exercise, or protect a right.

7.1.2.7. Provided that it does not harm the fundamental rights and freedoms of the data subject, personal data may be processed by ROYAL PHARMA without explicit consent where processing is mandatory for ROYAL PHARMA’s legitimate interests.

7.2. Processing of Special Categories of Personal Data

ROYAL PHARMA acts in accordance with the provisions stipulated for the processing of special categories of personal data under Article 6 of the DP Law. Pursuant to Article 6 of the DP Law, special categories of personal data may be processed without the explicit consent of the data subject only in the cases listed below, provided that adequate measures determined by the Board are taken:

7.2.1. Special categories of personal data other than those relating to health and sexual life, where stipulated by law;

7.2.2. Special categories of personal data relating to health and sexual life, only for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of healthcare services and financing, by persons under an obligation of confidentiality or by authorized institutions and organizations.

7.2.3. In this context, ROYAL PHARMA evaluates whether its personal data processing activities fall within the scope of these conditions and discontinues any personal data processing activity that cannot be based on one of these conditions. While processing special categories of personal data, the measures determined by the Board are taken.

7.2.4. Your special categories of personal data are additionally protected under a separate policy prepared in accordance with the Board’s decisions.

8. CLASSIFICATION OF PERSONAL DATA PROCESSED BY ROYAL PHARMA

8.1. Within ROYAL PHARMA, personal data in the categories listed below are processed—without being limited to these categories—based on one or more of the conditions for processing personal data set out in Article 5 of the DP Law and limited thereto, in line with ROYAL PHARMA’s legitimate and lawful personal data processing purposes, by complying with the general principles in the DP Law (including the principles stated in Article 4 regarding personal data processing) and all obligations set out in the DP Law, and by informing the relevant persons pursuant to Article 10 of the DP Law. Which data subject groups the personal data processed in these categories relate to is also specified in Article 8.2 of this Policy.

PERSONAL DATA

CLASSIFICATION

DESCRIPTION OF PERSONAL DATA CLASSIFICATION

Identity Data

Data that clearly belong to an identified or identifiable natural person; processed wholly or partly by automatic means or, provided that they form part of a data recording system, by non-automatic means; containing information regarding the person’s identity, such as name-surname, Turkish ID number, date of birth, social security number, tax identification number.

Contact Data

Data that clearly belong to an identified or identifiable natural person; processed wholly or partly by automatic means or, provided that they form part of a data recording system, by non-automatic means; such as phone number, home address, workplace address, personal email address, computer number, system username, fax number, IP address, access URL (web), etc.

Employment/Personnel Data

Data that clearly belong to an identified or identifiable natural person; processed wholly or partly by automatic means or, provided that they form part of a data recording system, by non-automatic means; any personal data processed to obtain information that forms the basis for establishing the employment rights of natural persons in an employment relationship with ROYAL PHARMA (CV information, education information, salary and bonus information, promotion/warning information, start date, job position(s), reporting manager name, work assignments, working hours, performance information, discharge document, annual leave information).

Financial Data

Data that clearly belong to an identified or identifiable natural person; processed wholly or partly by automatic means or, provided that they form part of a data recording system, by non-automatic means; personal data relating to information, documents and records indicating financial outcomes created depending on the type of legal relationship established by ROYAL PHARMA with the data subject, such as bank information, company credit card data (if any), employee expenses, salary information, social security data, credit card information, e-invoice information.

Visual and Audio Records

The data group containing visual and audio data belonging to a person (photograph, camera recording).

Location Data

Data that clearly belong to an identified or identifiable natural person; processed wholly or partly by automatic means or, provided that they form part of a data recording system, by non-automatic means; information that identifies the location of the data subject within the scope of operations carried out by ROYAL PHARMA units, during the use of ROYAL PHARMA products and services, or while employees of institutions we cooperate with use ROYAL PHARMA vehicles; such as GPS location, travel data, etc.

Family Members and Relatives Data

Data that clearly belong to an identified or identifiable natural person; processed wholly or partly by automatic means or, provided that they form part of a data recording system, by non-automatic means; contact information of the data subject’s family members (e.g., spouse, mother, father, child) and relatives, processed within the scope of operations carried out by ROYAL PHARMA units, in relation to ROYAL PHARMA’s products and services, or for the purpose of protecting the legal and other interests of ROYAL PHARMA and/or the data subject.

Other Data

Professional vehicle information, driver’s license class (where a vehicle is allocated), usage information for work phone allowance, department information of the employee (such as retail, wholesale, chain, e-commerce), targeted sales figures, emergency information form data, office entry-exit information, psychotechnical test data, personality inventory test information, knowledge test data, personal data relating to records and documents obtained during entry to a physical premise and during presence within the physical premise, camera recordings.


8.2. The table below details the categories of data subjects and the types of personal data processed for persons within these categories.

Employees

Identity Data: Name - surname, Turkish ID number, date of birth, social security number;

Contact Data: Mobile phone number, home address, personal email address, computer number, system username, IP address, access URL (web);

Employment/Personnel Data: CV information, education information, salary and bonus information, promotion/warning information, start date, job position(s), work assignments, working hours, performance information, discharge document, annual leave information;

Financial: Bank information, employee expenses, social security data, salary information, company credit card data (if any);

Visual and Audio Records: Employee photograph;

Location Data: GPS location, travel data;

Family Members and Relatives Data: Family members’ and relatives’ contact information, spouse and child status;

Other Data: Professional vehicle information, driver’s license class (where a vehicle is allocated), usage information for work phone allowance, office entry-exit information, personal data relating to records and documents obtained during entry to a physical premise and during presence within the physical premise, camera recordings, emergency information form data.

Sales Team

Identity: Name-surname;

Employment/Personnel: Performance information;

Location Data: GPS location, travel data;

Other Data: Information about the sales cluster the employee is part of (retail, wholesale, chain, e-commerce, etc.), targeted sales figures and realization rate, past years’ performance and comparison, office entry-exit information, personal data relating to records and documents obtained during entry to a physical premise and during presence within the physical premise, camera recordings, emergency information form data.

Former Employees

Identity: Name - surname, Turkish ID number, date of birth, social security number;

Contact: Home address, personal email address;

Employment/Personnel: CV information, education information, salary and bonus information, promotion/warning information, start date, job position(s), work assignments, working hours, performance information, discharge document, annual leave information, separation document;

Financial: Bank information, social security data, salary information, company credit card data (if any);

Visual and Audio Records: Employee photograph.

Employees’ Family Members

Identity: Name – surname.

Job Applicants

Identity Data: Name – surname

Contact Data: Mobile phone number, email address

Employment/Personnel Data: CV information

Visual and Audio Records: Applicant photograph (if included in the CV)

Other Data: Psychotechnical test data, personality inventory test information, knowledge test data

Natural Person Dealer

Identity: Name-surname, Turkish ID number, tax identification number;

Contact: Phone number, workplace address.

Legal Entity Dealer

Identity: Name-surname, Turkish ID number, tax identification number;

Contact: Phone number, address.

Guarantors of the Dealer

Identity: Name-surname, Turkish ID number;

Contact: Phone number, home address;

Family Members and Relatives Data: Name and surname of the guarantor’s spouse (where the spouse’s consent is required for the guarantee agreement).

Natural Person Dealer Applicant

Identity: Name-surname, Turkish ID number, tax identification number;

Contact: Phone number, workplace address.

Legal Entity Dealer Applicant

Identity: Name-surname, Turkish ID number, tax identification number;

Contact: Phone number, address.

Guarantors of the Dealer Applicant

Identity: Name - surname, Turkish ID number;

Contact: Phone number, home address;

Family Members and Relatives Data: Name and surname of the guarantor’s spouse (where the spouse’s consent is required for the guarantee agreement).

Natural Person Authorized Service

Identity: Name – surname, tax identification number;

Contact: Phone number, address;

Visual and Audio Records: Photograph of the service premises.

Legal Entity Authorized Service

Identity: Name - surname, Turkish ID number, tax identification number;

Contact: Phone number, address.

Consumer / Customer

Identity: Name - surname, date of birth, gender;

Contact: Mobile phone number, home address, email address;

Financial: Credit card information.


9. ERASURE, DESTRUCTION AND ANONYMIZATION OF PERSONAL DATA

9.1. Pursuant to Article 7 of the DP Law, although it may have been processed in accordance with applicable law, where the reasons requiring processing cease to exist, ROYAL PHARMA shall erase, destroy, or anonymize personal data either ex officio or upon the request of the data subject. ROYAL PHARMA has established a policy in accordance with the DP Law and the Regulation on the Erasure, Destruction or Anonymization of Personal Data, and carries out disposal depending on the nature of the data. In this scope, ROYAL PHARMA has determined periodic disposal periods and has created a schedule according to which periodic disposal will be carried out at various intervals as of the start of the obligation.

9.2. Techniques for Erasure, Destruction and Anonymization of Personal Data

9.2.1. The erasure or destruction techniques most commonly used by ROYAL PHARMA are listed below:

9.2.1.1. Physical Destruction: Personal data may also be processed by non-automatic means, provided that it forms part of a data recording system. In erasing/destroying such data, a method is applied whereby the personal data are physically destroyed in a manner that prevents any later use.

9.2.1.2. Secure Deletion from Software: For data processed wholly or partly by automatic means and stored in digital environments, methods are used to delete the data from the relevant software in a manner that prevents recovery.

9.2.1.3. Secure Deletion by an Expert: In some cases, ROYAL PHARMA may engage an expert to erase personal data on its behalf. In such case, personal data are securely erased/destroyed by the expert in a manner that prevents recovery.

9.2.2. The anonymization techniques most commonly used by ROYAL PHARMA are listed below:

9.2.2.1. Personal data are anonymized by removing the main identifying information from the dataset through data masking.

9.2.2.2. Through aggregation, multiple data are aggregated and personal data are rendered incapable of being associated with any person.

9.2.2.3. Through data derivation, more general content is created from the content of personal data and personal data are rendered incapable of being associated with any person.

9.2.2.4. Through data shuffling, the link between values and persons is severed by mixing values within the personal data set.

In accordance with Article 8 of the DP Law, anonymized personal data may be processed for purposes such as research, planning and statistics. Such processing falls outside the scope of the DP Law and explicit consent of the data subject will not be sought.

10. TRANSFER OF PERSONAL DATA AND PROCESSING BY THIRD PARTIES

10.1. Conditions for the Transfer of Personal Data

ROYAL PHARMA may transfer Personal Data and Special Categories of Personal Data of Data Subjects to third parties in accordance with the Law by establishing the necessary confidentiality conditions and taking security measures, in line with its purposes of processing Personal Data. ROYAL PHARMA acts in accordance with the arrangements stipulated in the Law during the transfer of Personal Data. In this context, ROYAL PHARMA may transfer Personal Data to third parties within the scope of one or more of the personal data processing conditions set out in Article 5 of the Law and limited thereto, for its legitimate and lawful Personal Data processing purposes, where:

      1. The data subject has explicit consent; or
      2. There is an explicit provision in the law regarding the transfer of Personal Data;
      3. The transfer is mandatory for the protection of the life or physical integrity of the data subject or another person, and the data subject is unable to declare consent due to factual impossibility or where legal validity is not granted to their consent;
      4. The transfer is necessary for the establishment or performance of a contract, provided that it is directly related thereto and concerns personal data of the parties to the contract;
      5. ROYAL PHARMA must transfer Personal Data to fulfill its legal obligations;
      6. Personal Data have been made public by the data subject;
      7. The transfer is mandatory for the establishment, exercise, or protection of a right;
      8. Provided that it does not harm the fundamental rights and freedoms of the data subject, the transfer is mandatory for ROYAL PHARMA’s legitimate interests; in which case the data may be transferred without seeking explicit consent.

10.2. Conditions for the Transfer of Special Categories of Personal Data

By exercising due care, taking the necessary security measures and the adequate measures prescribed by the Data Protection Board; the Company may transfer the Data Subject’s Special Categories of Personal Data to third parties in the following cases, in line with its legitimate and lawful Personal Data processing purposes:

10.2.1. Where the Data Subject has explicit consent; or

10.2.2. Where the following conditions exist, without seeking the Data Subject’s explicit consent:

10.2.2.1. Special Categories of Personal Data other than those relating to health and sexual life (race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, criminal convictions and security measures, biometric and genetic data), where stipulated in the law;

10.2.2.2. Special Categories of Personal Data relating to health and sexual life, only for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of healthcare services and financing, by persons under an obligation of confidentiality or by authorized institutions and organizations.

10.3. Conditions for Cross-Border Transfer of Personal Data

ROYAL PHARMA may transfer Personal Data and Special Categories of Personal Data of Data Subjects to third parties abroad by taking the necessary security measures, in line with its purposes of processing Personal Data. For such transfer, the explicit consent of the relevant person is primarily required under the legislation. If explicit consent is not obtained, Personal Data may be transferred by ROYAL PHARMA to foreign countries declared by the Board to have adequate protection, or—where adequate protection is not available—to foreign countries where the data controllers in Türkiye and in the relevant foreign country undertake in writing to provide adequate protection and where the Board has granted permission.

11. DATA SUBJECT RIGHTS AND EXERCISING THESE RIGHTS

11.1. The rights of the data subject are as follows:

11.1.1. To learn whether personal data are processed;

11.1.2. To request information if personal data have been processed;

11.1.3. To learn the purpose of processing personal data and whether they are used in accordance with their purpose;

11.1.4. To know the third parties to whom personal data are transferred domestically or abroad;

11.1.5. To request correction of personal data if they are processed incompletely or inaccurately and to request notification of the transaction carried out within this scope to the third parties to whom personal data have been transferred;

11.1.6. To request the erasure or destruction of personal data in the event that the reasons requiring processing cease to exist although they have been processed in accordance with the Data Protection Regulations, and to request notification of the transaction carried out within this scope to the third parties to whom personal data have been transferred;

11.1.7. To object to a result to the detriment of the person that occurs by analyzing the processed data exclusively through automated systems;

11.1.8. To request compensation for damages in the event that personal data are processed unlawfully.

11.2. ROYAL PHARMA informs the data subject of their rights in accordance with Article 10 of the DP Law and guides the data subject on how to exercise these rights regulated under Article 11 of the DP Law.

11.3. ROYAL PHARMA carries out the necessary channels, internal workflow, administrative and technical arrangements in accordance with Article 13 of the DP Law for the evaluation of data subjects’ requests and providing the necessary information to data subjects.

11.4. Cases where the data subject may not assert their rights

Since the following cases are excluded from the scope of the DP Law pursuant to Article 28, the data subject may not assert the rights listed in Article 11.1 regarding these matters:

11.4.1. Processing personal data by anonymizing them for purposes such as research, planning, and statistics as official statistics;

11.4.2. Processing personal data for artistic, historical, literary or scientific purposes or within the scope of freedom of expression, provided that it does not violate national defense, national security, public security, public order, economic security, the privacy of private life or personal rights, and does not constitute an offense;

11.4.3. Processing personal data within the scope of preventive, protective and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public security, public order or economic security;

11.4.4. Processing personal data by judicial authorities or enforcement offices in relation to investigation, prosecution, trial or execution proceedings.

Pursuant to Article 28/2 of the DP Law, in the following cases, the data subject may not assert the other rights listed in Article 11.1, except for the right to request compensation for damages:

11.4.5. Processing personal data is necessary for preventing a crime or for a criminal investigation;

11.4.6. Processing personal data that have been made public by the data subject;

11.4.7. Processing personal data is necessary for carrying out supervision or regulatory duties and disciplinary investigation or prosecution by authorized public institutions and organizations and professional organizations having the status of a public institution, based on the authority granted by law;

11.4.8. Processing personal data is necessary for protecting the economic and financial interests of the State in relation to budget, tax and financial matters.

11.5. Exercising data subject rights

11.5.1. The data subject may submit their requests regarding the rights set out in this Policy by filling in and signing the application form, together with information and documents that will identify them, through the methods specified below or through other methods determined by the Board, free of charge, to ROYAL PHARMA. In addition, as the data subject, you are required to attach information and documents relating to your request to your application.

As data subjects, you may submit your rights and requests regarding the implementation of the Law by obtaining the application form created by ROYAL PHARMA from our website or requesting it in person; by delivering the wet-signed copy in person; or by sending it via notary to the address “Beylikdüzü OSB, Mustafa Kurtoğlu Cd. Bakır ve Pirinçciler San. Sit No:31, 34524 Beylikdüzü/İstanbul”; or

By signing with a “secure electronic signature” defined under the Electronic Signature Law No. 5070 and sending it to royalpharmailac@hs01.kep.tr; or by contacting us via our email address: info@shayenparis.com. If you submit your requests to our Company, your request will be concluded free of charge within a maximum of 30 days depending on the nature of the request. If a written response is provided, no fee will be charged for up to the first 10 (ten) pages pursuant to the Communiqué on Procedures and Principles of Application to the Data Controller, and a processing fee of TRY 1 will be charged for each page exceeding 10 (ten) pages. If the response is provided on a recording medium such as a CD or flash drive, the cost of the recording medium will be charged to you.

For the application listed above to be accepted as a valid application, pursuant to the Communiqué on Procedures and Principles of Application to the Data Controller, the application must include:

11.5.1.1. Name, surname and, if the application is in writing, signature;

11.5.1.2. For Turkish citizens, Turkish ID number; for foreigners, nationality, passport number or, if any, identification number;

11.5.1.3. Residence or workplace address for service of notice;

11.5.1.4. If any, email address for notification, telephone and fax number;

11.5.1.5. Subject matter of the request;

These items must be stated. Otherwise, the application will not be considered a valid application. For applications made without filling in the application form, the above items must be fully provided to ROYAL PHARMA.

For third parties to apply on behalf of data subjects, a special power of attorney issued via notary in the name of the person who will apply must be provided by the data subject.

11.5.2. Where the data subject submits their request to ROYAL PHARMA, ROYAL PHARMA will finalize the request within thirty days at the latest, depending on the nature of the request. If the requested transaction requires an additional cost, a fee may be charged in accordance with the tariff determined by the Board. If the application is due to ROYAL PHARMA’s fault, the fee collected shall be refunded to the relevant person. ROYAL PHARMA may request information from the applicant in order to verify whether the applicant is the data subject. ROYAL PHARMA may ask the data subject questions regarding their application to clarify the matters included in the application. ROYAL PHARMA accepts the request or rejects it by explaining the reasons, and notifies the relevant person in writing or electronically. If the request is accepted, ROYAL PHARMA fulfills the requirements.

11.5.3. ROYAL PHARMA may reject the application of the applicant by explaining the reasons in the cases listed in Article 11.4 and/or in the cases below.

11.5.3.1. Where the data subject’s request may prevent the rights and freedoms of other persons;

11.5.3.2. Where the request requires disproportionate effort;

11.5.3.3. Where the requested information is publicly available;

11.5.3.4. Where the processing of the relevant data is necessary due to the nature of the service received.

11.5.4. The data subject’s right to lodge a complaint with the Board

Pursuant to Article 14 of the DP Law, in cases where the application is rejected, the response is found insufficient, or no response is provided in due time, the data subject may lodge a complaint with the Board within thirty days from the date they learn of ROYAL PHARMA’s response, and in any case within sixty days from the date of application.

12. PURPOSES OF PROCESSING AND TRANSFER OF PERSONAL DATA, AND RECIPIENTS OF TRANSFER

12.1. Purposes of Processing and Transfer of Personal Data

Personal Data are processed within the scope of the personal data processing conditions set out in Articles 5 and 6 of the Law, limited to the following purposes in accordance with the law and the purpose of the Law, for the Company’s:

12.1.1. -Planning and implementation of human resources policies in the best possible manner, 

-Accurate planning, execution and management of commercial partnerships and strategies,

-Ensuring the legal, commercial and physical security of itself and its business partners,

-Ensuring corporate operations and planning and execution of management and communication activities,

-Enabling Data Subjects to benefit from its products and services in the best possible manner and offering them by customizing according to their demands, needs and preferences,  

-Ensuring data security at the highest level,

-Creating databases,

-Improving the services offered on the website and eliminating errors on the site,

-Contacting Data Subjects who submit requests and complaints and ensuring request and complaint management,

-Managing relationships with business partners or suppliers,

-Carrying out personnel recruitment processes,

-Planning and execution of audit activities to ensure that Company activities are carried out in accordance with relevant legislation,

-Supporting the planning and execution of fringe benefits and interests to be provided to senior executives,

-Providing support for carrying out company and partnership law transactions,

-Execution/follow-up of financial reporting and risk management processes,

-Execution/follow-up of Company legal affairs,

-Carrying out activities aimed at protecting reputation,

-Providing information to authorized institutions as required by legislation,

-Creating and tracking visitor records

If the processing activity carried out for the aforementioned purposes does not meet any of the conditions envisaged under the Law, your explicit consent is obtained by the Company for the relevant processing process.

12.2. Recipients to Whom Personal Data May Be Transferred 

Personal Data may be shared with our suppliers, business and solution partners, banks, and other third parties who perform technical, logistics and similar operations on our behalf, to ensure that the service provided to you is complete and flawless, and only to the extent compatible with the nature of the service. These third parties are limited to those who must access the relevant information in order to provide the relevant services completely and flawlessly.

In addition, Personal Data may also be transferred where it is mandatory for the Company to fulfill its legal obligations, where it is explicitly stipulated in laws, or where there is a lawful judicial/administrative order, limited only to the relevant person or institution.

13. MATTERS REGARDING THE PROTECTION OF PERSONAL DATA

In accordance with Article 12 of the Law, the Company takes the necessary technical and administrative measures to ensure an adequate level of security to prevent unlawful processing of Personal Data, to prevent unlawful access to data, and to ensure the safeguarding of data; and carries out or commissions the necessary audits within this scope.

13.1. Ensuring the Security of Personal Data

13.1.1. Technical and Administrative Measures Taken to Ensure Lawful Processing of Personal Data

The Company takes technical and administrative measures—considering technological possibilities and implementation costs—to ensure the lawful processing of Personal Data.

13.1.1.1. Technical Measures Taken to Ensure Lawful Processing of Personal Data

The main technical measures taken by the Company to ensure the lawful processing of Personal Data are listed below:

-Personal data processing activities carried out within the Company are supervised through established technical systems.

-Technical measures taken are periodically reported to the relevant persons as required by the internal audit mechanism.

-Personnel knowledgeable in technical matters are employed.

13.1.1.2. Administrative Measures Taken to Ensure Lawful Processing of Personal Data

The main administrative measures taken by the Company to ensure the lawful processing of Personal Data are listed below:

-Employees are informed and trained on personal data protection law and lawful processing of personal data.

-All activities carried out by the Company are analyzed in detail on the basis of each business unit, and personal data processing activities are identified specifically for each unit’s activities as a result of this analysis.

-The requirements to be fulfilled to ensure compliance of each business unit’s personal data processing activities with the processing conditions required by the Law are determined specifically for each unit and for the detailed activities carried out.

-Awareness is created and implementation rules are set for each business unit to ensure legal compliance requirements; necessary administrative measures are implemented through internal policies and trainings to supervise these matters and ensure continuity of implementation.

-Contracts and documents governing the legal relationship between the Company and employees include provisions imposing obligations not to process, disclose or use Personal Data except for the Company’s instructions and legal exceptions; employees’ awareness is raised, and audits are carried out to fulfill obligations arising from the Law.

13.1.2. Technical and Administrative Measures Taken to Prevent Unlawful Access to Personal Data

To prevent the negligent or unauthorized disclosure, access, transfer or any other form of unlawful access to Personal Data, the Company takes technical and administrative measures, considering the nature of the data to be protected, technological possibilities and implementation costs.

13.1.2.1. Technical Measures Taken to Prevent Unlawful Access to Personal Data 

The main technical measures taken by the Company to prevent unlawful access to Personal Data are listed below:

-Technical measures are taken in line with technological developments; measures are periodically updated and renewed.

-Access and authorization technical solutions are implemented in accordance with the legal compliance requirements determined per business unit.

-Access authorities are restricted and regularly reviewed.

-Technical measures are periodically reported to the relevant persons as required by the internal audit mechanism; matters posing risk are reassessed and the necessary technological solutions are produced.

-Software and hardware including antivirus systems and firewalls are installed.

-Personnel knowledgeable in technical matters are employed.

-Regular security scans are conducted to identify security vulnerabilities in applications where Personal Data are collected; detected vulnerabilities are remedied.

13.1.2.2. Administrative Measures Taken to Prevent Unlawful Access to Personal Data  

The main administrative measures taken by the Company to prevent unlawful access to Personal Data are listed below:

-Employees are trained on technical measures to be taken to prevent unlawful access to Personal Data.

-Access and authorization processes for Personal Data within the Company are designed and implemented in accordance with legal compliance requirements on a business unit basis.

-Employees are informed that they may not disclose Personal Data they have learned to others in violation of the Law, and may not use them beyond the purpose of processing; and that this obligation continues after they leave their duties; the necessary undertakings are obtained accordingly.

-Agreements with parties to whom Personal Data are lawfully transferred include provisions requiring such parties to take the necessary security measures for the protection of Personal Data and to ensure compliance with these measures within their organizations.

13.1.3. Storing Personal Data in Secure Environments

The Company takes the necessary technical and administrative measures, considering technological possibilities and implementation costs, to ensure that Personal Data are stored in secure environments and to prevent them from being destroyed, lost, or altered for unlawful purposes.

13.1.3.1. Technical Measures Taken to Store Personal Data in Secure Environments

The main technical measures taken by the Company to store Personal Data in secure environments are listed below:

-Systems appropriate to technological developments are used to store Personal Data in secure environments.

-Expert technical personnel are employed.

-Technical security systems are established for storage areas; security tests and research are conducted to identify security vulnerabilities on IT systems; identified existing or potential risks are remedied. Technical measures taken are periodically reported to the relevant persons as required by the internal audit mechanism.

-Backup programs are used lawfully to ensure secure storage of Personal Data.

-Access to environments where Personal Data are stored is restricted so that only authorized persons can access such data, limited to the purpose of storage; access to data storage areas is logged and inappropriate access or attempts are notified to relevant persons instantly.

13.1.3.2. Administrative Measures Taken to Store Personal Data in Secure Environments

The main administrative measures taken by the Company to store Personal Data in secure environments are listed below:

-Employees are trained on ensuring the secure storage of Personal Data.

-Legal and technical consultancy services are obtained to follow developments in information security, privacy and personal data protection and to take the necessary actions.

-Where a service is obtained from outside for technical necessities regarding the storage of Personal Data, agreements with the relevant firms to whom Personal Data are lawfully transferred include provisions requiring such parties to take the necessary security measures for the protection of Personal Data and to ensure compliance with these measures within their organizations.

13.1.4. Audit of Measures Taken for the Protection of Personal Data

In accordance with Article 12 of the Law, the Company carries out or commissions the necessary audits within its organization. Audit results are reported to the relevant department within the scope of the Company’s internal functioning, and necessary activities are carried out to improve the measures taken.

13.1.5. Measures to Be Taken in Case of Unauthorized Disclosure of Personal Data

In accordance with Article 12 of the Law, the Company operates a system to ensure that if Personal Data processed in accordance with the Law are obtained by others through unlawful means, this situation is notified to the relevant Data Subject and the Data Protection Board as soon as possible. Where deemed necessary by the Board, this situation may be announced on the Board’s website or by another method.

13.2. Safeguarding the Legal Rights of Data Subjects

The Company protects all legal rights of Data Subjects under this Policy and the Law and takes all necessary measures to ensure the protection of these rights. Further details regarding Data Subjects’ rights are provided in the relevant section of this Policy.

13.3. Protection of Special Categories of Personal Data

The Law attaches special importance to Special Categories of Personal Data due to the risk that unlawful processing may cause the person to suffer harm and/or discrimination. Such data include race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data. Special Categories of Personal Data are classified by the Law as “special categories,” and the Company shows utmost sensitivity in protecting such Special Categories of Personal Data processed lawfully. In this scope, the technical and administrative measures taken by the Company for the protection of personal data are also applied and, where necessary, further enhanced for Special Categories of Personal Data, and the necessary audits are ensured within the Company.

Annex 1. Update Table

Changes made to this Policy are set out in the table below.

UPDATE DATE

SCOPE OF AMENDMENTS