FORD OTOMOTİV SANAYİ ANONİM ŞİRKETİ
PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA WITHIN THE SCOPE OF THE CAPI PORTAL

("Privacy Notice")

Ford Otomotiv Sanayi Anonim Şirketi ("Ford Otosan" or "Company") attributes great importance to the secure and transparent processing of your personal data in conformity with the law and good faith. This Privacy Notice ("Notice") is prepared for the objective of explaining how and for which purposes data relating to you will be processed and how you can manage your rights.

Below, you will find an explanation of general principles for the processing of personal data by Ford Otosan, the purposes for which your personal data is processed and the rights that you have concerning your personal data under the CAPI Portal ("CAPI Portal" or "Portal") and related services ("Services") offered by Ford Otosan.

This Privacy Notice has been executed in both English and the applicable local languages. In the event of discrepancy between the English and the applicable local language, the English text shall prevail.


General Information

While, being an entity located in the Republic of Turkey, Ford Otosan shall comply with the provisions of the Turkish Law No. 6698 on the Protection of Personal Data ("Law No. 6698"), the European General Data Protection Regulation ("GDPR") and applicable national data protection law as far as these laws apply for the processing of personal data by Ford Otosan.

Data Controller:

Ford Otomotiv Sanayi Anonim Şirketi
Akpınar Mahallesi, Hasan Basri Cad. No:2, 34885 Sancaktepe, İstanbul, Turkey
Company Registry No: 73232

Representative for the EU:

Ford Otosan Romania S.R.L.
Henry Ford 1863-1947 Street, no. 29, Dolj, Craiova, Romania
gdprrep@ford.com.tr

Data Protection Officer of Ford Otosan:

You may approach the Data Protection Officer at dpo@ford.com.tr or by addressing a letter to the "Data Protection Officer" at the address of the Data Controller.


What is Personal Data?

"Personal Data" means any information relating to an identified or identifiable individual (a data subject) in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual.

How do we collect Personal Data?

All personal data processed for the purposes set forth in this Privacy Notice are obtained by our Company (i) through your provision of such data verbally and/or in writing, in physical and/or electronic form, in person, and (ii) via the CAPI Portal.

Which Personal Data do we collect?

As a CAPI Portal registered user, your identity data (name, surname, ID number), contact data (telephone number, e-mail address), company information (company/trade name, title, tax identification number), application information (application credentials, application key and expiry date), system security data (log records, IP address), as well as your application and consent information are processed for the purposes of carrying out the CAPI Portal membership activities.

If you are not a registered CAPI Portal user but only a user who provides consent for the sharing of vehicle data, your identity data (name, surname), contact data (e-mail address, telephone number), information that may be associated with your vehicle, and application and consent information are processed.

We do not process special categories of Personal Data, as well as any biometric data.

For Which Purposes Is Your Personal Data Processed?

The purpose of processing Personal Data is to ensure functioning and development of CAPI Portal. This purpose implies the following cases of Personal Data use:

  • Within the scope of carrying out activities related to the CAPI Portal; ensuring secure access to the CAPI Portal and identification of the user within the CAPI Portal, carrying out CAPI Portal membership procedures and creating/completing the user profile, verifying that the products and services are provided to the correct person, providing all services committed through the CAPI Portal and online, managing data sharing consent processes and ensuring the secure execution of data sharing, receiving, assessing, reporting, and taking necessary actions in response to any of your requests, complaints, questions, and feedback regarding the CAPI Portal and the products and services offered through it, conducting communication activities with you within the scope of the above-mentioned activities.
  • Within the scope of management and regulatory compliance activities; carrying out data retention activities within the scope of the execution of the processes related to the above-mentioned activities; planning and execution of Ford Otosan's commercial and/or business strategies, conducting, evaluating, and reporting of risk analysis studies and internal audits; receiving, assessing, reporting, and taking necessary actions in response to any of your requests, complaints, questions, and feedback, and conducting related communication activities with you; managing information security processes in the environments where the personal data collected within the scope of the above-mentioned activities are stored; ensuring that all the above-mentioned activities are carried out in compliance with the applicable legislation; providing information to legally authorized institutions and organizations, following up legal affairs, and exercising our right of defense when necessary.

The following types of processing Personal Data are applied: collection, reception, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission or transfer, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

You may find additional detailed information about the purposes of processing Personal Data by Ford Otosan on its Policy on the Processing and Protection of Personal Data, which has been made available to the public through the web address https://www.fordotosan.com.tr/documents/Politikalar/antetli_ford-otosan_personal-data-protection-and-processing-policy(1).pdf. The aforementioned Policy on the Processing and Protection of Personal Data shall be applied in conjunction with this Notice. However, to ensure observance of the GDPR in case of its applicability, provisions of this Notice have always priority.

Legal Basis for Processing Personal Data

Depending on the purposes of processing and the circumstances, in processing your Personal Data we may rely on the following legal bases in the priority of their order below:

  • The processing is necessary in connection with any contractual relationship that you may enter into with us, including the provision of the Portal and Services;
  • The processing is required by applicable law;
  • The processing is necessary for compliance with a legal obligation to which our Company is subject;
  • We have a legitimate interest in carrying out the processing for the purpose of managing, improving, operating or promoting our business (including provision of the Services) and our relationship with your employer, service partner or you, assessing the quality of the services we provide, and the services our suppliers provide to us or on our behalf, developing new and improved products, services, and business strategies, conduct research, protect or defend our or another's rights or property, or to detect, prevent, or otherwise address fraud, security, safety, or privacy issues (If you like to receive detailed information on the legitimate interests on which we base our processing, please send us an e-mail to gdprrep@ford.com.tr .) or
  • The processing is necessary for the establishment, exercise or protection of any right.

We refer to Art. 6 para. 1 (b), (c) and (f) GDPR and Art. 5 para. 2 (a), (c), (ç), (e), and (f) Law No. 6698.

Who May Access Your Personal Data?

Ford Otosan processes the Personal Data alone or may give assignment to third parties to process your data. If we are involving data processors into the performance of our services and contractual obligations, we have entered into data processing agreements with them.

Ford Otosan may also transfer your Personal Data within the scope of this Notice to:

  • Microsoft Ireland Operations Limited, a cloud-based company operating in these areas, for the purpose of carrying out storage activities and receiving technical infrastructure services,
  • legally authorized private individuals and entities, including the relevant ministries, courts, and enforcement offices, as well as to legally competent public authorities, for the purposes of ensuring that the activities are carried out in compliance with applicable legislation, providing information to legally authorized institutions and authorities, following up on legal proceedings, and exercising our right of defense where necessary.

Ford Otosan and some of its third parties are located outside the EU, which have not been subject of an adequacy decision of the EU commission pursuant to Article 45 GDPR. Ford Otosan will ensure that the level of data protection guaranteed by the GDPR will be upheld by

  • Concluding EU Standard Contractual Clauses in accordance with Art. 46 para. 2 (c) GDPR.

Further information may be obtained by e-mail to gdprrep@ford.com.tr.

International transfer of your Personal Data is required in order to ensure that you benefit from the CAPI Portal and the Services; otherwise, it may not be possible to make full or partial use of the CAPI Portal and the Services.

How do we protect and store Personal Data

We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:

  • pseudonymisation and encryption of Personal Data;
  • the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing CAPI Portals and services;
  • the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident;
  • a process for regular testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

In assessing the appropriate level of security account shall be taken in particular of the risks that are presented by processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data transmitted, stored or otherwise processed.

Consequences in case we may not collect your Personal Data

We need your Personal Data to enable the use of the CAPI Portal and to provide the Services in order to perform our contractual obligations with you. Without providing such Personal Data, we may not be able to operate the CAPI Portal and provide the Services you are intending to receive.

Consent and withdrawal

Any consent is provided freely. If you give your consent, you have the right to withdraw your consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. After your withdrawal we will stop processing your Personal Data, including storage, unless further data processing is legally permitted.

To withdraw your consent, please send us an e-mail to gdprrep@ford.com.tr or a letter to Akpınar Mahallesi, Hasan Basri Caddesi, No:2, 34885 Sancaktepe, İstanbul, Turkey.

Legitimate Interest and Right to Object

You may object to the processing of your Personal Data based on legitimate interests of Ford Otosan or third parties. Unless your objection is directed solely against direct marketing by Ford Otosan, you have to explain your special situation, which makes the processing of your Personal Data based on legitimate interests unacceptable for you.

To object, please send us an e-mail to gdprrep@ford.com.tr or a letter to Akpınar Mahallesi, Hasan Basri Caddesi, No:2, 34885 Sancaktepe, İstanbul, Turkey.

Retention

We only keep your personal information in identifiable form for as long as one of the following applies:

  • Your information is reasonably required in order to satisfy the purpose for which you submitted or we collected the information;
  • Your information is reasonably required in order to protect and defend our rights or property (this will generally be the length of the relevant limitation period in your jurisdiction); or
  • We are otherwise required to keep your information by applicable laws or regulations.

Where information is used for more than one purpose, we will retain it until the purpose with the latest period expires. For more information about our retention policies, please send us an e-mail to gdprrep@ford.com.tr.

Your rights related to data privacy

You have the right to request access to and rectification or erasure of your Personal Data, or restriction of their processing. Furthermore, you have the right to request data portability. If you are situated in the EU, you have the right to file a complaint to the relevant data protection authority.

If you have questions or concerns regarding our use of your information, or would like to exercise any of your rights, please send us an e-mail to gdprrep@ford.com.tr or a letter to Akpınar Mahallesi, Hasan Basri Caddesi, No:2, 34885 Sancaktepe, İstanbul, Turkey.

Updates to this Privacy Notice

We may modify or update this information from time to time. Please check https://capi.ford.com.tr/privacy-notice for the latest version of this Privacy Notice.