Data Retention Policy

Data Retention Policy

Data Retention Policy

How long we keep personal data and how we destroy it when the period ends.

1. Purpose and scope

This policy sets out the principles for retaining and destroying personal data processed by TEX GROUP TURİZM LİMİTED ŞİRKETİ (“TEX Group”), in line with the Turkish Personal Data Protection Law No. 6698 and the Regulation on the Deletion, Destruction or Anonymisation of Personal Data. It applies to our staff, TEX Professionals specialists and service providers that process data on our behalf.

2. Where we keep data

  • Electronic media: corporate e-mail and document infrastructure (Google), website and form infrastructure (Framer), task tracking (Asana), company computers and mobile devices,

  • Physical media: paper documents such as contracts, invoices and written requests, kept in locked cabinets.

3. Reasons for retention and destruction

We keep personal data for as long as it is needed to enter into and perform contracts, comply with legal obligations, protect our rights and pursue our legitimate interests. Data is destroyed when the purpose of processing no longer exists, the retention period ends, explicit consent is withdrawn, or a data subject makes a justified request.

4. Retention periods

  • Contact form and e-mail requests (not leading to a business relationship, no proposal sent): 2 years after the request is closed,

  • Proposals sent and business correspondence: 10 years from the end of the calendar year in which they were issued (Turkish Commercial Code Art. 82),

  • Contracts: 10 years after the contract ends (Turkish Code of Obligations Art. 146),

  • Invoices, accounting and payment records: 10 years from the end of the relevant financial year (Turkish Commercial Code, Tax Procedure Law),

  • Travel and event service records: 10 years after the service is completed; copies of passports and visas, 6 months after the service is completed,

  • Special categories of data (health, dietary and accessibility information): at the latest 6 months after the service is completed,

  • Photos and videos used for promotion: until consent is withdrawn,

  • Photos and videos taken during a service and not used for promotion: 1 year after the service is completed,

  • Job applications: 1 year after the process is concluded; with explicit consent, at most 2 years,

  • TEX Professionals specialist records: 10 years after the business relationship ends; records that do not lead to a business relationship, 2 years,

  • Data subject requests and replies: 10 years after the request is concluded,

  • Website security and access logs: at most 2 years,

  • Analytics data (Google Analytics): at most 14 months,

  • Cookie preference record: in the visitor’s browser, until the visitor deletes it or changes their choice.

Where data is processed for more than one purpose, the longest period applies. If a dispute or official investigation begins before the period ends, the data concerned is kept until it is concluded.

5. Methods of destruction

  • Deletion: making electronic data inaccessible and unusable for the relevant users in any way; deleting records held by service providers using their permanent deletion functions.

  • Destruction: making paper documents irreversibly unreadable (for example, with a document shredder); physically destroying or securely wiping data storage devices that are no longer used.

  • Anonymisation: making data impossible to associate with an identified or identifiable person, even when matched with other data; used for statistical purposes.

6. Periodic destruction

Data whose retention period has ended is destroyed through periodic destruction carried out at intervals of no more than 6 months. A data subject’s request for destruction is fulfilled within 30 days at the latest, where it complies with the KVKK. All destruction operations are recorded, and these records are kept for at least 3 years.

7. Technical and administrative measures

  • Limiting access rights to roles and needs, and reviewing them regularly,

  • Strong passwords and two-step authentication,

  • Encrypted connections (HTTPS) and reliable cloud infrastructure,

  • Data processing and confidentiality agreements with service providers,

  • Confidentiality undertakings and regular awareness training for staff and specialists,

  • Locked, access-restricted storage for paper documents,

  • An incident response and notification procedure for data breaches.

8. Additional measures for special categories of data

In line with the adequate measures set by the Turkish Personal Data Protection Board, special categories of personal data are:

  • Processed only to the extent the service requires, and only by authorised people,

  • Kept in separate, access-restricted and password-protected folders,

  • Shared by e-mail, where necessary, only as encrypted files or over secure connections,

  • Destroyed at the latest 6 months after the service is completed.

9. Responsibility and updates

The company manager is responsible for implementing this policy; all staff and specialists involved in personal data processes must comply with it. The policy is updated when the law or our business processes change, and the current version is published on this page.

Last updated: 22 September 2026