BİRİKİM PİLLERİ BATTERY INDUSTRY AND TRADE LTD. CO. PERSONAL DATA PROTECTION AND PROCESSING POLICY

 1. PURPOSE OF THE POLICY

The Personal Data Protection and Processing Policy (“Policy”) of BİRİKİM PİLLERİ BATTERY INDUSTRY AND TRADE LTD. CO. (“BİRİKİM PİLLERİ”) has been prepared to establish the procedures and principles regarding the processing activities carried out by BİRİKİM PİLLERİ and the business practices related to the protection of personal data being processed.

Following the amendment made in 2010, with the addition to Article 20 of the Constitution, the protection of personal data has been constitutionally guaranteed, and it has been stipulated that the procedures and principles related to the protection of personal data shall be regulated by law. In this context, the Law No. 6698 on the Protection of

Personal Data (KVKK) came into effect on April 7, 2016. BİRİKİM PİLLERİ, recognizing the protection of personal data as primarily a constitutional right, organizes the necessary initiatives to raise awareness within the company and aligns its internal processes to comply with the personal data protection regulations, thereby formalizing this commitment as a company policy.

This Policy serves as guidance for the implementation of the regulations introduced by the personal data protection law and related legislation by BİRİKİM PİLLERİ.

2. DEFINITIONS OF TERMS

Explicit Consent: Consent based on being informed, relating to a specific matter, and declared with free will.

Anonymization: Making personal data unrelatable to an identified or identifiable real person, even when matched with other data.

Personal Data Subject: The real person whose personal data is processed (e.g., customers, employees).

Personal Data: Any kind of information relating to an identified or identifiable real person.

Special Category Personal Data: Data such as race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance, membership to associations, foundations or trade unions, health, sexual life, criminal convictions, security measures, as well as biometric and genetic data.

Protection of Personal Data: Any operation performed on data, such as obtaining, recording, storing, preserving, modifying, rearranging, disclosing, transferring, taking over, making available, classifying, or preventing the use of personal data, whether fully or partially by automatic means or non-automatic means that are part of a data recording system.

Data Processor: A real or legal person who processes personal data on behalf of the data controller based on the authority given by the data controller.

Data Controller: A real or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.

KVKK: The Law No. 6698 on the Protection of Personal Data.

3. PERSONAL DATA RECORDING ENVIRONMENTS

Personal data at BİRİKİM PİLLERİ is processed through the following recording environments:

4. EMPLOYEE, CANDIDATE, INTERN, AND PHYSICAL VISITOR GROUPS4.1. Personal Data Collected from Interns and Candidates

BİRİKİM PİLLERİ collects the following personal data from candidates applying for a job:

4.b. Personal Data Collected from Employees

BİRİKİM PİLLERİ collects the following personal data from employees due to the employment relationship and its

execution:

4.c. Purposes for Collecting and Processing Candidate and Intern Personal Data

Depending on the nature of the application, BİRİKİM PİLLERİ processes candidate and intern data for the following

purposes:

4.d. Purposes for Collecting and Processing Employee Personal Data

BİRİKİM PİLLERİ processes employee data for the following purposes:

4.e. Methods of Collecting and Processing Employee and Candidate Personal Data

During the recruitment process, candidate data is collected through the following methods, among others outlined in

this Policy:

4.f. Conducting Reference Checks on Candidates and Interns

BİRİKİM PİLLERİ may conduct reference checks on candidates and interns based on the information provided in the job application form. These checks are primarily aimed at verifying the accuracy of the details shared by the candidateor intern. Additionally, the reference check may seek to identify information the candidate or intern may have withheld but which could pose risks for BİRİKİM PİLLERİ.

When contacting third parties for reference checks, BİRİKİM PİLLERİ will fulfill its disclosure obligation at the first point of communication. As part of the reference check, necessary personal data such as identity information, work, and educational experience may be shared with third parties. Furthermore, personal data may also be obtained about the candidates and interns from third parties. Candidates and interns can contact BİRİKİM PİLLERİ at any time for information regarding the reference check conducted on them.

5. CUSTOMER

5.a. Personal Data Collected from Customers

Depending on the service, product, or commercial activity provided to the customer, the following personal data may be processed by BİRİKİM PİLLERİ in oral, written, or electronic form during the use of BİRİKİM PİLLERİ products and services:

5.b. Personal Data Collected from Suppliers or Supplier Employees

5.c. Purpose of Collecting and Processing Customer and Supplier DataBİRİKİM PİLLERİ processes customer and supplier data for the following purposes, considering the business relationship:

To handle payment or collection processes involving suppliers or customers.

5.d. Methods of Collecting and Processing Customer Data

5.e. Customer Rights Related to Their Personal Data

Customers wishing to exercise their rights under the Turkish Personal Data Protection Law (KVKK) can

apply to BİRİKİM PİLLERİ following the procedures and principles described in this Policy.

6. PRINCIPLES OF PERSONAL DATA PROCESSING6.a. Processing in Compliance with the Law and Rules of Integrity

Personal data is processed in compliance with legal principles, general trust, and rules of honesty.

6.b. Ensuring Accuracy and Up-to-Dateness

Periodic checks and updates are carried out to ensure the processed personal data of data subjects is accurate and up-to-date. Systems to verify and correct the accuracy of data are established within

BİRİKİM PİLLERİ.

6.c. Processing for Specific, Clear, and Legitimate Purposes

Personal data is processed for purposes that are clear, specific, and legitimate, detailed further in the document.

6.d. Being Relevant, Limited, and Proportionate to the Purpose

Data is processed only to the extent necessary to achieve the stated purposes, avoiding unrelated or excessive data processing.

6.e. Retention Only as Long as Necessary or Legally Required

Data is retained only for as long as necessary for processing purposes or as required by law. When retention periods end or processing purposes no longer exist, personal data is deleted, destroyed, or anonymized following BİRİKİM PİLLERİ’s Data Retention and Destruction Policy.

7. CONDITIONS FOR PROCESSING PERSONAL DATA

While explicit consent is one legal basis, personal data may also be processed under other lawful grounds, including:

7.a. Clearly Provided by Law:

If personal data processing is explicitly provided for in the law, BİRİKİM PİLLERİ may process data without separate consent (e.g., membership, electronic commercial permissions, order, payment, delivery, cancellation, or return processes under the Electronic Commerce Law).

7.b. Inability to Obtain Consent Due to Impossibility:

If obtaining consent is impossible due to the person’s inability to express it or lack of legal validity, data may be processed to protect life or bodily integrity.

7.c. Necessary for Contract Formation or Performance:

Data may be processed when necessary for the formation or execution of a contract.

7.d. Necessary for Legal Obligations:

Data may be processed without consent if required for legal obligations.

7.e. Publicly Disclosed by the Data Subject:

If the data subject has made their personal data public, processing may occur in line with the

disclosure.

7.f. Required for the Establishment or Protection of Rights:

Data may be processed to establish, exercise, or protect a right.

7.g. Processing Based on Legitimate Interest:

Without harming fundamental rights and freedoms, data may be processed for BİRİKİM PİLLERİ’slegitimate interests (e.g., conducting customer satisfaction surveys).

If none of the above apply, explicit consent is required.

8. CONDITIONS FOR PROCESSING SPECIAL CATEGORY PERSONAL DATA

8.a. With Explicit Consent:

Special category personal data may be processed with explicit consent, under the principles and

administrative/technical safeguards outlined in this Policy.

8.b. Without Explicit Consent:

Special category personal data may be processed without explicit consent under the sufficient safeguards determined by the Personal Data Protection Board, for example:

9. INFORMATION AND NOTIFICATION OF DATA SUBJECTS

When personal data is collected, BİRİKİM PİLLERİ informs the data subject of the data controller’s identity, the purpose of data processing, to whom and for what purposes the data may be transferred, the method of data collection, and their rights.

Requests for information can be made via email to birikimpilleri@hs01.kep.tr or kvkk@birikimpilleri.com, using a registered email (KEP) address, secure electronic signature, mobile signature, or the email address registered in BİRİKİM PİLLERİ’s systems. Alternatively, written requests can be submitted to Kemankeş Karamustafapaşa Mahallesi, Halil Paşa Sokak No: 1A, Beyoğlu, Istanbul.

10. CATEGORIES OF PERSONAL DATA PROCESSED

BİRİKİM PİLLERİ processes the following data categories:

11. PURPOSES OF PERSONAL DATA PROCESSING

11.a. Processing Conditions

11.b. Processing Purposes

For Candidates, Employees, Interns:

12. TRANSFER OF PERSONAL DATA TO THIRD PARTIES (DOMESTIC OR

ABROAD)

12.a. Data Transfer

Personal data may be transferred to third parties if the conditions under KVKK Articles 8 and 9 are met. For example, non-member online visitors’ anonymized data (such as site usage habits) may be collected and shared via cookies.

12.b. Third Parties and Transfer Purposes

Data may be transferred to:

13. PERSONAL DATA SECURITY

Measures are taken to prevent unauthorized access, accidental data loss, deliberate deletion, or

damage. Access is restricted to authorized personnel, with a permissions system designed to prevent excessive access. Special category data, such as health information, is protected with stricter measures. Authorized personnel undergo security checks and training. Access logs are maintained and regularly reviewed. Any unauthorized access triggers an immediate investigation. BİRİKİM PİLLERİ complies with obligations including:

14. LEGAL RIGHTS OF DATA SUBJECTS AND HOW TO EXERCISE THEM

14.a. Rights Under KVKK

Under Article 11 of KVKK, data subjects have the right to:

14.b. How to Exercise These Rights

Requests can be submitted via email to birikimpilleri@hs01.kep.tr or kvkk@birikimpilleri.com, using a KEP address, secure e-signature, mobile signature, or the registered email in BİRİKİM PİLLERİ systems. Applications can also be made via the KVKK Application Form on www.birikimpilleri.com. Responses will be provided within 30 days.

15. EFFECTIVENESS AND UPDATES

This Policy entered into force on November 26, 2020. It may be updated to comply with changing conditions and regulations. Updates will be announced on www.birikimpilleri.com.