, and Processing of Personal Data Policy
1. CHAPTER 1—INTRODUCTION
1.1 Introduction
The protection of personal data is one of the top priorities of ROXALL MEDICINE İLAÇ İTHALAT İHRACAT SANAYİ VE TİCARET LTD. ŞTİ (“ROXALL” or “the Company”), and the Company makes every effort to comply with all applicable laws and regulations in this regard. This Company Data Protection and Processing Policy (“Policy”) sets forth the principles adopted in the conduct of personal data processing activities carried out by our Company, as well as the fundamental principles adopted to ensure compliance with the provisions of the Personal Data Protection Law No. 6698 (“Law”). In this way, our Company ensures the necessary transparency by informing data subjects. With full awareness of our responsibilities in this regard, your personal data is processed and protected in accordance with this Policy.
1.2 Scope
This Policy applies to all personal data of individuals—including our company’s employees—that is processed either fully or partially by automated means, or by non-automated means provided that such processing forms part of a data filing system.
1.3 Implementation of the Policy and Relevant Legislation
The relevant legal regulations currently in force regarding the processing and protection of personal data shall take precedence. In the event of any inconsistency between the applicable legislation and this Policy, our Company acknowledges that the applicable legislation shall prevail. This Policy sets forth the rules established by the relevant legislation, translating them into concrete provisions within the context of the Company’s practices.
1.4 Effective Date of the Policy
This Policy is effective for the year 2022.
This Policy is published on the Company’s website [https://www.roxall.com.tr*] and is made available to data subjects upon request.
2. CHAPTER 2 – MATTERS RELATING TO THE PROTECTION OF PERSONAL DATA
2.1. Ensuring the Security of Personal Data
In accordance with Article 12 of the Law, our company takes the necessary measures—based on the nature of the data to be protected—to prevent the unlawful disclosure, access, or transfer of personal data, as well as any other security breaches that may occur. In this context, our company takes administrative measures and conducts or commissions audits to ensure the necessary level of security, in accordance with the guidelines published by the Personal Data Protection Board (“Board”).
2.2. Protection of Special Categories of Personal Data
The Law places special emphasis on certain categories of personal data because their unlawful processing poses a risk of causing harm to individuals or leading to discrimination. This data includes information related to race, ethnic origin, political opinions, philosophical beliefs, religion, denomination, or other beliefs; attire and clothing; membership in associations, foundations, or labor unions; health; sexual life; criminal convictions; and security measures, as well as biometric and genetic data.
The Company handles the protection of special-category personal data—as defined by the Law and processed in accordance with the law—with the utmost care. In this context, the technical and administrative measures taken by the Company to protect personal data are carefully implemented with regard to special category personal data, and the necessary audits are conducted within the Company.
Detailed information regarding the processing of special category personal data is provided in Section 3.3 (“Processing of Special Category Personal Data”) of this Policy.
2.3. Raising Awareness and Monitoring Business Units Regarding the Protection and Processing of Personal Data
The Company ensures that the necessary training is provided to its business units to raise awareness aimed at preventing the unlawful processing of personal data, unlawful access to personal data, and ensuring the protection of personal data.
The Company is establishing the necessary systems to foster awareness among its employees regarding the protection of personal data and works with consultants on this matter as needed. In this regard, our Company evaluates participation in relevant training programs, seminars, and informational sessions, and updates and refreshes its training programs in line with updates to the relevant legislation.
3. CHAPTER 3 – MATTERS RELATING TO THE PROCESSING OF PERSONAL DATA
3.1. Processing of Personal Data in Accordance with the Principles Set Forth in the Law
3.1.1. Processing in Accordance with the Principles of Law and Good Faith
The Company acts in accordance with the principles established by legal regulations governing the processing of personal data, as well as the general principles of good faith and fairness. Within this framework, personal data is processed only to the extent necessary for the Company’s business operations and is limited to those purposes.
3.1.2. Ensuring That Personal Data Is Accurate and, Where Necessary, Up-to-Date
The company takes the necessary measures to ensure that personal data remains accurate and up-to-date throughout the period during which it is processed, and establishes the necessary mechanisms to ensure the accuracy and timeliness of personal data at regular intervals.
3.1.3. Processing for Specific, Clear, and Legitimate Purposes
The company clearly states the purposes for which it processes personal data and processes such data in accordance with its business activities and for purposes related to those activities.
3.1.4. Relevance, Limitation, and Proportionality to the Purpose for Which They Are Processed
The company collects personal data only to the extent and in the manner required by its business activities and processes such data solely for the specified purposes.
3.1.5. Retention for the Period Specified in the Relevant Legislation or as Necessary for the Purpose for Which the Data Is Processed
The Company retains personal data for as long as necessary to fulfill the purpose for which it was processed and for the minimum period required by the applicable laws governing the relevant activity. In this context, our Company first determines whether the relevant legislation specifies a retention period for personal data; if a period is specified, it acts in accordance with that period. If no legal retention period exists, personal data is retained for as long as necessary for the purpose for which it was processed. At the end of the specified retention periods, personal data is destroyed in accordance with periodic destruction schedules or upon the data subject’s request, using the specified destruction methods (deletion and/or destruction and/or anonymization).
3.2. Conditions for the Processing of Personal Data
Unless the data subject has given explicit consent, the legal basis for the processing of personal data may be any one of the conditions listed below, or multiple conditions may serve as the legal basis for the same personal data processing activity. If the processed data constitutes special-category personal data, the conditions set forth in Section 3.3 of this Policy (“Processing of Special-Category Personal Data”) shall apply.
i. Existence of the Data Subject’s Explicit Consent
One of the conditions for processing personal data is the data subject’s explicit consent. The data subject’s explicit consent must be given in relation to a specific matter, based on information provided, and of their own free will.
If the conditions for processing personal data listed below are met, personal data may be processed without the data subject’s explicit consent.
ii. Explicit Provision in the Law
The data subject’s personal data may be processed if this is explicitly provided for by law—in other words, if there is an explicit provision in the relevant law regarding the processing of personal data.
iii. Failure to Obtain the Data Subject’s Explicit Consent Due to Actual Impossibility
If a person is unable to express consent due to actual impossibility or if their consent cannot be deemed valid, the data subject’s personal data may be processed if such processing is necessary to protect the life or physical integrity of that person or another person.
iv. Direct Relevance to the Conclusion or Performance of a Contract
Provided that the processing of personal data is necessary for the conclusion or performance of a contract to which the data subject is a party, this condition shall be deemed to have been met.
v. Compliance with the Company’s Legal Obligations
The data subject’s personal data may be processed if such processing is necessary for our company to comply with its legal obligations.
vi. Disclosure of Personal Data by the Data Subject
If the data subject has disclosed their personal data, the relevant personal data may be processed solely for the purpose of such disclosure.
vii. Data Processing Necessary for the Establishment or Protection of a Right
If data processing is necessary for the establishment, exercise, or protection of a right, the data subject’s personal data may be processed.
viii. Necessity of Data Processing for Our Company’s Legitimate Interests
Provided that it does not infringe upon the data subject’s fundamental rights and freedoms, the data subject’s personal data may be processed if such processing is necessary for our Company’s legitimate interests.
3.3. Processing of Special Category Personal Data
Sensitive personal data is processed by our Company in accordance with the principles set forth in this Policy, by taking all necessary administrative and technical measures—including those determined by the Board—and provided that the following conditions are met:
(i) Special category personal data other than that relating to health and sexual life may be processed without the data subject’s explicit consent if expressly provided for by law—that is, if the law governing the relevant activity contains an explicit provision regarding the processing of personal data. Otherwise, the data subject’s explicit consent must be obtained to process such special category personal data.
(ii) Special category personal data relating to health and sex life may be processed without the data subject’s explicit consent by persons subject to a duty of confidentiality or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, and the provision of medical diagnosis, treatment, and care services, as well as the planning and management of health services and their financing. Otherwise, the data subject’s explicit consent must be obtained in order to process such special-category personal data.
3.4. Informing the Data Subject
The Company provides information to data subjects in accordance with Article 10 of the Law and secondary legislation. In this context, the Company informs data subjects about who, as the data controller, processes their personal data; for what purposes; with whom it is shared and for what purposes; how it is collected; the legal basis for such processing; and the rights data subjects have regarding the processing of their personal data.
3.5. Processing by the Company of Data Processed by Group Companies
Personal data processed by the Company may also be processed by the Company for the purpose of ensuring that the Company’s operations are conducted in accordance with the principles, objectives, and strategies of the group companies, and to protect the Company’s rights, interests, and reputation. If the sharing of personal data between the Company and other group companies takes place within the scope of the Law as a transfer of personal data from one data controller to another, the relevant group company shall inform the data subject at the time of collection that their personal data may be sent to the Company.
3.6. Transfer of Personal Data
Our company may transfer the personal data and special category personal data of data subjects to third parties (third-party companies, public and private authorities, group companies, and third-party individuals) by taking the necessary security measures in accordance with lawful purposes for processing personal data. In this regard, our company acts in compliance with the provisions set forth in Article 8 of the Law. Detailed information on this subject can be found in the section of this Policy titled “Third Parties to Whom Our Company Transfers Personal Data and the Purposes of Such Transfers.”
3.6.1 Transfer of Personal Data
Even in the absence of the data subject’s explicit consent, personal data may be transferred to third parties by our Company, provided that one or more of the conditions listed below are met, with due care exercised and all necessary security measures—including those prescribed by the Board—being taken.
• The transfer of personal data is expressly provided for by law,
• The transfer of personal data by the Company is directly related to and necessary for the conclusion or performance of a contract,
• The transfer of personal data is necessary for the Company to fulfill its legal obligations,
• The transfer of personal data by our Company, limited to the purpose of disclosure, provided that the data has been made public by the data subject,
• The transfer of personal data by the Company is necessary for the establishment, exercise, or protection of the rights of the Company, the data subject, or third parties,
• It is necessary to transfer personal data for the Company’s legitimate interests, provided that such transfer does not infringe upon the data subject’s fundamental rights and freedoms,
• It is necessary to protect the life or physical integrity of the data subject or another person, where the data subject is unable to express consent due to actual impossibility or where their consent is not legally valid.
In addition to the above, personal data may be transferred to foreign countries declared by the Board to have adequate protection (“Foreign Country with Adequate Protection”) if any of the above conditions are met. In the absence of adequate protection, data may be transferred to foreign countries (“Foreign Country Where a Data Controller Committing to Adequate Protection Is Located”) where the data controllers in Turkey and the relevant foreign country have committed in writing to providing adequate protection in accordance with the data transfer conditions set forth in the legislation, and where the Board has granted its authorization.
3.6.2 Transfer of Special Category Personal Data
Sensitive personal data may be transferred by our Company in accordance with the principles set forth in this Policy, provided that all necessary administrative and technical measures—including those determined by the Board—are taken and the following conditions are met:
(i) Special category personal data other than that relating to health and sexual life may be processed without the data subject’s explicit consent if expressly provided for by law—that is, if there is an explicit provision in the relevant law regarding the processing of personal data. Otherwise, the data subject’s explicit consent must be obtained.
(ii) Special-category personal data relating to health and sexual life may be processed without the data subject’s explicit consent by persons subject to a duty of confidentiality or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, and the provision of medical diagnosis, treatment, and care services, as well as the planning and management of health services and their financing. Otherwise, the data subject’s explicit consent must be obtained. In addition to the above, personal data may be transferred to foreign countries with adequate protection if any of the above conditions are met. If adequate protection is not available, personal data may be transferred to foreign countries where the data controller has committed to providing adequate protection, in accordance with the data transfer conditions set forth in the legislation.
4. CHAPTER 4 – CATEGORIZATION OF PERSONAL DATA PROCESSED BY OUR COMPANY AND THE PURPOSES OF PROCESSING
In accordance with Article 10 of the Law and secondary legislation, data subjects are informed by our Company, and in line with our Company’s purposes for processing personal data, such processing is based on and limited to at least one of the conditions for processing personal data specified in Article 5 and 6 of the Law, and in a manner consistent with the general principles set forth in the Law—primarily the principles regarding the processing of personal data specified in Article 4 of the Law. Detailed information regarding the purposes of processing the personal data in question is provided in the appendix to this Policy (“Purposes of Personal Data Processing”).
5. CHAPTER 5 – STORAGE AND DISPOSAL OF PERSONAL DATA
Our company retains personal data for the period necessary to fulfill the purpose for which it was processed and in accordance with the minimum retention periods specified in the applicable laws governing the relevant activity. In this context, our company first determines whether the relevant legislation specifies a retention period for personal data; if a period has been established, it acts in accordance with that period. If no legal retention period exists, personal data is retained for as long as necessary to fulfill the purpose for which it was processed. At the end of the specified retention periods, personal data is destroyed in accordance with periodic destruction schedules or upon the data subject’s request, using the specified destruction methods (deletion and/or destruction and/or anonymization).
6. CHAPTER 6 – RIGHTS OF DATA SUBJECTS AND THE EXERCISE OF THOSE RIGHTS
6.1. Rights of Data Subjects
Data subjects have the following rights:
(1) To learn whether their personal data has been processed,
(2) To request information regarding the processing of their personal data, if it has been processed,
(3) To learn the purpose of the processing of their personal data and whether it is being used in accordance with that purpose,
(4) To know the third parties to whom personal data has been transferred, whether within the country or abroad,
(5) To request the correction of personal data if it has been processed incompletely or incorrectly, and to request that the third parties to whom the personal data has been transferred be notified of the correction,
(6) To request the erasure or destruction of personal data if the grounds justifying its processing no longer exist, even though it was processed in accordance with the provisions of this Law and other relevant laws, and to request that third parties to whom the personal data has been transferred be notified of this action,
(7) To object to a decision made solely through the automated processing of personal data that results in adverse consequences for the individual,
(8) To request compensation for damages incurred as a result of the unlawful processing of personal data.
6.2. Exercise of the Data Subject’s Rights
Data subjects may submit requests regarding the rights listed in Section 6.1 (“Data Subject Rights”) to our Company using the methods established by the Board. To this end, they may use the “Data Subject Request Form” available at https://www.roxall.com.tr.
6.3. Our Company’s Response to Inquiries
Our company takes the necessary administrative and technical measures to process requests submitted by data subjects in accordance with the Law and secondary legislation. If the data subject submits a request regarding the rights set forth in Section 6.1 (“Rights of the Data Subject”) to our Company in accordance with the prescribed procedure, our Company will process the request free of charge as soon as possible and no later than 30 (thirty) days, depending on the nature of the request. However, if the process involves additional costs, a fee may be charged in accordance with the tariff established by the Board.
7. CHAPTER 7 – SPECIFIC CIRCUMSTANCES IN WHICH PERSONAL DATA IS PROCESSED
7.1. Building Entrances, Personal Data Processing Activities Conducted Within the Building, and Website Visitors
To ensure security, the Company conducts personal data processing activities, including security camera monitoring at its buildings and facilities, as well as tracking the entry and exit of visitors.
7.2. Camera Surveillance Activities Conducted at the Entrances to and Inside Company Buildings and Facilities
The Company conducts video surveillance at its buildings and facilities to ensure security, in accordance with the Law on Private Security Services and relevant regulations. The Company carries out video surveillance at its buildings and facilities to ensure security, for the purposes specified in the applicable regulations, and in compliance with the conditions for processing personal data set forth in the Law.
In accordance with Article 10 of the Law, the Company informs data subjects about video surveillance activities through multiple methods. Furthermore, in accordance with Article 4 of the Law, the Company processes personal data in a manner that is relevant, limited, and proportionate to the purposes for which it is processed.
The Company’s purpose in conducting video surveillance is limited to the purposes listed in this Policy. Accordingly, the surveillance areas, number of security cameras, and timing of surveillance are implemented only to the extent necessary to achieve security objectives and are strictly limited to that purpose. Individuals are not subject to surveillance in areas where such monitoring could result in an intrusion into their privacy that goes beyond security purposes (e.g., restrooms).
Only a limited number of Company employees have access to live camera feeds and recordings stored digitally. The limited number of individuals with access to the recordings have signed a confidentiality agreement pledging to protect the confidentiality of the data to which they have access.
7.3. Tracking of Guest Entries and Exits at Company Building and Facility Entrances and Inside the Premises
The Company processes personal data to monitor visitor entry and exit at its buildings and facilities for the purposes of ensuring security and as specified in this Policy.
When the first and last names of individuals visiting the Company’s buildings as guests are collected, or through notices posted on Company premises or otherwise made available to guests, the data subjects are informed of this processing. The data collected for the purpose of tracking guest entries and exits is processed solely for this purpose, and the relevant personal data is recorded in a physical data recording system.
8. CHAPTER 8 – THE RELATIONSHIP BETWEEN THE COMPANY’S POLICY ON THE PROTECTION AND PROCESSING OF PERSONAL DATA AND OTHER POLICIES
The Company establishes not only internal policies regarding the protection and processing of personal data—as set forth in this Policy—but also fundamental policies for its group companies.
The Company aims to ensure that the principles of its internal policies are reflected in publicly available policies, to the extent applicable, so that stakeholders are informed within this framework and transparency and accountability regarding the Company’s personal data processing activities are ensured.
EK 1 – Purposes of Personal Data Processing
| MAIN OBJECTIVES (PRIMARY) | OTHER OBJECTIVES (SECONDARY) |
| Planning and Implementation of the Company’s Human Resources Policies and Processes | Conducting Personnel Recruitment Processes |
| Ensuring that our relevant business units carry out the necessary work and execute the related business processes to enable the Company to conduct its commercial activities | Event Management Planning and Execution of Corporate Communications Activities Planning of Information Security Processes, Audit, and Execution Establishment and Management of Information Technology Infrastructure Monitoring of Financial and/or Accounting Operations Planning and Execution of Corporate Sustainability Activities Conducting Effectiveness, Efficiency, and/or Appropriateness Analyses of Business Operations Planning and/or Execution of Activities Planning and Execution of Corporate Governance Activities |
| Planning and Execution of the Company’s Commercial and/or Business Strategies | Management of Relationships with Business Partners, Group Companies, Subsidiaries, and/or Suppliers : Implementation of Strategic Planning Activities |
| Planning and Implementation of Human Resources Policies and Processes for the Company and Its Group Companies | Employee Request and Complaint Management Planning analysis and improvement activities related to compensation management for Group Companies Planning and supporting processes for providing fringe benefits and perks to employees of the Company and Group Companies Supporting the Company’s compensation management planning activities Planning and supporting processes related to the training and career development of employees of the Company and Group Companies Planning and managing processes aimed at increasing employee satisfaction Planning and/or executing processes for the recruitment, placement, and operations of interns and/or students |
| Strategic Human Resources Planning for the Company and Its Group Companies, Succession Planning Processes, and | Managing the processes related to employee performance evaluations |
| Providing Support for Organizational Development Activities | Provide support for the company’s development and contingency planning activities Provide support for the management of staff and executive appointment and promotion processes within the company |
| Planning and Execution of Corporate Audit Activities | Providing support for the company and its group companies’ whistleblowing and investigation processes Planning and conducting audit activities to ensure that the company’s operations are carried out in accordance with group company procedures and applicable laws and regulations |
| Ensuring the legal, technical, and commercial-business security of the Company and the relevant individuals with whom the Company has a business relationship | Monitoring Legal Matters Creating and Tracking Visitor Records Planning and Executing the Operational Activities Necessary to Ensure That Company Operations Are Conducted in Compliance with Company Procedures and/or Relevant Legislation Ensuring the Security of Company Fixed Assets and/or resources Ensuring the security of company operations Providing information required by law to authorized institutions Carrying out corporate and partnership law transactions Providing support for carrying out corporate and partnership law transactions Ensuring that data is accurate and up-to-date Ensuring the security of company premises and/or Facilities Planning and Execution of Corporate Audit Activities |
EK 2 – Data Subjects
| DATA SUBJECT | DESCRIPTION |
| Corporate Customer | Natural persons whose personal data is obtained through the Company’s business relationships as part of operations conducted by the Company’s business units, regardless of whether they have any contractual relationship with the Company |
| Visitor | Individuals who have entered the Company’s physical premises for various purposes or who have visited our websites |
| Job Applicant | Individuals who have applied for a job with the Company by any means or who have submitted their resumes and related information for the Company’s review. |
| Company Employee | Employees of Group Companies whose personal data is processed in connection with activities conducted by the Company, such as employee satisfaction, human resources, auditing, information technology security and infrastructure, legal compliance, and other related activities |
| People with Aile and Their Loved Ones | The spouses, children, and close relatives of data subjects whose personal data is processed under this Policy in the course of the Company’s operations |
| Third Person | This Policy and other individuals not covered by the Company’s Personal Data Protection and Processing Policy (e.g., guarantors, companions, former employees) |
| Company Supplier | Natural persons who are employees, authorized representatives, or shareholders of a party that provides services to the Company on a contractual basis in accordance with the Company’s orders and instructions while the Company conducts its business activities. |
| Company Shareholder | The company's shareholders are individuals |
| Company Official | Members of the company's board of directors and other authorized individuals |
| Employees, Shareholders, and Officials of the Organizations We Partner With | Individuals, including employees, shareholders, and officers of entities with which the company has any type of business relationship (such as business partners and suppliers, but not limited to these) |
EK 3 – Categories of Personal Data
| CATEGORIZATION OF PERSONAL DATA | EXPLANATION OF PERSONAL DATA CATEGORIZATION |
| Identification Information | This data contains information regarding a person’s identity, including first and last name, Turkish ID number, nationality, place of birth, date of birth, gender, employer information, employee ID number, tax ID number, title, biography, and other similar details, as well as documents such as a driver’s license, professional ID, national ID card, and passport. |
| Contact Information | Information such as phone number, address, email address, fax number, etc. |
| Transaction Security Information | Your personal data processed to ensure our technical, administrative, legal, and commercial security during the course of our operations (e.g., log records, IP information, authentication information) |
| Transaction Information | Within the scope of the Company’s operations, data such as survey information, declaration information, transaction information, call center records, membership information, and cookie records—processed in connection with the services provided or for the purpose of protecting the legal and other interests of the Company and the data subject— |
| Individuals with Aile and Their Close Relatives | Information regarding the data subject’s family members (e.g., spouse, mother, father, child), close relatives, and other individuals who can be contacted in an emergency—processed in connection with the services provided or for the purpose of protecting the legal and other interests of the Company and the data subject—as part of the activities carried out by the Company |
| Physical and Mechanical Security Knowledge | Personal data related to records and documents collected upon entry into the physical premises and during the time spent on the premises; such as camera recordings, vehicle information records, and records collected at security checkpoints, etc. |
| Financial Information | Personal data processed in connection with information, documents, and records showing any and all financial outcomes arising from the type of legal relationship the company has established with the data subject, as well as data such as bank account numbers, IBAN numbers, income information, and information on debts and receivables |
| Visual/Audio Information | Photographs and video recordings (excluding those covered by Physical Premises Security Information) and audio recordings |
| Special Category Personal Data | Data related to a person’s race, ethnic origin, political views, philosophical beliefs, religion, denomination, or other beliefs; attire; membership in associations, foundations, or unions; health; sexual life; criminal convictions; and security measures; as well as biometric and genetic data |
| Legal Procedures and Compliance Information | Personal data processed for the purposes of identifying and monitoring our legal claims and rights, ensuring the fulfillment of our obligations, and complying with our legal obligations and the Company’s policies |
| Audit and Inspection Information | Personal data processed in connection with the conduct of our company’s operational, financial, fraud, and compliance audit activities |
| Information on Request/Complaint Management | Personal data related to the receipt and evaluation of any claims or complaints directed at the company |
In accordance with Articles 8 and 9 of the Personal Data Protection Law, the Company may transfer the personal data of data subjects governed by this Policy to the following categories of recipients:
(i) the Company’s business partners,
(ii) the Company’s suppliers,
(iii) the Company’s group companies,
(iv) public institutions and organizations authorized by law,
(v) private entities authorized by law
EK 4 – Third Parties to Which Our Company Discloses Personal Data and the Purposes of Such Disclosures
The scope of the individuals mentioned above to whom data is transferred, as well as the purposes of such transfers, are set forth below.
| People to Whom Data May Be Transferred | Definition | Purpose of Data Transfer |
| Business Partner | This term refers to parties with whom the Company has established business partnerships—either directly or in collaboration with the Company—for purposes such as carrying out various projects or obtaining services in the course of its commercial activities. Banks, etc. | To ensure that the objectives of the partnership are met, to a limited extent |
| Supplier | It refers to parties that provide services to the Company on a contractual basis in accordance with the Company’s orders and instructions while the Company conducts its business operations. | The Company obtains these services from a third-party supplier solely for the purpose of ensuring that the services necessary for the Company to carry out its business operations are provided to the Company. |
| Group Companies | Group companies | Solely for the purpose of ensuring the conduct of its commercial activities that require group participation, |
| Public Institutions and Organizations Authorized by Law | Public institutions and organizations authorized to obtain information and documents from the Company in accordance with the relevant legal provisions | Limited to the purpose requested by the relevant public institutions and organizations within the scope of their legal authority |
| Legal Entities Authorized by Law | Private entities authorized to obtain information and documents from the Company in accordance with the relevant legal provisions | Limited to the purpose requested by the relevant private legal entities within the scope of their legal authority |