Last Updated: September 2026
PRIVACY POLICY
1. Introduction & Scope
Türkiye Şişe ve Cam Fabrikaları A.Ş. (“Şişecam” or “we”, “our”, “us”), acting as the data controller under the General Data Protection Regulation (GDPR) and relevant data protection laws, processes the personal data of individuals who visit and use our website www.sisecam.com (“Website”), our microsites, and specific functions available on our platforms (such as communication, application, or request forms).
We believe that data protection should be transparent and easy to understand. This Privacy Policy is designed to provide you with clear information about how we collect, use, store, and share your personal data when you interact with our online presence.
Please note that this Policy specifically covers data processing activities related to the use of our Website and its built-in forms. Other processing operations—such as our HR recruitment processes, employee management, customer loyalty programs, or cookies—are governed by dedicated, specific privacy notices. For more details on how we use cookies, please refer directly to our Cookie Notice.
2. Data Controller
The Data Controller responsible for processing your personal data through this Website is: Türkiye Şişe ve Cam Fabrikaları Anonim Şirketi
Certain enquiries, requests or communications submitted through the Website may be handled by the relevant Şişecam Group company responsible for the relevant business area, product group or service. In such cases, the relevant Şişecam Group company may process your personal data as an independent data controller for the purposes of responding to your request, providing the relevant information or service, handling communications, and complying with applicable legal obligations.
3. Personal Data Categories We Process
We only collect and process personal data that is necessary to run a secure, functional website and to respond to your specific requests. Depending on how you interact with our Website, we may process the following categories of personal data:
| Data Category |
Definition and Scope of Processed Personal Data |
Methods of Data Collection |
| Identity Data |
First name, last name. |
Information provided through the contact/application/request forms available on our Website and our communication channels. |
| Contact Data |
Email address, phone number, address, and other contact details provided by you. |
Information provided through the contact/application/request forms available on our Website and our communication channels. |
| Professional Data |
Company name, department, position/job title, country of employment, and corporate/work contact details. |
Information provided through the contact/application/request forms available on our Website and our communication channels. |
| Customer / Visitor Transaction Data |
Sample order details, delivery records, records of actions taken and transaction history relating to your request, and information/content provided by you through website forms. |
Information provided through the contact/application/request forms available on our Website and our communication channels. |
| Request & Complaint Data |
Content of inquiries, questions, suggestions, feedback, complaints, and applications submitted via the website; selected request category, business area, subject, product/service, press contact requests, request date, and records of evaluations or responses provided. |
Information provided through the contact/application/request forms available on our Website and our communication channels. |
| Transaction Security Data |
IP address, date and time of access, log files, browser/device details, referrer URL, and session/system security logs generated during website usage. |
Information automatically collected when you visit the Website and use related IT systems |
| Marketing Data |
Subscription and communication preferences (if you opt-in to receive newsletters, announcements, or commercial electronic communications), message delivery logs, message open records, and link-click data. |
Information provided through subscription and preference management tools for receiving marketing communications, and information generated through your interactions with such communications, where applicable and based on your explicit consent. |
| Legal Transaction Data |
Records of data subject requests, correspondence with judicial or administrative authorities, official regulatory requests, legal disputes, and consent/rejection logs if website transactions become subject to legal proceedings. |
Information generated during the management of legal, regulatory, compliance and dispute resolution processes |
4. Purposes and Legal Bases for Processing Personal Data
Your personal data is processed in accordance with the conditions set forth in Article 6 of the EU General Data Protection Regulation (“GDPR”) as outlined below:
| Processing Activity |
Processed Personal Data |
Purpose of Processing |
Legal Basis under GDPR |
| Provision of our Website |
Transaction Security Data |
- Ensuring website security and preventing unauthorized access.
- Maintaining system safety, executing security audits, and keeping technical logs of website traffic.
|
Art. 6(1)(f) GDPR (Legitimate Interest): Our legitimate interest is to maintain secure IT operations and protect our network against cyber threats. |
| Contacting Us (via Online Forms or E-mail) |
Identity, Contact, Professional Data, Customer / Visitor Transaction Data, Request & Complaint, and Legal Transaction Data |
- Receiving and evaluating questions, requests, suggestions, commercial offers, business collaborations, or proposals submitted through website forms or direct corporate emails.
- Forwarding inquiries to relevant internal business units, resolving them, and communicating back to you
- Managing pre-contractual communication processes.
- Assessing feedback regarding our products and services.
|
Art. 6(1)(b) GDPR (Contractual/Pre-contractual Measures): Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Art. 6(1)(f) GDPR (Legitimate Interest): Processing is necessary for our legitimate business interests, provided they do not override your fundamental rights and freedoms. Our interest is to effectively manage customer relations, respond to public inquiries, and improve our services.
|
| Newsletter Subscription |
Contact, Professional Data, Customer / Visitor Transaction Data, Legal Transaction, and Marketing Data |
- Sending newsletters, event invitations, corporate announcements, campaigns, promotions, and other commercial electronic communications.
- Managing commercial communication opt-in and opt-out preferences.
- Keeping consent/refusal logs to fulfill legal audit obligations.
- Measuring the effectiveness and engagement of sent communications (open rates, link clicks) and implementing marketing improvements.
|
Art. 6(1)(a) GDPR (Explicit Consent): The data subject has given consent to the processing of his or her personal data for these specific purposes. |
| Compliance with Legal Obligations & Defense of Claims |
Identity, Contact, Professional Data, Customer / Visitor Transaction Data, Request & Complaint, Legal Transaction, Marketing, and Transaction Security Data |
- Receiving, evaluating, and finalizing data subject access requests (DSAR) in accordance with the law.
- Fulfilling requests from judicial or administrative authorities.
- Complying with legal obligations under applicable European laws.
- Retaining submitted requests and responses to prevent or resolve potential legal disputes.
- Establishing, exercising, or defending legal claims.
|
Art. 6(1)(c) GDPR (Legal Obligation): Processing is necessary for compliance with a legal obligation to which the controller is subject.
Art. 6(1)(f) GDPR (Legitimate Interest): Our legitimate interest lies in the establishment, exercise, or defense of legal claims.
|
The provision of your personal data is generally voluntary. However, some data (such as Transaction Security Data when browsing, or your name and email address when using contact forms) are necessary for technical reasons or to process your requests. If you choose not to provide this mandatory data, we will not be able to display our website to you or process and respond to your inquiries.
We do not use automated decision-making or profiling mechanisms under Article 22 (1) and (4) GDPR that have legal or equivalent consequences for you. While we may use basic website analytics cookies to optimize your browsing experience based on your consent, these activities do not constitute automated decision-making with legal or significant effects on your personal status.
5. Data Transfers & Recipients
To fulfill the purposes described in this Policy, your personal data may be shared with specific categories of recipients. We execute these transfers strictly in accordance with Articles 6, 28, and 44–49 of the GDPR:
- Suppliers and Technical Service Providers: We work with trusted external service providers who supply hosting services, IT maintenance, system administration, cloud storage, and email distribution infrastructure. These partners act as Data Processors on our behalf under strict Data Processing Agreements (Art. 28 GDPR).
- Şişecam Group Companies (Affiliates & Subsidiaries): If your inquiry, request, or commercial proposal relates directly to the operations of a specific Şişecam subsidiary, we will route your data to the relevant local entity so they can resolve your request.
- Authorized Public Authorities & Legal Representatives: We may disclose your data to regulatory bodies, judicial authorities, or external legal advisors to comply with a binding legal obligation or to defend our rights.
- International Transfers (Turkey and Third Countries): Since our parent company (Türkiye Şişe ve Cam Fabrikaları A.Ş.) is located in Turkey (outside the EU/EEA), your data will be transferred internationally when you use our website forms. To guarantee an adequate and safe level of data protection:
- We have implemented the European Commission’s approved Standard Contractual Clauses (SCCs) (pursuant to Art. 46(2)(c) GDPR).
- We maintain robust Technical and Organizational Measures (TOMs), including strict end-to-end encryption, network firewalls, and rigorous internal access permissions.
6. Data Retention Periods
We store your personal data only for as long as necessary to fulfill the processing purposes outlined in this Policy, or to satisfy applicable statutory retention periods under tax, corporate, or commercial laws.
When the processing purposes are complete, your consent is withdrawn, or the legal retention timelines expire, we will securely delete, destroy, or permanently anonymize your personal data so that it can no longer be linked to you, in accordance with Art. 17 GDPR.
7. Your Data Subject Rights under GDPR
Under Articles 15 to 22 of the GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15 GDPR): You have the right to request confirmation of whether we process your data and to receive a copy of your personal data along with detailed explanations.
- Right to Rectification (Art. 16 GDPR): You have the right to request the correction of inaccurate or incomplete personal data.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): You can request the deletion of your personal data under specific conditions (e.g., if the data is no longer needed or if you withdraw your consent).
- Right to Restriction of Processing (Art. 18 GDPR): You can request that we limit how we use your data under certain circumstances (such as when you challenge the accuracy of the data).
- Right to Data Portability (Art. 20 GDPR): You can request to receive your data in a structured, commonly used, and machine-readable format, and ask us to transmit it to another data controller.
- Right to Object (Art. 21 GDPR): You have the right to object to processing that is based on our legitimate interests (Art. 6(1)(f) GDPR) due to reasons relating to your specific personal situation.
- Right to Withdraw Consent (Art. 7(3) GDPR): If we process your data based on your consent, you can withdraw your consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
How to Exercise Your Rights
If you have any questions about this Privacy Policy, your data protection rights, or if you wish to submit a data subject request, please contact our Data Protection Team using one of our channels below:
By email:
By postal mail:
Türkiye Şişe ve Cam Fabrikaları A.Ş., İçmeler Mahallesi, D-100 Karayolu Caddesi No:44/A Tuzla / İstanbul, Turkey.
8. Right to Lodge a Complaint with a Supervisory Authority
Pursuant to Art. 77 GDPR, you have the right to lodge a complaint with a competent supervisory authority, in the Member State of your habitual residence, place of work, or place of the alleged infringement.
If, after contacting us, you believe that your rights have not been respected or that data processing does not comply with privacy protection regulations, you have the right to file a complaint with your competent supervisory authority.