CAGS Privacy Policy
Effective: 24 June 2026 | Last Updated: 24 June 2026 | Next Review: June 2027
1. Introduction & Data Controller
CAGS TOBACCO AND TOBACCO PRODUCTS INDUSTRY AND TRADE JOINT STOCK COMPANY ("CAGS", "we", "us", or "our") is committed to protecting the personal data of all individuals who interact with our business globally. We operate as a global B2B manufacturer and distributor of rolling papers, cigarette tubes, RYO/MYO tobacco, shisha tobacco, and smoking accessories, serving markets across Europe, the Middle East, Asia, Africa, and the Americas.
This Privacy Policy explains what personal data we collect, why we collect it, how we process and protect it, how long we retain it, and the rights available to individuals worldwide. It applies to all individuals interacting with CAGS — including website visitors, customers, business partners, job applicants, employees, and platform users — regardless of their location.
CAGS processes personal data in compliance with all applicable international data protection laws, including but not limited to:
- Turkey — Law on Protection of Personal Data No. 6698 (KVKK)
- European Union — General Data Protection Regulation (GDPR) EU 2016/679
- EU AI Act (applicable from 2025 onwards)
- ePrivacy Directive 2002/58/EC (as amended)
- Google EU User Consent Policy & 2026 Compliance Requirements
- All other applicable national and international data protection laws in markets where CAGS operates
- Company Name: CAGS TOBACCO AND TOBACCO PRODUCTS INDUSTRY AND TRADE JOINT STOCK COMPANY
- Registered Address: Fulya Mahallesi, Buyukdere Caddesi, Torun Center A Blok No: 74A, Ic Kapi No: 19, Sisli / Istanbul, Turkey
- Website: www.cagsgrp.com
- Email: info@cagsgrp.com
2. Scope of This Policy
This Privacy Policy covers all personal data collected through:
- Our website at www.cagsgrp.com and any associated subdomains
- Email, telephone, and direct business communications
- Printed forms and in-person interactions at our offices or events
- Third-party platforms and tools used in our business operations
- Employment and recruitment processes
- B2B commercial transactions and partnerships
3. What Personal Data Do We Collect?
We process the following categories of personal data, each collected for specific lawful purposes:
3.1 Identity Information
- Collected from: Job applicants, employees, customers, platform users, business partners, and visitors.
- Includes: Full name, gender, national ID number, social security number, nationality, marital status, date and place of birth, passport number, driver's licence details, vehicle registration, and copies of identity documents.
Legal Basis:
- Legal obligation — compliance with employment, tax, social security, and trade regulations
- Contractual necessity — performance of B2B commercial agreements
- Legitimate interests — security, audit, fraud prevention, and marketing activities
- Consent — where explicitly requested
3.2 Contact Information
- Collected from: All categories of individuals interacting with CAGS.
- Includes: Email address, home and business address, company name and title, telephone and fax numbers.
Legal Basis: Legal obligation, contractual necessity, and legitimate interests.
3.3 Financial Information
- Collected from: Employees and commercial customers.
- Includes: Bank account and card details, invoice and payment records, income and asset data, payroll records, and tax-related information.
Legal Basis:
- Legal obligation — tax, employment, and financial regulatory compliance
- Contractual necessity — payment processing and commercial fulfilment
3.4 Employment & Education Information
- Collected from: Employees and job applicants.
- Includes: Job title, qualifications and certificates, CV/resume, employment history, health and insurance records, and statutory employment documentation.
Legal Basis:
- Legal obligation — employment and social security law
- Contractual necessity — performance of employment contract
3.5 Technical & Website Usage Data
- Collected from: All visitors to www.cagsgrp.com.
- Includes: Anonymised IP address, browser type, device type, operating system, pages visited, session duration, geographic region, and traffic source.
Legal Basis:
- Consent — for analytics and tracking cookies (via our Cookie Consent Banner)
- Legitimate interests — for strictly necessary technical data
3.6 Visitor & Security Data
- Collected from: Physical visitors to CAGS premises.
- Includes: Name of person visited, purpose of visit, date and time.
Legal Basis: Legal obligation and legitimate interests — security and future service relationships.
4. How Long Do We Retain Your Data?
CAGS retains personal data only for as long as necessary for the purposes for which it was collected, and in line with applicable legal requirements:
- Statutory period applies: Data is retained for the legally required minimum period in the relevant jurisdiction, plus a buffer of 6–12 months to accommodate potential court orders, regulatory requests, or disputes. Data is then securely deleted or anonymised at the end of this extended period.
- No statutory period: Data is retained for the duration of the relevant relationship or contract. Upon termination, data is deleted, destroyed, or anonymised automatically — without requiring a separate request.
- Website/Cookie data (Google Analytics): Retained for a maximum of 14 months, in line with Google Analytics 4 default settings, unless a shorter period is configured.
- Deletion requests: Where data is subject to a statutory retention period, early deletion requests cannot be fulfilled. Where no statutory period applies and there is no remaining processing purpose, deletion will be completed within a maximum of 6 months of your request.
5. Do We Share Your Data with Third Parties?
CAGS shares personal data only where strictly necessary and in full compliance with applicable law. Your data may be shared with:
5.1 Legal & Regulatory Authorities
- Turkish governmental and regulatory authorities as required by KVKK and applicable legislation
- Authorised administrative institutions upon lawful request
- Courts of law pursuant to a valid court order
5.2 Business Partners & Service Providers
- Financial advisors and accounting firms
- Logistics and international shipping companies
- IT service providers and cloud hosting platforms
- HR and recruitment service providers
- Marketing and analytics platforms (see Section 7)
CAGS does not sell, rent, or trade your personal data to any third party for commercial purposes.
6. International Data Transfers
As a global business, CAGS may transfer personal data to recipients in countries outside Turkey and the European Economic Area (EEA). Such transfers are conducted only when one of the following appropriate safeguards is in place:
- Adequacy decisions — transfers to a country recognised as providing an adequate level of data protection by the KVKK Board or the EU Commission.
- Standard Contractual Clauses (SCCs) — EU Commission-approved transfer mechanisms.
- Binding Corporate Rules (BCRs) — where applicable.
- Data Processing Agreements (DPAs) — GDPR Article 28 compliant, with all processors.
- KVKK Board approval — for transfers of Turkish personal data where required.
- Explicit written consent — where none of the above mechanisms apply and consent is the most appropriate basis.
7. Cookies & Tracking Technologies
Our website www.cagsgrp.com uses cookies and similar tracking technologies to enhance your experience, analyse site traffic, and support our marketing activities. In accordance with the ePrivacy Directive and GDPR, non-essential cookies are only set after you have given your explicit consent.
7.1 Types of Cookies We Use
- Strictly Necessary Cookies: Essential for the website to function. These cannot be disabled and no consent is required. Examples: session cookies, security tokens.
- Analytics Cookies: Used to understand how visitors interact with our website. These require your consent before activation. We use Google Analytics 4 (GA4) for this purpose.
- Marketing & Preference Cookies: Used to personalise content and advertising. These require your explicit consent.
- Third-Party Cookies: Set by third-party platforms embedded on our site (e.g., social media buttons, YouTube embeds). These parties have their own privacy policies.
7.2 Google Analytics Disclosure
CAGS uses Google Analytics 4 (GA4), a web analytics service provided by Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. In accordance with Google's Terms of Service and 2026 privacy requirements, we disclose the following:
- Data collected by GA4 includes: IP address (anonymised), browser type, device type, operating system, pages visited, session duration, geographic region, and traffic source.
- Google acts as a data processor on our behalf. A Data Processing Agreement (DPA) is in place with Google in compliance with GDPR Article 28.
- Data may be transferred to Google servers in the United States. Such transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission.
- We use Google Consent Mode v2 to ensure Google Analytics does not activate before user consent is obtained.
- GA4 data is retained for a maximum of 14 months.
- You may opt out of Google Analytics tracking at any time by installing the Google Analytics Opt-out Browser Add-on.
- Google Analytics Opt-out: tools.google.com/dlpage/gaoptout
- Google Privacy Policy: policies.google.com/privacy
- Google Ad Settings: adssettings.google.com
7.3 Managing Your Cookie Preferences
You can control and manage cookies through:
- Our Cookie Consent Banner: Displayed on your first visit. You may accept, reject, or customise your cookie preferences at any time.
- Browser Settings: Most browsers allow you to block or delete cookies. Please note that blocking essential cookies may affect website functionality.
- Third-Party Opt-Out Tools: Such as the Google Analytics Opt-out Add-on or the Network Advertising Initiative opt-out tool.
8. Consent Management
In accordance with GDPR Article 7, the ePrivacy Directive, and Google's EU User Consent Policy 2026, CAGS implements the following consent practices:
- Active Consent: We obtain clear, affirmative consent before setting any non-essential cookies or collecting analytics data. Pre-ticked boxes or implied consent are not used.
- Granular Consent: Users can accept or reject individual categories of cookies (e.g., analytics, marketing) independently.
- Consent Records: We maintain records of when and how consent was given, including the version of the policy in effect at the time.
- Right to Withdraw: You may withdraw consent at any time, as easily as it was given, by accessing our Cookie Preference Centre or contacting us directly. Withdrawal does not affect the lawfulness of processing prior to withdrawal.
- Re-Consent: We will request fresh consent if our data practices change materially or after 12 months, in line with best practices.
- Google Consent Mode v2: We have implemented Google Consent Mode v2 to ensure all Google tags (including Google Analytics and Google Ads) respect user consent choices and do not activate before valid consent is obtained.
9. AI & Automated Decision-Making
In accordance with the EU AI Act (effective 2025) and GDPR Article 22, CAGS discloses the following regarding the use of artificial intelligence and automated processing:
9.1 Use of AI Tools
CAGS may use AI-powered tools for the following limited purposes:
- Internal business operations: AI-assisted tools may be used for HR screening support, data analysis, or operational efficiency.
- Website analytics: GA4 uses machine learning to model user behaviour where consent data is incomplete.
- Customer communications: AI tools may be used to support response drafting for enquiries.
9.2 Automated Decision-Making
CAGS does not make any solely automated decisions that produce significant legal effects on individuals without human review. Where automated processing is used to support decisions (e.g., candidate pre-screening), a human review is always conducted before any final decision is made.
9.3 Your Rights Regarding AI
- Right to explanation: You may request a meaningful explanation of any automated process that affects you.
- Right to human review: You may request that any automated decision be reviewed by a human.
- Right to object: You may object to automated profiling or processing at any time.
To exercise these rights, please contact us at info@cagsgrp.com.
10. Data Security
CAGS implements appropriate technical and organisational security measures to protect personal data against unauthorised access, disclosure, alteration, or destruction, in accordance with GDPR Article 32 and KVKK requirements:
- SSL/TLS Encryption: All data transmitted through www.cagsgrp.com is encrypted using SSL/TLS technology.
- Access Controls: Access to personal data is restricted to authorised personnel only, on a need-to-know basis, with role-based permissions for internal systems.
- Multi-Factor Authentication (MFA): Systems containing personal data are protected by strong authentication mechanisms, including MFA.
- Data Minimisation: We collect only the personal data necessary for the stated processing purpose.
- Regular Security Audits: Our systems and data processing activities are reviewed periodically through audits and vulnerability assessments to identify and address weaknesses.
- Vendor Security: All third-party processors handling personal data on our behalf must meet equivalent security standards, as required by GDPR Article 28 under a DPA.
- Breach Response Plan: We maintain a documented incident response and data breach procedure (see Section 11).
While we implement robust security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to applying industry best practices at all times.
11. Data Breach Notification
- Internal detection: CAGS maintains monitoring systems to detect breaches promptly.
- Regulatory notification: In the event of a breach posing risk to individuals, CAGS notifies the relevant supervisory authority (the KVKK Board and/or applicable national data protection authority) within 72 hours.
- Individual notification: Affected data subjects are informed without undue delay where the breach poses a high risk to their rights and freedoms.
- Documentation: All breaches are documented, including the facts, effects, and remedial actions taken.
12. Children's Data Protection
CAGS's website, products, and services are not directed at individuals under the age of 18. Tobacco and related products are strictly age-restricted in all markets in which we operate.
- We do not knowingly collect personal data from children under 18 years of age.
- Our website does not contain content directed at minors, and we do not conduct marketing targeting individuals under 18.
- If we become aware that personal data has been inadvertently collected from a minor, we will delete such data immediately.
If you are a parent or guardian and believe your child has submitted personal data to us, please contact us immediately at info@cagsgrp.com so we can take appropriate action.
13. Data Protection Officer (DPO) & Privacy Contact
CAGS has designated a Privacy Contact responsible for overseeing data protection compliance and handling data subject enquiries:
Privacy & Data Protection Contact
- CAGS TOBACCO AND TOBACCO PRODUCTS INDUSTRY AND TRADE JOINT STOCK COMPANY
- Fulya Mahallesi, Buyukdere Caddesi, Torun Center A Blok No: 74A, Ic Kapi No: 19, Sisli / Istanbul, Turkey
- Email: info@cagsgrp.com
- Website: www.cagsgrp.com/contact
All data protection enquiries, subject access requests, and complaints will be directed to this contact and handled in accordance with the timescales set out in Section 16.
14. Data Protection Complaints Procedure
CAGS is committed to resolving all data protection concerns promptly and transparently. If you have a complaint about how we process your personal data:
- Step 1 — Contact CAGS Directly: Submit your complaint in writing to info@cagsgrp.com or by post to our registered address. Include your full name, contact details, a description of the concern, and any supporting information.
- Step 2 — Acknowledgement: We will acknowledge receipt of your complaint within 30 calendar days of receiving it, confirm the steps we are taking to investigate, and provide an estimated resolution timeline.
- Step 3 — Investigation & Response: CAGS will investigate all complaints thoroughly and provide a written response within 60 calendar days. We maintain a record of all complaints received, the investigation conducted, actions taken, and the outcome.
- Step 4 — Escalation to Supervisory Authority: If you are not satisfied with our response, you may escalate your complaint to the relevant data protection supervisory authority in your country. Key authorities include:
- Turkey: Kişisel Verileri Koruma Kurumu (KVKK) — www.kvkk.gov.tr
- European Union: Your national Data Protection Authority (DPA) — edpb.europa.eu/about-edpb/board/members
- International: The supervisory authority of the country in which the alleged infringement took place
15. Your Rights as a Data Subject
Regardless of your location, CAGS respects the following internationally recognised data subject rights:
- Right to be Informed: To receive clear information about how your data is processed.
- Right of Access: To request a copy of the personal data we hold about you.
- Right to Rectification: To request correction of inaccurate or incomplete data.
- Right to Erasure: To request deletion where data is no longer necessary or consent is withdrawn.
- Right to Restriction: To request that processing be restricted in certain circumstances.
- Right to Data Portability: To receive your data in a structured, machine-readable format.
- Right to Object: To object to processing based on legitimate interests or for direct marketing.
- Right to Object to Automated Decision-Making: To request human review of automated decisions.
- Right to Withdraw Consent: At any time, where processing is based on consent.
- Right to Lodge a Complaint: With the relevant supervisory authority in your jurisdiction.
- Right to Compensation: For damages arising from unlawful processing of your personal data.
16. How to Exercise Your Rights
Data subjects may submit requests using any of the following methods:
16.1 By Email
Send your signed request or the CAGS PDPA Application Form, along with a copy of your valid identity document, to info@cagsgrp.com.
16.2 By Post or In Person
Fulya Mahallesi, Buyukdere Caddesi, Torun Center A Blok No: 74A, Ic Kapi No: 19, Sisli / Istanbul, Turkey.
16.3 Required Information
All requests must include: full name, signature (where written), national ID or passport number, correspondence address, email address, telephone number, a clear description of the request, and any supporting documents. Third-party requests require a duly executed power of attorney.
16.4 Response Timeframe
CAGS will respond to all data subject requests within a maximum of 30 calendar days from the date of receipt. Where a request is rejected, written reasons will be provided.
17. Policy Updates & Notification
CAGS reviews this Privacy Policy at least annually, and whenever there is a material change to our data processing activities, applicable laws, or the tools and services we use.
- Where changes are minor or administrative, we will update the 'Last Updated' date at the top of this policy.
- Where changes are material — such as new categories of data collected, new purposes, or new third-party processors — we will provide prominent notice on our website and, where appropriate, notify affected individuals directly by email.
Continued use of our website or services after the effective date of any update constitutes acceptance of the revised policy. We encourage all users to review this policy periodically to stay informed of how we protect your data.
Related Policies & Links
- Cookie Policy: www.cagsgrp.com/cookie-policy
- Terms & Conditions: www.cagsgrp.com/terms-and-conditions
- Accessibility Statement: www.cagsgrp.com/accessibility
- Data Complaints Policy: www.cagsgrp.com/complaints
- CAGS Products: www.cagsgrp.com/products
- KVKK Authority: www.kvkk.gov.tr
- Google Privacy Policy: policies.google.com/privacy
