1
Who is the data controller?
This text has been prepared by the company providing the eticaret.shop service. Your personal data is processed in the capacity of data controller under Turkish Personal Data Protection Law No. 6698 (KVKK).
- Address: Avşar Mah. Batı Çevre Yolu Bulvarı, KSÜ Avşar Kampüsü Teknokent, Bina No: 259, Ground Floor, No: 13
- Contact: the channels listed in the contact section below
Trade name, MERSIS number and registered e-mail (KEP) address must be completed from the panel.
2
What data do we process?
We collect only the data needed to provide the service. What we collect depends on the kind of relationship we have with you.
- Visitor: IP address, browser and device information, pages visited, cookie records.
- Form submissions: full name, e-mail, phone, company name, city, message content and any files sent.
- Customer: billing and subscription details, domain, panel user records, support correspondence.
- Job applicant: the education and experience details shared in your CV, together with your contact details.
3
For what purpose and on what legal basis do we process your data?
Every piece of data is tied to a specific and legitimate purpose. When the purpose no longer applies, the data is deleted.
- Formation and performance of a contract: opening your account, running the subscription, billing and technical support.
- Legitimate interest: service security, prevention of misuse, measuring service quality.
- Explicit consent: marketing messages and non-essential cookies. You may withdraw your consent at any time.
- Legal obligation: keeping the records required by tax, commercial and e-commerce legislation.
4
Who do we share your data with?
We do not sell your personal data. We share it only with the parties strictly necessary to deliver the service, and only as far as necessary.
- Hosting and infrastructure providers
- Payment institutions and banks
- E-invoice, accounting and courier integration providers
- Public authorities legally entitled to request information
Where a transfer abroad is required, the conditions set out in the KVKK are observed.
5
How long do we keep the data?
The retention period is determined by the purpose of processing and the limitation periods set out in the relevant legislation.
- Form records: at most two years from the resolution of the request.
- Customer and invoice records: for the period required by legislation (as a rule, ten years).
- Job applications: one year from the date of application; kept for future roles if you consent.
- Server and security logs: at most one year.
Once the period expires the data is deleted, destroyed or anonymised.
6
Your rights under the KVKK
Article 11 of the law grants you the following rights. You may submit your request through the channels in the contact section, and it will be concluded within thirty days at the latest.
- To learn whether your personal data is processed and, if so, to request information about it
- To learn the purpose of processing and whether the data is used in line with that purpose
- To know the third parties to whom the data is transferred, in Turkiye or abroad
- To request correction of incomplete or inaccurate data
- To request deletion or destruction where the conditions are met
- To request that correction, deletion and destruction be notified to the third parties concerned
- To object to a result reached against you through analysis by automated systems
- To claim compensation where you suffer loss due to unlawful processing
7
Cookies
Cookies are small files stored in your browser to make the site usable and to measure how it is used.
- Essential cookies: required for session management and security; they cannot be switched off.
- Preference cookies: remember settings such as your language choice.
- Measurement cookies: let us see which pages are used, in aggregate and without identifying you; they run only with your explicit consent.
You can delete or block cookies from your browser settings; if you do, parts of the site may not work.
8
Data security
We apply administrative and technical measures to protect your data against unauthorised access, loss and misuse.
- TLS encryption in transit
- Role-based access with logging
- Regular backups
- Access limited to staff who need it for their work
Even so, no transmission over the internet can promise absolute security.
9
Changes to this text
We update this text when legislation or our services change. The current version is always published on this page, and for significant changes we also notify our registered users.
10
Contact
You can submit requests and questions about your personal data through the channels on our contact page. Please include the information we need to verify your identity.