PERSONAL DATA PROTECTION POLICY
Information Notice Under Law No. 6698 on the Protection of Personal Data
PROTECTION OF PERSONAL DATA
1.1 Introduction
The protection of personal data is among the highest priorities of HEJAZIAN GLOBAL GROUP TEKSTİL TİCARET LİMİTED ŞİRKETİ (the "Company"), and the Company exercises the utmost care to comply with all applicable legislation in this regard. The most important element of this commitment is this HEJAZIAN GLOBAL GROUP TEKSTİL TİCARET LİMİTED ŞİRKETİ Policy (the "Policy"). This Policy explains the principles adopted in carrying out the personal data processing activities undertaken by our Company, as well as the fundamental principles adopted to ensure that our Company's data processing activities comply with the regulations set out in Law No. 6698 on the Protection of Personal Data (the "Law"). In doing so, our Company provides the necessary transparency by informing personal data owners. Fully aware of our responsibility in this regard, your personal data is processed and protected within the scope of this Policy.
1.2 Scope
This Policy applies to all personal data of persons other than our Company's employees and interns, processed by automated means or by non-automated means provided that it forms part of any data recording system. The Company's activities regarding the protection of our employees' personal data are governed under HEJAZIAN GLOBAL GROUP TEKSTİL TİCARET LİMİTED ŞİRKETİ, drawn up in parallel with the principles of this Policy.
1.3 Identity of the Data Controller
Pursuant to Article 10 of the Law, the identity and contact information of HEJAZIAN GLOBAL GROUP TEKSTİL TİCARET LİMİTED ŞİRKETİ, in its capacity as data controller, is set out below:
Trade Name: HEJAZIAN GLOBAL GROUP TEKSTİL TİCARET LİMİTED ŞİRKETİ
Address: Gökevler Mah. 2312. Sk. Halk Kent Çarşı No: 30/1 İç Kapı No: 6, Esenyurt/İstanbul
Tax Office: Esenyurt Tax Office
Tax Identification No: 4611106139
Telephone: +90 212 823 02 56
E-mail: info@nemotti.com / customercare@nemotti.com
KEP (Registered Electronic Mail) Address: hejazianglobalgroup@hs01.kep.tr
MATTERS RELATING TO THE PROCESSING OF PERSONAL DATA
2.1 Principles of Processing Personal Data
Our Company processes personal data in accordance with the procedures and principles set out in the Law and other relevant legislation. Accordingly, our Company processes personal data in compliance with the law and rules of good faith; accurately and, where necessary, kept up to date; for specified, explicit, and legitimate purposes; in a manner connected with, limited to, and proportionate to the purposes for which they are processed; and for the period stipulated in the relevant legislation or required for the purpose for which they are processed.
2.2 Processing of Personal Data
2.2.1 Processing of Personal Data
The explicit consent of the personal data owner is only one of the legal bases that make the lawful processing of personal data possible. Where one of the conditions set out below exists, personal data may be processed by our Company without seeking the explicit consent of the data owner. The basis for a personal data processing activity, apart from explicit consent, may be one of the following conditions, or more than one condition may form the basis of the same processing activity: where expressly provided for by law; where it is necessary to protect the life or physical integrity of the data owner or another person who is unable to give consent due to actual impossibility; where it is directly related to the establishment or performance of a contract; where it is necessary for the Company to fulfil a legal obligation; where the personal data has been made public by the data owner; where it is mandatory for the establishment or protection of a right; and where it is mandatory for the legitimate interests of our Company, provided that the balance of interests between our Company and the data owner is observed.
2.2.2 Processing of Special Categories of Personal Data
Some personal data is separately regulated as "special categories of personal data" and is subject to special protection. Because of the risk that unlawful processing may cause harm to individuals or expose them to discrimination, particular importance is attached to such data. Special categories of personal data are processed by our Company in accordance with the principles set out in this Policy, taking all necessary administrative and technical measures — including the methods to be determined by the Personal Data Protection Board (the "Board") — and where the following conditions exist:
(i) Special categories of personal data other than those concerning health and sexual life may be processed with the explicit consent of the data owner, or without seeking explicit consent in cases expressly provided for by law.
(ii) Special categories of personal data concerning health and sexual life may be processed with the explicit consent of the data owner, or without seeking explicit consent by persons under a duty of confidentiality or by authorized institutions and organizations, for the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning and management of healthcare services and their financing.
2.3 Purposes of Processing Personal Data
Within the scope of the conditions for processing personal data and special categories of personal data detailed in this Policy in accordance with the Law and other relevant legislation, our Company's purposes for processing personal data are as follows:
Carrying out the necessary work by our relevant business units for the performance of the commercial activities conducted by the Company and executing the associated business processes; planning and execution of supply chain management processes; monitoring of finance and accounting matters; planning and execution of logistics activities; planning and execution of the Company's human resources policies and processes; fulfilment of obligations arising from employment contracts and legislation for Company employees; planning and execution of employees' data access authorizations; planning and execution of the Company's commercial and business strategies; carrying out the necessary work by our business units to enable relevant persons to benefit from the products and services offered by the Company and executing the associated business processes; planning and execution of the sales processes of products and services; planning and execution of after-sales support service activities; planning and execution of customer relationship management processes; monitoring of contractual processes and legal claims; monitoring of customer requests and complaints; planning and execution of the activities required to recommend and promote the products and services offered by the Company to relevant persons by customizing them according to their preferences, usage habits, and needs; and ensuring the legal, technical, and commercial-business security of the Company and the relevant persons in a business relationship with the Company.
2.4 Categories of Personal Data Processed by Our Company
Within the framework of the purposes and conditions set out in this Policy and in accordance with the Law and other relevant legislation, our Company processes the following categories of personal data: identity information, visual and auditory information, financial information, legal transaction and compliance information, information on family members and relatives, CV, contact information, vehicle information, education information, physical premises security information, customer transaction information, marketing information, audit and inspection information, transaction security information, job candidate information, personnel file information, request and complaint management information, insurance information, location information, reputation management information, marital status information, fringe benefits and interests information, special categories of personal data, customer information, business partner information, and business information.
MATTERS RELATING TO THE TRANSFER OF PERSONAL DATA
In line with lawful personal data processing purposes and by taking the necessary security measures, our Company may transfer personal data and special categories of personal data to third parties ("Third Parties") within and/or outside Turkey. In doing so, our Company acts in accordance with the regulations set out in Articles 8 and 9 of the Law.
3.1 Transfer of Personal Data
Personal data may be transferred to Third Parties where the data owner's explicit consent exists, and — where the following conditions exist — without seeking the data owner's explicit consent, exercising due care and taking all necessary security measures, including the methods stipulated by the Board:
- Where the relevant activity concerning the transfer of personal data is expressly provided for by law;
- Where the transfer of personal data by the Company is directly related and necessary to the establishment or performance of a contract;
- Where the transfer of personal data is mandatory for the Company to fulfil its legal obligation;
- Where the personal data has been made public by the data owner, provided that the transfer by the Company is limited to the purpose of such disclosure;
- Where the transfer of personal data by the Company is mandatory for the establishment, exercise, or protection of the rights of the Company, the data owner, or third parties;
- Where it is mandatory to transfer personal data for the legitimate interests of the Company, provided that it does not harm the fundamental rights and freedoms of the data owner;
- Where it is mandatory to protect the life or physical integrity of a person who is unable to express consent due to actual impossibility, or whose consent is not legally valid, or of another person.
Where personal data is to be transferred abroad, in addition to the conditions above, our Company transfers personal data to foreign countries declared by the Board to have adequate protection ("Foreign Country with Adequate Protection"), or — in the absence of adequate protection — to foreign countries where the data controllers in Turkey and in the relevant foreign country undertake adequate protection in writing and the Board's authorization exists ("Foreign Country with a Data Controller Undertaking Adequate Protection").
3.2 Transfer of Special Categories of Personal Data
Our Company may transfer special categories of personal data within Turkey or abroad in line with lawful data processing purposes, exercising due care and taking the necessary security measures — including the methods stipulated by the Board — where the following conditions exist:
(i) Special categories of personal data other than those concerning health and sexual life may be transferred with the explicit consent of the data owner, or without seeking explicit consent in cases expressly provided for by law.
(ii) Special categories of personal data concerning health and sexual life may be transferred with the explicit consent of the data owner, or without seeking explicit consent by persons under a duty of confidentiality or by authorized institutions and organizations, for the purposes of protecting public health, preventive medicine, medical diagnosis, the provision of treatment and care services, and the planning and management of healthcare services and their financing. Where special categories of personal data are to be transferred abroad, in addition to the conditions above, our Company transfers such data to Foreign Countries with Adequate Protection or to Foreign Countries with a Data Controller Undertaking Adequate Protection.
3.3 Categories of Recipients to Whom Personal Data Is Transferred
In accordance with Articles 8 and 9 of the Law, our Company may transfer personal data to the following categories of recipient groups:
- Our suppliers
- Our business partners
- Courier and logistics companies (DHL)
- Legally authorized public institutions
- Legally authorized private institutions
RETENTION AND DESTRUCTION OF PERSONAL DATA
In accordance with the obligation to delete, destroy, or anonymize personal data set out in the Turkish Penal Code, the Law, and other relevant legislation, where the reasons requiring processing cease to exist — even though the data has been processed in accordance with the Law and other legislation — personal data is deleted, destroyed, or anonymized by our Company, either upon a decision taken by our Company on its own initiative or upon the request of the personal data owner.
ENSURING THE SECURITY AND CONFIDENTIALITY OF PERSONAL DATA
Our Company takes all necessary measures, to the extent possible and according to the nature of the data to be protected, to prevent the unlawful disclosure, access, or transfer of personal data, or other security lapses that may otherwise occur. In this context, our Company takes all necessary (i) administrative and (ii) technical measures, (iii) establishes an internal audit system, and (iv) acts in accordance with the measures stipulated in the Law in the event of the unlawful disclosure of personal data.
5.1 Administrative Measures Taken by Our Company to Ensure the Lawful Processing of Personal Data and to Prevent Unlawful Access to Personal Data
Our Company trains and raises the awareness of its employees regarding the processing and protection of personal data.
- Where personal data is subject to transfer, our Company ensures that provisions are added to the contracts concluded with the parties to whom personal data is transferred, requiring those parties to fulfil their obligations to ensure data security.
- The personal data processing activities carried out by our Company are examined in detail, and in this context, the steps to be taken to ensure compliance with the personal data processing conditions stipulated in the Law are identified.
- Our Company identifies the practices required to ensure compliance with the Law and regulates these practices through internal policies.
5.2 Technical Measures Taken by Our Company to Ensure the Lawful Processing of Data and to Prevent Unlawful Access to Personal Data
- Technical measures are taken to the extent permitted by technology regarding the processing and protection of personal data, and the measures taken are updated and improved in line with developments.
- Expert personnel are employed on technical matters.
- Audits are carried out at regular intervals regarding the implementation of the measures taken.
- Software and systems that ensure security are installed.
- Access authorization to the personal data processed within our Company is limited to the relevant employees in line with the defined processing purpose.
- In the protection of special categories of personal data, action is taken in accordance with the measures set out in the Law and other relevant legislation.
5.3 Measures to Be Taken in the Event of Unlawful Disclosure of Personal Data
Within the scope of the personal data processing activities carried out by our Company, in the event that personal data is unlawfully obtained by unauthorized persons, the situation will be reported to the Board and the relevant data owners without delay.
INFORMING PERSONAL DATA OWNERS
In accordance with Article 10 of the Law, our Company informs personal data owners at the time personal data is obtained. In this context, our Company provides information regarding the identity of our Company and its representative, if any; the purposes for which personal data will be processed; to whom and for what purpose the processed personal data may be transferred; the method and legal basis of personal data collection; and the rights of the personal data owner. Article 20 of the Constitution of the Republic of Turkey establishes that everyone has the right to be informed about their personal data. Accordingly, the right to "request information" is among the rights of the personal data owner set out in Article 11 of the Law.
In this context, in accordance with Article 20 of the Constitution and Article 11 of the Law, our Company provides the necessary information when the personal data owner requests it. Detailed information regarding the rights of the personal data owner is provided in Section 7.1 of this Policy ("Rights of the Personal Data Owner").
RIGHTS OF THE PERSONAL DATA OWNER AND THE EXERCISE OF THESE RIGHTS
7.1 Rights of the Personal Data Owner
The statutory rights that the data owner may exercise in relation to their personal data are set out below:
- To learn whether their personal data is being processed;
- To request information if their personal data has been processed;
- To learn the purpose of processing their personal data and whether it is used in accordance with that purpose;
- To learn the third parties to whom their personal data is transferred, within Turkey or abroad;
- To request the correction of their personal data if it has been processed incompletely or inaccurately, and to request that the action taken in this regard be notified to the third parties to whom the data has been transferred;
- To request the deletion, destruction, or anonymization of their personal data where the reasons requiring processing cease to exist — even though it has been processed in accordance with the Law and other relevant legislation — and to request that the action taken in this regard be notified to the third parties to whom the data has been transferred;
- To object to a result arising against them due to the exclusively automated analysis of their processed data;
- To request compensation for damages in the event that they suffer harm due to the unlawful processing of their personal data.
7.2 Cases in Which the Data Owner May Not Assert Their Rights
In the cases listed in Article 28 of the Law, personal data owners may not assert the rights listed in Section 7.1 ("Rights of the Personal Data Owner"), as these situations fall outside the scope of data protection set out in the Law. The cases listed under that article are as follows:
- The processing of personal data for purposes such as research, planning, and statistics by rendering it anonymous through official statistics;
- The processing of personal data for artistic, historical, literary, or scientific purposes, or within the scope of freedom of expression, provided that it does not violate national defense, national security, public safety, public order, economic security, the privacy of private life, or personal rights, and does not constitute a crime;
- The processing of personal data within the scope of preventive, protective, and intelligence activities carried out by public institutions and organizations legally authorized and assigned to ensure national defense, national security, public safety, public order, or economic security;
- The processing of personal data by judicial authorities or enforcement authorities in relation to investigation, prosecution, trial, or enforcement proceedings.
7.3 Exercise of Rights by Personal Data Owners
Personal data owners may submit their requests concerning the rights listed in Section 7.1 ("Rights of the Personal Data Owner") to our Company via nemotti.com, or by using a Registered Electronic Mail (KEP) address, Secure Electronic Signature, Mobile Signature, or an e-mail address you have previously notified to our Company and which is registered in our system.
7.4 Our Company's Response to Applications
Our Company takes all necessary administrative and technical measures to conclude applications made by the personal data owner effectively and in accordance with the law and the rule of good faith. Our Company may accept the personal data owner's application or may reject it by explaining its reasons. Our Company may communicate its response to the personal data owner in writing or electronically. Where the personal data owner submits their request concerning the rights under Section 7.1 ("Rights of the Personal Data Owner") to our Company in accordance with the stated procedures, our Company will conclude the request free of charge as soon as possible and within no later than 30 (thirty) days, depending on the nature of the request. However, if the process requires an additional cost, the fee stated below may be charged. Where our Company responds to the application in writing, no fee will be charged for up to ten pages; for each page over ten pages, a processing fee of 1 Turkish Lira may be charged, as set out in the Law and other relevant legislation.
GOVERNANCE STRUCTURE FOR THE PROTECTION AND PROCESSING OF PERSONAL DATA
By decision of the Company's senior management, a "Personal Data Protection Committee" has been established to manage this Policy and other policies connected and related to it. The duties of this committee are as follows:
- To prepare the fundamental policies on the protection and processing of personal data and submit them to senior management for approval and implementation;
- To decide how the implementation and audit of the policies on the protection and processing of personal data will be carried out, and, in this framework, to make internal assignments and ensure coordination, submitting these to senior management for approval;
- To identify the matters that need to be addressed to ensure compliance with the Law and other relevant legislation, submit them to senior management for approval, and oversee and coordinate their implementation;
- To raise awareness of the protection and processing of personal data within the Company and among the institutions with which the Company cooperates;
- To identify risks that may arise in the Company's personal data processing activities, ensure that the necessary measures are taken, and submit improvement recommendations to senior management for approval;
- To design training on the protection of personal data and the implementation of the policies created in this context, and to ensure their execution;
- To resolve the applications of personal data owners at the highest level;
- To coordinate the execution of information and training activities to ensure that personal data owners are informed about personal data processing activities and their statutory rights;
- To prepare changes to the fundamental policies on the protection and processing of personal data and submit them to senior management for approval and implementation;
- To follow developments and regulations regarding the protection of personal data and advise senior management on what needs to be done within the Company in line with these developments and regulations;
- To coordinate relations with the Board and the Personal Data Protection Authority;
- To carry out other duties assigned by the Company's senior management regarding the protection of personal data.
DEFINITIONS
Explicit Consent: Consent relating to a specific matter, based on information, and expressed with free will.
Personal Data Owner: The natural person whose personal data is processed.
Personal Data: Any information relating to an identified or identifiable natural person (e.g., name and surname, Turkish ID number, e-mail, address, date of birth, credit card number). Accordingly, the processing of information relating to legal entities is not within the scope of the Law.
Special Categories of Personal Data: Data relating to race; ethnic origin; political opinion; philosophical belief; religion, sect, or other beliefs; appearance and dress; membership of associations, foundations, or trade unions; health; sexual life; criminal convictions and security measures; and biometric and genetic data.
Processing of Personal Data: Any operation performed on personal data, such as obtaining, recording, storing, retaining, altering, reorganizing, disclosing, transferring, taking over, making obtainable, classifying, or preventing the use of data, by wholly or partly automated means or by non-automated means provided that it forms part of any data recording system.
Data Processor: The natural or legal person who processes personal data on behalf of the data controller based on the authority granted by the controller (e.g., the cloud computing company holding our Company's data, surveyors having customers sign forms, call center companies making calls within the framework of scripts).
Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system.
Registered Electronic Mail (KEP) Address: A qualified form of electronic mail that provides legal evidence regarding the use of electronic messages, including their transmission and delivery.
Mobile Signature: An electronic signature created using a mobile device.
Secure Electronic Signature: An electronic signature exclusively linked to the signatory, created with a secure electronic signature creation tool that is solely at the signatory's disposal, that enables the identification of the signatory based on a qualified electronic certificate, and that enables the detection of whether any subsequent alteration has been made to the signed electronic data.
PERSONAL DATA OWNERS
Person for Whom an Invoice Is Issued: The person whose information (personal data) is written on the invoice as a result of a purchase made with our Company.
Press: Members of the press contacted within the scope of our Company's corporate communication activities.
Employee and Intern Candidate: Natural persons who have applied for a job with our Company by any means, or who have made their CV and related information available for our Company's review.
Family Members of Employees: The family members and relatives of persons with whom our Company has established an employment contract.
Former Employee: Natural persons whose employment contract with our Company has ended for any reason (resignation, dismissal, retirement, etc.).
Business Partner Employee / Representative / Shareholder: Natural persons who are the shareholders, representatives, or employees of companies with which our Company has established cooperation or partnership — based on an existing contract — for purposes such as the sale, promotion, and marketing of our products and services and the operation of joint customer loyalty programs.
Customer: Natural persons who use or have used the products and services offered by our Company, regardless of whether there is any contractual relationship with our Company.
Client Company Shareholder and/or Legal Entity Shareholder Representative: Natural persons who are the shareholders, representatives, or employees of our legal entity customers who use or have used the products and services offered by our Company, regardless of any contractual relationship.
Potential Business Partner Representative / Employee / Shareholder: Natural persons who are the representatives, shareholders, or employees of legal entity companies with which our Company intends to establish cooperation, partnership, or program partnership in the future.
Potential Customer: Natural persons who have expressed a will to benefit from the products or services offered by our Company, or who our Company has assessed as likely to benefit from them.
Potential Supplier Representative / Employee / Shareholder: Natural persons who are the shareholders, representatives, or employees of companies that provide goods and/or services to our Company based on a contract likely to be established in the future.
Reference: Natural persons whose information has been shared for the purpose of conducting reference checks on candidates who have applied for a job with our Company.
Supplier Employee / Representative / Shareholder: Natural persons who are the shareholders, representatives, or employees of companies that provide goods and/or services to our Company based on an existing contract.
Person to Whom Delivery Will Be Made: Natural persons to whom our customers request the relevant product be delivered in purchases made with our Company.
Cargo Transfer in Return and Exchange Processes: All return and exchange transactions for the products offered by our Company are carried out exclusively through the courier company DHL. In this context, the personal data of the data owner requesting a return or exchange that is necessary for carrying out the return processes — such as name and surname, address, telephone number, and order information — is shared with DHL solely for the purpose of, and limited to, the receipt and transport of the relevant shipment. This transfer is carried out pursuant to Article 8 of the Law, on the legal grounds of the performance of the contract and the fulfilment of our Company's legal obligations.
Member Customer: Natural persons who use or have used the products and services offered by our Company as a member of our loyalty program.
Visitor: Natural persons who visit our Company's physical locations.
CATEGORIES OF PERSONAL DATA
Identity Information: All information contained in documents such as driver's licenses, ID cards, passports, and professional identity cards that clearly belong to an identified or identifiable natural person.
Contact Information: Telephone number, address, e-mail, and similar contact details that clearly belong to an identified or identifiable natural person.
Financial Information: Personal data processed in relation to information, documents, and records showing any financial result that clearly belongs to an identified or identifiable natural person, processed wholly or partly by automated means or as part of a data recording system by non-automated means.
Customer Information: Data obtained regarding the customer during the course of our commercial activities that clearly belongs to an identified or identifiable natural person.
Customer Transaction Information: Records regarding the use of our products and services, and information such as our customer's instructions and requests regarding the use of our products and services, that clearly belongs to an identified or identifiable natural person.
Transaction Security Information: Personal data processed to ensure the technical, administrative, legal, and commercial security of our Company while conducting our commercial activities, that clearly belongs to an identified or identifiable natural person.
Physical Premises Security Information: Personal data relating to records and documents taken upon entry to and during stay within physical premises, that clearly belongs to an identified or identifiable natural person.
Location Information: Information that determines the location of the personal data owner, that clearly belongs to an identified or identifiable natural person.
Audit and Inspection Information: Personal data processed within the scope of our Company's legal obligations and compliance with and audit of Company policies, that clearly belongs to an identified or identifiable natural person.
Legal Transaction and Compliance Information: Personal data processed within the scope of the determination and pursuit of our legal claims and rights, the fulfilment of our debts, and compliance with our legal obligations and Company policies, that clearly belongs to an identified or identifiable natural person.
Request/Complaint Management Information: Personal data relating to the receipt and evaluation of any request and/or complaint directed to our Company, that clearly belongs to an identified or identifiable natural person.
Family Members and Relatives Information: Information about the family members and relatives of our customers, employees, job candidates, and/or the personal data owners with whom we cooperate, that clearly belongs to an identified or identifiable natural person.
Visual and Auditory Data: Visual or auditory data such as photographs and videos that clearly belong to an identified or identifiable natural person.
Marketing Information: Personal data processed for the purpose of marketing our products and services by customizing them according to the usage habits, preferences, and needs of the personal data owner, and the reports and evaluations created as a result of such processing, that clearly belongs to an identified or identifiable natural person.
Vehicle Information: Information regarding vehicles associated with the data owner, that clearly belongs to an identified or identifiable natural person.
Job Candidate Information: The CV information of persons who have applied for a job with our Company by any means, and/or our employee and/or intern candidates.
Personnel File Information: Information forming the basis for the creation of the personnel rights and files of our employees and/or the employees of companies with which we cooperate, that clearly belongs to an identified or identifiable natural person.
Business Partner Information: Personnel information relating to the shareholders, representatives, or employees of our Company's current or potential suppliers, business partners, dealers, or authorized service providers, that clearly belongs to an identified or identifiable natural person.
Fringe Benefits and Interests Information: Personal data processed for the planning of fringe benefits and interests offered and to be offered to our employees, the determination of objective criteria for entitlement to them, and the monitoring of these entitlements, that clearly belongs to an identified or identifiable natural person.
Special Categories of Personal Data: Data relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations, or trade unions, health, sexual life, criminal convictions and security measures, and biometric and genetic data, that clearly belongs to an identified or identifiable natural person.
CATEGORIES OF THIRD PARTIES TO WHOM PERSONAL DATA IS TRANSFERRED
Business/Solution Partner: Parties with which our Company cooperates for purposes such as the sale, promotion, and marketing of our products and services, after-sales support, and the operation of joint customer loyalty programs while conducting our commercial activities.
Legally Authorized Public Institution: Public institutions or organizations authorized to request information and/or documents from our Company under the relevant legislation.
Legally Authorized Private Institution: Private institutions or organizations authorized to request information and/or documents from our Company under the relevant legislation.
Supplier: Parties that provide goods or services to enable our Company to sustain its commercial activities, in line with the instructions received from the Company and based on the contract between our Company and them.
APPENDIX — INFORMATION NOTICE ON THE PROCESSING OF CUSTOMER PERSONAL DATA (E-COMMERCE)
This section specifically governs, for our customers and site visitors who shop through the nemotti.com website, the methods by which personal data is collected, the legal grounds on which it is based, and how long it is retained. This section is an integral part of this Policy.
A. Personal Data Processed, Collection Methods, and Legal Grounds
Customer personal data is processed as shown in the table below, indicating the method by which each item of data is collected and the legal ground under Article 5 of the Law on which it is based:
Personal Data ProcessedCollection MethodLegal Ground (KVKK Art. 5)Name and surname, delivery/billing address, telephone, e-mailOrder/payment (checkout) pageEstablishment and performance of the contract — Art. 5/2-cOrder content, amount, order historyCheckout and post-sale transactionsPerformance of the contract — Art. 5/2-cPayment information (card, iyzico transaction data)Via the iyzico payment infrastructurePerformance of the contract — Art. 5/2-cInvoice and accounting recordsOrder completionLegal obligation — Art. 5/2-çReturn/exchange and request-complaint informationContact form, e-mail, DHL return processPerformance of the contract and legal obligation — Art. 5/2-c, çMembership information (account, password hash, preferences)Membership/registration formExplicit consent / performance of the contract — Art. 5/1, Art. 5/2-cE-mail/SMS marketing, campaign communicationsNewsletter registration, account preferencesExplicit consent — Art. 5/1 (with İYS approval)Mandatory cookies (session, cart, security)Website cookiesLegitimate interest — Art. 5/2-fAnalytics and advertising cookies/pixels (Meta, Google)Website cookies/pixelsExplicit consent — Art. 5/1 (with cookie approval)Traffic and transaction security data (IP, log)Automatically by systemsLegal obligation and legitimate interest — Art. 5/2-ç, f
For processing activities based on explicit consent (marketing messages, non-mandatory cookies and pixels, and certain preferences within the scope of membership), you may withdraw the explicit consent you have given at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
B. Purposes of Processing Customer Data
- Receiving, preparing, and delivering orders and carrying out payment transactions
- Conducting return and exchange processes (returns and exchanges are carried out exclusively through the courier company DHL)
- Issuing invoices and fulfilling financial/legal obligations
- Creating and managing the membership account
- Responding to requests, questions, and complaints and conducting customer relations
- Sending campaign and marketing messages by e-mail and SMS where explicit consent exists
- Operating the website, ensuring its security, and improving the user experience
C. Retention Periods for Customer Data
Customer personal data is retained for the period required by the processing purpose and taking into account the minimum periods stipulated in the relevant legislation. At the end of the period, the data is deleted, destroyed, or anonymized. The main retention periods are as follows:
Data CategoryRetention PeriodInvoice, accounting, and financial records10 years under the Tax Procedure Law and the Turkish Commercial CodeOrder and delivery/return records10 years from the end of the contractual relationship (throughout the statute of limitations)Membership account dataAs long as the membership continues; deleted/anonymized within a reasonable time after the account is closedRequest, complaint, and communication records3 years from the creation of the recordMarketing permission and commercial electronic message approvalsUntil the approval is withdrawn; 3 years after withdrawal as required by İYS legislationMandatory / session cookiesFor the duration of the session or a maximum of 1 yearAnalytics and advertising cookies/pixelsA maximum of 2 years depending on the relevant cookie type, or until consent is withdrawnTraffic and transaction security log recordsFor the minimum period under the relevant legislation (as a rule, 2 years)
The above periods are of a minimum/maximum framework nature; in the event of legislative changes or an ongoing legal dispute, the relevant data may be retained throughout the statute of limitations periods.