Personal Data and General Confidentiality Agreement
Personal Data and General Privacy Policy
Last Updated: 20 September 2017
Netislem Bilgi Teknolojileri. (Hereinafter referred to as "Netislem".) Netislem will not share, sell or allow the use of the personal data transmitted electronically by users through the website named www.Netislem.com.tr ("Website") or its mobile applications for different purposes, except in the cases explained under Law No. 6698 on the Protection of Personal Data and the General Data Protection Regulation (GDPR).
Netislem's "Personal Data and General Privacy Policy" is given below.
IP Numbers: Netislem detects and uses the IP address of users when necessary, in order to identify problems related to the system, to promptly resolve problems that may arise on the website / mobile applications, and to make notifications to legal authorities in accordance with legal procedures and principles when required. IP addresses may also be used to identify users in a general (anonymous) way and to collect comprehensive demographic information.
Anonymous Data: The information requested by Netislem or provided by the user, or information related to transactions carried out through the Website / Mobile Application, may be used anonymously (without disclosing the user's identity) by Netislem and the persons it cooperates with for various statistical evaluations, database creation, offering personalized packages / offers, and market research.
Linking to other sites: Netislem may provide links to other sites within the Website / Mobile Application. Netislem bears no responsibility for the privacy practices and content of the sites accessed via these links.
Bank / Credit Card Information: Netislem uses an SSL certificate (green bar) that ensures information security with a 256-bit encryption algorithm in data transmission. Users' bank / credit card information is used only during the purchase transaction by the bank or payment institution and is never stored in the database. Netislem may provide an infrastructure through which card information can be stored via PCI DSS certified institutions in order to facilitate users' next purchase transactions. As a result of Card Storage Services that hold the PCI DSS standard and are licensed by the BRSA (BDDK), the information on bank / credit cards facilitates the Authentication and Authorization steps, providing bank / credit card holders with a secure and easy means of payment.
Situations in which user data may be disclosed: A user's personal data includes name-surname, address, telephone number, e-mail address and any information intended to identify the user. Unless otherwise stated in this privacy policy, Netislem will not disclose any of the personal data to third parties other than those it cooperates with and its affiliates. In the cases specified below, Netislem may disclose users' information to third parties by going beyond the provisions of this privacy policy. These cases are;
Compliance with the obligations imposed by the legal rules issued and in force by the competent legal authority, such as Laws, Decree-Laws, Regulations, etc.;
Fulfilment and implementation of the requirements of the contracts concluded by Netislem with users;
Cases where information about users is requested for the purpose of conducting an investigation or inquiry duly carried out by the competent administrative and judicial authority, and where it is necessary to provide information to protect the rights or safety of Users.
Netislem undertakes to keep confidential information strictly private and confidential, to regard this as a duty of secrecy, and to take all necessary measures and exercise due care to ensure and maintain confidentiality and to prevent all or any part of the confidential information from entering the public domain, being used without authorization, or being disclosed to a third party.
Status of cookies: Netislem may obtain information about users and users' use of the Website by using a technical communication file (Cookie) prepared by itself or by third parties. The said technical communication files are small text files that a website sends to the user's browser to be stored in the main memory. The technical communication file keeps the session open by storing the user's session information, password and preferences, and facilitates use by recognizing the user on their next visit. The technical communication file helps to obtain statistical information about how many people use the Website, for what purpose and how many times a person visits the Website and how long they stay, and helps dynamically generate advertisements and content from user pages specially designed for users. The technical communication file is not designed to obtain data or any other personal information from the main memory or e-mail. Most browsers are initially designed to accept the technical communication file; however, if they wish, users can change their settings so that the technical communication file is not received, or so that a warning is given when it is sent.
Data collected in surveys, contests and similar cases: The information requested from users who respond to periodic surveys and contests organized by Netislem within the Website is used by Netislem and the persons it cooperates with for the purpose of direct marketing to these users, statistical analysis and database creation.
E-newsletter deliveries and announcements: Netislem sends a weekly e-newsletter to inform its users about economic developments, current events and their own fields. When it deems necessary, or in case of agreement with third-party partners, it may send Campaign / Offer / Package announcements containing promotional and informational content. When you create an account on our system for the first time, you accept e-mail and SMS transmissions by default. Users can block these e-mails from reaching them by clicking the specified link, as explained at the bottom of the e-mail. In addition, there are means to block these in your user panel. If you wish to opt out of our daily e-mail list at any time, you can easily opt out of the e-newsletter subscription with a single click by clicking the "Please click to opt out of our e-newsletter list" link at the bottom of the e-mails we send.
General information about the Personal Data Protection Law
Law No. 6698 on the Protection of Personal Data was adopted on 24 March 2016 and published in the Official Gazette No. 29677 dated 7 April 2016. The European Union Data Protection Regulation (EU General Data Protection Regulation - GDPR) entered into force on 25 May 2018. As the data controller within the scope of Law No. 6698 on the Protection of Personal Data and the EU General Data Protection Regulation (GDPR), we will record, classify, process, store and update the personal data of you, our valued customers, and may disclose it to third parties in cases permitted by the legislation and by the permission you grant; we hereby inform you regarding our mutual rights and obligations within the scope of the said legal regulation.
Information in the capacity of data controller
As Netislem, whose detailed corporate information is published below, in accordance with the laws mentioned above and in the capacity of Data Controller, your personal data will be recorded, stored, updated, disclosed / transferred to third parties in cases permitted by the legislation, classified and processed within the framework explained below.
Definition of Personal Data within the scope of the Law
It refers to any information that will make you identified or identifiable, such as your identity (name, surname, date of birth, ID number, etc.), contact information, and information regarding the methods used during access to products (IP, mobile phone brand-model, browser type and version, social media information, movements performed on screens, etc.).
How your personal data may be processed
Pursuant to Law No. 6698 (KVKK) and the EU General Data Protection Regulation - GDPR, the personal data you share with our company may be processed by us - wholly or partially, automatically, or by non-automatic means provided that it is part of a data recording system - by being obtained, recorded, stored, modified and reorganized; and, provided that its security and confidentiality are ensured within the scope of the legislation: by being disclosed, transferred, taken over, made obtainable, classified, or prevented from use - in short, subject to any kind of processing carried out on the data. Within the scope of the aforementioned laws, any operation carried out on the data is considered "processing of personal data".
Purposes and legal grounds for processing your personal data
The personal data you share will be processed in accordance with the scope, procedures and principles of Law No. 6698 (KVKK) and the EU General Data Protection Regulation - GDPR, in order to:
- fulfil the requirements of the services we provide to our customers in a manner appropriate to the requirements of the contract and technology, and improve the products and services we offer,
- officially issue invoices after the purchase of all the products and services we offer,
- comply with the information-storage, reporting and notification obligations stipulated by the legislation and other authorities,
- provide information to prosecutors' offices, courts and relevant public officials upon request and in accordance with the legislation, on matters concerning public security and in legal disputes.
Your identity, address, tax number and other information will be recorded in order to determine the transaction owner and counterparty in all transactions to be carried out regarding all products and services we offer you; documents and information forming the basis for transactions to be carried out electronically will be prepared; the information-storage, reporting and notification obligations stipulated by all competent judicial and administrative authorities (courts, TBB, BDDK, SPK, TCMB, MASAK, BTK, etc.) under the relevant legislation will be complied with; and it will be processed for the purposes of providing other products and services offered and requested by Netislem and fulfilling the requirements of the contracts between us.
Information about the third parties or organizations to which your personal data may be transferred
For the purposes stated above, the persons / organizations to which the personal data you share with our company may be transferred are: our main shareholders, our direct or indirect domestic / foreign subsidiaries, and, without being limited to these, persons and organizations related to the service provided - that is, program-partner organizations, domestic / foreign organizations and other third parties from which we receive service, with which we cooperate, or in the capacity of Data Processor, in order to carry out our activities.
In addition, your personal data may be transferred, within the framework of our relevant cooperations, to institutions, organizations, banks, financial institutions, providers or companies from which we receive service or with which we cooperate on product/service comparison and application matters; to persons and institutions from which we receive cloud data-storage service; to institutions with which we have agreements regarding the sending of the messages we send to our customers; and to other third parties.
How your personal data is collected
Your personal data may be processed and collected;
through the forms on our company's website and mobile applications - in the form of name, surname, citizenship number, passport number, address, telephone, business or personal e-mail address, age, gender, occupation, preferences on pages logged in using username and password, IP records of transactions performed, cookie data collected by the browser, data including browsing time and details, and location data;
through our sales and marketing department employees, agencies, dealers, paper-based forms, business cards, digital marketing and call-center channels, verbally, in writing or electronically;
from persons who share their personal data through business cards, resumes (CV), submitting offers and other means, for purposes such as establishing a commercial relationship with our company, applying for a job, or submitting an offer - in a physical or virtual environment, face-to-face or remotely, verbally, in writing or electronically;
In addition, data obtained indirectly through different channels - data obtained from (micro) websites used for websites, blogs, contests, surveys, games, campaigns and similar purposes, and from social media; e-newsletter reading or clicking actions; data provided by publicly available databases; and profiles and data open to sharing from social platforms (Facebook, Twitter, Google, Instagram, Snapchat, etc.) - may also be processed and collected.
Your personal data obtained before Law No. 6698 (KVKK) and the EU General Data Protection Regulation - GDPR entered into force
Your personal data lawfully obtained before 7 April 2016, the effective date of the KVKK, and 25 May 2018, the effective date of the EU General Data Protection Regulation - GDPR, is also processed and maintained in accordance with the terms and conditions set out in this document.
Storage and protection of personal data
Your personal data will be kept confidential in the database and systems within our company pursuant to Law No. 6698 (KVKK) and the EU General Data Protection Regulation - GDPR; it will not be shared with third parties in any way other than legal obligations and the regulations specified in this document. Our company is obliged to take software measures such as hashing, encryption, transaction logging and access management, as well as physical security measures, in order to prevent the unlawful processing of personal data, to prevent unauthorized persons' access, and to ensure their preservation, in accordance with Law No. 6698 (KVKK) and the EU General Data Protection Regulation - GDPR. In the event that it is learned that personal data has been obtained by others through unlawful means, the situation will be reported immediately, in writing and in accordance with the legal regulation, to the Personal Data Protection Board.
Personal data will be stored as long as the purpose of providing this information is valid. In order to determine your needs, provide you with faster service and meet your subsequent service requests, your data will continue to be processed by us after the service you receive from us. If the data needs to be kept for reporting and information purposes to legal authorities and relevant public authorities subject to legal periods, or stored for longer periods in accordance with the legislation, these limits will be complied with. The necessary security measures will be taken by us to prevent the stored and recorded data from being lost, from falling into the hands of unauthorized persons, and to prevent unlawful use.
Keeping personal data up-to-date and accurate
Pursuant to Article 4 of the KVKK, our company has the obligation to keep your personal data accurate and up-to-date. In this context, in order for our company to fulfil its obligations arising from the applicable legislation, our Customers must share their accurate and up-to-date data or update it through the website / mobile application.
Rights of the personal data owner pursuant to Law No. 6698 (KVKK) and the EU General Data Protection Regulation - GDPR
The Personal Data Owner has the right, by applying to our Company (data controller), regarding themselves, to;
- learn whether personal data is processed,
- request information if personal data has been processed,
- learn the purpose of processing personal data and whether it is used in accordance with its purpose,
- know the third parties to whom personal data is transferred domestically or abroad,
- request the correction of personal data in case it has been processed incompletely or incorrectly,
- request the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the KVKK,
- request that the correction, deletion or destruction of personal data be notified to the third parties to whom the personal data has been transferred,
- object to the emergence of a result against the person themselves resulting from the analysis of the processed data exclusively through automated systems,
- request the compensation of the damage in case of suffering damage due to the unlawful processing of personal data.
The Data Controller Representative to be appointed by Netislem will be announced in the Data Controllers Registry and at the internet address where this document is located when the legal infrastructure is provided.
Personal Data Owners may direct their questions, opinions or requests to any of the following contact channels:
e-mail: bilgi@netislem.com.tr
Telephone: +90 258 911 0545
Our company may provide a positive/negative response to the requests submitted, verbally or digitally, provided that it is reasoned and responds within 30 days. It is essential that the necessary procedures regarding the requests are free of charge. However, if the procedures require a cost, our company reserves the right to charge a fee. These fees are determined over the tariff set by the Personal Data Protection Board pursuant to Article 13 of the Law on the Protection of Personal Data.