GDPR LAWYER AND CONTRACT
Privacy Policy and Personal Data Protection Agreement Compliant with KVKK (Turkish Personal Data Protection Law)

1. Introduction
This privacy policy and personal data protection agreement explains how Deniz Moda processes personal data collected, used, and protected. This document has been prepared in accordance with the Law No. 6698 on the Protection of Personal Data (“KVKK”).
2. Definitions
- Personal DataPersonal data is defined, within the scope of the Personal Data Protection Law (KVKK) and similar regulations, as any information relating to an identified or identifiable natural person. Personal data includes information that can reveal a person's identity directly or indirectly. This information may include:
1. Identity Information: Any information used to identify an individual, such as name, surname, Turkish Republic identity number, and passport number.
2. Contact Information: Information that allows contact with an individual, such as address, telephone number, and email address.
3. Demographic Information: Information specifying personal characteristics such as age, gender, marital status, occupation, and education level.
4. Financial Information: Information related to economic status, such as bank account number, credit card information, and income information.
5. Health Information: Special health-related data such as the individual's health status, medical history, and genetic data.
6. Location Information: Geographic location data, such as real-time location information.
7. Online Identifiers: Information used to identify an individual electronically, such as IP address, cookie data, and MAC address.The protection of personal data aims to safeguard the privacy and fundamental rights of the data subject. This data may only be processed on a legal basis and for the specified purposes. Data subjects have various rights over their personal data, such as the right to access, rectify, delete, and object to processing.
- Data ControllerAccording to the KVKK (Personal Data Protection Law) text, "data controller" refers to the party that determines the purposes and means of processing personal data
The data controller is responsible for conducting data processing activities and is therefore accountable to data subjects and regulatory authorities for the processing of personal data. Consequently, they play a crucial role in matters such as implementing compliance processes under the Personal Data Protection Law (KVKK), taking data security measures, and protecting the rights of data subjects.
- The data controller is the natural or legal person who identifies the data and establishes and manages the data recording system. The data controller is obligated to act in accordance with the law during data processing, take necessary security measures, and protect the rights of data subjects. Furthermore, in accordance with the Personal Data Protection Law (KVKK), the data controller must comply with regulations concerning the protection of personal data, and ensure the lawful collection, storage, and, if necessary, destruction of data.
- Data ProcessorIn the text of the KVKK (Personal Data Protection Law)
The responsibilities of the data processor include the following:
1. Data Security: The data processor must take the necessary technical and administrative measures to ensure the security of the personal data it processes.
2. Compliance with the Data Controller: The data processor must act in accordance with the instructions of the data controller and the requirements of the Personal Data Protection Law (KVKK).
3. Data Breach: In the event of any data breach, the data processor is obliged to immediately notify the data controller.All measures taken and procedures implemented by the data processor during data processing activities are considered under the general responsibilities of the data controller. Therefore, the selection and supervision of the data processor must be carefully carried out by the data controller. A clear and explicit agreement must be made between the data processor and the data controller regarding the protection of the processed data and the conduct of processing activities in accordance with the Personal Data Protection Law (KVKK).
- “Data processor” refers to any natural or legal person who processes personal data on behalf of and under the authority granted by the data controller. The data processor processes the data within the framework defined by the data controller and in accordance with their instructions. The data processor cannot have access to or control over personal data independently of the data controller; they can only perform the operations specified by the data controller.
- Explicit ConsentAccording to the KVKK (Turkish Personal Data Protection Law), "explicit consent" refers to the informed and free will of the data subject regarding the processing of personal data. Explicit consent requires a clear, subject-specific approval given after being informed, eliminating ambiguity.
Characteristics of Explicit Consent:
1. Clarity: Consent must be limited to a specific operation and should not contain general or vague statements.
2. Informed Consent: The data subject must be fully informed of the purpose for which their data will be processed, to whom it may be transferred, and why.
3. Freedom: Consent must not be obtained under any coercion or duress. It is essential that the data subject freely gives their consent.
4. Explicit Expression: Consent must be given through an explicit action by the data subject (e.g., checking a box or giving approval on an electronic form). Silence or inaction is not considered consent.When is Explicit Consent Required?
According to the Turkish Personal Data Protection Law (KVKK), the consent of the data subject is generally required for the processing of personal data. Explicit consent is sought, especially when dealing with sensitive personal data (such as health information, biometric data, and ethnic origin). However, except in certain exceptional circumstances, explicit consent is absolutely necessary for the processing of personal data.
Exceptions to Explicit Consent:
In some cases, personal data may be processed without the explicit consent of the data subject. These include:
– Cases explicitly provided for in the laws
– Situations requiring urgent intervention in favor of individuals who are unable to express their consent due to factual impossibility or whose consent lacks legal validity
– When the processing of personal data belonging to the parties of a contract is necessary, provided that it is directly related to the establishment or performance of the contract
– When it is necessary for the data controller to fulfill its legal obligations
– When processing personal data that has been made public by the data subject themselves
– When data processing is necessary for the establishment, exercise, or protection of a right
– When data processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject. In such cases, explicit consent is not required.Obtaining explicit consent should be regulated according to the nature and purposes of the data being processed, and data subjects should be provided with transparent information throughout this process.
3. Processing of Personal Data
Personal Data Processed:
- First name, last name
- Address
- Email address
- Phone number
- Payment information
- IP address and other browser information
Data Processing Purposes:
- Conducting sales and marketing activities
- Order processing and delivery
- Providing customer service
- Fulfillment of legal obligations
4. Methods of Collecting Personal Data
Personal data is collected through purchases made via the Site, user accounts, e-newsletter subscriptions, and communications with customer service.
1. Collection Through Forms
– Online Forms: Registration, contact, and order forms on websites, applications, and social media platforms.
– Paper Forms: Physical form-filling processes, surveys, and application forms.
2. Transaction Records:
– Financial Transactions: Financial activities such as banking transactions and credit card purchases.
– Electronic Transactions: Email traffic, user login activity, online shopping history.
3. Device and Application Data:
– Cookies and Tracking Technologies: Websites use cookies and similar tracking technologies to monitor user behavior.
– Mobile Applications: Information collected via mobile devices, such as location data and usage statistics.
4. Monitoring and Recording:
– Security Cameras: Visual recording via security cameras in workplaces, public areas, or private properties.
– Audio Recordings: Customer service calls, meeting recordings.
5. Obtaining from Third-Party Sources:
– Data Purchase: Buying data such as demographic information, interests, and consumer habits from market research companies.
– Partnerships and Networks: Obtaining data from business partners or affiliated organizations.
6. Social Media and Other Platforms:
– Social Media Profiles: Users' interactions and posts on social media platforms.
– Comments and Forums: Comments made by users in online forums or blogs.
7. Directly Provided by the User:
– Customer Feedback: Feedback provided through customer service or via direct communication.
– Interviews and Surveys: Surveys and interviews conducted in person or by telephone.
All the data collection methods we have mentioned must be implemented within the framework of relevant legal regulations and ethical guidelines. In particular, the protection of personal data and respect for privacy form a delicate foundation for these processes. Data collection institutions must take appropriate security measures according to the nature of the data collected and the collection methods used, and must inform data owners transparently about the data collection processes.
5. Storage and Protection of Personal Data
Personal data is stored and protected in secure databases in accordance with the Turkish Personal Data Protection Law (KVKK). Data security measures include encryption, access control, and data integrity assurance methods.
6. Transfer of Personal Data to Third Parties
Personal data is transferred to third parties only within the scope of legal obligations and with the explicit consent of users. Domestic and international data transfers are carried out in accordance with relevant legislation.
7. Data Subjects' Rights
Data subjects have the following rights under the KVKK (Turkish Personal Data Protection Law):
- To find out whether your personal data is being processed
- Requesting information about processed personal data
- To learn the purpose of the processing and whether it is being used in accordance with those purposes
- Knowing the third parties to whom personal data is transferred, whether domestically or internationally
- Requesting the correction of personal data if it has been processed incompletely or inaccurately
- Requesting the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the KVKK (Law on Protection of Personal Data)
- Requesting notification of corrections, deletions, or destructions to third parties to whom personal data has been transferred
- The right to object to an outcome that is detrimental to oneself, resulting solely from the analysis of processed data by automated systems
- The right to claim compensation for damages incurred as a result of the unlawful processing of personal data
8. Data Subjects' Right to Apply and Complaint
Data subjects can contact Deniz Moda to exercise their rights under the Personal Data Protection Law (KVKK). Applications will be processed within a maximum of 30 days. Complaints can be submitted to the Personal Data Protection Authority. Data subjects can apply to the data controller in writing or via methods such as registered electronic mail (KEP) or secure electronic signature to exercise the following rights under the KVKK:
- To find out whether your personal data is being processed
- Requesting data correction or update
- Access to processed data and obtaining information
- Deletion or destruction of data
- Notification of third parties to whom the processed data is transferred
- Objections to analysis by automated systems
- Compensation for damages resulting from unlawful data processing
9. Explicit Consent
Users explicitly consent to the processing of their personal data. Explicit consent can be withdrawn at any time. However, the withdrawal process does not affect data processing activities that took place before the withdrawal.
10. Data Breach and Reporting
In the event of a data breach, necessary measures are taken to minimize the effects of the breach, and affected data owners and the Personal Data Protection Authority are notified.
11. Entry into Force and Duration of the Agreement
This agreement comes into effect upon the user's use of the Site (Deniz Moda). The agreement remains in effect unless terminated by the user or updated by the Site.
12. Other Provisions
This agreement may be updated from time to time. Updates will be announced on the Site and presented to users for their acceptance. Turkish Law shall apply to the resolution of disputes, and the Istanbul Courts shall have jurisdiction.
Behiye Zeynep Ozdemir
