CONFIDENTIALITY AGREEMENT

PRIVACY POLICY

It adopts the principles stipulated by the KVK Law in order to comply with the Law on the Protection of Personal Data No. 6698 (“KVK Law”), and fulfills its obligations regarding the processing, deletion, destruction, anonymization, transfer, enlightenment of the person concerned and ensuring data security. brings. The Privacy and Personal Data Protection Policy regulated in this context is made available to natural persons whose personal data are processed (“Relevant Person”).

1. Scope and Purpose of Privacy and Personal Data Protection Policy

This Privacy and Personal Data Protection Policy;

  1. Personal data collection methods and legal reasons,

  2. Which person groups' personal data are processed (Data Subject Person Group Categorization),

  3. Which category of personal data is processed in relation to these groups of people (Data Categories) and sample data types,

  4. In which business processes and for what purposes this personal data is used,

  5. Technical and administrative measures taken to ensure the security of personal data,

  6. To whom and for what purpose personal data can be transferred,

  7. Personal data retention periods,

  8. Profiling and Segmentation

  9. What are the rights of the Relevant Persons on their personal data and how they can use these rights,

  10. How Relevant Persons can change their positive or negative preferences in receiving electronic commercial messages,

  11. Sharing personal data with official authorities

  12. Cookie Usage and Management

explains.

 

a. Personal Data Collection Methods and Legal Reasons

UTARIT INFORMATION ENERGY AND TECHNOLOGY INDUSTRY AND TRADE JOINT STOCK COMPANY

  Personal data specified in Article 5 of the Personal Data Protection Law No. 6698

  • clearly stipulated in the law

  • it is necessary to process the personal data of the parties to the contract, provided that it is directly related to the establishment or performance of a contract.

  • The fact that the person concerned has been made public by himself

  • Data processing is mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject.

  • Data processing is mandatory for the establishment, exercise or protection of a right

Based on legal reasons, it collects audio, electronic or written forms through websites, mobile applications of websites, social media accounts, cookies, call center, notifications from administrative and judicial authorities and other communication channels.

b. In Which Business Processes and For What Purposes Personal Data is Used

Member Customer Personal Data

  • Execution of membership transactions,

  • “Solicell” operated by UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ; Improving the services offered on the website, developing new services and informing about it,

  • For the purpose of the execution of the Membership Agreement established with the Member Customer, for the Member Customers with commercial electronic message approval; Analyzing the preferences, tastes and needs of the Member Customer and providing special promotions, opportunities and benefits to the Member Customer,

  • Remarketing, targeting, profiling and analysis in line with the express consent of the Member Customer, and promoting and marketing the applications, goods/products and services in line with the Member Customer's preference and liking,

  • Resolving Member Customer problems and complaints,

  • Improving the Member Customer experience on both the platform and the mobile application,

  • Follow-up of accounting and purchasing transactions,

  • Legal processes and compliance with legislation,

  • Answering information requests from administrative and judicial authorities,

  • Ensuring information and transaction security and preventing malicious use,

  • Making necessary arrangements in order to ensure that the processed data is up-to-date and correct.


 

NS. Technical and Administrative Measures Taken to Ensure the Security of Personal Data

UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ undertakes to take all necessary technical and administrative measures and to show the necessary care in order to ensure the confidentiality, integrity and security of your personal data.

UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ takes the necessary precautions to prevent unauthorized access, misuse, unlawful processing, disclosure, alteration or destruction of personal data. UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ uses generally accepted security technology standards such as firewalls and Secure Socket Layer (SSL) encryption when processing personal data. In addition, when sending your personal data to UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ via the website, mobile application and mobile site, this data is transferred using SSL.

Regarding the prevention of unlawful access to the personal data processed by UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ, preventing the illegal processing of this data and ensuring the protection of personal data:

  • All areas on the website or mobile application from which personal data are obtained are protected with SSL,

  • Creates and implements access authorization and control matrices for its employees so that personal data collected from the website or mobile application is not processed unlawfully,

  • In order to ensure that personal data is not accessed unlawfully; periodically performs penetration tests, tests the system's resistance to unauthorized access,

  • For all secondary data processing other than the primary processing purpose, it uses the Pseudonymization (aliased data) method. Pseudonymous uses encryption methods in the systems where this data is located in order to make it impossible to identify the person concerned, and applies a stricter access authorization and control policy to this data,

  • It ensures that personal data in paper media is kept in locked cabinets and only accessed by authorized persons.

  • Personal data processed through cookies belonging to third parties from which service is received, are deleted from the systems of third parties if the membership is terminated.

Although UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ has taken the necessary information security measures, the platforms operated by UTARİT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ or the personal data of UTARİT BİLGİ ENERJİCARZİCARET ANONİM ŞİRKETİ are damaged or the personal data is damaged as a result of attacks on the authorization system In the event that it falls into the hands of third parties, UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ immediately notifies you and the Personal Data Protection Board and takes the necessary measures.

f. To Whom Personal Data Can Be Transferred And For What Purpose

UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ transfers personal data to third parties only for the purposes specified in this Privacy and Personal Data Protection Policy and in accordance with Articles 8 and 9 of the KVK Law. Member Customer/Guest Customer data processed in this context and the person on whose behalf the purchased product will be delivered are shared with the cargo company and this data can also be accessed by the call center when necessary. The information of the person on whose behalf an invoice will be issued is shared with the cargo company for the purpose of sending the invoice to the relevant person.

Mobile phone number and/or e-mail address of the Member Customer/Guest Customer; Based on the commercial electronic message approval, it is shared with the commercial electronic message tool service provider in order to provide promotion, advertisement, benefit and opportunity in line with shopping preferences, tastes and habits.

Website or mobile application usage preferences and browsing history are shared with our domestic/abroad business partners from whom cookie service is obtained, for the purpose of segmentation and communication with Member Customer/Guest Customer in line with their tastes and preferences. Personal data transfers within this scope are carried out through the secure environment and channels provided by the relevant third party. Depending on the content and scope of the service received from third parties; In all cases where there is no need to transfer the personal data of the Member Customer/Guest Customer, the transfer is made using Pseudonymous data (pseudonymous data).

In addition, your personal data will be shared with our business partners abroad for the purposes of providing business development services, providing statistical and technical services and conducting customer relations.

In addition to the technical measures to ensure their security, the personal data subject to domestic and international transfer we mentioned above; Considering that the other party of the legal relationship is a data controller or a data processor, it is also legally protected by the provisions in line with the KVK Law included in our contracts.

While transferring personal information to countries other than Turkey during the sharing of information as stated above, it is ensured that the data is transferred in accordance with this policy and as permitted by the applicable law regarding data protection.

g. Personal Data Retention Periods

UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ preserves the personal data it processes in accordance with the KVK Law for the periods stipulated in the relevant legislation or required by the processing purpose. In our Personal Data Retention and Disposal Policy, these periods are approximately as follows:

Call Center audio recordings

3 years

Law No. 6563 and related secondary legislation

Membership and order records

10 years

Law No. 6098

All records related to accounting and financial transactions

10 years

Law No. 6102, Law No. 213

Cookies

Up to 540 days

 

Commercial electronic message confirmation records

1 year from the date of withdrawal of consent

Law No. 6563 and related secondary legislation

Traffic information about online visitors

2 years

Law No. 5651

Information and/or CVs received due to job application

1 year

 

Personal data of Member Customer/Guest Customers

10 years after the legal relationship ends; 6563 3 years in accordance with the law and related secondary legislation

Law No. 6563, Law No. 6102, Law No. 6098, Law No. 213, Law No. 6502

Personal data regarding suppliers

10 years after the legal relationship ends

Law No. 6102, Law No. 6098 and Law No. 213

Personal data received for the purpose of usability testing research

2 weeks

 

You can review our Cookie Policy for the retention periods of personal data we obtain through cookies.

h. Profiling and Segmentation

UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ by using the personal data processed in relation to the Member Customer/Guest Customer;

  • a. Regarding the Member Customer/Guest Customer who has given consent to receive commercial electronic messages, it carries out profiling and segmentation in order to prepare more suitable content for the Member Customer/Guest Customer's tastes and preferences, and to make advertisements, promotions and discounts.

  • b. In terms of Member Customer/Guest Customer who have not given commercial electronic message approval, profiling and segmentation is carried out;

    1. Making product improvement (determining the most sold or unsold product categories),

    2. Organizing campaigns for customer groups that have the potential to buy a certain product by making models by analyzing shopping preferences and uploading them to the system,

    3. Efforts are being made to take actions to increase the sales potential.

Within the scope of profiling and segmentation studies, the personal data of the Member Customer/Guest Customer, especially name and surname, mobile phone, e-mail or address information, are not used directly, instead, transactions are made with the Member Customer/Guest Customer IDs assigned to them. The personal data of the Customer/Member is protected by the use of the Member Customer/Guest Customer ID or in other words pseudonymous data. Member Customer/Guest Customer IDs are only accessible to relevant persons or departments within UTARİT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ. These IDs assigned to the Member Customer/Guest Customer are kept encrypted within the system by UTARİT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ and access to this section is only given to limited persons.

NS. What are the Rights of the Related Persons on their Personal Data and How They Can Use These Rights

The rights of the Related Person on the personal data processed by UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ pursuant to article 11 of the KVK Law are listed below:

  • Learning whether personal data is processed or not,

  • If personal data has been processed, requesting information about it,

  • Learning the purpose of processing personal data and whether they are used in accordance with the purpose,

  • Knowing the third parties to whom personal data is transferred at home or abroad,

  • Requesting correction of personal data in case of incomplete or incorrect processing,

  • Requesting the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the KVK Law,

  • Requesting notification of the transactions made pursuant to subparagraphs (d) and (e) to third parties to whom personal data has been transferred,

  • Objecting to the emergence of a result against the person himself by analyzing the processed data exclusively through automated systems,

  • To request the compensation of the damage in case of loss due to unlawful processing of personal data.

In order to exercise your rights over your personal data; You can access your account from the "My Account" section of the UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ website, mobile application and mobile site and make the necessary changes, updates and/or deletions. In addition, you can make your application and exercise your rights using the methods specified in the "Application Form" issued in accordance with Article 13 of the KVK Law, which is included in the website or mobile application of electronic commerce platforms operated by UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ.

j. How Relevant Persons Can Change Their Positive or Negative Preferences for Receiving Electronic Commercial Messages

You can change or update your positive or negative preferences for receiving commercial electronic messages that you have given at any time by accessing the "My Account" section, while subscribing to the website or mobile application of the electronic commerce platforms operated by UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ.

Termination of membership does not mean withdrawing your consent to receive commercial electronic messages. For this reason, be sure to complete all the procedures to revoke your consent.

In terms of cookie management, you can follow the steps specified in our Cookie Policy.

k. Personal Data Sharing with Official Authorities

Your personal data regarding your visit or membership to electronic commerce platforms and mobile applications operated by UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ, UTARİT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ and your traffic information such as your navigation information; In order for UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ to fulfill its obligation before the law (including but not limited to the fight against crime, the threat of state and public security, and the like, legal or administrative notification or in cases where there is an obligation to provide information) with public institutions and organizations that are legally authorized to request this information.

l. Cookie Usage and Management

You can review our Cookie Policy for detailed information about the cookies used by UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ, types of cookies, their purposes, storage periods and cookie management.

2. Terms of Deletion, Destruction and Anonymization of Personal Data

UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ stores the personal data it processes through its website, mobile application or mobile site for the periods stipulated by the relevant laws and/or the processing purpose in accordance with Article 7, 17 of the KVK Law and Article 138 of the Turkish Penal Code. . In the event that these periods expire, it will delete, destroy or anonymize Personal Data in accordance with the provisions of the Regulation on the Deletion, Destruction or Anonymization of Personal Data.

Deletion of personal data by UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ means the process of making personal data inaccessible and unusable for the relevant users in any way. UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ creates and implements a user-level access authorization and control matrix for this purpose. It takes the necessary measures to perform the deletion in the database.

Destruction of personal data by UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ means the process of making personal data inaccessible, unrecoverable and unusable by anyone in any way.

Anonymization of personal data by UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ means that personal data cannot be associated with an identified or identifiable natural person under any circumstances, even if it is matched with other data.

UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ explains in detail the methods of deletion, destruction and anonymization and the technical and administrative measures it has taken within the scope of the Personal Data Storage and Disposal Policy prepared in accordance with the Regulation on the Deletion, Destruction or Anonymization of Personal Data. . In this Policy, the period of time for the periodic destruction stipulated by the Regulation is determined as 6 months.

3. Changes to the Privacy/Personal Data Protection Policy

UTARIT BİLGİ ENERJİ ve TEKNOLOJİ SANAYİ TİCARET ANONİM ŞİRKETİ can always make changes in this Privacy/Personal Data Protection Policy. These changes will become effective immediately upon the publication of the amended new Privacy/Personal Data Protection Policy. You, our members, will be informed about the changes in this Privacy/Personal Data Protection Policy.