GDPR
Creatives Data – Policy on the Protection and Processing of Personal Data
1. INTRODUCTION
As the data controller, the protection of personal data belonging to individuals who receive products and services from Creatives Data, our employees, business partners, and other natural persons with whom we are in a relationship is of great importance. The purpose of this Creatives Data Policy on the Protection and Processing of Personal Data (“Policy”) is to ensure the lawful processing and protection of the personal data of our customers who establish a relationship with the company, our employees, employee candidates, visitors, employees of institutions with which we cooperate, and third parties. In this context, the necessary administrative and technical measures are taken by the company in accordance with the Law on the Protection of Personal Data No. 6698 (“Law”) and the relevant legislation for the processing and protection of personal data.
PURPOSE AND SCOPE OF THE POLICY
The primary purpose of this Policy is to provide explanations regarding the personal data processing activities carried out lawfully by the company and the systems adopted for the protection of personal data, to ensure transparency toward the persons with whom our company is associated, and to inform the relevant persons about the processing of personal data.
The scope of this Policy covers the personal data of customers, our employees, employee candidates, visitors, employees of institutions with which we cooperate, and third parties that are processed automatically or, provided that they are part of any data recording system, processed by automatic or non-automatic means.
MATTERS RELATING TO THE PROTECTION OF PERSONAL DATA
3.1 Protection of Personal Data
In accordance with Article 12 of the Law, our company takes the necessary technical and administrative measures to ensure an appropriate level of security to prevent the unlawful processing of the personal data it processes, prevent unlawful access to the data, and ensure the preservation of the data; and in this context, carries out or has carried out the necessary audits. In this regard, our company takes the necessary administrative and technical measures in line with the guidelines published by the Personal Data Protection Board (“Board”), and follows and audits the work carried out within the company.
3.2 Protection of Special Categories of Personal Data
Since the unlawful processing of sensitive personal data may cause victimization or discrimination, special importance is attributed to these data within the scope of the Law. Pursuant to Article 6 of the Law, special categories of personal data are personal data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership in associations, foundations or trade unions, criminal convictions and security measures (special category personal data other than health and sexual life), and health, sexual life, biometric and genetic data (special category personal data relating to health and sexual life). The technical and administrative measures taken by the company for the protection of personal data are applied to special categories of personal data in line with the adequate measures stipulated in the Board’s Decision dated 31/01/2018 and numbered 2018/10, as explained in the Special Categories of Personal Data Protection Policy; and the work carried out in this regard is monitored and audited within the framework of audits conducted within the company.
3.3 Audit of Measures Taken for the Protection of Personal Data and Training of Company Personnel
A Personal Data Protection Committee exists within the company. On behalf of the company as the data controller, and in accordance with the duty arising from Article 12 of the Law, the Committee carries out the necessary audits to ensure the implementation of the provisions of the Law within its own institution or organization and, where necessary, has such audits carried out by competent organizations by obtaining support. According to the results of these audits, violations, adverse situations, and nonconformities identified are reported to the responsible persons within the committee, and the necessary measures are taken in this respect. In cases where personal data are transferred to real or legal persons from whom the company receives services, additional agreements are concluded with the relevant companies stating that personal data are transferred in compliance with the law and that the persons to whom personal data are transferred will take the necessary security measures for the protection of personal data and ensure compliance with these measures within their own organizations. In addition, Creatives Data executes agreements with its personnel to ensure compliance with personal data protection measures.
The company organizes the necessary training to raise awareness for the prevention of unlawful processing of personal data, prevention of unlawful access to data, and ensuring the preservation of data.
MATTERS RELATING TO THE PROCESSING OF PERSONAL DATA
The company carries out personal data processing activities in accordance with Article 20 of the Constitution and Article 4 of the Law. Creatives Data retains personal data for the period stipulated in the laws or for the period required by the purpose of processing personal data. In accordance with Article 10 of the Law, the company informs the relevant persons whose personal data are processed and, in cases where consent is required, seeks their consent, and processes these personal data based on the criteria set out below.
4.1 Processing in Accordance with the Law and the Principle of Good Faith
In processing personal data, the company acts in compliance with the principles introduced by legal regulations and the principle of public trust and good faith. In accordance with the principle of good faith, the company considers the rights of the relevant persons while pursuing its objectives in data processing.
4.2 Ensuring that Personal Data Are Accurate and Up-to-Date When Necessary
Keeping personal data accurate and, when necessary, up-to-date is necessary to protect the fundamental rights and freedoms of the relevant person for the company. The company exercises utmost care to ensure that personal data are accurate and up-to-date. For this reason, all communication channels are open for the relevant persons whose personal data are processed by the company to keep their information accurate and up-to-date, and the company takes the necessary measures in this regard.
4.3 Processing for Specific, Explicit and Legitimate Purposes
Creatives Data determines in a clear and precise manner the legitimate and lawful purposes for processing personal data. The company processes personal data to the extent necessary for its activities and commercial services and in connection with the activity being carried out.
4.4 Being Relevant, Limited and Proportionate to the Purpose for which They Are Processed
The company processes personal data within the scope relevant to and necessary for the execution of its work. Therefore, the company processes personal data in a manner suitable for achieving the set purposes and avoids processing personal data that are not related to or needed to achieve the purpose.
4.5 Retention for the Period Stipulated in the Relevant Legislation or Required for the Purpose for which They Are Processed
The company retains personal data only for the period stipulated in the relevant legislation or for the period required for the purpose for which they are processed in accordance with company policies. In this context, the company first determines whether a period is stipulated in the relevant legislation for the retention of personal data; if a period is specified, it acts in accordance with this period; if no period is specified, it retains personal data for the period required for the purpose for which they are processed and specified in the company’s retention policy. The company bases the retention periods on the personal data inventory; at the end of the periods specified therein, within the framework of obligations under the Law, personal data are deleted, destroyed or anonymized depending on the nature and purpose of use of the data.
PROCESSING OF PERSONAL DATA
The explicit consent of the relevant person is only one of the legal grounds that enables the processing of personal data. Apart from explicit consent, personal data may also be processed if one of the conditions specified in the Law exists. The legal ground for a personal data processing activity may be only one of the conditions listed below, or more than one of these conditions may constitute the legal ground for the same personal data processing activity. If the processed data are special categories of personal data, the conditions set out in section 5.2 of this Policy (Processing of Special Categories of Personal Data) shall apply.
5.1 Conditions for Processing Personal Data
a) Explicit Consent of the Relevant Person
One of the conditions for processing personal data is the explicit consent of the relevant person. The explicit consent of the relevant person must relate to a specific subject, be based on information and be declared with free will. In the presence of the personal data processing conditions listed below, personal data may be processed without the explicit consent of the relevant person.
b) Explicitly Stipulated by Laws
If the personal data of the relevant person are explicitly stipulated in the law, in other words, if there is an explicit provision in the relevant law regarding the processing of personal data, this condition shall be deemed to exist.
c) Inability to Obtain the Consent of the Relevant Person Due to Actual Impossibility
If it is necessary to process the personal data of a person who is unable to declare consent due to actual impossibility or whose consent cannot be considered valid, in order to protect the life or physical integrity of such person or another person, the personal data of the relevant person may be processed.
d) Being Directly Related to the Establishment or Performance of a Contract
If it is necessary to process personal data directly related to the establishment or performance of a contract to which the relevant person is a party, this condition shall be deemed fulfilled.
e) Necessity for Creatives Data to Fulfill its Legal Obligation
If it is necessary to process personal data to fulfill the company’s legal obligations, the personal data of the relevant person may be processed.
f) Personal Data Made Public by the Relevant Person
If the relevant person has made the personal data public, the relevant personal data may be processed limited to the purpose of making them public.
g) Necessity of Data Processing for the Establishment, Exercise or Protection of a Right
If it is necessary to process data for the establishment, exercise or protection of a right, the personal data of the relevant person may be processed.
h) Necessity of Data Processing for the Legitimate Interests of Creatives Data
Provided that the fundamental rights and freedoms of the relevant person are not harmed, if data processing is necessary for the legitimate interests of our company, the personal data of the relevant person may be processed.
5.2 Processing of Special Categories of Personal Data
Special categories of personal data are processed by our company in accordance with the principles set out in this Policy and by taking all necessary administrative and technical measures, including the methods to be determined by the Board, and in the presence of the following conditions:
a) Special categories of personal data other than those relating to health and sexual life may be processed without the explicit consent of the relevant person if it is explicitly stipulated by law, i.e., if there is an explicit provision in the relevant law regarding the processing of personal data. Otherwise, the explicit consent of the relevant person shall be obtained.
b) Special categories of personal data relating to health and sexual life may be processed, without explicit consent, by persons under the obligation of confidentiality or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, medical diagnosis, execution of treatment and care services, and planning and management of health services and their financing. Otherwise, the explicit consent of the relevant person shall be obtained.
PURPOSES OF PROCESSING PERSONAL DATA
The company processes personal data limited to the purposes within the personal data processing conditions specified in Article 5(2) and Article 6(3) of the Law. For detailed information on this subject, please refer to Annex-2 (Annex 2 – Personal Data Processed by the Company and Their Purposes) of this Policy. In addition, the general purposes regarding the processed personal data are also mentioned in the Data Controllers Registry in which we are registered.
INFORMATION AND NOTICE TO THE RELEVANT PERSON
In accordance with Article 10 of the Law, the company informs the relevant persons whose personal data are obtained at the time of obtaining the personal data. In this context, depending on the nature of the relevant person and the data processing process, the company provides information on the identity of the data controller and, if any, the identity of its representative, the purpose for which personal data will be processed, to whom and for what purpose the processed personal data may be transferred, the method and legal basis for collecting personal data, and the rights of the relevant persons whose personal data are processed. In this context, preliminary information notices and information texts have been placed within the company and in common areas where they can be easily seen. On the company website, along with this policy, process- and person-based information texts, the cookie policy, and the application form have been published.
TRANSFER OF PERSONAL DATA
The company may transfer the personal data of the relevant person to third parties by taking necessary security measures in line with the purposes of lawful personal data processing. In this context, personal data may be transferred where:
-
There is an explicit provision in the law for the transfer of personal data,
-
It is necessary to transfer personal data of the parties to a contract, provided that it is directly related to the establishment or performance of the contract,
-
It is mandatory for the company to fulfill its legal obligation,
-
It is necessary for the establishment, exercise or protection of a right,
-
Provided that the fundamental rights and freedoms of the relevant person are not harmed, it is mandatory for the legitimate interests of the company,
-
For special categories of personal data other than those relating to health and sexual life; if stipulated by law,
-
For personal data relating to health and sexual life; only if there is a necessity to share them with authorized persons, institutions and organizations within the scope of protecting public health, preventive medicine, medical diagnosis, execution of treatment and care services, and planning and management of health services and their financing.
THIRD PARTIES TO WHOM CREATIVES DATA TRANSFERS PERSONAL DATA AND PURPOSES OF TRANSFER
In line with the purposes of lawful personal data processing and by taking necessary security measures, the company may transfer the personal data and special categories of personal data of the relevant person to third parties. In this respect, our company acts in accordance with the regulations laid down in Articles 8 and 9 of the Law. For detailed information on this subject, please refer to Annex-3 (Annex 3 – Third Parties to Whom Our Company Transfers Personal Data and Purposes of Transfer) of this Policy.
CREATIVES DATA PERSONAL DATA INVENTORY AND CLASSIFICATION OF PERSONAL DATA
Within Creatives Data, in line with the company’s legitimate and lawful personal data processing purposes, and limited to and based on one or more of the personal data processing conditions specified in Articles 5 and 6 of the Law, personal data under the categories specified below are processed by informing the relevant persons, in compliance with the general principles stipulated in the Law and all obligations set forth therein.
In accordance with the Regulation on the Data Controllers Registry put into effect by the Personal Data Protection Authority, the company has created a personal data inventory. This data inventory includes data categories, the source of the data, the purposes of processing, the data processing process, recipient groups to whom the data are transferred, and retention periods. In this context, the following categories of personal data are included in the company’s personal data inventory.
PERSONAL DATA CATEGORIZATION
Personal Data Category
Description
Identity Data
The group of data containing information about a person’s identity.
Contact Data
The group of data that can be used to contact the person.
Visual and Audio Data
The group of data containing visual and audio data belonging to the person.
Personnel Data
This category refers to data types such as payroll information, asset declaration information, résumé information, etc.
Financial Data
The group of data containing the financial information of the person.
Professional Experience
The group of data containing information about the person’s profession, professional experience, and education.
Customer Transaction Data
This category refers to data types such as call center records, receipts, acknowledgements, valuable paper information, and invoice information.
Marketing Data
This category refers to the group of data used for marketing and sales purposes that contains digital traces resulting from the processing of the person’s information—such as website browsing information, cookies for marketing purposes, and shopping history.
Legal Transaction Data
This category refers to data types such as information in correspondence with judicial authorities and information in case files.
Transaction Security Data
The group of data containing transaction security data such as IP information, log records, and cookies belonging to the person.
Physical Space Security Data
The group of data containing physical space security data such as camera recordings and entry-exit records belonging to the person.
Risk Management
This category refers to data types processed to manage technical and administrative risks.
Health Data
The group of data relating to the person’s health.
Other
The category refers to Military Service Status information that is not categorized in the Data Controllers Registry.
RETENTION PERIODS OF PERSONAL DATA
In cases stipulated in the relevant laws and regulations, the company retains personal data for the period specified in these regulations. If there is no period stipulated in the legislation regarding how long personal data should be retained, personal data are retained for as long as required by the company’s practices and commercial customs, in connection with the activity that the company carries out while processing that data.
Pursuant to Article 138 of the Turkish Penal Code, Article 7 of the Law, and the “Regulation on the Deletion, Destruction and Anonymization of Personal Data” put into effect by the Personal Data Protection Authority, personal data processed in accordance with the provisions of the relevant laws shall be deleted, destroyed or anonymized upon the elimination of the reasons requiring processing, in accordance with the company’s policies or upon the request of the relevant person. The company has established a policy on this subject in accordance with the provisions of the regulation and acts in accordance with this policy.
RIGHTS OF THE RELEVANT PERSON AND THE EXERCISE OF THESE RIGHTS
In accordance with Article 10 of the Law, the company informs the relevant person of his/her rights and guides the relevant person on how to exercise the rights regulated in Article 11; and the company carries out the necessary channels, internal functioning, administrative and technical arrangements for the evaluation of the rights of the relevant persons and for providing the necessary information to the relevant persons in accordance with Article 13 of the Law.
12.1 Rights of the Relevant Person Whose Personal Data Are Processed
The relevant persons whose personal data are processed have the following rights:
-
To learn whether personal data are processed,
-
If personal data have been processed, to request information regarding this,
-
To learn the purpose of processing personal data and whether they are used in accordance with their purpose,
-
To know the third parties to whom personal data are transferred domestically or abroad,
-
To request the correction of personal data if they are incomplete or incorrectly processed, and to request that the transaction carried out within this scope be notified to the third parties to whom the personal data are transferred,
-
Despite being processed in accordance with the Law and other relevant laws, to request the deletion or destruction of personal data if the reasons requiring processing are eliminated, and to request that the transaction carried out within this scope be notified to the third parties to whom the personal data are transferred,
-
To object to any result against themselves arising from the analysis of processed data exclusively through automated systems,
-
To request compensation for damage in the event of damage due to unlawful processing of personal data.
12.2 Cases Where the Relevant Person Whose Personal Data Are Processed Cannot Assert His/Her Rights
Pursuant to Article 28 of the Law, since the following cases are excluded from the scope of the Law, the relevant persons whose personal data are processed cannot assert their rights listed in Article 12.1 regarding these issues:
-
Processing of personal data for purposes such as research, planning and statistics by anonymizing them with official statistics,
-
Processing of personal data for the purposes of art, history, literature or scientific purposes or within the scope of freedom of expression, provided that they do not violate national defense, national security, public security, public order, economic security, privacy of private life or personal rights, or constitute a crime,
-
Processing of personal data within the scope of preventive, protective and intelligence activities carried out by public institutions and organizations authorized by law to ensure national defense, national security, public security, public order or economic security,
-
Processing of personal data by judicial authorities or execution authorities in relation to investigation, prosecution, trial or execution proceedings.
Pursuant to Article 28(2) of the Law; in the cases listed below, except for the right to request compensation for damages, the relevant persons whose personal data are processed cannot assert the other rights listed in Article 12.1:
-
Where processing of personal data is necessary for the prevention of crime or for criminal investigation,
-
Processing of personal data made public by the relevant person,
-
Where processing of personal data is necessary for the execution of supervisory or regulatory duties by public institutions and organizations and by professional organizations in the nature of public institutions, based on the authority granted by law, and for disciplinary investigation or prosecution,
-
Where processing of personal data is necessary for the protection of the State’s economic and financial interests in relation to budget, tax and financial matters.
12.3 Exercise of the Rights of the Relevant Person
The relevant persons whose personal data are processed may submit their requests regarding their rights specified in this Policy to the company free of charge together with the information and documents that will identify them and by the methods specified below or by other methods determined by the Personal Data Protection Board, by filling out and signing the application form. The relevant arrangements have been made in the Creatives Data Personal Data Application and Response Procedure and the information texts.
The relevant person may exercise his/her rights:
-
By delivering in person or sending by registered mail with return receipt a wet-ink signed copy of the form available on our website, after it is filled in, to the address “Fikirtepe Mah. Rüzgar Sok. No: 29-1, Store: 10”, or by applying in person,
-
By applying to creativesdata.com via software or application developed for the purpose of application.
For an application to be considered valid under the Communiqué on the Procedures and Principles of Application to the Data Controller, the relevant person must provide the following information in the application:
a) Name, surname and, if the application is in writing, signature,
b) For Turkish citizens, T.R. identification number; for foreigners, nationality, passport number or, if any, identification number,
c) Residential or workplace address for notification,
ç) If any, e-mail address for notification, telephone and fax number,
d) Subject of the request.
Otherwise, the application will not be considered a valid application. In applications made without filling out the application form, these matters must be submitted to the company completely.
For third parties to submit an application request on behalf of the relevant persons whose personal data are processed, a special power of attorney issued by the relevant person through a notary public in favor of the person to apply must be present.
Data Controller: CREATIVES DATA
Below are definitions to assist in the review of the policy and tables of purposes for processing and transfer of personal data.
ANNEX-1 – DEFINITIONS
-
Explicit Consent: Consent that is related to a specific subject, based on being informed, and declared with free will.
-
Anonymization: The alteration of personal data in such a way that the data no longer qualify as personal data and this situation cannot be reversed. For example, through masking, aggregation, data corruption, etc., making the data unrelatable to a real person.
-
Application Form: The “Application Form Regarding Applications to be Made by the Data Subject to the Data Controller Pursuant to the Law No. 6698 on the Protection of Personal Data” used by the data subjects whose personal data are processed to exercise their rights.
-
Employee Candidate: Real persons who have applied for a job at CREATIVES DATA in any way or have opened their CV and related information.
-
Employees, Shareholders, and Officials of Cooperating Institutions: Real persons employed in institutions with which the company has any kind of business relationship (such as business partners, suppliers, etc., but not limited to these), including shareholders and officials of such institutions.
-
Business Partner: Parties with which the company establishes business partnerships to directly or jointly carry out various projects, receive services, etc.
-
Processing of Personal Data: Any operation performed on personal data, whether wholly or partially by automatic means, or by non-automatic means provided that it is part of a data recording system; such as collection, recording, storage, preservation, alteration, reorganization, disclosure, transfer, acquisition, making available, classification, or prevention of use.
-
Data Subject: The real person whose personal data are processed (e.g., visitor, employee, customer, etc.).
-
Personal Data: Any information relating to an identified or identifiable natural person (e.g., name-surname, TR ID number, e-mail, address, date of birth, credit card number, etc.). Information related to legal entities is not considered personal data under the Law.
-
Special Categories of Personal Data: Data regarding race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations, or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
-
Supplier: Parties who provide services to the company on a contractual basis in line with CREATIVES DATA’s orders and instructions while carrying out the company’s activities.
-
Third Party: Real persons whose personal data are processed within the scope of the policy but who are not otherwise defined in the policy (e.g., family members, former employees).
-
Data Processor: Real or legal persons who process personal data on behalf of the data controller based on the authority granted by the data controller (e.g., companies providing services to the company).
-
Data Controller: The person who determines the purposes and means of processing personal data and manages the place where the data are kept systematically (data recording system). Under this Policy, CREATIVES DATA is the data controller.
-
Deletion of Data: The process of preventing access to personal data by all relevant users within the company through encryption, with only the data protection officer holding the decryption key.
-
Destruction of Data: The complete and irreversible elimination of personal data physically or through technological methods.
-
Visitor: Real persons who enter the physical building owned by the company for various purposes.
ANNEX-2 – PERSONAL DATA PROCESSED BY CREATIVES DATA AND THEIR PURPOSES
Data Subject
Personal Data Categories Processed
Purposes of Processing
Employee
Identity, Contact, Professional Experience, Legal Transaction, Finance, Personnel, Visual and Audio Records, Military Data
To comply with obligations under the Labor Law No. 4857 and related regulations, ensure employee satisfaction and loyalty, fulfill obligations arising from employment contracts and legislation, manage employee benefits and rights, ensure compliance with legislation, conduct finance and accounting processes, manage assignment processes, follow up and conduct legal affairs, carry out internal audit/investigation/intelligence activities, conduct communication activities, manage and audit business activities, manage contract processes, plan HR processes, provide information to authorized persons/institutions/organizations, and carry out training activities.
Employee
Health Data
To monitor employees’ suitability for duty.
Employee Candidate
Identity, Contact, Professional Experience, Visual and Audio Records
To evaluate candidates for suitable positions during recruitment processes and to prepare for employment-related procedures; processing of identity, contact, professional experience, and financial information.
Visitor
Identity, Physical Space Security
To monitor entry/exit at company premises and ensure safety, and record visitor images via company cameras for the company’s legitimate interests.
Visitor
Identity, Transaction Security
To comply with the Law No. 5651 on Regulating Publications on the Internet and Combating Crimes Committed through Such Publications by recording who uses the internet service and for what purpose, to conduct e-commerce activities on our corporate website and mobile applications, and to verify user information.
Customer (Product/Service Recipient)
Identity, Contact, Marketing Data, Customer Transaction Data
To carry out direct marketing, digital marketing, remarketing, targeting and analysis in line with users’ preferences and needs, to promote and market products and services on our websites managed by the company.
Customer (Product/Service Recipient)
Identity, Contact, Finance, Customer Transaction Data
To deliver services to customers and carry out payment activities when services are purchased from the company.
Customer (Product/Service Recipient)
Identity, Contact, Transaction Security
To create user profiles and enable efficient use of services when users register on the company website.
Customer (Product/Service Recipient)
Identity, Contact, Legal Transaction Data
To fulfill legal and regulatory obligations arising from legislation and contracts when services are purchased from the company.
Supplier Representatives/Employees
Identity, Contact, Financial Information
For finance, accounting and legal transactions, to ensure communication, to conduct and audit business activities, and to manage contract processes within the scope of contractual relationships.
Shareholders
Identity, Contact, Risk Management, Finance, Legal Transaction
To fulfill the company’s establishment purposes, follow up investment and administrative processes, and meet obligations arising from legislation.
ANNEX-3 – THIRD PARTIES TO WHOM CREATIVES DATA TRANSFERS PERSONAL DATA AND PURPOSES OF TRANSFER
Recipient Group
Data Subjects
Purpose of Transfer
Business Partners
Customers (Product/Service Recipients)
To enable product/service recipients to access products and services at more favorable prices, to provide various advantages, and to ensure access to affordable products tailored to customers, for advertising, promotion, sales, marketing, information, promotion, campaign notifications, membership processes, and services within this scope. Data are transferred in a limited manner to research, promotion, and consultancy service providers processing data on behalf of CREATIVES DATA.
Production Companies
Customers (Product/Service Recipients)
Data are transferred to production companies and business partners on set with whom we contractually provide services and conduct mediation activities, to offer acting opportunities to service recipients.
Service Providers
Customers (Product/Service Recipients)
To ensure the quality and continuity of services provided to website users, data are transferred in a limited manner to our technology partners such as website providers, advertising agencies, and cloud infrastructure suppliers.
Service Providers
Customers (Product/Service Recipients)
To evaluate requests and complaints in line with the services provided to users, data are transferred in a limited manner to call center companies from which we receive services.
Suppliers
Customers (Product/Service Recipients)
Data are transferred in a limited manner to suppliers to provide the outsourced services necessary for the company to carry out its activities.
Authorized Public Institutions and Organizations
Customers (Product/Service Recipients)
To comply with demands of public institutions and organizations that present legal grounds, data are transferred in a limited manner.
Commercial Electronic Communication Service Providers
Customers (Product/Service Recipients)
To conduct the services provided to customers, and to fulfill legal obligations by sending electronic communications and other messages.
Banks
Customers (Product/Service Recipients)
To carry out payment activities when customers choose to make payments through our website, data are transferred in a limited manner.