Etesio undertakes to keep confidential information strictly private and confidential, to deem this as an obligation of non-disclosure, and to take all necessary measures and show due diligence to ensure and maintain confidentiality, and to prevent all or any part of the confidential information from entering the public domain, or its unauthorized use, or its disclosure to a third party.
General Information on the Law on the Protection of Personal Data
The Law on the Protection of Personal Data No. 6698 was enacted on March 24, 2016, and was published in the Official Gazette No. 29677 dated April 7, 2016. The European Union General Data Protection Regulation (GDPR) entered into force on May 25, 2018. In our capacity as the data controller under the Law on the Protection of Personal Data No. 6698 and the European Union General Data Protection Regulation (GDPR), we may record, classify, process, store, update, and—under circumstances permitted by legislative rules and your given consent—disclose the personal data of you, our esteemed customers, to third parties. We hereby inform you regarding our mutual rights and obligations within the scope of the aforementioned legal regulations.
Information on Capacity as Data Controller
In accordance with the laws specified above, Etesio, whose detailed corporate information is published below, in its capacity as the Data Controller, shall record, store, update, classify, process, and—where permitted by legislation—disclose / transfer your personal data to third parties within the framework explained below.
Definition of Personal Data Under the Law
It refers to any information that makes you identified or identifiable, such as your identity credentials (first name, last name, date of birth, national ID number, etc.), contact details, and information regarding the methods used during access to products (IP address, mobile phone brand-model, browser type, version, social media information, interactions performed on screens, etc.).
Methods of Processing Your Personal Data
In accordance with the KVKK No. 6698 and the EU General Data Protection Regulation (GDPR), your personal data shared with our company may be processed by us either fully or partially, by automated means, or by non-automated means provided that it forms part of any data filing system, through obtaining, recording, storing, altering, or reorganizing; and provided that its security and confidentiality are ensured under the legislation: through disclosing, transferring, taking over, making available for collection, classifying, or preventing its use—in short, by being subject to any operation performed on data. Under the laws specified above, any operation performed on data is deemed as "processing of personal data".
Purposes and Legal Grounds for Processing Your Personal Data
Your shared personal data shall be processed in accordance with the scope, procedures, and principles of the KVKK No. 6698 and the EU General Data Protection Regulation (GDPR) for the following purposes:
- To fulfill the requirements of the services we provide to our customers, in accordance with the requirements of the contract and technology, and to develop our offered products and services;
- To issue official invoices following the purchase of all products and services we provide;
- To comply with data retention, reporting, and information disclosure obligations stipulated by legislation and other regulatory authorities;
- To provide information upon request and as required by legislation to prosecutor's offices, courts, and relevant public officials regarding matters of public safety and legal disputes.
Your identity, address, tax number, and other information will be recorded to determine the transaction owner and counterparty in any business or transaction carried out regarding all kinds of products and services to be offered to you; information and documents that will serve as the basis for business and transactions to be carried out in electronic environment will be issued; data retention, reporting, and information disclosure obligations stipulated by all administrative and judicial competent authorities (such as courts, TBB, BRSA, CMB, CBRT, MASAK, ICTA) pursuant to the relevant legislation will be complied with; and other products and services offered and requested by Etesio will be supplied, and the requirements of the contracts between us will be fulfilled.
Information on Third Parties or Organizations to Which Your Personal Data May Be Transferred
For the purposes specified above, the persons / organizations to which your personal data shared with our company may be transferred are: our main shareholders, our direct or indirect domestic / foreign subsidiaries, and, including but not limited to, persons and organizations related to the service provided, organizations of program partners, domestic / foreign organizations, and other third parties from whom we receive services or with whom we cooperate to carry out our activities and/or in the capacity of Data Processor.
Furthermore, your personal data may be transferred, within the framework of our respective collaborations, to institutions, organizations, banks, financial institutions, providers, or firms with which we cooperate, form program partnerships, or receive services regarding product/service comparison and application placement; to persons and institutions from which we receive cloud data storage services; to institutions with which we have agreements regarding the delivery of communications dispatched to our customers, and to other third parties.
Methods of Collection of Your Personal Data
Your personal data may be processed and collected through the following channels:
- In the form of identity and profile details including first name, last name, national identification number, passport number, address, telephone number, business or personal email address, age, gender, profession, username, and password via the forms on our Company's website and mobile applications; along with data containing preferences on pages logged into, IP logs of transactions performed, cookie data collected by the browser, browsing durations and details, and location data;
- Verbally, in writing, or electronically through our sales and marketing department employees, our agents, our dealers, paper-based forms, business cards, digital marketing, and call center channels;
- Physically or virtually, face-to-face or remotely, verbally, in writing, or electronically from persons who share their personal data via business cards, curriculum vitae (CV), submission of proposals, and other means for purposes such as establishing a commercial relationship with our Company, making a job application, or submitting a proposal;
- Furthermore, data obtained indirectly from different channels, including (micro) websites and social media used for purposes such as websites, blogs, contests, surveys, games, campaigns, and similar intents; e-newsletter reading or clicking interactions; data provided by public databases; and profiles and data open to sharing on social networking sites such as social media platforms (Facebook, Twitter, Google, Instagram, Snapchat, etc.).
Your personal data obtained prior to the entry into force of the KVKK No. 6698 and the EU General Data Protection Regulation (GDPR), which was legally obtained before the effective date of the KVKK (April 7, 2016) and the effective date of the EU General Data Protection Regulation (GDPR) (May 25, 2018), is also processed and maintained on our servers located in a data center in "Germany", which is "secured 24/7 and equipped with all kinds of protective measures" in accordance with the terms and conditions set forth in this document.
Retention and Protection of Personal Data
Your personal data shall be stored confidentially in the database and systems held by our company in accordance with the KVKK No. 6698 and the EU General Data Protection Regulation (GDPR); and shall under no circumstances be shared with third parties except for legal obligations and the regulations specified in this document. Our Company is obliged to take software-based technical measures such as hashing, encryption, transaction logging, access management, and physical security measures in order to prevent unlawful processing of personal data, block access by unauthorized persons, and ensure their preservation as per the KVKK No. 6698 and the EU General Data Protection Regulation (GDPR). In the event that it is learned that personal data has been obtained by others through unlawful means, the situation shall be notified immediately, duly in accordance with the legal regulations and in writing, to the Personal Data Protection Board.
Personal data shall be retained as long as the purpose of providing this information remains valid. In order to determine your needs, provide you with faster service, and meet your subsequent service requests, your data will continue to be processed by us even after the service you receive from us terminates. If the data is required to be held for reporting and informational purposes before legal authorities and relevant public authorities subject to statutory periods, or to be stored for longer periods pursuant to legislation, these limits shall be complied with. Necessary security measures shall be taken by us to ensure that stored and recorded data is not lost, does not fall into the hands of unauthorized persons, and to prevent unlawful uses.
Keeping Personal Data Accurate and Up-to-Date
Pursuant to Article 4 of the KVKK, our Company has an obligation to keep your personal data accurate and up-to-date. Within this scope, in order for our Company to fulfill its obligations arising from the applicable legislation, our Customers must share their accurate and up-to-date data or update it via the website / mobile application.
Rights of the Personal Data Subject Pursuant to KVKK No. 6698 and EU General Data Protection Regulation (GDPR)
The Personal Data Subject has the right to apply to our Company (data controller) and request the following regarding themselves:
- To learn whether their personal data is being processed,
- To request information if their personal data has been processed,
- To learn the purpose of processing the personal data and whether they are used in accordance with their purpose,
- To know the third parties to whom personal data is transferred domestically or abroad,
- To request correction of personal data if it is incomplete or incorrectly processed,
- To request the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the KVKK,
- To request that the third parties to whom the personal data has been transferred be notified of these operations in the event of correction, deletion, or destruction of personal data,
- To object to the occurrence of a result against the person himself/herself by analyzing the processed data exclusively through automated systems,
- To demand the compensation of the damage in case of incurring damage due to unlawful processing of personal data.
Registered under the trade registry number 29462 of the Şanlıurfa Chamber of Commerce, possessing the MERSIS number 0925106481600001, located at the address "Ulubağ Mah. Recep Tayyip Erdoğan Bulv. No: 287/A, İç Kapı No: 212, Haliliye / ŞANLIURFA", Etesio Teknoloji ve Yazılım San. ve Tic. Ltd. Şti. is the Data Controller within the scope of the KVKK No. 6698 and the EU General Data Protection Regulation (GDPR).
Personal Data Subjects may direct their questions, opinions, or requests to any of the following communication channels:
Email: info@etesio.com.tr
Postal Address: Ulubağ Mah. Recep Tayyip Erdoğan Bulv. No: 287/A, İç Kapı No: 212, Haliliye / ŞANLIURFA
Our Company may respond to the transmitted requests positively or negatively, provided that it is reasoned and within 30 days, in written or digital environment. It is essential that the necessary transactions regarding the requests are free of charge. However, if the transactions require a cost, our Company reserves the right to demand a fee. These fees are determined over the tariff specified by the Personal Data Protection Board according to Article 13 of the Law on the Protection of Personal Data.