X
X
X
X

Personal Data and General Confidentiality Agreement

HomepagePersonal Data and General Confidentiality Agreement
DATA PROTECTION (KVKK) AND GENERAL PRIVACY AGREEMENT
 
 
 
Etesio Teknoloji ve Yazılım San. ve Tic. Ltd. Şti. (hereinafter referred to briefly as “Etesio”) shall not share, sell, or allow the use of personal data transmitted to it electronically by Users via the website named www.etesio.net.tr (hereinafter referred to as the “Website”) for any purposes other than the circumstances specified under the “Law on the Protection of Personal Data No. 6698 (KVKK)” and the “General Data Protection Regulation (GDPR)”.
 
At Etesio, the privacy and security of our Users are of paramount importance. Etesio is committed to protecting the data you share with us. Whenever the terms "Etesio", "we", "us", or "our" are used within this Policy, they refer to Etesio (the “Data Controller”), which is responsible for the protection of your personal information in accordance with this Privacy Policy.
Etesio’s “Personal Data and General Privacy Policy” is set forth below. This Privacy Policy (hereinafter referred to as the “Policy”) explains how Etesio processes information collected on our Site and through our services (hereinafter referred to as the “Service”) that can be used directly or indirectly to identify an individual (hereinafter referred to as “Personal Data”).
 
IP Addresses: Etesio detects and utilizes the IP addresses of users when necessary to identify system-related issues, promptly resolve problems that may arise on the website / mobile applications, and, when required, notify legal authorities in accordance with the procedures and principles of the law. IP addresses may also be used to identify users in a general (anonymous) manner and to gather comprehensive demographic information.
 
Anonymous Data: Information requested by Etesio, information provided by the user, or information regarding transactions conducted via the Website may be used by Etesio and its affiliates anonymously (without disclosing the user's identity) for various statistical evaluations, database creation, presenting customized packages / offers, and market research.
 
Links to Other Websites: Etesio may provide links to other websites within the Website. Etesio bears no responsibility for the privacy practices or the content of the websites accessed via such links.
 
Bank / Credit Card Information: Etesio utilizes an SSL certificate (green bar) that ensures data security with a 256-bit encryption algorithm during data transmission. Users' bank / credit card information is used solely by the bank or the payment institution during the transaction and is under no circumstances retained or stored in the database. Etesio may offer an infrastructure through PCI DSS certified institutions where card information can be stored to facilitate the next purchase transactions of the Users. As a result of Card Storage Services that hold the PCI DSS standard and are licensed by the BRSA (Banking Regulation and Supervision Agency), the information contained in bank / credit cards facilitates the Authentication and Authorization steps, providing bank / credit card holders with the opportunity to use a secure and easy payment tool.
 
Circumstances Under Which User Data May Be Disclosed: Personal data belonging to the User includes first name-last name, address, telephone number, e-mail address, and any information aimed at identifying the user. Unless otherwise stated in this privacy policy, Etesio shall not disclose any of the personal data to third parties, except for affiliates and companies with which Etesio collaborates. Under the circumstances specified below, Etesio may deviate from the provisions of this privacy policy and disclose the information belonging to the users to third parties. These circumstances are:
  • Compliance with the obligations brought by the legal rules in force issued by the competent legal authority, such as Laws, Decrees having the Force of Law, Regulations, etc.;
  • Fulfilling the requirements of the contracts concluded by Etesio with the users and putting them into practice;
  • Cases where information regarding users is requested for the purpose of conducting an investigation or inquiry duly carried out by a competent administrative and judicial authority, and where providing information is necessary to protect the rights or security of the Users.
Etesio undertakes to keep confidential information strictly private and confidential, to deem this as an obligation of non-disclosure, and to take all necessary measures and show due diligence to ensure and maintain confidentiality, and to prevent all or any part of the confidential information from entering the public domain, or its unauthorized use, or its disclosure to a third party.
 
Status of Cookies: Etesio may obtain information about users and users' utilization of the Website by using a technical communication file (Cookie) prepared by itself or by third parties. The aforementioned technical communication files are small text files sent by a website to the user's browser to be stored in the main memory. The technical communication file keeps the session open by storing the user's session information, password, and preferences, and facilitates use by recognizing the user upon their next visit. The technical communication file helps to obtain statistical information regarding how many people use the Website, for what purpose and how many times a person visits the Website, and how long they stay, and to dynamically generate advertisements and content from user pages specially designed for users. The technical communication file is not designed to retrieve data or any other personal information from the main memory or e-mail. Most browsers are initially designed to accept the technical communication file; however, users may change the settings so that the technical communication file is blocked or a warning is given when the technical communication file is sent.
 
Data Collected in Surveys, Contests, and Similar Cases: Information requested from users who respond to periodic surveys and contests organized by Etesio within the Website is used by Etesio and its collaborators for the purposes of direct marketing to these users, performing statistical analysis, and creating databases.
 
E-newsletter Dispatches and Announcements: Etesio dispatches weekly e-newsletters to inform its users about economic developments, the agenda, and their respective fields. When deemed necessary or in the event of an agreement with third-party partners, it may send Campaign / Offer / Package announcements with promotional and informational content. When you create an account on our system for the first time, you accept e-mail and SMS transmissions by default. Users can prevent these e-mails from reaching them by clicking on the specified link, as explained at the bottom of the e-mail. Furthermore, options to block these are available in your user panel. If you wish to unsubscribe from our daily e-mail distribution list at any time, you can easily unsubscribe from the e-newsletter with a single click by clicking on the link "Please click to unsubscribe from our e-newsletter list" located at the bottom of the e-mails we send.
 
General Information on the Law on the Protection of Personal Data
The Law on the Protection of Personal Data No. 6698 was enacted on March 24, 2016, and was published in the Official Gazette No. 29677 dated April 7, 2016. The European Union General Data Protection Regulation (GDPR) entered into force on May 25, 2018. In our capacity as the data controller under the Law on the Protection of Personal Data No. 6698 and the European Union General Data Protection Regulation (GDPR), we may record, classify, process, store, update, and—under circumstances permitted by legislative rules and your given consent—disclose the personal data of you, our esteemed customers, to third parties. We hereby inform you regarding our mutual rights and obligations within the scope of the aforementioned legal regulations.
 
Information on Capacity as Data Controller
In accordance with the laws specified above, Etesio, whose detailed corporate information is published below, in its capacity as the Data Controller, shall record, store, update, classify, process, and—where permitted by legislation—disclose / transfer your personal data to third parties within the framework explained below.
 
Definition of Personal Data Under the Law
It refers to any information that makes you identified or identifiable, such as your identity credentials (first name, last name, date of birth, national ID number, etc.), contact details, and information regarding the methods used during access to products (IP address, mobile phone brand-model, browser type, version, social media information, interactions performed on screens, etc.).
 
Methods of Processing Your Personal Data
In accordance with the KVKK No. 6698 and the EU General Data Protection Regulation (GDPR), your personal data shared with our company may be processed by us either fully or partially, by automated means, or by non-automated means provided that it forms part of any data filing system, through obtaining, recording, storing, altering, or reorganizing; and provided that its security and confidentiality are ensured under the legislation: through disclosing, transferring, taking over, making available for collection, classifying, or preventing its use—in short, by being subject to any operation performed on data. Under the laws specified above, any operation performed on data is deemed as "processing of personal data".
Purposes and Legal Grounds for Processing Your Personal Data
Your shared personal data shall be processed in accordance with the scope, procedures, and principles of the KVKK No. 6698 and the EU General Data Protection Regulation (GDPR) for the following purposes:
  • To fulfill the requirements of the services we provide to our customers, in accordance with the requirements of the contract and technology, and to develop our offered products and services;
  • To issue official invoices following the purchase of all products and services we provide;
  • To comply with data retention, reporting, and information disclosure obligations stipulated by legislation and other regulatory authorities;
  • To provide information upon request and as required by legislation to prosecutor's offices, courts, and relevant public officials regarding matters of public safety and legal disputes.
Your identity, address, tax number, and other information will be recorded to determine the transaction owner and counterparty in any business or transaction carried out regarding all kinds of products and services to be offered to you; information and documents that will serve as the basis for business and transactions to be carried out in electronic environment will be issued; data retention, reporting, and information disclosure obligations stipulated by all administrative and judicial competent authorities (such as courts, TBB, BRSA, CMB, CBRT, MASAK, ICTA) pursuant to the relevant legislation will be complied with; and other products and services offered and requested by Etesio will be supplied, and the requirements of the contracts between us will be fulfilled.
 
Information on Third Parties or Organizations to Which Your Personal Data May Be Transferred
For the purposes specified above, the persons / organizations to which your personal data shared with our company may be transferred are: our main shareholders, our direct or indirect domestic / foreign subsidiaries, and, including but not limited to, persons and organizations related to the service provided, organizations of program partners, domestic / foreign organizations, and other third parties from whom we receive services or with whom we cooperate to carry out our activities and/or in the capacity of Data Processor.
Furthermore, your personal data may be transferred, within the framework of our respective collaborations, to institutions, organizations, banks, financial institutions, providers, or firms with which we cooperate, form program partnerships, or receive services regarding product/service comparison and application placement; to persons and institutions from which we receive cloud data storage services; to institutions with which we have agreements regarding the delivery of communications dispatched to our customers, and to other third parties.
 
Methods of Collection of Your Personal Data
Your personal data may be processed and collected through the following channels:
  • In the form of identity and profile details including first name, last name, national identification number, passport number, address, telephone number, business or personal email address, age, gender, profession, username, and password via the forms on our Company's website and mobile applications; along with data containing preferences on pages logged into, IP logs of transactions performed, cookie data collected by the browser, browsing durations and details, and location data;
  • Verbally, in writing, or electronically through our sales and marketing department employees, our agents, our dealers, paper-based forms, business cards, digital marketing, and call center channels;
  • Physically or virtually, face-to-face or remotely, verbally, in writing, or electronically from persons who share their personal data via business cards, curriculum vitae (CV), submission of proposals, and other means for purposes such as establishing a commercial relationship with our Company, making a job application, or submitting a proposal;
  • Furthermore, data obtained indirectly from different channels, including (micro) websites and social media used for purposes such as websites, blogs, contests, surveys, games, campaigns, and similar intents; e-newsletter reading or clicking interactions; data provided by public databases; and profiles and data open to sharing on social networking sites such as social media platforms (Facebook, Twitter, Google, Instagram, Snapchat, etc.).
Your personal data obtained prior to the entry into force of the KVKK No. 6698 and the EU General Data Protection Regulation (GDPR), which was legally obtained before the effective date of the KVKK (April 7, 2016) and the effective date of the EU General Data Protection Regulation (GDPR) (May 25, 2018), is also processed and maintained on our servers located in a data center in "Germany", which is "secured 24/7 and equipped with all kinds of protective measures" in accordance with the terms and conditions set forth in this document.
 
Retention and Protection of Personal Data
Your personal data shall be stored confidentially in the database and systems held by our company in accordance with the KVKK No. 6698 and the EU General Data Protection Regulation (GDPR); and shall under no circumstances be shared with third parties except for legal obligations and the regulations specified in this document. Our Company is obliged to take software-based technical measures such as hashing, encryption, transaction logging, access management, and physical security measures in order to prevent unlawful processing of personal data, block access by unauthorized persons, and ensure their preservation as per the KVKK No. 6698 and the EU General Data Protection Regulation (GDPR). In the event that it is learned that personal data has been obtained by others through unlawful means, the situation shall be notified immediately, duly in accordance with the legal regulations and in writing, to the Personal Data Protection Board.
Personal data shall be retained as long as the purpose of providing this information remains valid. In order to determine your needs, provide you with faster service, and meet your subsequent service requests, your data will continue to be processed by us even after the service you receive from us terminates. If the data is required to be held for reporting and informational purposes before legal authorities and relevant public authorities subject to statutory periods, or to be stored for longer periods pursuant to legislation, these limits shall be complied with. Necessary security measures shall be taken by us to ensure that stored and recorded data is not lost, does not fall into the hands of unauthorized persons, and to prevent unlawful uses.
 
Keeping Personal Data Accurate and Up-to-Date
Pursuant to Article 4 of the KVKK, our Company has an obligation to keep your personal data accurate and up-to-date. Within this scope, in order for our Company to fulfill its obligations arising from the applicable legislation, our Customers must share their accurate and up-to-date data or update it via the website / mobile application.
 
Rights of the Personal Data Subject Pursuant to KVKK No. 6698 and EU General Data Protection Regulation (GDPR)
The Personal Data Subject has the right to apply to our Company (data controller) and request the following regarding themselves:
  • To learn whether their personal data is being processed,
  • To request information if their personal data has been processed,
  • To learn the purpose of processing the personal data and whether they are used in accordance with their purpose,
  • To know the third parties to whom personal data is transferred domestically or abroad,
  • To request correction of personal data if it is incomplete or incorrectly processed,
  • To request the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the KVKK,
  • To request that the third parties to whom the personal data has been transferred be notified of these operations in the event of correction, deletion, or destruction of personal data,
  • To object to the occurrence of a result against the person himself/herself by analyzing the processed data exclusively through automated systems,
  • To demand the compensation of the damage in case of incurring damage due to unlawful processing of personal data.
Registered under the trade registry number 29462 of the Şanlıurfa Chamber of Commerce, possessing the MERSIS number 0925106481600001, located at the address "Ulubağ Mah. Recep Tayyip Erdoğan Bulv. No: 287/A, İç Kapı No: 212, Haliliye / ŞANLIURFA", Etesio Teknoloji ve Yazılım San. ve Tic. Ltd. Şti. is the Data Controller within the scope of the KVKK No. 6698 and the EU General Data Protection Regulation (GDPR).
 
Personal Data Subjects may direct their questions, opinions, or requests to any of the following communication channels:
Email: info@etesio.com.tr
Postal Address: Ulubağ Mah. Recep Tayyip Erdoğan Bulv. No: 287/A, İç Kapı No: 212, Haliliye / ŞANLIURFA
 
Our Company may respond to the transmitted requests positively or negatively, provided that it is reasoned and within 30 days, in written or digital environment. It is essential that the necessary transactions regarding the requests are free of charge. However, if the transactions require a cost, our Company reserves the right to demand a fee. These fees are determined over the tariff specified by the Personal Data Protection Board according to Article 13 of the Law on the Protection of Personal Data.

 

Top