GDPR

ÇİĞDEM KUNDURA CLARIFICATION TEXT ON THE PROCESSING OF PERSONAL DATA

1. DATA CONTROLLER

Within the scope of the Personal Data Protection Law No. 6698, your personal data is processed by the following data controller:

Trade Name: HASAN CAVİT TATAR - ÇİĞDEM KUNDURA
Business Type: Sole Proprietorship
MERSİS Number: 3184-3000-3460-0013
Tax Office: Arhavi Tax Office
Tax Number: 8310006836
Address: Musazade Mahallesi, İzmir Pasajı No: 20/B, Arhavi/Artvin
Phone: 0466 312 39 40
E-mail: bilgi@cigdemkundura.com
Website: https://www.cigdemkundura.com

In this text, the data controller will be referred to as "Çiğdem Kundura".

2. SCOPE OF THE CLARIFICATION TEXT

This Clarification Text covers;

  1. Those who visit the website,
  2. Those who create a membership account,
  3. Customers who place orders,
  4. Those who shop at the physical store,
  5. Those who make return, exchange, or product inspection requests,
  6. Those who communicate with customer service,
  7. Those who provide consent for commercial electronic messages

are covered.

3. PERSONAL DATA THAT MAY BE PROCESSED

Depending on the nature of the activity, the following personal data may be processed:

Identity Information: Name, surname, tax identity information and legal entity title if required for invoicing.

Contact Information: Phone number, e-mail address, delivery address, and billing address.

Customer Transaction Information: Orders, products, basket information, delivery records, return and exchange transactions, campaign and coupon usage, customer service requests, and complaints.

Financial Information: Payment status, refund amount, transaction number, and invoice information. Full card details are not stored directly by Çiğdem Kundura.

Transaction Security Information: IP address, session and login records, device and browser information, security records, and cookie identifiers.

Marketing Information: Commercial electronic message preferences, campaign interactions, shopping, and interest analyses.

Legal Transaction Information: Correspondence with authorized institutions, dispute and application records.

Visual and Auditory Information: Photographs, videos, and voice recordings sent by the customer during product inspection, return, exchange, or complaint processes.

4. PURPOSES OF PROCESSING PERSONAL DATA

Personal data may be processed for the following purposes:

  1. Creating and managing membership accounts,
  2. Receiving, preparing, and delivering orders,
  3. Executing payment, invoicing, accounting, and refund transactions,
  4. Finalizing return, exchange, right of withdrawal, and product inspection requests,
  5. Executing customer service, request, and complaint processes,
  6. Ensuring the security of identity, communication, orders, and payments,
  7. Preventing fraud, fake orders, and abuse,
  8. Operating, improving, and measuring the performance of the website,
  9. Managing inventory, sales, supply, accounting, and business processes,
  10. Fulfilling legal obligations,
  11. Meeting the lawful requests of authorized public institutions,
  12. Establishing, exercising, or protecting a right,
  13. Conducting campaign and marketing activities in the presence of explicit consent or commercial message approval.

5. LEGAL GROUNDS FOR PROCESSING PERSONAL DATA

Personal data is processed based on the following legal grounds, depending on the nature of the activity:

  1. Being directly related to the establishment or performance of a contract,
  2. Fulfillment of a legal obligation by the data controller,
  3. Processing being necessary for the establishment, exercise, or protection of a right,
  4. Legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject,
  5. Being clearly stipulated by law,
  6. Explicit consent of the data subject for necessary activities.

In cases where explicit consent is the legal basis, the data subject may withdraw their consent at any time. The withdrawal of consent does not affect the legality of the processing carried out prior to the withdrawal.

6. METHODS OF COLLECTING PERSONAL DATA

Personal data may be collected through;

  1. Membership and order forms,
  2. Payment and delivery screens,
  3. Physical store transactions,
  4. Telephone, e-mail, WhatsApp, and contact forms,
  5. Return, exchange, and product inspection applications,
  6. Cookies and similar technologies,
  7. Transaction records received from shipping, payment, and e-commerce infrastructure providers,
  8. Authorized public institutions and other legally authorized sources

via automated or non-automated methods.

7. TRANSFER OF PERSONAL DATA

Personal data may be transferred to the following categories of recipients, provided that it is limited and proportionate to the processing purposes:

  1. Shipping and logistics companies,
  2. Banks and payment service providers,
  3. E-commerce infrastructure, hosting, software, ERP, and integration service providers,
  4. Accounting, financial consultancy, legal, and advisory service providers,
  5. Communication, messaging, and customer service providers,
  6. Advertising and analysis service providers, provided there is explicit consent or another appropriate legal basis,
  7. Manufacturers, importers, and suppliers,
  8. Authorized public institutions, courts, and enforcement offices.

Transfers are carried out only for the purpose of fulfilling the relevant service, meeting legal obligations, or protecting rights.

8. TRANSFER OF DATA ABROAD

Personal data may be transferred abroad due to the fact that e-commerce infrastructure, hosting, payment, analysis, communication, or similar technological services are offered through systems located abroad.

Transfers abroad are carried out if one of the conditions specified in Article 9 of Law No. 6698 is met and the necessary security or permission processes are applied.

In cases where the transfer must be based on explicit consent, the data subject's separate explicit consent is obtained.

9. STORAGE OF DATA

Personal data is retained for the period necessary for the processing purpose and in accordance with the retention periods stipulated in the relevant legislation.

Order, invoice, payment, accounting, delivery, return, and legal transaction records may be kept during the statutory retention periods.

Data for which the retention period has expired and for which there is no other legal basis requiring its processing is deleted, destroyed, or anonymized.

10. DATA SECURITY

Çiğdem Kundura takes technical and administrative measures proportionate to the risk in order to;

  1. Prevent unlawful processing of personal data,
  2. Prevent unlawful access to personal data,
  3. Ensure the secure storage of personal data.

Authorization, access restriction, password security, record keeping, updates, and service provider controls may be included among these measures.

11. COMMERCIAL ELECTRONIC MESSAGES

Creating a membership or placing an order does not mean that automatic consent is given for sending electronic messages for advertising and marketing purposes.

When necessary, commercial electronic message consent is obtained separately.

The data subject may withdraw their commercial message permission via the opt-out method specified in the message or by contacting Çiğdem Kundura.

Notifications regarding orders, delivery, payment, security, and customer service may be sent as part of fulfilling the service.

12. RIGHTS OF THE DATA SUBJECT

Within the scope of Article 11 of Law No. 6698, data subjects have the right to;

  1. Learn whether their personal data has been processed,
  2. Request information if it has been processed,
  3. Learn the purpose of processing and whether it is used in accordance with its purpose,
  4. Know the third parties to whom it is transferred domestically or abroad,
  5. Request correction of incomplete or incorrectly processed data,
  6. Request deletion or destruction if the legal conditions are met,
  7. Request notification of the correction, deletion, or destruction operations to third parties to whom the data was transferred,
  8. Object to the emergence of a result against them as a result of the analysis of the data exclusively through automated systems,
  9. Request compensation for damages in case of loss due to unlawful data processing.

13. APPLICATION METHOD

Applications within the scope of the KVKK may be submitted via;

  1. In writing with documents verifying identity to the address: Musazade Mahallesi, İzmir Pasajı No: 20/B, Arhavi/Artvin,
  2. Via the e-mail address registered in the Çiğdem Kundura systems to bilgi@cigdemkundura.com,
  3. Other methods accepted by legislation.

The application must contain the name, surname, contact information, a clear explanation of the request, and information suitable for identity verification.

Çiğdem Kundura concludes the application as soon as possible and within thirty days at the latest, depending on the nature of the request.

If the process requires additional costs, a fee permitted by legislation may be charged.