Hakan Yigen Test AŞ
Como funciona Recursos Setores e-Fatura Preços FAQ
Türkçe English Español Deutsch العربية Português Bahasa Indonesia Bahasa Melayu हिन्दी
Entrar Trial gratuito de 7 dias
Início / Aviso de Privacidade KVKK

Aviso de Privacidade KVKK

Informações sobre o tratamento de dados pessoais conforme a Lei Turca nº 6698.

Última atualização: 01.04.2025

1. Identity of the Data Controller

Pursuant to the Turkish Personal Data Protection Law No. 6698 ("Law"), your personal data will be processed by Fatih Öztürk (Convord.com, the "Company") as the data controller within the scope described below.

Data ControllerFatih Öztürk
Trade NameConvord.com
AddressŞeyhmüftü Mahallesi, Çarıkçılar Çarşısı Sokak No:2 İç Kapı No:2, Mustafakemalpaşa/Bursa
Phone+90 XXX XXX XX XX
Emailkvkk@convord.com
Websitehttps://convord.com

This Disclosure Notice has been prepared in accordance with Article 10 of the Law and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform, and is intended to inform you about our personal data processing activities.

2. Personal Data Processed and Purposes of Processing

The table below sets out in detail the categories of personal data processed and the purposes for which they are processed:

Data CategoryData ProcessedPurposes of Processing
Identity Information First name, last name, Turkish ID number (e-invoice only), company name, tax number
  • Creation and management of membership registration
  • Conclusion and performance of the contract
  • Issuance of invoices and financial documents
  • Fulfillment of legal obligations
Contact Information Email address, phone number, WhatsApp number, business address
  • Account verification and security notifications
  • WhatsApp Business API integration
  • Technical support and communication
  • Notification of service changes
Financial Information Subscription plan, payment history, billing information
  • Subscription management and billing
  • Maintenance of financial records
  • Fulfillment of legal accounting obligations
Transaction Information Order details, WhatsApp message content, product catalog information, customer data, invoice/delivery note data
  • Provision of Platform services
  • Conversion of messages into order data
  • Order management and inventory tracking
  • Creation of e-invoice/e-archive invoice
Transaction Security Information IP address, session information, access logs, password (hashed)
  • Ensuring Platform security
  • Detection and prevention of unauthorized access
  • Conduct of information security processes
Marketing Information Cookie data, page views, preference information
  • Improvement of user experience
  • Service development and analysis
  • Marketing activities where explicit consent has been obtained
Audio/Visual Records WhatsApp voice message files, text transcriptions of voice messages
  • Conversion of voice orders into text
  • Order verification and error checking

3. Legal Grounds for Processing Personal Data

Your personal data is processed on the following legal grounds specified in Article 5 of the Law:

3.1. Explicit Consent (Law Art. 5/1)

  • Transmission of commercial electronic messages
  • Use of non-essential cookies
  • Profiling and delivery of personalized content

3.2. Explicitly Provided for by Law (Law Art. 5/2-a)

  • Issuance and retention of invoices and financial documents under the Tax Procedure Law
  • Maintenance of commercial books and records under the Turkish Commercial Code
  • Information obligations under the Law on the Regulation of Electronic Commerce

3.3. Conclusion or Performance of a Contract (Law Art. 5/2-c)

  • Creation of membership registration
  • Provision of Platform services
  • Subscription management and payment transactions
  • Processing of WhatsApp messages and creation of orders
  • Provision of technical support

3.4. Legal Obligation of the Data Controller (Law Art. 5/2-ç)

  • Compliance with legal regulations
  • Disclosure of information to authorized institutions and organizations
  • Conduct of financial audit processes

3.5. Legitimate Interest of the Data Controller (Law Art. 5/2-f)

  • Ensuring Platform security
  • Prevention of fraud and misuse
  • Improvement of service quality
  • Statistical analysis (with anonymized data)

4. Transfer of Personal Data

4.1. Domestic Transfer

Your personal data may be transferred to the following parties pursuant to Article 8 of the Law:

  • Uyumsoft: Invoice and tax information for the purpose of issuing e-invoice and e-archive invoice
  • PayTR: Billing information for the purpose of carrying out payment transactions
  • Legal authorities: Relevant public institutions and organizations in cases of legal obligation
  • Accounting software: Logo, Mikro, or Eta accounting software at the user's request

4.2. Cross-Border Transfer

Your personal data may be transferred abroad in the following circumstances pursuant to Article 9 of the Law:

  • WhatsApp (Meta Platforms, USA): Message data for the provision of WhatsApp Business API services
  • Artificial intelligence service providers: Message content for message analysis and order extraction
  • Stripe / PayPal (USA): For the purpose of carrying out international payment transactions
  • Server infrastructure provider: For data hosting services

Cross-border transfer is carried out where your explicit consent exists or where the conditions set forth in Articles 5/2 and 9 of the Law are met. Whether adequate protection exists in the countries to which data is transferred is assessed by the Board; where adequate protection does not exist, Standard Contractual Clauses or binding corporate rules are applied.

5. Method of Collecting Personal Data

Your personal data is collected by automatic or non-automatic means through the following methods:

  • Platform membership and registration forms (non-automatic)
  • User interactions on the Platform (automatic)
  • Messages received via WhatsApp Business API (automatic)
  • Cookies and similar tracking technologies (automatic)
  • Email and communication channels (non-automatic)
  • Third-party service providers (payment providers, e-invoice service, etc.)

6. Rights of the Data Subject

Pursuant to Article 11 of the Law, as a data subject you have the following rights:

  1. To learn whether your personal data is being processed
  2. To request information if your personal data has been processed
  3. To learn the purpose of processing your personal data and whether they are used in accordance with that purpose
  4. To know the third parties to whom your personal data is transferred domestically or abroad
  5. To request correction where your personal data has been processed incompletely or inaccurately
  6. To request deletion or destruction of your personal data within the framework of the conditions set forth in Article 7 of the Law
  7. To request that the operations carried out pursuant to Articles 5 and 6 be notified to third parties to whom your personal data has been transferred
  8. To object to the emergence of a result against you by means of analysis of processed data exclusively through automated systems
  9. To request compensation for damage suffered due to unlawful processing of your personal data

7. Application Method

To exercise the rights set out above, you may use one of the following methods:

Application MethodAddress / InformationSubject of Application
Email kvkk@convord.com The subject line must include "KVKK Information Request"
Within the Platform Settings > Profile > Data Request Direct submission of a request through the system
Post Şeyhmüftü Mahallesi, Çarıkçılar Çarşısı Sokak No:2 İç Kapı No:2, Mustafakemalpaşa/Bursa Wet-signed or notarized petition
KEP (To be updated when the KEP address is determined) Application via registered electronic mail

7.1. Information Required in the Application

  • First name, last name, and signature (for physical applications)
  • Turkish ID number (for citizens of the Republic of Türkiye) or passport number (for foreign nationals)
  • Residential or business address for service of process
  • Email address and/or phone number for notification
  • Subject of the request

7.2. Response to Applications

  • Applications are concluded free of charge as soon as possible and in any event within 30 (thirty) days, depending on the nature of the request.
  • Where the operation requires an additional cost, a fee may be charged in accordance with the tariff determined by the Personal Data Protection Board.
  • Where a request is rejected, the grounds for rejection are communicated to the applicant in writing or by electronic means.

8. Data Security Measures

Our Company takes all necessary technical and administrative measures to ensure an appropriate level of security in order to prevent unlawful processing of and access to your personal data and to ensure their safekeeping:

8.1. Technical Measures

  • Data transmission security with SSL/TLS 256-bit encryption
  • Database encryption (encryption at rest)
  • Storage of passwords using one-way hash algorithms (bcrypt/argon2)
  • Web application firewall (WAF) and intrusion detection/prevention systems (IDS/IPS)
  • Regular penetration tests and security scans
  • Maintenance and monitoring of access logs (audit log)
  • Automatic daily backup and disaster recovery plan
  • Rate limiting and brute-force protection
  • CSRF, XSS, SQL Injection protections

8.2. Administrative Measures

  • Personal data processing inventory and data classification
  • Access authorization matrix and principle of least privilege
  • Regular data security training for employees
  • Confidentiality and data processing agreements
  • Data breach response procedure
  • Regular internal audits

9. Retention Periods for Personal Data

Your personal data is retained for the period required by the purposes of processing and for the limitation periods prescribed by applicable legislation. Upon expiry of the retention period or where the purpose of processing ceases to exist, your personal data is deleted, destroyed, or anonymized in accordance with the provisions of the Regulation on Deletion, Destruction, or Anonymization of Personal Data.

Principal statutory retention periods:

  • Turkish Commercial Code (Art. 82): Commercial books and records – 10 years
  • Tax Procedure Law (Art. 253): Invoices and financial documents – 5 years
  • Law No. 6563: Electronic commerce records – 3 years
  • Code of Obligations (Art. 146): General limitation period – 10 years
  • Labor Law: Employee data – 5 years from termination of the employment relationship

10. Application to the Personal Data Protection Authority

Where your application to our Company is rejected, the response provided is found insufficient, or no response is given within the prescribed period, you may lodge a complaint with the Personal Data Protection Authority ("Board") within 30 (thirty) days from the date on which you learn of the response, and in any event within 60 (sixty) days from the date of application.

Personal Data Protection Authority:
Nasuh Akar Mahallesi, Ziyabey Caddesi No:6, 06520 Balgat-Çankaya/Ankara
Web: www.kvkk.gov.tr

11. Changes to This Disclosure Notice

This Disclosure Notice may be updated in line with changes in legal regulations, updates to our data processing activities, or decisions of the Board. The updated text enters into force upon publication on the Platform. You will be notified by email of material changes.

Hakan Yigen Test AŞ

Backbone de pedidos atacado WhatsApp: pedidos, estoque e contas a receber em um painel.

Soluções

  • Guia de pedidos WhatsApp
  • Gestão de pedidos WhatsApp
  • Pedidos atacado e estoque
  • Contas a receber
  • Guia de Integração

Documentação

  • Todos os documentos
  • Configuração Meta e WhatsApp
  • Configuração Logo e Mikro
  • Guia de configuração Uyumsoft
  • Preços

Legal

  • Política de Privacidade
  • Termos de Serviço
  • Aviso de Privacidade (KVKK)
  • Contrato de Venda à Distância
  • Política de Cookies
  • Programa de Parceiros

© 2026 Convord. Todos os direitos reservados.