Skip to Content

EMBEDYA PRIVACY AND KVKK POLICY


DOCUMENT INFORMATION

Information - Details

Document Name: Privacy and KVKK Policy

Version: v1.0

Effective Date: 02 May 2025

Data Controller: Embedya Yazılım Donanım ve Arge Ltd. Şti.

MERSİS Number: 0333267315000001

Tax Identification Number (VKN): 3332673150

Address: İVEDİKOSB MAH. 2224 CAD. NO: 1 İÇ KAPI NO: 116 YENİMAHALLE/ANKARA

Contact: Email: info@embedya.com | Phone:

1. INTRODUCTION

At Embedya, we attach great importance to the privacy and security of your personal data. This Privacy and KVKK Policy explains how personal data collected through Embedya’s website (“Website”), mobile application (“Mobile Application”), and all of its services is processed and protected, as well as the rights you have regarding your personal data.

This Policy has been prepared in accordance with the Turkish Personal Data Protection Law No. 6698 (“KVKK”) and the relevant legislation. For detailed information, please visit our KVKK Clarification Text and Cookie Policy pages.

2. DATA CONTROLLER

Embedya Yazılım Donanım ve Arge Ltd. Şti.

MERSİS Number: 0333267315000001

Tax Identification Number: 3332673150

Address: İVEDİKOSB MAH. 2224 CAD. NO: 1 İÇ KAPI NO: 116 YENİMAHALLE/ANKARA

Email: info@embedya.com

Phone:

Your personal data is processed by Embedya, whose details are provided above, in its capacity as the data controller.

3. PERSONAL DATA COLLECTED

Embedya may collect personal data in the following categories:

3.1. Identity Information

  • First name and surname
  • Turkish Republic Identity Number (where necessary)
  • Date of birth
  • Gender

3.2. Contact Information

  • Email address
  • Telephone number
  • Fax number (if applicable)
  • Postal address

3.3. Membership and Account Information

  • Username
  • Password (in encrypted form)
  • Membership date
  • Account status
  • Preferences and settings

3.4. Financial Information

  • Payment information (through secure payment systems)
  • Billing information
  • IBAN (in the event of refunds)
  • Payment history
  • Credit card information (not stored directly)

3.5. Transaction and Shopping Information

  • Order history
  • Product preferences
  • Shopping behaviour
  • Return/warranty records
  • Shopping cart contents

3.6. Marketing and Communication Preferences

  • Newsletter subscription
  • Campaign preferences
  • Preferred communication channels
  • Points/rewards programme information

3.7. Technical Information

  • IP address
  • Cookie information
  • Device information
  • Website and application usage data

3.8. Training Services Information

  • Training records
  • Training history
  • Certificate information
  • Assessments

3.9. Communication Records

  • Customer service conversations
  • Email correspondence
  • Live support conversations

4. METHODS OF COLLECTING PERSONAL DATA

  • Website and Mobile Application (membership, orders, and forms)
  • Email communications
  • Telephone conversations
  • Social media channels
  • Cookies and similar technologies
  • Physical events (if applicable)
  • Business partners
  • Public institutions (within the scope of legal obligations)

5. PURPOSES OF PROCESSING PERSONAL DATA

5.1. Provision of Services

  • Membership procedures
  • Processing orders
  • Payment transactions
  • Invoicing processes
  • Return/exchange/warranty procedures
  • Training services
  • Provision of software licences

5.2. Customer Relations

  • Support services
  • Complaint management
  • Customer satisfaction monitoring

5.3. Product and Service Development

  • Technical support
  • Product/service improvement
  • Consultancy

5.4. Marketing and Communications (Subject to Explicit Consent)

  • Campaigns
  • Promotions
  • Personalised offers
  • Segmentation and analyses

5.5. Legal and Administrative Obligations

  • Tax and accounting procedures
  • Statutory records
  • Audits
  • Legal proceedings

5.6. Security and Risk Management

  • Fraud prevention
  • Detection of security breaches
  • Risk analysis

6. SHARING OF PERSONAL DATA

6.1. Business Partners

  • Payment service providers
  • Logistics companies
  • Marketing agencies
  • Data analytics companies

6.2. Suppliers and Service Providers

  • IT services
  • Cloud systems
  • Software providers
  • Call centre services

6.3. Public Institutions

  • Tax offices
  • Trade registry offices
  • Courts
  • Other authorised institutions

6.4. International Data Transfers

Pursuant to Article 9 of the KVKK, personal data may be transferred to countries that provide adequate protection or to data processors that have provided the necessary undertakings.

7. RETENTION AND SECURITY OF PERSONAL DATA

7.1. Retention Periods

  • Membership information: For the duration of the membership
  • Order/invoice records: 10 years (pursuant to tax legislation)
  • Communication records: 2 years
  • Marketing data: Until consent is withdrawn
  • Technical data: 2 years

7.2. Technical and Administrative Measures

Technical Measures:

  • SSL/TLS
  • Firewalls
  • Intrusion prevention systems
  • Data backups
  • Access controls

Administrative Measures:

  • Personnel training
  • Confidentiality agreements
  • Audits
  • Security policies

7.3. Data Breaches

In the event of a personal data breach, the necessary notifications will be made in accordance with Article 12 of the KVKK.

8. RIGHTS OF THE DATA SUBJECT

All rights granted under Article 11 of the KVKK:

  1. To learn whether personal data is being processed
  2. To request information regarding the processing
  3. To learn the purposes for which personal data is processed
  4. To learn the third parties to whom personal data has been transferred
  5. To request the rectification of personal data
  6. To request the deletion or destruction of personal data
  7. To request that such actions be notified to third parties
  8. To object to processing carried out exclusively through automated systems
  9. To claim compensation in the event of damage

These rights may be exercised by submitting a request via email or in writing.

9. COOKIES AND SIMILAR TECHNOLOGIES

Cookies are used on the Website and Mobile Application to improve the user experience.

For detailed information, please refer to the Cookie Policy.

10. COMMERCIAL COMMUNICATIONS

Subject to explicit consent, communications may be sent by email, SMS, telephone, or mobile notification.

Communication preferences may be managed, or consent may be withdrawn at any time.

11. CHILDREN’S PRIVACY

Personal data is not knowingly collected from individuals under the age of 18.

If such data is identified, it will be deleted.

12. THIRD-PARTY LINKS

Embedya is not responsible for the privacy policies of third-party websites.

The relevant privacy policies should be reviewed before visiting such websites.

13. CHANGES TO THE PRIVACY POLICY

Embedya reserves the right to amend this Policy.

Material changes will be announced through the Website/Mobile Application.

Individuals who continue to use the Website, Mobile Application, or services will be deemed to have accepted the changes.

14. CONTACT

For your questions and KVKK-related requests:

Email: info@embedya.com

Address: İVEDİKOSB MAH. 2224 CAD. NO: 1 İÇ KAPI NO: 116 YENİMAHALLE/ANKARA

Business Hours: Weekdays, 09:00–17:00

15. LEGAL BASIS

  • Turkish Personal Data Protection Law No. 6698 (KVKK)
  • Guidelines issued by the Turkish Personal Data Protection Authority
  • Turkish Law on the Regulation of Electronic Commerce
  • Regulation on Commercial Electronic Communications
  • GDPR (for users located outside Türkiye)

16. RELATED DOCUMENTS

  • KVKK Clarification Text
  • Cookie Policy
  • Commercial Communication Consent
  • Membership Agreement
  • Warranty and Return Conditions

Last Updated: 02 May 2025

Version: v1.0