KVKK Disclosure Statement
DIMUEM İÇ VE DIŞ TİCARET A.Ş. — PERSONAL DATA PROTECTION AND PROCESSING POLICY
Effective Date: July 31, 2026
Version: 3.0
1. PURPOSE, SCOPE AND LEGAL BASIS
1.1. Purpose
This Policy has been prepared to establish the fundamental principles and rules for the lawful processing, protection, transfer, storage, and destruction of personal data processed by Dimuem İç ve Dış Ticaret A.Ş. ("Company" or "Dimuem") within the scope of e-commerce, membership, subscription, online payment, order, delivery, after-sales support, marketing, advertising, campaign, analytics, content, and influencer/UGC operations.
1.2. Scope
This Policy covers real persons whose personal data is processed by the Company, including customers, members, potential customers, subscribers, website visitors, commercial electronic message recipients, influencers and user-generated content (UGC) owners, supplier and service provider authorities and employees, and job applicants. The dimuem.com website, dimuemworks.online operation panel, Shopify infrastructure, payment, e-invoice, cargo, analytics, and advertising systems are within the scope of this Policy.
1.3. Legal Basis
This Policy has been prepared based on the Constitution of the Republic of Turkey, the Personal Data Protection Law No. 6698 ("KVKK"), amendments to the KVKK that came into force in 2024, the Regulation on the Deletion, Destruction or Anonymization of Personal Data, the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform, the Communiqué on the Procedures and Principles for Applications to the Data Controller, the Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad, the Law on the Regulation of Electronic Commerce No. 6563, the Message Management System legislation, Law No. 5651, and other relevant legislation.
2. DATA CONTROLLER
The data controller under the KVKK is Dimuem İç ve Dış Ticaret A.Ş.
| Information | Description |
|---|---|
| Trade Name | Dimuem İç ve Dış Ticaret A.Ş. |
| Head Office Address | Acarlar Mah. 2. Cad. Acarkent Sitesi C251 No: 4 İç Kapı No: 1 Beykoz/İstanbul |
| Website | https://dimuem.com |
| Operation Panel | https://dimuemworks.online |
| KVKK Application E-mail Address | kvkk@dimuem.com |
| KEP Address | kvkk@dimuem.com |
| Tax ID / MERSİS Number | 2951338795 |
3. DEFINITIONS
| Term | Definition |
|---|---|
| Explicit Consent | Consent relating to a specific matter, based on information, and declared with free will. |
| Anonymization | Rendering personal data incapable of being associated with an identified or identifiable natural person, even if matched with other data. |
| Data Subject | The natural person whose personal data is processed. |
| Personal Data | Any information relating to an identified or identifiable natural person. |
| Special Categories of Personal Data | Information enumerated restrictively in Article 6 of the KVKK; race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, dress and attire, association, foundation or union membership, health, sexual life, criminal convictions and security measures, biometric and genetic data. |
| Data Processor | A natural or legal person who processes personal data on behalf of the data controller based on the authority granted by them. |
| Data Controller | A natural or legal person who determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system. |
| Periodic Destruction | The process of deleting, destroying, or anonymizing personal data at predetermined recurring intervals when all conditions for processing personal data no longer apply. |
| UGC | Visual, video, text, and similar content generated by users or influencers. |
4. FUNDAMENTAL PRINCIPLES REGARDING THE PROCESSING OF PERSONAL DATA
- Lawfulness and fairness.
- Accuracy and, where necessary, kept up to date.
- Processed for specified, explicit, and legitimate purposes.
- Relevant, limited, and proportionate to the purposes for which they are processed.
- Retained for the period stipulated by relevant legislation or required for the purpose for which they are processed.
The Company carries out personal data processing activities in line with the principles of data minimization, purpose limitation, transparency, accountability, and security; it does not collect unnecessary personal data and does not use existing data for purposes other than those intended.
5. DATA SUBJECT GROUPS
- Customers, members, subscribers, and potential customers
- Website visitors
- Commercial electronic message recipients
- Influencers, content creators, and UGC owners
- Authorized representatives and employees of suppliers, business partners, and service providers
- Employees, interns, and job applicants
- Shareholders, board members, and company officials
- Parties to legal transactions or disputes and their representatives
6. CATEGORIES OF PERSONAL DATA PROCESSED
| Data Category | Processed Data |
|---|---|
| Identity | Name, surname; other identity information required for invoicing and contracting when a transaction necessitates it. |
| Contact | Phone, mobile phone, email, delivery/invoice address, WhatsApp contact information. |
| Customer Transaction | Membership, account, subscription, order, shopping cart, delivery, return, request and complaint, customer support records. |
| Financial | Payment information related to credit card transactions, payment and refund records, invoice information. Full card data is not stored by the Company; it is processed within the payment institution's infrastructure. |
| Transaction Security | IP address, log records, browser and device information, Cookie ID, Session ID, session and security records. |
| Visual and Audio Records | Photos, videos, and UGC/influencer content. |
| Marketing | Commercial electronic message preferences, consent records, campaign and advertisement interactions, segment and analysis results. |
| Legal Transaction | Contracts, warnings and correspondences, records required in dispute and judicial/administrative authority processes. |
| Professional Experience and Personnel | Only profession, title, CV, and employment relationship records when necessary for employee, job applicant, intern, or supplier personnel processes. |
7. METHODS OF OBTAINING PERSONAL DATA
Personal data is obtained through the following channels, fully or partially by automatic means or by non-automatic means as part of a data recording system:
- dimuem.com website, membership, and customer account screens
- Contact and order forms
- Email and WhatsApp correspondences
- Cookies and similar technologies
- Contracts, subscription, and commercial electronic message consent processes
- Records from cargo, payment, e-invoice, analytics, advertising, and other service providers
- Social media platforms and content directly shared by the data subject
- dimuemworks.online internal operation panel
8. PURPOSES AND LEGAL GROUNDS FOR PROCESSING PERSONAL DATA
| Purpose of Processing | Main Legal Ground |
|---|---|
| Creating membership and customer accounts, identity verification, and session management | KVKK Art.5/2-c for the establishment or performance of a contract; Art.5/2-f for legitimate interest |
| Order taking, payment, delivery, return, and after-sales support | KVKK Art.5/2-c for the establishment or performance of a contract; Art.5/2-ç for legal obligation |
| Invoicing, accounting, tax, and commercial record keeping | KVKK Art.5/2-a explicitly provided for by law; Art.5/2-ç for legal obligation |
| Information security, system management, logging, prevention of fraud and abuse | KVKK Art.5/2-ç for legal obligation; Art.5/2-f for legitimate interest |
| Request, complaint, and customer satisfaction processes | KVKK Art.5/2-c for the performance of a contract; Art.5/2-f for legitimate interest |
| Conducting legal processes and the establishment, exercise, or protection of rights | KVKK Art.5/2-ç for legal obligation and Art.5/2-e for the establishment, exercise, or protection of a right |
| Analytics, performance measurement, and statistics | Explicit consent for non-essential cookies; in other cases, Art.5/2-f for legitimate interest, while observing fundamental rights and freedoms |
| Marketing, advertising, campaigns, personalization, and commercial electronic messages | Explicit consent and commercial electronic message approval within the scope of Law No. 6563/IYS legislation |
| Management, publication of Influencer and UGC content, and contract processes | KVKK Art.5/2-c for the establishment or performance of a contract; Art.5/2-e for the establishment, exercise, or protection of a right; explicit consent when necessary |
9. SPECIAL CATEGORIES OF PERSONAL DATA
In current e-commerce and website processes, regular processing of health data or any other special category of personal data is not foreseen. If special categories of personal data are processed, no processing will be carried out without at least one of the current processing conditions in Article 6 of the KVKK. Explicit consent, explicit provision by law, factual impossibility, processing of data made public by the data subject in accordance with their intention of public disclosure, establishment/exercise/protection of a right, employment and occupational health and safety obligations, health services carried out by persons under public health and secrecy obligations, and activities of foundations/associations/unions and similar non-profit organizations in accordance with legislation are evaluated based on the specific case.
Adequate measures determined by the Board are taken for special categories of personal data; access authorizations are restricted, access and processing records are kept, transfer channels are secured, and personnel work under confidentiality obligations.
10. TRANSFER OF PERSONAL DATA DOMESTICALLY
| Recipient Group | Purpose of Transfer | Data Categories | Continuity |
|---|---|---|---|
| iyzico | Payment processing and refund processes | Identity, contact, financial/customer transaction | Continuous |
| Banks (via iyzico) | Payment collection and refund | Financial | Continuous |
| Yurtiçi Kargo and other cargo companies when necessary | Order delivery and return | Identity, contact, address, order | Continuous |
| BirFatura | E-invoice/e-archive issuance | Identity, contact, financial, customer transaction | Continuous |
| Revenue Administration and tax offices | Legal obligation | Identity, financial, invoice | As required by legislation |
| Financial advisor | Accounting and financial obligations | Identity, financial, invoice | Periodic |
| IYS (Message Management System) | Commercial electronic message permission management | Contact and permission records | Continuous |
| Courts, public prosecutors' offices, and authorized public institutions | Legal obligations and dispute processes | Varies according to the scope of the request | Upon request |
11. TRANSFER OF PERSONAL DATA ABROAD
11.1. General Principle and Transfer Hierarchy
The Company transfers personal data abroad only in accordance with the conditions stipulated in Article 9 of the KVKK. Uploading data to a cloud service abroad, remote access to data by support personnel abroad, or processing data through a platform abroad is also considered transfer abroad.
- First, the processing condition under KVKK Art.5 or Art.6 on which the transfer is based is determined.
- It is checked whether the Board has an adequacy decision regarding the country to which the transfer will be made, the sector within the country, or the international organization.
- If there is no adequacy decision, one of the appropriate safeguards under KVKK Art.9/4 is established.
- In the absence of an adequacy decision and appropriate safeguards, transfer can only be made if one of the limited exceptions in KVKK Art.9/6 exists for incidental transfers.
For continuously used services such as Shopify, Vercel, Supabase, Google, and Meta, incidental transfer exceptions cannot be used as a permanent basis. Explicit consent does not automatically eliminate the need to establish appropriate safeguards for regular and systematic transfers.
11.2. Overseas Service Providers and Transfer Map
| Service Provider | Purpose | Data Categories | Likely Region | Typical Role |
|---|---|---|---|---|
| Shopify Inc. | E-commerce, customer account, order, and hosting | Identity, contact, customer transaction, financial, transaction security | Canada, USA, and EU | Data Processor |
| Vercel Inc. | dimuemworks.online hosting | Transaction security and operational data | USA and service regions | Data Processor |
| Supabase | Internal panel database and authentication | Contact, visual, UGC, and transaction security | Selected EU/other region | Data Processor |
| Google LLC / related entity | Analytics and measurement | Device, browser, cookie, IP, and usage data | USA and other regions | Data Processor or Data Controller depending on the product |
| Meta Platforms entities | Advertising, conversion measurement, and targeting | Device, browser, cookie, IP, and usage data | Ireland, USA, and other regions | Data Processor or Data Controller depending on the product |
11.3. Appropriate Safeguard Methods
- Making agreements with public institutions or international organizations abroad that are not international treaties and obtaining permission from the Board.
- Applying binding corporate rules approved by the Board for groups of undertakings engaged in a joint economic activity.
- Signing the standard contract published by the Board, using the appropriate module according to the parties' status, and notifying the Authority.
- Signing a written undertaking containing provisions that will provide adequate protection and obtaining permission from the Board.
12. STANDARD CONTRACTS
12.1. Selecting the Correct Module
| Module | Transferor | Transferee | Usage from Dimuem's Perspective |
|---|---|---|---|
| 1 | Data Controller | Data Controller | Scenarios where the transferee, such as Google/Meta, independently determines its own purposes. |
| 2 | Data Controller | Data Processor | Typical module for services like Shopify, Vercel, Supabase, and hosting/processing on behalf of Dimuem. |
| 3 | Data Processor | Data Processor | Exceptional cases where Dimuem processes data on behalf of another data controller and transfers it to a sub-processor. |
| 4 | Data Processor | Data Controller | Exceptional cases where the data processor in Turkey transfers data to a data controller abroad. |
12.2. Preparation, Signing, and Notification Rules
- For each service provider, the data controller/data processor status of the transferor and transferee is determined separately according to current service terms.
- The essential provisions of the standard contract published by the Board are not altered; optional fields and appendices are filled in completely.
- The full trade name, address, representatives, and signing authorities of the parties are verified with current documents.
- Data subject groups, data categories, purpose, transfer frequency, retention period, presence of special categories of data, and the nature of the data processing activity are clearly stated.
- Technical and administrative measures are explained to cover encryption, access control, logging, backup, breach response, sub-processor management, deletion/return, and business continuity.
- The Turkish text of the standard contract is taken as the basis; if there is a foreign language version, full compatibility with the Turkish text is ensured.
- The contract is signed by the authorized representatives of the parties and is notified by the data exporter to the Authority via the notification module, KEP, or an accepted physical method within five business days from the completion of the signatures.
- If there are significant changes in the party, address, role, subject of transfer, or appendices, the necessity for a new contract/notification is evaluated.
- The termination of the contract is notified to the Authority within five business days from the termination date.
12.3. Continuous Compliance and Auditing
- It is checked at least once a year whether the transfer remains limited to the purpose, data category, and frequency specified in the contract.
- The recipient's technical and administrative measures, independent reports, certificates, sub-processor list, and data breach records are monitored.
- It is evaluated whether the country legislation and public authority access practices applicable to the recipient hinder compliance with the contract; if necessary, additional encryption or pseudonymization is applied.
- If adequate safeguards cannot be maintained, the transfer is suspended or terminated; the return or deletion of data is ensured.
- Signed contracts, appendices, signature authorization documents, translations, notification receipts, and change records are stored in an auditable manner.
12.4. Service Provider-Based Completion Plan
| Service | Pre-Assessment | Action to be Completed |
|---|---|---|
| Shopify | Dimuem is the data controller; Shopify is mostly the data processor. | Module 2 should be completed by confirming the contract party and data regions; sub-processor and security appendices should be finalized. |
| Vercel | Dimuem is the data controller; Vercel is the data processor for hosting. | Module 2; project logs, access data, server region, and sub-processors should be documented. |
| Supabase | Dimuem is the data controller; provider is the data processor. | Module 2; data region, backup, authentication, deletion, and sub-processor terms should be documented. |
| Google Analytics | Role may vary depending on the product and settings. | Module 1 or 2 should be selected based on role analysis; analytical cookies should only function after explicit consent. |
| Meta Pixel/Conversions | Role may vary depending on the product and joint processing terms. | Module 1 or 2 according to current product terms; advertising cookies should only function after explicit consent. |
13. COOKIES AND SIMILAR TECHNOLOGIES
The dimuem.com website may use essential, functional, analytical, and advertising/marketing cookies. Essential cookies are necessary for the website's operation, security, shopping cart, payment, customer login, language, and cookie preference storage. Analytical and advertising cookies are not activated without the user's explicit consent. Users are offered "Accept", "Decline", and "Manage Preferences" options with equal visibility and ease; pre-checked consent boxes are not used. Detailed information is provided in the current Cookie Policy.
14. RETENTION PERIODS AND DESTRUCTION
| Data Category | Retention Period | Basis |
|---|---|---|
| Orders, invoices, and commercial records | 10 years | TCC Art. 82 and relevant tax legislation |
| Payment and refund records | 10 years | TCC Art. 82 and legal obligations |
| Membership data | Membership duration and a maximum of 10 years thereafter, limited by dispute/statute of limitations periods | TCO Art. 146 and establishment/protection of rights |
| Marketing consent and communication data | Until consent is withdrawn; consent/refusal records for the period stipulated by legislation | Law No. 6563 and IYS legislation |
| Traffic and log records | 1–2 years depending on specific obligation | Law No. 5651 and purpose of information security |
| Customer support correspondence | 3 years or for the duration of a dispute | Purpose of processing and protection of rights |
| Influencer/UGC data | Contract duration and a maximum of 10 years thereafter | TCO Art. 146 and protection of rights |
| Cookie data | Each cookie's own lifespan | Cookie Policy and preference records |
When all processing conditions cease to exist, personal data is deleted, destroyed, or anonymized ex officio or upon the request of the data subject. If the company has a VERBIS registration obligation, it also prepares a retention and destruction policy and fulfills periodic destruction obligations. Destruction processes are recorded, and relevant records are stored for at least three years.
15. TECHNICAL AND ADMINISTRATIVE MEASURES
- Limiting Shopify admin access to role-based personnel accounts.
- Implementing user-based access control in the dimuemworks.online panel.
- Not granting full admin privileges to agencies and third parties beyond necessity.
- Using one-time codes via email instead of passwords for customer accounts.
- Maintaining Shopify admin activity logs, session history, and order timeline.
- Using backup in Shopify and Supabase infrastructure.
- Using firewall, DDoS protection, and SSL at Shopify/Cloudflare level.
- Processing payments through PCI DSS compliant iyzico infrastructure.
16. DISCLOSURE AND EXPLICIT CONSENT MANAGEMENT
When obtaining personal data, the data subject is informed about the identity of the data controller, processing purposes, recipient groups and purposes of transfer, collection method and legal basis, and their rights under KVKK Art. 11. Disclosure is provided separately from the request for explicit consent. For activities requiring explicit consent, consent must be specific, informed, given freely, and verifiable. The provision of the service is not conditioned on non-essential marketing or analytical consent. The data subject can withdraw their consent as easily as they gave it.
17. RIGHTS OF THE DATA SUBJECT
- To learn whether their personal data is processed.
- To request information if their personal data has been processed.
- To learn the purpose of processing and whether the data is used appropriately for its purpose.
- To know the third parties to whom personal data is transferred, whether domestically or abroad.
- To request correction of incomplete or incorrectly processed data.
- To request the deletion or destruction of data within the framework of KVKK Art. 7 conditions.
- To request notification of correction, deletion, or destruction operations to third parties to whom data has been transferred.
- To object to a negative outcome arising from the analysis solely by automated systems.
- To request compensation for damages incurred due to unlawful processing of data.
18. PROCEDURE FOR APPLICATION TO THE DATA CONTROLLER
Data subjects can submit their requests under KVKK Art. 11 to the Company in accordance with the Communiqué on the Procedures and Principles for Application to the Data Controller. The application must include the first name and last name, signature (for written applications), T.R. identity number or passport/ID number for foreigners, residential or business address for notification, email/phone/fax information for notification if available, and the subject of the request.
| Application Method | Address | Description |
|---|---|---|
| Written application | Acarlar Mah. 2. Cad. Acarkent Sitesi C251 No: 4 İç Kapı No: 1 Beykoz/İstanbul | The envelope must be marked "Information Request under KVKK". |
| KEP | [KEP address has not been provided by the Company.] | The subject line must be "Information Request under KVKK". |
| Email address registered in the Company system | kvkk@dimuem.com | The subject line must be "Information Request under KVKK". |
| Email with secure electronic signature/mobile signature | kvkk@dimuem.com | The application must be suitable for signature verification. |
Applications are concluded free of charge as soon as possible and within thirty days at the latest, depending on the nature of the request. If the process requires additional cost, a fee determined by the Board may be charged. If the application is rejected, the answer is deemed insufficient, or no answer is given within the specified period, the data subject may file a complaint with the Personal Data Protection Board within thirty days from the date they learned of the answer, and in any case, within sixty days from the date of application.
19. PERSONAL DATA BREACH MANAGEMENT
If the Company learns that processed personal data has been obtained by others through unlawful means, it will promptly assess the breach, take necessary technical and administrative measures, notify the affected data subjects by appropriate means, and report the breach to the Board without delay and at the latest within 72 hours from the date it learned of the breach, in accordance with the Board's decision no. 2019/10. If notification cannot be made within 72 hours for a justifiable reason, the reasons for the delay are explained along with the notification. The notification includes the time of the breach, affected data and data subject categories, potential consequences, measures taken/recommended, and contact information. Breach records, impacts, and corrective actions are documented.
20. ROLES AND RESPONSIBILITIES
| Role | Responsibility |
|---|---|
| Board of Directors | Responsible for approving the policy, allocating resources, overseeing compliance, and updating it. |
| Department/Operations Managers | Implement data minimization, disclosure, access control, and retention rules in their own processes. |
| Information Technologies / Technical Service Providers | Conduct access, security, log, backup, vulnerability, and breach response controls. |
| Contact Person / KVKK Officer | Coordinates VERBIS, data subject applications, policy updates, training, and communication with the Authority. |
| All Employees and Authorized Users | Adhere to confidentiality obligations, do not access data outside their authority, and immediately report suspicious incidents. |
21. PUBLICATION, UPDATE, AND EFFECTIVENESS OF THE POLICY
The policy is published on the website and made accessible to data subjects. It is reviewed when legislation, Company activities, technology used, and service providers change. The policy is checked at least once a year; necessary changes come into force with the approval of the Board of Directors. This Policy came into effect on July 31, 2026.
APPENDIX-1: COMPLIANCE AND COMPLETION CHECKLIST
- Company's current KEP address
- Email address to be used for KVKK applications
- Confirmation of VERBIS registration obligation and contact person information
- Confirmation of the current international transfer mechanism and standard contract notifications used for Shopify, Vercel, Supabase, Google, and Meta
- Verification of the cookie table with technical scanning on the live system
- Completion of separate disclosure texts and retention periods if employee/candidate processes are carried out
- Implementation of two-factor authentication and a written data breach response plan
- Legal entities contracting with Shopify, Vercel, Supabase, Google, and Meta, and data regions must be confirmed from account panels.
- For each service provider, a role analysis should be performed, the appropriate standard contract module should be signed, and notified to the Authority within five business days.
- Standard contract notification numbers, signature, and authorization documents must be recorded in the international transfer inventory.
- Two-factor authentication must be mandatory for critical accounts.
- A written data breach response plan and a 72-hour notification workflow must be implemented.
- The cookie inventory must be verified with technical scanning on the live system; analytical and advertising cookies must be blocked before explicit consent.
- VERBIS obligation and contact person information must be checked annually.
APPENDIX-2: MAJOR LEGISLATION AND OFFICIAL GUIDES
- Law No. 6698 on the Protection of Personal Data.
- Amendments made to Articles 6 and 9 of the KVKK by Law No. 7499, which entered into force on June 1, 2024.
- Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad.
- Personal Data Protection Authority, Guide on the Transfer of Personal Data Abroad.
- Personal Data Protection Authority, Guide on the Processing of Special Categories of Personal Data.
- Decision of the Personal Data Protection Board dated 24.01.2019 and numbered 2019/10 regarding data breach notification.
- Regulation on the Deletion, Destruction, or Anonymization of Personal Data.
- Communiqué on the Procedures and Principles to be Followed in Fulfilling the Disclosure Obligation.
- Communiqué on the Procedures and Principles for Application to the Data Controller.