Privacy policy

Baran Atok sole proprietorship (hereinafter "Company") considers the privacy and security of your personal data among its highest priorities. In fulfillment of our disclosure obligation arising from Article 10 of the Personal Data Protection Law No. 6698 ("PDPL"), we hereby inform you about the personal data processed through our website www.atokjewelry.com. Personal data refers to any information that renders your identity specific or identifiable. The personal data processed by the Company, the purposes of processing, recipient groups to whom data may be transferred, methods of collection, legal bases, and your rights regarding such data are set out below.

A — Registered Members

1. What personal data does the Company process?

Individuals who accept the membership terms of the Atok Jewelry platform, access the website, and follow and/or purchase products listed on the platform are defined as "Members." The following categories of personal data may be processed:

  • Identity Data: Full name; Turkish National ID Number (processed solely where required by applicable legislation); and, where voluntarily provided, gender, date of birth, height, and weight.
  • Contact Data: Phone number, delivery address, and e-mail address.
  • Customer Transaction Data: Order and invoice records; delivery records; transaction history; requests and complaints; content shared in product reviews or questions; and chat records via the Atok Jewelry assistant.
  • Transaction Security Data: IP address, password and credential information, and cookie data.
  • Marketing Data: Purchase history, campaign information, profiling and segmentation data, and cookie records.
  • Legal Transaction Data: Correspondence with authorized persons and authorities; litigation and enforcement records; and statutory information requests.

2. For what purposes and by what methods is your personal data collected?

Identity, contact, and customer transaction data are collected directly from you and automatically via the website for the following purposes:

  • Formation and performance of contracts
  • Financial and accounting processes
  • Execution and supervision of business activities
  • Invoicing
  • Logistics, cargo, and delivery monitoring
  • Verification of identity for online purchases
  • Marketing and advertising activities (where explicit consent has been obtained)
  • Customer analytics and improvement of products and services
  • Strategic analysis and communication activities
  • Presenting relevant products based on your preferences
  • Informing you about contract terms and updates
  • Informing you about developments and opportunities at Atok Jewelry (where explicit consent has been obtained)
  • Customer surveys through partner organizations
  • Evaluating requests, complaints, and suggestions
  • After-sales support services
  • Information security and platform security
  • Regulatory compliance and legal proceedings
  • Providing information to authorized public institutions and authorities

Transaction security data are collected for the following purposes:

  • Formation and performance of contracts
  • Execution of business activities
  • Identity verification for online purchases
  • Marketing activities (where explicit consent has been obtained)
  • Customer analytics and service improvement
  • Information security and platform security
  • Regulatory compliance
  • Providing information to authorized authorities

Legal transaction data are collected for the following purposes:

  • Formation and performance of contracts
  • Execution of business activities
  • Evaluating requests, complaints, and suggestions
  • Information security and platform security
  • Regulatory compliance and legal proceedings
  • Providing information to authorized authorities

3. What is the legal basis for processing your personal data?

Your personal data is processed on the following legal grounds set out in Articles 5, 8, and 9 of the PDPL:

  • Explicit statutory obligation: Fulfillment of obligations under applicable legislation including Law No. 6563 on Electronic Commerce, Turkish Commercial Code No. 6102, Turkish Penal Code No. 5237, and Consumer Protection Law No. 6502.
  • Necessity for contract formation or performance: Formation and execution of distance sales agreements; processing purchase transactions; delivery monitoring; handling requests and complaints; financial and accounting processes.
  • Compliance with a legal obligation: Fulfillment of obligations under the Distance Contracts Regulation and related secondary legislation; provision of information to authorities; regulatory compliance; legal and financial proceedings.
  • Establishment, exercise, or defense of a legal claim: Legal and litigation proceedings.
  • Legitimate interests of the Company: Development and improvement of products and services, provided such interests do not override your fundamental rights and freedoms.
  • Explicit consent: Transfer of personal data abroad.

4. To whom and for what purposes does the Company transfer your personal data?

The Company processes personal data in accordance with the principles of "need to know" and "need to use," applying appropriate data minimization and implementing necessary technical and administrative security measures. Your personal data may be shared, to the extent necessary and limited to the purposes stated in this Notice, with the following parties:

  • Product sellers and service providers for purchase processes
  • Cargo companies and couriers for logistics and delivery
  • Business partners, banks, and financial advisors for invoicing and accounting
  • Partners for quality control, complaint management, and risk analysis
  • E-invoice partners and delivery companies for invoice and document delivery
  • Tax authorities and Ministry of Treasury and Finance officials for tax compliance
  • Technology infrastructure and IT service providers
  • Partners for risk management and financial reporting
  • Lawyers, auditors, and other professional advisors for legal compliance
  • Regulatory authorities, courts, and enforcement offices
  • Other public institutions authorized to request personal data; domestic and international affiliates, suppliers, and business partners

B — Guest Users

1. What personal data does the Company process?

Individuals who browse and/or purchase products on the Atok Jewelry platform without registering are defined as "Guest Users." The following personal data are processed:

  • Identity Data: First name and last name
  • Contact Data: Mobile phone number, delivery address, and e-mail address
  • Customer Transaction Data: Order and invoice records, delivery records, transaction history, and requests and complaints
  • Transaction Security Data: IP address and cookie data
  • Legal Transaction Data: Correspondence with authorized persons and authorities; litigation records; and statutory information requests

The same purposes, collection methods, legal bases, and data transfer practices described for Registered Members apply equally to Guest Users, with the exception of membership-specific services.

How Does the Company Protect Your Personal Data?

  • Penetration tests are conducted periodically in accordance with national and international data privacy standards.
  • Personal data transmitted via the website is protected using SSL (Secure Sockets Layer) technology.
  • Regular risk analyses are carried out in relation to personal data processing activities, and measures are taken to mitigate identified risks.
  • Access and authorization controls are applied to prevent unauthorized access to personal data.
  • Data processing policies are updated on an ongoing basis.

Your Rights Regarding the Protection of Your Personal Data

By submitting a request to the Company through the methods described in the "Contact" section below, you have the right to:

  • Learn whether your personal data is being processed
  • Request information if your data has been processed
  • Learn the purpose of processing and whether data is used in accordance with that purpose
  • Know the third parties to whom data has been transferred, domestically or abroad
  • Request correction of incomplete or inaccurate data
  • Request deletion or destruction of your personal data under the conditions stipulated in the PDPL
  • Request that corrections, deletions, or destructions be communicated to third parties to whom data has been transferred
  • Object to any outcome arising solely from automated processing of your personal data that is to your detriment
  • Claim compensation for damages suffered as a result of unlawful processing of your personal data

Contact

You may submit your questions and requests regarding your personal data through the following channels:

Method Address
In-person written application Kuloğlu Mahallesi, Ağa Hamamı Sokak No:33, Beyoğlu, Istanbul
Notary Kuloğlu Mahallesi, Ağa Hamamı Sokak No:33, Beyoğlu, Istanbul
Registered e-mail address on file shopatox@gmail.com

The Company will finalize your request free of charge within a maximum of 30 (thirty) days of receipt.

About This Notice

The Company reserves the right to update this Privacy Notice at any time in accordance with changes in applicable legislation.

Last updated: September 16, 2024