This English text is provided for information only. The binding version of this policy is the Turkish original, published at Gizlilik Politikası. In the event of any discrepancy between the two, the Turkish text prevails.
At giftasmile.co we attach great importance to the security of our visitors and customers. To that end, and in order to protect your personal data and give you clearer information, we have prepared two important further pages: the KVKK Information Notice and the Cookie Policy.
Our company details
At Balz E-Ticaret Reklam Tekstil Sanayi Ve Ticaret Ltd. Şti., our priority is to ensure that the personal data of natural persons — including our members, customers, visitors, suppliers and employees — is processed in accordance with the relevant legislation, in particular the Constitution of the Republic of Türkiye, the international conventions on human rights to which our country is a party, and Law No. 6698 on the Protection of Personal Data ("KVKK"), and to enable the data subjects whose data is processed to exercise their rights effectively.
For this reason, we carry out the processing, storage and transfer of all personal data obtained in the course of our activities — including but not limited to that of our employees, suppliers, customers, visitors, members and the users who visit our stores, our website and our mobile applications — in accordance with the Balz E-Ticaret Reklam Tekstil Sanayi Ve Ticaret Ltd. Şti. (giftasmile.co) Personal Data Protection and Processing Policy (the "Policy").
The protection of personal data and respect for the fundamental rights and freedoms of the natural persons whose personal data is collected are the core principles of our policy on the processing of personal data. For this reason, we conduct all our activities involving the processing of personal data with regard for the protection of privacy, the confidentiality of personal information, the confidentiality of communications, freedom of thought and belief, and the right to effective legal remedies.
In order to protect personal data, we take all administrative and technical protective measures required by the nature of the data concerned, in accordance with the legislation and current technology.
This Policy explains the methods we follow in processing, storing, transferring and erasing or anonymising the personal data shared with us during our commercial, promotional/marketing, social responsibility and similar activities, within the framework of the principles set out in the KVKK.
All personal data processed by the Company, including that of our visitors, business contacts, business partners, employees, suppliers, members and third parties, falls within the scope of this Policy.
Our Policy applies to all activities involving the processing of personal data owned or managed by the Company, and has been drawn up and prepared having regard to the KVKK, other relevant legislation on personal data, and international standards in this field.
The Board of Directors is responsible for the senior oversight of the establishment and operation of notification, investigation and sanction mechanisms in the event of non-compliance with the Policy, rules and regulations.
The Personal Data Protection and Processing Policy has been approved by the Board of Directors.
It is the authorised approval mechanism for ensuring that the Policy is created, implemented and, where necessary, updated.
The Audit Unit is responsible for taking the measures necessary to ensure the compliance of the employees involved and of outsourced firms with the Policy, and for examining matters with a view to investigating any issues contrary to the Policy.
The Information Systems Committee is responsible for preparing, developing, implementing and updating this Policy. It assesses this Policy, where necessary, in terms of currency and development needs.
Publishing the prepared document on the corporate portal is the responsibility of the Information Systems Committee Manager.
Our legal obligations as data controller in relation to the protection and processing of personal data under the KVKK are set out below:
As data controller, when collecting personal data we have a duty to inform the data subject about:
As a Company, we take care to ensure that this publicly available Policy is clear, understandable and easily accessible.
As data controller, we take the administrative and technical measures prescribed by the legislation in order to ensure the security of the personal data in our custody. The obligations relating to data security and the measures taken are set out in detail in sections 9 and 10 of this Policy.
Personal data is any information relating to an identified or identifiable natural person. The protection of personal data concerns natural persons only; information belonging to legal entities that does not contain information relating to a natural person falls outside the scope of personal data protection. For this reason, this Policy does not apply to data belonging to legal entities.
Data relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of an association, foundation or trade union, health, sexual life, criminal convictions and security measures, together with biometric and genetic data, constitute special categories of personal data.
We process personal data in accordance with the following principles:
7.1.1. Processing lawfully and fairly: We process personal data fairly, transparently and within the framework of our duty to inform.
7.1.2. Ensuring that personal data is accurate and, where necessary, up to date: We take the necessary measures in our data processing procedures to ensure that the data processed is accurate and up to date. We also enable the personal data owner to contact us in order to update their existing data and to correct any errors in the data processed.
7.1.3. Processing for specified, explicit and legitimate purposes: As a Company, we process personal data within our legitimate purposes, the scope and content of which are clearly determined and which are established in order to conduct our activities within the framework of the legislation and the ordinary course of commercial life.
7.1.4. Personal data being relevant, limited and proportionate to the purposes for which it is processed: We process personal data in a manner that is relevant, limited and proportionate to the purpose we have clearly and precisely determined. We avoid processing personal data that is irrelevant or that does not need to be processed. For this reason, unless there is a legal requirement, we do not process special categories of personal data, or, where we must process them, we obtain explicit consent on the matter.
7.1.5. Retaining personal data for the period prescribed by legal regulations and for the duration of our legitimate commercial interests: Many provisions in the legislation require personal data to be retained for a certain period. For this reason, we retain the personal data we process for as long as is prescribed in the relevant legislation or as is necessary for the purposes for which the personal data is processed. Where the retention period prescribed in the legislation expires or the purpose of processing ceases to exist, we erase, destroy or anonymise the personal data.
We process personal data for the following purposes:
Special categories of personal data are processed by us where the administrative and technical measures prescribed by law and by the KVK Board have been taken and explicit consent exists, or in cases where the legislation makes it compulsory.
Since special categories of personal data relating to health and sexual life may be processed, for the purposes of protecting public health, preventive medicine, medical diagnosis, and the conduct of treatment and care services, and the planning and management of health services and their financing, only by persons under a duty of confidentiality or by authorised institutions and organisations, such data is not processed by us other than the data of our employees.
We use cookies to improve the way our web pages and mobile applications operate and are used, and we seek to make the time you spend on our digital platforms more efficient and more enjoyable. In addition, we make use of certain cookies to remember the choices you make on our websites and mobile applications, and in this way we provide you with an enhanced and personalised experience.
We may collect your personal data through the cookies on our digital platforms, and we may process, transfer and store the data we collect. You can find detailed information about the cookies we use in the giftasmile Cookie Policy.
We process, store and transfer the personal data contained in your CV, diploma, photograph and other documents that you share with us during the application process as a job candidate, for the purpose of evaluating the job application. The processing, transfer and storage of the personal data you share as a job candidate falls within the scope of this Policy. Employees' personal data is collected, processed and stored within the framework of giftasmile Human Resources, outside this Policy.
In order to become a member of the digital platforms through the giftasmile.co system, visitors create a membership on the system by sharing with us their:
Personal data obtained through application forms, CVs and applications made to intermediary institutions will be recorded for use in evaluating the job application.
Those who apply using the application form create a CV by sharing information such as their identity details, contact details, education details, work experience, foreign language skills, computer skills, certificates, references, photograph, health data, and driving licence/ability to travel.
The information shared by applicants within their CV may be viewed by employer companies. Within the scope of the legislation, the company retains the identity, education and occupational details of THE PERSON MAKING THE APPLICATION and may, upon request, transfer this data to solution partners and to public institutions and organisations.
When a purchase is made, the CUSTOMER's financial information is transferred to persons and institutions such as banks or credit card companies in order to carry out the transaction. The data transferred is data relating to payment purposes, such as the credit card number, expiry date, CVV2 or bank account details.
During a purchase, the customer's invoice and payment details (first name, surname, Turkish ID number, telephone number, invoice address), the invoices sent, and data such as sample receipts for payments received from members, the payment number, invoice amount, invoice number and invoice date are obtained. This data is processed within the scope of managing the invoicing process, accounting, after-sales services, communication, marketing, auditing, control, and the processes carried out with payment service providers. Credit card details are not held in giftasmile's databases.
During purchases, video recording may be made in stores/facilities for security purposes and in order to monitor till transactions. In distance sales made by telephone, audio recording is made in order to enable the sale to be carried out securely.
We may process personal data without obtaining explicit consent in the following exceptional cases arising from the law:
As a Company, we act in accordance with the KVKK and the decisions and regulations adopted by the KVK Board in relation to the transfer of personal data. Without prejudice to the exceptional cases set out in the legislation, personal data and special categories of data are not transferred by us to other natural or legal persons without the data subject's explicit consent.
As a rule, personal data is not transferred abroad without the data subject's explicit consent. However, where the exceptional cases set out in this Policy exist, transfers may be made to third parties located abroad without seeking explicit consent, provided that they are located in countries declared by the KVK Board to offer adequate protection, or in cases where adequate protection has been undertaken and the approval of the KVK Board exists.
We work with service providers located abroad for purposes such as developing the website and digital platforms, conducting surveys, increasing the range of products and services according to the preferences of visitors and members, and measuring the user experience.
Personal data may be transferred, in accordance with the principles and rules explained above, to:
8.4.1. Technical measures: Establishing the internal technical organisation, ensuring the security of databases, building the technical infrastructure, carrying out periodic audits, keeping antivirus and firewall infrastructure up to date, and employing specialist personnel.
8.4.2. Administrative measures: Establishing internal access authorisation procedures, training and informing employees on the KVKK, and adding confidentiality and security undertakings to the contracts concluded with data processors.
Without prejudice to the retention periods prescribed in the legislation, we retain personal data for as long as the purpose of processing the personal data requires. Where the retention period in the legislation expires or the purpose of processing ceases to exist, the personal data is erased, destroyed or anonymised.
The administrative and technical infrastructure necessary for the secure retention of personal data is established, contingency plans are drawn up, and authorised personnel are employed.
We take the necessary administrative and technical measures in order to prevent the unlawful processing of and access to personal data, and to ensure its lawful retention.
Authorisation procedures are established, periodic internal audits are carried out, cyber security software is used, and mechanisms are operated to ensure that the KVK Board and the data subjects concerned are notified immediately in the event of any data breach.
In relation to their personal data, the personal data owner has the right to:
The personal data owner may submit a request relating to their personal data:
The application must contain:
Requests are concluded free of charge as soon as possible, depending on their nature, and within 30 (thirty) days at the latest.
Where the application is rejected, the response given is found insufficient, or no response is given within the time limit, the applicant has the right to lodge a complaint with the KVK Board within 30 (thirty) days from the date on which they learned of the response, and in any event within 60 (sixty) days from the date of the application.
This Policy is retained in two different media: printed paper and electronic form.
This Policy is reviewed at least once every two years and updated in accordance with its principles where necessary.
This Policy is deemed to have entered into force upon its publication on the Company's website.
Should a decision be taken to repeal it, the former wet-signed copies of this Policy will be cancelled by the Legal Unit with the written approval of the Department Manager and retained for a period of 5 years.
Detailed information can be obtained from our Cookie Policy page.