Free shipping on orders over 1000₺ 🚚
Send a smile to someone you love ✨

Privacy Policy

At giftasmile.co we attach great importance to the security of our visitors and customers. To that end, and in order to protect your personal data and give you clearer information, we have prepared two important further pages: the KVKK Information Notice and the Cookie Policy.

Our company details

  • Company name: Balz E-Ticaret Reklam Tekstil Sanayi Ve Ticaret Ltd. Şti.
  • Address: Ünalan Mahallesi Besim Çeçener Caddesi No: 3/A Üsküdar / İstanbul, Türkiye
  • Email address: info@giftasmile.co
  • MERSIS number: [MERSIS Number]
  • Telephone: [Phone Number] (Call centre)

1. PURPOSE

At Balz E-Ticaret Reklam Tekstil Sanayi Ve Ticaret Ltd. Şti., our priority is to ensure that the personal data of natural persons — including our members, customers, visitors, suppliers and employees — is processed in accordance with the relevant legislation, in particular the Constitution of the Republic of Türkiye, the international conventions on human rights to which our country is a party, and Law No. 6698 on the Protection of Personal Data ("KVKK"), and to enable the data subjects whose data is processed to exercise their rights effectively.

For this reason, we carry out the processing, storage and transfer of all personal data obtained in the course of our activities — including but not limited to that of our employees, suppliers, customers, visitors, members and the users who visit our stores, our website and our mobile applications — in accordance with the Balz E-Ticaret Reklam Tekstil Sanayi Ve Ticaret Ltd. Şti. (giftasmile.co) Personal Data Protection and Processing Policy (the "Policy").

The protection of personal data and respect for the fundamental rights and freedoms of the natural persons whose personal data is collected are the core principles of our policy on the processing of personal data. For this reason, we conduct all our activities involving the processing of personal data with regard for the protection of privacy, the confidentiality of personal information, the confidentiality of communications, freedom of thought and belief, and the right to effective legal remedies.

In order to protect personal data, we take all administrative and technical protective measures required by the nature of the data concerned, in accordance with the legislation and current technology.

This Policy explains the methods we follow in processing, storing, transferring and erasing or anonymising the personal data shared with us during our commercial, promotional/marketing, social responsibility and similar activities, within the framework of the principles set out in the KVKK.

2. SCOPE

All personal data processed by the Company, including that of our visitors, business contacts, business partners, employees, suppliers, members and third parties, falls within the scope of this Policy.

Our Policy applies to all activities involving the processing of personal data owned or managed by the Company, and has been drawn up and prepared having regard to the KVKK, other relevant legislation on personal data, and international standards in this field.

3. DEFINITIONS AND ABBREVIATIONS

  • giftasmile.co: Balz E-Ticaret Reklam Tekstil Sanayi Ve Ticaret Ltd. Şti.
  • Explicit consent: Consent relating to a specific matter, based on information and free will, expressed in unambiguous terms and limited to that transaction alone.
  • Anonymisation: Rendering personal data incapable of being associated with an identified or identifiable natural person in any way, even by matching it with other data.
  • Employee: Company personnel.
  • Personal data owner (data subject): The natural person whose personal data is processed.
  • Personal data: Any information relating to an identified or identifiable natural person.
  • Special categories of personal data: Data relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of an association, foundation or trade union, health, sexual life, criminal convictions and security measures, together with biometric and genetic data.
  • Processing of personal data: Any operation performed on data, such as obtaining, recording, storing, retaining, altering, reorganising, disclosing, transferring, taking over, making available, classifying or preventing the use of personal data, by wholly or partly automated means or by non-automated means provided that it forms part of a data filing system.
  • Data processor: The natural or legal person who processes personal data on behalf of the data controller, on the authority granted by the data controller.
  • Data controller: The natural or legal person who determines the purposes and means of processing personal data and who is responsible for establishing and managing the data filing system.
  • KVK Board: The Personal Data Protection Board.
  • KVK Authority: The Personal Data Protection Authority.
  • KVKK: Law No. 6698 on the Protection of Personal Data, published in Official Gazette No. 29677 of 7 April 2016.
  • Policy: The Balz E-Ticaret Reklam Tekstil Sanayi Ve Ticaret Ltd. Şti. Personal Data Protection and Processing Policy.

4. ROLES AND RESPONSIBILITIES

4.1. Board of Directors

The Board of Directors is responsible for the senior oversight of the establishment and operation of notification, investigation and sanction mechanisms in the event of non-compliance with the Policy, rules and regulations.

The Personal Data Protection and Processing Policy has been approved by the Board of Directors.

It is the authorised approval mechanism for ensuring that the Policy is created, implemented and, where necessary, updated.

4.2. Audit Unit

The Audit Unit is responsible for taking the measures necessary to ensure the compliance of the employees involved and of outsourced firms with the Policy, and for examining matters with a view to investigating any issues contrary to the Policy.

4.3. Information Systems Committee

The Information Systems Committee is responsible for preparing, developing, implementing and updating this Policy. It assesses this Policy, where necessary, in terms of currency and development needs.

Publishing the prepared document on the corporate portal is the responsibility of the Information Systems Committee Manager.

5. LEGAL OBLIGATIONS

Our legal obligations as data controller in relation to the protection and processing of personal data under the KVKK are set out below:

5.1. Our duty to inform

As data controller, when collecting personal data we have a duty to inform the data subject about:

  • the purpose for which their personal data will be processed;
  • our identity and, where applicable, information on the identity of our representative;
  • to whom and for what purpose the processed personal data may be transferred;
  • our method of collecting the data and the legal ground for doing so;
  • the rights arising from the Law.

As a Company, we take care to ensure that this publicly available Policy is clear, understandable and easily accessible.

5.2. Our duty to ensure data security

As data controller, we take the administrative and technical measures prescribed by the legislation in order to ensure the security of the personal data in our custody. The obligations relating to data security and the measures taken are set out in detail in sections 9 and 10 of this Policy.

6. CLASSIFICATION OF PERSONAL DATA

6.1. Personal data

Personal data is any information relating to an identified or identifiable natural person. The protection of personal data concerns natural persons only; information belonging to legal entities that does not contain information relating to a natural person falls outside the scope of personal data protection. For this reason, this Policy does not apply to data belonging to legal entities.

6.2. Special categories of personal data

Data relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of an association, foundation or trade union, health, sexual life, criminal convictions and security measures, together with biometric and genetic data, constitute special categories of personal data.

7. PROCESSING OF PERSONAL DATA

7.1. Our principles for processing personal data

We process personal data in accordance with the following principles:

7.1.1. Processing lawfully and fairly: We process personal data fairly, transparently and within the framework of our duty to inform.

7.1.2. Ensuring that personal data is accurate and, where necessary, up to date: We take the necessary measures in our data processing procedures to ensure that the data processed is accurate and up to date. We also enable the personal data owner to contact us in order to update their existing data and to correct any errors in the data processed.

7.1.3. Processing for specified, explicit and legitimate purposes: As a Company, we process personal data within our legitimate purposes, the scope and content of which are clearly determined and which are established in order to conduct our activities within the framework of the legislation and the ordinary course of commercial life.

7.1.4. Personal data being relevant, limited and proportionate to the purposes for which it is processed: We process personal data in a manner that is relevant, limited and proportionate to the purpose we have clearly and precisely determined. We avoid processing personal data that is irrelevant or that does not need to be processed. For this reason, unless there is a legal requirement, we do not process special categories of personal data, or, where we must process them, we obtain explicit consent on the matter.

7.1.5. Retaining personal data for the period prescribed by legal regulations and for the duration of our legitimate commercial interests: Many provisions in the legislation require personal data to be retained for a certain period. For this reason, we retain the personal data we process for as long as is prescribed in the relevant legislation or as is necessary for the purposes for which the personal data is processed. Where the retention period prescribed in the legislation expires or the purpose of processing ceases to exist, we erase, destroy or anonymise the personal data.

7.2. Our purposes for processing personal data

We process personal data for the following purposes:

  • to conduct our commercial activities;
  • to provide support services within the scope of the contract and the framework of our service standards;
  • to identify the preferences and needs of our members/visitors and to shape and update the services we provide accordingly;
  • to fulfil our legal obligations as required or made compulsory by legal regulations;
  • to evaluate job applications;
  • to maintain contact with persons who have a business relationship with the Company;
  • to carry out marketing activities;
  • to support the training, development and career processes of our employees;
  • compliance management;
  • vendor/supplier management;
  • statutory reporting;
  • managing invoicing processes;
  • operating the giftasmile and giftasmile.co membership system;
  • enabling communication between giftasmile job candidates and employers;
  • managing call centre processes;
  • providing corporate communications;
  • personalising all of giftasmile's campaigns and making campaign and promotion recommendations based on areas of interest;
  • providing liaison, specifically for giftasmile, between the company and the shipping or technical service/returns processes after a product purchase;
  • sending newsletters by SMS and email, carrying out marketing activities or issuing notifications.

7.3. Processing of special categories of personal data

Special categories of personal data are processed by us where the administrative and technical measures prescribed by law and by the KVK Board have been taken and explicit consent exists, or in cases where the legislation makes it compulsory.

Since special categories of personal data relating to health and sexual life may be processed, for the purposes of protecting public health, preventive medicine, medical diagnosis, and the conduct of treatment and care services, and the planning and management of health services and their financing, only by persons under a duty of confidentiality or by authorised institutions and organisations, such data is not processed by us other than the data of our employees.

7.4. Processing of personal data collected through cookies

We use cookies to improve the way our web pages and mobile applications operate and are used, and we seek to make the time you spend on our digital platforms more efficient and more enjoyable. In addition, we make use of certain cookies to remember the choices you make on our websites and mobile applications, and in this way we provide you with an enhanced and personalised experience.

We may collect your personal data through the cookies on our digital platforms, and we may process, transfer and store the data we collect. You can find detailed information about the cookies we use in the giftasmile Cookie Policy.

7.5. Processing of personal data for recruitment and employment purposes

We process, store and transfer the personal data contained in your CV, diploma, photograph and other documents that you share with us during the application process as a job candidate, for the purpose of evaluating the job application. The processing, transfer and storage of the personal data you share as a job candidate falls within the scope of this Policy. Employees' personal data is collected, processed and stored within the framework of giftasmile Human Resources, outside this Policy.

7.6. Processing of personal data collected in connection with other memberships provided through the giftasmile.co membership system

In order to become a member of the digital platforms through the giftasmile.co system, visitors create a membership on the system by sharing with us their:

  • first name and surname;
  • email address;
  • telephone number;
  • date of birth / Turkish ID number.

7.7. Processing of personal data collected in connection with job applications

Personal data obtained through application forms, CVs and applications made to intermediary institutions will be recorded for use in evaluating the job application.

Those who apply using the application form create a CV by sharing information such as their identity details, contact details, education details, work experience, foreign language skills, computer skills, certificates, references, photograph, health data, and driving licence/ability to travel.

The information shared by applicants within their CV may be viewed by employer companies. Within the scope of the legislation, the company retains the identity, education and occupational details of THE PERSON MAKING THE APPLICATION and may, upon request, transfer this data to solution partners and to public institutions and organisations.

7.8. Processing of personal data collected in connection with purchase transactions

When a purchase is made, the CUSTOMER's financial information is transferred to persons and institutions such as banks or credit card companies in order to carry out the transaction. The data transferred is data relating to payment purposes, such as the credit card number, expiry date, CVV2 or bank account details.

During a purchase, the customer's invoice and payment details (first name, surname, Turkish ID number, telephone number, invoice address), the invoices sent, and data such as sample receipts for payments received from members, the payment number, invoice amount, invoice number and invoice date are obtained. This data is processed within the scope of managing the invoicing process, accounting, after-sales services, communication, marketing, auditing, control, and the processes carried out with payment service providers. Credit card details are not held in giftasmile's databases.

During purchases, video recording may be made in stores/facilities for security purposes and in order to monitor till transactions. In distance sales made by telephone, audio recording is made in order to enable the sale to be carried out securely.

7.9. Exceptional cases in which explicit consent is not required for the processing of personal data

We may process personal data without obtaining explicit consent in the following exceptional cases arising from the law:

  • where it is expressly provided for by law;
  • where it is necessary to process the personal data of the parties to a contract, provided that it is directly related to the conclusion or performance of that contract;
  • where data processing is mandatory for the establishment, exercise or protection of a right;
  • where processing your data is mandatory for our legitimate interests as data controller, provided that it does not harm your fundamental rights and freedoms.

8. TRANSFER OF PERSONAL DATA

8.1. Transfer of personal data within Türkiye

As a Company, we act in accordance with the KVKK and the decisions and regulations adopted by the KVK Board in relation to the transfer of personal data. Without prejudice to the exceptional cases set out in the legislation, personal data and special categories of data are not transferred by us to other natural or legal persons without the data subject's explicit consent.

8.2. Transfer of personal data abroad

As a rule, personal data is not transferred abroad without the data subject's explicit consent. However, where the exceptional cases set out in this Policy exist, transfers may be made to third parties located abroad without seeking explicit consent, provided that they are located in countries declared by the KVK Board to offer adequate protection, or in cases where adequate protection has been undertaken and the approval of the KVK Board exists.

8.2.1. Transfer abroad for the purposes of providing our services and marketing activities

We work with service providers located abroad for purposes such as developing the website and digital platforms, conducting surveys, increasing the range of products and services according to the preferences of visitors and members, and measuring the user experience.

8.3. Institutions and organisations to which personal data is transferred

Personal data may be transferred, in accordance with the principles and rules explained above, to:

  • our suppliers;
  • our business partners and business contacts;
  • technical services;
  • transport and courier companies;
  • legally authorised public institutions and organisations;
  • legally authorised private law persons;
  • independent audit firms.

8.4. Measures taken in relation to the lawful transfer of personal data

8.4.1. Technical measures: Establishing the internal technical organisation, ensuring the security of databases, building the technical infrastructure, carrying out periodic audits, keeping antivirus and firewall infrastructure up to date, and employing specialist personnel.

8.4.2. Administrative measures: Establishing internal access authorisation procedures, training and informing employees on the KVKK, and adding confidentiality and security undertakings to the contracts concluded with data processors.

9. RETENTION OF PERSONAL DATA

9.1. Retention periods

Without prejudice to the retention periods prescribed in the legislation, we retain personal data for as long as the purpose of processing the personal data requires. Where the retention period in the legislation expires or the purpose of processing ceases to exist, the personal data is erased, destroyed or anonymised.

9.2. Measures taken in relation to retention

The administrative and technical infrastructure necessary for the secure retention of personal data is established, contingency plans are drawn up, and authorised personnel are employed.

10. SECURITY OF PERSONAL DATA

10.1. Our obligations

We take the necessary administrative and technical measures in order to prevent the unlawful processing of and access to personal data, and to ensure its lawful retention.

10.2. Measures to prevent unlawful processing and access

Authorisation procedures are established, periodic internal audits are carried out, cyber security software is used, and mechanisms are operated to ensure that the KVK Board and the data subjects concerned are notified immediately in the event of any data breach.

11. RIGHTS OF THE PERSONAL DATA OWNER

In relation to their personal data, the personal data owner has the right to:

  • learn whether their personal data is being processed;
  • request information if their personal data has been processed;
  • learn the purpose of processing their personal data and whether it is used in accordance with that purpose;
  • know the third parties in Türkiye or abroad to whom their personal data has been transferred;
  • request the correction of their personal data if it has been processed incompletely or inaccurately;
  • request the erasure or destruction of their personal data where the reasons requiring its processing cease to exist;
  • request that correction, erasure or destruction operations be notified to the third parties to whom the data has been transferred;
  • object to a result arising against them as a consequence of the analysis of the processed data exclusively by automated systems;
  • claim compensation for the damage suffered as a result of the unlawful processing of their personal data.

11.1. Exercising these rights

The personal data owner may submit a request relating to their personal data:

  • In writing with a wet signature: by post or in person to the address Ünalan Mahallesi Besim Çeçener Caddesi No: 3/A Üsküdar / İstanbul, Türkiye.
  • Via registered electronic mail (KEP): to the KEP account [KEP Address].
  • By email: from the email address registered in our system to info@giftasmile.co.

The application must contain:

  • first name, surname and, if the application is in writing, a signature;
  • the Turkish ID number for Turkish citizens, and nationality, passport number or identity number (if any) for foreign nationals;
  • the place of residence or business address for service of notice;
  • the email address, telephone and fax number for notification, if any;
  • the subject of the request.

11.2. Evaluation of the application

Requests are concluded free of charge as soon as possible, depending on their nature, and within 30 (thirty) days at the latest.

11.3. Right to complain to the KVK Board

Where the application is rejected, the response given is found insufficient, or no response is given within the time limit, the applicant has the right to lodge a complaint with the KVK Board within 30 (thirty) days from the date on which they learned of the response, and in any event within 60 (sixty) days from the date of the application.

12. PUBLICATION AND RETENTION OF THE DOCUMENT

This Policy is retained in two different media: printed paper and electronic form.

13. UPDATE PERIOD

This Policy is reviewed at least once every two years and updated in accordance with its principles where necessary.

14. ENTRY INTO FORCE

This Policy is deemed to have entered into force upon its publication on the Company's website.

15. REPEAL

Should a decision be taken to repeal it, the former wet-signed copies of this Policy will be cancelled by the Legal Unit with the written approval of the Department Manager and retained for a period of 5 years.

16. DISABLING BROWSER COOKIES

Detailed information can be obtained from our Cookie Policy page.