Menu
Your Cart

Privacy Policy |allbazaardan.com

Privacy Policy | allbazaardan.com

Last updated date: 15.07.2026
Text version: 1.0
Platform: allbazaardan.com

1. Purpose and scope

This Privacy Policy; The allbazaardan.com website explains how personal data is processed within the scope of mobile compatible pages, customer accounts, seller stores, seller panel, order and payment processes, support channels, campaigns and other online services offered by the platform.

This policy may cover the following people:

  • site visitors,

  • members and members. candidates,

  • buyers,

  • order delivery recipients,

  • sellers and seller candidates,

  • sellers' officials, employees and representatives,

  • people sharing product evaluations or user content,

  • people making support, complaints or legal applications,

  • marketing and communication. users who express their preference,

  • other real persons who establish commercial or legal relations with the platform.

All personal data specified in this policy about each user are not processed. Scope of data processed; varies depending on the service used, the role of the user, the country of the order, the actual seller and the applicable legal requirements.

2.Legal nature of the policy

This policy explains allbazaardan.com's general approach to personal data processing.

This text:

  • does not stand alone as a statement of explicit consent,

  • does not replace a membership or vendor agreement,

  • does not constitute a commercial electronic message confirmation,

  • does not mean that all cookie categories are accepted.

  • It does not replace the special information texts that must be presented for each transaction.

In certain transactions such as membership, seller application, identity verification, order, payment, cookie, marketing, artificial intelligence use, precise location or data transfer abroad, the user may be informed separately and at the time of the transaction.

There is a distinction between disclosure and explicit consent. Just because the user reads this policy or accepts the membership agreement does not mean that the user automatically accepts all transactions that require explicit consent.

3. Data controller

Data controller in terms of activities determined by Aydın Kaydin Private Enterprise, the personal data processing purposes and methods within the scope of the operation of allbazaardan.com:

Commercial enterprise: Aydın Kaydin Private Enterprise
Tax number: 5370203844
Address: Hamzabey Mahallesi, Karacabey Caddesi No:25/7, Mustafakemalpaşa / Bursa 16500, Turkey
Phone: +90 535 920 73 78
E-mail: [email protected]
KEP: [email protected]

Organizations that provide hosting, software, security, support or similar services on behalf of the platform and in line with the instructions given may act as data processors according to the concrete service.

Sellers, banks, payment institutions, cargo companies or other service providers who independently determine their own data processing purposes are also data controllers in terms of their own activities. maybe.

4.Global marketplace structure

allbazaardan.com aims to operate as a multi-seller marketplace where buyers and independent sellers located in different countries can meet electronically.

The actual seller of a product on the platform:

  • Aydın Kaydin Sole Proprietorship,

  • An independent seller located in Turkey or

  • an independent seller located in another country. It may be the seller

.

Actual seller information, to the extent possible:

  • on the product page,

  • in the cart,

  • at checkout,

  • in the preliminary information form,

  • in the sales contract,

  • in the invoice or commercial In the document,

  • it is shown in the order details

.

Personal data required for the preparation, invoicing, sending, return and execution of after-sales services of the order by the real seller can be transferred to the relevant seller.

5. Roles of the platform and independent sellers

Independent sellers may act as data processors in some activities in which they process order data only under the instructions of the platform.

However, the seller must:

  • create its own legal records,

  • issue invoices,

  • manage the shipment of the product,

  • warranty or after-sales service

  • fulfill its own legal obligations,

  • process customer data on its own behalf and with its own decisions

the seller may also be the data controller.

The seller's own advertising list, customer relations system or off-platform communication activity is evaluated separately from the data processing activity of allbazaardan.com.

The marketing permission given for the platform is automatic permission for independent sellers' own advertising activities. does not create.

6.Applicable data protection regulations

For the operator of allbazaardan.com in Turkey, the Personal Data Protection Law No. 6698 and the relevant Turkish legislation are taken as basis.

Mandatory data protection regulations of other countries may also be applied depending on the country where the user is located, the seller's place of residence, the delivery country and the nature of the service offered.

Providing products or services to persons in the European Union or the European Economic Area or offering such persons. When monitoring platform behavior, GDPR provisions are taken into account to the extent applicable. GDPR; It regulates the principles of transparency, legality, limitation of purpose, data minimization, accuracy, storage limitation, security and accountability.

7. Personal data processing principles

Personal data is processed in accordance with the following basic principles in accordance with the applicable legislation:

  • compliance with the law and the rules of honesty,

  • accuracy and up-to-dateness when necessary,

  • processing for specific, clear and legitimate purposes,

  • being limited and proportionate to the purpose of processing,

  • necessary technical and administrative ensuring security,

  • storing for the period stipulated in the relevant legislation or required for the purpose,

  • processing activities being provable when necessary.

Just because a data is technically obtainable or accessible over the internet does not mean that the data can be processed unlimitedly.

8. Categories of personal data that may be processed

8.1. Identity information

According to the role of the user and the nature of the transaction:

  • name and surname,

  • user or customer number,

  • date of birth,

  • T.R.identification number,

  • foreign identification or passport information,

  • tax identification number,

  • authentication information,

  • signature and representative information,

  • identification information of the seller representative

can be processed.

The identification number or identification document is requested only to the extent necessary for verification, tax, payment, security or legal liability.

If it is necessary to obtain an identity document, areas that are not required for the transaction may be requested to be closed or darkened.

8.2. Contact information

  • phone number,

  • e-mail address,

  • delivery and billing address,

  • residence or workplace address,

  • postal code,

  • country, city and region information,

  • KEP address,

  • preferred communication language and channel.

8.3. Account and membership information

  • username,

  • customer and vendor account number,

  • password summary,

  • account creation date,

  • account status,

  • verification status,

  • login and exit records,

  • language, country and currency preferences,

  • favorites and saved lists,

  • notification preferences,

  • account authorizations.

It is essential that passwords are not stored in clear text and are protected with appropriate security methods.

8.4.Order and customer transaction information

  • products viewed or purchased,

  • basket and order content,

  • product quantity and variant,

  • order date and status,

  • real seller information,

  • delivery and cargo. records,

  • customs or import transaction information,

  • cancellation, withdrawal and return records,

  • refund information,

  • warranty and service requests,

  • support and complaint records,

  • seller-buyer messages,

  • user comments and evaluations,

  • campaign, coupon and promotion usage.

8.5. Finance and payment information

According to the nature of the transaction:

  • payment method,

  • payment transaction number,

  • collection and refund status,

  • bank or payment institution reference,

  • payment currency,

  • installment information,

  • invoice and tax information,

  • seller's IBAN or payment account,

  • seller progress payment, commission and offset records,

  • chargeback and payment dispute information

can be processed.

Card number, security code, bank password and strong customer verification codes can be directly processed by the authorized bank according to the payment infrastructure used. or processed by the payment institution.

The platform, seller or support staff do not ask the user for a bank password, card PIN code or single-use verification code.

8.6.Seller and commercial activity information

Within the scope of seller acceptance and store management:

  • trade name and store name,

  • company or business type,

  • tax and trade registry information,

  • country and activity address,

  • MERSİS, ESBİS or equivalent foreign commercial records,

  • representative and authorized information,

  • bank and payment account information,

  • invoice and accounting records,

  • manufacturer, importer or distributor information,

  • brand usage and authorized dealer documents,

  • category-specific permits, licenses, licenses and compliance. documents,

  • product safety and supply chain documents,

  • vendor performance, violation and sanction records

can be processed.

8.7. Transaction security information

  • IP address,

  • device and browser information,

  • operating system,

  • session ID,

  • access and transaction records,

  • time stamps,

  • failed login attempts,

  • identity and account verification records,

  • security events,

  • bot and automated usage indicators,

  • fraud and risk records,

  • payment and account security indicators.

8.8. Location and region information

  • delivery and billing address,

  • country, city and postal code,

  • Approximate location estimated from IP address,

  • delivery region selected by the user,

  • location shared with browser or device permission

can be processed.

It is required if the exact device location is to be used. To the extent necessary, device or browser permission is also obtained.

8.9.Marketing and preference information

  • commercial message approval and rejection records,

  • e-mail, SMS, telephone and notification preferences,

  • cookie and advertising preferences,

  • campaign interactions,

  • allowed personalization information,

  • user segments,

  • communication language and timing preferences.

8.10. Visual and audio information

  • profile and store images,

  • product photos and videos,

  • return or damage photos,

  • content sent within the scope of support,

  • images that may be required for verification,

  • call center received by informing the user records.

8.11. Legal transaction and compliance information

  • relevant person applications,

  • complaints and objections,

  • official correspondence,

  • consumer disputes,

  • court and arbitral tribunal records,

  • mediation and enforcement. records,

  • intellectual property violation notifications,

  • defense and evidence records,

  • sanctions and compliance reviews,

  • authorized public institution requests.

9.Personal data of special nature

The platform aims not to collect personal data of special nature for basic membership and shopping services.

Users may use product comment, seller message, support, return or document upload areas that are not required for the transaction:

  • health information,

  • biometric or genetic data,

  • political opinion,

  • religion or sect. information,

  • union membership,

  • criminal conviction information,

  • information about sexual life

should not be entered.

In exceptional cases where it is necessary to process special personal data, the applicable legal processing condition is determined and additional security measures are applied. KVKK's processing conditions for special data were changed in 2024 and the updated guide was published by the Authority.

10. Methods of obtaining personal data

Personal data can be obtained from the following sources automatically or by non-automatic methods provided that they are part of a data recording system:

  • membership and account forms,

  • seller applications,

  • product, basket and order transactions,

  • payment and refund processes,

  • delivery and cargo. integrations,

  • customs or cross-border logistics transactions,

  • support, return and warranty requests,

  • e-mail, KEP and telephone communication,

  • user comments and messages,

  • cookies and similar technologies,

  • server, system and security. records,

  • banks and payment institutions,

  • cargo and logistics companies,

  • e-invoice and accounting services,

  • sellers, manufacturers and authorized services,

  • user-authorized integrations,

  • official legal documents. sources.

If the user enters delivery information on behalf of another person, he/she is responsible for sharing this information accurately and legally.

11.Personal data processing purposes

11.1. Membership and account management

  • creating a membership account,

  • enabling user and seller login,

  • account verification,

  • password resetting and account recovery,

  • applying language, country and currency preferences,

  • account security. protection,

  • management of user rights.

11.2. Order and marketplace transactions

  • viewing the products and adding them to the cart,

  • creating the order,

  • determining the real seller,

  • creating contract and preliminary information records,

  • transmitting the order to the seller,

  • stock and delivery transactions. execution,

  • notifying the order status,

  • performing cancellation, withdrawal, return and refund transactions.

11.3. Payment and finance transactions

  • receiving and verifying payment,

  • strong customer verification,

  • offering different currencies and payment options,

  • refund transactions,

  • vendor progress and commission management,

  • invoicing and accounting transactions,

  • reverse Management of submission and payment disputes,

  • financial reconciliation and audit.

11.4. Cross-border delivery and customs procedures

In case the order is sent to a different country:

  • determination of the delivery country,

  • preparation of the transport document,

  • customs and import procedures,

  • tax and duty calculations,

  • contact with the carrier and customs representative. Necessary information may be processed for coordination,

  • delivery and return tracking

purposes.

11.5.Seller acceptance and verification

  • evaluation of seller application,

  • identity and commercial activity verification,

  • control of representation authority,

  • verification of payment account,

  • examination of category-specific permissions,

  • risk of fake sellers and unauthorized stores

  • ensuring product and seller security,

  • implementing platform rules.

11.6. After-sales support

  • receiving withdrawal and return requests,

  • defective, incorrect, incomplete or damaged product transactions,

  • warranty and service requests,

  • recording communication between the seller and the buyer,

  • examining complaints and disputes,

  • recall and product safety notifications. execution.

11.7. Information security and fraud prevention

  • preventing the risk of account takeover,

  • detection of fake accounts, orders or payment transactions,

  • preventing bots and data scraping attempts,

  • examining unusual account movements,

  • ensuring payment and user security,

  • cyber security. investigating events,

  • protecting transaction records.

11.8. Legal and financial obligations

  • keeping tax and accounting records,

  • documenting electronic commerce and consumer transactions,

  • fulfilling product safety obligations,

  • meeting the requests of authorized institutions,

  • managing disputes and legal applications,

  • contractual and protection of legal rights.

11.9.Service development

  • technical error and performance measurement,

  • improvement of user experience,

  • development of product, category and search structure,

  • preparation of collective and statistical reports,

  • security and capacity planning,

  • customer and vendor support processes. development.

11.10. Marketing and personalization

When there is an appropriate legal requirement:

  • notifying campaigns and opportunities,

  • sending commercial messages via e-mail, SMS or other channels,

  • offering product recommendations in line with the user's preferences,

  • measuring advertising and campaign performance,

  • personalized content to the extent permitted.

Data processing for marketing purposes is not made a mandatory condition for basic membership and shopping services.

12. Personal data processing conditions

Personal data may be processed based on one or more of the following legal reasons, depending on the concrete processing activity:

  • explicit consent of the relevant person,

  • explicitly foreseen by law,

  • required for the establishment or execution of a contract,

  • fulfillment of the legal obligation of the data controller.

  • protecting the life or physical integrity of the person concerned or another person,

  • being made public by the person concerned and processed in accordance with the purpose of publicization,

  • establishing, exercising or protecting a right,

  • legitimate interest provided that it does not harm the fundamental rights of the person concerned,

  • other legal provisions stipulated in the applicable foreign legislation. bases.

If a data processing activity is based on a valid legal reason other than explicit consent, explicit consent is not obtained unnecessarily for the same activity.

In cases where GDPR is applicable, the appropriate one of the fulfillment of the contract, legal obligation, legitimate interest, explicit consent and other legal bases specified in the relevant regulation is determined.

13.Transfer of order information to the seller

In case of ordering from an independent seller, necessary for the preparation and fulfillment of the order:

  • name of buyer or delivery recipient,

  • delivery address,

  • phone number,

  • e-mail or order contact information,

  • purchased products,

  • ordering and delivery instructions,

  • information required for invoice

can be transferred to the real seller.

Transfer; It is limited to order preparation, invoicing, sending, delivery, return, warranty and after-sales services.

The seller cannot:

  • add the customer information accessed within the scope of the order to its own independent advertising list,

  • send commercial messages without legal basis,

  • sell it to third parties,

  • profiling for unrelated purposes. cannot,

  • cannot store it unnecessarily after the transaction is completed.

14. Sharing with cargo, logistics and customs parties

Information required to deliver the order:

  • to cargo companies,

  • international carriers,

  • logistics and storage providers,

  • customs consultants,

  • mail or delivery It can be transferred to operators,

  • authorized institutions in the delivery country

.

Data to be transferred; Identification of the shipment is limited to the scope required for delivery, customs clearance, tax or import liability.

In cross-border delivery, the recipient's name, address, telephone number, product information, value, shipping and tax information may be shared with the authorized institutions in accordance with the legislation of the relevant country.

15. Payment transactions

Payments can be carried out through authorized banks or payment institutions.

Depending on the payment infrastructure, card information may be transmitted directly to the relevant bank or payment institution.The Platform only records limited records such as:

  • transaction reference,

  • payment status,

  • collection amount,

  • currency,

  • masked card information,

  • installment,

  • refund or chargeback information

Transactions carried out by the payment institution for its own purposes may also be subject to the confidentiality and disclosure texts of the relevant institution.

16. Seller verification and identity review

For the security and legality of seller accounts:

  • identity,

  • tax registration,

  • company registration,

  • business address,

  • bank account,

  • representation authority,

  • supply and brand authority,

  • product safety documentation

can be verified.

Verification; It can be done through platform personnel, official records or appropriate identity verification services.

It is essential to process only the necessary data about the seller for the evaluation of the application and compliance with the legislation.

17. Commercial electronic message

Commercial electronic message consent, cookie consent and general privacy information are different from each other.

If it will be sent to the user for advertising or campaign purposes:

  • e-mail,

  • SMS,

  • phone call,

  • instant notification

to the relevant country and communication channel. Necessary permission is obtained accordingly.

Service messages such as order confirmation, payment result, security warning, cargo information, return result or support response are separate from marketing messages.

The user can change marketing preferences from account settings, the rejection method in the message or support channels.

18.Cookies and similar technologies

On the platform:

  • mandatory,

  • preference,

  • analytical,

  • advertising and marketing,

  • third party

cookies may be used.

Non-mandatory analytical and advertising cookies are necessary. It is operated according to the user's active preference to the extent.

The name, provider, purpose, category and duration of cookies are disclosed in the cookie preference panel with the Cookie Policy.

Cookie consent does not constitute automatic permission to send commercial messages or independent marketing activities of sellers.

19. User comments and public content

Published by the user:

  • product evaluation,

  • store comment,

  • question or answer,

  • profile or display username,

  • uploaded image

made available to other users

Users may access public areas:

  • telephone number,

  • full address,

  • identification number,

  • payment or bank information,

  • private correspondence,

  • personal data of third parties,

  • special quality not required for the transaction. should not add

data.

The platform may remove or limit the visibility of user content that contains personal data or security risks.

20.Automated risk assessment

The platform may utilize automated systems for security and fraud prevention purposes.

These systems:

  • identify unusual logins,

  • unsuccessful payment attempts,

  • signs of account takeover,

  • fake order patterns,

  • bots and automated transactions.

  • merchant performance risks,

  • suspicious product or user activity

automated systems may direct an account or transaction for additional verification or create a temporary security measure.

If a decision that has significant legal or similar consequences for a user is based solely on automated evaluation, the user has the opportunity to appeal the decision and request human review in accordance with applicable legislation.

GDPR provides special protections, in the relevant circumstances, only for decisions based on automatic processing and which have a legal or similar significant impact on a person.

21.Artificial intelligence supported transactions

Platform; can benefit from artificial intelligence-supported tools for the following purposes:

  • product content improvement,

  • translation and language support,

  • customer support recommendations,

  • fraud and security analysis,

  • inappropriate product or content detection,

  • seller and store performance analysis,

  • technical error. and service improvement.

If it is necessary to transfer personal data to the artificial intelligence service:

  • data scope,

  • processing purpose,

  • legal role of the provider,

  • storage of the data,

  • whether it is used for model training,

  • overseas transfer. conditions,

  • security measures

are also evaluated.

Masked, pseudonymous or anonymized data that does not contain personal data is used to the extent possible.

Users should not enter personal or special data that is not necessary for the process in the artificial intelligence command, support or product content fields.

22.Data transfer within the country

Personal data may be transferred to the following recipient groups to the extent required by the transaction:

  • real sellers,

  • manufacturers, importers and authorized services,

  • banks and payment institutions,

  • cargo and logistics companies,

  • customs and foreign trade services. providers,

  • e-invoicing and accounting providers,

  • hosting, software and security services,

  • e-mail, SMS and communications services,

  • customer support providers,

  • auditors, financial advisors, lawyers and consultants,

  • insurance and fraud prevention services,

  • legally authorized public institutions,

  • courts and dispute resolution authorities.

For domestic transfer, there must be a legal basis in accordance with the personal data processing conditions.

Only the data required for the relevant service is transferred to each recipient.

23. Transfer of personal data abroad

During the execution of the global marketplace service, personal data may be transferred outside Turkey for the following reasons:

  • preparation of an order by a foreign seller,

  • international cargo and customs procedures,

  • payment or bank services abroad,

  • cloud and hosting services,

  • e-mail and communication. infrastructure,

  • content distribution and security services,

  • analytical and advertising tools,

  • artificial intelligence and technical support services,

  • manufacturer or authorized service operations in a foreign country.

For transfer abroad, the method appropriate to the concrete transaction is determined.Within the scope of the current transfer regime in Turkey:

  • adequacy decision,

  • standard contract,

  • binding company rules,

  • other appropriate assurances approved by the Board,

  • incidental transfer conditions limitedly regulated in the law

can be evaluated.

In case a standard contract is used, the text announced by the Authority is the basis. are received and relevant notification obligations are fulfilled.

The user's consent to a category of cookies or a certain feature does not mean that all conditions for the transfer of personal data abroad are automatically met.

24. Data transfer from the European Economic Area

In cases where the GDPR is applied, the international data transfer rules of the GDPR are taken into account for the transfer of personal data from the European Economic Area to Turkey or another third country.

Depending on the nature of the transfer:

  • adequacy decision,

  • standard contractual clauses,

  • binding corporate rules,

  • other appropriate safeguards,

  • limited exceptions

can be evaluated.

The transfer method is determined by taking into account the roles of the parties sending and receiving the data, the categories of data transferred and the conditions of the relevant country. Articles 44 et seq. of the GDPR regulate the conditions for transfers to third countries.

25. Sharing with authorized institutions

Personal data:

  • legal obligation,

  • court or prosecutor's office decision,

  • consumer dispute,

  • tax and financial audit,

  • customs and foreign trade transaction,

  • product safety It may be transferred to legally authorized institutions due to investigation,

  • suspicion of fraud or crime,

  • protection of platform or user rights

.

Every official request; It is evaluated in terms of the authority of the institution, the legal basis of the request and the scope of the requested data.

It is essential not to share more personal data than necessary.

26.Storage periods

Personal data:

  • purpose of processing,

  • membership or contractual relationship,

  • ordering and delivery processes,

  • tax and accounting obligations,

  • consumer and electronic commerce regulations,

  • customs and foreign trade obligations,

  • product safety requirements,

  • dispute and statute of limitations,

  • security and fraud risks,

  • need for legal proof

.

A single storage period does not apply to all personal data.

For example:

  • active. account data as long as the membership continues,

  • order and invoice records during the financial and commercial retention periods,

  • seller verification documents during the sales relationship and legal requirement,

  • support and dispute records throughout the request and proof need,

  • security logs for a limited period commensurate with the risk,

  • marketing permission and rejection records as proof of permission status.

Closing the account does not require the immediate deletion of records that must be kept legally.

27.Deletion, destruction and anonymization

When all the conditions requiring the processing of personal data are eliminated, the data is:

  • deleted,

  • destroyed or

  • anonymized.

In case the reasons for processing disappear, the data controller has the obligation to delete, destroy or anonymize; Application of the relevant person for this process is not mandatory in all cases.

Deletion and destruction method:

  • is determined by taking into account the environment in which the data is kept,

  • legal storage requirement,

  • technical possibilities,

  • backup structure,

  • information security risk

.

Storage and destruction. For data controllers who are obliged to prepare a policy, it is envisaged that the periodic destruction interval should not exceed six months.

Data in backups can be blocked from access and deleted within the backup cycle.

28. Information security

Technical and administrative measures proportionate to the risk are applied to prevent personal data from being unlawfully processed, changed, lost or accessed by unauthorized persons.

These measures may include, as appropriate:

  • task and role-based access authorizations,

  • strong password rules,

  • multi-factor authentication,

  • secure connection and encryption,

  • firewall and intrusion prevention,

  • malware protection,

  • logging and event monitoring,

  • backup and restore controls,

  • software updates and security patches,

  • data minimization,

  • employee and service provider authorization,

  • confidentiality and data processing agreements,

  • security tests,

  • incident response plans.

No internet system can guarantee absolute security. In addition, it is aimed to implement up-to-date and reasonable measures appropriate to foreseeable risks.

29.Account security

The user should:

  • use a strong and unique password,

  • not share passwords and verification codes with others,

  • log out of shared devices,

  • report suspicious logins without delay,

  • update account contact information.

In case of suspicious account activity, the platform may:

  • request additional verification,

  • terminate sessions,

  • apply temporary account restrictions,

  • initiate a password reset.

30. Personal data breaches

In case it is understood that personal data has been obtained by others through illegal means:

  • the incident is investigated,

  • its effects are limited,

  • measures are taken to stop access,

  • evidence and intervention records are protected,

  • if required by legislation, relevant persons and authorized data protection institutions.

Notification obligation; It is evaluated according to the nature of the breach, affected persons, data categories, possible damages and applicable country legislation.

31. Children's personal data

The platform is not designed for children who do not have legal capacity to open merchant accounts independently or carry out high-risk payment and commercial transactions.

Parental or legal representative approval may be requested depending on the user's age, country of residence and the nature of the transaction.

Children's:

  • identity document,

  • payment information,

  • open address,

  • exact location,

  • recognizable photo,

  • school or regular place information

should not be shared unnecessarily.

Information for children must be clear, easy to understand and age appropriate.Children are considered as persons who need special protection in the processing of personal data.

If it is thought that the personal data of a child has been processed unlawfully, a notification can be made via [email protected].

32. Responsibilities of users

Users must:

  • provide accurate and up-to-date information,

  • not share other people's data unlawfully,

  • not add unnecessary personal information to product reviews or support areas,

  • protect account access information,

  • be careful against fraudulent payment and identity verification requests. should be,

  • report suspicious data usage to the platform.

The fact that the user shares information voluntarily does not prevent the platform from intervening in content that is unlawful, excessive or poses a security risk.

33. Relevant person rights within the scope of KVKK

Relevant persons to whom KVKK applies in Turkey can apply to the data controller to:

  • find out whether their personal data is processed,

  • request information if processed,

  • learn the purpose of processing and whether it is used in accordance with the purpose,

  • third parties to whom it is transferred domestically or abroad.

  • requesting correction of incomplete or inaccurate data,

  • requesting deletion or destruction when the conditions are met,

  • requesting correction or deletion to be notified to the transferred parties,

  • objecting to an unfavorable result as a result of analysis exclusively through automatic systems,

  • removing the damage caused by unlawful processing. has the right to demand

.

These rights are not absolute. Requests are evaluated taking into account legal retention obligations, rights of other persons, public interest and applicable exceptions.

34.User rights in other countries

Depending on the data protection legislation applicable in the country where the user is located, the user may also be granted the following rights:

  • access to his/her data,

  • correction of data,

  • deletion of data,

  • restriction of processing,

  • to certain operations. objection,

  • data portability,

  • withdrawal of express consent,

  • objection against automated decisions,

  • complaint to the competent data protection authority.

Relevant persons to whom the GDPR applies; may have rights such as access, correction, deletion, limitation of processing, data portability and objection.

Whether a request will be accepted or not is evaluated according to the type of request, the country where the user is located and the legislation applicable to the platform.

35. Application methods

Requests within the scope of KVKK can be submitted by one of the following methods:

  • written application with wet signature,

  • secure electronic signature,

  • mobile signature,

  • registered e-mail,

  • user's e-mail address registered in the system,

  • for application. created electronic form or application.

In the application, to the extent possible:

  • name and surname,

  • information sufficient for identity or account verification,

  • contact address,

  • registered e-mail or KEP address, if any,

  • subject of the request,

  • relevant account, order or transaction information,

  • documents supporting the request

must be available.

Identity verification commensurate with the nature of the request may be requested.

Applications are evaluated within the periods specified in the applicable legislation.

36.Application channels

Written application address:
Aydın Kaydin Sole Proprietorship
Hamzabey Mahallesi, Karacabey Caddesi No:25/7
Mustafakemalpaşa / Bursa 16500, Turkey

KEP: [email protected]

Via the e-mail registered in the system: [email protected]

Sending the application from the e-mail address registered in the user account, if possible It is recommended.

Writing the application subject:

“Personal Data Application – allbazaardan.com”

makes it easier to separate the request from general support records.

37. Third party links and services

On the platform:

  • independent seller sites,

  • banks and payment institutions,

  • shipping and tracking pages,

  • manufacturer or authorized services,

  • map and video services,

  • social media There may be links to platforms,

  • other third-party services

.

If the user switches to a third-party service, the privacy policy and terms of use of the relevant organization may apply.

The platform may not have full control over the data processing purposes and methods of the independent third party.

38.Closing the account

When the user closes the account:

  • active use of the account may be terminated,

  • profile visibility may be removed,

  • new orders or transactions may be prevented,

  • data that is not legally required to be kept may be subject to deletion and destruction.

The account may be deleted. closing:

  • order,

  • payment,

  • invoice,

  • tax,

  • customs,

  • security,

  • complaint,

  • legal The transaction does not require the immediate deletion of records that must be kept due to

  • statute of limitations

.

In case of serious breach or fraud, limited security records may be retained for appropriate legal reason to prevent the same risk from recurring.

39. Policy changes

This policy may be updated in the following cases:

  • providing services in a new country or market,

  • change of seller or payment model,

  • use of a new service provider,

  • change of personal data processing purposes,

  • addition of a new artificial intelligence or analysis system,

  • international data flow. changes,

  • updating information security or storage practices,

  • changes in legislation and authorized institution decisions.

The current date of the policy is shown at the top of the page.

Changes that significantly affect user rights or the scope of data processing:

  • site notification,

  • account notification,

  • e-mail. or

  • another appropriate communication method

.

If the new processing purpose requires explicit consent, the existing consent is not automatically considered valid for the new purpose.

40.Relationship with other texts

This Privacy Policy is evaluated together with the following texts:

  • Information Text on the Processing of Personal Data,

  • Explicit Consent Policy,

  • Cookie Policy,

  • KVKK Application Form,

  • Membership and Use Conditions,

  • Seller Membership and Brokerage Agreement,

  • Distance Sales Agreement,

  • Preliminary Information Form,

  • Commercial Electronic Message Preferences,

  • Overseas Data Transfer explanations.

In case there is a difference between these texts, the clarification text specific to the concrete transaction and the applicable mandatory information. legislation is taken as basis.

41. Business and contact information

Platform: allbazaardan.com

Service model: Global multi-vendor electronic commerce and online marketplace platform

Data controller, electronic commerce intermediary service provider and legal operator: Aydın Kaydin Sole Proprietorship

Tax number: 5370203844

Address: Hamzabey Mahallesi, Karacabey Caddesi No:25/7, Mustafakemalpaşa / Bursa 16500, Turkey

Phone: +90 535 920 73 78

E-mail: [email protected]

KEP: [email protected]

Digital support and personal data applications are always available through online channels.

Telephone and live support services are provided according to the current work and support calendar published on allbazaardan.com.

42.Allbazaardan approach

allbazaardan.com; It aims to bring together buyers and independent sellers in different countries with the principles of open seller identity, registered transaction, secure payment and accessible support.

Personal data:

  • must be limited to the scope necessary to provide the service,

  • should not be used unauthorized for purposes other than ordering,

  • should not be opened to unauthorized marketing activities of independent sellers,

  • appropriate legal data in cross-border transfers. and should be protected with technical safeguards,

  • managed with systems where users can exercise their rights effectively.

The purpose of the platform is; To create a transparent global marketplace where users can understand which data is processed and why, manage their preferences, apply for personal data and carry out the international shopping process safely.

Cookies and Privacy Preferences

allbazaardan.com uses strictly necessary cookies to keep the website secure and functioning properly. Non-essential functional, analytics and advertising cookies may be used according to your preferences.

For detailed information, please review our Cookie Policy , Privacy Policy and KVKK Information Notice .

Closing this notice does not mean that you consent to non-essential cookies.