Privacy and Protection of Personal Data Policy is an important matter for Winfluencer Digital Marketing Services Inc. (“Winfluencer”). As the data controller, Winfluencer adopts the principles stipulated in the Personal Data Protection Law No. 6698 (“PDPL Law”) to ensure compliance with the PDPL Law and fulfills its obligations regarding the processing, deletion, destruction, anonymization, transfer, informing the data subject, and ensuring data security of personal data. In this context, the Privacy and Protection of Personal Data Policy, which is prepared, is made accessible to the individuals (“Data Subjects”) whose personal data is processed.

 

Scope and Purpose of the Privacy and Protection of Personal Data Policy

This Privacy and Protection of Personal Data Policy includes:

 

The methods and legal reasons for collecting personal data,

The categories of individuals whose personal data is processed (Categorization of Data Subject Groups),

The categories of personal data processed regarding these groups of individuals (Data Categories) and example data types,

The business processes and purposes for which personal data is used,

Technical and administrative measures taken to ensure the security of personal data,

To whom and for what purposes personal data may be transferred,

Storage periods of personal data,

Profiling and Segmentation,

The rights of the Data Subjects regarding their personal data and how to exercise these rights,

How Data Subjects can change their preferences regarding receiving electronic commercial communications,

Sharing personal data with official authorities,

Use and management of cookies.

  1. Methods and Legal Reasons for Collecting Personal Data

 

Winfluencer collects personal data through websites, mobile applications of websites, social media accounts, cookies, call centers, notifications received from administrative and judicial authorities, and other communication channels based on the legal reasons explicitly stipulated in Article 5 of the Personal Data Protection Law No. 6698, which are:

 

It is expressly provided for by the laws,

It is necessary for the performance of a contract to which the data subject is a party, or for the conclusion of a contract,

The personal data of the data subject is made public by the data subject,

Data processing is necessary for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject,

Data processing is necessary for the establishment, exercise, or protection of a right,

based on auditory, electronic, or written means through websites, mobile applications of websites, social media accounts, cookies, call centers, notifications received from administrative and judicial authorities, and other communication channels.

  1. Categorization of Data Subject Groups

 

Winfluencer categorizes the groups of data subjects whose personal data is processed in its personal data processing activities and related processes as follows. However, personal data of other groups of individuals (consultants, educators, bloggers) may also be processed in accordance with the personal data processing conditions specified in Articles 5 and 6 of the Personal Data Protection Law (PDPL Law) and within the legal reasons stated in this Privacy and Protection of Personal Data Policy.

 

  1. Data Categories and Example Data Types

 

Member Customer

  • Identity Information: Name, surname, date of birth, gender, national identification number
  • Location Information: City of residence, district (delivery address for purchases made through Winfluencer.com)
  • Contact Information: Mobile phone, email address, address, postal code, landline phone
  • Financial Information: Tax office, invoice details
  • Customer/Member Information: Membership information, membership ID number
  • Customer/Member Transaction Information: Purchased product(s), purchase amount, purchase date, call center conversation records, commercial communication consent, utilized campaigns/contests, used coupons, order-related information
  • Risk Management Information: IP address
  • Transaction Security Information: Password, password information
  • Marketing Information: Cookie records, targeting information, evaluations indicating habits and preferences
  • Audio Data: Call center conversation records
  • Legal Transaction and Compliance Information: Start and end time of the provided service, type of service utilized, amount of transferred data, consent for commercial electronic messages given by the Relevant Person, membership agreement given, corporate membership agreement, other legal texts and contracts enabling the utilization of services provided by Winfluencer
  • Direct Marketing Information: Marketing SMS messages, email messages, or calls made by the call center sent based on the commercial electronic message consent given by the relevant person
  • Request/Complaint Management/Reputation Management Information: Records related to complaints and/or requests communicated by the relevant person through the website, mobile application, social media accounts, or call center regarding the purchased product or service, and the evaluation or management processes of these requests.

Guest Customer (non-member users)

  • Identity Information: Name, surname, date of birth, Turkish identification number
  • Location Information: City of residence, district (delivery address for purchases made through Winfluencer.com)
  • Contact Information: Mobile phone, email address, address, postal code, landline phone
  • Financial Information: Tax office, invoice details
  • Guest Customer Transaction Information: Purchased product(s), purchase amount, purchase date, call center conversation records, commercial communication consent, utilized campaigns
  • Risk Management Information: IP address
  • Transaction Security Information: Password, password information
  • Marketing Information: Cookie records, targeting information, evaluations indicating habits and preferences
  • Audio Data: Call center conversation records
  • Legal Transaction and Compliance Information: Start and end time of the provided service, type of service utilized, amount of transferred data, consent for commercial electronic messages given by the Relevant Person, legal texts and contracts enabling the utilization of services provided by Winfluencer
  • Direct Marketing Information: Marketing SMS messages, email messages, or calls made by the call center sent based on the commercial electronic message consent given by the relevant person
  • Request/Complaint Management/Reputation Management Information: Records related to complaints and/or requests communicated by the relevant person through the website, mobile application, social media accounts, or call center regarding the purchased product or service, and the evaluation or management processes of these requests.

 

Online Visitor

  • Transaction Security Information: Password, mobile phone, password information
  • Legal Transaction Information/Risk Management Information: IP address
  • Legal Transaction and Compliance Information: Start and end time of the provided service, type of service utilized, amount of transferred data.

 

Recipient of the Purchased Product

  • Identity Information: Name, surname, date of birth, gender, Turkish identification number
  • Location Information: City of residence, district (delivery address for purchases made through Winfluencer.com)
  • Contact Information: Mobile phone, email address, address, postal code, landline phone
  • Financial Information: Tax office, invoice details

 

Seller/Supplier/Seller Candidate/Seller or Supplier Employee or Representative

  • Identity Information: Turkish Identification Number, Name, surname
  • Contact Information: Email address, phone, KEP address, address, mobile phone
  • Financial Information: Account number, Tax office, Tax Identification Number, tax certificate, IBAN
  • Legal Transaction and Compliance Information: Signature circular, business license
  • Special Category Personal Data/Legal Transaction Information: Signature
  • Visual Information: Photograph

Personal Data Usage in Which Business Processes and for What Purposes

  1. a) Personal Data of Member Customers

 

  • Conducting membership processes,
  • Improving the services provided through the “Winfluencer.com” e-commerce platforms (“platform”) operated by Winfluencer, developing new services, and providing related information,
  • Performance of the Membership Agreement established with the Member Customer, for existing Member Customers with regard to obtaining their commercial electronic message consent; analyzing the preferences, likes, and needs of the Member Customer and providing personalized promotions, opportunities, and benefits to the Member Customer,
  • Conducting marketing, targeting, profiling, and analysis based on the explicit consent of the Member Customer and promoting and marketing applications, goods/products, and services in line with the preferences and likes of the Member Customer,
  • Resolving issues and complaints of Member Customers,
  • Improving the Member Customer experience on both the platform and mobile application,
  • Tracking accounting and purchasing transactions,
  • Legal processes and compliance with legislation,
  • Responding to information requests from administrative and judicial authorities,
  • Ensuring information and transaction security and preventing misuse,
  • Making necessary arrangements to ensure the accuracy and currency of processed data.

 

  1. b) Personal Data of Guest Customers (users who make purchases from the site without becoming members)

 

  • Enabling shopping as a “guest” on the platforms,
  • Improving the services provided through the platforms, developing new services, and providing related information,
  • Analyzing the preferences, likes, and needs of Guest Customers with regard to obtaining their commercial electronic message consent and providing personalized promotions, opportunities, and benefits to Guest Customers,
  • Conducting marketing, targeting, profiling, and analysis based on the explicit consent of the Guest Customer and promoting and marketing applications, goods/products, and services in line with the preferences and likes of the Guest Customer,
  • Resolving issues and complaints of Guest Customers,
  • Improving the Guest Customer experience on both the platform and mobile application,
  • Tracking accounting and purchasing transactions,
  • Legal processes and compliance with legislation,
  • Responding to information requests from administrative and judicial authorities,
  • Ensuring information and transaction security and preventing misuse,
  • Making necessary arrangements to ensure the accuracy and currency of processed data,
  • Fulfilling legal obligations.

 

Personal Data of Online Visitors

  • Processing online visitor data within the scope of Law No. 5651,
  • Legal processes and compliance with legislation,
  • Responding to information requests from administrative and judicial authorities,
  • Ensuring information and transaction security and preventing misuse,
  • Fulfilling legal obligations.

 

Personal Data of the Recipient of the Purchased Product

  • Execution of product delivery processes,
  • Tracking accounting and purchasing transactions,
  • Legal processes and compliance with legislation,
  • Responding to information requests from administrative and judicial authorities,
  • Ensuring information and transaction security and preventing misuse,
  • Making necessary arrangements to ensure the accuracy and currency of processed data,
  • Fulfilling legal obligations.

 

Personal Data of Seller/Supplier/Seller Candidate/Seller or Supplier Employee or Representative

  • Conducting contract processes,
  • Tracking accounting and purchasing transactions,
  • Legal processes and compliance with legislation,
  • Responding to information requests from administrative and judicial authorities,
  • Ensuring information and transaction security and preventing misuse,
  • Making necessary arrangements to ensure the accuracy and currency of processed data,
  • Fulfilling legal obligations.

To ensure the security of personal data, Winfluencer undertakes to take all necessary technical and administrative measures and exercise due diligence.

 

Winfluencer takes necessary measures to prevent unauthorized access to personal data, misuse, unlawful processing, disclosure, alteration, or destruction of personal data. Winfluencer uses widely accepted security technology standards such as security firewalls and Secure Socket Layer (SSL) encryption when processing personal data. Additionally, when you submit your personal data to Winfluencer through the website, mobile application, or mobile site, this data is transferred using SSL.

 

To prevent unauthorized access to personal data, unlawful processing of such data, and ensure the preservation of personal data, Winfluencer:

 

  • Protects all fields in the website or mobile application where personal data is collected with SSL.
  • Establishes and implements access authorization and control matrices for its employees to prevent unlawful processing of personal data collected from the website or mobile application.
  • Conducts periodic penetration tests and tests the system’s resilience to unauthorized access to ensure that personal data is not accessed unlawfully.
  • Uses the Pseudonymization method for all secondary data processing that goes beyond the primary processing purpose. It employs encryption methods in systems containing pseudonymous data to make it impossible to identify the relevant individual and applies stricter access authorization and control policies to such data.
  • Ensures that personal data in paper format is kept in locked cabinets and accessed only by authorized personnel.
  • Personal data processed through cookies belonging to third parties providing services are deleted from the systems of these third parties when the membership ends.

 

In the event that personal data is compromised or falls into the hands of unauthorized third parties as a result of attacks on the platforms operated by Winfluencer or the Winfluencer system, Winfluencer immediately notifies you and the Personal Data Protection Authority and takes necessary measures.

 

  1. Recipients and Purposes of Personal Data Transfers

 

Winfluencer transfers personal data to third parties only for the purposes specified in this Privacy and Personal Data Protection Policy and in accordance with Articles 8 and 9 of the Personal Data Protection Law (PDPL). Within this scope, customer data of Member Customers/Guest Customers and the recipient information of the purchased product for delivery purposes are shared with sellers and the shipping company Winfluencer, and this data can also be accessed by the call center when necessary. The recipient information for invoicing purposes is shared with the shipping company Winfluencer for the delivery of the invoice to the relevant person.

 

Mobile phone number and/or email address of Member Customers/Guest Customers are shared with commercial electronic communication service providers based on the consent given for commercial electronic communication, in order to send promotional messages, advertisements, and offers according to shopping preferences, likes, and habits.

 

Website or mobile application usage preferences and browsing history are shared with our domestic/foreign business partners for segmentation and communication with Member Customers/Guest Customers based on their preferences and likes, using cookie services.

 

In this context, personal data transfers are carried out through secure environments and channels provided by the relevant third party. Depending on the content and scope of the services obtained from third parties, transfers of personal data of Member Customers/Guest Customers that do not require transfers are made using Pseudonymous data.

 

Data of Member Customers/Guest Customers are shared with Winfluencers conducting market research to enhance customer satisfaction and loyalty.

 

Personal data may also be shared with our business partners abroad for the provision of business development services, statistical and technical services, and the management of customer relations.

 

If Member Customers/Guest Customers/Online Visitors contact Winfluencer via the corporate WhatsApp line, their personal data will be transmitted abroad since the WhatsApp platform is a service provided from abroad. If Member Customers/Guest Customers/Online Visitors do not want to send their personal data abroad using WhatsApp, they can use other communication methods offered by Winfluencer.

 

The personal data transferred within the scope mentioned above are protected legally through the provisions included in our contracts, taking into account whether the counterparty of the legal relationship is a data controller or data processor and ensuring a secure environment and channels provided by the relevant third party.

 

When transferring personal information to countries other than Turkey during the information sharing process mentioned above, the data is transferred in compliance with this policy and in accordance with the applicable data protection laws.

  1. Storage Periods for Personal Data

 

Winfluencer retains the personal data it processes in compliance with the Personal Data Protection Law (PDPL), for the periods prescribed in the relevant legislation or as required by the processing purpose. Additionally, your personal data may be stored to the extent necessary for the realization of the necessary defenses in the event of any dispute between you and Winfluencer.

 

You can refer to our Cookie Policy for information on the storage periods of personal data obtained through cookies.

 

  1. Profiling and Segmentation

 

By processing the personal data of Winfluencer Member Customers/Guest Customers, Winfluencer performs profiling and segmentation for the purpose of preparing more suitable content, advertisements, promotions, and discounts based on the preferences and choices of the Member Customers/Guest Customers who have given consent to receive commercial electronic communications.

 

For Member Customers/Guest Customers who have not given consent for commercial electronic communications, profiling and segmentation are also carried out for the following purposes:

 

Product improvement (determining the best-selling or least-sold product categories)

Analyzing shopping preferences and creating models to organize campaigns and upload them to the system for customer groups with the potential to purchase specific products

Taking actions to increase sales potential

Within the scope of profiling and segmentation activities, the personal data of Member Customers/Guest Customers, such as name, surname, mobile phone, email, or address information, are not directly used. Instead, the data is processed using Member Customer/Guest Customer IDs assigned to them. The use of Member Customer/Guest Customer IDs or, in other words, pseudonymous data ensures the protection of the personal data of the Customer/Member. Member Customer/Guest Customer IDs are only accessible to the relevant individuals or departments within Winfluencer. These IDs assigned to Member Customers/Guest Customers are encrypted and stored within the Winfluencer system, and access to this section is restricted to authorized personnel only.

 

  1. Rights of Data Subjects and How to Exercise These Rights

 

The rights that the Data Subject has regarding the personal data processed by Winfluencer, in accordance with Article 11 of the PDPL, are listed below:

 

To learn whether personal data is being processed,

To request information regarding the processing of personal data if it has been processed,

To learn the purpose of the processing of personal data and whether they are used in accordance with their purpose,

To know the third parties to whom personal data is transferred, domestically or abroad,

To request the correction of personal data if it is incomplete or inaccurate,

To request the deletion or destruction of personal data within the framework of the conditions stipulated in Article 7 of the PDPL,

To request the notification of the operations carried out as per subparagraphs (d) and (e) to third parties to whom personal data has been transferred,

To object to the occurrence of a result against the data subject by solely analyzing the processed data through automated systems,

To demand the compensation of damages in case the data subject incurs damages due to the unlawful processing of personal data.

To exercise your rights regarding your personal data, you can access your account and perform necessary changes, updates, and/or deletions through the “My Account” section on the Winfluencer website, mobile application, and mobile site. Additionally, you can make your application and exercise your rights using the methods specified in the “Application Form” regulated in accordance with Article 13 of the PDPL, available on the website or mobile application of the electronic commerce platforms operated by Winfluencer.