GDPR & Data Protection Policy
GDPR & DATA PROTECTION POLICY
At Hiber Bilisim, we respect the privacy and security of personal data belonging to our customers, visitors, users and business partners.
This GDPR & Data Protection Policy describes our approach to the processing of personal data under the European Union General Data Protection Regulation (GDPR / Regulation (EU) 2016/679).
Hiber Bilisim is a business based in Türkiye. The GDPR may apply to certain activities where its territorial scope requirements are met, including, where applicable, offering goods or services to individuals located in the European Union or European Economic Area or monitoring the behavior of individuals where such behavior falls within the scope of the GDPR.
Our personal data processing activities in Türkiye are also subject, where applicable, to Türkiye's Personal Data Protection Law No. 6698 (KVKK) and other applicable legislation.
1. SCOPE
Where the GDPR applies to the relevant processing activity, this Policy may apply to personal data relating to:
- Website visitors,
- Customers,
- Members and account holders,
- Individuals placing orders,
- Prospective customers,
- Individuals contacting us through communication forms,
- Business partners and supplier representatives.
2. PERSONAL DATA WE MAY PROCESS
Depending on the services provided and our relationship with you, categories of personal data we may process include:
- First and last name,
- Email address,
- Telephone number,
- Billing and delivery information,
- Address information,
- Customer and account information,
- Order and transaction information,
- Return and support records,
- Communications,
- IP address,
- Browser and device information,
- Security and system logs,
- Cookie and preference information,
- Marketing preferences where applicable and permitted.
We aim to process only personal data that is appropriate and necessary for the relevant purpose.
3. PURPOSES OF PROCESSING
Personal data may be processed for purposes including:
- Creating and managing user accounts,
- Receiving and processing orders,
- Delivering products,
- Processing payments,
- Billing and accounting,
- Managing returns, replacements and warranty processes,
- Providing customer service and technical support,
- Responding to user requests,
- Maintaining website and system security,
- Preventing fraud and misuse,
- Complying with legal obligations,
- Establishing, exercising or defending legal claims,
- Improving website performance and user experience,
- Conducting marketing and communications where the necessary permissions or other lawful basis exists.
4. LAWFUL BASES FOR PROCESSING
Where the GDPR applies, personal data may be processed under one or more lawful bases provided by Article 6 of the GDPR, depending on the nature and purpose of the processing.
Performance of a Contract:
Processing may be necessary to enter into or perform a contract, including receiving, preparing and delivering an order.
Legal Obligation:
Processing may be necessary to comply with tax, accounting, consumer protection or other legal obligations.
Legitimate Interests:
Processing may be necessary for legitimate interests pursued by Hiber Bilisim or a third party where those interests are not overridden by the fundamental rights and freedoms of the individual. System security and fraud prevention may be examples.
Consent:
Certain processing activities, particularly certain marketing activities and non-essential cookies where required by applicable law, may be based on the individual's consent.
Vital Interests or Public Interest:
Other lawful bases provided by the GDPR may apply in exceptional circumstances where relevant to the particular processing activity.
5. DATA MINIMIZATION
We aim to ensure that personal data is:
- Processed for specified and legitimate purposes,
- Relevant to those purposes,
- Limited to what is necessary,
- Kept accurate and updated where necessary.
We aim to avoid collecting personal data that is not reasonably necessary for the relevant service or legal obligation.
6. SHARING PERSONAL DATA
Where necessary to provide services or comply with legal obligations, personal data may be shared with parties including:
- Shipping and logistics providers,
- Payment service providers and banks,
- Hosting and infrastructure providers,
- Software and technical service providers,
- Accounting and financial service providers,
- Communications providers,
- Legal and professional advisers,
- Competent public authorities.
We aim to limit personal data shared with service providers to what is necessary for the relevant purpose.
Where service providers process personal data on behalf of Hiber Bilisim and the GDPR applies, appropriate data protection obligations are established where required.
7. INTERNATIONAL DATA TRANSFERS
As Hiber Bilisim is based in Türkiye, the transfer of personal data relating to an individual in the European Union or European Economic Area to Türkiye or another country may constitute an international transfer under the GDPR.
Where GDPR rules on international transfers apply, appropriate transfer mechanisms and safeguards under Chapter V of the GDPR will be considered.
Depending on the circumstances, these may include adequacy decisions, Standard Contractual Clauses (SCCs) adopted by the European Commission, or another transfer mechanism permitted under the GDPR.
8. DATA RETENTION
We aim not to retain personal data for longer than reasonably necessary for the purposes for which it was collected.
Retention periods may take into account:
- The purpose of processing,
- Contractual relationships,
- Tax and accounting requirements,
- Consumer protection requirements,
- Applicable limitation periods,
- Potential legal disputes,
- Security requirements.
When personal data is no longer required, it may be deleted, destroyed or anonymized in accordance with applicable law and technical requirements.
9. DATA SECURITY
We aim to implement technical and organizational security measures appropriate to the risk to protect personal data against unauthorized access, loss, alteration, disclosure or misuse.
Where appropriate, these measures may include:
- Encrypted communications using HTTPS/TLS,
- Access controls,
- Authentication,
- Authorization,
- Firewalls,
- System and security updates,
- Logging,
- Backups,
- Network and server security,
- Security incident monitoring.
No internet or electronic transmission method can provide absolute security. Security measures are therefore reviewed in light of identified risks and technological developments.
10. YOUR RIGHTS UNDER THE GDPR
Where the GDPR applies to our processing of your personal data and the relevant requirements are met, you may have rights including:
- The right to access your personal data,
- The right to request correction of inaccurate or incomplete personal data,
- The right to request erasure in certain circumstances ("Right to Erasure" or "Right to be Forgotten"),
- The right to request restriction of processing,
- The right to object to certain processing,
- The right to data portability where applicable,
- The right to withdraw consent at any time where processing is based on consent,
- Rights relating to certain decisions based solely on automated processing where the requirements of the GDPR are met,
- The right to lodge a complaint with a competent data protection supervisory authority.
These rights are not absolute and may be subject to conditions and exceptions under the GDPR.
11. WITHDRAWAL OF CONSENT
Where processing is based on consent, you may withdraw your consent at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
Following withdrawal, the relevant consent-based processing will cease unless another lawful basis permits or requires continued processing.
12. COOKIES AND SIMILAR TECHNOLOGIES
Our website may use strictly necessary, functional, analytics, advertising and marketing cookies or similar technologies.
Where applicable law requires consent, non-essential technologies requiring consent will not be activated before the required user choice has been obtained.
Further information about cookies and managing your preferences is available in the Hiber Bilisim Cookie Policy.
13. MARKETING COMMUNICATIONS
Electronic marketing communications are sent in accordance with applicable legal requirements and, where required, the appropriate consent or another applicable lawful basis.
Users may change their marketing preferences through the unsubscribe or preference-management mechanisms provided.
14. CHILDREN'S PERSONAL DATA
Hiber Bilisim's e-commerce services are not specifically designed or directed toward children.
Where the processing of children's personal data occurs, additional requirements and safeguards required by applicable law will be considered.
15. AUTOMATED DECISION-MAKING AND PROFILING
If Hiber Bilisim conducts decision-making based solely on automated processing that produces legal effects concerning an individual or similarly significantly affects them, applicable GDPR requirements and data subject rights will be taken into account.
Where automated systems are used for analytics, product recommendations or marketing, appropriate transparency and preference mechanisms will be considered according to the nature of the processing.
16. PERSONAL DATA BREACHES
If a security incident affecting personal data occurs, the incident will be assessed and, where the GDPR applies, appropriate risk assessment, documentation and notification procedures will be followed.
Where required by the GDPR, a competent supervisory authority will be notified and, in certain circumstances involving a high risk to individuals, affected data subjects will also be informed.
17. EXERCISING YOUR RIGHTS
You may contact Hiber Bilisim through the contact channels provided on our website to exercise rights available to you under the GDPR.
We may request reasonable additional information where necessary to verify the identity of the person making the request and protect personal data from unauthorized disclosure.
Requests will be evaluated within the time limits required by applicable law where the GDPR applies.
18. RIGHT TO LODGE A COMPLAINT
Where the GDPR applies, individuals may have the right to lodge a complaint with a competent data protection supervisory authority if they believe that the processing of their personal data infringes the GDPR.
19. GDPR AND TURKISH DATA PROTECTION LAW
As Hiber Bilisim is based in Türkiye, personal data processing activities may also be subject to Türkiye's Personal Data Protection Law No. 6698 (KVKK) and other applicable Turkish legislation.
Where a particular processing activity falls within the scope of the GDPR, the applicable GDPR requirements are additionally taken into account.
This Policy should be read together with the Hiber Bilisim Privacy Policy, Cookie Policy, Information Security Policy and applicable KVKK Privacy Notice.
20. CHANGES TO THIS POLICY
This GDPR & Data Protection Policy may be updated to reflect changes in legislation, technologies, services or Hiber Bilisim's personal data processing activities.
The current version becomes effective when published on our website.
21. CONTACT
If you have questions about this GDPR & Data Protection Policy, your personal data or your rights under the GDPR, you may contact Hiber Bilisim through the contact channels provided on our website.
Hiber Bilisim
Last Updated: September 7, 2026