1. DATA CONTROLLER IDENTITY AND CONTACT INFORMATION
A. Data Controller Information
Beta Alg Biotechnology Limited Company, MERSIS No: 0167089381300001 (“Company” or “Sepiidastore”), acts as the “Data Controller” pursuant to the Personal Data Protection Law No. 6698 (“Law”). Our Company is the legal entity that determines the purposes and means of processing personal data and is responsible for the establishment and management of the data recording system. As the data controller, our primary priority is to protect the fundamental rights and freedoms of data subjects and to ensure the highest level of security for personal data. Accordingly, all data processing activities conducted within our company are carried out in accordance with the principles of legality and fairness, accuracy and up-to-date nature, and processing for specific, explicit, and legitimate purposes.
Our company’s corporate identity and legal status are registered in accordance with applicable legislation, and all our operational processes are strictly bound by this legal framework. As the data controller, we take all necessary technical and administrative measures to ensure the security of the data we process and regularly audit these processes. The confidentiality of the data entrusted to us by our users and customers is an integral part of our corporate culture and business ethics. This document has been prepared to provide the most comprehensive and up-to-date information regarding our data processing procedures, in accordance with our principles of transparency and accountability as the data controller.
B. Communication Channels
Data subjects may submit any questions, comments, or requests regarding the processing of their personal data through our company’s official communication channels. Our company has assigned a dedicated data protection team to effectively manage requests from data subjects and respond within legal timeframes. The email address [email protected], used in our communication processes, has been designated as the primary
digital channel for data subjects to exercise their rights. Requests submitted through this channel are carefully reviewed in accordance with our company’s data security protocols and forwarded to the relevant departments.
For physical correspondence, our company’s headquarters located at Kültür Mahallesi, Çakmaklar Caddesi, Teknokent Main Building, Block No. 2, Inner Door No. 47, 14300 Merkez – BOLU / TURKEY is used. Data subjects must adhere to the application procedures detailed at the end of this document when submitting requests via notary or registered mail. The accessibility and transparency of our communication channels reflect our company’s respect for data subjects and our commitment to legal compliance. Our company continuously updates its communication infrastructure by following technological developments and facilitates data subjects’ access to information.
2. INTRODUCTION AND THE PURPOSE OF THE INFORMATION OBLIGATION
A. Purpose and Scope of the Policy
This Privacy Policy and Information Notice has been prepared to establish the procedures and principles regarding the processing of personal data of users, customers, and other relevant individuals who visit the Sepiidastore website. The primary purpose of this policy is to define the boundaries of our data processing activities and to inform data subjects about these processes in the most transparent manner possible. This document comprehensively addresses all categories of data collected through our website, the purposes for which this data is processed, and to whom it is disclosed. Our company aims not only to fulfill a legal obligation through this policy but also to establish a relationship of trust with our users.
Within the scope of this policy, all data collection points—from membership forms on our website to order screens, from cookie applications to customer support channels—have been analyzed. This document covers all digital assets within the Sepiidastore ecosystem and the data traffic conducted through these assets. Data subjects can review this document to learn which of their data is processed, why it is processed, how the security of their data is ensured, and how they can exercise their legal rights. The policy serves as the cornerstone of our company’s data protection strategy and is binding for all our employees and business partners.
B. Legal Basis (KVKK Art. 10)
The obligation to provide information regarding the processing of personal data is established as a legal requirement under Article 10 of the Law. Pursuant to this article, the data controller is obligated to provide the data subjects, at the time of collecting personal data, with information regarding the identity of the data controller, the purposes for which the data will be processed, to whom and for what purposes the processed data may be transferred, the method and legal basis of data collection, and the rights of the data subject. Our company fulfills this legal obligation through this text in full compliance with the provisions of the “Communication on the Procedures and Principles to Be Followed in Fulfilling the Duty to Inform.”
Our legal basis is not limited solely to Article 10 of the Law but is also directly related to the right to privacy of private life and the protection of personal data as stipulated in Article 20 of the Constitution. Our company bases its determination of the legal grounds for data processing on the criteria set forth in Articles 5 and 6 of the Law. Fulfilling the duty to inform is one of the prerequisites for the lawfulness of data processing activities. Therefore, as Sepiidastore, we act in accordance with these legal grounds in every service we offer and every dataset we collect.
3. METHODS OF COLLECTING PERSONAL DATA AND LEGAL BASES
A. Data Collection Methods (Automated and Semi-Automated Methods)
Your personal data is collected during transactions conducted through the Sepiidastore website, either entirely or partially through automated means, or through non-automated methods provided they form part of a data recording system. Automated methods include: website cookies, server log records, IP address detection systems, and browser data. These methods are based on the recording of technical data as a result of the system’s operation, without direct user intervention. Semi-automated methods, on the other hand, refer to processes requiring active user participation, such as filling out membership forms, entering order information, sending messages via contact forms, or subscribing to newsletters.
The digital tools used in the data collection process are configured in accordance with data security standards. For example, card information entered on the payment page is transmitted directly to the relevant payment institution via encrypted channels without being stored on our company’s servers. The data collection process typically begins the moment the user first interacts with the website and continues until the transaction is completed. When determining data collection methods, our company adheres to the “data minimization” principle and collects only the minimum data necessary to fulfill the service provided. All these processes are conducted with the data subject’s knowledge and within the framework of legal grounds.
B. Data Processing Activities Table
The table below summarizes the core data processing activities carried out within our company, the categories of data processed, the purposes of processing, and the legal grounds we rely on in accordance with Article 5 of the Law:
| Data Category | Processing Activity and Purpose | Legal Basis (KVKK Art. 5) |
| Identity, Contact, Customer Transactions | Creating an account, receiving orders, delivering products, and managing post-sales support processes. | Art. 5/2-c: Directly related to the conclusion or performance of a contract. |
| Financial Data | Collection of payments, issuance of invoices, and submission of reports required by tax legislation. | Art. 5/2-d: To enable the data controller to fulfill its legal obligations. |
| Transaction Security (IP, Log) | Ensuring website security, preventing fraud, and analyzing system performance. | Art. 5/2-f: The necessity of processing data for the data controller’s legitimate interests. |
| Marketing Data | Sending campaign, discount, and promotional content; providing personalized offers based on user preferences. | Art. 5(1): The data subject’s explicit consent. |
| Legal Proceedings Data | Use as evidence in potential disputes and provision of information to competent authorities. | Art. 5/2-e: Data processing is necessary for the establishment, exercise, or defense of a legal claim. |
4. PURPOSES OF PROCESSING PERSONAL DATA
A. Order, Delivery, and Customer Relationship Management
Our company processes your personal data primarily to ensure that orders placed through Sepiidastore are fulfilled in full. In this context, your first name, last name, address, and contact information are essential for delivering products to the correct address, tracking shipping processes, and contacting you when necessary. This process, which begins with the establishment of a contractual relationship, continues until the product reaches you and your post-sale warranty or return rights are exercised. To ensure customer satisfaction, these data are critical for keeping you informed about the status of your order and finding solutions in the event of potential delays.
In our customer relationship management processes, we analyze your past orders and requests to provide you with faster and higher-quality service. The information you share during support requests or complaints is recorded to identify the root cause of the issue and develop permanent solutions. This processing activity is mandatory for the performance of the contract in accordance with Article 5/2-c of the Law. Our company shares the data processed for this purpose only with the relevant operational units, and there is
. Your data is considered a strategic tool to enhance customer loyalty and elevate our service quality above industry standards.
B. Conducting Financial and Accounting Processes
As a legal requirement of our commercial activities, financial records of every sales transaction must be maintained and documented. Accordingly, your identification and address information, as well as your payment details, required for invoicing, are processed in our accounting systems. In accordance with the Turkish Commercial Code and the Tax Procedure Code, the retention of issued invoices and related financial documents for specific periods is a legal requirement. During this process, your data is used solely for the purpose of fulfilling financial obligations and managing audit processes. (Art. 5/2-c)
The management of financial processes also includes ensuring payment security. Our company implements the necessary controls to minimize unauthorized payment transactions and the risk of financial fraud. Data sharing with banks and payment institutions is limited solely to the completion of the transaction and the verification of its security. Accounting records are meticulously maintained in accordance with our company’s principle of transparent management and kept ready for legal audits. Our data processing activities in this area serve the purpose of securing the state’s tax revenue and maintaining the order of commercial life.
5. TRANSFER OF PERSONAL DATA
A. Recipient Groups to Which Data Is Transferred
Your personal data may be shared with specific recipient groups in order to achieve the purposes outlined above. These recipient groups include: shipping and logistics companies responsible for product delivery; banks and electronic money institutions handling payment transactions; and accounting and financial advisory firms that maintain our company’s financial records. Additionally, cloud service providers and hosting companies that provide the technical infrastructure for our website and ensure the secure storage of data are also among the parties to whom data is transferred
. Our company enters into confidentiality agreements containing data security protocols with each party to whom data is transferred.
The parties to whom data is transferred may process your data only to the extent and for the duration necessary to fulfill the service assigned to them. For example, a shipping company may only access the name and address information necessary to make a delivery; it may not use this data for its own marketing activities. Our company regularly audits data transfer processes and monitors our business partners’ compliance with the Law. Data sharing with public institutions and organizations is conducted only when there is a legal obligation or an official request, and strictly within the boundaries set by the law.
B. Purposes and Legal Bases of Data Transfers
The primary purpose of our data transfer activities is to ensure that the service provided to the data subject is completed seamlessly and securely. Transfers to shipping companies are a mandatory component for the performance of the contract (Art. 5/2-c), as the delivery of the product cannot be carried out without this transfer. Transfers to payment institutions similarly serve the purpose of fulfilling contractual obligations and ensuring financial security. Transfers to cloud service providers, on the other hand, are based on our legitimate interest (Art. 5/2-f) in storing data on modern and secure infrastructures and ensuring its accessibility.
Our legal bases are assessed separately for each transfer scenario. If a transfer activity does not fall under one of the exceptions listed in Article 5/2 of the Law, the data subject’s explicit consent is sought. Our company maintains the transferred data at a minimum level in accordance with the “need-to-know” principle. End-to-end encryption and secure data transfer protocols are used to protect the integrity and confidentiality of data during transfer processes. This ensures that your data remains under high protection standards even when it leaves our company.
6. DECLARATION REGARDING SPECIAL CATEGORIES OF PERSONAL DATA
A. Commitment Not to Process Health Data
As Beta Alg Biotechnology, we explicitly declare and commit that, within the scope of standard commercial activities conducted through the Sepiidastore website, we do not process special category personal data such as health data, biometric data, or genetic data belonging to our users. Although our company operates in the biotechnology sector, the data collected through our e-commerce platform is limited solely to sales and marketing processes. We do not request any health reports, medical history, or similar sensitive information from our users during the registration or ordering stages. This approach is a result of our data minimization and risk-based data protection strategy.
If our users voluntarily share any health information through customer support lines or contact forms, this data is immediately deleted from our systems and is not included in any record-keeping system. The processing of special category data requires much stricter protective measures and specific legal grounds under the Law. Our company will continue to adhere to a policy of avoiding sensitive data unless we offer a service that necessitates the processing of such data. This commitment is part of our respect for data subjects’ privacy and our sensitivity regarding legal compliance.
B. Protection Principles Under Article 6 of the KVKK
Article 6 of the Law establishes the conditions for the processing of special category personal data and stipulates that such data is limited in scope (numerus clausus). The data listed in this article include data related to race, ethnic origin, political opinions, philosophical beliefs, religion, denomination, attire, membership in associations, foundations, or trade unions, health, sexual life, criminal convictions, and security measures, as well as biometric and genetic data. Our company is aware that the processing of this data is only permitted with the explicit consent of the data subject or in the limited cases provided for by law.
Additional security measures established by the Board for the protection of special category data are maintained as part of our company’s general data security policy. Although
we do not currently process such data, should the processing of this data become necessary in the future as part of new services offered, full compliance with Article 6 of the Law will be ensured, and a separate “Consent for the Processing of Special Category Personal Data” will be obtained from the data subjects. Our data security infrastructure is designed to protect even the most sensitive data categories and is continuously enhanced in accordance with legal requirements.
7. DATA SECURITY AND RETENTION PERIODS
A. Technical and Administrative Measures
Our company takes all necessary technical and administrative measures in accordance with Article 12 of the Law to prevent the unlawful processing of personal data and to block unauthorized access to data. As part of technical measures, network and application security are ensured, data is stored in encrypted environments, and access permissions are restricted in accordance with the “separation of duties” principle. Penetration tests and vulnerability scans are conducted regularly on our systems, and up-to-date firewalls and antivirus software are used to protect against potential cyberattacks. Additionally, data traffic is continuously monitored using data loss prevention (DLP) systems.
In terms of administrative measures, all our employees receive regular training on the protection of personal data and information security. Internal policies and procedures have been updated in compliance with the Law, and confidentiality clauses have been added to employees’ employment contracts. Contracts with our data-processing business partners include clauses containing strict penalties regarding data security. A “Personal Data Security Breach Response Plan” has been established within our company, and the procedures for notifications to be made to the Board and relevant individuals in the event of a potential breach have been defined. This comprehensive approach ensures that your data remains secure at every stage.
B. Data Retention and Destruction Policy Criteria
Your personal data is retained for as long as necessary to fulfill the purpose of processing or for the statutory retention periods specified in applicable legislation. The determination of retention periods is based on:
the continuation of contractual obligations, statute of limitations periods, tax legislation requirements, and our company’s legitimate interests. For example, data related to a sales transaction must be retained for 10 years in accordance with the Turkish Commercial Code. Data for which the processing purpose has ended and the legal retention period has expired is deleted, destroyed, or anonymized during the first disposal period in accordance with our company’s “Personal Data Retention and Disposal Policy.”
Destruction processes involve permanently removing data from systems in a manner that cannot be reversed. In the anonymization process, data is rendered unlinkable to any specific individual and is subsequently excluded from the scope of the Law. Our company periodically reviews retention periods to prevent the retention of unnecessary data. Data subjects may request information regarding the retention periods of their data at any time. Our retention and destruction processes are documented in accordance with our principles of transparency and accountability and are subject to audits.
8. DATA SUBJECT’S RIGHTS (KVKK Art. 11)
A. Rights to Information and Access
Pursuant to Article 11 of the Law, every data subject has the right to inquire with our company whether personal data concerning them is being processed and, if so, to request information regarding such processing. This right ensures the transparent management of your data and maintains your control over it. Additionally, you have the right to learn the purpose of the processing of your personal data and whether it is being used in accordance with that purpose. Our company is obligated to respond to these requests as soon as possible and in clear, understandable language. The right to access information is one of the fundamental elements of data protection law, and our company provides the necessary infrastructure to facilitate the exercise of this right.
Under the right of access, you also have the right to know to whom your data has been transferred (whether within the country or abroad). This allows you to be informed about third parties with whom your data is shared and to track your data flow. By providing this access to data subjects, our company demonstrates its accountability. Your requests for information and access are processed after passing through our identity verification process
. The exercise of these rights reflects the data subject’s right to ownership and oversight of their own data.
B. Requests for Correction, Deletion, and Anonymization
You have the right to request the correction of your personal data if it has been processed inaccurately or incompletely. Data accuracy is critical both for the quality of our company’s services and for the protection of your rights. Additionally, even if your personal data has been processed in compliance with the Law and relevant regulations, you may request its deletion or destruction if the grounds justifying its processing no longer exist. Our company will review your request and remove your data from its systems unless there is a legal obligation to retain it.
Requests for deletion and correction are also communicated to third parties to whom your data has been transferred. Thus, updates to your data or decisions to delete it are applied simultaneously across the entire data ecosystem. A request for anonymization, on the other hand, means that the link between your data and your identity is completely severed. These rights provide the data subject with a broad protective shield under the “right to be forgotten.” Our company mobilizes its technical capabilities to fulfill these requests and respects the data subject’s will. The processes related to the exercise of your rights are managed through the application procedures outlined at the end of this text.
C. Objection and Limitation of Data Processing Activities
You have the right to object to a decision made solely through the automated analysis of processed data that results in a negative outcome for you. This right is particularly significant in automated decision-making processes such as profiling or scoring. Additionally, you have the right to request compensation for any damage incurred due to the unlawful processing of your personal data. Our company is fully aware of its legal responsibilities to prevent any violations of rights arising from data processing activities and to compensate for any resulting damages.
A request to restrict data processing ensures that your data is only
stored for a specific period but not subjected to any further processing. This right is typically exercised during transitional periods when the accuracy of the data is contested or a request for erasure is being evaluated. Our company carefully reviews data subjects’ objections and immediately takes the necessary corrective actions if any unlawful situation is identified. The right to object serves to protect the data subject’s digital autonomy in a democratic society.
9. PROCEDURES AND PRINCIPLES FOR SUBMITTING REQUESTS
A. Minimum Required Information for Applications
In accordance with the Notice on Procedures and Principles for Applications to the Data Controller, the following information must be included in applications submitted to our company:
- First name, last name, and signature if the application is in writing,
- Turkish Republic ID number for Turkish citizens; nationality, passport number, or ID number (if available) for foreign nationals,
- Residence or business address for service of notice,
- Email address, phone number, and fax number (if applicable),
- Subject of the request (The specific right being exercised and the content of the request must be clearly stated).
Applications that do not contain this information may not be accepted as valid applications in accordance with the Notice. Our company reserves the right to request additional information or documents (such as a copy of your ID) to verify that the application is yours. The accuracy and currency of the information provided in your application are your responsibility. Providing incorrect or incomplete information may result in delays in processing your request. Including any relevant information and documents related to your request in the application form will help expedite the process.
B. Application Methods and Contact Information
You may submit your applications using one of the following methods:
- Written Application: By sending a handwritten letter with a wet signature to “Kültür Mahallesi, Çakmaklar Caddesi, Teknokent Main Building, Block No. 2, Inner Door No. 47, 14300 Merkez – BOLU / TURKEY”
- in person or via a notary.
- Registered Electronic Mail (KEP): By using a secure electronic signature or mobile signature to our company’s KEP address [[email protected]].
- Email: By sending a message to [email protected] using the email address you previously provided to our company and which is registered in our system.
Writing “Request for Information Under the Law on the Protection of Personal Data” on the envelope or in the subject line of the email will ensure your request reaches the relevant department more quickly. Our company aims to provide convenience to data subjects by offering various application methods. The date your request is received will be considered the application date, depending on the method you choose.
C. Resolution of Requests (30-Day Legal Deadline)
Our company will process the requests you submit free of charge within the shortest possible time and no later than thirty days, depending on the nature of the request. However, if the process incurs additional costs, a fee in accordance with the tariff determined by the Board may be charged. If your request is accepted, the necessary actions will be taken by our company; if it is rejected, the reason will be communicated to you in writing or electronically. The 30-day period begins on the date your request is received by our company in accordance with the proper procedure.
If your request is rejected, you find the response insufficient, or no response is provided within the prescribed timeframe, you retain the right to file a complaint with the Personal Data Protection Board within thirty days from the date of notification of the response and, in any case, within sixty days from the date of your request. Our company exercises the utmost diligence in complying with legal deadlines and optimizes its processes to avoid causing any harm to data subjects. The outcome of your request will be communicated to you via the communication channel you selected.
10. POLICY CHANGES AND ENFORCEMENT
A. Update Procedure
Our company reserves the right to make changes to this Privacy Policy and Information Notice at any time in accordance with changes in legislation, Board decisions, or our company’s new data processing procedures
The updates can be tracked via the “Last Updated Date” at the beginning of the text. In the event of significant changes, users will be notified via our website or through registered communication channels. It is important for you to periodically review the current version of the Policy to stay informed about our processes regarding the protection of your data.
The update process is carefully managed by our company’s legal and data security departments. Each new version replaces the previous one and becomes binding for all data subjects as of the date of publication. Our company archives past versions and refers to these records when necessary to ensure transparency. Policy changes apply only to future actions and do not affect transactions that were lawfully completed in the past.
B. Effective Date
This policy document entered into effect on May 12, 2026, the date it was published on the Sepiidastore website. The text is deemed applicable to all individuals who visit the website or share data with our company as of the date of publication. With the entry into effect of this policy, previously published privacy texts of earlier dates have lost their validity. Our company maintains a permanent link in the website’s footer to ensure this text remains accessible at all times.
This current policy reflects our company’s current commitments regarding data protection and our level of legal compliance. Data subjects may exercise their rights under the Law within this framework for as long as this policy remains in effect. Our company will continue to operate its internal mechanisms to monitor and continuously improve the implementation of this policy.
Beta Alg Biotechnology Limited Company
