Personal Data Processing Policy of SIPWALL Gayrimenkul Ltd. Şti.
1. General Provisions
1.1. This Policy sets out the main principles, purposes, conditions and methods of processing personal data, the categories of data subjects and of personal data processed by SIPWALL GAYRİMENKUL DANIŞMANLIK TEKSTİL TURİZM TİCARET İTHALAT VE İHRACAT LİMİTED ŞİRKETİ (hereinafter the “Controller”), the rights and obligations of the Controller when processing personal data, and the rights of data subjects.
Contact details of the Controller:
SIPWALL GAYRİMENKUL DANIŞMANLIK TEKSTİL TURİZM TİCARET İTHALAT VE İHRACAT LİMİTED ŞİRKETİ
Address: Oba Mah. 225 Sk. Summer Park Sitesi B Blok No: 8B İç Kapı No: 20, Alanya / Antalya, Türkiye
MERSİS No.: 0770125112200001
Trade Registry: Alanya Trade Registry, Registration No. 30951
Tax office / Tax No. (VKN): Alanya / 7701251122
E-mail: mail@sipwall.estate
Phone: +90 551 507 90 67
1.2. This Policy has been prepared in accordance with the following legislation:
- Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”);
- the Turkish Regulation on the Erasure, Destruction or Anonymisation of Personal Data;
- the Turkish Communiqué on the Procedures and Principles for Fulfilling the Obligation to Inform;
- decisions of the Turkish Personal Data Protection Board and other applicable Turkish legislation.
For visitors from the European Union / European Economic Area, personal data is also processed in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) where applicable.
1.3. Personal data means any information relating to an identified or identifiable natural person (the data subject).
Processing of personal data means any operation performed on personal data, wholly or partly by automated means or by non-automated means which form part of a filing system, including collection, recording, storage, retention, alteration, reorganisation, disclosure, transfer, takeover, making available, classification or prevention of use.
1.4. The Controller processes the following personal data of website users and clients:
- full name, e-mail, telephone, IP address.
2. Main Principles, Purposes and Cases of Personal Data Processing
2.1. The Controller processes personal data taking into account the need to protect the fundamental rights and freedoms of data subjects, including the right to privacy, in accordance with the following principles of Article 4 KVKK:
- lawfulness and fairness;
- accuracy and, where necessary, keeping data up to date;
- processing for specified, explicit and legitimate purposes; processing incompatible with the purposes of collection is not permitted;
- relevance, limitation and proportionality to the purposes of processing; excessive processing is not permitted;
- databases containing personal data processed for mutually incompatible purposes are not combined;
- retention only for the period laid down by law or necessary for the purposes of processing;
- the Controller’s employees have access to personal data only as required by their duties;
- personal data is erased, destroyed or anonymised once the purposes of processing cease to exist.
2.2. The purposes of processing personal data are:
- preparing individual offers;
- informing clients about goods, services and company news;
- obtaining feedback.
2.3. The Controller processes personal data under Article 5 KVKK (and, where applicable, Article 6 GDPR) where:
- the data subject has given explicit consent;
- processing is directly related to the conclusion or performance of a contract;
- processing is necessary for compliance with a legal obligation of the Controller;
- processing is necessary to protect the life or physical integrity of a person who is unable to give consent;
- processing is necessary for the establishment, exercise or protection of a right;
- processing is necessary for the legitimate interests of the Controller, provided that the fundamental rights and freedoms of the data subject are not harmed.
3. Measures to Ensure the Security of Personal Data
3.1. In accordance with Article 12 KVKK, the Controller takes all necessary technical and organisational measures to ensure an appropriate level of security in order to prevent unlawful processing of and unlawful access to personal data and to ensure its safekeeping.
3.2. The security of personal data is ensured in particular by:
- appointing a person responsible for organising the processing of personal data;
- adopting internal regulations on the processing and protection of personal data;
- applying technical and organisational measures to the security of personal data processed in information systems;
- detecting instances of unauthorised access and taking the necessary measures, including notifying data breaches to the data subject and the Turkish Personal Data Protection Board as soon as possible under Article 12 KVKK;
- storing personal data and data carriers processed for different purposes and containing different categories of data separately;
- establishing rules of access to personal data in information systems and logging all actions performed with personal data;
- monitoring the security measures taken and the level of protection of the information systems;
- other measures provided for by Turkish legislation.
4. Obligations of the Controller’s Employees
4.1. The Controller’s employees authorised to process personal data are obliged to:
- know and strictly comply with the requirements of this Policy;
- process personal data only in the performance of their duties;
- not disclose personal data obtained in the performance of their duties;
- prevent actions of third parties that may lead to the disclosure (destruction, distortion) of personal data;
- identify instances of disclosure (destruction, distortion) of personal data and inform their direct supervisor thereof;
- keep information containing personal data confidential in accordance with the Controller’s internal regulations; this obligation continues after the end of their duties.
4.2. The Controller’s employees authorised to process personal data are prohibited from unauthorised copying of personal data onto paper or onto any electronic media not intended for storing personal data.
4.3. Each new employee who directly processes personal data shall be familiarised with Turkish personal data protection legislation, this Policy and other internal regulations, and undertakes to comply with them.
4.4. Persons violating personal data protection legislation bear administrative, civil or criminal liability under applicable Turkish law, including the KVKK and the Turkish Penal Code No. 5237.
5. Rights of the Data Subject
5.1. Under Article 11 KVKK, every data subject has the right, by applying to the Controller:
- to learn whether their personal data is being processed;
- to request information about the processing if their personal data has been processed;
- to learn the purpose of the processing and whether the data is used in accordance with that purpose;
- to know the third parties in Türkiye or abroad to whom their personal data is transferred;
- to request rectification of personal data that is incomplete or inaccurate;
- to request erasure or destruction of their personal data under the conditions set out in Article 7 of the KVKK;
- to request that rectification, erasure or destruction be notified to the third parties to whom the data has been transferred;
- to object to a result to their detriment arising from the analysis of the processed data exclusively by automated systems;
- to claim compensation for damage suffered as a result of unlawful processing of their personal data.
Requests concerning these rights may be sent to mail@sipwall.estate or in writing to the controller’s address above. Requests are handled free of charge as soon as possible and within thirty days at the latest (Article 13 KVKK). If the application is rejected, the answer is found insufficient or no answer is given in time, the data subject may lodge a complaint with the Turkish Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) under Article 14 KVKK. The data subject may withdraw consent at any time.
Where the GDPR applies, data subjects in the EU/EEA also have the right of access to their personal data, the right to rectification, the right to erasure, the right to restriction of processing, the right to data portability, the right to object, the right to withdraw consent at any time (without affecting the lawfulness of processing based on consent before its withdrawal) and the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work or place of the alleged infringement.
6. Erasure, Destruction and Anonymisation of Personal Data
6.1. If unlawful processing of personal data is identified upon a request of the data subject, the Controller stops processing and restricts access to the data concerned from the moment of such request.
6.2. If inaccurate or incomplete personal data is identified upon a request of the data subject, the Controller restricts the use of such data until it is rectified, provided that this does not violate the rights and legitimate interests of the data subject or third parties.
6.3. If the inaccuracy is confirmed on the basis of information or documents provided by the data subject, the Controller rectifies the data without delay and within thirty days at the latest and lifts the restriction.
6.4. If unlawful processing is identified, the Controller ceases the unlawful processing without delay.
6.5. If it is impossible to ensure the lawfulness of processing, the Controller erases, destroys or anonymises such data without delay and within thirty days at the latest.
6.6. The Controller notifies the data subject and, upon request, the third parties to whom the data was transferred of the elimination of the violations or of the erasure of the data.
6.7. Upon achievement of the purpose of processing, the Controller ceases processing and erases, destroys or anonymises the personal data within periodic destruction intervals not exceeding six months, in accordance with the Turkish Regulation on the Erasure, Destruction or Anonymisation of Personal Data.
6.8. If the data subject withdraws consent and there is no other legal ground for processing, the Controller ceases processing and erases, destroys or anonymises the personal data within thirty days from the date of receipt of the withdrawal.
6.9. Where legislation requires a longer retention period, the data is kept with restricted access for that period and destroyed at its end.
7. Final Provisions
7.1. The current electronic version of this Policy is publicly available on the Controller’s website at /.
7.2. The Controller may transfer personal data of data subjects to third parties solely for the purpose of performing the contract with the user and ensuring the functioning of the website. Such third parties include:
- hosting providers;
- online consultation and user request handling services;
- CRM systems;
- messaging services (WhatsApp, Telegram);
- email and mailing services;
- payment systems;
- organisations providing technical support and maintenance of the website.
The transfer is carried out in accordance with Articles 8 and 9 KVKK (and, where applicable, Chapter V GDPR) on the basis of data processing agreements or other contracts containing the third party’s obligation to comply with personal data protection legislation. The Controller ensures that third parties process personal data only to the extent necessary to achieve the stated purposes and ensure its confidentiality and security.
09.10.2026