SASAHUB — Cookie Policy

v1.1

Document ID
LEG-003
Version
1.1
Effective date
Date of official publication
Controlling language
Turkish

Section 1. General Provisions

1.1. Purpose of the Policy

This Cookie Policy (the “Cookie Policy” or “Policy”) sets out the rules governing the use of cookies and similar technologies on the SASAHUB digital platform (the “Platform”), including user information, consent where required, preference management and the exercise of rights related to such technologies. To the extent that personal data is processed through cookies, SHAMUS E‑TİCARET LOJİSTİK VE GIDA TİCARET LİMİTED ŞİRKETİ acts as the Platform Operator and, where applicable, the data controller / Veri Sorumlusu under Turkish data protection law.

1.2. Objectives

This Policy is intended to:

1.3. Scope

This Policy applies to the official SASAHUB website, mobile applications and other digital services in which cookies, SDKs, local storage, device identifiers or comparable technologies are used.

1.4. Core Principles

The Operator applies the principles of lawfulness, transparency, purpose limitation, data minimisation, security, confidentiality, accountability, Privacy by Design and Privacy by Default. Optional technologies that require consent under applicable law are not activated before valid consent is obtained.

1.5. Applicable Law

Cookie use is governed by mandatory rules applicable in light of the User’s location, the nature of the service and the actual processing activity. For Türkiye, this includes applicable personal data protection legislation and official KVKK guidance and decisions. For Users in the EEA, applicable national rules implementing the ePrivacy framework and the GDPR in relation to subsequent personal data processing may apply. Where mandatory law provides a higher level of protection, that mandatory rule prevails.

1.6. International Nature of the Platform

SASAHUB provides international digital services. Cookie use may involve infrastructure or providers located in other countries. International transfers of personal data are carried out only where a legally valid transfer mechanism and the required safeguards are in place.

1.7. Relationship with Other Documents

This Policy applies together with:

1.8. Definitions

Unless otherwise stated in this Policy, terms have the meanings assigned in the Terms of Service and Privacy Policy. The term “Cookie” may also refer, where the context permits, to comparable technologies that store information on or access information from a User’s device.

1.9. Electronic Publication

The current Policy is published on the official SASAHUB website, mobile application or another official SASAHUB electronic resource. The Operator may also maintain Cookie Settings / Cookie Centre / Cookie Register functionality containing current technology-specific information.

1.10. Effective Date

This Policy becomes effective on the date of official publication following corporate approval and remains in force until replaced by a new version.

Section 2. Cookies and Similar Technologies

2.1. What Is a Cookie?

Cookies are small files or data items stored on, or read from, a User’s device by a website or related digital service. They may support functionality, security, preference storage, analytics or other disclosed purposes.

2.2. Similar Technologies

The Platform may use, for example:

2.3. Purposes

Cookies may be used for Platform operation, authentication, security, fraud prevention, preference storage, performance measurement, analytics and service improvement, only for disclosed purposes and in accordance with applicable law.

2.4. Identifiability

Cookies may contain or generate unique identifiers, IP addresses, session information, technical parameters or other data. Even where a cookie does not contain a User’s name, related information may constitute personal data where it can directly or indirectly identify a natural person or link activity to a particular User.

2.5. Cookies and Personal Data

Where cookie information constitutes personal data or is combined with personal data, the Privacy Policy also applies. Each legal basis is used only for the relevant processing activity and purpose.

2.6. Services in Which Technologies May Be Used

Technologies may be used on the website, mobile application, User account, administrative interfaces and other SASAHUB digital services. A technology should not be deployed in a service where it is not actually necessary or disclosed.

2.7. Automatic Operation

Strictly necessary technologies may operate automatically where they are objectively required to provide a service explicitly requested by the User and such use is permitted by law. Optional technologies requiring consent remain disabled by default until the User makes an active choice.

2.8. Restricting Use

Users may manage optional technologies through Platform, browser or device settings. Blocking strictly necessary technologies at browser or device level may make certain functions unavailable.

2.9. Related Documents

Information generated or obtained through cookies is considered together with the Privacy Policy, Information Security Policy, Data Governance Policy and Terms of Service.

2.10. Technical Changes

Technologies may change as the Platform develops. Material changes to purposes, categories, recipients, retention or consent mechanisms require updated information and, where required, renewed consent.

Section 3. Categories of Cookies and Similar Technologies

3.1. General Classification

A technology is classified according to its actual function and purpose, not merely its name. The same technical tool may require a different legal assessment depending on configuration and use.

3.2. Strictly Necessary Cookies

Strictly necessary cookies are objectively required to provide an explicitly requested function or core security. They may support sessions, authentication, load balancing, CSRF and abuse prevention, storage of mandatory cookie choices and comparable critical functions. They are used without separate consent only to the extent permitted by applicable law.

3.3. Functional Cookies

Functional cookies may store language, region, interface settings and other preferences. Where a specific functional technology is not objectively necessary for a function explicitly requested by the User and consent is required by law, it is activated only after consent.

3.4. Analytics Cookies

Analytics technologies may measure visits, feature use, interaction paths and service quality. Where consent is required, analytics cookies do not operate before opt-in and must not be misclassified as “necessary”.

3.5. Performance Cookies

Performance technologies may measure speed, errors, stability and technical efficiency. Where such processing is not strictly necessary for the requested service and consent is required by law, it is used only after consent.

3.6. Security Cookies

Security cookies may support authentication, fraud prevention, abuse detection and infrastructure protection. Merely labelling a technology “security” does not automatically exempt it from consent requirements; actual necessity is assessed.

3.7. Third-Party Cookies

Third-party cookies are placed or read by an external service provider. Before integration, the Operator assesses the purpose, provider role, data categories, retention, international transfer and consent requirements.

3.8. New Categories

Before a new category is deployed, its purpose and legal basis are assessed, the Cookie Register is updated and, where required, consent is obtained before activation.

3.9. Consent Rule

Where no lawful basis permits a cookie to be used without consent, the technology is not activated before the User provides freely given, specific, informed and unambiguous consent through an affirmative action.

3.10. Related Documents

Cookie categories are assessed together with the Privacy Policy, Information Security Policy and Data Governance Policy.

3.11. Ongoing Review

The Operator periodically reviews technologies actually in operation. A prior classification does not make a category permanently valid if a technology’s function or configuration changes.

Section 4. Purposes of Cookie Use

4.1. General Rule

Cookies are used only for predetermined, lawful and transparent purposes. Information must not be repurposed for an incompatible new purpose without an appropriate legal basis and additional information where required.

4.2. Platform Operation

Strictly necessary technologies may support page loading, sessions, authentication, protected areas, cart/form functions, network resilience and other core services.

4.3. User Preferences

Technologies may store language, regional, display and other preferences. The legal treatment depends on whether storage is objectively necessary for a function explicitly requested by the User.

4.4. Security

Cookies may be used to detect suspicious login attempts, protect against automated attacks, prevent fraud and abuse, and maintain security state.

4.5. Analytics and Improvement

Where an appropriate legal basis exists, technologies may be used to analyse service use, errors, stability, interface performance and functional development.

4.6. Statistics

Where possible, statistics are used in aggregated or anonymised form. Later anonymisation does not remove a prior requirement for consent where access to or storage on the device initially required consent.

4.7. Legal Requirements

Technologies may be used to record cookie preferences, support security, audit and meet other mandatory requirements where such processing is necessary and lawful.

4.8. Third-Party Technologies

External technologies are used only for disclosed purposes and within contractual and technical limits. A provider’s independent purposes are not automatically treated as SASAHUB purposes.

4.9. No Undisclosed Purpose Expansion

The Operator does not use cookies for hidden tracking or other purposes that have not been properly disclosed. Continued browsing does not constitute consent to optional cookies where affirmative consent is required.

4.10. Related Documents

Where personal data is processed, the Privacy Policy and Data Governance Policy apply; security matters are governed by the Information Security Policy.

4.11. Minimum Inventory Information

For every technology actually used, the Operator must determine at least its category, purpose, provider, duration, first- or third-party status and applicable legal basis.

Section 5. Third-Party Cookies and Technologies

5.1. General Provisions

SASAHUB may use external technologies that store information on or access information from a User’s device. Use of a third-party service does not remove the Operator’s own duties regarding transparency, consent and lawful processing.

5.2. Provider Categories

Providers may include hosting, CDN, cloud infrastructure, analytics, information security, payment infrastructure, authentication, communications, technical support and other technology providers required for Platform functions.

5.3. Purposes

Third-party technologies may be used for specifically disclosed Platform functions such as security, authentication, performance, analytics, payments and communications.

5.4. Provider Due Diligence

The Operator may assess contractual terms, security, processing location, retention, deletion mechanisms, subprocessors, international transfers and available consent-management tools before deployment.

5.5. Third-Party Notices

Where a provider acts as an independent controller, its own privacy notices may also apply. SASAHUB does not disclaim responsibility for its own provider selection, integration or data disclosure where applicable law assigns responsibility to SASAHUB.

5.6. International Processing

Transfers of personal data to foreign providers are carried out in accordance with the Privacy Policy and applicable international transfer rules.

5.7. Data Minimisation

Providers receive only the data and access objectively necessary for the relevant service.

5.8. Security

The Operator implements reasonable contractual, organisational and technical safeguards and monitors provider compliance within the scope of its role.

5.9. Consent

If a third-party technology requires consent, it is not activated before consent is obtained. Refusal should not block core services where the technology is not strictly necessary.

5.10. Provider Changes

The Cookie Register is updated before or at the time a new provider is deployed. If purposes or the scope of consent change, renewed consent is obtained where required.

5.11. Related Documents

The Privacy Policy, Payment Policy, Information Security Policy, Data Governance Policy and Terms of Service apply as relevant.

5.12. Public Information

Current information on a specific provider, cookie/SDK, purpose and retention must be available through the Cookie Register, Cookie Settings or another easily accessible interface.

Section 6. User Consent

6.1. General Provisions

Where applicable law requires prior consent, optional cookies and similar technologies are activated only after valid consent is obtained.

6.2. Requirements for Consent

Consent must be freely given, specific, informed, unambiguous and expressed through an affirmative action. Silence, continued browsing, pre-ticked controls or inactivity do not constitute valid opt-in consent where affirmative consent is required.

6.3. Categories Requiring Consent

Consent is requested for optional technologies where no other lawful basis permits use without consent. Labels such as “analytics”, “performance” or “functional” do not by themselves remove a consent requirement.

6.4. First Layer of the Cookie Banner

Where a banner is used, Users are given clear choices. “Accept All”, “Reject Optional” and “Manage Preferences” options should be readily visible and should not be designed to unjustifiably steer the User toward consent.

6.5. Preference Management and Withdrawal

Users may change or withdraw consent at any time through permanently accessible Cookie Settings or an equivalent tool. Withdrawal should not be more difficult than giving consent.

6.6. Refusal and Access to the Service

Refusal of optional cookies should not, by itself, deny access to core Platform functions where those cookies are not objectively necessary for the requested service. Cookie walls are used only where and to the extent permitted by applicable law.

6.7. Changes to Preferences

A new preference applies to future processing. Where technically feasible, previously placed optional cookies are deleted, disabled or no longer read after consent is withdrawn.

6.8. Consent Records

The Operator may retain limited evidence of the User’s choice, such as date, banner/Policy version, selected categories, consent identifier and withdrawal/change events, only as necessary for compliance and audit purposes.

6.9. Mobile Applications

In mobile applications, preferences may be managed through the app interface, operating-system permissions, privacy settings, SDK consent-management tools or other lawful mechanisms.

6.10. Separation of Information and Consent

Providing privacy information and obtaining consent are separate legal actions. The Operator does not use a general statement such as “I accept the Cookie Policy” as a substitute for separate consent to optional technologies, and does not bundle cookie consent with acceptance of the Terms of Service where separate choice is required.

6.11. Renewed Consent

New consent is requested where purposes, categories, recipients, technology or the scope of processing changes materially, or where required by law. Unnecessarily frequent requests that may create consent fatigue are avoided.

Section 7. Cookie and Preference Management

7.1. Right to Choose

Users may select permitted optional technology categories and change their choices at any time where applicable law provides such a choice.

7.2. Management Tools

Preferences may be managed through Cookie Settings, the banner, account settings, app settings, browser settings or mobile-device settings.

7.3. Browser Controls

Browsers may allow Users to view, delete or block cookies. Browser controls operate independently from the Platform and may also affect required functionality.

7.4. Mobile Device Controls

Mobile operating systems may provide controls for identifiers, tracking, local storage and SDK access. SASAHUB respects those controls to the extent technically feasible and legally required.

7.5. Changing Preferences

Once a new choice is saved, it is applied to future use and, where technically possible, further use of withdrawn optional technologies is stopped.

7.6. Strictly Necessary Technologies

A technology that is objectively necessary and lawfully used without consent may not be switchable off through the Platform interface. Users may block it at browser/device level, which may prevent the related service from functioning.

7.7. Third-Party Controls

Users may also use provider-level opt-out or privacy controls where available. Such controls do not replace any consent mechanism SASAHUB is required to provide.

7.8. Effect of Changes

A preference change operates prospectively and does not render prior processing unlawful where that processing was lawful when performed.

7.9. Support

Questions about cookies may be sent to privacy@sasahub.com.tr or support@sasahub.com.tr.

7.10. Related Provisions

Consent is governed by Section 6; processing of personal data is governed by the Privacy Policy.

7.11. Accessibility of Controls

The Operator aims to provide simple and continuous access to Cookie Settings without requiring Users to locate hidden or unnecessarily complex controls.

Section 8. Consequences of Disabling Cookies

8.1. General Provisions

Users may refuse optional cookies. Such refusal is not treated as a breach of the Terms of Service.

8.2. Possible Functional Impact

Blocking cookies may result in repeated authentication, loss of preferences, limited functions or reduced personalisation depending on the category involved.

8.3. Strictly Necessary Cookies

Blocking necessary session, security or anti-fraud technologies at device level may prevent authentication, protected operations or proper service operation.

8.4. Optional Categories

Refusal of analytics, performance and other optional technologies should generally not prevent core use of the Platform where the technology is not required for a specifically requested function.

8.5. Third-Party Services

Disabling an external technology may make a related optional function unavailable. If a technology is necessary for a specific service, the User should be informed before using that service.

8.6. User Choice and Operator Responsibility

Users manage their own preferences, but the Operator does not transfer to the User responsibility for unlawful cookie configuration or failure to provide a consent mechanism required by law.

8.7. Re-enabling Technologies

Re-enabling a previously disabled category may require page reload, re-authentication or re-saving preferences.

8.8. Limitation of Responsibility

Where a User technically blocks objectively necessary technologies, the Operator does not guarantee full functionality except where mandatory law provides otherwise.

8.9. Related Documents

The Terms of Service, Privacy Policy and Information Security Policy apply.

8.10. Final Rule of this Section

Consequences of refusal must reflect genuine technical dependency and must not be used as an artificial means of pressuring the User into consenting to optional cookies.

Section 9. Cookie Retention Periods

9.1. General Provisions

Cookies are not used or retained longer than necessary for the disclosed purpose, taking into account data minimisation and applicable legal requirements.

9.2. Session Cookies

Session cookies generally expire when the session or browser is closed, subject to short periods objectively required for a specific technical function.

9.3. Persistent Cookies

Persistent cookies may remain on the device for a predetermined period. The duration must be proportionate to the purpose and stated in the Cookie Register.

9.4. Third-Party Cookies

Retention of external technologies may depend on provider configuration and contractual settings. The Operator seeks to minimise retention and to reflect the actual period in the public register.

9.5. Changes to Retention

A material extension of a retention period requires reassessment of the legal basis and, where required, updated information or renewed consent.

9.6. Early Deletion

Users may delete cookies through browser/device settings or through the Platform interface where such functionality is available.

9.7. Minimisation

Optional cookies are not retained for indefinite or disproportionately long periods without an objective justification.

9.8. End of Use

When the relevant period expires, a cookie is deleted, invalidated or ceases to be used. After consent is withdrawn, further processing based on that consent stops unless another lawful basis applies.

9.9. Related Documents

Retention of personal data generated or obtained through cookies is also governed by the Privacy Policy.

9.10. Public Register

For every technology actually used, the Cookie Register must state the retention period or a clear criterion for determining it.

Section 10. International Transfers Related to Cookies

10.1. General Provisions

Cookie use may involve processing through infrastructure located in different countries. Where the information constitutes personal data, international transfer is carried out in accordance with the Privacy Policy and applicable law.

10.2. International Infrastructure

Cloud services, CDNs, data centres, security, analytics, monitoring and other technology solutions may be used after appropriate legal and technical assessment.

10.3. Transfers to Providers

Only information necessary for the specific service is transferred, taking into account whether the provider acts as a processor, independent controller or joint controller.

10.4. International Transfers of Personal Data

For personal data subject to the KVKK, transfers are based on a mechanism permitted under the current Article 9 of the KVKK, which may include an applicable adequacy decision, appropriate safeguards such as standard contractual mechanisms, or statutory exceptional/occasional transfer circumstances. Mandatory transfer mechanisms of other applicable jurisdictions are applied where relevant.

10.5. Safeguards

The Operator assesses contractual, organisational and technical safeguards, data categories, destination countries, recipients, onward transfers and access risks.

10.6. International Providers

The international status of a provider is not by itself a legal basis for a transfer. The actual data flow and valid transfer mechanism must be separately identified.

10.7. Infrastructure Changes

A change in storage country or recipient is assessed in advance. The Cookie Register and Privacy Policy are updated where the change affects information provided to Users.

10.8. EEA and Other Jurisdictions

Where additional mandatory rules apply to terminal-device access, consent or transfer for a specific User, those requirements are applied to the relevant processing activity.

10.9. Related Documents

Detailed international transfer rules are set out in the Privacy Policy; security matters are governed by the Information Security Policy and Data Governance Policy.

10.10. Special Procedures Prevail

This Section does not replace standard contracts, regulator notifications, transfer impact assessments or other mandatory transfer procedures.

Section 11. Changes to the Cookie Policy

11.1. General Provisions

The Policy is reviewed when legislation, the Platform, providers, technologies or processing purposes change.

11.2. Grounds for Update

Updates may result from changes to legal requirements, cookie categories, SDKs, providers, international data flows, security functions, the consent interface or internal processes.

11.3. Publication of a New Version

A new version is published on the official website or application. Material changes may also be communicated through the Platform interface or other official channels.

11.4. Effective Date of Changes

Changes take effect on the stated date. If a new processing activity requires new consent, the relevant technology is not activated until that consent is obtained.

11.5. New Technologies

A new technology is not activated until it has been classified, added to the Cookie Register and supported by the required notice/consent mechanism.

11.6. User Awareness

Users may access the current Policy at any time. Continued use of the Platform does not constitute consent to new optional cookies where affirmative consent is legally required.

11.7. Existing Preferences

An update to the text does not automatically alter a previously saved preference. New consent is requested where a new purpose or scope falls outside the consent previously provided.

11.8. International Application

Updates take account of mandatory requirements of other jurisdictions where applicable to the relevant processing activity.

11.9. Coordination with Other Documents

A change to the Cookie Policy does not automatically amend the Privacy Policy, Terms of Service or other documents. Related changes are coordinated where necessary.

11.10. Version Control

The Operator maintains the version number, approval date, effective date and, where appropriate, a Change Log for legally material changes.

Section 12. Contact Information and Final Provisions

12.1. Application

This Policy applies to all SASAHUB digital services in which cookies or similar technologies are actually used.

12.2. Relationship with Official SASAHUB Documents

This Policy applies together with the Terms of Service, Privacy Policy, Seller Policy, Buyer Policy, Payment Policy, Refund & Return Policy, Information Security Policy, Data Governance Policy, AI Usage Policy, AML/KYC Policy, Export Control & Sanctions Policy, Dispute Resolution & Complaints Policy and other official SASAHUB documents within their respective subject matter.

12.3. Contact Information

For cookie and privacy matters:

12.4. Handling Requests

Requests are handled within the time limits and procedures required by applicable law. Personal data requests are also processed in accordance with the Privacy Policy and the applicable data-subject request procedure.

12.5. Severability

If any provision is held invalid, the remaining provisions continue to apply to the extent they can operate independently.

12.6. Governing Law

To the extent a choice of law is permitted, this Policy is governed by the laws of the Republic of Türkiye, without prejudice to mandatory rules of any other applicable jurisdiction.

12.7. Entry into Force

This Policy enters into force on the date of official publication following corporate approval.

12.8. Document Information

12.9. Official Language Versions

The Policy may be published in Turkish, Russian and English. The Turkish version is the controlling version unless mandatory law requires otherwise. Translations must reflect the same legal content.

12.10. Completion of the Document

This Cookie Policy v1.1 is the SASAHUB Cookie Policy and applies together with the Privacy Policy and Terms of Service.

Appendix A. Cookie Register and Required Information

The current list of technologies actually deployed must be maintained in Cookie Settings / Cookie Centre / Cookie Register. For each cookie, SDK or similar technology, the following information should be made available where applicable: