SASAHUB — PRIVACY POLICY
v1.1
Status: official published version
Revision date: 09 August 2026
Effective date: from the date of official
publication
Official (controlling) language version: Turkish
Operator / Data Controller
SHAMUS E‑TİCARET LOJİSTİK VE GIDA TİCARET LİMİTED
ŞİRKETİ
Legal form: Limited Şirket
Address: Cevizli Mah. Mustafa Kemal Cad. Hukukçular Towers Sitesi A Blok
No: 66A İç Kapı No: 111 Kartal / İstanbul, Türkiye
MERSİS No: 0768110028600001
Trade Registry No: 1114861
Tax Identification No: 7681100286
Tax Office: Kartal Vergi Dairesi
For the purposes of the personal data protection laws of the Republic of Türkiye, the legal entity identified above acts as the Veri Sorumlusu (Data Controller) with respect to processing activities for which it determines the purposes and means of processing.
Privacy and personal data contacts:
privacy@sasahub.com.tr
legal@sasahub.com.tr
Security: security@sasahub.com.tr
General support: support@sasahub.com.tr
Person authorised to approve this document on behalf of the
company:
SHAMIL TEMIEV — Şirket Müdürü, Münferiden Temsile Yetkili.
Section 1. General Provisions
1.1. Purpose of the Policy
This Privacy Policy (the “Policy”) sets out the principles, conditions and procedures governing the processing of personal data and other information associated with use of the SASAHUB digital platform (the “Platform”), as well as the rights of data subjects and the obligations of the Data Controller.
This Policy applies to all personal data processing operations carried out by the Data Controller in connection with the provision of Platform services.
1.2. Objectives of the Policy
This Policy has been developed to:
- ensure lawful, fair and transparent processing of personal data;
- protect the rights and freedoms of data subjects;
- define the categories of data processed;
- define the purposes and legal bases of processing;
- define procedures for retention, transfer, deletion and other processing of data;
- define measures for ensuring information security;
- comply with Applicable Law.
1.3. Scope
This Policy applies to all personal data processing associated with use of the SASAHUB Platform, including processing of data relating to:
- Registered Users;
- unregistered visitors to the website and mobile application, to the extent information is actually collected;
- Buyers;
- Sellers;
- representatives of legal entities;
- prospective business partners;
- persons contacting support;
- other persons interacting with the Platform.
1.4. Core Principles of Personal Data Processing
The Data Controller processes personal data in accordance with the following principles:
- lawfulness and fairness;
- transparency;
- purpose limitation;
- data minimisation;
- accuracy and keeping data up to date where necessary;
- storage limitation;
- confidentiality;
- integrity and availability of information;
- accountability;
- data protection by design and by default (Privacy by Design and Privacy by Default) to the extent applicable to the Platform's activities and Applicable Law.
1.5. Applicable Law
The Data Controller processes personal data primarily in accordance with Law No. 6698 on the Protection of Personal Data of the Republic of Türkiye (Kişisel Verilerin Korunması Kanunu — KVKK), applicable secondary legislation and binding decisions of the Kişisel Verileri Koruma Kurulu.
Where Regulation (EU) 2016/679 (GDPR) or mandatory rules of another jurisdiction apply to a specific processing activity by virtue of their territorial scope, the Data Controller applies those requirements to the extent they are mandatory for that processing activity.
Where mandatory Applicable Law provides a data subject with a higher level of protection than this Policy, those mandatory provisions prevail.
This Policy is SASAHUB's general public privacy policy and does not replace specific privacy notices or information notices, including KVKK Aydınlatma Metni, that may be provided to Users at the point at which personal data are collected for particular processing activities.
1.6. International Nature of the Platform
SASAHUB is an international digital e-commerce platform.
Due to the international nature of its activities, personal data may be processed in connection with cross-border services, international trade, international payments, logistics and other activities related to use of the Platform.
Any such processing is carried out in accordance with this Policy and Applicable Law.
1.7. Relationship with Other Official Documents
This Policy applies together with:
- Terms of Service;
- Cookie Policy;
- Buyer Policy;
- Seller Policy;
- Payment Policy;
- Refund & Return Policy;
- Information Security Policy;
- Data Governance Policy;
- AI Usage Policy;
- AML/KYC Policy;
- Export Control & Sanctions Policy;
- Moderation Policy;
- Dispute Resolution & Complaints Policy;
- other official SASAHUB documents.
Where a particular matter is regulated in detail by a specialised policy, that document applies within the scope of the matter it regulates.
1.8. Interpretation of Terms
Terms used in this Policy have the meanings given in the Terms of Service, unless this Policy or mandatory Applicable Law expressly provides otherwise.
1.9. Electronic Form of the Document
This Policy is published primarily in electronic form.
The version published on the official SASAHUB website, in the mobile application or on another official electronic resource designated by the Data Controller is considered the official published version.
1.10. Entry into Force
This Policy enters into force on the date of its official publication by the Data Controller and remains in effect until a new version is adopted, unless mandatory Applicable Law requires otherwise.
Section 2. Categories of Data Processed
2.1. General Provisions
The Data Controller processes only those personal data and other information that are necessary to provide Platform services, implement this Policy, comply with legal requirements, ensure security and develop SASAHUB functionality.
The scope of data processed depends on the nature of the User's interaction with the Platform, the services used and Applicable Law.
2.2. Identification Data
Depending on the services used, the Data Controller may process the following identification data:
- first name, last name and other name information, where applicable;
- organisation or company name;
- information about a representative of a legal entity;
- position or title;
- Account identifier;
- unique User identifier;
- other information provided by the User during registration or use of the Platform.
2.3. Contact Data
The Data Controller may process:
- email address;
- telephone number;
- postal address, where necessary;
- delivery address, where the relevant functionality is used;
- other contact details voluntarily provided by the User.
2.4. Corporate Data
Where a User acts on behalf of a legal entity or sole proprietor, the Data Controller may process:
- organisation name;
- registration information;
- tax identifiers;
- information concerning representatives;
- company details;
- information concerning the representative's authority;
- other corporate information necessary to use the Platform.
2.5. Platform Usage Data
The Data Controller may process information concerning the User's interaction with the Platform, including:
- date and time of service use;
- activity and transaction history;
- search history;
- history of interaction with Content;
- information concerning listed goods, services and RFQs;
- support request history;
- Account settings;
- User preferences;
- other information generated through use of the Platform.
2.6. Technical Data
The following technical data may be processed to operate the Platform:
- IP address;
- browser information;
- operating system information;
- device information;
- unique device identifiers;
- event logs and log files;
- technical connection parameters;
- information concerning service performance;
- diagnostic information;
- other technical data necessary to ensure the security and stable operation of the Platform.
2.7. Payment Information
When paid Platform services are used, information necessary to initiate and support payments may be processed, including:
- payment information;
- payment transaction status;
- transaction identifiers;
- information required for accounting and tax records.
SASAHUB does not store full payment card details unless this is required by the payment infrastructure used or Applicable Law.
Processing of information associated with payments is additionally governed by the Payment Policy.
2.8. Documents and Information Provided by the User
A User may voluntarily provide documents and information necessary for use of specific Platform services, including:
- documents confirming identity or authority;
- company registration documents;
- licences;
- certificates;
- documents required for international trade;
- other information provided by the User on the User's own initiative or in response to a lawful request by the Data Controller.
2.9. Data Obtained from Third-Party Sources
Where permitted by law or Platform functionality, the Data Controller may obtain information from:
- payment organisations;
- logistics companies;
- public registers and official records;
- business partners;
- identification and authentication service providers;
- other lawful sources.
Such data are used solely for the purposes described in this Policy.
2.10. Special Categories of Personal Data
The Data Controller does not intentionally collect special categories of personal data unless such processing is objectively necessary for a specific service or required by law.
This category may include information subject to a special protection regime under Applicable Law. Where processing of such data is necessary, it is carried out only where a statutory legal condition applies, limited to what is necessary and subject to additional safeguards.
Where a User voluntarily submits special-category data that are not required for the relevant purpose, the Data Controller may restrict the processing of, delete or anonymise such information to the extent permitted by law and provided this does not prevent compliance with mandatory obligations.
2.11. Data Minimisation
The Data Controller seeks to collect and process only the amount of personal data objectively necessary to achieve the stated processing purposes.
Excessive information is not collected unless required by Applicable Law or by use of a specific Platform function.
2.12. Methods of Collecting Personal Data
Personal data may be collected:
- directly from the User during registration, completion of forms, posting of Content, submission of RFQs, transactions or support requests;
- automatically during use of the website, mobile application and other digital services through technical logs, identifiers, Cookies and similar technologies;
- from other Users through authorised Platform functionality;
- from payment, logistics, identification and other service providers;
- from public, corporate and other lawful sources where collection from those sources is permitted by law.
The method by which data are obtained is taken into account when determining the legal basis for processing and the information that must be provided to the data subject.
2.13. Final Provisions of the Section
This Section applies together with:
- Terms of Service;
- Payment Policy;
- Information Security Policy;
- Data Governance Policy;
- Cookie Policy;
- AI Usage Policy;
- other official SASAHUB documents.
This Section identifies categories of information that may be processed by the Data Controller. The purposes of processing, legal bases, retention periods, transfer procedures and other aspects of processing are governed by subsequent Sections of this Policy and specialised SASAHUB documents.
Section 3. Purposes of Processing Personal Data
3.1. General Provisions
The Data Controller processes personal data only for lawful, specific and predetermined purposes.
Unless otherwise permitted by Applicable Law, personal data are not processed in a manner incompatible with the purposes for which they were originally collected.
The scope and nature of processing are limited to data objectively necessary to achieve the relevant purpose.
3.2. Providing Access to the Platform
Personal data may be processed for:
- creating and maintaining an Account;
- identifying the User;
- providing access to Platform functionality;
- authorisation and authentication;
- Account management;
- restoring access;
- ensuring proper operation of services.
3.3. Performance of the Terms of Service
Data are processed for:
- performance of the Terms of Service;
- implementation of other official SASAHUB documents;
- provision of digital services;
- supporting use of the Platform;
- performance of mutual obligations between the Data Controller and the User.
3.4. Provision of E-Commerce Functionality
For the purpose of operating e-commerce services, the Data Controller may process personal data for:
- listing goods, works and services;
- processing RFQs (Requests for Quotation);
- supporting negotiations between Users;
- facilitating interaction between Buyers and Sellers;
- performing other functions of the electronic trading platform.
This Section does not regulate the commercial terms of Transactions, which are governed by the relevant specialised SASAHUB documents.
3.5. Processing Payments and Financial Operations
When paid Platform services are used, personal data may be processed for:
- supporting payment operations;
- issuing invoices and payment documents;
- accounting and tax records;
- preventing fraud;
- complying with legal requirements.
Processing of information associated with payments is additionally governed by the Payment Policy.
3.6. Communications with Users
Personal data may be used for:
- sending service, transactional and legally significant notices;
- responding to enquiries;
- providing information concerning Platform operation;
- technical support;
- notifying Users of changes to official documents;
- performing obligations under this Policy.
Service-related and legally necessary communications may be sent without separate marketing consent to the extent permitted by law.
Advertising or marketing communications are sent only where an appropriate legal basis exists and, where required by Applicable Law, after obtaining the User's separate consent, with the ability to opt out subsequently.
3.7. Platform Security
Data may be processed for:
- preventing fraud;
- protecting Accounts;
- preventing unauthorised access;
- detecting violations;
- ensuring information security;
- investigating incidents;
- protecting the rights of Users and the Data Controller.
3.8. Compliance with Legal Requirements
Personal data may be processed for:
- complying with legal requirements;
- performing obligations towards public authorities;
- complying with court decisions;
- tax, accounting and other mandatory record-keeping;
- compliance with other binding requirements of Applicable Law.
3.9. Improvement of Platform Services
The Data Controller may use personal data and anonymised information for:
- analysing service operation;
- developing functionality;
- correcting technical errors;
- evaluating service quality;
- improving performance;
- internal analytics;
- improving User experience.
Where consent is required for such processing, it is obtained in the circumstances prescribed by Applicable Law.
3.10. Use of Artificial Intelligence and Automated Processing
For the development and operation of the Platform, the Data Controller may use artificial intelligence and automated data processing technologies for:
- intelligent search;
- generating recommendations;
- automatic classification of information;
- preventing fraud;
- ensuring security;
- automated moderation;
- improving service efficiency.
Such processing is carried out in accordance with the AI Usage Policy, this Policy and Applicable Law.
Where automated processing may produce legal effects concerning a User or otherwise similarly significantly affect the User, the Data Controller applies the safeguards required by Applicable Law, including rights to information, objection or human review where such rights are provided by law.
3.11. Statistical and Analytical Processing
The Data Controller may use anonymised or aggregated data for:
- producing statistics;
- analysing use of the Platform;
- assessing the effectiveness of digital services;
- forecasting development of functionality;
- preparing internal reports.
Unless otherwise provided by law, such data are used in a manner that does not permit identification of a particular User.
3.12. Final Provisions of the Section
This Section applies together with:
- Terms of Service;
- Payment Policy;
- Cookie Policy;
- AI Usage Policy;
- Information Security Policy;
- Data Governance Policy;
- Buyer Policy;
- Seller Policy;
- other official SASAHUB documents.
This Section defines only the purposes of processing personal data. Legal bases, data categories, retention periods, transfer procedures, User rights and other matters are governed by the relevant Sections of this Policy and specialised SASAHUB documents.
Section 4. Legal Bases for Processing Personal Data
4.1. General Provisions
The Data Controller processes personal data only where a legal basis recognised by Applicable Law exists. The specific legal basis is determined by taking into account the purpose of processing, the category of data, the method by which the data are obtained, the service used and the applicable jurisdiction.
For processing subject to the KVKK, the processing conditions set out, in particular, in Articles 5 and 6 of Law No. 6698 apply. Where the GDPR applies to a particular processing activity, the legal basis is determined in accordance with the relevant provisions of the GDPR.
4.2. Performance of a Contract and Steps Prior to Entering into a Contract
Personal data may be processed where processing is necessary for the conclusion or performance of a contract to which the data subject is a party, including:
- User registration;
- creation and maintenance of an Account;
- provision of access to the Platform;
- provision of requested digital services;
- support of transactions and enquiries;
- performance of obligations associated with use of the Platform.
4.3. Compliance with the Data Controller's Legal Obligations
The Data Controller may process personal data where necessary to comply with a legal obligation, including requirements arising from:
- tax and accounting law;
- e-commerce law;
- lawful requirements of competent public authorities;
- court decisions;
- legislation concerning fraud prevention, AML/KYC, export controls and sanctions restrictions, to the extent such requirements apply to the Data Controller;
- other mandatory rules of law.
4.4. Processing Expressly Provided for by Law
Personal data may be processed without separate consent where the relevant processing is expressly provided for by law and all statutory conditions are satisfied.
4.5. Legitimate Interests
Where permitted by Applicable Law, the Data Controller may process personal data for its legitimate interests, including:
- ensuring Platform security;
- preventing fraud and abuse;
- protecting the rights of Users and the Data Controller;
- maintaining resilience and continuity of services;
- risk management;
- internal audit;
- establishing, exercising or defending legal claims;
- reasonable improvement of services and analysis of their operation.
This legal basis is used only where the processing does not prejudice the fundamental rights and freedoms of the data subject. Where appropriate, the Data Controller carries out a balancing assessment.
4.6. Establishment, Exercise or Protection of a Right
Personal data may be processed where necessary for the establishment, exercise or protection of a right, including handling claims, resolving disputes, protecting against fraud and conducting judicial or administrative proceedings.
4.7. Data Made Public by the Data Subject
Where permitted by law, the Data Controller may process personal data made public by the data subject on the data subject's own initiative, solely within the scope of the purpose for which they were made public and subject to the principles of proportionality and fairness.
4.8. Protection of Life or Physical Integrity
In circumstances expressly provided for by Applicable Law, personal data may be processed where necessary to protect the life or physical integrity of a person who is physically incapable of giving consent or whose consent is not legally valid.
4.9. User Consent
Where the law requires consent for a specific processing activity, the Data Controller obtains such consent separately, on an informed basis and before the relevant processing begins.
The User may withdraw consent in accordance with Applicable Law. Withdrawal does not affect the lawfulness of processing carried out before withdrawal and does not prevent continued processing where an independent lawful basis exists after withdrawal.
4.10. Special Categories of Personal Data
Special categories of personal data are processed only where a specific legal condition applies and additional security requirements established by Applicable Law are satisfied.
The Data Controller does not use consent as a universal basis for processing special-category data where the law provides another applicable condition or imposes additional requirements.
4.11. International Processing and the GDPR
Where the GDPR applies to a specific processing activity, the Data Controller determines the appropriate legal basis under Article 6 GDPR and, for special categories of personal data, the applicable condition under Article 9 GDPR.
This provision does not mean that the GDPR applies to all SASAHUB processing activities; it applies only where the territorial scope requirements established by the Regulation are met.
4.12. Change of Purpose or Legal Basis
Before further processing personal data for a new purpose, the Data Controller assesses the compatibility of that purpose with the original purpose, the availability of an appropriate legal basis and whether additional information must be provided to the User or consent obtained.
4.13. Documentation of Processing
The Data Controller may maintain internal records of processing activities, legal bases, categories of data, recipients, retention periods and security measures for the purposes of internal control, audits, risk management and compliance with Applicable Law.
4.14. Final Provisions of the Section
This Section applies together with:
- Terms of Service;
- Data Governance Policy;
- Information Security Policy;
- AML/KYC Policy;
- AI Usage Policy;
- Export Control & Sanctions Policy;
- other official SASAHUB documents.
Specific purposes, data categories, recipients, retention periods and other processing parameters are determined by this Policy, the relevant User journey and specialised official SASAHUB documents.
Section 5. Transfer of Personal Data and International Transfers
5.1. General Provisions
The Data Controller may disclose or transfer personal data to third parties only in the circumstances permitted by this Policy, official SASAHUB documents and Applicable Law.
Any transfer is limited to the extent necessary to achieve the relevant processing purpose and must be supported by an appropriate legal basis.
5.2. Transfers to Service Providers
For the operation of the Platform, the Data Controller may transfer personal data to organisations providing services on behalf of or under instructions from the Data Controller, including:
- cloud infrastructure providers;
- data centres;
- hosting providers;
- information security providers;
- payment organisations;
- identification and authentication service providers;
- logistics providers;
- support services;
- analytics and technical service providers;
- other contractors whose involvement is necessary for operation of the Platform.
Such persons may process personal data only within the scope of the authority granted to them and must comply with Applicable Law and contractual confidentiality and security obligations.
5.3. Transfers Between Platform Users
When Platform functionality is used, certain personal data may become available to other Users to the extent necessary to provide the relevant service, including interaction between Buyers and Sellers.
The scope of information disclosed is determined by Platform functionality, User settings and the nature of the relevant operation.
5.4. Transfers Required by Law
The Data Controller may transfer personal data to competent public authorities, courts, law enforcement bodies and other authorised organisations in the circumstances and manner provided by Applicable Law.
Such transfer is limited to the scope of the relevant lawful requirement.
5.5. International (Cross-Border) Transfers of Personal Data
Due to the international nature of SASAHUB's activities, personal data may be transferred to other countries only where there is a lawful basis for the underlying processing and the specific requirements applicable to international transfers are satisfied.
For transfers subject to the KVKK, the Data Controller applies the mechanism established by the current version of Article 9 of Law No. 6698 and relevant secondary legislation. Depending on the circumstances, a transfer may be made:
- on the basis of an adequacy decision (yeterlilik kararı) applicable to the relevant country, sector within a country or international organisation;
- where no adequacy decision exists, on the basis of one of the appropriate safeguards (uygun güvenceler) provided by law, including applicable standard contracts, binding corporate rules or another mechanism permitted by law;
- in exceptional circumstances, on the basis of one of the limited statutory derogations for occasional transfers where neither an adequacy decision nor an appropriate safeguard is available.
Where a standard contract prescribed by Turkish law for international transfers is used, the Data Controller complies with the associated mandatory notification requirements to the Kişisel Verileri Koruma Kurumu within the statutory period.
Where the GDPR or the law of another jurisdiction applies to a particular transfer, the corresponding international transfer mechanisms and safeguards required for that transfer are also applied.
This Policy does not, by itself, constitute the User's consent to an international transfer and does not replace any contractual or other safeguards required by law.
5.6. Safeguards for Transfers
When personal data are transferred to third parties, the Data Controller seeks to ensure, as appropriate:
- processing solely for stated purposes;
- confidentiality;
- implementation of necessary organisational and technical security measures;
- compliance with contractual obligations;
- compliance with Applicable Law.
5.7. Transfers in Connection with Corporate Changes
In the event of reorganisation, merger, acquisition, sale of the business, transfer of assets or other corporate changes, personal data may be transferred to the relevant legal successor to the extent necessary for continued operation of the Platform.
The successor must comply with this Policy or provide a level of protection no lower than that required by Applicable Law.
5.8. Transfers Based on User Consent
Where Applicable Law requires separate consent to transfer personal data, the transfer is made only after the required consent has been obtained.
The User may withdraw consent in the circumstances and manner provided by law.
5.9. Restrictions on Transfers
The Data Controller does not sell Users' personal data.
Personal data are not transferred to third parties for independent use for their own advertising or other commercial purposes without an independent lawful basis and, where required by law, the User's appropriate consent.
Access by service providers to personal data is limited to what is necessary to perform the assigned function, unless their independent status under Applicable Law requires otherwise.
5.10. Documentation of Transfers
The Data Controller may maintain internal records of personal data transfers for the purposes of:
- compliance with legal requirements;
- internal control;
- corporate audit;
- risk management;
- information security;
- demonstrating compliance with this Policy.
5.11. Relationship with Specialised Documents
This Section applies together with:
- Data Governance Policy;
- Information Security Policy;
- Payment Policy;
- Terms of Service;
- AML/KYC Policy;
- Export Control & Sanctions Policy;
- other official SASAHUB documents.
Matters specifically regulated by those documents are governed by the relevant policy.
5.12. Final Provisions of the Section
This Section governs only the general principles applicable to transfers of personal data to third parties and international transfers.
Detailed procedures for data-flow management, access control, internal exchange of information, retention and corporate data governance are determined by the Data Governance Policy, Information Security Policy and other official SASAHUB documents.
Section 6. Retention, Deletion and Anonymisation of Personal Data
6.1. General Provisions
The Data Controller retains personal data only for as long as necessary to achieve the purposes of processing, implement this Policy, comply with legal requirements, protect the legitimate interests of the Data Controller and Users and fulfil other obligations arising under Applicable Law.
When the relevant purposes have been achieved or the legal basis for processing has ceased to exist, personal data are deleted, destroyed, anonymised or otherwise cease to be processed unless continued retention or processing is required by law.
6.2. Retention Periods
Specific retention periods are determined taking into account:
- purposes of personal data processing;
- nature of the services provided;
- requirements of Applicable Law;
- mandatory accounting, tax and other record-keeping periods;
- the need to protect the rights and legitimate interests of the parties;
- limitation periods;
- other legally relevant circumstances.
The Data Controller does not establish a single retention period for all categories of personal data because the appropriate period depends on the specific processing purpose.
6.3. Retention of Account Data
Personal data associated with a User Account may be retained throughout the period during which the Platform is used.
After use of the Account ends, data may continue to be retained where necessary:
- to comply with legal requirements;
- to protect the rights of the Data Controller or Users;
- to prevent fraud;
- to handle claims and litigation;
- to ensure information security;
- to comply with other mandatory legal requirements.
6.4. Deletion of Personal Data
Personal data are deleted or processing ceases:
- after the purposes of processing have been achieved;
- after expiry of applicable retention periods;
- upon withdrawal of User consent where processing was based solely on consent and no other lawful basis for continued processing exists;
- at the User's request where provided by law;
- in other circumstances required by Applicable Law.
Deletion is not carried out where the Data Controller is required to continue processing by law or another valid legal basis remains in effect.
6.5. Anonymisation of Personal Data
The Data Controller may anonymise personal data where permitted by law and consistent with the processing purposes.
Following anonymisation, information may be used for:
- statistical analysis;
- development of Platform functionality;
- internal analytics;
- service quality assessment;
- scientific, research or other lawful purposes.
When anonymised data are used, the Data Controller takes reasonable measures to prevent identification of a specific User unless otherwise permitted by law.
6.6. Archival Retention
Where provided by law or internal document-management procedures, the Data Controller may retain certain categories of information in archives.
Archival retention is permitted solely for:
- compliance with legal requirements;
- corporate governance;
- internal and external audit;
- resolution of judicial and administrative disputes;
- information security;
- protection of the legitimate interests of the Data Controller and Users.
6.7. Backups
To ensure business continuity and protect information, the Data Controller may create backup copies of data.
Backups are used solely for:
- restoring information following technical incidents;
- maintaining Platform resilience;
- protecting data;
- implementing internal recovery procedures.
Personal data contained in backups are processed in accordance with this Policy and Applicable Law.
6.8. Restriction of Processing
Where Applicable Law grants a User the right to request restriction of personal data processing, the Data Controller considers the request and takes the appropriate decision in accordance with Applicable Law.
During a period of restricted processing, the data may continue to be stored to the extent permitted by law.
6.9. Documentation of Retention and Deletion Operations
The Data Controller may maintain internal records relating to:
- retention of personal data;
- deletion of information;
- anonymisation;
- restoration of data;
- destruction of storage media;
- backups.
Such documentation is used solely for legal compliance, internal control, audit and information security.
6.10. Relationship with Specialised Documents
This Section applies together with:
- Data Governance Policy;
- Information Security Policy;
- Business Continuity & Disaster Recovery Policy;
- Terms of Service;
- AI Usage Policy;
- other official SASAHUB documents.
Matters specifically regulated by those documents are governed by the relevant policy.
6.11. Final Provisions of the Section
This Section establishes general principles for the retention, deletion, anonymisation and restriction of processing of personal data.
Detailed procedures for data lifecycle management, backups, archiving, information destruction and corporate data governance are determined by the Data Controller's internal rules and specialised official SASAHUB documents.
official SASAHUB documents.Section 7. Data Subject Rights
7.1. General Provisions
The Data Controller respects the rights of data subjects and enables them to exercise those rights in accordance with Applicable Law.
The scope of specific rights depends on the applicable jurisdiction and the legal basis for processing. For data subjects whose data are subject to the KVKK, the rights set out in Article 11 of Law No. 6698 are taken fully into account. Where the GDPR applies to a particular processing activity, the rights provided by the GDPR are additionally available to the extent its conditions apply.
7.2. Rights under Article 11 of the KVKK
Where the KVKK applies, a data subject may apply to the Data Controller and has the right to:
- learn whether personal data relating to the data subject are being processed;
- request information concerning the processing where personal data have been processed;
- learn the purpose of processing and whether the personal data are used in accordance with that purpose;
- know the third parties in Türkiye or abroad to whom personal data have been transferred;
- request rectification where personal data are incomplete or inaccurately processed;
- request deletion or destruction of personal data where the statutory conditions are met;
- request notification to recipients of rectification, deletion or destruction operations;
- object to a result arising against the data subject as a consequence of analysis of processed data exclusively through automated systems;
- request compensation for damage suffered as a result of unlawful processing of personal data.
7.3. Additional Rights Where the GDPR Applies
Where the GDPR applies to a specific processing activity and the relevant conditions are satisfied, a data subject may, in particular, have the right:
- to access personal data;
- to rectification;
- to erasure;
- to restriction of processing;
- to data portability;
- to object to processing;
- to withdraw consent;
- not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects the data subject, subject to statutory exceptions;
- to lodge a complaint with a competent supervisory authority.
These rights are not absolute and apply subject to the conditions and exceptions established by law.
7.4. Information about Sources and Recipients
To the extent provided by Applicable Law, a User may request information concerning the categories of data processed, the purposes and legal bases of processing, the retention period or criteria used to determine it, the sources from which data were obtained and the categories of recipients, including information concerning international transfers.
7.5. Rectification, Deletion and Restriction of Processing
The Data Controller considers requests for rectification, deletion, destruction, anonymisation or restriction of processing in accordance with Applicable Law.
Such requests may be refused in whole or in part where continued processing is necessary, for example, to comply with a legal obligation, perform a contract, establish or defend a right, ensure security or on another independent lawful basis.
7.6. Withdrawal of Consent and Objection
Where processing is based on consent, the User may withdraw that consent. Withdrawal operates prospectively and does not affect the lawfulness of processing carried out before the Data Controller receives the withdrawal.
Where Applicable Law provides a right to object to processing, the Data Controller considers the objection in light of the relevant legal basis, the nature of the processing and any mandatory exceptions.
7.7. Automated Decisions
Where Applicable Law gives a data subject the right to challenge a result arising exclusively from automated processing, the User may submit an appropriate request to the Data Controller.
Where required by law, the Data Controller provides the opportunity for human review, an explanation or the User's expression of their position.
7.8. Procedure for Applications under the KVKK
To exercise rights under Article 11 of the KVKK, a data subject may submit an application to the Data Controller using methods permitted by current Turkish law, including:
- a written application sent to the Data Controller's registered address;
- KEP, secure electronic signature, mobile signature or another electronic method permitted by law, where the relevant technical facility is available;
- an email sent to privacy@sasahub.com.tr from an email address previously provided by the User to the Data Controller and registered in the Data Controller's information systems;
- a dedicated form or software interface, if SASAHUB provides such a tool for this purpose.
An application must contain the information necessary to identify the applicant and understand the request. The Data Controller may request additional information only to the extent necessary to verify identity and prevent unauthorised disclosure of personal data.
Where required by the Turkish rules governing applications to a data controller, a formal application must be submitted in Turkish.
7.9. Response Period
Applications under the KVKK are handled as soon as possible according to the nature of the request and, in any event, no later than 30 days after receipt of a valid application, unless a different period is established by law.
Where the GDPR applies, data subject requests are handled within the time limits established by the GDPR.
7.10. Cost of Requests
Data subject requests are handled free of charge unless Applicable Law expressly permits otherwise. Where the law allows a fee in exceptional circumstances, any such fee is determined only in the manner prescribed by law.
7.11. Right to Apply to a Competent Authority
If a User believes that their rights have been infringed, the User may use the remedies provided by law, including applying to the Kişisel Verileri Koruma Kurumu/Kurulu, a competent court or another supervisory authority where the relevant jurisdiction applies.
The procedure and time limits for complaints are determined by Applicable Law.
7.12. Security in Handling Requests
To protect personal data, the Data Controller may verify the applicant's identity, limit disclosure where necessary to protect the rights and freedoms of others, trade secrets and other legitimate interests, and use secure channels to provide a response.
Such limitations must not be used to unjustifiably refuse the exercise of lawful data subject rights.
7.13. Contact Details for Requests
Data Controller / Veri Sorumlusu:
SHAMUS E‑TİCARET LOJİSTİK VE GIDA TİCARET LİMİTED ŞİRKETİ
Postal address:
Cevizli Mah. Mustafa Kemal Cad. Hukukçular Towers Sitesi A Blok No: 66A
İç Kapı No: 111 Kartal / İstanbul, Türkiye
Personal data email: privacy@sasahub.com.tr
Legal matters: legal@sasahub.com.tr
7.14. Relationship with Specialised Documents
This Section applies together with:
- Terms of Service;
- Information Security Policy;
- Data Governance Policy;
- AI Usage Policy;
- Dispute Resolution & Complaints Policy;
- other official SASAHUB documents.
7.15. Final Provisions of the Section
Detailed internal procedures for verifying applicants, recording applications, fulfilling requests, identity verification and retaining evidence of compliance are determined by the Data Controller's internal rules and Applicable Law.
Section 8. Protection of Personal Data
8.1. General Provisions
The Data Controller takes reasonable organisational, technical and administrative measures to ensure the security of personal data and to prevent accidental or unlawful loss, destruction, alteration, disclosure, unauthorised access or other unlawful processing.
Security measures are determined taking into account the nature of the data processed, potential risks, technologies used and the requirements of Applicable Law.
8.2. Security Principles
When organising personal data processing, the Data Controller applies the following security principles:
- lawful processing;
- confidentiality;
- integrity of information;
- availability of data;
- risk minimisation;
- segregation of access rights;
- accountability;
- data lifecycle management;
- continuous improvement of safeguards.
8.3. Organisational and Administrative Measures
The Data Controller may apply organisational and administrative safeguards including:
- segregation of employee roles and responsibilities;
- access-rights management;
- internal personal data processing procedures;
- staff training on information security and data protection;
- internal monitoring of compliance with this Policy;
- corporate risk-management procedures;
- other organisational measures appropriate to the nature of the Platform's activities.
8.4. Technical Safeguards
To protect personal data, the Data Controller may use current technical safeguards including:
- encryption where appropriate;
- authentication and authorisation controls;
- event logging;
- security monitoring;
- threat-detection tools;
- backups;
- protection of network infrastructure;
- other technical measures appropriate to the current state of technology.
This Section does not disclose the specific architecture of the security system where such disclosure could reduce Platform security.
8.5. Restriction of Access to Data
Access to personal data is granted only to persons who require such access to perform their job duties or contractual obligations.
All persons with access to personal data must comply with confidentiality requirements and Applicable Law.
8.6. Response to Security Incidents and Personal Data Breaches
The Data Controller maintains internal procedures for detecting, analysing, containing, documenting and remediating information security incidents.
Where personal data are unlawfully obtained by third parties or another incident occurs that is subject to a mandatory notification requirement, the Data Controller:
- takes measures to limit the consequences and prevent recurrence;
- documents the nature of the incident, its effects and measures taken;
- notifies the competent authority and affected data subjects to the extent and within the periods required by Applicable Law.
For incidents subject to the KVKK, notification to the Kişisel Verileri Koruma Kurulu is made without undue delay and, in accordance with the applicable practice of the Kurul, generally no later than 72 hours after the Data Controller becomes aware of the breach; affected data subjects are informed within a reasonably prompt period after they have been identified.
Where the GDPR applies, the Data Controller complies with the GDPR requirements concerning personal data breaches, including the applicable notification criteria and time limits.
8.7. Monitoring and Audit
The Data Controller may conduct:
- internal monitoring of compliance with this Policy;
- information-security reviews;
- risk assessments;
- internal audits of data-processing activities;
- analysis of the effectiveness of safeguards;
- other activities intended to maintain the required level of security.
8.8. User Responsibilities
The User also participates in protecting the security of their personal data and undertakes to:
- keep Account credentials confidential;
- use strong passwords;
- not provide the Account to third parties;
- promptly update contact information;
- use current software;
- immediately notify the Data Controller of suspected unauthorised access to the Account.
8.9. Use of Service Providers
Where personal data are processed with the involvement of third parties, the Data Controller takes reasonable measures to ensure their compliance with confidentiality, information-security and Applicable Law requirements.
8.10. Continuous Improvement of the Security System
The Data Controller may regularly review and improve organisational and technical safeguards for personal data taking into account:
- technological developments;
- emerging threats;
- changes in law;
- results of internal reviews;
- recognised international good practices.
8.11. Relationship with Specialised Documents
This Section applies together with:
- Information Security Policy;
- Data Governance Policy;
- Business Continuity & Disaster Recovery Policy;
- AI Usage Policy;
- Terms of Service;
- other official SASAHUB documents.
Matters specifically regulated by those documents are governed by the relevant policy.
8.12. Final Provisions of the Section
This Section establishes general principles for protection of personal data.
Detailed requirements concerning information-security architecture, technical safeguards, access management, incident response, backups, data recovery and risk management are governed by the Information Security Policy, Business Continuity & Disaster Recovery Policy and other specialised SASAHUB documents.
Section 9. Use of Cookies and Similar Technologies
9.1. General Provisions
To operate the SASAHUB Platform, the Data Controller may use Cookies and similar technologies that support correct service operation, security, analysis of Platform use and improvement of User experience.
This Section establishes general principles for the use of such technologies. Detailed rules are governed by the separate Cookie Policy.
9.2. Purposes of Using Cookies
Cookies and similar technologies may be used for:
- ensuring proper operation of the Platform;
- maintaining User sessions;
- storing User settings;
- ensuring Account security;
- preventing fraud;
- analysing use of services;
- assessing Platform performance;
- improving functionality;
- providing a personalised User experience;
- complying with legal requirements.
Cookies are used only for lawful purposes.
9.3. Categories of Technologies Used
Depending on their purpose, the Platform may use different categories of Cookies and similar technologies, including:
- strictly necessary or technical Cookies;
- functional Cookies;
- analytics Cookies;
- performance Cookies;
- security Cookies;
- other categories permitted by Applicable Law.
The specific classification and description of each category are provided in the Cookie Policy.
9.4. Use of Third-Party Services
Certain Platform functions may use technologies provided by third parties, including analytics, security, payment infrastructure, cloud solutions and other service providers.
Such technologies are used in accordance with this Policy, the Cookie Policy, agreements with the relevant providers and Applicable Law.
9.5. Managing Cookie Preferences
The User may manage the use of Cookies through:
- browser settings;
- consent-management tools provided by the Platform, where available;
- other methods provided by Platform functionality and Applicable Law.
Disabling certain categories of Cookies may affect the availability or proper operation of certain Platform functions.
9.6. User Consent
Where Applicable Law requires consent for the use of certain categories of Cookies or similar technologies, the Data Controller obtains such consent before the relevant processing begins.
The User may change preferences or withdraw consent in accordance with the Cookie Policy and Applicable Law.
Withdrawal of consent does not affect the lawfulness of processing carried out before the Data Controller receives the withdrawal.
9.7. Use of Analytics Data
Information collected through Cookies and similar technologies may be used for:
- analysing use of the Platform;
- assessing service effectiveness;
- detecting technical errors;
- improving performance;
- developing functionality;
- preparing statistical reports.
Where possible and appropriate, such information is used in aggregated or anonymised form.
9.8. Protection of Information
Information obtained through Cookies and similar technologies is processed using reasonable organisational and technical safeguards in accordance with this Policy, the Information Security Policy and Applicable Law.
9.9. International Use of Technologies
Where the use of a particular technology involves an international transfer of information, that processing is carried out in accordance with the international transfer provisions of this Policy and Applicable Law.
9.10. Relationship with Specialised Documents
This Section applies together with:
- Cookie Policy;
- Privacy Policy;
- Information Security Policy;
- Data Governance Policy;
- Terms of Service;
- AI Usage Policy;
- other official SASAHUB documents.
Matters specifically regulated by the Cookie Policy are governed by that policy.
9.11. Final Provisions of the Section
This Section governs only the general principles applicable to Cookies and similar technologies.
Detailed Cookie categories, retention periods, technologies used, procedures for obtaining and withdrawing consent and management of User preferences are determined by the Cookie Policy.
Section 10. Processing Personal Data of Minors
10.1. General Provisions
The SASAHUB Platform is intended primarily for use by adults, legal entities and their authorised representatives.
The Data Controller recognises that personal data relating to minors require additional protection and takes reasonable measures to comply with Applicable Law.
10.2. Age Restrictions
Use of certain Platform services may be subject to age requirements established by Applicable Law or the Terms of Service.
Where the law requires consent from a parent, legal representative or guardian for processing personal data relating to a minor, such consent must be obtained before the relevant processing begins.
10.3. No Intentional Collection of Children's Data
The Data Controller does not intentionally collect personal data relating to children unless the relevant service is specifically intended for minors or such processing is otherwise permitted by Applicable Law.
10.4. Voluntary Provision of Information
Where a minor or another person provides personal data without satisfying applicable legal requirements, the Data Controller may:
- restrict processing of such data;
- request evidence of the authority of a legal representative;
- delete the relevant information;
- restrict access to certain services;
- take other measures provided by law and this Policy.
10.5. Requests by Legal Representatives
Legal representatives of minors may contact the Data Controller to request:
- information concerning processing of personal data;
- rectification of inaccurate data;
- deletion of personal data;
- restriction of processing;
- exercise of other rights provided by Applicable Law.
The Data Controller may request documents confirming the authority of the legal representative.
10.6. Additional Safeguards
When processing personal data relating to minors, the Data Controller applies additional organisational and technical safeguards to the extent required by Applicable Law and appropriate to the nature of the services provided.
10.7. International Nature of Processing
Where the Platform is used in different countries, the age at which a person may independently consent to processing of their personal data is determined by the law of the relevant jurisdiction.
Where Applicable Law provides a higher level of protection for minors, those mandatory provisions apply.
10.8. Accuracy of Age Information
The User or the User's legal representative is responsible for the accuracy of age information provided during registration and use of the Platform.
Where the Data Controller had no objective means of determining that such information was inaccurate, it shall not be liable for consequences arising from the provision of inaccurate information except where mandatory Applicable Law provides otherwise.
10.9. Relationship with Specialised Documents
This Section applies together with:
- Terms of Service;
- Privacy Policy;
- Information Security Policy;
- Data Governance Policy;
- Dispute Resolution & Complaints Policy;
- other official SASAHUB documents.
Matters specifically regulated by those documents are governed by the relevant provisions.
10.10. Final Provisions of the Section
This Section establishes general principles for processing personal data relating to minors.
If SASAHUB introduces services specifically intended for children or minors in the future, the Data Controller may adopt an additional privacy policy for such services. Until such a policy is adopted, this Policy and mandatory Applicable Law apply.
Section 11. Amendments, Contact Information and Final Provisions
11.1. General Provisions
This Privacy Policy is an official SASAHUB document governing the processing of Users' personal data.
The Policy applies together with the Terms of Service and other official SASAHUB documents governing specific aspects of Platform activities.
11.2. Amendments to the Policy
The Data Controller may amend, supplement or update this Policy for the purposes of:
- bringing it into compliance with legal requirements;
- developing Platform functionality;
- introducing new services;
- improving personal data protection measures;
- correcting inaccuracies;
- complying with lawful requirements of public authorities;
- pursuing other lawful purposes.
Amendments are made in good faith and may not arbitrarily restrict data subject rights granted by mandatory law.
11.3. Publication of a New Version
The current version of this Policy is published on the official SASAHUB website, in the official mobile application or on another official electronic resource designated by the Data Controller.
Where appropriate, the Data Controller may additionally notify Users by:
- email;
- notifications in the User Account;
- push notifications;
- messages in the mobile application;
- other official communication channels.
11.4. Entry into Force of Amendments
Unless otherwise required by law or specified in the new version of the Policy, amendments enter into force on the date stated by the Data Controller upon publication.
Where Applicable Law requires advance notice or User consent, those requirements are satisfied before the relevant amendments take effect.
11.5. Contact Information
For matters concerning personal data processing and this Policy, the Data Controller may be contacted at:
SHAMUS E‑TİCARET LOJİSTİK VE GIDA TİCARET LİMİTED
ŞİRKETİ
Cevizli Mah. Mustafa Kemal Cad. Hukukçular Towers Sitesi A Blok No: 66A
İç Kapı No: 111 Kartal / İstanbul, Türkiye
Privacy / personal data: privacy@sasahub.com.tr
Legal matters: legal@sasahub.com.tr
Security reports: security@sasahub.com.tr
General support: support@sasahub.com.tr
MERSİS No: 0768110028600001
Trade Registry No: 1114861
Tax Identification No: 7681100286
Tax Office: Kartal Vergi Dairesi
Formal data subject rights applications are submitted using the methods set out in Section 7 of this Policy.
11.6. Handling of Requests
The Data Controller records and handles requests relating to processing of personal data in accordance with the procedures and time limits established by Applicable Law.
Requests subject to the KVKK are answered as soon as possible according to the nature of the request and no later than 30 days after receipt of a valid application.
Where necessary, the Data Controller may request additional information solely to verify the applicant's identity, clarify the scope of the request or protect personal data from unauthorised disclosure.
11.7. Cooperation with Competent Authorities
The Data Controller may cooperate with public authorities, personal data protection authorities, courts and other authorised organisations in the circumstances and manner provided by Applicable Law.
Such cooperation is limited to the relevant legal powers and requirements.
11.8. International Application of the Policy
This Policy applies taking into account the international nature of SASAHUB's activities.
Where the law of a relevant jurisdiction provides a higher level of personal data protection than this Policy, the mandatory provisions of that law apply.
11.9. Priority of Language Versions
This Policy is published in Russian, Turkish and English.
Because the Data Controller is a legal entity incorporated in Türkiye, the Turkish version is the official and controlling version for SASAHUB corporate publication, unless mandatory Applicable Law requires otherwise.
The Russian and English versions are officially published translations intended to make the document accessible to international Users. In the event of an inconsistency of interpretation between language versions, the Turkish version prevails to the extent permitted by Applicable Law.
No language provision limits any data subject right that cannot lawfully be restricted by contract or policy.
11.10. Relationship with Official SASAHUB Documents
This Policy applies together with:
- Terms of Service;
- Cookie Policy;
- Buyer Policy;
- Seller Policy;
- Payment Policy;
- Refund & Return Policy;
- Information Security Policy;
- Data Governance Policy;
- AI Usage Policy;
- AML/KYC Policy;
- Export Control & Sanctions Policy;
- Business Continuity & Disaster Recovery Policy;
- Dispute Resolution & Complaints Policy;
- other official SASAHUB documents.
Where a particular matter is specifically regulated by another policy, the provisions of that document apply within the scope of the matter it regulates.
11.11. Entry into Force of the Policy
This Privacy Policy v1.1 enters into force on the date of its official publication by the Data Controller and remains effective until a new version is adopted or it is withdrawn in accordance with Applicable Law.
11.12. Final Provision
This Privacy Policy v1.1 is SASAHUB's general public policy concerning privacy and the processing of personal data.
It applies together with specific privacy notices, KVKK Aydınlatma Metinleri, consent forms, the Cookie Policy and other specialised documents where their use is required for a particular processing activity.
Matters not governed by this Policy are subject to the relevant official SASAHUB documents and mandatory provisions of Applicable Law.