SASAHUB — PRIVACY POLICY

v1.1

Status: official published version
Revision date: 09 August 2026
Effective date: from the date of official publication
Official (controlling) language version: Turkish

Operator / Data Controller

SHAMUS E‑TİCARET LOJİSTİK VE GIDA TİCARET LİMİTED ŞİRKETİ
Legal form: Limited Şirket
Address: Cevizli Mah. Mustafa Kemal Cad. Hukukçular Towers Sitesi A Blok No: 66A İç Kapı No: 111 Kartal / İstanbul, Türkiye
MERSİS No: 0768110028600001
Trade Registry No: 1114861
Tax Identification No: 7681100286
Tax Office: Kartal Vergi Dairesi

For the purposes of the personal data protection laws of the Republic of Türkiye, the legal entity identified above acts as the Veri Sorumlusu (Data Controller) with respect to processing activities for which it determines the purposes and means of processing.

Privacy and personal data contacts:
privacy@sasahub.com.tr
legal@sasahub.com.tr

Security: security@sasahub.com.tr
General support: support@sasahub.com.tr

Person authorised to approve this document on behalf of the company:
SHAMIL TEMIEV — Şirket Müdürü, Münferiden Temsile Yetkili.


Section 1. General Provisions


1.1. Purpose of the Policy

This Privacy Policy (the “Policy”) sets out the principles, conditions and procedures governing the processing of personal data and other information associated with use of the SASAHUB digital platform (the “Platform”), as well as the rights of data subjects and the obligations of the Data Controller.

This Policy applies to all personal data processing operations carried out by the Data Controller in connection with the provision of Platform services.


1.2. Objectives of the Policy

This Policy has been developed to:


1.3. Scope

This Policy applies to all personal data processing associated with use of the SASAHUB Platform, including processing of data relating to:


1.4. Core Principles of Personal Data Processing

The Data Controller processes personal data in accordance with the following principles:


1.5. Applicable Law

The Data Controller processes personal data primarily in accordance with Law No. 6698 on the Protection of Personal Data of the Republic of Türkiye (Kişisel Verilerin Korunması Kanunu — KVKK), applicable secondary legislation and binding decisions of the Kişisel Verileri Koruma Kurulu.

Where Regulation (EU) 2016/679 (GDPR) or mandatory rules of another jurisdiction apply to a specific processing activity by virtue of their territorial scope, the Data Controller applies those requirements to the extent they are mandatory for that processing activity.

Where mandatory Applicable Law provides a data subject with a higher level of protection than this Policy, those mandatory provisions prevail.

This Policy is SASAHUB's general public privacy policy and does not replace specific privacy notices or information notices, including KVKK Aydınlatma Metni, that may be provided to Users at the point at which personal data are collected for particular processing activities.


1.6. International Nature of the Platform

SASAHUB is an international digital e-commerce platform.

Due to the international nature of its activities, personal data may be processed in connection with cross-border services, international trade, international payments, logistics and other activities related to use of the Platform.

Any such processing is carried out in accordance with this Policy and Applicable Law.


1.7. Relationship with Other Official Documents

This Policy applies together with:

Where a particular matter is regulated in detail by a specialised policy, that document applies within the scope of the matter it regulates.


1.8. Interpretation of Terms

Terms used in this Policy have the meanings given in the Terms of Service, unless this Policy or mandatory Applicable Law expressly provides otherwise.


1.9. Electronic Form of the Document

This Policy is published primarily in electronic form.

The version published on the official SASAHUB website, in the mobile application or on another official electronic resource designated by the Data Controller is considered the official published version.


1.10. Entry into Force

This Policy enters into force on the date of its official publication by the Data Controller and remains in effect until a new version is adopted, unless mandatory Applicable Law requires otherwise.

Section 2. Categories of Data Processed


2.1. General Provisions

The Data Controller processes only those personal data and other information that are necessary to provide Platform services, implement this Policy, comply with legal requirements, ensure security and develop SASAHUB functionality.

The scope of data processed depends on the nature of the User's interaction with the Platform, the services used and Applicable Law.


2.2. Identification Data

Depending on the services used, the Data Controller may process the following identification data:


2.3. Contact Data

The Data Controller may process:


2.4. Corporate Data

Where a User acts on behalf of a legal entity or sole proprietor, the Data Controller may process:


2.5. Platform Usage Data

The Data Controller may process information concerning the User's interaction with the Platform, including:


2.6. Technical Data

The following technical data may be processed to operate the Platform:


2.7. Payment Information

When paid Platform services are used, information necessary to initiate and support payments may be processed, including:

SASAHUB does not store full payment card details unless this is required by the payment infrastructure used or Applicable Law.

Processing of information associated with payments is additionally governed by the Payment Policy.


2.8. Documents and Information Provided by the User

A User may voluntarily provide documents and information necessary for use of specific Platform services, including:


2.9. Data Obtained from Third-Party Sources

Where permitted by law or Platform functionality, the Data Controller may obtain information from:

Such data are used solely for the purposes described in this Policy.


2.10. Special Categories of Personal Data

The Data Controller does not intentionally collect special categories of personal data unless such processing is objectively necessary for a specific service or required by law.

This category may include information subject to a special protection regime under Applicable Law. Where processing of such data is necessary, it is carried out only where a statutory legal condition applies, limited to what is necessary and subject to additional safeguards.

Where a User voluntarily submits special-category data that are not required for the relevant purpose, the Data Controller may restrict the processing of, delete or anonymise such information to the extent permitted by law and provided this does not prevent compliance with mandatory obligations.


2.11. Data Minimisation

The Data Controller seeks to collect and process only the amount of personal data objectively necessary to achieve the stated processing purposes.

Excessive information is not collected unless required by Applicable Law or by use of a specific Platform function.


2.12. Methods of Collecting Personal Data

Personal data may be collected:

The method by which data are obtained is taken into account when determining the legal basis for processing and the information that must be provided to the data subject.


2.13. Final Provisions of the Section

This Section applies together with:

This Section identifies categories of information that may be processed by the Data Controller. The purposes of processing, legal bases, retention periods, transfer procedures and other aspects of processing are governed by subsequent Sections of this Policy and specialised SASAHUB documents.

Section 3. Purposes of Processing Personal Data


3.1. General Provisions

The Data Controller processes personal data only for lawful, specific and predetermined purposes.

Unless otherwise permitted by Applicable Law, personal data are not processed in a manner incompatible with the purposes for which they were originally collected.

The scope and nature of processing are limited to data objectively necessary to achieve the relevant purpose.


3.2. Providing Access to the Platform

Personal data may be processed for:


3.3. Performance of the Terms of Service

Data are processed for:


3.4. Provision of E-Commerce Functionality

For the purpose of operating e-commerce services, the Data Controller may process personal data for:

This Section does not regulate the commercial terms of Transactions, which are governed by the relevant specialised SASAHUB documents.


3.5. Processing Payments and Financial Operations

When paid Platform services are used, personal data may be processed for:

Processing of information associated with payments is additionally governed by the Payment Policy.


3.6. Communications with Users

Personal data may be used for:

Service-related and legally necessary communications may be sent without separate marketing consent to the extent permitted by law.

Advertising or marketing communications are sent only where an appropriate legal basis exists and, where required by Applicable Law, after obtaining the User's separate consent, with the ability to opt out subsequently.


3.7. Platform Security

Data may be processed for:


Personal data may be processed for:


3.9. Improvement of Platform Services

The Data Controller may use personal data and anonymised information for:

Where consent is required for such processing, it is obtained in the circumstances prescribed by Applicable Law.


3.10. Use of Artificial Intelligence and Automated Processing

For the development and operation of the Platform, the Data Controller may use artificial intelligence and automated data processing technologies for:

Such processing is carried out in accordance with the AI Usage Policy, this Policy and Applicable Law.

Where automated processing may produce legal effects concerning a User or otherwise similarly significantly affect the User, the Data Controller applies the safeguards required by Applicable Law, including rights to information, objection or human review where such rights are provided by law.


3.11. Statistical and Analytical Processing

The Data Controller may use anonymised or aggregated data for:

Unless otherwise provided by law, such data are used in a manner that does not permit identification of a particular User.


3.12. Final Provisions of the Section

This Section applies together with:

This Section defines only the purposes of processing personal data. Legal bases, data categories, retention periods, transfer procedures, User rights and other matters are governed by the relevant Sections of this Policy and specialised SASAHUB documents.


4.1. General Provisions

The Data Controller processes personal data only where a legal basis recognised by Applicable Law exists. The specific legal basis is determined by taking into account the purpose of processing, the category of data, the method by which the data are obtained, the service used and the applicable jurisdiction.

For processing subject to the KVKK, the processing conditions set out, in particular, in Articles 5 and 6 of Law No. 6698 apply. Where the GDPR applies to a particular processing activity, the legal basis is determined in accordance with the relevant provisions of the GDPR.


4.2. Performance of a Contract and Steps Prior to Entering into a Contract

Personal data may be processed where processing is necessary for the conclusion or performance of a contract to which the data subject is a party, including:


The Data Controller may process personal data where necessary to comply with a legal obligation, including requirements arising from:


4.4. Processing Expressly Provided for by Law

Personal data may be processed without separate consent where the relevant processing is expressly provided for by law and all statutory conditions are satisfied.


4.5. Legitimate Interests

Where permitted by Applicable Law, the Data Controller may process personal data for its legitimate interests, including:

This legal basis is used only where the processing does not prejudice the fundamental rights and freedoms of the data subject. Where appropriate, the Data Controller carries out a balancing assessment.


4.6. Establishment, Exercise or Protection of a Right

Personal data may be processed where necessary for the establishment, exercise or protection of a right, including handling claims, resolving disputes, protecting against fraud and conducting judicial or administrative proceedings.


4.7. Data Made Public by the Data Subject

Where permitted by law, the Data Controller may process personal data made public by the data subject on the data subject's own initiative, solely within the scope of the purpose for which they were made public and subject to the principles of proportionality and fairness.


4.8. Protection of Life or Physical Integrity

In circumstances expressly provided for by Applicable Law, personal data may be processed where necessary to protect the life or physical integrity of a person who is physically incapable of giving consent or whose consent is not legally valid.


Where the law requires consent for a specific processing activity, the Data Controller obtains such consent separately, on an informed basis and before the relevant processing begins.

The User may withdraw consent in accordance with Applicable Law. Withdrawal does not affect the lawfulness of processing carried out before withdrawal and does not prevent continued processing where an independent lawful basis exists after withdrawal.


4.10. Special Categories of Personal Data

Special categories of personal data are processed only where a specific legal condition applies and additional security requirements established by Applicable Law are satisfied.

The Data Controller does not use consent as a universal basis for processing special-category data where the law provides another applicable condition or imposes additional requirements.


4.11. International Processing and the GDPR

Where the GDPR applies to a specific processing activity, the Data Controller determines the appropriate legal basis under Article 6 GDPR and, for special categories of personal data, the applicable condition under Article 9 GDPR.

This provision does not mean that the GDPR applies to all SASAHUB processing activities; it applies only where the territorial scope requirements established by the Regulation are met.


Before further processing personal data for a new purpose, the Data Controller assesses the compatibility of that purpose with the original purpose, the availability of an appropriate legal basis and whether additional information must be provided to the User or consent obtained.


4.13. Documentation of Processing

The Data Controller may maintain internal records of processing activities, legal bases, categories of data, recipients, retention periods and security measures for the purposes of internal control, audits, risk management and compliance with Applicable Law.


4.14. Final Provisions of the Section

This Section applies together with:

Specific purposes, data categories, recipients, retention periods and other processing parameters are determined by this Policy, the relevant User journey and specialised official SASAHUB documents.

Section 5. Transfer of Personal Data and International Transfers


5.1. General Provisions

The Data Controller may disclose or transfer personal data to third parties only in the circumstances permitted by this Policy, official SASAHUB documents and Applicable Law.

Any transfer is limited to the extent necessary to achieve the relevant processing purpose and must be supported by an appropriate legal basis.


5.2. Transfers to Service Providers

For the operation of the Platform, the Data Controller may transfer personal data to organisations providing services on behalf of or under instructions from the Data Controller, including:

Such persons may process personal data only within the scope of the authority granted to them and must comply with Applicable Law and contractual confidentiality and security obligations.


5.3. Transfers Between Platform Users

When Platform functionality is used, certain personal data may become available to other Users to the extent necessary to provide the relevant service, including interaction between Buyers and Sellers.

The scope of information disclosed is determined by Platform functionality, User settings and the nature of the relevant operation.


5.4. Transfers Required by Law

The Data Controller may transfer personal data to competent public authorities, courts, law enforcement bodies and other authorised organisations in the circumstances and manner provided by Applicable Law.

Such transfer is limited to the scope of the relevant lawful requirement.


5.5. International (Cross-Border) Transfers of Personal Data

Due to the international nature of SASAHUB's activities, personal data may be transferred to other countries only where there is a lawful basis for the underlying processing and the specific requirements applicable to international transfers are satisfied.

For transfers subject to the KVKK, the Data Controller applies the mechanism established by the current version of Article 9 of Law No. 6698 and relevant secondary legislation. Depending on the circumstances, a transfer may be made:

Where a standard contract prescribed by Turkish law for international transfers is used, the Data Controller complies with the associated mandatory notification requirements to the Kişisel Verileri Koruma Kurumu within the statutory period.

Where the GDPR or the law of another jurisdiction applies to a particular transfer, the corresponding international transfer mechanisms and safeguards required for that transfer are also applied.

This Policy does not, by itself, constitute the User's consent to an international transfer and does not replace any contractual or other safeguards required by law.


5.6. Safeguards for Transfers

When personal data are transferred to third parties, the Data Controller seeks to ensure, as appropriate:


5.7. Transfers in Connection with Corporate Changes

In the event of reorganisation, merger, acquisition, sale of the business, transfer of assets or other corporate changes, personal data may be transferred to the relevant legal successor to the extent necessary for continued operation of the Platform.

The successor must comply with this Policy or provide a level of protection no lower than that required by Applicable Law.


Where Applicable Law requires separate consent to transfer personal data, the transfer is made only after the required consent has been obtained.

The User may withdraw consent in the circumstances and manner provided by law.


5.9. Restrictions on Transfers

The Data Controller does not sell Users' personal data.

Personal data are not transferred to third parties for independent use for their own advertising or other commercial purposes without an independent lawful basis and, where required by law, the User's appropriate consent.

Access by service providers to personal data is limited to what is necessary to perform the assigned function, unless their independent status under Applicable Law requires otherwise.


5.10. Documentation of Transfers

The Data Controller may maintain internal records of personal data transfers for the purposes of:


5.11. Relationship with Specialised Documents

This Section applies together with:

Matters specifically regulated by those documents are governed by the relevant policy.


5.12. Final Provisions of the Section

This Section governs only the general principles applicable to transfers of personal data to third parties and international transfers.

Detailed procedures for data-flow management, access control, internal exchange of information, retention and corporate data governance are determined by the Data Governance Policy, Information Security Policy and other official SASAHUB documents.

Section 6. Retention, Deletion and Anonymisation of Personal Data


6.1. General Provisions

The Data Controller retains personal data only for as long as necessary to achieve the purposes of processing, implement this Policy, comply with legal requirements, protect the legitimate interests of the Data Controller and Users and fulfil other obligations arising under Applicable Law.

When the relevant purposes have been achieved or the legal basis for processing has ceased to exist, personal data are deleted, destroyed, anonymised or otherwise cease to be processed unless continued retention or processing is required by law.


6.2. Retention Periods

Specific retention periods are determined taking into account:

The Data Controller does not establish a single retention period for all categories of personal data because the appropriate period depends on the specific processing purpose.


6.3. Retention of Account Data

Personal data associated with a User Account may be retained throughout the period during which the Platform is used.

After use of the Account ends, data may continue to be retained where necessary:


6.4. Deletion of Personal Data

Personal data are deleted or processing ceases:

Deletion is not carried out where the Data Controller is required to continue processing by law or another valid legal basis remains in effect.


6.5. Anonymisation of Personal Data

The Data Controller may anonymise personal data where permitted by law and consistent with the processing purposes.

Following anonymisation, information may be used for:

When anonymised data are used, the Data Controller takes reasonable measures to prevent identification of a specific User unless otherwise permitted by law.


6.6. Archival Retention

Where provided by law or internal document-management procedures, the Data Controller may retain certain categories of information in archives.

Archival retention is permitted solely for:


6.7. Backups

To ensure business continuity and protect information, the Data Controller may create backup copies of data.

Backups are used solely for:

Personal data contained in backups are processed in accordance with this Policy and Applicable Law.


6.8. Restriction of Processing

Where Applicable Law grants a User the right to request restriction of personal data processing, the Data Controller considers the request and takes the appropriate decision in accordance with Applicable Law.

During a period of restricted processing, the data may continue to be stored to the extent permitted by law.


6.9. Documentation of Retention and Deletion Operations

The Data Controller may maintain internal records relating to:

Such documentation is used solely for legal compliance, internal control, audit and information security.


6.10. Relationship with Specialised Documents

This Section applies together with:

Matters specifically regulated by those documents are governed by the relevant policy.


6.11. Final Provisions of the Section

This Section establishes general principles for the retention, deletion, anonymisation and restriction of processing of personal data.

Detailed procedures for data lifecycle management, backups, archiving, information destruction and corporate data governance are determined by the Data Controller's internal rules and specialised official SASAHUB documents.

official SASAHUB documents.

Section 7. Data Subject Rights


7.1. General Provisions

The Data Controller respects the rights of data subjects and enables them to exercise those rights in accordance with Applicable Law.

The scope of specific rights depends on the applicable jurisdiction and the legal basis for processing. For data subjects whose data are subject to the KVKK, the rights set out in Article 11 of Law No. 6698 are taken fully into account. Where the GDPR applies to a particular processing activity, the rights provided by the GDPR are additionally available to the extent its conditions apply.


7.2. Rights under Article 11 of the KVKK

Where the KVKK applies, a data subject may apply to the Data Controller and has the right to:


7.3. Additional Rights Where the GDPR Applies

Where the GDPR applies to a specific processing activity and the relevant conditions are satisfied, a data subject may, in particular, have the right:

These rights are not absolute and apply subject to the conditions and exceptions established by law.


7.4. Information about Sources and Recipients

To the extent provided by Applicable Law, a User may request information concerning the categories of data processed, the purposes and legal bases of processing, the retention period or criteria used to determine it, the sources from which data were obtained and the categories of recipients, including information concerning international transfers.


7.5. Rectification, Deletion and Restriction of Processing

The Data Controller considers requests for rectification, deletion, destruction, anonymisation or restriction of processing in accordance with Applicable Law.

Such requests may be refused in whole or in part where continued processing is necessary, for example, to comply with a legal obligation, perform a contract, establish or defend a right, ensure security or on another independent lawful basis.


Where processing is based on consent, the User may withdraw that consent. Withdrawal operates prospectively and does not affect the lawfulness of processing carried out before the Data Controller receives the withdrawal.

Where Applicable Law provides a right to object to processing, the Data Controller considers the objection in light of the relevant legal basis, the nature of the processing and any mandatory exceptions.


7.7. Automated Decisions

Where Applicable Law gives a data subject the right to challenge a result arising exclusively from automated processing, the User may submit an appropriate request to the Data Controller.

Where required by law, the Data Controller provides the opportunity for human review, an explanation or the User's expression of their position.


7.8. Procedure for Applications under the KVKK

To exercise rights under Article 11 of the KVKK, a data subject may submit an application to the Data Controller using methods permitted by current Turkish law, including:

An application must contain the information necessary to identify the applicant and understand the request. The Data Controller may request additional information only to the extent necessary to verify identity and prevent unauthorised disclosure of personal data.

Where required by the Turkish rules governing applications to a data controller, a formal application must be submitted in Turkish.


7.9. Response Period

Applications under the KVKK are handled as soon as possible according to the nature of the request and, in any event, no later than 30 days after receipt of a valid application, unless a different period is established by law.

Where the GDPR applies, data subject requests are handled within the time limits established by the GDPR.


7.10. Cost of Requests

Data subject requests are handled free of charge unless Applicable Law expressly permits otherwise. Where the law allows a fee in exceptional circumstances, any such fee is determined only in the manner prescribed by law.


7.11. Right to Apply to a Competent Authority

If a User believes that their rights have been infringed, the User may use the remedies provided by law, including applying to the Kişisel Verileri Koruma Kurumu/Kurulu, a competent court or another supervisory authority where the relevant jurisdiction applies.

The procedure and time limits for complaints are determined by Applicable Law.


7.12. Security in Handling Requests

To protect personal data, the Data Controller may verify the applicant's identity, limit disclosure where necessary to protect the rights and freedoms of others, trade secrets and other legitimate interests, and use secure channels to provide a response.

Such limitations must not be used to unjustifiably refuse the exercise of lawful data subject rights.


7.13. Contact Details for Requests

Data Controller / Veri Sorumlusu:
SHAMUS E‑TİCARET LOJİSTİK VE GIDA TİCARET LİMİTED ŞİRKETİ

Postal address:
Cevizli Mah. Mustafa Kemal Cad. Hukukçular Towers Sitesi A Blok No: 66A İç Kapı No: 111 Kartal / İstanbul, Türkiye

Personal data email: privacy@sasahub.com.tr
Legal matters: legal@sasahub.com.tr


7.14. Relationship with Specialised Documents

This Section applies together with:


7.15. Final Provisions of the Section

Detailed internal procedures for verifying applicants, recording applications, fulfilling requests, identity verification and retaining evidence of compliance are determined by the Data Controller's internal rules and Applicable Law.

Section 8. Protection of Personal Data


8.1. General Provisions

The Data Controller takes reasonable organisational, technical and administrative measures to ensure the security of personal data and to prevent accidental or unlawful loss, destruction, alteration, disclosure, unauthorised access or other unlawful processing.

Security measures are determined taking into account the nature of the data processed, potential risks, technologies used and the requirements of Applicable Law.


8.2. Security Principles

When organising personal data processing, the Data Controller applies the following security principles:


8.3. Organisational and Administrative Measures

The Data Controller may apply organisational and administrative safeguards including:


8.4. Technical Safeguards

To protect personal data, the Data Controller may use current technical safeguards including:

This Section does not disclose the specific architecture of the security system where such disclosure could reduce Platform security.


8.5. Restriction of Access to Data

Access to personal data is granted only to persons who require such access to perform their job duties or contractual obligations.

All persons with access to personal data must comply with confidentiality requirements and Applicable Law.


8.6. Response to Security Incidents and Personal Data Breaches

The Data Controller maintains internal procedures for detecting, analysing, containing, documenting and remediating information security incidents.

Where personal data are unlawfully obtained by third parties or another incident occurs that is subject to a mandatory notification requirement, the Data Controller:

For incidents subject to the KVKK, notification to the Kişisel Verileri Koruma Kurulu is made without undue delay and, in accordance with the applicable practice of the Kurul, generally no later than 72 hours after the Data Controller becomes aware of the breach; affected data subjects are informed within a reasonably prompt period after they have been identified.

Where the GDPR applies, the Data Controller complies with the GDPR requirements concerning personal data breaches, including the applicable notification criteria and time limits.


8.7. Monitoring and Audit

The Data Controller may conduct:


8.8. User Responsibilities

The User also participates in protecting the security of their personal data and undertakes to:


8.9. Use of Service Providers

Where personal data are processed with the involvement of third parties, the Data Controller takes reasonable measures to ensure their compliance with confidentiality, information-security and Applicable Law requirements.


8.10. Continuous Improvement of the Security System

The Data Controller may regularly review and improve organisational and technical safeguards for personal data taking into account:


8.11. Relationship with Specialised Documents

This Section applies together with:

Matters specifically regulated by those documents are governed by the relevant policy.


8.12. Final Provisions of the Section

This Section establishes general principles for protection of personal data.

Detailed requirements concerning information-security architecture, technical safeguards, access management, incident response, backups, data recovery and risk management are governed by the Information Security Policy, Business Continuity & Disaster Recovery Policy and other specialised SASAHUB documents.

Section 9. Use of Cookies and Similar Technologies


9.1. General Provisions

To operate the SASAHUB Platform, the Data Controller may use Cookies and similar technologies that support correct service operation, security, analysis of Platform use and improvement of User experience.

This Section establishes general principles for the use of such technologies. Detailed rules are governed by the separate Cookie Policy.


9.2. Purposes of Using Cookies

Cookies and similar technologies may be used for:

Cookies are used only for lawful purposes.


9.3. Categories of Technologies Used

Depending on their purpose, the Platform may use different categories of Cookies and similar technologies, including:

The specific classification and description of each category are provided in the Cookie Policy.


9.4. Use of Third-Party Services

Certain Platform functions may use technologies provided by third parties, including analytics, security, payment infrastructure, cloud solutions and other service providers.

Such technologies are used in accordance with this Policy, the Cookie Policy, agreements with the relevant providers and Applicable Law.


The User may manage the use of Cookies through:

Disabling certain categories of Cookies may affect the availability or proper operation of certain Platform functions.


Where Applicable Law requires consent for the use of certain categories of Cookies or similar technologies, the Data Controller obtains such consent before the relevant processing begins.

The User may change preferences or withdraw consent in accordance with the Cookie Policy and Applicable Law.

Withdrawal of consent does not affect the lawfulness of processing carried out before the Data Controller receives the withdrawal.


9.7. Use of Analytics Data

Information collected through Cookies and similar technologies may be used for:

Where possible and appropriate, such information is used in aggregated or anonymised form.


9.8. Protection of Information

Information obtained through Cookies and similar technologies is processed using reasonable organisational and technical safeguards in accordance with this Policy, the Information Security Policy and Applicable Law.


9.9. International Use of Technologies

Where the use of a particular technology involves an international transfer of information, that processing is carried out in accordance with the international transfer provisions of this Policy and Applicable Law.


9.10. Relationship with Specialised Documents

This Section applies together with:

Matters specifically regulated by the Cookie Policy are governed by that policy.


9.11. Final Provisions of the Section

This Section governs only the general principles applicable to Cookies and similar technologies.

Detailed Cookie categories, retention periods, technologies used, procedures for obtaining and withdrawing consent and management of User preferences are determined by the Cookie Policy.

Section 10. Processing Personal Data of Minors


10.1. General Provisions

The SASAHUB Platform is intended primarily for use by adults, legal entities and their authorised representatives.

The Data Controller recognises that personal data relating to minors require additional protection and takes reasonable measures to comply with Applicable Law.


10.2. Age Restrictions

Use of certain Platform services may be subject to age requirements established by Applicable Law or the Terms of Service.

Where the law requires consent from a parent, legal representative or guardian for processing personal data relating to a minor, such consent must be obtained before the relevant processing begins.


10.3. No Intentional Collection of Children's Data

The Data Controller does not intentionally collect personal data relating to children unless the relevant service is specifically intended for minors or such processing is otherwise permitted by Applicable Law.


10.4. Voluntary Provision of Information

Where a minor or another person provides personal data without satisfying applicable legal requirements, the Data Controller may:


Legal representatives of minors may contact the Data Controller to request:

The Data Controller may request documents confirming the authority of the legal representative.


10.6. Additional Safeguards

When processing personal data relating to minors, the Data Controller applies additional organisational and technical safeguards to the extent required by Applicable Law and appropriate to the nature of the services provided.


10.7. International Nature of Processing

Where the Platform is used in different countries, the age at which a person may independently consent to processing of their personal data is determined by the law of the relevant jurisdiction.

Where Applicable Law provides a higher level of protection for minors, those mandatory provisions apply.


10.8. Accuracy of Age Information

The User or the User's legal representative is responsible for the accuracy of age information provided during registration and use of the Platform.

Where the Data Controller had no objective means of determining that such information was inaccurate, it shall not be liable for consequences arising from the provision of inaccurate information except where mandatory Applicable Law provides otherwise.


10.9. Relationship with Specialised Documents

This Section applies together with:

Matters specifically regulated by those documents are governed by the relevant provisions.


10.10. Final Provisions of the Section

This Section establishes general principles for processing personal data relating to minors.

If SASAHUB introduces services specifically intended for children or minors in the future, the Data Controller may adopt an additional privacy policy for such services. Until such a policy is adopted, this Policy and mandatory Applicable Law apply.

Section 11. Amendments, Contact Information and Final Provisions


11.1. General Provisions

This Privacy Policy is an official SASAHUB document governing the processing of Users' personal data.

The Policy applies together with the Terms of Service and other official SASAHUB documents governing specific aspects of Platform activities.


11.2. Amendments to the Policy

The Data Controller may amend, supplement or update this Policy for the purposes of:

Amendments are made in good faith and may not arbitrarily restrict data subject rights granted by mandatory law.


11.3. Publication of a New Version

The current version of this Policy is published on the official SASAHUB website, in the official mobile application or on another official electronic resource designated by the Data Controller.

Where appropriate, the Data Controller may additionally notify Users by:


11.4. Entry into Force of Amendments

Unless otherwise required by law or specified in the new version of the Policy, amendments enter into force on the date stated by the Data Controller upon publication.

Where Applicable Law requires advance notice or User consent, those requirements are satisfied before the relevant amendments take effect.


11.5. Contact Information

For matters concerning personal data processing and this Policy, the Data Controller may be contacted at:

SHAMUS E‑TİCARET LOJİSTİK VE GIDA TİCARET LİMİTED ŞİRKETİ
Cevizli Mah. Mustafa Kemal Cad. Hukukçular Towers Sitesi A Blok No: 66A İç Kapı No: 111 Kartal / İstanbul, Türkiye

Privacy / personal data: privacy@sasahub.com.tr
Legal matters: legal@sasahub.com.tr
Security reports: security@sasahub.com.tr
General support: support@sasahub.com.tr

MERSİS No: 0768110028600001
Trade Registry No: 1114861
Tax Identification No: 7681100286
Tax Office: Kartal Vergi Dairesi

Formal data subject rights applications are submitted using the methods set out in Section 7 of this Policy.


11.6. Handling of Requests

The Data Controller records and handles requests relating to processing of personal data in accordance with the procedures and time limits established by Applicable Law.

Requests subject to the KVKK are answered as soon as possible according to the nature of the request and no later than 30 days after receipt of a valid application.

Where necessary, the Data Controller may request additional information solely to verify the applicant's identity, clarify the scope of the request or protect personal data from unauthorised disclosure.


11.7. Cooperation with Competent Authorities

The Data Controller may cooperate with public authorities, personal data protection authorities, courts and other authorised organisations in the circumstances and manner provided by Applicable Law.

Such cooperation is limited to the relevant legal powers and requirements.


11.8. International Application of the Policy

This Policy applies taking into account the international nature of SASAHUB's activities.

Where the law of a relevant jurisdiction provides a higher level of personal data protection than this Policy, the mandatory provisions of that law apply.


11.9. Priority of Language Versions

This Policy is published in Russian, Turkish and English.

Because the Data Controller is a legal entity incorporated in Türkiye, the Turkish version is the official and controlling version for SASAHUB corporate publication, unless mandatory Applicable Law requires otherwise.

The Russian and English versions are officially published translations intended to make the document accessible to international Users. In the event of an inconsistency of interpretation between language versions, the Turkish version prevails to the extent permitted by Applicable Law.

No language provision limits any data subject right that cannot lawfully be restricted by contract or policy.


11.10. Relationship with Official SASAHUB Documents

This Policy applies together with:

Where a particular matter is specifically regulated by another policy, the provisions of that document apply within the scope of the matter it regulates.


11.11. Entry into Force of the Policy

This Privacy Policy v1.1 enters into force on the date of its official publication by the Data Controller and remains effective until a new version is adopted or it is withdrawn in accordance with Applicable Law.


11.12. Final Provision

This Privacy Policy v1.1 is SASAHUB's general public policy concerning privacy and the processing of personal data.

It applies together with specific privacy notices, KVKK Aydınlatma Metinleri, consent forms, the Cookie Policy and other specialised documents where their use is required for a particular processing activity.

Matters not governed by this Policy are subject to the relevant official SASAHUB documents and mandatory provisions of Applicable Law.