Protection of Personal Data

This privacy policy has been prepared by Vimesoft A.Ş., acting as the data controller, pursuant to Article 10 of Law No. 6698 on the Protection of Personal Data (the “Law”) and the Communiqué on the Procedures and Principles to Be Followed in Fulfilment of the Obligation to Inform.

Vimesoft A.Ş. takes the necessary technical and administrative measures, using its technological and infrastructural capabilities, to ensure the secure storage and lawful processing of personal data and to fulfil its obligations regarding data security under Article 12 of Law No. 6698 on the Protection of Personal Data.

Personal data is processed by Vimesoft A.Ş. in accordance with the Law and applicable legislation. Natural persons whose personal data is processed within the scope of the Law may obtain information regarding the personal data that may be processed by Vimesoft A.Ş. in its capacity as data controller, the purposes of processing, the recipient groups to whom such data may be transferred, the methods and legal grounds for collection, and their rights in relation to such personal data.

Personal Data Processed or That May Be Processed

Although the personal data processed within the products and services offered by Vimesoft A.Ş. may vary from person to person, the categories of personal data that may generally be processed by Vimesoft A.Ş. are listed below:

Identity Data: This category includes the individual’s first name and surname.

Contact Data: This category includes the individual’s mobile phone number, e-mail address, address, province/district, postal code, tax office and tax identification number.

Employment Data: This category includes information regarding the institution or organization where the individual works.

Transaction Security Data: This category includes user identification information, passwords and verification codes.

Visual and Audio Records: This category includes photographs, camera images and audio data.

Financial Data: This category includes the name and surname appearing on the credit card, credit card number, expiration date and card security code.

Purposes of Processing Personal Data

The personal data listed below is processed within the products and services offered by Vimesoft A.Ş. for the following purposes:

Contact Data: The individual’s mobile phone number is processed for the purposes of conducting service purchase processes and managing access authorizations. The e-mail address is processed for conducting service purchase processes, managing access authorizations and providing services. Address, province/district, postal code, tax office and tax identification number are processed for conducting finance and accounting activities and service sales processes.

Employment Data: Information regarding the institution or organization where the individual works is processed for conducting service purchase processes and marketing processes relating to products and services.

Transaction Security Data: User identification information and verification codes are processed for managing access authorizations, while password information is processed for conducting service purchase processes and managing access authorizations.

Visual and Audio Records: Photographs, camera images and audio data are processed for the purpose of providing services.

Financial Data: The name and surname appearing on the credit card, credit card number, expiration date and security code are processed for conducting service sales processes and finance and accounting activities.

Transfer of Personal Data

Collected personal data may be transferred, in accordance with the fundamental principles set forth in the Law and the personal data transfer requirements specified in Articles 8 and 9 of the Law, and for the purposes stated below, to legally authorized public institutions and organizations, natural persons or private-law legal entities located in Türkiye or abroad, suppliers with whom Vimesoft A.Ş. establishes a business relationship, and service providers.

Identity Data: The individual’s first name and surname may be transferred to suppliers providing the infrastructure used for the membership process and to other users during the provision of services.

Contact Data: The individual’s mobile phone number and e-mail address may be transferred to suppliers providing the infrastructure on which the system is hosted for membership registration and application login processes, to SMS service providers for sending membership activation notifications, and to e-mail service providers for delivering invoices containing address, province/district, postal code, tax office and tax identification information generated following billing.

Employment Data: Information regarding the institution or organization where the individual works may be transferred to suppliers providing the infrastructure on which the system is hosted for membership and application login processes.

Transaction Security Data: User identification information and verification codes may be transferred to SMS service providers for the purpose of enabling the user to initiate membership through SMS services. User passwords may be transferred to suppliers providing the infrastructure on which the system is hosted for application login processes.

Visual and Audio Records: The individual’s photograph may be transferred to suppliers providing the infrastructure on which the system is hosted for profile customization purposes. Camera images and audio data may be transferred to other participants during the provision of services.

Financial Data: The name and surname appearing on the credit card, credit card number, expiration date and security code may be transferred for the purpose of using payment services during the membership process.

Method and Legal Basis for Collecting Personal Data

Personal data may be collected through electronic environments such as the application membership page, quotation request form, payment information page, profile page, conference creation and invitation page, and conference screen, as well as through voice communication, by fully automated, partially automated or non-automated means. Such data may be processed and transferred for the purposes stated in this Policy.

Pursuant to Article 5 of the Law, Vimesoft A.Ş. may process personal data lawfully without obtaining explicit consent in the following circumstances:

  • Where expressly provided for by law,

  • Where processing is necessary to protect the life or physical integrity of the data subject or another person who is unable to express consent due to physical impossibility, or whose consent is not legally valid,

  • Where processing of personal data belonging to the parties to a contract is necessary, provided that it is directly related to the establishment or performance of a contract between Vimesoft A.Ş. and the Personal Data Subject,

  • Where processing is necessary for Vimesoft A.Ş. to fulfil its legal obligations,

  • Where the personal data has been made public by the Personal Data Subject,

  • Where processing is necessary for the establishment, exercise or protection of a right,

  • Where processing is necessary for the legitimate interests of Vimesoft A.Ş., provided that such processing does not prejudice the fundamental rights and freedoms of the Personal Data Subject.

In addition, pursuant to Article 6 of the Law, Vimesoft A.Ş. may process special categories of personal data lawfully without obtaining explicit consent in the circumstances permitted by applicable law.

Special categories of personal data include data relating to a person’s race, ethnic origin, political opinions, philosophical beliefs, religion, sect or other beliefs, appearance and clothing, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.

Special categories of personal data other than data relating to health and sexual life may be processed where such processing is expressly provided for by law.

Personal data relating to health and sexual life may only be processed, without explicit consent, by persons under an obligation of confidentiality or by authorized institutions and organizations for the purposes of protecting public health, preventive medicine, medical diagnosis, treatment and care services, and the planning and management of healthcare services and their financing.

Rights of the Personal Data Subject

Pursuant to Article 11 of the Law, the Personal Data Subject may apply to the data controller at any time and exercise the following rights:

  • To learn whether their personal data is being processed,

  • To request information if their personal data has been processed,

  • To learn the purpose of processing their personal data and whether it is being used in accordance with that purpose,

  • To know the third parties to whom their personal data has been transferred, whether in Türkiye or abroad,

  • To request correction of personal data if it has been processed incompletely or inaccurately,

  • To request deletion or destruction of personal data where the reasons requiring its processing no longer exist, taking into account the principles of purpose, duration and legitimacy,

  • To request the deletion, destruction or anonymization of personal data where the reasons requiring its processing no longer exist, even if such data has been processed in accordance with Law No. 6698 on the Protection of Personal Data and other applicable legislation,

  • To request that third parties to whom personal data has been transferred be notified of any correction, deletion or destruction carried out in relation to such data,

  • To object to the occurrence of a result against the individual arising from the analysis of processed data exclusively through automated systems,

  • To claim compensation for damages suffered as a result of the unlawful processing of personal data.

How to Exercise the Rights of the Personal Data Subject

In order to exercise the rights set out above under Article 11 of the Law, the Personal Data Subject must complete the application form in full and submit it to Vimesoft A.Ş. through the communication channels specified in the form.

Vimesoft A.Ş. will process and conclude the request free of charge as soon as possible and no later than thirty (30) days, depending on the nature of the request. However, where the processing of the request incurs an additional cost, Vimesoft A.Ş. reserves the right to charge the fee determined in the tariff published by the Personal Data Protection Board.

Retention Periods for Personal Data

Personal data processed for the purposes specified in this Privacy Policy in accordance with the Law will be deleted, destroyed or anonymized by Vimesoft A.Ş. when the purpose requiring its processing no longer exists pursuant to Article 7 of the Law and/or when the applicable statutory limitation and retention periods requiring Vimesoft A.Ş. to process such data have expired.