Personal Data Protection & Processing Policy

(Modalco)

Data Controller: Modalco
Address: Karşıyaka mh. Odabaşı cd. No:4089/3 Mamak/Ankara
E-mail: info@modalco.com
Web: modalco.com

1. Purpose and Scope

This Policy determines the procedures and principles regarding Modalco’s data processing activities (including website, membership/order, call center, marketing, supplier, and employee processes) in accordance with the Personal Data Protection Law No. 6698 (“KVKK”) and relevant legislation. The Policy covers all natural persons such as customers, visitors, members/subscribers, supplier/business partner representatives, and job candidates.

2. Definitions

Personal Data: Any information relating to an identified or identifiable natural person.
Sensitive Personal Data: Race, ethnic origin, health, etc. (Modalco does not process sensitive personal data; additional measures in accordance with legislation are applied in mandatory cases).
Processing: Any operation performed on data such as obtaining, recording, storing, modifying, transferring, etc.
Explicit Consent: Consent regarding a specific subject, based on information, and disclosed with free will.

3. Fundamental Principles (KVKK Art. 4)

  • Compliance with the law and principles of good faith

  • Being accurate and up-to-date

  • Being for specific, explicit, and legitimate purposes

  • Being relevant, limited, and proportionate to the purpose of processing (minimization)

  • Being retained for the duration stipulated in the relevant legislation or required for the purpose

4. Data Categories and Data Subject Groups

  • Identity/Contact: Name-surname, phone, e-mail, address (customer/member/visitor/supplier representative/candidate).

  • Customer Transaction: Cart, order, return/cancellation, support records.

  • Finance/Payment: Invoice information; card data is with the payment provider, and is not stored in Modalco systems.

  • Marketing: Newsletter subscription, permission/refusal preferences, campaign interactions.

  • Transaction Security/Technical: IP, device/browser information, logs, error/crash data.

  • Online Identifiers/Cookies: Strictly necessary, performance, functional, and advertising/targeting cookie data.

5. Processing Purposes and Legal Grounds

Purposes: Order and delivery processes; customer support; membership/account management; financial/tax obligations; fraud and security; business/product development; communication and commercial electronic messages (with consent); website analytics and advertising activities (with consent).
Legal grounds:

  • Conclusion/performance of a contract (KVKK Art. 5/2-c)

  • Legal obligation (Art. 5/2-ç)

  • Establishment/exercise/protection of a right (Art. 5/2-e)

  • Legitimate interest (Art. 5/2-f)

  • Explicit consent (Art. 5/1) – marketing/retargeting cookies and commercial messages

6. Collection Methods

  • Directly: Membership/order/contact forms, call center.

  • Automated means: Cookies, analytics and advertising tags, logs.

  • From third parties: Payment providers/banks, shipping/logistics, communication and IT service providers.

7. Transfers and International Transfer

Data may be shared, limited to the principle of purpose and proportionality, with Shopify (e-commerce hosting), payment institutions/banks, shipping/logistics, IT/Cloud, analytics and communication services, call center, and legally authorized public institutions.
International transfer requirements are handled in accordance with KVKK Art. 9; data is transferred to countries with adequate protection; otherwise, explicit consent is obtained or commitment mechanisms accepted by the Board are applied.

8. Storage and Destruction

Data is kept in accordance with the periods stipulated in the legislation and Modalco Storage and Destruction Procedure; upon expiration, it is deleted, destroyed, or anonymized. Example periods:

  • Order/invoice records: 10 years

  • Customer support records: 3 years

  • Marketing permission/refusal records: Permission validity + 3 years

9. Security Measures

Technical: TLS/HTTPS, HSTS; encryption and password hashing; access authorization (least-privilege, MFA); WAF and rate limiting; DDoS/security audits; logging/monitoring; patch and vulnerability management; regular penetration tests; backups.
Administrative: Authorization matrix; confidentiality agreements; KVKK provisions in supplier contracts (DPA); staff training; incident response and business continuity plans; logging of access requests.

10. Sensitive Personal Data

Modalco does not normally process sensitive personal data. In mandatory and legally required cases (e.g., submission of health reports), additional security measures in compliance with Board decisions and Art. 6 are taken, and access is restricted with strict authorization.

11. Cookies and Similar Technologies

Cookie usage, types/durations, and preference management are detailed in the Cookie Policy. Cookies other than strictly necessary ones are subject to explicit consent; they can be managed via the consent panel.

12. Data Subject Rights and Application

In accordance with KVKK Art. 11, you have the rights to learn whether personal data is processed, request information, rectify/delete, learn the third parties to whom data is transferred, object, and demand compensation in case of damage.
Application channels:

  • E-mail: info@modalco.com

  • Mail: Karşıyaka mh. Odabaşı cd. No:4089/3 Mamak/Ankara – “KVKK Information Request”
    Applications are concluded within 30 days at the latest depending on their nature; if additional costs arise, the Board's tariff may be applied.

13. Relationship with the Clarification Text

This Policy is evaluated together with the KVKK Clarification Text published on the Site. The Clarification text concretely explains which data is processed for which purposes, based on which legal grounds, and the storage periods.

14. Suppliers and Data Processors

Data processing agreements (DPA) are made with all suppliers processing data on behalf of Modalco; technical/administrative measures are contractually guaranteed and regularly audited.

15. Audit, Training, and Awareness

Periodic internal audits are conducted for KVKK compliance; initial and regular awareness training are provided to employees. Compliance with the Policy is supported by senior management.

16. Data Breach Management

Upon detection of a breach affecting personal data, the Incident Response Plan is implemented; risk mitigation measures are taken; notification to the Board and affected persons is made within a reasonable time.

17. Publication, Enforcement, and Updates of the Policy

The Policy is published on the Site and updated as necessary. The most current version is accessible at www.modalco.com.


APPENDIX-1 — Sample Data Inventory (summary table)

Data Category Data Subject Group Purpose Legal Ground Storage Period Recipient/Transfer
Identity/Contact Customer/Member Order, delivery, support Art. 5/2-c, ç, f 10 years (invoice); 3 years (support) Shipping, payment, IT/Cloud
Customer Transaction Customer/Member Order, return/cancellation Art. 5/2-c 10 years IT/Cloud, call center
Marketing Member/Subscriber Campaign/message Art. 5/1 (consent) Permission validity + 3 years E-mail/SMS providers
Transaction Security Visitor/Member Security, abuse prevention Art. 5/2-f 2 years (log) Security/IT services
Cookie Data Visitor/Member Analytics & advertising Necessary: Art. 5/2-f; Others: Art. 5/1 Duration of cookie Analytics/Advertising suppliers

APPENDIX-2 — Summary of Application Methods

  • E-mail/post with the subject “KVKK Information Request”

  • Information required for identity verification

  • Response within 30 days depending on the nature of the request