SİPAY ELEKTRONİK PARA VE ÖDEME HİZMETLERİ A.Ş.
PRIVACY AND INFORMATION SECURITY POLICY
Pursuant to Law No. 6493 on Payment and Securities Settlement Systems, Payment Services and Electronic Money Institutions and the applicable secondary legislation, Sipay Elektronik Para ve Ödeme Hizmetleri A.Ş. (“Sipay”) regards protecting the confidentiality, integrity and availability of its customers’, users’, business partners’ and other service recipients’ personal data and financial information as one of its fundamental principles. Sipay provides its services with a commitment to achieving the highest level of customer satisfaction, adopting a customer-first approach and fostering mutual trust.
Sipay is committed to safeguarding information obtained through the services it provides via its website, mobile applications, API infrastructure, payment solutions, virtual point-of-sale (POS) services, electronic money services, open banking services and all electronic service channels currently available or introduced in the future, and to processing that information in accordance with applicable legislation.
In compliance with the legal requirements by which it is bound, Sipay implements the measures necessary to maintain the confidentiality and security of customer information at the highest level and applies the practices set out below.
PROCESSING OF INFORMATION
Information obtained by Sipay is processed for the following purposes;
Further information concerning the processing of personal data is provided in the “Privacy Notice on the Protection of Personal Data”.
PROTECTION OF INFORMATION
Sipay continuously develops its technical and organisational measures to safeguard the confidentiality of its customers’ personal data, financial information and transaction records.
Within this framework, Sipay;
INFORMATION SECURITY PRINCIPLES
Sipay conducts its information-security activities in accordance with the following fundamental principles:
SHARING INFORMATION WITH THIRD PARTIES
Sipay may share personal data;
Sipay takes care to ensure that third parties providing support services maintain appropriate information-security standards and puts the necessary contractual obligations in place.
PROTECTION OF PERSONAL DATA
Sipay processes personal data;
Where explicit consent is required, personal data will not be processed unless the data subject’s explicit consent has first been obtained.
INFORMATION SECURITY
Sipay has established processes for identifying, reporting, assessing and remediating incidents that may affect the security of personal data or information assets.
If a personal data breach occurs, the notifications required under applicable legislation will be made to the competent authorities and affected data subjects within the prescribed time limits.
Sipay shall not be liable for any direct or indirect loss, damage or expense arising from any interruption, delay in the provision of information, computer virus or system failure that may occur while the digital platforms are being used. Where such circumstances are not attributable to Sipay, Sipay shall not be liable for claims made by Digital Platforms users under applicable legislation or in connection with Personal Data Protection Law No. 6698 (“PDPL”) and its implementation.
The information contained on the has been prepared in accordance with applicable legislation. However, changes in practice may affect the accuracy of that information. The information is provided solely for information purposes and does not constitute an offer and/or acceptance under any circumstances.
Personal data relating to customers, whether collected through the Digital Platforms or otherwise processed by Sipay in connection with the provision of its products and services, shall not be disclosed to any third party without the customer's explicit consent, except where such disclosure is required or permitted under applicable laws or requested by competent public authorities in accordance with the applicable legal procedures.
All copyright, trade mark, patent and other intellectual and industrial property rights in the information and materials available on the Digital Platforms, other than materials belonging to third parties, vest in Sipay or in such natural or legal persons as Sipay may designate.
User information shared with Sipay by customers may be disclosed in accordance with the PDPL where requested by public institutions or authorities authorised to access that information.
Where Sipay considers it necessary, it may obtain support services from other organisations. Pursuant to Law No. 6493 and applicable legislation, Sipay ensures that those organisations comply with its privacy standards and requirements.
Sipay assumes no liability, and no fault may be attributed to it, for any adverse consequences relating to information security or privacy arising from links provided on Sipay’s Digital Platforms to other platforms. Sipay shall not be responsible for any material or non-material loss that may be sustained through such platforms.
By accessing Sipay’s Digital Platforms, users are deemed to have accepted the conditions set out above. Sipay reserves the right to amend and update the terms and conditions contained in this legal notice without prior notice.
SECURITY TIPS
POTENTIAL THREATS
Stay informed about virus attacks and other similar online-security threats so that you can take appropriate precautions.
Virus Attacks: Your computers, smartphones and tablets may be exposed to viruses through various means, including:
Phishing Attacks: Phishing attacks generally involve sending users enticing fraudulent messages by email, such as notifications concerning unusually high bills, gifts, discounts, promotions or prizes, with the intention of stealing sensitive data such as credit card details, identification information, Turkish Identification Numbers and customer numbers. Fraudsters may use this information for various purposes and may seek to cause material or non-material harm. Phishing attacks commonly take the form of fraudulent emails that appear to have been sent by financial institutions and create a false sense of urgency or importance.
Measures to Take Against Phishing Attacks: One of the most effective ways of protecting yourself against phishing attacks is to verify that any website to which an email directs you uses “https” and has a valid security certificate. Do not click URL links contained in suspicious emails.
If you encounter any fraud or suspicious transaction, or have any questions or requests concerning this Policy, you may contact Sipay Elektronik Para ve Ödeme Hizmetleri A.Ş. through the contact channels provided on our website.
PRIVACY NOTICE ON THE PROCESSING OF PERSONAL DATA
This Privacy Notice has been prepared by Sipay Elektronik Para ve Ödeme Hizmetleri Şirketi (“the Company”) in relation to the personal data of customers who open an account through the mobile application or website offered by the Company under the name “SiPay” (together, the “SiPay Application”) (“Customer”), for the purposes of ensuring that such personal data are processed in accordance with the Constitution of the Republic of Turkey, the international treaties concerning human rights to which Turkey is a party and the applicable legislation, particularly the Personal Data Protection Law No. 6698 (“PDPL”), and that data subjects whose personal data are processed are able to exercise their rights effectively. All personal data shared with the Company may be processed lawfully, in a manner relevant to and proportionate to the purposes of our activities and services.
The terms “personal data”, “special category personal data” and “processing of personal data” used in this Privacy Notice have the meanings assigned to them under the PDPL. Under the PDPL, “personal data” means any information relating to an identified or identifiable natural person; “special category personal data” means data concerning a person’s race, ethnic origin, political opinions, philosophical beliefs, religion, religious sect or other beliefs, appearance and clothing, membership of an association, foundation or trade union, health, sexual life, criminal convictions and security measures, and biometric and genetic data; and “processing of personal data” means any operation performed on personal data, including collection, recording, storage, retention, alteration, reorganisation, disclosure, transfer, acquisition, making available, classification or restriction of use, whether wholly or partly by automated means or by non-automated means, provided that the operation forms part of a data filing system.
The Company handles transfers of personal data in accordance with the provisions of the PDPL. Subject to the exceptions prescribed by law, we do not transfer personal data or special category personal data to other natural or legal persons without the data subject’s explicit consent. Where an exception under the PDPL or other applicable legislation applies, the utmost care is taken to ensure that transfers of personal data to authorised administrative or judicial authorities or private organisations comply with the procedural requirements and limitations prescribed by law.
For the purpose of fulfilling its statutory obligations, the Company may transfer your personal data to authorised public authorities and bodies and to private persons authorised by law, in accordance with the procedures and principles prescribed by applicable legislation and the conditions and purposes for the transfer of personal data set out in Article 8 of the PDPL.
Subject to compliance with Article 8 of the PDPL, entitled “Transfer of Personal Data”, and/or Article 9, entitled “Transfer of Personal Data Abroad”, and provided that the necessary technical and organisational measures are implemented, your personal data may, solely to the extent required to achieve the relevant purpose and strictly for the purposes set out below, be transferred to our affiliates and subsidiaries; to business partners engaged under our contracts, in accordance with applicable legislation, to provide bulk SMS and email distribution services; to our suppliers and authorised service centres for the relevant products where required for after-sales services; and to authorised persons and public authorities where required by law for us to fulfil our statutory obligations. Your personal data may also be recorded in programmes and/or systems provided or made available for our use by our technology infrastructure suppliers.
We process the personal data included in the processes set out below for the specified processing purposes, in accordance with the general principles laid down in Article 4 of the PDPL: processing lawfully and fairly; ensuring that the data are accurate and, where necessary, kept up to date; processing for specified, explicit and legitimate purposes; and ensuring that processing is relevant, limited and proportionate to those purposes.
| Personal Data | Purpose of Processing | Legal Basis | Recipient | Purpose of Transfer |
|---|---|---|---|---|
| Identity Details (First Name and Surname) Contact Details (Email Address and Telephone Number) |
Promoting and marketing services, promoting the Company and enhancing its profile through content such as messages of congratulations and good wishes | Explicit consent | Our suppliers providing technical infrastructure services | Provision of storage and technical infrastructure services |
*Pursuant to Law No. 6563 on the Regulation of Electronic Commerce, we are required to obtain your consent before sending commercial electronic communications to you. At any time and without stating a reason, you may stop the relevant commercial communications by using the opt-out mechanism specified in the commercial electronic communications we send, thereby bringing to an end the personal data processing activities based on your explicit consent.
| Personal Data | Purpose of Processing | Legal Basis | Recipient | Purpose of Transfer |
|---|---|---|---|---|
| Contact (Email Address, Telephone Number) | Carrying out the wallet-account creation processes, Sending an SMS OTP. |
Establishment of a contract. | Suppliers providing technical-infrastructure services, The supplier engaged to send SMS OTPs. |
Carrying out storage and archiving activities, Transmitting OTPs. |
| Identity (Cardholder's Full Name) Financial (Card Number, Card Security Code, Card Expiry Date, Amount Sent) Other (Description Entered When Adding Funds) |
Carrying out remote identity-verification processes Carrying out the processes for adding funds by credit card Carrying out card-storage processes upon request |
Compliance with a legal obligation Establishment of a contract Explicit consent for the card-storage service |
Suppliers providing technical-infrastructure services | Carrying out storage and archiving activities |
| Personal Data | Purpose of Processing | Legal Basis | Recipient | Purpose of Transfer |
|---|---|---|---|---|
| Identity (Full Name, Sex, Date of Birth, Turkish ID No., Identity Card Serial No., Foreign National ID No., Place of Birth, Mother's and Father's Names, Passport Details, Front and Reverse of Identity Card, Nationality, Signature) Contact (Address, Email Address, Telephone Number) Transaction Security (IP Address Details, Device Details) Visual Records (Physical Images) Biometric Data (Facial Recognition and Liveness Check) Professional Experience (Occupation Details) Other (Contract) |
Carrying out the Customer's conversion to a contractual account Enabling the Customer to use the services provided as part of the wallet service Carrying out remote identity-verification processes |
Establishment of a contract Compliance with a legal obligation Explicit consent (in respect of biometric data) Expressly provided for by law |
Suppliers providing technical-infrastructure services Suppliers Competent public authorities |
Carrying out storage and archiving activities Verification of Customer information Compliance with legal obligations Providing information to competent public authorities |
| Identity (Full Name, Turkish ID No.) | Verification with the infrastructure provider as part of the KYC (Know Your Customer) process | Compliance with a legal obligation | BKM TRİPS system | Compliance with legal obligations |
| For the parents or guardians of users under the age of 18; Identity (Full Name, Place and Date of Birth, Nationality, Type and Number of Identity Document, Turkish ID No., Mother's and Father's Names) Contact (Address, Telephone Number, Email Address) |
Obtaining parental or guardian approval for the contractual accounts of users under the age of 18 | Establishment of a contract Compliance with a legal obligation |
Suppliers providing technical-infrastructure services Suppliers Competent public authorities |
Carrying out storage and archiving activities, verification of Customer information Compliance with legal obligations Providing information to competent public authorities |
| Personal Data | Purpose of Processing | Legal Basis | Recipient | Purpose of Transfer |
|---|---|---|---|---|
| The following information is processed in respect of the authorised representatives of sole traders and capital companies; Identity (Full Name, Date of Birth, Turkish ID No., Foreign National ID No., Tax Identification No., Place of Birth, Mother's and Father's Names, Passport Details, Copy of Identity Card, Signature, Information Contained in the Signature Circular, Tax Certificate and TTSG Notices, Nationality, Tax Certificate, Certificate of Activity, Trade Name) Contact (Address, Email Address, Telephone Number, Fax Number) Other (Contract) |
Carrying out the corporate wallet-account creation processes Carrying out remote identity-verification processes |
Establishment of a contract Compliance with a legal obligation |
Suppliers providing technical-infrastructure services Suppliers Competent public authorities |
Carrying out storage and archiving activities Verification of Customer information Compliance with statutory obligations Providing information to competent public authorities |
| In addition to the foregoing; Criminal Record (For Customers Considered High-Risk) |
Carrying out the corporate wallet-account creation processes Carrying out remote identity-verification processes Ensuring transaction security |
Explicit consent | Suppliers providing technical-infrastructure services | Carrying out storage and archiving activities |
| Identity (Full Name, Turkish ID No.) | Verification with the infrastructure provider as part of the KYC (Know Your Customer) process | Compliance with a legal obligation | BKM TRİP system | Compliance with legal obligations |
| Personal Data | Purpose of Processing | Legal Basis | Recipient | Purpose of Transfer |
|---|---|---|---|---|
| Identity (Cardholder's Full Name) Financial (Card Number, Card Security Code, Card Expiry Date) |
Carrying out card-storage processes upon request | Explicit consent | Suppliers providing technical-infrastructure services | Carrying out storage and archiving activities |
| Personal Data | Purpose of Processing | Legal Basis | Recipient | Purpose of Transfer |
|---|---|---|---|---|
| Financial (Invoice Number, Amount Paid) | Processing bill payments through the SiPay Application | Performance of a contract | Suppliers providing technical-infrastructure services Suppliers |
Carrying out storage and archiving activities Processing bill payments |
| Location | Showing nearby ATMs to Customers wishing to withdraw cash | Explicit consent | None | None |
| Other (Location at Which the Transaction Took Place) | Detecting and preventing fraud | Legitimate interest | None | None |
| Transaction Security (Log Records, IP Address Details and Device Details) | Ensuring transaction security Implementing data-security measures |
Legitimate interest Compliance with a legal obligation |
Suppliers providing technical-infrastructure services | Ensuring transaction security Carrying out storage and archiving activities |
| Identity (Full Name, Date of Birth, Turkish ID No., Foreign National ID No., Nationality) Contact (Address, Email Address, Telephone Number) Financial (Payment-Account Details, Account Transactions) |
Provision of open-banking services | Performance of a contract | Account information service providers holding the Customer's payment account, BKM | Provision of open-banking services |
| Identity (Customer's and Recipient's Full Names, Customer's Turkish ID No., Tax Identification No.) Financial (Customer's and Recipient's Bank-Account/Card Details, Receipt Number Customer Account Number, Customer Number, Transaction Date, Transaction Number, Transaction Amount, Description) |
Managing account transactions and funds transfers | Performance of a contract | Banks | Managing funds-transfer processes |
| Identity (Full Name) Contact (Email Address, Address, Telephone Number) Transaction Security (ID Details) |
Verifying the user and activating the account for the processing of payments using an anonymous prepaid card | Performance of a contract | Business partner | Carrying out verification processes |
| Contact (Email Address) | Administering cashback in connection with payments made using an anonymous prepaid card | Performance of a contract | No transfer is made. | No transfer is made. |
| Identity (Full Name, Date of Birth, Turkish ID No., Mother's and Father's Names) | Managing fraud-related processes Detecting and preventing fraud |
Compliance with a legal obligation | Systems integrated to enable data to be shared with competent public authorities | Detecting and preventing fraud |
| Other (Weight of Precious Metal in Grams) | Provision of brokerage services for trading in precious metals | Performance of a contract | Suppliers providing technical-infrastructure services Suppliers providing precious-metals trading services |
Carrying out storage and archiving activities Provision of brokerage services for trading in precious metals |
| Identity (Full Name) Contact (Address, Telephone Number) |
Processing requests for virtual and physical cards through the SiPay Application | Performance of a contract | Suppliers providing card-printing services Suppliers providing technical-infrastructure services |
Carrying out storage and archiving activities Processing physical-card requests |
| Identity (Full Name, Turkish ID No., Identity Card, Signature) Contact (Telephone Number, Address) |
Carrying out identity verification upon delivery of a physical card requested by the Customer | Performance of a contract Compliance with a legal obligation |
Courier company engaged to deliver the physical card Suppliers providing technical-infrastructure services |
Carrying out storage and archiving activities Carrying out physical-card delivery processes |
| Identity (Full Name) Contact (Telephone Number) |
Sending an OTP (one-time password) when a card transaction is carried out | Performance of a contract Compliance with a legal obligation |
Suppliers providing technical-infrastructure services Supplier engaged to send OTPs |
Carrying out storage and archiving activities Sending OTPs |
| Financial (First Six and Last Four Digits of the Card, Whether the Transaction Was Successful or Unsuccessful) | Processing transactions carried out using a physical or virtual card | Performance of a contract Compliance with a legal obligation |
BKM | Compliance with a legal obligation |
| Identity (Full Name, Signature) Contact (Telephone Number) Financial (First Six and Last Four Digits of the Card, Invoice Details, Transaction Amount, Transaction Date, Refund Slip) |
Handling card-transaction disputes | Performance of a contract Compliance with a legal obligation |
Suppliers providing technical-infrastructure services | Carrying out storage and archiving activities |
| Personal Data | Purpose of Processing | Legal Basis | Recipient | Purpose of Transfer |
|---|---|---|---|---|
| Identity (Full Name, Signature) Contact (Telephone Number) Other (Document Obtained through e-Devlet Confirming That the Telephone Number Is Registered in the Individual's Name) |
Processing requests to change a mobile telephone number | Performance of a contract Compliance with a legal obligation |
Suppliers providing technical-infrastructure services | Carrying out storage and archiving activities |
| Identity (Full Name, Sex, Date of Birth, Turkish ID No., Foreign National ID No., Mother's and Father's Names, Identity Card, Signature, New Full Name) Visual Records (Photograph) Other (Reason for the Change) |
Processing requests to change the registered first name and surname | Performance of a contract Compliance with a legal obligation |
Suppliers providing technical-infrastructure services | Carrying out storage and archiving activities |
| Personal Data | Purpose of Processing | Legal Basis | Recipient | Purpose of Transfer |
|---|---|---|---|---|
| Transaction Security (Log Records) | Testing whether the functions of the SiPay Application operate correctly Carrying out maintenance and technical-support processes |
Performance of a contract Legitimate interest Compliance with a legal obligation |
Suppliers providing technical-infrastructure services | Carrying out storage and archiving activities Carrying out maintenance and technical-support processes |
| Personal Data | Purpose of Processing | Legal Basis | Recipient | Purpose of Transfer |
|---|---|---|---|---|
| Identity (Full Name, Turkish ID No., Foreign National ID No.) Financial (Cardholder's Full Name, First Six and Last Four Digits of the Card, Fraud Information, Payment ID, Transaction Number, Transaction Amount, Transaction Date) |
Handling suspicious-transaction notifications received from banks Verifying transactions carried out by SiPay |
Compliance with a legal obligation Provided for by law |
Suppliers providing technical-infrastructure services Banks |
Carrying out storage and archiving activities Compliance with a legal obligation |
| Identity (Full Name, Turkish ID No., Foreign National ID No., Tax Identification No., Identity Card, Full Name in the Case of Sole Traders) Contact (Email Address, Telephone Number) Financial (Card No., Transaction Date, Account Transactions, Transaction Number, Transaction Amount, Transaction Date, Receipt Number, Account-Blocking Status, Disposition of Funds Subject to an Investigation, Transaction Descriptions) Transaction Security (IP Address Details, Port Details) Other (Order/Item Details, Status of Customer Complaint or Objection) |
Responding to official correspondence and requests for information received from Public Prosecutors' Offices, the Police/Gendarmerie and Courts in connection with investigation files | Compliance with a legal obligation Provided for by law |
Suppliers providing technical-infrastructure services Competent public authorities and official bodies |
Carrying out storage and archiving activities Compliance with a legal obligation |
| Identity (Full Name, Turkish ID No., Foreign National ID No., Tax Identification No., Place of Birth) Contact (Address, Telephone Number) Financial (Card No., Transaction Date, Transaction Amount) Other (Statement of Defence) |
Preparing statements of defence and responses to official correspondence received from Consumer Arbitration Committees | Compliance with a legal obligation Provided for by law |
Suppliers providing technical-infrastructure services Competent public authorities and official bodies |
Carrying out storage and archiving activities Compliance with a legal obligation |
| Identity (Full Name) Financial (Customer Account Number, Balance Details, Whether an Account Exists, Account Opening Date) |
Responding to official correspondence and requests for information received from the Ministry of Trade | Compliance with a legal obligation Provided for by law |
Suppliers providing technical-infrastructure services Competent public authorities and official bodies |
Carrying out storage and archiving activities Compliance with a legal obligation |
| Identity (Full Name, Tax Identification No., Full Name in the Case of Sole Traders, Turkish ID No.) Financial (IBAN Details, Transaction Statements) |
Responding to official correspondence and requests for information received from the Tax Inspection Board and Tax Offices | Compliance with a legal obligation Provided for by law |
Suppliers providing technical-infrastructure services Competent public authorities and official bodies |
Carrying out storage and archiving activities Compliance with a legal obligation |
| Contact (Address, Email Address, Telephone Number) Professional Experience (Occupation Details) Financial (Customer Account Number, Customer Number, Balance Details, Transaction Amount, Whether an Account Exists, Account Opening Date, Account Closure Date) |
Responding to correspondence and requests for information received from MASAK | Compliance with a legal obligation Provided for by law |
Suppliers providing technical-infrastructure services Competent public authorities and official bodies |
Carrying out storage and archiving activities Compliance with a legal obligation |
| Identity (Full Name) Financial (Invoice Details, Wallet Number, Customer Number, Transaction Date, Transaction Number, Transaction Amount, Account Opening Date, IBAN Details) |
Responding to correspondence and requests for information received from the TÖDEB Individual Customer Arbitration Panel | Compliance with a legal obligation Provided for by law |
Suppliers providing technical-infrastructure services Competent public authorities and official bodies |
Carrying out storage and archiving activities Compliance with a legal obligation |
| Identity (Full Name, Turkish ID No., Foreign National ID No., Tax Identification No.) Legal Proceedings (Enforcement, Attachment of Salary and Maintenance Information) Financial (Balance Details, Whether an Account Exists) |
Responding to correspondence and requests for information received from Enforcement Offices | Compliance with a legal obligation Provided for by law |
Suppliers providing technical-infrastructure services Competent public authorities and official bodies |
Carrying out storage and archiving activities Compliance with a legal obligation |
| Identity (Full Name, Date of Birth, Turkish ID No., Foreign National ID No., Tax Identification No., Mother's and Father's Names, Identity Card Serial No., Nationality) Contact (Address, Email Address, Telephone Number) Professional Experience (Title) Financial (Customer Number, Transaction Date, Transaction Number, Transaction Amount, Transaction Descriptions) |
Submitting suspicious-transaction reports to MASAK | Compliance with a legal obligation Provided for by law |
Suppliers providing technical-infrastructure services Competent public authorities and official bodies |
Carrying out storage and archiving activities Compliance with a legal obligation |
| All information relating to the Customer | Submitting the necessary information to the relevant court in connection with prospective legal proceedings Complying with the obligation to retain information for the period prescribed by applicable legislation |
Establishment of a right Provided for by law |
Suppliers providing technical-infrastructure services Competent public authorities and official bodies |
Carrying out storage and archiving activities Conducting defence and claim proceedings |
The technical-infrastructure, SMS and card-printing suppliers to whom the Company transfers your personal data act as “Data Processors” under the PDPL. Your personal data are processed solely for the purposes and in accordance with the instructions determined by the Company, with appropriate data-security measures in place. Suppliers are prohibited from using the data for their own purposes.
Your personal data are retained for the maximum period necessary for the purposes for which they are processed or for the statutory retention periods prescribed by applicable legislation, including Law No. 6493 and MASAK legislation (for example, 10 years). Upon expiry of the applicable period, your personal data are erased, destroyed or anonymised ex officio or at your request, in accordance with the Company’s Personal Data Retention and Disposal Policy. In operational processes, sensitive data such as Turkish ID Numbers are used in masked form (***) in accordance with the principle of proportionality and, where considered necessary, are anonymised.
Accordingly, the personal data of our employees, job applicants, customers and all natural persons whose personal data are held by the Company for any reason are retained and disposed of in accordance with the law.
| Source of Personal Data | Retention Period |
|---|---|
| Membership Records | 10 Years |
| Accounting and Financial Transaction Records | 10 Years |
| Cookies | 2 Years |
| Commercial Email Consent Records | 1 Year |
| Personal Data Relating to Customers | 10 Years Following Termination of the Legal Relationship |
| Personal Data Relating to Agents | 10 Years Following Termination of the Legal Relationship |
| Contracts | 10 Years Following Termination of the Contract |
| Corporate Communication Activities | 10 Years Following Completion of the Activity |
| Audio or Electronic Information Relating to Informing Consumers and Enabling Them to Exercise the Right of Withdrawal | 3 Years |
| Consent Records and Data Other Than Consent Records Relating to Commercial Electronic Communications Sent to Recipients’ Electronic Contact Addresses for the Purposes of Promoting or Marketing Goods and Services, Promoting the Business or Enhancing Its Profile Through Content Such as Messages of Congratulations and Good Wishes | 1 Year |
| Visitors’ Personal Data | 2 Years |
| Personal Data Processed Due to the Obligation to Provide After-Sales Services under the Law on Consumer Protection | 15 Years |
| Customer Transaction Information | 10 Years |
Where a longer period is prescribed by law, including in relation to limitation periods, time limits resulting in the forfeiture of rights or statutory retention periods, the period prescribed by the applicable legislation shall be treated as the maximum retention period.
Access to the basic electronic-money and wallet services provided by the Company is not conditional upon your giving explicit consent to marketing activities or to the processing of your biometric data. Before a transaction is carried out, you are presented, through the relevant interfaces, with an informed-consent statement concerning risks inherent in financial transactions, including system outages, the risk of fraud and the irreversibility of transactions.
You may submit your requests under Article 11 of the PDPL, including requests for the erasure or rectification of your personal data or for information as to whether your personal data are being processed, at any time to the addresses below, either in writing in accordance with the Communiqué on the Procedures and Principles for Applications to the Data Controller or by using a registered electronic mail (KEP) address, a secure electronic signature, a mobile signature or the email address previously notified to us and registered in our system.
Depending on the nature of your request, your application will be handled effectively and concluded free of charge as soon as possible and, in any event, within 30 (thirty) days.
Data: Sipay Elektronik Para ve Ödeme Hizmetleri Şirketi
Email: kvkk@sipay.com.tr
KEP Address: sipayelektronik@hs06.kep.tr
Address: Küçükçamlıca Mah. Ord. Prof. Fahrettin Gökay Cad. No:49, 34696 Üsküdar/İstanbul