Our GDPR Policy

ETGİ GRUP PERSONAL DATA PROTECTION POLICY
This Personal Data Protection Policy (“Policy”) has been prepared by Etgi Grup Bilişim Teknolojileri Yazılım Donanım Bilgisayar Mimarlık Mühendislik İnşaat Taahhüt İthalat İhracat Ticaret A.Ş. (“Etgi Grup” or the “Company”), acting in its capacity as data controller, in accordance with the Law No. 6698 on the Protection of Personal Data (“KVKK”) and relevant secondary legislation.

1. PURPOSE AND SCOPE
1.1. This Policy determines the procedures and principles regarding the processing, storage, transfer, and destruction of personal data obtained by Etgi Grup.
1.2. This Policy covers employees, customers and suppliers, business partners, visitors, and all natural persons with whom Etgi Grup has a legal or commercial relationship.

2. LEGAL BASES
2.1. In the processing of personal data, Law No. 6698 (KVKK), Law No. 6563 on the Regulation of Electronic Commerce, Law No. 6502 on the Protection of Consumers, the Turkish Code of Obligations, the Turkish Commercial Code, and the Turkish Penal Code No. 5237 are taken into account.
2.2. Etgi Grup undertakes to comply with current principle decisions taken by the Personal Data Protection Board (“Board”).

3. PRINCIPLES REGARDING THE PROCESSING OF PERSONAL DATA
Etgi Grup processes personal data in accordance with the following principles pursuant to Article 4 of the KVKK:– Compliance with the law and principles of honesty,– Being accurate and, where necessary, kept up to date,– Processing for specific, explicit, and legitimate purposes,– Being relevant, limited, and proportionate to the purposes for which they are processed,– Being retained for the period foreseen by relevant legislation or the period required for the purpose of processing.

4. PURPOSES OF PROCESSING PERSONAL DATA
Etgi Grup processes personal data for the following purposes:– Provision, development, and improvement of services,– Fulfillment of contractual and legal obligations,– Customer relationship management, support services, and information activities,– Marketing, campaign, and promotional activities,– Information security, system management, and audit processes,– Fulfillment of legal obligations and execution of legal proceedings.

5. TRANSFER OF PERSONAL DATA
5.1. Personal data may be shared, within the scope of Articles 8 and 9 of the KVKK and by taking necessary technical and administrative measures, with: business partners, suppliers, group companies, domestic and international cloud service providers, consultants, and legally authorized public institutions.
5.2. Cross-border data transfer is carried out to countries declared by the Board to have adequate protection, or to data recipients who undertake adequate protection.

6. DATA STORAGE AND DESTRUCTION
6.1. Etgi Grup retains personal data for the duration required by the processing purposes and during the storage periods foreseen by relevant legislation.
6.2. Personal data whose storage period has expired or whose processing purpose has ceased to exist shall be deleted, destroyed, or anonymized in accordance with the Company’s “Personal Data Storage and Destruction Policy.”

7. DATA SECURITY
Etgi Grup takes all necessary technical and administrative measures within the scope of Article 12 of the KVKK to ensure the security of personal data. In this context:
– Access authorization and logging systems are used.
– Encryption, logging, network security, and anti-virus systems are implemented.
– Regular KVKK trainings are provided to employees.
– Confidentiality and data security provisions are included in agreements made with third parties.

8. RIGHTS OF THE DATA SUBJECT
Natural persons whose personal data are processed have the following rights pursuant to Article 11 of the KVKK:
– To learn whether their personal data are processed,
– To request information if processed,
– To learn the purpose of processing and whether they are used in accordance with the purpose,
– To know the third parties to whom data are transferred domestically or abroad,
– To request rectification in case of incomplete or inaccurate processing,
– To request erasure or destruction pursuant to Article 7 of the KVKK,
– To request notification of these operations to third parties to whom data have been transferred,
– To object to the occurrence of a result against themselves through analysis exclusively via automated systems,
– To request compensation for damages in case of unlawful processing.

9. APPLICATION METHOD
Personal data subjects may submit their requests to Etgi Grup via any of the communication channels listed below, together with identity verification documents:
Address: Hacettepe Teknokent 4. Ar-Ge Binası, Üniversiteler Mah. 1596. Cad. A Blok No:95-A/21, Beytepe, Çankaya, ANKARA / TÜRKİYE
E-mail: bilgi@vedubox.com
KEP (Registered Electronic Mail): etgigrup@hs03.kep.tr
Applications shall be concluded within a maximum of 30 (thirty) days. In the event of additional costs, a fee may be requested according to the tariff determined by the Personal Data Protection Board.

10. ENTRY INTO FORCE AND UPDATE OF THE POLICY
This Policy entered into force in 2025 and may be updated with the approval of Etgi Grup. Policy changes enter into force on the date they are published at www.vedubox.com. Etgi Grup reserves the right to revise the Policy in the event of changes in personal data processing activities.

11. APPLICABLE LAW AND JURISDICTION
Turkish Law shall apply to the implementation of this Policy. Ankara Central Courts and Enforcement Offices are authorized to resolve disputes.