Data Protection and Handling Policy

Piolent Baskı Reklam Tasarım San. ve Tic. Ltd. Şti.
Version 1.0 · Effective 14 September 2026 · Policy owner: Halil İbrahim Demirtaş (hibrahim@piolent.com)

1. Purpose and scope

This policy sets out how Piolent collects, classifies, handles, stores, shares and disposes of information, including personal data of our customers and data we receive from sales channels such as Amazon ("Amazon Information"). It applies to all staff, all systems we operate (our online store, our internal order management panel and its server) and all service providers acting on our behalf. It complements our Privacy Policy and our obligations under the Turkish Personal Data Protection Law No. 6698 (KVKK).

2. Roles and responsibilities

  • Policy owner and Incident Management Point of Contact: Halil İbrahim Demirtaş — approves this policy, owns the records of processing, and leads incident response.
  • System administrators: named individuals who manage hosting, the deployment platform and the code repository; the only people with access to encryption keys and production secrets.
  • Staff: use information only for the tasks their role requires and follow the handling rules below.

3. Data classification

Level Examples Handling rules
Public Product listings, prices, published store pages No restrictions on disclosure.
Internal Stock levels, order counts, sales reports without personal data Staff only; not shared outside the company.
Confidential API credentials, encryption keys, settlement and financial records, supplier terms Named administrators only; stored encrypted; never in code repositories, email or chat; masked in logs.
Restricted (PII) Buyer name, delivery and billing address, phone number, e-mail; all Amazon buyer PII Role-based access on a need-to-know basis; encrypted at rest (AES-256-GCM) and in transit (TLS); no bulk export; no copies on personal devices or removable media; used only for the stated purpose; deleted on schedule.

4. Handling rules

  • Collection: we collect only the data needed to fulfil an order and meet legal obligations. Amazon buyer PII is obtained only through the Amazon Selling Partner API, only for our own orders.
  • Use: Restricted data is used only to ship the order, issue the legally required invoice, and handle customer service for that order. It is never used for marketing, profiling, analytics or sold.
  • Access: every user has an individual, named account; shared accounts are not permitted. Access is granted by role and enforced by the server on every page and API endpoint. Access rights are reviewed when staff join, change role or leave.
  • Storage: Restricted and Confidential data is stored only in our own database on our EU server, encrypted at application level with AES-256-GCM. Encryption keys are held as server environment secrets, separate from the database and the code repository.
  • Transmission: all transfers use encrypted connections (HTTPS/TLS).
  • Personal devices: staff must not copy, photograph, download or store Restricted data on personal devices, USB drives or cloud accounts. The panel provides no bulk export of buyer PII.
  • Testing: production Restricted data is never copied to test environments or developer machines; testing uses synthetic records.
  • Backups: database backups are encrypted and stored in a geographically separate location; restores are tested periodically.
  • Logging: access to systems and every create, update and delete action is logged with user, time and IP address. Logs are reviewed every two weeks and retained for at least 12 months.

5. Retention and disposal

  • Amazon buyer PII: deleted no later than 30 days after order delivery, unless a longer period is required by law.
  • Invoice records: retained only for the period required by Turkish tax and commercial law, then deleted.
  • Other customer personal data: retained only as long as necessary for the purpose it was collected for and legal obligations.
  • Deletion is automated where possible. Deleted data is removed from the live database; backups containing it expire under the backup retention cycle.

6. Sharing with third parties

Restricted data is shared only where necessary to fulfil an order or meet a legal obligation, and only the minimum data required:

  • Yurtiçi Kargo (carrier) — recipient name, delivery address and phone number, to deliver the order.
  • Our e-invoice service provider and the Turkish Revenue Administration (GİB) — buyer name and address on the legally required e-Archive invoice.

We do not share Amazon Information with any other party.

7. Security incidents

  1. Contain: revoke affected sessions and API tokens, rotate credentials and encryption keys, block the source.
  2. Assess: identify affected records using audit and API logs.
  3. Notify: incidents involving Amazon Information are reported to security@amazon.com within 24 hours of detection; affected individuals and the Personal Data Protection Authority are notified as required by KVKK.
  4. Recover: restore from clean backups and fix the root cause.
  5. Review: record the root cause and corrective actions.

The incident response plan is reviewed at least every six months.

8. Records of processing activities

Processing activity Data categories Data subjects Purpose Legal basis (KVKK Art. 5) Recipients Retention
Order fulfilment (own store and marketplaces) Name, delivery address, phone Buyers Pack and ship the order Performance of a contract (5/2-c) Carrier (Yurtiçi Kargo) Marketplace PII: max. 30 days after delivery
Invoicing Name, billing address, tax ID where provided Buyers Issue e-Archive / e-Invoice Legal obligation (5/2-ç) E-invoice provider, GİB Period required by tax and commercial law
Customer service and returns Name, order details, messages Buyers Answer questions, process returns Performance of a contract (5/2-c) None Until the case is closed and legal periods expire
Marketplace account management Order and listing data without PII, settlement data Listings, stock, pricing, reconciliation Legitimate interest (5/2-f) None As long as the account is active
System access and audit logging Staff name, e-mail, IP address, actions Staff Security and accountability Legitimate interest (5/2-f) None At least 12 months

9. Training and acknowledgement

Every person with access to Restricted data is informed of this policy before access is granted and confirms that they have read it.

10. Review

This policy and the records of processing are reviewed at least once a year and whenever our systems, service providers or legal requirements change.

11. Contact

Questions, data subject requests under KVKK and security reports: hibrahim@piolent.com