Legal

KVKK information notice

This notice has been prepared pursuant to Law No. 6698 on the Protection of Personal Data ("KVKK") in order to inform you about the purposes and legal grounds for processing your personal data, its transfer, retention periods, and your rights arising from the KVKK.

1. Data Controller

In the capacity of data controller, your personal data is processed by the legal entity/natural person whose identity is set out below.

Trade Name: [Ticaret Unvanı / Şahıs Adı]

Brand: OkulTedarigim

Tax Office / No: [Vergi Dairesi] / [Vergi Numarası]

MERSİS No: [MERSİS No (varsa)]

Address: [Tam Adres — Mahalle, Cadde, No, İlçe, İl, Posta Kodu]

E-mail: destek@okultedarigim.com

Phone: +90 549 774 71 37

VERBİS Registration No: [VERBİS Kayıt No (kayıt yapıldıysa)]

2. Personal Data Processed

The following categories of personal data are processed within the scope of the order process:

  • Identity data: first name, surname, T.C. national identity number (mandatory only for e-Archive/e-Invoice issuance)
  • Contact data: phone number, e-mail address, delivery and billing address
  • Student data (child data): the student's first name, surname, school and class information
  • Order data: order number, order contents, amount, date, order note
  • Financial data: tax number, tax office (in case of a corporate invoice preference), invoice number
  • Transaction security data: IP address, session information, failed login records
  • Payment data: only the transaction reference number and amount are stored; the card number, CVV and expiry date are not stored in our system and are transmitted directly to the licensed payment institution (PCI-DSS compliant).

3. Special Notice Regarding Children's Personal Data

During the order process, personal data belonging to students under the age of 18 (first name, surname, class, school) is processed. This data is processed solely by the student's parent/legal guardian, for the purpose of delivering the school supply package to the student, within the framework of the consent given in the capacity of parent.

The person filling out the order form declares that they are the student's parent/legal guardian and that they are authorized to process the student's personal data within the scope of the KVKK. The child's data is processed only for the period necessary to perform the service and is not used for marketing purposes.

4. Purposes of Processing Personal Data

  • Carrying out order and payment processes
  • Planning and carrying out the product/package delivery process
  • Fulfilling legal invoicing obligations through e-Archive and e-Invoice issuance
  • Customer relationship management, order tracking, evaluation of cancellation and return requests
  • Carrying out communication activities (order notification, shipping notification)
  • Carrying out information security processes (session, brute-force protection, audit trail)
  • Fulfilling obligations under legislation such as Laws No. 6502, 6698, 213 and the VUK
  • Evaluating consumer complaints and disputes

5. Legal Grounds for Processing (KVKK Art. 5)

  • Being directly related to the establishment or performance of a contract (Art. 5/2-c) — the order and delivery process
  • Being mandatory for the data controller to fulfill its legal obligation (Art. 5/2-ç) — invoice issuance, financial record-keeping
  • Being mandatory for the legitimate interests of the data controller, provided that it does not harm the fundamental rights and freedoms of the data subject (Art. 5/2-f) — information security, fraud prevention
  • Explicit consent (Art. 5/1) — marketing notifications and the consent, as a parent, to process the child's data

6. Transfer of Personal Data

Your personal data may be transferred only for the following purposes and in a limited manner, within the scope of KVKK Art. 8 and Art. 9:

  • Payment service provider (Iyzico Ödeme Hizmetleri A.Ş.) — for the purpose of carrying out the payment transaction
  • e-Invoice integrator (KolayBi / Türkiye Bilimsel ve Teknolojik Araştırma Kurumu — GİB) — for the purpose of invoice issuance
  • Shipping company (Aras Kargo) — for cargo delivery, only the recipient, phone, and address information
  • E-mail service (Resend) and SMS service (Twilio) — for transmitting notifications
  • Legal authorities and public institutions — in the event of legal obligations or a court/prosecutor's office request
  • Cloud infrastructure providers (Vercel Inc., TiDB Cloud / PingCAP Inc.) — data storage and serving infrastructure; the servers are located in the European Union (Frankfurt) region.

Transfers abroad take place within the framework of the safeguards provided by the relevant provider under KVKK Art. 9. In cases where the transfer abroad is carried out with explicit consent, separate consent is obtained.

7. Retention Periods

  • Order and invoice data: 10 (ten) years pursuant to the VUK and the TTK
  • KVKK information notice records and audit trail (system_logs): 5 (five) years
  • Communication and marketing data: until explicit consent is withdrawn or for a maximum of 3 years
  • Failed login and session security records: a maximum of 1 year
  • Cancellation/return records: 10 (ten) years from the date of record

Data whose retention period has expired is deleted, destroyed, or anonymized in the first destruction period.

8. Rights of the Personal Data Owner (KVKK Art. 11)

As the data owner, you have the following rights pursuant to Article 11 of the KVKK:

  • To learn whether your personal data is being processed
  • To request information regarding it if it has been processed
  • To learn the purpose of processing and whether it is being used in accordance with that purpose
  • To know the third parties to whom it has been transferred domestically or abroad
  • To request its correction in the event it has been processed incompletely or incorrectly
  • To request its deletion or destruction within the framework of the conditions stipulated in the KVKK
  • To request that correction, deletion, and destruction operations be notified to the third parties to whom the data has been transferred
  • To object to a result that arises against you as a result of analysis by automated systems
  • To request compensation for the damage in the event you suffer damage due to unlawful processing

9. Application Method

Pursuant to KVKK Art. 13, you may submit your requests regarding the above rights through one of the following channels, in a manner that allows identity verification:

  • E-mail: kvkk@okultedarigim.com (from your registered e-mail address)
  • Written application: [Tam Adres — Mahalle, Cadde, No, İlçe, İl, Posta Kodu]
  • Within the scope of the Communiqué on the Procedures and Principles of Application to the Data Controller

Your application is finalized within at most 30 (thirty) days pursuant to KVKK Art. 13/2. In the event you are not satisfied with the response given to your application, you have the right to file a complaint with the KVKK Board (kvkk.gov.tr).

10. Data Security

The following technical and administrative measures are applied to prevent the unlawful processing of, access to, and loss of your personal data:

  • TLS 1.2+ encrypted communication, HSTS policy
  • Storage of passwords with one-way cryptographic hashing (bcrypt)
  • Authorized access control and session security (httpOnly, secure, sameSite cookie policies)
  • Brute-force protection and rate limiting
  • Database backup (TiDB Cloud automatic daily backup)
  • Data processor agreements with third-party subcontractors
  • Employee awareness and confidentiality obligations

11. Cookie Policy Summary

On our site, only session cookies (token, mudur_token for admin/principal login) are used. No third-party tracking/marketing cookies are placed, and no analytics tool is used. Session cookies are set only for logged-in users and on the legal ground of KVKK Art. 5/2-c (performance of the contract).

12. Updates

This information notice may be updated in line with legislative changes and developments in the scope of our service. The current version is always published on this page.

Last updated: April 2026 — Version 2.0