Privacy & Policy
1. PREAMBLE AND SCOPE
As GDS EĞİTİM DANIŞMANLIK VE TEKNOLOJİ ANONİM ŞİRKETİ (“GODDESS”), the protection of personal data belonging to all natural persons with whom we interact—including but not limited to our users, visitors to our websites and facilities, commercial customers, business partners, natural person suppliers, employees of legal entity suppliers, job applicants, and current/former employees (collectively referred to as “Individuals”) — is our utmost priority.
This Privacy Policy (“Policy”) has been drafted in accordance with the Law on the Protection of Personal Data No. 6698 (“KVKK”) in Turkey, secondary legislation, and the decisions of the Personal Data Protection Board (collectively, “Data Protection Legislation”), as well as international standards such as the General Data Protection Regulation (GDPR). We conduct all processing, storage, and transfer activities regarding personal data acquired during our operations pursuant to the principles of transparency, legality, and the protection of fundamental rights and freedoms.
2. DEFINITIONS
Personal Data: Any information relating to an identified or identifiable natural person.
Data Subject (Individual): The natural person whose personal data is being processed.
Processing of Personal Data: Any operation performed on data, such as collection, recording, storage, preservation, alteration, reorganization, disclosure, transfer, or restriction.
Data Controller: The natural or legal person (GODDESS) who determines the purposes and means of processing personal data.
Explicit Consent: Freely given, specific, and informed agreement by the Data Subject.
Special Categories of Personal Data: Sensitive data such as race, ethnic origin, political opinions, philosophical beliefs, religion, health data, biometric/genetic data, and criminal convictions.
3. CATEGORIES OF PERSONAL DATA COLLECTED
We collect and process the following categories of data:
Identity and Contact Information: Name, surname, e-mail address, password, and in certain cases, phone number.
Financial Information: GODDESS does not collect or process credit/debit card data for in-app purchases; these are handled by Apple, Google, or Huawei. For direct website purchases, we and our payment providers collect limited data (IBAN, card type, expiry date, billing address, and the last four digits of the card) via unique anonymous “tokens.”
Customer Transaction & Device Data: Operating system version, device type, system performance data, and IP addresses.
Third-Party Data (Referral System): If you use our “Invite a Friend” system, you provide their name and email. The responsibility for obtaining explicit consent from said third parties for this sharing rests solely with you.
4. LEGAL GROUNDS FOR DATA PROCESSING
Pursuant to Article 5 of the KVKK and Article 6 of the GDPR, GODDESS may process personal data without explicit consent under the following exhaustive conditions:
- Where clearly provided for in the laws.
- Where it is mandatory for the protection of life or physical integrity.
- Where the processing is necessary for the conclusion or performance of a contract.
- Where it is mandatory for the Controller to fulfill its legal obligations.
- Where the data has been made public by the Data Subject themselves.
- Where processing is mandatory for the establishment, exercise, or protection of a right.
- Where processing is mandatory for the legitimate interests of the Data Controller.
5. TRACKING TECHNOLOGIES AND ANALYTICS
5.1. Cookies and Beacons: We utilize cookies, tags, and scripts to enhance user experience and measure experience metrics.
5.2. Third-Party Partners: We partner with entities like Google and Facebook for ad management and retargeting.
5.3. Analytics: We use Google Analytics to estimate visitor volume and usage patterns.
6. DATA STORAGE AND SECURITY
We implement SSL encryption for all payment transactions and follow generally accepted industry standards to protect data both during transmission and once received.
Server Locations: Data is primarily stored on secure servers within the Republic of Turkey. However, data may be transferred to and processed by global affiliates or service providers located outside your country of residence.
7. DATA RETENTION POLICY
Account Data: Retained as long as the account is active.
Transaction Data: Retained for the duration of the contractual relationship and thereafter for 10 years.
Commercial Communications: Processed until you withdraw your consent.
Cookies: Generally retained for 12 months.
8. DATA SUBJECT RIGHTS
Pursuant to Article 11 of the KVKK and the GDPR, you have the right to:
- Request information on whether your data is processed;
- Know the third parties to whom data is transferred;
- Request rectification of incomplete/inaccurate data;
- Request erasure or destruction of data;
- Object to negative results arising from purely automated analysis.
9. CONTACT US
GDS EĞİTİM DANIŞMANLIK VE TEKNOLOJİ ANONİM ŞİRKETİ
Address: Yeşilköy Mah. Atatürk Cad. EGS BUSİNESS PARK BLOK NO: 12 İÇ KAPI NO: 1 BAKIRKÖY/İSTANBUL/TÜRKİYE
Email: info@thegoddesswellbeing.com