GDPR & Privacy Policy Fal Deryası
This document has been prepared to inform users about the processing of personal data collected through the Fal Deryası platform in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.
By using Fal Deryası, you are deemed to have read, understood, and accepted this policy.
---
1. Data Controller Under GDPR, your personal data is processed by Fal Deryası (“Platform”) acting as the Data Controller.
This policy applies to the Fal Deryası website, all digital platforms, and related services.
---
2. Personal Data Processed When you use the platform, place orders, or make payments, the following personal data may be processed:
2.1 Identity Information - First name, last name
2.2 Contact Information - Phone number - Email address - Address information (only if required for invoicing or delivery)
2.3 Account Information - User ID / account details - Passwords (stored in encrypted/hashed form)
2.4 Payment & Financial Information - Transaction amounts and payment history - Payment method details (wallet, card, etc.) - Wallet balance and wallet transaction history - Invoice details (if applicable)
> Important: Credit card numbers, CVV codes, or full card details are never stored on Fal Deryası servers. Payments are processed through licensed payment service providers.
2.5 Usage & Transaction Data - Order history - Purchased services or products - Transaction timestamps and usage logs
2.6 Technical Data - IP address - Browser type and version - Device information - Operating system - Log records - Cookies
2.7 Uploaded Content - Images uploaded by users - Information submitted through forms - Files or documents related to services
---
3. Purposes of Processing Personal Data Your personal data may be processed for the following purposes:
- Creating and managing user accounts
- Managing login and authentication processes
- Processing orders and payments
- Managing wallet balance and transactions
- Enabling service delivery between users and sellers
- Providing customer support and communication
- Preventing fraud, abuse, and security breaches
- Fulfilling legal and regulatory obligations
- Managing accounting and tax processes
- Ensuring system security and logging
- Improving user experience and service quality
- Performing analytics and statistical analysis
- Responding to requests from authorized public authorities
---
4. Legal Bases for Processing Personal data is processed in accordance with GDPR Articles 6 and 9 based on the following legal grounds:
- Explicit consent (where required)
- Performance of a contract
- Compliance with legal obligations
- Protection of legitimate interests (security, fraud prevention, system integrity)
- Establishment, exercise, or defense of legal claims
---
5. Transfer of Personal Data Fal Deryası may share personal data with the following third parties when necessary:
5.1 Payment Service Providers & Banks - Payment processing - Refund handling - Financial security checks
5.2 Hosting & Infrastructure Providers - Server hosting - Data storage - System and network security
5.3 SMS & Email Service Providers - Verification codes - Notifications and system messages - Account-related communications
5.4 Accounting, Financial Advisors & Authorities - Tax compliance - Invoicing - Audits and legal obligations
5.5 Authorized Public Authorities - Court orders - Legal requests - Regulatory requirements
Data transfers are carried out in accordance with GDPR data protection safeguards.
---
6. Data Retention Period Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable laws.
- After the retention period expires, data is:
- Deleted,
- Destroyed, or
- Anonymized.
---
7. Data Security Fal Deryası implements appropriate technical and organizational measures to protect personal data, including:
- SSL/TLS encrypted communication
- Access control and authorization mechanisms
- Secure password hashing
- Logging and monitoring systems
- Tokenized payment processing
- Secure third-party payment infrastructures
While absolute security cannot be guaranteed over the internet, Fal Deryası commits to maintaining industry-standard security practices.
---
8. Cookies Fal Deryası uses cookies to improve functionality and user experience.
- Cookies may be used for:
- Session management
- Security
- Traffic analysis
- Preference storage
You may disable cookies through your browser settings; however, some features may not function properly.
---
9. Data Subject Rights (GDPR Articles 12–23) Under GDPR, users have the right to:
- Access their personal data
- Request correction of inaccurate or incomplete data
- Request deletion (“right to be forgotten”)
- Restrict processing
- Object to processing
- Request data portability
- Withdraw consent at any time
- Lodge a complaint with a supervisory authority
Requests can be submitted to Fal Deryası and will be handled within the legally required timeframe.
---
10. Contact & Requests Users may submit GDPR-related requests to Fal Deryası.
All requests are reviewed and responded to in accordance with GDPR requirements.
---
11. Policy Updates Fal Deryası reserves the right to update this GDPR & Privacy Policy at any time.
Updates become effective once published on the platform. Users are encouraged to review the policy periodically.
---
12. Effective Date This GDPR & Privacy Policy enters into force as of the date it is published on Fal Deryası.
Continued use of the platform constitutes acceptance of this policy.
---
Last updated: 01/26/2026

