Privacy Policy

PRIVACY POLICY

1. Protection of Personal Data and Processing Principles

Stoneline Yapı Ürünleri Sanayi Anonim Şirketi (hereinafter referred to as “StoneArchive”) adopts the protection of the confidentiality and security of personal data as one of its fundamental principles in accordance with the Law No. 6698 on the Protection of Personal Data (“KVKK”).

In this context, StoneArchive takes the necessary technical and administrative measures to protect personal data against unauthorized access, loss, disclosure, or any unlawful processing activities. These measures include system access controls, secure data transfer methods, business continuity precautions, and other institutional security mechanisms.

StoneArchive strictly complies with the principles set forth in Article 4 of KVKK when processing personal data, including:

. processing in compliance with the law and good faith principles,
. ensuring accuracy and keeping data up to date when necessary,
. processing for specific, explicit, and legitimate purposes,
. ensuring that processing is relevant, limited, and proportionate to the purpose,
. retaining personal data only for the period required for the purpose for which it is processed.

2. Definitions

For the purposes of this Policy:

KVKK: Law No. 6698 on the Protection of Personal Data
Personal Data: Any information relating to an identified or identifiable natural person
Commercial Electronic Message: Messages containing data, audio, or visual content sent for commercial purposes via electronic means such as telephone, call centers, fax, automatic calling machines, smart voice recording systems, email, or SMS
Commercial Electronic Message Management System (İYS): The system that enables obtaining consent for commercial electronic messages, exercising the right to opt out, and managing complaint processes
Commercial Communication: Any communication related to electronic commerce conducted for profit-making purposes within professional or commercial activities, excluding domain names and email addresses
Processing of Personal Data: Any operation performed on personal data, such as obtaining, reviewing, recording, or using
Data Controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system


3. Channels for Collecting and Processing Personal Data

The personal data processed by StoneArchive may vary depending on the type and nature of the relationship between StoneArchive and data subjects, the communication channels used, and the purpose of such relationship.

In this scope:

. Browsing data is obtained through cookies used during visits to StoneArchive websites.
. Identity and contact information declared by data subjects may be collected through data subject application forms or sponsorship application forms available on the website.
. Identity and contact data of customers or potential customers are processed to effectively manage requests, suggestions, and complaints submitted through the call center.

Additionally, personal data obtained from participants in fairs, organizations, events, and market research activities organized by StoneArchive; data obtained from media outlets and local government websites; data collected through StoneArchive blogs, competitions, surveys, games, campaigns, and similar websites; and identity, contact, and visual data verbally or electronically provided by data subjects are processed.

Furthermore, information shared through phone calls, email correspondence, and similar communication channels with customers and potential customers constitutes part of personal data processing activities. The basic contact information obtained through these channels is processed to ensure effective use of StoneArchive’s products and services.

All such personal data processing activities are carried out in compliance with KVKK and relevant legislation and within the framework of the principles defined above.

4. Purposes of Processing Personal Data

Personal data is processed by StoneArchive solely for purposes determined in accordance with KVKK and relevant legislation and is retained for the period required by these purposes.

In this context, data obtained through the application is processed to provide effective services by responding to and managing questions, requests, suggestions, and complaints submitted by users.
Additionally, data processing purposes include conducting marketing activities, recording communications with data subjects to ensure service and transaction security, measuring user/customer satisfaction, and contacting relevant individuals accordingly.

Furthermore, data obtained through cookies during application visits is processed to enhance communication activities, enable targeted advertising, and offer personalized product recommendations.

5. Transfer of Personal Data

In line with the activities carried out by StoneArchive and the processing purposes stated above, personal data may be shared with third parties only in accordance with KVKK and relevant legislation and by taking the necessary administrative and technical measures to ensure data security.

Accordingly, data may be transferred:

. to StoneArchive’s affiliated companies operating abroad for administrative processes,
. to internal business units and production facilities to ensure coordination, cooperation, and efficiency,
. to companies and system administrators providing technological support,
. to research companies, agencies, and marketing firms for customer satisfaction, brand reputation, and campaign/promotion activities.

Additionally, personal data may be shared with human resources firms within the scope of recruitment processes; legal advisors for legal and compliance activities; payment institutions, tax offices, banks, audit firms, and relevant public institutions for payment and invoicing processes.

Similarly, personal data may be shared with companies hosting or operating StoneArchive websites, data analytics firms, customer service providers, and third parties acting on behalf of StoneArchive for the evaluation of requests, complaints, and suggestions.

Furthermore, personal data may also be transferred to sponsors, advertisers, advertising networks, ad servers, social media platforms, analytics companies, and third parties providing marketing, promotion, or data enrichment services.

In cases of legal obligations, personal data may be shared with relevant public institutions and organizations. This includes circumstances such as fulfilling legal obligations, responding to information requests from authorized administrative or judicial authorities, enforcing or verifying StoneArchive policies, preventing fraud or security vulnerabilities, responding to emergencies, or protecting the rights, property, and safety of StoneArchive, its users, or the public.

6. Transfer of Personal Data Abroad

StoneArchive maintains its commitment to personal data protection in international data transfers. Within the scope of this Policy, personal data may be transferred abroad only to the extent necessary for carrying out relevant activities.

Such transfers may include regions where StoneArchive’s or its suppliers’ servers are located, such as European Union countries and the United Kingdom.

During this process, the confidentiality, integrity, and security of personal data are prioritized, and all necessary technical, administrative, and contractual measures are fully implemented to protect data subject rights. Data is transferred solely for processing and storage purposes or for other purposes specified in the Information Notice, in compliance with international data protection standards.

Thus, personal data is managed in accordance with both legal regulations and StoneArchive’s security policies, ensuring the protection of data subject rights.

7. Security of Personal Data

In accordance with Article 12 of KVKK, StoneArchive takes all necessary administrative and technical measures to prevent unlawful processing of personal data and unauthorized access.

Information security forms the foundation of StoneArchive’s data protection approach. Physical and environmental security measures across all StoneArchive locations are regularly reviewed and improved.

Key security practices include:

. managing access through authorization and approval mechanisms,
. regularly auditing and updating access rights,
. logging processing activities and enabling retrospective audits,
. conducting periodic tests and controls to identify system vulnerabilities,
. performing risk analyses against potential security breaches,
. recording and resolving security incidents.

StoneArchive supports data security not only through technical measures but also through administrative arrangements, employee awareness initiatives, training programs, and internal policies, making personal data protection an integral part of corporate culture.

8. Rights of the Data Subject

Natural persons whose personal data is processed are deemed data subjects under KVKK and may exercise their rights before StoneArchive.

Accordingly, data subjects have the right to:

. learn whether their personal data is processed,
. request information if their data has been processed,
. learn the purpose of processing and whether it is used in accordance with that purpose,
. know the third parties to whom personal data is transferred domestically or abroad,
. request correction or updating of incomplete or inaccurate data,
. request deletion or destruction of personal data when the reasons for processing cease.

Data subjects may also request that correction or deletion actions be notified to third parties to whom data has been transferred, object to outcomes arising solely from automated processing, and request compensation for damages incurred due to unlawful processing.

To exercise any of the rights listed above, data subjects may submit a request by completing the “DATA SUBJECT APPLICATION FORM” available within the application.