Menu

Privacy and Payment Security

DUNA PRIVACY POLICY

Privacy and Payment Security

Learn about the purposes for which your personal data are processed, the parties with whom they may be shared, the principal measures applied to payment security and your rights under the Turkish Personal Data Protection Law (KVKK).

01

Lawful processing

Personal data are processed to the extent necessary for specified, explicit and legitimate purposes.

02

Controlled transfers

Data are transferred only to parties necessary for the provision of services and fulfilment of legal obligations.

03

Secure payments

Payments are processed through the secure infrastructure of a bank or an authorised payment service provider.

04

Right to apply

You may submit your requests under the KVKK by email, registered electronic mail (KEP) or written application.

1Data Controller

The data controller under Law No. 6698 on the Protection of Personal Data is:

DUNA Dış Ticaret Ltd. Şti.

Perpa Ticaret Merkezi, B Blok, Kat 2, No: 75, Okmeydanı, Şişli, İstanbul, Türkiye

Telephone: +90 212 222 72 20

Email: info@duna.com.tr

Registered Electronic Mail (KEP): duna@hs03.kep.tr

This page provides general information about our privacy and payment security practices. Details of personal data processing activities are explained in the relevant KVKK privacy notices.

2Personal Data That May Be Processed

The following categories of data may be processed in connection with membership, orders, delivery, payment, customer service and use of the Website:

Identity informationFirst name, surname, authorised representative details and similar identity information.
Contact informationTelephone number, email address, billing address and delivery address.
Company informationTrade name, tax office, tax identification number and company representative details.
Customer transaction informationOrders, purchase history, returns, requests and support records.
Financial informationPayment method, invoices, current account information and payment transaction records.
Transaction security informationIP address, login records, device information and Website usage data.

3Purposes of Processing Personal Data

  • Creating and managing membership and corporate customer records.
  • Managing order, payment, invoicing, shipment, delivery, return, service and warranty processes.
  • Responding to customer requests, complaints and support applications.
  • Carrying out current account, accounting, finance and tax procedures.
  • Ensuring Website security and preventing unauthorised transactions and misuse.
  • Developing products and services, measuring Website performance and improving the user experience.
  • Sending campaign and informational communications to persons who have consented to receive commercial electronic communications.
  • Fulfilling legal obligations and responding to requests from authorised public authorities.

Personal data may be processed on the legal bases of entering into or performing a contract, fulfilling legal obligations, establishing, exercising or protecting a right, pursuing legitimate interests and, where necessary, obtaining explicit consent.

4Transfer of Personal Data

Your personal data are not sold for any purpose. However, data necessary for the provision of services and fulfilment of legal obligations may be shared, strictly for the relevant purpose, with the following parties:

Cargo and logistics companiesFor delivery of orders to the specified address.
Banks and payment institutionsFor payment, collection, refund and transaction security processes.
E-invoicing and accounting service providersFor invoicing, accounting and compliance with statutory record-keeping obligations.
Information technology service providersFor hosting, software, data backup, security and technical support services.
Legal and financial advisersFor the protection of rights, management of disputes and provision of advisory services.
Authorised public authoritiesFor statutory notifications and responses to requests from competent authorities.

Where the use of overseas infrastructure, analytics or cloud services involves a transfer of personal data abroad, the transfer is carried out in accordance with the conditions and appropriate safeguards set out in Article 9 of the KVKK.

5Cookies and Website Use

Cookies may be used to operate the Website, preserve session and shopping-cart information, maintain security, remember preferences and measure Website performance.

Non-essential analytics, personalisation or marketing cookies are activated, to the extent applicable, in accordance with the User’s preferences and permissions.

Information collected through cookies, including IP addresses, device identifiers and usage activity, may constitute personal data in the relevant circumstances. Details regarding the use of cookies are provided in the relevant cookie notice.

6Data Retention and Security

Personal data are retained for as long as required by the purposes for which they are processed and within the statutory retention periods prescribed by applicable legislation. When the retention period expires and the conditions for processing no longer apply, the data are erased, destroyed or anonymised in accordance with applicable legislation.

Reasonable technical and administrative measures, including access authorisation, user authentication, logging, backup and secure communications, are applied to protect personal data against unlawful access, loss, alteration or disclosure.

Although absolute security cannot be guaranteed for any system used over the internet, identified security risks are assessed and the necessary measures are updated.

Payment and Credit Card Security

Payments are processed through the secure payment infrastructure of the relevant bank or authorised payment service provider.

Sensitive card information, including the credit card number, expiry date and security code, is transmitted over a secure connection to the relevant bank or payment institution for the purpose of processing the payment. DUNA does not store your complete credit card number or security code in plain form within its own systems.

Depending on the nature of the transaction and the bank’s practices, 3D Secure or similar additional authentication methods may be used during payment.

HTTPS/TLS connectionData transmitted between your browser and the Website are communicated over an encrypted connection.
Bank authenticationPayment authorisation and the required security checks are carried out by the bank or payment institution.
Restricted data accessPayment transaction records may be accessed only by persons authorised as required by their duties.
For your account securityDo not share your password or card information with other persons. Do not leave your membership session open on shared devices. If you notice a suspicious transaction, contact your bank and DUNA without delay.

7Your Rights Under the KVKK

Under Article 11 of Law No. 6698, you have the following rights in relation to your personal data:

  • To learn whether your personal data are being processed.
  • To request information if your personal data have been processed.
  • To learn the purpose of processing and whether the data are used in accordance with that purpose.
  • To learn the third parties to whom the data are transferred in Türkiye or abroad.
  • To request correction of personal data that have been processed incompletely or inaccurately.
  • To request erasure or destruction of personal data under the conditions specified by law.
  • To request notification of correction, erasure or destruction operations to third parties to whom the data have been transferred.
  • To object to an outcome arising against you as a result of analysis conducted exclusively through automated systems.
  • To claim compensation if you suffer damage due to the unlawful processing of personal data.

KVKK Applications

You may submit your requests under the KVKK to DUNA Dış Ticaret Ltd. Şti. through the following channels, together with information sufficient to verify your identity and request:

Written applicationPerpa Ticaret Merkezi, B Blok, Kat 2, No: 75, Okmeydanı, Şişli, İstanbul, Türkiye
Registered Electronic Mail (KEP)duna@hs03.kep.tr

Applications are concluded as soon as possible according to the nature of the request and no later than 30 days. If processing the application requires an additional cost, the fees specified in the tariff determined by the Turkish Personal Data Protection Board may be charged.

T-Soft 360 Logo Powered by T-SOFT E-Commerce