Privacy Policy

Last updated: 12 June 2026

This Privacy Policy explains how your personal data is collected, used, protected and shared in connection with the services offered on komshia.com (the "Platform"). The Platform operates in compliance with the EU General Data Protection Regulation (GDPR) and Turkish Law No. 6698 on the Protection of Personal Data (KVKK).

1. Data Controller

The data controller is Komshia, a company incorporated under the laws of Bulgaria (Burgas, Bulgaria). All privacy-related requests can be sent to info@komshia.com.

2. Scope

This policy covers buyers registered on the Platform, business representatives applying as or approved as sellers, and all visitors. For users resident in Türkiye the KVKK applies; for users resident in the EU the GDPR applies; where the two regimes differ, the provision more favourable to the user prevails.

3. Data We Collect

  • Account data: full name, e-mail address, phone number, password (stored as an irreversible hash).
  • Seller business data: trade name, tax/company number, authorised contact details, bank account details (for payouts).
  • Order data: delivery address, invoice details, order history.
  • Payment data: payments are processed by Stripe (EUR) and iyzico (TRY); your card number is never stored on our servers.
  • Technical data: session cookies, IP address (truncated/masked in security logs), browser information.

4. Social-ID: Pseudonymisation and Encryption

The Platform protects personal data through a pseudonymisation architecture we call "Social-ID". Directly identifying data (PII) such as name, e-mail, phone and address is stored in the database encrypted with the AES-256-GCM algorithm.

In internal processes (order records, support tickets, seller dashboards) users are represented by a unique number (Social-ID) assigned to them instead of their real identity. As a result, no party accessing operational records can see your identity without decryption authorisation.

Encryption keys are managed separately from application data and access is restricted under the principle of least privilege.

5. Purposes and Legal Bases of Processing

  • Conclusion and performance of the membership agreement — performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5/2-c).
  • Handling of orders, payments, escrow and delivery — performance of a contract.
  • Compliance with legal obligations (tax, accounting, anti-money-laundering) — legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5/2-ç).
  • Fraud prevention and platform security — legitimate interest (GDPR Art. 6(1)(f); KVKK Art. 5/2-f).
  • Marketing communications — only with your explicit consent (GDPR Art. 6(1)(a); KVKK Art. 5/1).

6. Recipients of Data

  • Payment institutions: Stripe Payments Europe Ltd. and iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş. — for payment processing.
  • Carriers and logistics companies — only the delivery details required to fulfil the shipment.
  • Hosting and infrastructure providers (EU region, Frankfurt) — encrypted data storage.
  • Competent public authorities — only where legally required.
  • Sellers — the minimum delivery details necessary to fulfil the order; the buyer’s other personal data is not shared with the seller.

7. International Data Transfers

Your data is stored primarily on servers within the European Union (Frankfurt). Transfers between Türkiye and the EU are carried out with appropriate safeguards (including standard contractual clauses and explicit consent) pursuant to KVKK Art. 9 and Chapter V of the GDPR.

8. Retention Periods

  • Account data: for the duration of membership and, after termination, for the statutory limitation period (maximum 10 years).
  • Order and invoice records: 10 years as required by tax legislation.
  • Security and access logs: 2 years.
  • Marketing consent data: until consent is withdrawn.

9. Your Rights

Under GDPR Arts. 15-22 and KVKK Art. 11 you have the following rights:

  • To learn whether your data is processed and to access it,
  • To request rectification of incomplete or inaccurate data,
  • To request erasure or destruction of your data (the "right to be forgotten"),
  • To request restriction of processing and to object to processing,
  • Data portability (receiving your data in a structured format),
  • To object to outcomes produced against you solely by automated analysis,
  • To claim compensation in case of damage.

10. Requests and Complaints

To exercise your rights, you may submit a written request to info@komshia.com. Requests are answered free of charge within 30 days at the latest. You also retain the right to lodge a complaint with the Turkish Personal Data Protection Authority (KVKK), the Bulgarian Commission for Personal Data Protection (CPDP), or the supervisory authority of the EU member state in which you reside.

11. Security Measures

All connections are encrypted with TLS; PII fields are stored encrypted with AES-256-GCM; access is restricted via role-based authorisation; personal data is redacted in system logs; rate limiting and security headers (CSP, HSTS) are enforced.

12. Children’s Data and Changes

The Platform is not directed at persons under 18; accounts found to belong to minors are closed and the data deleted.

This policy may be updated; material changes are announced on the Platform. The current version is always published on this page.

Komshia · Burgas, Bulgaria · info@komshia.com