Last updated:
1. Who we are
This privacy notice is issued by İlhan ŞEBİKBAY - Nist Reklam ve Metal Tic. (MERSIS no. 3124-3682-0980-0001, registered address: Cevizlik Mah. Akın 3 İşhanı No: 3 Daire: 15, Bakırköy, Istanbul, Türkiye) ("DealersPay", "we") as data controller under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and, where it applies to you, the EU and UK General Data Protection Regulation ("GDPR").
For anything related to your personal data, contact us at [email protected].
2. Scope and our role
This notice covers visitors to dealerspay.com, people who submit the demo request or contact forms, representatives of our customers, and users of the DealersPay platform (admin panel, dealer portal and payment pages).
Our role depends on whose data it is:
- We are the data controller for website visitors, demo and contact requests, customer representatives and platform user accounts.
- For dealer, account and payment data that our customers ("creditor companies") upload to or process through the platform, the creditor company is the data controller. DealersPay processes that data only on the creditor company's instructions, as a data processor.
- If you paid a company through the platform, please direct requests about that payment to the company you paid first. If such a request reaches us, we forward it to that company without delay and help them answer it.
3. Personal data we process
| Category | Data | Source |
|---|---|---|
| Identity | First and last name | Forms, platform account |
| Contact | Email address, phone number, company you work for | Forms, platform account |
| Customer transaction | Demo request details (industry, notes), the content of your message, support correspondence | Forms, email |
| Security | IP address, browser and device information (user agent), session and sign-in records, audit logs of actions taken in the panel | Automatically, from server logs |
| Financial (platform only) | Payment amount, currency, number of instalments, cardholder name, first 6 and last 4 digits of the card number, issuing bank and card type, 3D Secure result, the payment provider's transaction reference | Payment page and payment provider |
We never store the full card number, the expiry date or the security code (CVV). They are sent only at the moment of payment, over an encrypted connection, to a licensed payment institution or bank.
We do not collect special categories of personal data (health, biometric data, religion, ethnic origin, etc.). Please do not include such information in forms or messages.
4. Why we process it
- To receive your demo request, create your demo accounts and email you the sign-in details
- To answer your messages and send the quote or information you asked for
- To enter into and perform contracts with our customers and to open and manage platform accounts
- To pass payments made through the platform to the payment provider, complete them, issue receipts and run refund and reconciliation processes
- To prevent abuse, fraud, unauthorised access and automated (bot) traffic and to keep our systems secure
- To meet our legal obligations and respond to requests from competent authorities and courts
- To establish, exercise or defend legal claims
We do not use your personal data for automated decision-making or profiling, and we do not send you marketing emails or text messages without your prior consent.
5. Legal bases
| Basis | KVKK | GDPR | Used for |
|---|---|---|---|
| Contract | Art. 5/2(c) | Art. 6(1)(b) | Demo requests, quotes, customer contracts, platform accounts, payments |
| Legal obligation | Art. 5/2(ç) | Art. 6(1)(c) | Tax, commercial and payment-services record keeping |
| Legal claims | Art. 5/2(e) | Art. 6(1)(f) | Disputes, objections and complaints |
| Legitimate interests | Art. 5/2(f) | Art. 6(1)(f) | Security logs, abuse prevention, service quality |
We do not rely on consent for any current processing. If we ever start processing that requires consent (for example marketing messages), we will ask for it separately.
6. Who we share it with
We do not sell your personal data or share it for advertising. We share it only as far as necessary for the purposes above:
| Recipient | Purpose | Location |
|---|---|---|
| Payment institutions and banks licensed under Turkish Law No. 6493 | Processing payments, 3D Secure authentication, refunds and chargebacks | Türkiye |
| The creditor company you paid (our customer) | Posting the payment to the right account and issuing receipts | Türkiye |
| Our server and hosting provider | Hosting our systems | Türkiye |
| Brevo (Sendinblue SAS) | Sending transactional emails (demo sign-in details, notifications) | France (EU) |
| Cloudflare, Inc. | Delivering the website quickly and securely and blocking attacks (IP address and request data) | USA and global network |
| Google LLC (Google Fonts) | Loading the website font (IP address and browser data) | USA |
| Our legal, accounting and audit advisers | Legal and financial obligations | Türkiye |
| Competent public authorities, courts and enforcement offices | Requests we are legally required to fulfil | Türkiye |
Transfers outside Türkiye are made with the safeguards required by Article 9 KVKK, primarily the standard contracts published by the Turkish Personal Data Protection Authority. Where GDPR applies, transfers outside the EEA/UK rely on adequacy decisions or the European Commission's Standard Contractual Clauses.
7. How long we keep it
| Data | Retention |
|---|---|
| Demo requests | 2 years from the request |
| Demo accounts | Access is closed 24 hours after creation; the records are kept together with the demo request |
| Contact messages and correspondence | 2 years from the last message |
| Contracts, invoices and payment records | 10 years (Turkish Commercial Code Art. 82, Tax Procedure Law Art. 253) |
| Security, access and audit logs | 2 years |
When the retention period ends or the reason for processing no longer exists, we delete, destroy or anonymise the data at the latest in the next six-monthly periodic destruction cycle.
8. How we protect it
- All connections are encrypted with TLS (HTTPS).
- Passwords are stored as one-way hashes, and card data is not stored.
- Access to systems is restricted by role, and actions in the panel are recorded in an audit log.
- Forms are protected by rate limits and bot protection, and requests between the website and our servers are signed.
- In the event of a data breach we notify the supervisory authority and affected people as required by law.
9. Your rights
Under Article 11 KVKK you have the right to:
- learn whether your personal data is processed and, if so, request information about it
- learn the purpose of processing and whether it is used accordingly
- know the third parties it is transferred to, in Türkiye or abroad
- have it corrected if it is incomplete or inaccurate
- have it deleted or destroyed under the conditions of Article 7 KVKK
- have third parties it was transferred to informed of any correction, deletion or destruction
- object to a result against you that arises solely from automated analysis
- claim compensation for damage caused by unlawful processing
If GDPR applies to you, you also have the rights of access, rectification, erasure, restriction, data portability and objection to processing based on legitimate interests, and the right to lodge a complaint with the data protection authority where you live or work.
10. How to make a request
Send your request with your full name, your Turkish ID number (for foreign nationals: nationality and passport number), your postal address, and, if available, your email address and phone number, together with what you are asking for:
- in writing with a wet signature, in person or through a notary, to: Cevizlik Mah. Akın 3 İşhanı No: 3 Daire: 15, Bakırköy, Istanbul, Türkiye
- by registered electronic mail (KEP), or by email signed with a secure electronic or mobile signature or sent from the email address registered with us, to: [email protected]
We answer free of charge within 30 days at the latest. If the request involves a separate cost, a fee may be charged according to the tariff set by the authority. We may ask for additional information to verify your identity. If your request is refused, you find the answer insufficient or we do not answer in time, you may complain to the Turkish Personal Data Protection Board under Article 14 KVKK.
11. Changes
We may update this notice when the law or our processing activities change. The current version is always published on this page, with the date shown at the top.