1. Who we are and what this policy covers
This Privacy Policy explains how Wemeep Teknoloji Limited Şirketi (“Wemeep”, “we”) processes personal data on wemeep.com, on the Wemeep platform and across our support channels. Wemeep is established in Türkiye and processes personal data under the Turkish Personal Data Protection Law No. 6698 (“KVKK”, Law No. 6698).
Data controller:
| Legal name | Wemeep Teknoloji Limited Şirketi |
| Address | Yiğitçavuş Mah. Silvan Blv. Dicle Teknokent No: 222, İç Kapı No: 1, Sur / Diyarbakır, Türkiye |
| MERSİS (central registry) no | 0801175518600001 |
| Tax office / number | Süleymannazif Vergi Dairesi / 8011755186 |
| E-mail / registered e-mail (KEP) | hello@wemeep.com · wemeepteknoloji@hs01.kep.tr |
| Phone | 0850 305 54 80 |
This policy covers three groups of people:
- Visitors — anyone browsing wemeep.com.
- Subscribers and their users — businesses that buy the service and the people they authorise.
- People who contact us — by e-mail, phone, forms or messaging channels.
2. Categories of personal data we process
| Category | Examples |
|---|---|
| Identity | Name, title; national ID / tax ID number where required for invoicing |
| Contact | E-mail address, phone number, business address |
| Customer transaction | Order records, subscription term, invoice and refund records |
| Financial | Transaction amount, payment status, iyzico transaction reference, the card’s last four digits and card type (the card number, CVC and expiry date are never processed by Wemeep) |
| Transaction security | IP address, session records, sign-in/sign-out times, device and browser information, server logs |
| Legal claims | Requests, complaints and dispute records |
3. Purposes and legal bases
| Purpose | Legal basis (KVKK art. 5) |
|---|---|
| Setting up the subscription, opening the account, providing the service | 5/2-(c) — necessary for the formation or performance of a contract |
| Taking payment and processing refunds | 5/2-(c) — performance of the contract |
| Issuing invoices, keeping statutory books and records | 5/2-(ç) — legal obligation of the data controller |
| Handling requests, complaints and support conversations | 5/2-(c) and 5/2-(f) — legitimate interest |
| Securing our systems, preventing abuse and fraud, keeping logs | 5/2-(ç) and 5/2-(f) |
| Establishing and defending legal claims | 5/2-(e) |
| Sending commercial electronic messages (marketing) | Explicit consent (KVKK art. 5/1) and İYS registration |
Personal data is collected through the website and the platform, by e-mail and phone, and through the payment infrastructure. In line with KVKK art. 4 it is processed only in a way that is relevant, limited and proportionate to these purposes. We do not sell, rent or trade personal data for marketing purposes.
4. Payments and card data
Payments are taken through iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş. (iyzico), an electronic money institution licensed by the Central Bank of Türkiye under Law No. 6493.
- Card number, expiry date and CVC are entered directly into a payment form hosted by iyzico and certified to PCI DSS Level 1. This data is never transmitted to Wemeep servers, and is never seen or stored by Wemeep.
- The only financial data Wemeep can access is the transaction amount, transaction status, the iyzico transaction reference, and the card’s type and last four digits — needed to match orders, process refunds and keep accounting records.
- Cardholder verification uses 3D Secure where the issuing bank supports it.
- If your subscription uses automatic renewal, the card is stored on the iyzico side, not by Wemeep; Wemeep holds only a payment token that cannot be reversed into a card number.
- iyzico acts as an independent data controller for this processing under its own regulatory framework, and its own privacy policy also applies.
6. International transfers
The cloud infrastructure, content delivery network, contact-centre and e-mail services we use may, by their technical nature, process data on servers located outside Türkiye.
Such transfers are made under KVKK art. 9 as amended by Law No. 7499: on the basis of an adequacy decision of the Turkish Data Protection Board where one exists; otherwise with appropriate safeguards (standard contractual clauses, binding corporate rules or written undertakings); and in occasional cases only under the exceptions in KVKK art. 9/6. You can request up-to-date information about our infrastructure providers and the legal basis of a transfer by writing to hello@wemeep.com.
8. Support conversations and messaging channels
You can reach us by e-mail (hello@wemeep.com), by phone (0850 305 54 80) and — where offered — through business messaging channels such as Apple Messages for Business. Live agents are available every day, 09:00–18:00 (GMT+3, Türkiye).
- When you contact us, we process the content of the conversation, the contact details or channel identifiers it arrives with, and related transaction records, in order to answer your request and keep a record of it (KVKK art. 5/2-(c) and (f)).
- Messaging platforms identify you to us with an opaque, platform-generated identifier; for example, Apple Messages for Business does not share your phone number or Apple ID with us. The platform provider processes the delivery of messages under its own privacy policy.
- Support conversations are routed through our contact-centre infrastructure (Amazon Connect, operated by Amazon Web Services), which acts as our data processor and is bound by data-processing terms.
- Support correspondence is retained for two years after the request is closed, then deleted or anonymised.
9. How long we keep personal data
| Data | Retention | Basis |
|---|---|---|
| Invoices, orders and accounting records | 10 years | Turkish Commercial Code art. 82; tax legislation |
| Subscription and contract records | 10 years after the contract ends | Code of Obligations art. 146 (limitation period) |
| Account and user data | 30 days after the subscription ends (export window), then deleted or anonymised | KVKK arts. 4 and 7 |
| Server and traffic logs | 1–2 years | Law No. 5651 and secondary legislation |
| Support correspondence | 2 years after the request is closed | Legitimate interest |
| Commercial message consent records | 3 years after consent is withdrawn | Commercial communications legislation |
10. Security measures
- All traffic is encrypted with TLS; the database sits in a private network with no public endpoint.
- Tenant data is isolated at the database level with row-level security, which the application layer cannot switch off.
- Authorisation is permission-based and deny-by-default, re-checked server-side on every request.
- Passwords and verification/reset tokens are stored hashed, are single-use and are never logged.
- Personal data and secrets are redacted from logs; least-privilege access with access records.
- In the event of a data breach, the affected individuals and the Turkish Data Protection Board are notified without undue delay in accordance with KVKK art. 12/5.
11. Data our subscribers upload: Wemeep as processor
Subscribers may upload personal data relating to their own dealers, customers or employees. For that data, the subscriber is the data controller and Wemeep is the data processor: we process it only on the subscriber’s instructions and for the performance of the service, we do not use it for our own commercial purposes — including training AI models — and we do not sell it.
The scope of this relationship, the sub-processors, security measures and breach-notification duties are set out in the Data Processing Agreement (published in Turkish), which can also be requested in signed form via hello@wemeep.com.
12. Your rights and how to exercise them
Under KVKK art. 11 you have the right to:
- learn whether your personal data is processed;
- request information about that processing;
- learn the purpose of processing and whether data is used in line with it;
- know the third parties to whom data is transferred, in Türkiye or abroad;
- request correction of incomplete or inaccurate data, and request deletion or destruction under KVKK art. 7, with notification to recipients;
- object to a result produced exclusively by automated analysis of your data;
- claim compensation for damage caused by unlawful processing.
You can apply by e-mail to hello@wemeep.com (from the address registered with us), by registered e-mail to wemeepteknoloji@hs01.kep.tr, or by signed letter to Yiğitçavuş Mah. Silvan Blv. Dicle Teknokent No: 222, İç Kapı No: 1, Sur / Diyarbakır, Türkiye. Applications are answered free of charge within 30 days at the latest. If your application is rejected or not answered in time, you may lodge a complaint with the Turkish Personal Data Protection Board (KVKK art. 14). These channels are available wherever you are located.
13. Children
Wemeep is a business-to-business service and is not directed at anyone under 18. We do not knowingly collect children’s data; if we learn that such data has been processed, the record is deleted without delay.
14. Changes, language and contact
We may update this policy when legislation or the service changes. The current version is always published on this page, with the last-updated date and version number shown at the top. Material changes are additionally communicated to subscribers by e-mail.
This Privacy Policy is published in English for international users and platform reviews. For matters governed by Turkish law, the Turkish KVKK privacy notice and cookie policy is the authoritative text; in the event of a conflict, the Turkish text prevails.
Questions and requests: hello@wemeep.com · 0850 305 54 80