İçeriğe geç

Legal document

Privacy Policy

What we collect, why we process it, who receives it, how long we keep it, and how you exercise your rights.

Last updated:
Version:
1.0
Issued by:
Wemeep Teknoloji Limited Şirketi

In short: we use no advertising or tracking cookies, and visit measurement is cookieless. Your card details never reach Wemeep — they are entered into a PCI DSS Level 1-certified payment form hosted by iyzico. For the data our subscribers upload, we act as a data processor and never use it to train AI models. Live support runs every day, 09:00–18:00 (GMT+3, Türkiye).

1. Who we are and what this policy covers

This Privacy Policy explains how Wemeep Teknoloji Limited Şirketi (“Wemeep”, “we”) processes personal data on wemeep.com, on the Wemeep platform and across our support channels. Wemeep is established in Türkiye and processes personal data under the Turkish Personal Data Protection Law No. 6698 (“KVKK”, Law No. 6698).

Data controller:

Legal nameWemeep Teknoloji Limited Şirketi
AddressYiğitçavuş Mah. Silvan Blv. Dicle Teknokent No: 222, İç Kapı No: 1, Sur / Diyarbakır, Türkiye
MERSİS (central registry) no0801175518600001
Tax office / numberSüleymannazif Vergi Dairesi / 8011755186
E-mail / registered e-mail (KEP)hello@wemeep.com · wemeepteknoloji@hs01.kep.tr
Phone0850 305 54 80

This policy covers three groups of people:

  • Visitors — anyone browsing wemeep.com.
  • Subscribers and their users — businesses that buy the service and the people they authorise.
  • People who contact us — by e-mail, phone, forms or messaging channels.

2. Categories of personal data we process

CategoryExamples
IdentityName, title; national ID / tax ID number where required for invoicing
ContactE-mail address, phone number, business address
Customer transactionOrder records, subscription term, invoice and refund records
FinancialTransaction amount, payment status, iyzico transaction reference, the card’s last four digits and card type (the card number, CVC and expiry date are never processed by Wemeep)
Transaction securityIP address, session records, sign-in/sign-out times, device and browser information, server logs
Legal claimsRequests, complaints and dispute records

3. Purposes and legal bases

PurposeLegal basis (KVKK art. 5)
Setting up the subscription, opening the account, providing the service5/2-(c) — necessary for the formation or performance of a contract
Taking payment and processing refunds5/2-(c) — performance of the contract
Issuing invoices, keeping statutory books and records5/2-(ç) — legal obligation of the data controller
Handling requests, complaints and support conversations5/2-(c) and 5/2-(f) — legitimate interest
Securing our systems, preventing abuse and fraud, keeping logs5/2-(ç) and 5/2-(f)
Establishing and defending legal claims5/2-(e)
Sending commercial electronic messages (marketing)Explicit consent (KVKK art. 5/1) and İYS registration

Personal data is collected through the website and the platform, by e-mail and phone, and through the payment infrastructure. In line with KVKK art. 4 it is processed only in a way that is relevant, limited and proportionate to these purposes. We do not sell, rent or trade personal data for marketing purposes.

4. Payments and card data

Payments are taken through iyzi Ödeme ve Elektronik Para Hizmetleri A.Ş. (iyzico), an electronic money institution licensed by the Central Bank of Türkiye under Law No. 6493.

  • Card number, expiry date and CVC are entered directly into a payment form hosted by iyzico and certified to PCI DSS Level 1. This data is never transmitted to Wemeep servers, and is never seen or stored by Wemeep.
  • The only financial data Wemeep can access is the transaction amount, transaction status, the iyzico transaction reference, and the card’s type and last four digits — needed to match orders, process refunds and keep accounting records.
  • Cardholder verification uses 3D Secure where the issuing bank supports it.
  • If your subscription uses automatic renewal, the card is stored on the iyzico side, not by Wemeep; Wemeep holds only a payment token that cannot be reversed into a card number.
  • iyzico acts as an independent data controller for this processing under its own regulatory framework, and its own privacy policy also applies.

5. Who receives personal data

Personal data is shared under KVKK art. 8, only to the extent required by the purposes above, with the following categories of recipients:

  • The payment institution and banks — taking payment, refunds and chargebacks.
  • Cloud infrastructure and hosting providers — running the application, content delivery and attack protection.
  • The managed database service provider — storing data.
  • Contact-centre and e-mail delivery infrastructure — routing support conversations and sending transactional notifications.
  • The e-invoice integrator and our accountant — invoicing and bookkeeping.
  • Legal advisors — in case of a dispute, to the extent necessary.
  • Competent public authorities — where the law requires it.

Suppliers that act as data processors are bound by contracts imposing confidentiality and data-security obligations under KVKK art. 12. Personal data is never sold, rented or transferred for marketing.

6. International transfers

The cloud infrastructure, content delivery network, contact-centre and e-mail services we use may, by their technical nature, process data on servers located outside Türkiye.

Such transfers are made under KVKK art. 9 as amended by Law No. 7499: on the basis of an adequacy decision of the Turkish Data Protection Board where one exists; otherwise with appropriate safeguards (standard contractual clauses, binding corporate rules or written undertakings); and in occasional cases only under the exceptions in KVKK art. 9/6. You can request up-to-date information about our infrastructure providers and the legal basis of a transfer by writing to hello@wemeep.com.

7. Cookies and similar technologies

wemeep.com uses no advertising, profiling or cross-site tracking cookies, and no visitor-identifying analytics tool is installed. No non-essential record is written to your device before you consent through the cookie banner, where “Reject all” is presented with the same prominence as “Accept all”. You can change or withdraw your choice at any time via Cookie preferences in the footer.

  • cf_clearance (Cloudflare) — a strictly necessary security cookie, written only when a security check is triggered; records that you passed the check.
  • Session and payment cookies — strictly necessary for signing in to your account and completing a payment.
  • Theme and cookie-choice records (local storage) — kept on your device only; never sent to our servers. Wemeep writes no cookies of its own.
  • Cookieless visit measurement — Cloudflare Web Analytics measures page views without writing anything to your device, without fingerprinting and without cross-site tracking; measurements are reported to an endpoint on our own domain.
  • Cloudflare Turnstile — protects the contact form from bots on the page where the form appears; writes no cookies and does not attempt to identify you across sites.

The full cookie table, including retention periods and consent bases, is published in the Turkish KVKK privacy notice.

8. Support conversations and messaging channels

You can reach us by e-mail (hello@wemeep.com), by phone (0850 305 54 80) and — where offered — through business messaging channels such as Apple Messages for Business. Live agents are available every day, 09:00–18:00 (GMT+3, Türkiye).

  • When you contact us, we process the content of the conversation, the contact details or channel identifiers it arrives with, and related transaction records, in order to answer your request and keep a record of it (KVKK art. 5/2-(c) and (f)).
  • Messaging platforms identify you to us with an opaque, platform-generated identifier; for example, Apple Messages for Business does not share your phone number or Apple ID with us. The platform provider processes the delivery of messages under its own privacy policy.
  • Support conversations are routed through our contact-centre infrastructure (Amazon Connect, operated by Amazon Web Services), which acts as our data processor and is bound by data-processing terms.
  • Support correspondence is retained for two years after the request is closed, then deleted or anonymised.

9. How long we keep personal data

DataRetentionBasis
Invoices, orders and accounting records10 yearsTurkish Commercial Code art. 82; tax legislation
Subscription and contract records10 years after the contract endsCode of Obligations art. 146 (limitation period)
Account and user data30 days after the subscription ends (export window), then deleted or anonymisedKVKK arts. 4 and 7
Server and traffic logs1–2 yearsLaw No. 5651 and secondary legislation
Support correspondence2 years after the request is closedLegitimate interest
Commercial message consent records3 years after consent is withdrawnCommercial communications legislation

10. Security measures

  • All traffic is encrypted with TLS; the database sits in a private network with no public endpoint.
  • Tenant data is isolated at the database level with row-level security, which the application layer cannot switch off.
  • Authorisation is permission-based and deny-by-default, re-checked server-side on every request.
  • Passwords and verification/reset tokens are stored hashed, are single-use and are never logged.
  • Personal data and secrets are redacted from logs; least-privilege access with access records.
  • In the event of a data breach, the affected individuals and the Turkish Data Protection Board are notified without undue delay in accordance with KVKK art. 12/5.

11. Data our subscribers upload: Wemeep as processor

Subscribers may upload personal data relating to their own dealers, customers or employees. For that data, the subscriber is the data controller and Wemeep is the data processor: we process it only on the subscriber’s instructions and for the performance of the service, we do not use it for our own commercial purposes — including training AI models — and we do not sell it.

The scope of this relationship, the sub-processors, security measures and breach-notification duties are set out in the Data Processing Agreement (published in Turkish), which can also be requested in signed form via hello@wemeep.com.

12. Your rights and how to exercise them

Under KVKK art. 11 you have the right to:

  • learn whether your personal data is processed;
  • request information about that processing;
  • learn the purpose of processing and whether data is used in line with it;
  • know the third parties to whom data is transferred, in Türkiye or abroad;
  • request correction of incomplete or inaccurate data, and request deletion or destruction under KVKK art. 7, with notification to recipients;
  • object to a result produced exclusively by automated analysis of your data;
  • claim compensation for damage caused by unlawful processing.

You can apply by e-mail to hello@wemeep.com (from the address registered with us), by registered e-mail to wemeepteknoloji@hs01.kep.tr, or by signed letter to Yiğitçavuş Mah. Silvan Blv. Dicle Teknokent No: 222, İç Kapı No: 1, Sur / Diyarbakır, Türkiye. Applications are answered free of charge within 30 days at the latest. If your application is rejected or not answered in time, you may lodge a complaint with the Turkish Personal Data Protection Board (KVKK art. 14). These channels are available wherever you are located.

13. Children

Wemeep is a business-to-business service and is not directed at anyone under 18. We do not knowingly collect children’s data; if we learn that such data has been processed, the record is deleted without delay.

14. Changes, language and contact

We may update this policy when legislation or the service changes. The current version is always published on this page, with the last-updated date and version number shown at the top. Material changes are additionally communicated to subscribers by e-mail.

This Privacy Policy is published in English for international users and platform reviews. For matters governed by Turkish law, the Turkish KVKK privacy notice and cookie policy is the authoritative text; in the event of a conflict, the Turkish text prevails.

Questions and requests: hello@wemeep.com · 0850 305 54 80

Company details

Wemeep Teknoloji Limited Şirketi · Yiğitçavuş Mah. Silvan Blv. Dicle Teknokent No: 222, İç Kapı No: 1, Sur / Diyarbakır · Süleymannazif Vergi Dairesi Tax No 8011755186 · MERSİS 0801175518600001 · Trade Registry No 50696 · KEP wemeepteknoloji@hs01.kep.tr · hello@wemeep.com · 0850 305 54 80