Privacy Policy: At MEDEX ELECTRONIC COMMERCE AND SERVICES INC. (“MEDEX”) (medexsepeti.com), we work to protect the privacy of our members who use our site to ensure that our users can benefit from our services safely and completely. In this context, the MEDEX Privacy Policy (“Policy”) has been prepared to process our members’ personal data in full compliance with the Personal Data Protection Law No. 6698 (“Law”) and to inform our users in this regard. The medexsepeti.com cookie policy is an integral part of this Policy.
The purpose of this Policy is to determine the terms and conditions regarding the use of personal data shared with MEDEX by the members/visitors/users of the medexsepeti.com website and mobile application (collectively referred to as the “Platform”) operated by MEDEX or generated by MEDEX during the Data Subject’s use of the Platform (all collectively referred to as “Data Subject”).
Which Data is Processed? Below is a list of data processed by MEDEX, which is considered personal data under the Law. Unless explicitly stated otherwise, the term “personal data” within the scope of this Policy will cover the information listed below.
- Identity Information
- Name and surname
- Contact Information
- User Information
- User Transaction Information
- Email address
- Phone number
- Transaction Security Information
- Financial Information
- Marketing Information
- Request/Complaint Management Information
- We may provide paid products and/or services within the service. In this case, we use third-party services for payment transactions (e.g., payment processors). We will not store or collect your payment card information. This information is provided directly to our third-party payment processors whose use of your personal information is subject to their Privacy Policies. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express, and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
To complete the shopping transaction, the user must enter their bank card information on the https://medexsepeti.com/ website to the payment server. At this step, user data is not stored in the database but processed directly.
In accordance with Articles 3 and 7 of the Personal Data Protection Law, data that has been irreversibly anonymized will not be considered personal data according to the provisions of the said law, and processing activities related to this data will be carried out without being bound by the provisions of this Policy.
Please note that this is a partial translation, and the text may contain legal terms specific to the jurisdiction it applies to. It is advisable to consult with a legal expert for a comprehensive understanding. If you need further assistance or more translations, feel free to ask.
Purposes of Personal Data Processing MEDEX processes the personal data provided by the Data Subject for the purposes of creating membership registration and account and keeping related records, enabling the Data Subject to benefit from the services provided through the Platform, detecting system errors to monitor performance and improve the operation of the Platform, and providing maintenance and backup services. These activities are necessary for the business units to carry out and manage the related business processes to benefit the relevant individuals from the products and services offered by MEDEX, including planning and executing activities required to customize these products and services according to the preferences, usage habits, and needs of the relevant individuals, and to suggest and promote them. The necessary work by the relevant business units and the related business processes will be conducted for the execution of commercial activities carried out by MEDEX, ensuring the legal, technical, and commercial-business security of MEDEX and the individuals it is in business relations with, and for the planning and execution of MEDEX’s commercial and/or business strategies.
As MEDEX, we process your personal data to provide our services to our customers in the best way possible, to fulfill the requirements of the contract and technology accurately, and to develop the offered products and services according to the needs of our customers. For this purpose, under the Law No. 6563 on the Regulation of Electronic Commerce, the Law No. 6502 on Consumer Protection, and the regulations prepared based on these laws, such as the Regulation on Service Providers and Intermediary Service Providers in Electronic Commerce published in the Official Gazette No. 29457 dated 26.08.2015, the Regulation on Distance Contracts published in the Official Gazette No. 29188 dated 27.11.2014, and other relevant legislation, we record identity, address, and other necessary information to determine the transaction owner’s details.
For the mandatory payment systems in the field of electronic payment and banking, to arrange all records and documents that will be the basis for electronic contracts and paper-based processing, to comply with the information storage, reporting, and informing obligations foreseen by other authorities as required by the legislation,
To provide information to prosecutors, courts, and relevant public institutions and officials in matters related to public safety and in case of legal disputes that may arise, upon request and as required by legal legislation,
Personal Data to be Processed with the Explicit Consent of the Data Subjects and Purposes of Processing With the explicit consent of the Data Subject, MEDEX can process data to track the movements of the Data Subjects on the Platform to enhance user experience, create statistics, perform profiling, direct marketing and remarketing, create and convey special promotion suggestions to the Data Subject, and use the data obtained in this context in all kinds of advertising and material content. MEDEX can share this data with the parties mentioned below.
Transfer of Personal Data: MEDEX may transfer personal data belonging to the Data Subject and new data obtained using this personal data to third parties that benefit from MEDEX’s services, limited to the provision of the said services, in order to achieve the purposes set out in this Privacy Policy. MEDEX may share with third parties, including external service providers, hosting service providers (hosting services), law offices, research companies, call centers, etc., who send SMS, for the purpose of enhancing the Data Subject’s experience (including improvement and personalization), ensuring the Data Subject’s security, detecting fraudulent or unauthorized uses, conducting operational evaluation research, correcting errors related to Platform services, and any of the purposes stated in this Privacy Policy.
Information on third parties or organizations to whom your personal data may be transferred: For the purposes mentioned above, the persons/organizations to whom your personal data shared with our Company may be transferred include primarily our Company’s e-commerce infrastructure provider, suppliers, cargo companies, and other related persons and organizations, program partner organizations we cooperate with and/or receive services from as a Data Processor, domestic/foreign organizations, and other third parties.
Personal data may be shared with company officials, shareholders, our business partners, our suppliers, legally authorized public institutions and organizations, and legally authorized private institutions within the framework of the personal data processing conditions and purposes specified in Articles 8 and 9 of the Law, and may be transferred abroad within the framework of the procedures and principles referred to in Article 9 of the Law and the decisions of the Personal Data Protection Board, limited to these purposes.
Method and Legal Reason for Collecting Personal Data: Personal data will be processed in accordance with the Law No. 6698 on the Protection of Personal Data (KVKK) and related secondary regulations.
Personal data is collected through the Platform and electronically. Personal data collected for the legal reasons mentioned above can be processed and transferred for the purposes stated in Articles 5 and 6 of the Law No. 6698 and this Privacy Policy.
Rights of the Personal Data Subject: According to Article 11 of the Law, data subjects have the right to:
- Learn whether personal data is processed,
- Request information if personal data has been processed,
- Learn the purpose of processing personal data and whether they are used appropriately for their purpose,
- Know the third parties to whom personal data is transferred domestically or abroad,
- Request correction of personal data if it is incomplete or incorrectly processed, and request that the process carried out in this context be notified to the third parties to whom the personal data has been transferred,
- Request the deletion or destruction of personal data within the framework of the conditions provided in Article 7 of the KVKK,
- Request notification of the processes related to the correction, deletion, or destruction of personal data to the third parties to whom the personal data has been transferred,
- Object to the emergence of a result against the person himself/herself through the analysis of the processed data exclusively by automated systems,
- Request compensation for damages in case of damage due to the unlawful processing of personal data.
Requests related to the exercise of these rights can be communicated by personal data owners through the methods specified in the Policy on the Processing and Protection of Personal Data prepared by MEDEX within the scope of Law No. 6698, which is located at medexsepeti.com. MEDEX will conclude the said requests within thirty days. MEDEX reserves the right to charge a fee based on the tariff (if any) determined by the Personal Data Protection Board regarding the requests.
Cookie Policy: At MEDEX ELECTRONIC COMMERCE AND SERVICES INC. (“MEDEX”), we work to protect the privacy of individuals using our site to ensure that our users can benefit from our services safely and completely. Like most websites, cookies are used on medexsepeti.com (“Site”) and the mobile application (collectively referred to as “Platform”) to display personal content and advertisements to visitors, perform analytical activities within the site, and track visitor usage habits. This Cookie Policy is an integral part of the medexsepeti.com Privacy Policy. MEDEX has prepared this Cookie Policy (“Policy”) to explain which cookies are used on the Site and how users can manage their preferences regarding this matter. We recommend that you review the medexsepeti.com Privacy Policy for more detailed information regarding the processing of your personal data by medexsepeti.com. What is a Cookie (“Cookie”)? Cookies are small text files stored on your device or network server by browsers from the websites you visit. Cookies are created by the servers associated with the website you visit. This way, when a visitor revisits the same site, the server can recognize it. A cookie is information stored on your computer by a webpage you visit. Cookies are not malicious software or applications that harm your computer. On the contrary, cookies are used to remember the choices you made during your previous visit to the web pages you have visited, thus ensuring that a higher quality service is provided with the correct configuration and information during the second and subsequent visits. Cookies do not contain personal data such as the name, gender, or address of the visitors. For more detailed information about cookies, you can visit www.aboutcookies.org and www.allaboutcookies.org. Which Cookies Are Used? Cookies can be categorized based on their owners, lifespans, and purposes of use: According to the party placing the cookie, Platform cookies and third-party Cookies are used. While Platform cookies are created by MEDEX, third-party cookies are managed by different companies in collaboration with MEDEX.Based on the duration they are active, session cookies and persistent cookies are used. Session cookies are deleted when the visitor leaves the Platform, while persistent cookies can remain on the visitors’ devices for various periods depending on their usage area.According to their purposes of use, technical cookies, authentication cookies, targeting/advertising cookies, personalization cookies, and analytical cookies are used on the Platform.Why Are Cookies Used? On the Platform, Cookies are used for the following purposes: i. Absolutely necessary ii. Efficiency and functionality iii. Marketing
To elaborate in detail:
- To perform the essential functions necessary for the operation of the Platform. For example, ensuring that the products in MEDEX members’ shopping carts do not disappear during their visit. Members who are logged in do not need to re-enter their password while visiting different pages on the Platform.
- To analyze the Platform and improve its performance. For instance, integrating the different servers on which the Platform operates, determining the number of visitors to the Platform and making performance adjustments accordingly, or facilitating visitors to find what they are looking for.
- To enhance the functionality of the Platform and provide ease of use. For example, sharing on third-party social media platforms through the Platform, remembering the username information or search queries of the visitor on their subsequent visits.
- To conduct personalization, targeting, and advertising activities. For example, displaying advertisements related to the interests of visitors based on the pages and products they view.
How Can You Manage Your Cookie Preferences? MEDEX places great importance on users being able to exercise their preferences over their personal data. However, preference management is not possible for some Cookies that are mandatory for the operation of the Site. We would also like to remind you that if some Cookies are disabled, various functions of the Site may not work. The information on how preferences for Cookies used on the Platform can be managed is as follows:
- Visitors have the opportunity to personalize their preferences for cookies by changing the browser settings they use to view the Platform. If the browser being used offers this possibility, it is possible to change preferences related to Cookies through the browser settings. Accordingly, although it may vary depending on the options provided by the browser, data owners have the opportunity to block the use of cookies, prefer to receive a warning before a cookie is used, or disable or delete only certain Cookies. While these preferences vary depending on the browser used, a general explanation can be accessed at https://www.aboutcookies.org. It may be necessary to make cookie-related preferences separately for each device through which the visitor accesses the Platform.
- Click here to disable Cookies managed by Google Analytics. Google Analytics Opt-out
- Click here to manage the personalized advertising experience provided by Google. Google Ad Settings
- Preferences for cookies used by many companies for advertising activities can be managed via “Your Online Choices.”
- The settings menu of the mobile device can be used to manage Cookies on mobile devices.
What Rights Do You Have? Under Article 11 of the Personal Data Protection Law No. 6698, visitors can apply to MEDEX and have the right to:
- Find out if personal data concerning them is being processed,
- Request information if their personal data has been processed,
- Learn the purpose of processing personal data and whether they are used appropriately for their purpose,
- Know the third parties in the country or abroad to whom personal data has been transferred,
- Request correction of personal data if it has been processed incompletely or inaccurately and request that the process carried out in this context be notified to the third parties to whom the personal data has been transferred,
- Request the deletion or destruction of personal data in case the reasons necessitating their processing cease to exist despite being processed in accordance with the provisions of the law and other related laws, and request that the process carried out in this context be notified to the third parties to whom the personal data has been transferred,
- Object to any outcome that emerges against the person themselves through the analysis of the processed data exclusively by automated systems,
- Request compensation for damages in case of loss due to unlawful processing of personal data.
These rights will be evaluated and concluded within 30 (thirty) days when conveyed by personal data owners through the methods specified in the Policy on the Processing and Protection of Personal Data prepared by MEDEX within the scope of Law No. 6698. Although it is the principle not to charge any fee for the requests, MEDEX reserves the right to charge a fee based on the tariff determined by the Personal Data Protection Board.
Changes to Consent and Privacy Policy MEDEX aims to provide its users with a detailed explanation of the scope and purposes of Cookie use with the Privacy Policy (“Policy”) and to inform its users about their Cookie preferences. Therefore, it is accepted that consent to the use of Cookies is given if the Cookie information warning on the Platform is closed and the Site continues to be used. Users always have the opportunity to change their Cookie preferences.
MEDEX may change the provisions of the Policy at any time. The current Policy becomes effective on the date it is published on the Platform