Privacy policy and protection of personal data
This notice explains how personal data is processed in connection with the Fuaye Çarşı website and digital channels, in line with Law No. 6698 on the Protection of Personal Data (“KVKK”) and related legislation.
Last updated: 19 April 2026
1. Data controller
As the data controller under Article 10 of the KVKK, your personal data is processed by Fuaye Çarşı for the purposes and legal bases set out below. For contact and requests: info@fuayecarsi.com.tr · +90 (216) 290 38 91 · Zümrütevler, Ertuğrul Gazi Cd. No:10, 34852 Maltepe / Istanbul, Türkiye.
2. Scope
This notice applies to the website at fuayecarsi.com.tr, contact forms on the site, cookies and similar online tracking technologies. Independent stores and brands within the centre are responsible for their own data processing activities.
3. Categories of personal data
Depending on the service, data in the following categories may be processed:
- Identity / contact: first and last name (if provided), email address, phone number.
- Customer transaction: contact form or request content, message text, preference statements.
- Transaction security: IP address, browser and device type, operating system, session and security logs, date/time stamp.
- Marketing (if explicit consent exists): campaign and newsletter preferences.
4. Purposes of processing
Your data is processed mainly to: operate the website securely and continuously; receive, assess and respond to contact requests; comply with legal obligations; measure and improve service quality; respond to requests from competent public authorities; establish evidence in disputes; and run information security processes based on legitimate interests.
5. Legal bases
Processing may rely on explicit consent, performance or conclusion of a contract, legal obligations of the controller, establishment or protection of a right, legitimate interests of the controller (e.g. cybersecurity, fraud prevention), or cases expressly provided by law under Articles 5(2) and 6 of the KVKK. Special categories of personal data are not processed; if ever needed, explicit consent and statutory conditions apply.
6. Transfers
Your data may be transferred, limited to the above purposes, to hosting and infrastructure providers, email delivery services, legal and audit service providers, and competent public authorities. Where transfer abroad occurs, Article 9 of the KVKK and appropriate safeguards apply.
7. Collection method and legal basis
Data may be collected via website forms and by automated or partly automated means (cookies, log files). The applicable legal basis for each processing activity is determined according to the concrete situation at the time of processing and recorded.
8. Retention
Personal data is stored for the period required by applicable law or for the purpose for which it was processed; thereafter it is deleted, destroyed or anonymised. Contact records are typically kept for a reasonable period after the request is closed; log data is retained for a limited period in line with information security policies.
9. Rights of the data subject under Article 11 of the KVKK
Under Article 11, you have the right to learn whether your data is processed; request information if it has been processed; learn the purpose and whether use is consistent with that purpose; know third parties to whom data is transferred domestically or abroad; request rectification if incomplete or inaccurate; request erasure or destruction under Article 7 where conditions are met; request notification of rectification/erasure to third parties to whom data was transferred; object to adverse results from solely automated processing; and claim compensation if you suffer damage due to unlawful processing.
10. How to submit a request
You may exercise your rights in writing using the contact channels above. Requests are concluded free of charge within thirty days at the latest, depending on nature; if the process requires a separate cost, a fee may be charged according to the tariff set by the Personal Data Protection Board.
11. Security
Technical and organisational measures (access control, encryption and secure transmission where appropriate, up-to-date software and security monitoring) are applied to prevent unauthorised access, loss or disclosure of personal data.
12. Cookies and similar technologies
Cookies may be used for site experience, preference management and analytics. See our Cookie policy for details. You can update cookie preferences at any time via “Cookie settings” in the site footer.
13. Changes to this notice
This notice may be updated due to operational or legal changes. Material changes will be announced on the site where possible. The current version is always published on this page.