Privacy and
Data Security Policy
1. PRINCIPLES OF CONFIDENTIALITY
NETSAN AMBALAJ
MOBİLYA SAN. VE TİC. LTD. ŞTİ (“Company”) processes, stores, and
protects the corporate and/or personal data of its business partners (customer
companies, suppliers, solution partners, etc.) via its website www.arnettib2b.com,
in full compliance with the Turkish Personal Data Protection Law No. 6698
(KVKK), the EU General Data Protection Regulation (GDPR), and other
applicable data protection legislation.
The Company shall never
share the personal or commercial data of its business partners with any
third parties, institutions, or individuals for commercial, statistical, or
any other purpose, unless express consent is given.
2. DEFINITION OF DATA
In the context of
B2B operations, the following types of data may be processed:
- Corporate name, tax number, trade registry
details
- Name and surname of authorized
personnel, job titles
- Business address, email address,
landline and mobile numbers
- Order, invoice, and payment details
- IP addresses, session data, and
transaction logs
This data is
processed solely to establish and maintain contractual relationships and to
ensure the secure continuation of commercial operations.
3. COMMITMENT TO DATA CONFIDENTIALITY
The Company
unconditionally commits to the following for the protection of business partner
data:
- Keeping all commercial and personal
data strictly confidential
- Treating such data under the obligation
of professional secrecy
- Taking all administrative,
technical, and physical security measures to prevent unauthorized
access, alteration, sharing, or deletion
- Acting in accordance with national and
international information security standards
Despite all
necessary measures, in the event of cyberattacks or external interventions
leading to data breaches or unauthorized access, the Company cannot be held
liable for any damages or disclosures beyond its control.
4. PAYMENT SECURITY AND SSL
All online
transactions on the site are protected using 128-bit SSL (Secure Socket
Layer) encryption technology. This protocol ensures that credit card
information entered during payment is encrypted in a way that only the
bank’s systems can decrypt.
- Card data is never stored on our
systems.
- All transactions occur through a
secure, encrypted channel between the user and the bank.
- The virtual POS infrastructure offers
the same security level as physical POS devices.
The Company's system
is supported by Globalsign-issued SSL certificates, internationally
valid and compliant with EU e-commerce directives.
5. DATA SUBJECT RIGHTS
Data subjects
(company representatives and authorized personnel) have the following rights
under KVKK and GDPR:
- To learn which of their data is being
processed
- To request correction, deletion, or
suspension of data processing
- To object to data processing
- To file complaints or legal claims
regarding their data
All such requests
may be submitted via email to [email protected]. Requests will be
addressed within a maximum of 30 days.
The Company remains fully committed to ensuring the
confidentiality and security of its business partners’ data at the highest
standard.