Clear-title property in North Cyprus
About UsContact
deedloom
deedloom
HomeLegalPrivacy Policy

Privacy Policy

At deedloom, we treat the security of your personal data with the utmost importance and process your data in a transparent, secure, and lawful manner in accordance with the Personal Data Protection Law No. 6698 (KVKK) and the EU General Data Protection Regulation (GDPR).

Last updated: March 2026Version: 1.0
Privacy Policy

1. Data Controller

Your personal data are processed by the data controller identified below in accordance with KVKK No. 6698 and GDPR.

Company: Bubi Medya Dijital Hizmetler Tax ID: 32332011454 Tax Office: Kuşadası Vergi Dairesi Address: Değirmendere Mah. Sanayi Cd. 4. Sokak No: 1/2, 09400 Kuşadası / Aydın, Türkiye Phone: +90 545 572 16 09 Email: info@deedloom.com Website: deedloom.com

2. Purpose and Scope of this Policy

This Privacy Policy governs the processing of personal data of all natural persons using the deedloom platform (deedloom.com website, mobile applications, and related digital services). This Policy has been prepared within the framework of the Personal Data Protection Law No. 6698 (KVKK), the Communiqué on the Obligation to Inform, the EU General Data Protection Regulation (GDPR – 2016/679), and the provisions of the relevant secondary legislation.

  • Users residing in Turkey: KVKK provisions apply primarily
  • Users residing in EU/EEA countries: GDPR provisions apply additionally
  • Users residing in other countries: KVKK provisions and the legislation of the relevant country apply
  • Platform visitors, buyer members, real estate agency members, and persons submitting leads are covered by this Policy

3. Personal Data Collected

The following categories of personal data are collected and processed on our platform:

Data CategoryData TypesCollection Source
Identity DataFirst name, last name, national identity number (where required), date of birthRegistration form, identity verification
Contact DataE-mail address, phone number, WhatsApp number, addressRegistration form, contact form, lead form
Transaction Security DataIP address, browser information, operating system, login/logout timestamps, session informationAutomatic collection (log records)
Financial DataInvoice details, payment references, bank IBAN (for real estate agencies)Payment transactions, billing
Marketing DataCookie preferences, e-mail open/click rates, advertising interaction dataCookies, e-mail system (with consent)
Location DataGeneral location information (province/district level), IP-based locationIP address, browser location permission (with consent)
Visual/Audio DataProfile photograph, listing photographs (for real estate agencies)User upload
Customer Transaction DataListing view history, favourites list, search history, lead historyPlatform usage
Professional DataCompany name, tax number, licence information (for real estate agencies)Corporate application form

4. Purposes of Processing Personal Data

Your collected personal data are processed for the following purposes:

  • Management of membership and account transactions, identity verification
  • Provision of real estate listing services, publication and management of listings
  • Lead management: forwarding buyer requests to the relevant real estate agency
  • Provision of search, filtering, and personalisation services within the platform
  • Statistical analysis, user behaviour analysis, and service improvement
  • Ensuring platform security, detection and prevention of fraud
  • Fulfilment of legal obligations (tax, commerce, e-invoice legislation)
  • Marketing activities: campaigns, notifications, and promotions (with explicit consent)
  • Customer satisfaction measurement, complaint and request management
  • Management of boost and featured listing services
  • Management of real estate agency verification and licensing processes
  • Monitoring of legal proceedings and protection of legal rights

5. Legal Bases for Processing Data

Your personal data are processed on the legal grounds set out in KVKK Art. 5 and GDPR Art. 6.
Legal BasisKVKK ReferenceGDPR ReferenceScope of Application
Explicit ConsentArt.5/1Art.6/1(a)Marketing communications, analytics cookies, profiling
Performance of ContractArt.5/2(c)Art.6/1(b)Membership transactions, listing publication, lead forwarding
Legal ObligationArt.5/2(c)Art.6/1(c)Tax records, e-commerce legislation, official authority requests
Legitimate InterestArt.5/2(f)Art.6/1(f)Platform security, fraud prevention, service improvement
Public DomainArt.5/2(d)Art.6/1(e)Publicly available listing data
Vital InterestArt.5/2(a)Art.6/1(d)Personal safety in emergency situations

6. Transfer of Personal Data

Important: Your personal data are not shared with third parties for commercial purposes without your explicit consent. Your lead information is shared only with the real estate agency to which you submitted the request.

Your personal data may be transferred to the following recipient groups within the framework of KVKK Art. 8 and Art. 9 and GDPR Art. 44–49:

  • Real Estate Agencies: Information you submit via the lead form (name, phone, e-mail, message) is forwarded to the relevant verified real estate agency
  • Payment Service Providers: For the execution of payment transactions (Iyzico/Stripe, etc.)
  • Cloud Infrastructure Providers: Data storage and hosting services (with SSL/TLS encryption)
  • Analytics Service Providers: Google Analytics (anonymised/pseudonymised data)
  • E-mail and Notification Services: For transactional notifications and marketing communications
  • Legal Advisors and Financial Consultants: For the conduct of legal proceedings
  • Authorised Public Authorities: Where required by law (court orders, prosecutorial requests)
  • Business Partners: For advertising and marketing purposes (only with explicit consent)

7. International Data Transfers (GDPR)

As a Turkey-based platform, deedloom processes the data of users accessing from EU/EEA countries in Turkey. Turkey is a country for which the European Commission has not yet issued an "adequacy decision". Accordingly, the following safeguards apply to the transfer of personal data of EU/EEA residents to Turkey:

  • Standard Contractual Clauses (SCC): Standard contractual clauses approved by the European Commission are used
  • Additional Technical Measures: Data are protected with TLS 1.3 encryption during and after transfer
  • Data Processing Agreements: GDPR-compliant data processing agreements (DPA) have been executed with all third-party service providers
  • Data Minimisation: Only the minimum data necessary for service delivery are transferred
  • Regular Audits: The security of data transfer processes is audited annually

8. Data Retention Periods

Your personal data are retained for the period required by the processing purpose and within the framework of legal obligations. Data whose retention period has expired are destroyed by erasure, destruction, or anonymisation.

Data TypeRetention PeriodBasis / Deletion Condition
Membership Account InformationFor the duration the account is active + 3 yearsTCC Art. 82, limitation periods
Listing DataFor the duration published + 5 yearsTCC Art. 82, commercial record obligation
Lead Records3 years from the date of transactionLaw of Obligations limitation periods
Invoice and Payment Information10 yearsTPL Art. 253, TCC Art. 82
Log and Access Records2 yearsLaw No. 5651 Art. 5, KVKK
Cookie Data30 days – 13 months depending on cookie typeePrivacy Directive, KVKK
Marketing DataUntil consent is withdrawnExplicit consent condition
Application and Complaint Records2 years from resolutionKVKK Art. 13 and limitation periods
Statistical Data (Anonymised)IndefiniteAnonymised data fall outside the scope of KVKK

9. Data Security Measures

deedloom applies the highest level of technical and administrative measures to protect your personal data against the risks of unauthorised access, loss, alteration, and disclosure.
  • TLS 1.3 Encryption: All data transmissions are protected with SSL/TLS encryption
  • Database Encryption: Sensitive data are encrypted and stored with AES-256
  • Access Control (RBAC): Role-based access control ensures that only authorised personnel can access data
  • Firewall and IDS/IPS: Professional firewalls and intrusion detection systems for network security
  • Regular Backups: Automated backup and disaster recovery plans
  • Penetration Testing: Independent security tests are conducted on a regular basis
  • Staff Training: Regular KVKK/GDPR training is provided to all personnel involved in data processing
  • Data Breach Notification Procedure: In the event of a data breach, notification is made to the KVKK Board within 72 hours and, under GDPR, to the relevant EU supervisory authority within 72 hours. Data subjects are also informed as soon as possible.
  • Confidentiality Agreements: Confidentiality agreements are signed with all employees and suppliers having access to data
  • Log Monitoring: System access logs are continuously monitored and anomalies are detected

10. Your Rights under KVKK (Article 11)

Pursuant to Article 11 of KVKK No. 6698, as a data subject you have the following rights:

  • The right to learn whether your personal data are being processed
  • The right to request information if your personal data have been processed
  • The right to learn the purpose of processing your personal data and whether they are being used in accordance with that purpose
  • The right to know the third parties to whom your personal data have been transferred, whether domestically or abroad
  • The right to request the rectification of your personal data in the event of incomplete or incorrect processing
  • The right to request the erasure or destruction of your personal data within the scope of KVKK Art. 7
  • The right to request that rectification, erasure, and destruction operations be notified to the third parties to whom your personal data have been transferred
  • The right to object to a result that is detrimental to you arising from the analysis of your processed data exclusively through automated systems
  • The right to claim compensation for damages in the event that your personal data are processed unlawfully

11. Your Rights under GDPR

Users residing in EU/EEA countries have the following additional rights under GDPR:

  • Right to be Informed (Art. 13–14): The right to receive clear and comprehensible information about how your data are processed
  • Right of Access (Art. 15): The right to request a copy of your processed personal data
  • Right to Rectification (Art. 16): The right to have incorrect or incomplete data corrected
  • Right to Erasure / Right to be Forgotten (Art. 17): The right to request the deletion of your data under certain conditions
  • Right to Restriction of Processing (Art. 18): The right to request the temporary suspension of processing of your data
  • Right to Data Portability (Art. 20): The right to receive your data in a structured, commonly used, and machine-readable format and to transmit them to another data controller
  • Right to Object (Art. 21): The right to object to processing based on legitimate interest or public interest; you may object to processing for direct marketing purposes at any time
  • Right not to be Subject to Automated Decision-Making (Art. 22): The right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant effects on you
  • Right to Lodge a Complaint with a Supervisory Authority: The right to lodge a complaint with the data protection authority (DPA) of the EU country in which you reside, work, or in which the alleged infringement took place

12. Automated Decision-Making and Profiling

deedloom does not make decisions based solely on automated processing that produce legal effects or significantly affect individuals. All automated processing is subject to human oversight.

The following automated processing and profiling activities take place on the deedloom platform:

  • Listing Ranking and Boost: The promotion of boosted listings in search results is carried out by automated algorithms. This ranking is based on factors such as the fee paid, listing quality, and recency.
  • Analytics and Statistics: User behaviour (page views, search preferences, click-through rates) is processed for statistical analysis. This data is used for general service improvement, not for individual decision-making.
  • Advertising Targeting: Advertisements based on your interests may be displayed through third-party advertising networks (Google Ads, etc.). This processing is subject to your explicit consent.
  • Fraud Prevention: Suspicious account activity is automatically detected and subject to review.
puzzle

13. Browser Extensions (Chrome/Edge)

Listings transferred via the extension are created in "Draft" status in your deedloom dashboard and are not published without your approval. You may stop the transfer at any time and delete transferred data from your dashboard. The full source code of the extension is made available upon request for KVKK/GDPR compliance audit.

deedloom publishes Chrome/Edge browser extensions to enable users to easily migrate their own listings from other real estate platforms to their deedloom dashboard (e.g. "deedloom Listing Importer"). These extensions operate for the purpose of enabling users to transfer their own data in accordance with KVKK Art. 11/g (transfer of data to another data controller) and GDPR Art. 20 (data portability).

  • The extension only reads pages visible within the source platform account to which the user is logged in (e.g. sahibinden.com). It does not access other users' data.
  • Data flow: Source platform pages → user's browser → deedloom API → user's deedloom account. deedloom servers do not send any requests to the source platform and do not access the user's session.
  • Data collected: Only the title, price, location, photograph URL, room/area, and description of the user's own listings. No personal data (identity, contact details, session information) are collected.
  • Local storage: The extension stores the user's deedloom access token exclusively in the browser's local storage (localStorage). The token is refreshed every 24 hours and is not shared with third parties.
  • Cookies, session data, or user account information on source platforms are not read, copied, or stored by the extension.
  • Transfer speed is randomised in a manner similar to human behaviour (1.5–3 second delay); no excessive load is placed on the source platform.

14. Children's Privacy

The deedloom platform is not directed at individuals under the age of 18. We do not knowingly collect personal data from persons under the age of 18. Under KVKK: The explicit consent of a legal representative (parent/guardian) is required for the processing of personal data of persons under the age of 18. Under GDPR: Parental consent is required for the processing of personal data of children under the age of 16 (in some EU member states the applicable age ranges between 13 and 16). If you become aware or learn that the data of an individual under the age of 18 have been collected, please notify us immediately at info@deedloom.com. The relevant data will be deleted as soon as possible.

15. Changes to this Policy

This Privacy Policy may be updated from time to time due to legislative changes, platform updates, or changes in business processes. When changes are made: - The updated policy is published at deedloom.com/privacy - The "Last updated" date is revised - Registered users are notified by e-mail in the case of significant changes - Where processing based on explicit consent is affected by a change, fresh consent is obtained Your continued use of the platform constitutes your acceptance of the updated policy. You retain the right to close your account if you do not accept the changes to the policy.

16. Application and Contact

You may exercise your rights under KVKK and GDPR through the following channels: Methods of Application: - E-mail: Written application with identity-verifying documents to info@deedloom.com - Post: — notarised or signed petition - KEP: — Processing of Applications: - Your application will be concluded free of charge within 30 days (KVKK Art. 13) - Requests under GDPR are answered within 1 month; for complex requests an additional 2-month period may be taken (GDPR Art. 12) - If the processing requires an additional cost, the fee schedule determined by the KVKK Board applies Right to Lodge a Complaint: - KVKK Board: If the data controller's response is not found satisfactory or no response is given within 30 days, you may lodge a complaint with the Personal Data Protection Board (KVKK Art. 14) - EU Data Protection Authorities (DPA): Users residing in EU/EEA may lodge a complaint with the data protection authority of their country of residence