Privacy Policy
At deedloom, we treat the security of your personal data with the utmost importance and process your data in a transparent, secure, and lawful manner in accordance with the Personal Data Protection Law No. 6698 (KVKK) and the EU General Data Protection Regulation (GDPR).
Table of Contents
- 1. Data Controller
- 2. Purpose and Scope of this Policy
- 3. Personal Data Collected
- 4. Purposes of Processing Personal Data
- 5. Legal Bases for Processing Data
- 6. Transfer of Personal Data
- 7. International Data Transfers (GDPR)
- 8. Data Retention Periods
- 9. Data Security Measures
- 10. Your Rights under KVKK (Article 11)
- 11. Your Rights under GDPR
- 12. Automated Decision-Making and Profiling
- 13. Browser Extensions (Chrome/Edge)
- 14. Children's Privacy
- 15. Changes to this Policy
- 16. Application and Contact
1. Data Controller
Company: Bubi Medya Dijital Hizmetler Tax ID: 32332011454 Tax Office: Kuşadası Vergi Dairesi Address: Değirmendere Mah. Sanayi Cd. 4. Sokak No: 1/2, 09400 Kuşadası / Aydın, Türkiye Phone: +90 545 572 16 09 Email: info@deedloom.com Website: deedloom.com
2. Purpose and Scope of this Policy
This Privacy Policy governs the processing of personal data of all natural persons using the deedloom platform (deedloom.com website, mobile applications, and related digital services). This Policy has been prepared within the framework of the Personal Data Protection Law No. 6698 (KVKK), the Communiqué on the Obligation to Inform, the EU General Data Protection Regulation (GDPR – 2016/679), and the provisions of the relevant secondary legislation.
- ›Users residing in Turkey: KVKK provisions apply primarily
- ›Users residing in EU/EEA countries: GDPR provisions apply additionally
- ›Users residing in other countries: KVKK provisions and the legislation of the relevant country apply
- ›Platform visitors, buyer members, real estate agency members, and persons submitting leads are covered by this Policy
3. Personal Data Collected
The following categories of personal data are collected and processed on our platform:
| Data Category | Data Types | Collection Source |
|---|---|---|
| Identity Data | First name, last name, national identity number (where required), date of birth | Registration form, identity verification |
| Contact Data | E-mail address, phone number, WhatsApp number, address | Registration form, contact form, lead form |
| Transaction Security Data | IP address, browser information, operating system, login/logout timestamps, session information | Automatic collection (log records) |
| Financial Data | Invoice details, payment references, bank IBAN (for real estate agencies) | Payment transactions, billing |
| Marketing Data | Cookie preferences, e-mail open/click rates, advertising interaction data | Cookies, e-mail system (with consent) |
| Location Data | General location information (province/district level), IP-based location | IP address, browser location permission (with consent) |
| Visual/Audio Data | Profile photograph, listing photographs (for real estate agencies) | User upload |
| Customer Transaction Data | Listing view history, favourites list, search history, lead history | Platform usage |
| Professional Data | Company name, tax number, licence information (for real estate agencies) | Corporate application form |
4. Purposes of Processing Personal Data
Your collected personal data are processed for the following purposes:
- ›Management of membership and account transactions, identity verification
- ›Provision of real estate listing services, publication and management of listings
- ›Lead management: forwarding buyer requests to the relevant real estate agency
- ›Provision of search, filtering, and personalisation services within the platform
- ›Statistical analysis, user behaviour analysis, and service improvement
- ›Ensuring platform security, detection and prevention of fraud
- ›Fulfilment of legal obligations (tax, commerce, e-invoice legislation)
- ›Marketing activities: campaigns, notifications, and promotions (with explicit consent)
- ›Customer satisfaction measurement, complaint and request management
- ›Management of boost and featured listing services
- ›Management of real estate agency verification and licensing processes
- ›Monitoring of legal proceedings and protection of legal rights
5. Legal Bases for Processing Data
| Legal Basis | KVKK Reference | GDPR Reference | Scope of Application |
|---|---|---|---|
| Explicit Consent | Art.5/1 | Art.6/1(a) | Marketing communications, analytics cookies, profiling |
| Performance of Contract | Art.5/2(c) | Art.6/1(b) | Membership transactions, listing publication, lead forwarding |
| Legal Obligation | Art.5/2(c) | Art.6/1(c) | Tax records, e-commerce legislation, official authority requests |
| Legitimate Interest | Art.5/2(f) | Art.6/1(f) | Platform security, fraud prevention, service improvement |
| Public Domain | Art.5/2(d) | Art.6/1(e) | Publicly available listing data |
| Vital Interest | Art.5/2(a) | Art.6/1(d) | Personal safety in emergency situations |
6. Transfer of Personal Data
Your personal data may be transferred to the following recipient groups within the framework of KVKK Art. 8 and Art. 9 and GDPR Art. 44–49:
- ›Real Estate Agencies: Information you submit via the lead form (name, phone, e-mail, message) is forwarded to the relevant verified real estate agency
- ›Payment Service Providers: For the execution of payment transactions (Iyzico/Stripe, etc.)
- ›Cloud Infrastructure Providers: Data storage and hosting services (with SSL/TLS encryption)
- ›Analytics Service Providers: Google Analytics (anonymised/pseudonymised data)
- ›E-mail and Notification Services: For transactional notifications and marketing communications
- ›Legal Advisors and Financial Consultants: For the conduct of legal proceedings
- ›Authorised Public Authorities: Where required by law (court orders, prosecutorial requests)
- ›Business Partners: For advertising and marketing purposes (only with explicit consent)
7. International Data Transfers (GDPR)
As a Turkey-based platform, deedloom processes the data of users accessing from EU/EEA countries in Turkey. Turkey is a country for which the European Commission has not yet issued an "adequacy decision". Accordingly, the following safeguards apply to the transfer of personal data of EU/EEA residents to Turkey:
- ›Standard Contractual Clauses (SCC): Standard contractual clauses approved by the European Commission are used
- ›Additional Technical Measures: Data are protected with TLS 1.3 encryption during and after transfer
- ›Data Processing Agreements: GDPR-compliant data processing agreements (DPA) have been executed with all third-party service providers
- ›Data Minimisation: Only the minimum data necessary for service delivery are transferred
- ›Regular Audits: The security of data transfer processes is audited annually
8. Data Retention Periods
Your personal data are retained for the period required by the processing purpose and within the framework of legal obligations. Data whose retention period has expired are destroyed by erasure, destruction, or anonymisation.
| Data Type | Retention Period | Basis / Deletion Condition |
|---|---|---|
| Membership Account Information | For the duration the account is active + 3 years | TCC Art. 82, limitation periods |
| Listing Data | For the duration published + 5 years | TCC Art. 82, commercial record obligation |
| Lead Records | 3 years from the date of transaction | Law of Obligations limitation periods |
| Invoice and Payment Information | 10 years | TPL Art. 253, TCC Art. 82 |
| Log and Access Records | 2 years | Law No. 5651 Art. 5, KVKK |
| Cookie Data | 30 days – 13 months depending on cookie type | ePrivacy Directive, KVKK |
| Marketing Data | Until consent is withdrawn | Explicit consent condition |
| Application and Complaint Records | 2 years from resolution | KVKK Art. 13 and limitation periods |
| Statistical Data (Anonymised) | Indefinite | Anonymised data fall outside the scope of KVKK |
9. Data Security Measures
- ›TLS 1.3 Encryption: All data transmissions are protected with SSL/TLS encryption
- ›Database Encryption: Sensitive data are encrypted and stored with AES-256
- ›Access Control (RBAC): Role-based access control ensures that only authorised personnel can access data
- ›Firewall and IDS/IPS: Professional firewalls and intrusion detection systems for network security
- ›Regular Backups: Automated backup and disaster recovery plans
- ›Penetration Testing: Independent security tests are conducted on a regular basis
- ›Staff Training: Regular KVKK/GDPR training is provided to all personnel involved in data processing
- ›Data Breach Notification Procedure: In the event of a data breach, notification is made to the KVKK Board within 72 hours and, under GDPR, to the relevant EU supervisory authority within 72 hours. Data subjects are also informed as soon as possible.
- ›Confidentiality Agreements: Confidentiality agreements are signed with all employees and suppliers having access to data
- ›Log Monitoring: System access logs are continuously monitored and anomalies are detected
10. Your Rights under KVKK (Article 11)
Pursuant to Article 11 of KVKK No. 6698, as a data subject you have the following rights:
- ›The right to learn whether your personal data are being processed
- ›The right to request information if your personal data have been processed
- ›The right to learn the purpose of processing your personal data and whether they are being used in accordance with that purpose
- ›The right to know the third parties to whom your personal data have been transferred, whether domestically or abroad
- ›The right to request the rectification of your personal data in the event of incomplete or incorrect processing
- ›The right to request the erasure or destruction of your personal data within the scope of KVKK Art. 7
- ›The right to request that rectification, erasure, and destruction operations be notified to the third parties to whom your personal data have been transferred
- ›The right to object to a result that is detrimental to you arising from the analysis of your processed data exclusively through automated systems
- ›The right to claim compensation for damages in the event that your personal data are processed unlawfully
11. Your Rights under GDPR
Users residing in EU/EEA countries have the following additional rights under GDPR:
- ›Right to be Informed (Art. 13–14): The right to receive clear and comprehensible information about how your data are processed
- ›Right of Access (Art. 15): The right to request a copy of your processed personal data
- ›Right to Rectification (Art. 16): The right to have incorrect or incomplete data corrected
- ›Right to Erasure / Right to be Forgotten (Art. 17): The right to request the deletion of your data under certain conditions
- ›Right to Restriction of Processing (Art. 18): The right to request the temporary suspension of processing of your data
- ›Right to Data Portability (Art. 20): The right to receive your data in a structured, commonly used, and machine-readable format and to transmit them to another data controller
- ›Right to Object (Art. 21): The right to object to processing based on legitimate interest or public interest; you may object to processing for direct marketing purposes at any time
- ›Right not to be Subject to Automated Decision-Making (Art. 22): The right not to be subject to decisions based solely on automated processing that produce legal effects or similarly significant effects on you
- ›Right to Lodge a Complaint with a Supervisory Authority: The right to lodge a complaint with the data protection authority (DPA) of the EU country in which you reside, work, or in which the alleged infringement took place
12. Automated Decision-Making and Profiling
The following automated processing and profiling activities take place on the deedloom platform:
- ›Listing Ranking and Boost: The promotion of boosted listings in search results is carried out by automated algorithms. This ranking is based on factors such as the fee paid, listing quality, and recency.
- ›Analytics and Statistics: User behaviour (page views, search preferences, click-through rates) is processed for statistical analysis. This data is used for general service improvement, not for individual decision-making.
- ›Advertising Targeting: Advertisements based on your interests may be displayed through third-party advertising networks (Google Ads, etc.). This processing is subject to your explicit consent.
- ›Fraud Prevention: Suspicious account activity is automatically detected and subject to review.
13. Browser Extensions (Chrome/Edge)
deedloom publishes Chrome/Edge browser extensions to enable users to easily migrate their own listings from other real estate platforms to their deedloom dashboard (e.g. "deedloom Listing Importer"). These extensions operate for the purpose of enabling users to transfer their own data in accordance with KVKK Art. 11/g (transfer of data to another data controller) and GDPR Art. 20 (data portability).
- ›The extension only reads pages visible within the source platform account to which the user is logged in (e.g. sahibinden.com). It does not access other users' data.
- ›Data flow: Source platform pages → user's browser → deedloom API → user's deedloom account. deedloom servers do not send any requests to the source platform and do not access the user's session.
- ›Data collected: Only the title, price, location, photograph URL, room/area, and description of the user's own listings. No personal data (identity, contact details, session information) are collected.
- ›Local storage: The extension stores the user's deedloom access token exclusively in the browser's local storage (localStorage). The token is refreshed every 24 hours and is not shared with third parties.
- ›Cookies, session data, or user account information on source platforms are not read, copied, or stored by the extension.
- ›Transfer speed is randomised in a manner similar to human behaviour (1.5–3 second delay); no excessive load is placed on the source platform.
14. Children's Privacy
The deedloom platform is not directed at individuals under the age of 18. We do not knowingly collect personal data from persons under the age of 18. Under KVKK: The explicit consent of a legal representative (parent/guardian) is required for the processing of personal data of persons under the age of 18. Under GDPR: Parental consent is required for the processing of personal data of children under the age of 16 (in some EU member states the applicable age ranges between 13 and 16). If you become aware or learn that the data of an individual under the age of 18 have been collected, please notify us immediately at info@deedloom.com. The relevant data will be deleted as soon as possible.
15. Changes to this Policy
This Privacy Policy may be updated from time to time due to legislative changes, platform updates, or changes in business processes. When changes are made: - The updated policy is published at deedloom.com/privacy - The "Last updated" date is revised - Registered users are notified by e-mail in the case of significant changes - Where processing based on explicit consent is affected by a change, fresh consent is obtained Your continued use of the platform constitutes your acceptance of the updated policy. You retain the right to close your account if you do not accept the changes to the policy.
16. Application and Contact
You may exercise your rights under KVKK and GDPR through the following channels: Methods of Application: - E-mail: Written application with identity-verifying documents to info@deedloom.com - Post: — notarised or signed petition - KEP: — Processing of Applications: - Your application will be concluded free of charge within 30 days (KVKK Art. 13) - Requests under GDPR are answered within 1 month; for complex requests an additional 2-month period may be taken (GDPR Art. 12) - If the processing requires an additional cost, the fee schedule determined by the KVKK Board applies Right to Lodge a Complaint: - KVKK Board: If the data controller's response is not found satisfactory or no response is given within 30 days, you may lodge a complaint with the Personal Data Protection Board (KVKK Art. 14) - EU Data Protection Authorities (DPA): Users residing in EU/EEA may lodge a complaint with the data protection authority of their country of residence