Zum Inhalt springen
HammaddePazari

Privacy Policy

Last updated: 2026-10-11

At HammaddePazari Teknoloji A.Ş. ("HammaddePazari") we take the protection of your personal data seriously. This policy explains what data we collect, why, how we protect it and what your rights are. For users in Türkiye, further details are given in the Personal Data Notice (KVKK); for users in the EU/EEA, this policy also serves as our GDPR information notice.

1. Data we collect

Category Examples
Identity and contact Full name, business e-mail, phone, job title
Company details Legal name, tax number, address, bank account (IBAN)
Verification documents Tax certificate, trade registry, signature circular
Transaction data Listings, requests, offers, messages, contracts, invoices
Security data IP address, browser details, sign-in logs, 2FA status
Payment data Amount, status, provider reference (card details are not stored)

2. Why we process data (legal bases)

  • To create your account and provide Platform services (performance of contract)
  • Company verification, fraud prevention and security (legitimate interest, legal obligation)
  • Invoicing, tax and bookkeeping obligations (legal obligation)
  • Evidence in disputes (establishment and defence of legal claims)
  • Market insights and matching request alerts (only with your consent)

3. Sharing

We never sell your data. We share it only:

  • With other Members: your company profile and listings are public. Your contact details are masked in the deal room until a contract is signed.
  • With service providers: hosting, e-mail delivery, payment institutions (iyzico, PayTR, Stripe, PayPal), bot protection (Cloudflare Turnstile).
  • With authorities: where required by law.

Some providers may be located outside your country. Such transfers are made with the safeguards required by applicable law (e.g. standard contractual clauses).

4. Security

  • Sensitive documents and bank details are stored encrypted and can only be downloaded through authorized, time-limited links.
  • All traffic is encrypted with HTTPS; passwords are hashed with Argon2id.
  • Two-factor authentication, new-device alerts and rate limiting are in place.
  • Critical actions are recorded in a tamper-evident audit log.

5. Retention

Account data is kept while your membership is active. Contracts, invoices and transaction records are kept for 10 years as required by commercial and tax law. Security logs are kept for up to 2 years. Afterwards data is deleted or anonymised.

6. Your rights

You have the right to access, rectify, erase, restrict and object to the processing of your data, and to receive it in a portable format. You can export your data or delete your account from your account settings. For any other request, contact destek@hammadde.antwebsoft.com. You may also lodge a complaint with your data protection authority.

7. Cookies

See our Cookie Policy for the cookies we use.

8. Contact

HammaddePazari Teknoloji A.Ş. — İstanbul, Türkiye
E-mail: destek@hammadde.antwebsoft.com