25% OFF
Free Shipping Over $35
Valid From Orders EU, US and CA

FREE NEXT DAY DELIVERY*

* On Business Days - On Orders Over $35

Privacy Policy and GPDR

Confidentiality Agreement and Protection of Personal Data Protection GPDR

Personal data protection is a priority for SOLIVA TANITIM HİZMETLERİ TIC. LTD. ŞTI. ("Luviloom"). Luviloom, as data controller, adheres to the KVK Law's principles in order to comply with the Personal Data Protection Law No. 6698 ("KVK Law"), and fulfils its obligations with respect to the processing, deletion, destruction, anonymization, transfer, disclosure, and data security of the person concerned. The real people whose personal data has been processed are given access to the Privacy and Personal Data Protection Policy regulated within this scope ("Relevant Person").

1. The Scope and Purpose of the Policy on Privacy and Personal Data Protection

 

This Policy on Privacy and Personal Data Protection describes

a. Data collection methods and legal justifications,

b. Which categories of individuals' personal data are processed (Data Subject Person Group Categorization),

c. Which categories of personal data are processed in relation to these individuals (Data Categories) and sample data types

d. The business processes in which this personal data is used and the purposes for which it is used.

e. Technical and administrative safeguards for the protection of personal data

f. The recipients and purposes for which personal data may be transferred,

g. Retention periods for personal data,

h. Segmentation and Profiling

i. What are the Relevant Persons' rights regarding their personal data and how can they exercise them?

j. How Relevant Individuals can alter their preferences for receiving electronic commercial messages,

k. Sharing personal information with government authorities

l. Cookie Management and Utilization.

a. Techniques for Collecting Personal Data and Legal Justifications

Based on the legal reasons defined in Article 5 of Personal Data Protection Law No. 6698.

 

 

• expressly stated in the law

• processing the personal data of contract parties is necessary if it is directly related to the establishment or performance of the contract.

• The fact that the individual in question has made himself public

• Data processing is required to protect the data controller's legitimate interests, provided that it does not jeopardise the data subject's fundamental rights and freedoms.

• Processing of personal data is required for the establishment, exercise, or protection of a legal right, based on these legal reasons,

Luviloom collects personal data in audio, electronic, and written forms via websites, website mobile applications, social media accounts, cookies, call centre, administrative and judicial authority notifications, and other communication channels.

b. Classification of Data Subject Group

Luviloom classifies data subject groups into the following categories based on how their personal data is processed during personal data processing processes and activities associated with these processes. However, personal data of other individual groups (consultant, educator, blogger) may be processed in accordance with the conditions for processing personal data specified in Articles 5 and 6 of the KVK Law and for the legal reasons specified in this Privacy/Personal Data Protection Policy.

c. Data Categories and Example Data Types

1. a) Customer who is a member

• Personal identifiers: first and last names, date of birth, gender, and TR identification number

• Location Information: City and county of residence (delivery address for shopping made through luviloom.com)

• Contact Information: cell phone number, e-mail address, physical address, zip code, and landline phone

• Financial Information: contact information for the tax office and invoice information

• Customer/Member Information: Information about the customer or member, including the member's ID number.

• Customer/Member Transaction Information: Purchased product/s, shopping amount, shopping date, call centre call records, permission for commercial communication, used campaigns/competitions, coupons used, order information

• Information pertaining to risk management: IP address

• Security Information for Transactions: Password, password information

• Marketing Data: Cookie records, targeting data, and reviews revealing habits and preferences

• Audio Data: Recordings of call centre conversations

• Legal Action and Compliance Information: The start and end dates of the service, the type of service used, the amount of data transferred, the Relevant Person's permission to send commercial electronic messages in an electronic environment, the approved membership agreement, the corporate membership agreement, and any other legal texts that permit the use of Luviloom's services.

• Direct Marketing Information: SMS, e-mail messages, or calls made by the call centre for marketing purposes that are sent in accordance with the relevant person's permission to receive commercial electronic messages.

• Request/Complaint Management/Reputation Management Information: Records of complaints and/or requests submitted by the individual via the website, mobile application, social media accounts, or call centre regarding the product or service purchased, as well as the transactions conducted during the evaluation or management of these requests.

b) Visiting Customer (users who shop on the site without being a member)

• Identification Information: first and last names, date of birth, and TR ID number

• Location Information: City and county of residence (delivery address for shopping made through luviloom.com)

• Contact Information: cell phone number, e-mail address, physical address, zip code, and landline phone

• Financial Information: contact information for the tax office and invoice information

• Guest Customer Transaction Information: Purchased product(s), amount spent, date spent, call centre call records, permission for commercial communication, campaigns used, and order information.

• Information pertaining to risk management: IP address

• Security Information for Transactions: Password, password information

• Marketing Data: Cookie records, targeting data, and reviews revealing habits and preferences

• Audio Data: Recordings of call centre conversations

• Legal Action and Compliance Information: The start and end dates of the service, the type of service used, the amount of data transferred, the Relevant Person's permission to send commercial electronic messages in an electronic environment, and other legal texts and contracts that enable the Relevant Person to benefit from Luviloom's services.

• Direct Marketing Information: SMS, e-mail messages, or calls made by the call centre for marketing purposes that are sent in accordance with the relevant person's permission to receive commercial electronic messages.

• Request/Complaint Management/Reputation Management Information: Records of complaints and/or requests submitted by the individual via the website, mobile application, social media accounts, or call centre regarding the product or service purchased, as well as the transactions conducted during the evaluation or management of these requests.

2. Online Visitor

• Security Information for Transactions: Password, mobile phone, and password information

• Legal Transaction Data/Risk Management Data: Internet protocol address

• Legal and Compliance Information: The start and end dates of the service, the type of service utilised, and the amount of data transferred.

3. The individual to whom the Purchased Product will be delivered

• Personal identifiers: first and last names, date of birth, gender, and TR identification number

• Location Information: City and county of residence (delivery address for shopping made through luviloom.com)

• Contact Information: cell phone number, e-mail address, physical address, zip code, and landline phone

• Financial Information: contact information for the tax office and invoice information

d. How Personal Data Are Used in Business Processes and for What Purposes

1. a) Personal Information about Members and Customers

• Transactions relating to membership,

• the "luviloom.com" e-commerce platforms ("platform") operated by Luviloom; enhancing the services available on the website, developing new services, and informing users about them.

• To carry out the terms of the Membership Agreement with the Member Customer, to approve commercial electronic messages, to analyse the Member Customer's preferences, tastes, and needs in comparison to other Member Customers, and to provide special promotion, opportunity, and benefit to the Member Customer,

• Remarketing, targeting, profiling, and analysis with the express consent of the Member Customer, as well as promoting and marketing applications, goods/products, and services based on the Customer's preferences and tastes.

• Resolving Member Customer complaints and issues

• Enhancing the Member Customer experience across the board, including the platform and mobile application.

• Accounting and purchasing transactions are monitored.

• Legal procedures and adherence to applicable legislation

• Responding to requests for information from administrative and judicial authorities,

• Ensuring the security of data and transactions and preventing malicious use

• Taking the necessary steps to ensure that the processed data is current and accurate.

b) Guest Customer's Personal Information (users who shop on the site without being a member)

• To be able to shop as a "guest" on the platforms.

• Improving the services available on platforms, developing new ones, and informing users about them

• Approval of commercial electronic messages, which includes analysing the preferences, tastes, and needs of existing Guest Customers and providing them with special promotions, opportunities, and benefits.

• Remarketing, targeting, profiling, and analysis with the Guest Customer's express consent, as well as promotion and marketing of applications, goods/products, and services based on the Guest Customer's preferences and tastes.

• Resolving customer service issues and complaints,

• Improving the Guest Customer experience across the board, including the platform and mobile application

• Accounting and purchasing transactions are monitored.

• Legal procedures and adherence to applicable legislation

• Responding to requests for information from administrative and judicial authorities,

• Ensuring the security of data and transactions and preventing malicious use

• Taking the necessary steps to ensure that the processed data is current and accurate;

• Compliance with legal requirements

2. Online Visitor's Personal Information

• Processing of online visitor data in accordance with the provisions of Law No. 5651

• Legal procedures and adherence to applicable legislation

• Responding to requests for information from administrative and judicial authorities,

• Ensuring the security of data and transactions and preventing malicious use

• Compliance with legal requirements

3. Personal Information about the Individual to whom the Purchased Product will be Delivered

• Processes for product delivery

• Accounting and purchasing transactions are monitored.

• Legal procedures and adherence to applicable legislation

• Responding to requests for information from administrative and judicial authorities,

• Ensuring the security of data and transactions and preventing malicious use

• Taking the necessary steps to ensure that the processed data is current and accurate;

• Compliance with legal requirements

e. Technical and Administrative Security Measures Taken to Protect Personal Data

Luviloom commits to implementing all necessary technical and administrative safeguards and exercising due diligence in order to maintain the confidentiality, integrity, and security of your personal data.

Luviloom takes appropriate security measures to protect personal data from unauthorised access, misuse, unlawful processing, disclosure, alteration, or destruction. When processing personal data, Luviloom adheres to generally accepted security technology standards such as firewalls and Secure Sockets Layer (SSL) encryption. Additionally, when you send personal information to Luviloom via the website, mobile application, or mobile site, this information is encrypted using SSL.

Regarding the prevention of unauthorised access to Luviloom's personal data, the prevention of unauthorised processing of this data, and the protection of personal data:

 

• Uses SSL to secure all areas of the website or mobile application that collect personal data.

• Establishes and maintains access authorization and control matrices for its employees to ensure that personal data collected via the website or mobile application is not processed in an unauthorised manner.

• To ensure that personal data is not accessed in an unauthorised manner; conducts periodic penetration tests and evaluates the system's resistance to unauthorised access.

• It uses the pseudonymization (aliased data) method for all secondary data processing other than the primary data processing purpose. To ensure that pseudonymous data cannot be used to identify the individual, it encrypts the systems on which it is stored and applies a more stringent access authorization and control policy to this data.

• It ensures that personal data stored on paper media is securely stored in locked cabinets and is accessible only to authorised individuals.

• When a membership is terminated, personal data processed through third-party cookies used to provide the service is deleted from the third-systems. party's

Despite Luviloom's precautionary measures regarding information security, if personal data is compromised or falls into the hands of unauthorised third parties as a result of attacks on Luviloom's platforms or the Luviloom system, Luviloom immediately notifies you and the Personal Data Protection Board and takes the necessary measures.

f. To Whom and For What Purposes can Personal Data be Transferred

Luviloom discloses personal information to third parties only for the purposes specified in this Privacy and Personal Data Protection Policy and in accordance with KVK Law Articles 8 and 9. Member Customer/Guest Customer data processed in this context, as well as the person to whom the purchased product will be delivered, are shared with the seller and the shipping company, and can also be accessed by the call centre as needed.

The cargo company shares the information of the person on whose behalf an invoice will be issued in order to send the invoice to the appropriate person.

The mobile phone number and/or e-mail address of the Member Customer/Guest Customer are shared with the commercial electronic message service provider in order to make promotions, advertisements, and offer benefits and opportunities in line with their shopping preferences, tastes and habits, based on the commercial electronic message approval.

Our domestic/international business partners from whom we obtain cookie services share our website or mobile application users' preferences and browsing history in order to segment and communicate with Member Customer/Guest Customer based on their tastes and preferences. Transfers of personal data within this scope are made in a secure environment and via channels provided by the relevant third party. Depending on the nature and scope of the service received from third parties; In all cases where it is unnecessary to transfer the Member Customer's/Guest Customer's personal data, the transfer is made using pseudonymous data (pseudonymous data).

Member Customer/Guest Customer data is shared with companies conducting market research to improve customer satisfaction and loyalty.

The Member Customer/Guest Customer's data is shared with Luviloom's partners Doğuş Holding A. and SK Planet Ltd for the purpose of reporting and statistical analysis.

Additionally, your personal data will be shared with our business partners located outside the United States for the purposes of business development, statistical and technical analysis, and customer relations.

If a Member Customer/Guest Customer/Online Visitor contacts Luviloom via the corporate Whatsapp line, their personal data will be sent abroad, as the Whatsapp platform is a service offered from a foreign location. If a Member Customer/Guest Customer/Online Visitor does not wish to send their personal data abroad via Whatsapp, they may use one of Luviloom's other communication options.

Along with the technical safeguards mentioned previously, the personal data subject to domestic and international transfers is also legally protected by the provisions of the KVK Law incorporated into our contracts, depending on whether the other party to the legal relationship is a data controller or a data processor.

When personal information is transferred to countries other than Turkey as part of the information sharing described above, it is ensured that the data is transferred in accordance with this policy and the applicable data protection laws.

g. Retention Periods for Personal Data

Luviloom retains personal data it processes in accordance with the KVK Law for the periods specified in applicable legislation or as necessary for the processing purpose. These periods are approximated in our Personal Data Retention and Disposal Policy:

Membership and order records, 10 Years, Law No. 6098

All accounting and financial transaction records: 10 years -the Law no. 6102, Legislation No. 213

Cookies  540 days at most.

Confirmation records for commercial electronic messages, 1 year from the date of withdrawal- Law No. 6563 and related secondary legislation

Information about traffic for online visitors, 2 years, the Law No. 5651

1 year for receipt of information and/or curriculum vitae in response to a job application.

Member Customer/Guest Customer Personal Data, 10 years after the legal relationship ended; 3 years pursuant to Law 6563 and related secondary legislation, the Law no. 6563, the Law no. 6102, the Law no. 6098, the Law no. 213 and the Law no. 6502.

Personal information collected for the purpose of conducting usability testing research, 2 weeks

You can review our Cookie Policy to learn about the time periods for which we retain personal data obtained through cookies.

h. Segmentation and Profiling

Utilization of personal data processed by Luviloom Member/Guest Customers;

• a. Regarding the Member Customer/Guest Customer who has given consent to receive commercial electronic messages, it carries out profiling and segmentation in order to prepare more suitable content for the Member Customer/Guest Customer's tastes and preferences, and to make advertisements, promotions and discounts.

• b. Profiling and segmentation of Member Customers/Guest Customers who have not consented to commercial electronic messages are conducted;

a. Improving the product (determining the most sold or unsold product categories),

b. Organizing campaigns for customer segments with the potential to purchase a particular product by developing models and uploading them to the system,

c. Efforts are being made to increase the potential for sales.

Profiling and segmentation studies do not directly use the Member Customer/Guest Customer's personal data, particularly their name and surname, mobile phone, e-mail, or address information; rather, transactions are made using the Member Customer/Guest Customer IDs assigned to them. The Customer/personal Member's data is protected through the use of the Member Customer/Guest Customer ID, or pseudonymous data. Member Customer/Guest Customer IDs are password-protected and are only accessible to designated individuals or departments within Luviloom. These Member Customer/Guest Customer IDs are encrypted by Luviloom within the system, and access to this section is restricted to a small number of individuals.

i. What are Related Persons' Rights Regarding Their Personal Data and How Can They Exercise These Rights

The following are the Related Person's rights regarding the personal data processed by Luviloom pursuant to article 11 of the KVK Law:

• Determining whether or not personal data is processed;

• Inquiring about the processing of personal data,

• Ascertaining the purpose for which personal data is processed and ensuring that it is used in accordance with that purpose.

• Identifying third parties to whom personal data is transferred domestically or internationally,

• Inquiring about the correction of personal data that has been processed inadvertently or incorrectly,

• Submitting a request for the deletion or destruction of personal data in accordance with the conditions set forth in Article 7 of the KVK Law.

• Notifying third parties to whom personal data has been transferred of transactions made pursuant to subparagraphs (d) and (e);

• Objecting to the emergence of a result against the individual through the use of exclusively automated systems to analyse the processed data,

• To seek redress for damages incurred as a result of wrongful processing of personal data.

To exercise your rights regarding your personal data, you may log into your account via the "My Account" section of the Luviloom website, mobile application, or mobile site and make any necessary changes, updates, or deletions. Additionally, you may apply for and exercise your rights in accordance with the procedures specified in the "Application Form" issued pursuant to Article 13 of the KVK Law on the website or mobile application of Luviloom's electronic commerce platforms.

j. How Relevant Individuals Can Modify Their Preferences for Receiving Electronic Commercial Messages

You can change or update your positive or negative preferences for receiving commercial electronic messages, which you provided when subscribing to the Luviloom website or mobile application, at any time by accessing the "My Account" section.

Membership cancellation does not imply that you have withdrawn your consent to receive commercial electronic messages. As a result, be certain to complete all procedures necessary to revoke your consent.

To manage cookies, you can follow the steps outlined in our Cookie Policy.

k. Disclosure of Personal Information to Official Authorities

Luviloom, your personal data relating to your visit to or membership in Luviloom's electronic commerce platforms and mobile applications, and traffic data such as your browsing information, in order for Luviloom to comply with its legal obligations (such as, but not limited to, fight against crime, threat to state and public security, etc.). If Luviloom is required to notify or provide information by law or administrative order, it may share this information with public institutions and organisations that are legally authorised to request it.

l. Cookie Management and Utilization

You can review our Cookie Policy for detailed information about the cookies used by Luviloom, including the types of cookies used, their intended uses, the duration of their storage, and how to manage cookies.

2. Conditions for the Erasure, Deletion, and Anonymization of Personal Data

Luviloom retains personal data processed via its website, mobile application, or mobile site for the duration specified by applicable laws and/or as required by the purpose of processing, in accordance with KVK Law articles 7, 17, and 138 of the Turkish Penal Code. When these time periods have expired, it will delete, destroy, or anonymize Personal Data in accordance with the Regulation on the Deletion, Destruction, or Anonymization of Personal Data.

Luviloom defines deletion of personal data as the process of making personal data inaccessible and unusable in any way to the relevant users.

Luviloom accomplishes this by developing and implementing a user-level access authorization and control matrix. It takes the necessary steps to delete the record from the database.

Luviloom defines data destruction as the process of making personal data inaccessible, unrecoverable, and unusable in any way by anyone.

Luviloom's anonymization of personal data means that it cannot be associated in any way with an identified or identifiable natural person, even when combined with other data.

Luviloom describes in detail the deletion, destruction, and anonymization processes it uses, as well as the technical and administrative safeguards it implements in accordance with the Regulation on the Deletion, Destruction, or Anonymization of Personal Data. The period of time specified by the Regulation for periodic destruction is determined in this Policy to be six months.

3. Modifications to the Privacy/Protection of Personal Data Policy

Luviloom reserves the right to update or modify this Privacy/Personal Data Protection Policy at any time. These modifications will become effective immediately upon publication of the revised new Privacy/Personal Data Protection Policy. Our members will be notified when this Privacy/Personal Data Protection Policy is updated.