Peşin fiyatına 3 taksit

Personal Data Retention and Disposal Policy

Last updated: 11 September 2026

1. Purpose and Scope

This policy sets out the procedures and principles for retaining and disposing of personal data processed by GNR Oyuncak Gıda Sanayi Ticaret Limited Şirketi under Law No. 6698 on the Protection of Personal Data and the Regulation on the Deletion, Destruction or Anonymisation of Personal Data.

The policy covers all natural persons whose personal data are processed, including customers, visitors, supplier employees and job applicants.

2. Definitions

Deletion Making personal data inaccessible and unusable in any way by relevant users
Destruction Making personal data inaccessible, irrecoverable and unusable in any way by anyone
Anonymisation Making personal data impossible to associate with an identified or identifiable natural person, even when matched with other data
Periodic disposal Deleting, destroying or anonymising personal data on the organisation's own initiative at the recurring intervals specified in the policy once the conditions for processing no longer exist

3. Storage Environments

Electronic environments Non-electronic environments
E-commerce platform (Shopify), email servers, accounting and electronic invoicing software, cloud storage, backup environments and office computers Printed invoices and dispatch notes, printed forms, written contracts and archive cabinets

4. Legal Grounds Requiring Retention

  • Law No. 6502 on the Protection of Consumers
  • Law No. 6563 on the Regulation of Electronic Commerce
  • Tax Procedure Law No. 213
  • Turkish Commercial Code No. 6102
  • Turkish Code of Obligations No. 6098
  • Law No. 6698 on the Protection of Personal Data

5. Retention Periods

Data / process Retention period Disposal timing
Order, invoice and accounting records 5 years from the end of the year to which they relate under Tax Procedure Law No. 213 At the first periodic disposal after the period expires
Contracts and commercial records 10 years under Turkish Commercial Code No. 6102 At the first periodic disposal after the period expires
Membership and customer account information For the duration of the account and for 10 years under the Turkish Code of Obligations No. 6098 after it ends At the first periodic disposal after the period expires
Request, complaint and support records 3 years At the first periodic disposal after the period expires
Commercial electronic message consent records 3 years after consent is withdrawn under the Regulation on Commercial Electronic Messages At the first periodic disposal after the period expires
Internet access and transaction log records 2 years At the first periodic disposal after the period expires
Camera recordings 14 days (automatically overwritten by the recording device) Automatically at the end of the period

6. Disposal Methods

Deletion

  • Making the database record inaccessible to relevant users
  • Removing access permissions in cloud and server environments
  • Redacting data on paper

Destruction

  • Irreversibly shredding paper documents in a document shredder
  • Physically destroying storage media (disks, USB drives) or overwriting them with secure software

Anonymisation

  • Removing identifying fields and using masking and aggregation techniques so the data cannot be associated with a natural person

7. Periodic Disposal Schedule

Periodic disposal schedule, responsible persons and recording method: Periodic disposal is carried out every June and December, no more than six months apart, and documented in a record.. The schedule is determined with regard to the maximum periods under applicable legislation.

Disposal requested by a data subject is completed within 30 days of receipt of the request.

8. Technical and Organisational Measures

Measures actually implemented concerning access control, secure communications, backups, records, training and data processor agreements: Admin access is restricted to authorised persons; card data is processed by a PCI DSS-compliant payment provider; Shopify is PCI DSS Level 1 compliant; corporate email uses SPF and DKIM; confidentiality obligations and data-processing terms are used with staff and service providers..

9. Responsibilities and Allocation of Duties

Company name Responsibility
Company Owner and Manager Implementing and updating the policy
Accounting Officer Carrying out and documenting periodic disposal
E-commerce Officer Implementing technical measures

10. Entry into Force and Updates

This policy entered into force on 11 September 2026. It is updated when legislation changes or as needed; the current version is published on this page.

11. Contact

For questions and requests about the policy: kvkk@romansonofficial.com · gnroyuncak@hs01.kep.tr · Mahmutbey Mahallesi, 2412. Sokak, C Plaza, Kat: 8, No: 89, Bağcılar / İstanbul