innthebox
legal

Notice on the Protection and Processing of Personal Data (GDPR)

In accordance with the EU General Data Protection Regulation (GDPR) and Law No. 6698 on the Protection of Personal Data (the "Law"), this notice explains, in our capacity as data controller, the purposes for which INNTHEBOX Yazılım ve Pazarlama A.Ş. ("INNTHEBOX", the "Company") processes your personal data, to whom it may be transferred, how long it is retained, and the rights you hold in this respect.

This notice applies to visitors of innthebox.com, to anyone completing the contact and demo request forms on the site, to employees of our customers and business partners, and to everyone who contacts us by email, by phone or at events.

Data controller

INNTHEBOX Yazılım ve Pazarlama A.Ş.

  • Address: Müeyyetzade Mah. Kemeraltı Cad. No: 24 İç Kapı No: 7, 34425 Beyoğlu, İstanbul, Türkiye
  • Email: info@innthebox.com
  • Website: innthebox.com

The personal data we process

We only ask you for the data we need in order to answer your request and provide our service. The categories of data processed are as follows:

Identity and contact data

  • Name and surname
  • Email address, phone number
  • The organisation you work for and your role

Request and correspondence content

  • The request topic you select in the form (demo, project, support, partnership)
  • The content of your message and the correspondence between us
  • Meeting and call notes

Transaction security and technical data

  • IP address, browser and device information
  • Pages visited, date and time of the visit
  • Usage records collected through cookies

Marketing and preference data

  • Your consent to commercial electronic messages (email, SMS) and your consent history
  • Your language and site usage preferences

We do not request special categories of personal data (health, biometric data, beliefs, trade union membership, etc.). Please do not enter such data into our forms.

How we collect your personal data

Your personal data is collected by wholly or partly automated means through the following channels:

  • The contact and demo/project request forms on the site
  • Communication with us by email, telephone and online meeting software
  • Cookies and similar technologies (details: Cookie Policy)
  • Business cards and information you give us at fairs, events and promotional activities
  • Contact details shared with us by the organisation whose customer you are

Purposes of processing

  • Responding to your requests, questions and complaints, and communicating with you
  • Running demo and proposal processes
  • Establishing, performing and following up contractual processes
  • Providing, improving and supporting the services we offer
  • Ensuring the security of the site and preventing misuse and fraud
  • Measuring and improving how the site is used
  • Sending promotional and campaign messages where you have given explicit consent
  • Fulfilling our financial, legal and administrative obligations
  • Responding to requests from authorised public institutions and organisations

Legal grounds

Your personal data is processed on the following legal grounds set out in Articles 5 and 6 of the Law:

  • Conclusion or performance of a contract (Art. 5/2-c): running proposal, demo and contract processes
  • Legal obligation (Art. 5/2-ç): obligations arising from tax, commercial and e-commerce legislation
  • Establishment, exercise or protection of a right (Art. 5/2-e): retention as evidence in the event of a dispute
  • Legitimate interest (Art. 5/2-f): site and information security, measuring and improving service quality
  • Explicit consent (Art. 5/1): sending commercial electronic messages and non-essential measurement cookies

Where processing is based on explicit consent, you may withdraw your consent at any time; withdrawal does not invalidate the processing carried out up to that point.

Who we share it with

We do not sell your personal data and we do not transfer it to third parties for marketing purposes. Your data may be transferred to the following parties only to the extent required by the purposes listed above and with the necessary security measures in place:

  • Our suppliers of hosting, server and cloud infrastructure services
  • Our providers of email, online meeting and customer communication infrastructure
  • Business partners and solution providers we work with in order to deliver the service
  • Our legal and financial advisors and independent auditors
  • Authorised public institutions, organisations and judicial authorities upon request

We conclude agreements with the suppliers to whom data is transferred, requiring that personal data be processed solely in line with our instructions. Where a transfer abroad is necessary, the conditions in Article 9 of the Law are observed; such a transfer is made only where the safeguards prescribed by the Board are in place, or with your explicit consent.

Retention periods

Your personal data is retained for as long as necessary for the purpose for which it is processed, and for the limitation periods prescribed by the relevant legislation. As a rule, we apply the following periods:

  • Records that turn into a contractual relationship: 10 years from the end of the relationship
  • Form and request records that do not turn into a contract: a maximum of 2 years from the date the record is created
  • Consent records for commercial electronic messages: 3 years from the withdrawal of consent
  • Site traffic and security logs: for the period prescribed by the relevant legislation

Once the period expires, your personal data is deleted, destroyed or anonymised.

Data security

We take the technical and administrative measures needed to ensure an appropriate level of security, in order to prevent the unlawful processing of your personal data and unlawful access to it:

  • Use of encryption in transit and at rest (HTTPS/TLS)
  • Role-based access authorisation and regular review of the authorisation matrix
  • Up-to-date patch management, firewalls and access logging
  • Confidentiality undertakings and awareness training for our employees
  • Assessment of suppliers in terms of data security

Your rights

Under Article 11 of the Law, by applying to us you have the following rights:

  • Learn whether your personal data is being processed
  • Request information about it if it has been processed
  • Learn the purpose of processing and whether the data is used in line with that purpose
  • Know the third parties in Türkiye or abroad to whom the data is transferred
  • Request the correction of incomplete or incorrectly processed data
  • Request its erasure or destruction within the conditions set out in the law
  • Request that correction, erasure and destruction be notified to the third parties to whom the data has been transferred
  • Object to a result against you arising from the analysis of the processed data exclusively by automated systems
  • Claim compensation for damage suffered as a result of unlawful processing

You may exercise these rights as described below.

Application

To exercise your rights you can follow the route described on the GDPR Data Subject Request page, or send your application to info@innthebox.com or to our postal address above. Depending on the nature of the request, your application will be concluded free of charge within thirty days at the latest. Where the process incurs an additional cost, the fee set out in the tariff determined by the Personal Data Protection Board may be charged.

If your application is rejected, if you find the response insufficient, or if no response is given within the applicable period, you retain the right to lodge a complaint with the Personal Data Protection Board.

Updates to this notice

This notice may be updated in line with changes in legislation and developments in our business processes. The current version is always published on this page.