This Privacy Policy explains how TruckDoc handles personal data when you visit truckdoc.net, create an account, place an order, or contact us. Because TruckDoc is operated from Türkiye and serves customers internationally, this policy is written to satisfy both Türkiye's Personal Data Protection Law (KVKK, Law No. 6698) and the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) in a single English-language document. Where the two regimes diverge, we apply the higher standard.
1. Who we are (Data controller)
TruckDoc operates the website at truckdoc.net. The data controller is TRUCKDOC E-TİCARET OTOMOTİV ANONİM ŞİRKETİ (“TruckDoc”), a Turkish joint-stock company registered with the Seğmenler Tax Office under tax number 8591405012, with its registered office at:
Kızılırmak Mah. Dumlupınar Bul. Nextlevel No: 3A İç Kapı No: 10
Çankaya / Ankara, Türkiye
TruckDoc is registered with the Turkish Personal Data Protection Authority Data Controllers’ Registry (VERBIS). Registry application submitted on 14 May 2026; the VERBIS Registry Number will be published here once the application is finalised.
You can reach us at info@truckdoc.net or through the postal address above. For privacy-specific requests, please use the dedicated mailbox described under How to exercise these rights below rather than the general contact address — it shortens response time.
2. What data we collect
We process the following categories of personal data:
- Account data — your name, email address, optional phone number, and a salted bcrypt hash of your password (we never store the password itself).
- Order data — billing and shipping addresses, the items you purchase, invoice records, and any tax identifiers required by law.
- Technical data — IP address, user-agent string, session cookies, device and browser metadata, and security logs (failed login attempts, suspicious requests, rate-limit events).
- Communication data — messages you send through the contact form, email correspondence with our support team, and any attachments you provide.
3. Purposes of processing
We process personal data to:
- operate your account and authenticate you across sessions;
- fulfil orders, issue invoices, and arrange shipping with our carriers;
- provide customer support and resolve disputes or warranty claims;
- protect the service against fraud, account takeover, abuse, and security incidents;
- comply with legal obligations under tax, consumer-protection, accounting, and electronic-commerce law.
4. Legal basis
Our processing rests on four legal bases. We rely on performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)) to operate your account, fulfil your orders, and handle returns. We rely on legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç)) to retain invoices, tax records, and accounting books for the periods required by Turkish commercial and tax law. We rely on legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)) for fraud prevention, network and information security, and limited internal analytics needed to keep the service reliable. Where neither of the above applies — for example, non-essential analytics or marketing emails — we rely on your consent (GDPR Art. 6(1)(a); KVKK Art. 5(1)), which you can withdraw at any time without affecting prior lawful processing.
5. Recipients and transfers
We share personal data only with processors who help us run the service: payment processors (to charge your card and remit funds), shipping carriers (to deliver your orders), email service providers (to send transactional and account messages), and infrastructure hosts (to operate our servers, databases, and backups). Each processor is bound by a written agreement requiring confidentiality, security, and data-minimisation. Where personal data leaves Türkiye or the EEA, we rely on Standard Contractual Clauses or an equivalent transfer mechanism under KVKK Art. 9 and GDPR Chapter V. We do not sell personal data, and we do not share it with advertising networks for cross-site tracking.
6. Retention
We keep personal data only as long as we need it. Account data is retained while your account is active and for up to twelve months after closure, so we can reinstate it if you change your mind or resolve outstanding issues. Order and invoice records are retained for the period required by Turkish tax and commercial law — typically ten years from the end of the fiscal year in which the transaction occurred. Security logs are retained for twelve months. After the applicable retention period expires, data is deleted or irreversibly anonymised.
7. Your rights (KVKK Art. 11 + GDPR Art. 15–22)
Under Turkish and EU data protection law, and regardless of where you reside, you have the right to:
- be informed about whether we process your personal data;
- request information about the processing if we do;
- learn the purposes of processing and whether the data is used in line with them;
- know the third parties to whom personal data is transferred, in Türkiye or abroad;
- request correction of incomplete or inaccurate data;
- request deletion or destruction of personal data when the grounds for processing no longer apply;
- object to outcomes produced solely by automated processing where they affect you adversely;
- receive your data in a structured, commonly used, machine-readable format and have it transmitted to another controller, where technically feasible (data portability, GDPR Art. 20);
- seek compensation for damage arising from unlawful processing.
You also have the right to lodge a complaint with a supervisory authority — the Turkish Personal Data Protection Authority (KVKK Kurumu) or your local EU data protection authority.
8. How to exercise these rights
To exercise any of the rights above, email privacy@truckdoc.net from the address associated with your account. We respond within thirty days under KVKK and within one month under GDPR, with a possible two-month extension for complex or high-volume requests (we will tell you within the first month if we need the extension and why). To prevent unauthorised disclosure, we may ask you to verify your identity before acting on a request; the verification step is itself processed only for that purpose and discarded afterwards.
9. Cookies
We use a small number of strictly necessary cookies to keep you signed in and to protect against CSRF. Non-essential cookies — analytics and any future marketing cookies — fire only after you give consent through our cookie banner, and can be revoked at any time from the same banner. For the full list of cookies, their purpose, and their lifetime, see our Cookie Policy.
10. Updates to this policy
The “Last updated” date at the top of this page reflects the most recent change. When we make material changes — such as new processing purposes, new recipients, or longer retention periods — we will notify registered users by email and post a prominent notice on the site before the change takes effect.
11. Contact
- Data controller — TRUCKDOC E-TİCARET OTOMOTİV ANONİM ŞİRKETİ
- Registered office — Kızılırmak Mah. Dumlupınar Bul. Nextlevel No: 3A İç Kapı No: 10, Çankaya / Ankara, Türkiye
- Tax registration — Seğmenler Tax Office, VKN 8591405012
- General inquiries — info@truckdoc.net
- Privacy / Data Protection Officer — privacy@truckdoc.net
If you would prefer to contact us through the website, please use our contact page. For information about returns and refunds, see Returns & Refunds; for delivery details, see Shipping Information; and for the contractual terms governing your purchase, see our Terms of Service.