Explains how we process the personal data of passenger-app and website users, who we share it with, and your rights under the KVKK.
Data controller: Volt Lines Akıllı Ulaşım Teknolojileri ve Taşımacılık A.Ş.
01
Introduction and data controller
This Notice has been prepared to explain and inform you how Volt Lines Akıllı Ulaşım Teknolojileri ve Taşımacılık A.Ş. (“Volt Lines”), acting as data controller for the personal data obtained through the website it has created and operates, processes the personal data it collects from website visitors and users, in accordance with Turkish Personal Data Protection Law no. 6698 (the “Law” or “KVKK”).
02
Personal data we process
2.1 · Everyone who visits the website
Transaction security data: website entry and exit records, IP address information. Other information: data obtained through the cookies we use, and messages containing your requests and suggestions.
2.2 · Users who request information through the website
Meeting or direct contact request: full name, mobile phone number, email address, and the name of the legal entity / company on whose behalf the request is made. Quote request: in addition to the above, the region the company is in, its headcount, the number of vehicles requested, the service type, and any other information the user provides about the service requested.
03
Why we process your data
We process the personal data we collect for the following purposes, within the framework set out in Articles 5 and 6 of the Law:
01 To maintain information and transaction security on the website. 02 To respond to your suggestions, complaints and requests about our services and activities. 03 To deliver service of the quality and standard we committed to in the employee shuttle transport agreement with your employer. 04 To comply with the laws, regulations, circulars and directives governing shuttle transport operations. 05 To provide information to the competent authorities where required by legislation or by an official request. 06 To improve our services and the Volt Lines applications. 07 To carry out marketing and promotional activities. 08 To increase use of our website, run the marketing processes for our brand and products, and serve personalised advertising. 09 To plan the activities needed to recommend our products and services tailored to preferences, usage habits and needs. 10 To analyse how visitors and users use the website. 11 To audit and report on our service levels and user experience. 12 To plan and carry out visitor and user relationship management processes. 13 To track visitor and user feedback, requests and complaints. 14 To develop new products and solutions.
In addition, for those acting on behalf of a legal entity, the contact details declared through the website may be used to contact you by email or SMS as part of marketing activities such as promotion, advertising, campaigns, offers, announcements, greetings, surveys, prize draws, competitions and newsletters.
04
Do we transfer your personal data to third parties?
We do not share any of your personal data with third parties without your consent, unless we are obliged to do so under applicable law or required to by order of a competent authority. Volt Lines may disclose personal data in line with requests from the relevant legal authorities in order to meet legal requirements, act on its legal rights or defend itself against legal claims, protect the interests of Volt Lines, combat fraud and uphold principles of good faith, or protect the rights or safety of any person.
We use the secure cloud infrastructure of Amazon Web Services to operate the Volt Lines applications. Personal data collected through the application is held in the Central Europe region (Frankfurt), subject to the security features and strong encryption algorithms below:
Data at restProtected with the AES-256 encryption algorithm.Data in transitOnly SSL / TLS (secure) client connections are permitted.Access controlThrough the AWS identity and access management system, only a small group of people within the company (system administrators) are allowed to access the data.Network isolation and firewallData servers sit inside a virtual private cloud (VPC) with no access from outside; only servers in the same VPC can reach the data.Database activity streamsBeyond external threats, AWS also protects against insider risk; the activity stream is monitored and the relevant alarms are raised.
For more about AWS and data security you can visit aws.amazon.com.
We take the administrative and technical measures needed to prevent unauthorised access to your personal data by Volt Lines staff or by third parties, and to prevent that data being used for purposes other than those it was transferred for. Where users share special categories of personal data, we will protect that data appropriately to its nature, subject to additional security measures and authorisations. Where your personal data is transferred to third parties on the basis of the consent you have given, we are responsible for ensuring the transfer is carried out securely. Should your personal data be subject to unauthorised access of any kind, or become accessible to third parties outside the transfers described in this notice, we will notify you immediately.
As both data processor and data controller, we inform our employees and subcontractor personnel in writing that the necessary security measures must be taken and observed in relation to the processing of your personal data.
05
Your rights under Article 11 of the KVKK
As a data subject you have the following rights:
01 To learn whether your personal data is being processed. 02 To request information about it if your personal data has been processed. 03 To learn the purpose of processing and whether your data is used in line with that purpose. 04 To know the third parties, in Türkiye or abroad, to whom your personal data has been transferred. 05 To request correction of your personal data where it has been processed incompletely or inaccurately, and to request that the correction be notified to the third parties the data was transferred to. 06 To request erasure or destruction of your data where the reasons requiring its processing have ceased to exist, even though it was processed lawfully, and to request that this be notified to third parties. 07 To object to an outcome to your detriment arising from analysis of your processed data solely by automated systems. 08 To claim compensation for damage suffered as a result of unlawful processing of your personal data.
06
How to submit a request
You can submit requests relating to your rights through the channels below, together with the documents needed to verify your identity and your contact details:
By postWet-signed, to: Sultan Selim Mah. Hümeyra Sokak, Nef 09 Sitesi B Blok No: 7/217, Kağıthane / İstanbul, Türkiye
By emailSend your request straight to our data protection team.
Once you send us your request, we will provide a reasoned response free of charge within thirty days at the latest, depending on the nature of the request. Where responding incurs an additional cost, we apply the fees in the tariff set by the Personal Data Protection Board.