This notice has been prepared under article 10 of Personal Data Protection Law no. 6698 to explain how your personal data is processed in orders placed at https://www.opencartextra.com and during card payment, to whom it is transferred, how long it is retained and what your rights are. It is an information notice; it contains no consent or approval statement.
1. Data controller
Data controller: W3 Bilişim Teknolojileri ve Yazılım Hizmetleri Limited Şirketi. Address: Cevizli Mah. Zuhal Cad. Ritim İstanbul A5 Blok No: 46 E İç Kapı No: 179 Maltepe / İstanbul. Tax office/number: Kartal V.D. · 7881052037. MERSİS: 0788-1052-0370-0001. E-mail: hello@w3.net.tr. Telephone: +90 532 476 9667.
OpencartExtra.com is the trade mark and service surface of this company. This notice is specific to the order and payment processes at https://www.opencartextra.com; the site's general data processing activities are explained in the KVKK Privacy Notice, cookies in the Cookie Policy, and live chat in the Live Chat Privacy Notice.
This document is an information notice. The processing activities described below rely not on explicit consent but on the legal grounds in the second paragraph of article 5 of the Law; no consent statement is therefore requested from you for this notice.
2. Personal data processed
Identity data: name and surname, for corporate orders the company name and the name of the authorised person, the national identity number or tax identification number used for invoicing, and the tax office.
Contact data: e-mail address, telephone number, billing address, district, province, postal code and country.
Customer transaction data: order number, order items, quantity and term, amount, currency, exchange rate and rate date, tax amount, proforma and invoice records, payment reference number (merchant_oid), payment status and type, failure codes and refund records.
Transaction security data: the IP address at the time of the order and of the approval, the date and time stamp, browser information (user agent), session identifiers and the version numbers of the legal documents approved.
Service-specific data: store address, OpenCart version, current hosting provider, domain name and extension, nameserver details, migration request and customer notes.
Card data is not processed. Your card number, expiry date and security code (CVV) are never transmitted to us at any stage; that data is processed only on the payment institution's own screen. Only the outcome of the transaction, the card type (credit/debit) and any instalment information are returned to us.
3. Why we never see your card details
The payment screen opens inside a separate frame (iframe) running on the payment institution's infrastructure. You enter your card details directly into the payment institution's screen; that data is never transmitted to our servers or to our page in your browser.
This design keeps card data on the side subject to the PCI DSS standard and means it never exists on our side at all.
3D Secure verification takes place between you and your card issuing bank; the verification code is not transmitted to us.
4. Purposes of processing
Creating your order, issuing the proforma document and sending it to you.
Taking and verifying payment, reconciling with the payment institution and carrying out refund processes.
Performing the service you purchased: installing the server, registering the domain name, planning support and maintenance work.
Issuing invoices and meeting accounting and tax obligations.
Delivering and retaining the pre-contractual information and contract texts on a durable medium as required by distance contract legislation.
Keeping records of approval and meeting the burden of proof in the event of a dispute.
Sending informational messages about the order, payment, performance and support processes.
Preventing fraud, misuse and automated attacks, and maintaining information security.
Managing complaint, refund and dispute processes at your request.
5. Legal grounds
KVKK art. 5/2-c — Processing directly related to the conclusion or performance of a contract: the identity, contact and customer transaction data processed in the order, payment, proforma, performance and refund processes relies on this ground.
KVKK art. 5/2-ç — Processing necessary for the data controller to fulfil a legal obligation: issuing and retaining invoices and accounting records under the Tax Procedure Law and the Turkish Commercial Code, and retaining the pre-contractual information and contract documents under distance contract legislation.
KVKK art. 5/2-e — Processing necessary for the establishment, exercise or protection of a right: evidential records such as the date and time of approval, the IP address and the document version rely on this ground.
KVKK art. 5/2-f — The legitimate interests of the data controller, provided that this does not harm your fundamental rights and freedoms: preventing fraud and misuse, maintaining transaction security and measuring service quality.
The sending of commercial electronic messages is outside the scope of this notice and relies solely on the separate consent obtained under Law no. 6563. That consent is not a condition of placing an order or of payment and may be withdrawn free of charge at any time.
6. Recipients of personal data and the purposes of transfer
Payment institution: in order for a card payment to be taken, your name and surname, e-mail address, telephone number, billing address, order amount, the titles of the order items, the order reference number and the IP address at the time of the transaction are shared with PayTR Ödeme ve Elektronik Para Hizmetleri A.Ş. The transfer is made in order to carry out the payment transaction and to meet obligations under Law no. 5549 and Law no. 6493.
Banks and card schemes: for authorisation of the payment, 3D Secure verification, reconciliation and refunds, through the payment institution.
Financial advisers and e-invoice/e-archive service providers: in order to issue invoices and keep statutory books.
Domain registrar and the relevant registry: where a domain registration has been ordered, your name, address, e-mail and telephone details are transferred as registrant under ICANN rules. Some of that information may appear in public registration lookups (WHOIS/RDAP) under ICANN policies.
Infrastructure and service providers: our suppliers of server hosting, e-mail delivery, backup and security services, only to the extent required by the service.
Competent public authorities and judicial bodies: within the scope of requests for information and documents arising from legislation.
Your personal data is not otherwise shared with third parties, sold or transferred for marketing purposes.
7. Transfers abroad
Records relating to the order and payment process are held on servers located in Türkiye, and the payment institution is established in Türkiye.
Where a domain registration has been ordered, registrant details are transferred to registrars and registries established abroad, as required by ICANN and registry rules. That transfer relies on the exceptions applied under article 9 of the KVKK where it is necessary for the performance of the contract, and it is technically impossible to complete a domain registration otherwise.
Transfers within the scope of the measurement and security services used on the site are explained in the Cookie Policy and the KVKK Privacy Notice.
In transfers abroad we act in accordance with the conditions of article 9 of the KVKK, and the transfer is limited to the minimum data required for the purpose.
8. How data is collected
Your personal data is collected electronically when you complete the order form, start the payment flow, contact us by e-mail or telephone and use live chat.
Data on the outcome of a payment is obtained automatically through the notification sent from the payment institution to our server and through reconciliation queries.
Information you have provided in a previous order may be pre-filled in the form so that you do not have to type it again; you can always change it.
9. Retention periods
Invoice, payment and accounting records: ten (10) years, under article 253 of the Tax Procedure Law and article 82 of the Turkish Commercial Code.
Order records, proforma documents and contract texts (together with the approved version information): ten (10) years.
Approval records — the date and time of approval, the IP address at the moment of approval, browser information and the approved document version: ten (10) years, in order to meet the burden of proof. These records are kept because distance contract legislation places the burden of proof on the seller, and are preserved throughout the applicable limitation periods.
Failed payment and fraud prevention records: two (2) years.
Commercial electronic message consent records: three (3) years from withdrawal of the consent.
At the end of the period, personal data is deleted, destroyed or anonymised. Where anonymisation is applied, accounting records such as the amount, document number and payment reference number continue to be retained while the data that makes an individual identifiable is irreversibly removed.
If you request deletion before the retention period expires, your request is answered with reasons in respect of data that must be retained because of a legal obligation or an evidential requirement.
10. Why the IP address and time stamp are retained
In distance contracts, the burden of proving that the consumer received the pre-contractual information and that the contract was concluded lies with the seller.
For that reason, the moment you tick the approval boxes is recorded together with the date, time, IP address and the version number of the document you approved. The same stamp also appears on the contract documents sent to you and on the proforma page.
The IP address is retained in these records unmasked; a masked record could not perform the evidential function. The record is used only for evidential, security and statutory purposes; it is not used for advertising, profiling or personalisation.
Access to these records is limited to a small number of employees who need it for their duties, and access events are logged.
11. Automated decisions and profiling
No assessment producing legal effects concerning you and carried out solely by automated systems is applied during the payment process.
Technical controls carried out for fraud prevention and automated request protection (rate limiting, bot protection) do not constitute an assessment of personality, and where an order is blocked the matter is open to human review.
The decision to approve or decline a card transaction is taken by the card issuing bank; we have no influence over that decision.
12. Data security
The site and the entire payment flow are encrypted with TLS. The payment screen runs on the payment institution's PCI DSS compliant infrastructure.
Notifications received from the payment institution are subjected to cryptographic signature verification; notifications that cannot be verified are not processed.
Database access is restricted by authorisation, backups are stored encrypted and infrastructure updates are applied regularly.
The administrative and technical measures required by article 12 of the KVKK are taken in order to prevent the unlawful processing of personal data and unlawful access to it. In the event of a data breach, notification is made to the Personal Data Protection Board and to the data subjects within the period prescribed by legislation.
13. Your rights and how to apply
Under article 11 of the KVKK you have the right to learn whether your personal data is being processed, to request information if it has been processed, to learn the purpose of processing and whether the data is used in line with that purpose, to know the third parties to whom it is transferred in Türkiye or abroad, to request that it be corrected if it is incomplete or inaccurate, to request its erasure or destruction, to request that correction, erasure and destruction operations be notified to the third parties to whom the data was transferred, to object to a result arising against you from analysis carried out solely by automated systems, and to claim compensation if you suffer loss because of unlawful processing.
You may submit your applications, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller and together with information verifying your identity, in writing to hello@w3.net.tr or to Cevizli Mah. Zuhal Cad. Ritim İstanbul A5 Blok No: 46 E İç Kapı No: 179 Maltepe / İstanbul.
Your application is concluded free of charge as soon as possible and in any event within thirty days, depending on the nature of the request. Where the transaction incurs a cost, the fee set out in the tariff determined by the Board may be charged.
If your application is refused, if you find the response inadequate or if no response is given within the period, you may lodge a complaint with the Personal Data Protection Board within thirty days of learning of the response and in any event within sixty days of the date of your application.
14. Changes to this notice
This privacy notice may be updated because of changes in legislation or in our processes. The current version is always published in the legal documents section at https://www.opencartextra.com.
The version of this document is 1.0. Its effective date is shown at the top of the document.
The version in force at the time of an order applies to that order, and the approved version number is retained together with your order record.