Fabik

Legal · KVKK

Privacy Policy

Last updated: 20 June 2026

Data Controller

NEHES LABS TEKNOLOJİ SANAYİ VE TİCARET LİMİTED ŞİRKETİ
Brand
Fabik
Address
Fatih Mah. 3302 Sk. Seyitoğlu Yapı-6 No: 16 A, Merkez / Batman, Türkiye
Tax Office / No
Batman Tax Office — 6301465945
Phone
+90 538 737 48 12
Email
info@fabik.com.tr
This is an English translation provided for your convenience. This document was originally drawn up in Turkish; in the event of any discrepancy between the English and Turkish versions, the Turkish version shall prevail.

This Information Notice sets out the principles governing the fulfilment of the obligation to inform you about the personal data processed by NEHES LABS TEKNOLOJİ SANAYİ VE TİCARET LİMİTED ŞİRKETİ (brand: 'Fabik') within the scope of the services provided through the Fabik web and mobile applications (fabik.com.tr / app.fabik.com.tr), pursuant to the Turkish Personal Data Protection Law No. 6698 ('KVKK') and the relevant secondary legislation, together with the principles applicable to the use of cookies. Fabik is a multi-tenant factory and production management software offered under a software-as-a-service (SaaS) model over the internet, and is intended solely for businesses (merchant/B2B); no service is offered to individual consumers. This notice covers the natural persons who directly register with or transact on Fabik (the Subscriber's authorised representatives, agents and users); with respect to the personal data of third parties that the Subscriber uploads to the platform, the obligation to inform rests with the Subscriber in its capacity as data controller, as explained in Section 13. Please review this notice carefully together with the Distance Sales Agreement and the Delivery & Refund Policy.

1Identity of the Data Controller

Your personal data is processed in the capacity of data controller under the KVKK by NEHES LABS TEKNOLOJİ SANAYİ VE TİCARET LİMİTED ŞİRKETİ (brand: 'Fabik'), whose identity and contact details are set out below.

  • Company name: NEHES LABS TEKNOLOJİ SANAYİ VE TİCARET LİMİTED ŞİRKETİ (brand: Fabik)
  • Address: Fatih Mah. 3302 Sk. Seyitoğlu Yapı-6 No: 16 A, Merkez / Batman
  • Tax Office / No: Batman V.D. — 6301465945
  • Phone: +90 538 737 48 12
  • E-mail: info@fabik.com.tr
  • Web: fabik.com.tr / app.fabik.com.tr

2Definitions

The principal terms used in this notice have the following meanings, in accordance with the definitions set out in the KVKK and the relevant legislation:

2.1. Personal data: Any information relating to an identified or identifiable natural person.

2.2. Special categories of personal data: Data relating to a person's race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of an association, foundation or trade union, health, sex life, criminal convictions and security measures, as well as biometric and genetic data.

2.3. Data subject: The natural person whose personal data is processed.

2.4. Data controller: The natural or legal person who determines the purposes and means of processing personal data and is responsible for establishing and managing the data recording system.

2.5. Data processor: The natural or legal person who processes personal data on behalf of the data controller, based on the authority granted by the data controller.

2.6. Processing: Any operation performed on personal data, such as obtaining, recording, storing, modifying, transferring, taking over and any other operation, carried out by wholly or partly automated means, or by non-automated means provided that it forms part of a data recording system.

2.7. Explicit consent: Consent relating to a specific matter, based on information and expressed freely.

2.8. Anonymisation: Rendering personal data incapable of being associated with an identified or identifiable natural person in any manner whatsoever, even where it is matched with other data.

2.9. Subscriber (Buyer): The merchant/business that acquires the service within the scope of its commercial or professional activity; this refers to the same person as the party referred to as 'Buyer / Subscriber' in the Distance Sales Agreement.

3Categories of Personal Data Processed

Depending on the nature of the service and the features you use, the following categories of personal data may be processed by Fabik:

3.1. Identity: Name and surname.

3.2. Contact: Mobile phone number, e-mail address.

3.3. Customer transaction / company information: Business name, tax office and tax number, information relating to subscription and account activity.

3.4. Transaction security: IP address, log records, session and device information, OTP verification records.

3.5. Marketing: Information relating to demo requests and preferences, and to consents given for permitted commercial electronic messages.

3.6. Finance / payment: Transaction information relating to subscription payments. Your card details are not stored or viewed by Fabik; the payment transaction is carried out by the licensed payment institution iyzico, and only the transaction result and, where necessary, masked information are transmitted to Fabik.

3.7. Location: Delivery address and location information entered or used within the scope of the map and delivery/shipment features.

With respect to the data that the Subscriber itself uploads to the Fabik platform (for example, data relating to its own customers, employees, orders and production processes), the Subscriber is the data controller; in respect of such data, Fabik acts as a data processor operating in accordance with the Subscriber's instructions. The principles relating to this matter are explained in Section 13.

4Purposes of Processing Personal Data

Your personal data is processed for the following purposes:

  • Providing, maintaining and improving the Fabik service (SaaS),
  • Creating and managing account and membership registration,
  • Providing passwordless identity verification by means of a one-time code (OTP) sent to your phone number,
  • Conducting subscription and payment processes and carrying out billing and accounting operations,
  • Delivering push notifications and providing map, delivery address and location display features,
  • Providing support services in relation to requests, questions and complaints,
  • Conducting information security processes, preventing misuse and ensuring system security,
  • Fulfilling legal obligations arising from the relevant legislation,
  • Carrying out communication activities,
  • Providing demo access,
  • Carrying out permitted marketing and promotional activities where your explicit consent is present.

5Legal Grounds for Processing

Your personal data is processed on the basis of the following legal grounds set out in Article 5 of the KVKK:

5.1. Establishment or performance of a contract (Art. 5/2-c): Your identity, contact, customer transaction/company, location and finance/payment data is processed on this ground for the purposes of creating an account, identity verification via OTP, providing the service, delivering push notifications, providing map/delivery address and location features, and conducting subscription and payment processes.

5.2. Legal obligation (Art. 5/2-ç): Your company and finance/payment data is processed on this ground for the purpose of fulfilling retention, billing and disclosure obligations to authorised public authorities arising from tax, commercial and other legislation.

5.3. Establishment, exercise or protection of a right (Art. 5/2-e): Your data relating to transaction security and contractual processes is processed on this ground for the purpose of constituting evidence in possible disputes and providing a defence against legal claims.

5.4. Legitimate interest (Art. 5/2-f): Your transaction security data is processed on this ground, provided that it does not harm the fundamental rights and freedoms of the data subject, for the purposes of ensuring system security, preventing fraud and misuse, and improving the service.

5.5. Explicit consent (Art. 5/1): Processing of personal data for marketing purposes is carried out on this ground where your explicit consent is present. The sending of commercial electronic messages is, additionally, subject to your consent under the Turkish Electronic Commerce Law No. 6563 (ETK), and this consent is a separate consent independent of the KVKK explicit consent. You may withdraw your explicit consent and your ETK consent at any time; the withdrawal of consent does not affect processing operations that are mandatory for the performance of the service. The legal framework relating to cross-border data transfers is explained in Section 7.2.

6Method of Collecting Personal Data

Your personal data is collected in electronic form, by wholly or partly automated means or by non-automated means provided that it forms part of a data recording system, through the following channels:

  • Registration, account and demo request forms on the web and mobile application, and manual entries made into such forms,
  • The identity verification flow via a one-time code (OTP) sent to your phone,
  • Cookies and similar technologies,
  • Log, session and device records automatically generated by the system,
  • Indirectly from business partners and service providers (for example, transaction result information returned from the payment institution).

7Transfer of Personal Data

Your personal data may be transferred to the following parties, limited to the purposes set out above and in compliance with the conditions set out in Articles 8 and 9 of the KVKK.

7.1. Domestic transfer: The recipients set out below provide their services from Türkiye, and your data is processed in Türkiye:

  • iyzico — For the purpose of conducting payment processes; a licensed payment/electronic money institution operating domestically. Your card details are not held/viewed at Fabik; they are processed by the PCI-DSS compliant iyzico.
  • Netgsm — For the purpose of sending SMS/OTP; a messaging service provider operating domestically.
  • Natro — Within the scope of hosting (server) services; your data is held in Türkiye.
  • Authorised public institutions and organisations — Upon request, as required by legal obligation.

7.2. Cross-border transfer (KVKK Art. 9): Your personal data is transferred abroad within the scope of the use of the following services:

  • Firebase / Google — For the purpose of delivering push notifications,
  • Google Maps — For the purpose of providing the map and the delivery/shipment address and location display features used by the Subscriber within the application.

Since the push notification and map/location features are necessary and functional for the provision of the service, the relevant processing is based on the legal grounds of performance of a contract (KVKK Art. 5/2-c) and, where necessary, legitimate interest (Art. 5/2-f); these processing operations are not subject to the requirement of explicit consent. The cross-border component of the transfer is carried out, pursuant to KVKK Art. 9, primarily where an adequacy decision announced by the Personal Data Protection Board exists; in the absence thereof, by providing one of the appropriate safeguards set out in Art. 9/2 (a standard contract notified to the Board, binding corporate rules, or an undertaking authorised by the Board). Explicit consent is applied only in the incidental cases enumerated in Art. 9/6 and where no adequacy decision or appropriate safeguard exists, as a fallback legal basis; it is not the basis for continuous and systematic transfers.

8Retention Periods

Your personal data is retained for the period necessary for the purpose for which it is processed and for the maximum periods provided for in the relevant legislation.

8.1. Commercial books, records and documents are retained for 10 years pursuant to Article 82 of the Turkish Commercial Code No. 6102. For documents within the scope of the Tax Procedure Law, the minimum retention period is 5 years; where the same document is also subject to the Turkish Commercial Code, the longer 10-year period applies.

8.2. Account and service data is retained for the duration of the subscription; after the subscription ends, it is retained for the period necessary, not exceeding the relevant general limitation period (a maximum of 10 years), without prejudice to evidentiary obligations and the limitation periods relating to possible legal disputes.

8.3. Upon expiry of the retention period, your personal data is deleted, destroyed or anonymised in the first periodic destruction cycle or upon your request. Fabik fulfils its obligations relating to the destruction of personal data within the framework of periodic destruction principles.

9Technical and Administrative Measures Taken for Data Security

Fabik takes the necessary technical and administrative measures to ensure an appropriate level of security, in order to prevent the unlawful processing of and unlawful access to personal data and to ensure the preservation of such data.

9.1. Technical measures: Access control and authorisation, encryption in the transmission and storage of data, identity verification via OTP, logging (recording) of system activity, regular backups and up-to-date security applications. In the multi-tenant structure, each Subscriber's data is kept separate from that of others.

9.2. Administrative measures: Confidentiality undertakings for employees, application of the principle of need-based and limited access, and regular awareness and training activities.

10Rights of the Data Subject (KVKK Art. 11)

Pursuant to Article 11 of the KVKK, you may exercise the following rights by applying to the data controller:

  • To learn whether your personal data is being processed,
  • To request information if your personal data has been processed,
  • To learn the purpose of processing your personal data and whether it is used in accordance with that purpose,
  • To know the third parties, domestic or abroad, to whom your personal data is transferred,
  • To request the correction of your personal data if it has been processed incompletely or inaccurately,
  • To request the deletion or destruction of your personal data within the framework of the conditions set out in the KVKK and the relevant legislation,
  • To request that the correction, deletion and destruction operations be notified to the third parties to whom your personal data has been transferred,
  • To object to a result arising against you through the analysis of your processed data exclusively by automated systems,
  • To request the compensation of damages if you suffer loss due to the unlawful processing of your personal data,
  • To withdraw, at any time, the explicit consent you have given, in the case of processing based on explicit consent.

11Method of Application

You may submit your requests relating to the rights enumerated in Section 10 by the following methods, pursuant to the Communiqué on the Procedures and Principles of Application to the Data Controller:

  • In writing, by means of a wet-signed petition, to the address Fatih Mah. 3302 Sk. Seyitoğlu Yapı-6 No: 16 A, Merkez / Batman,
  • By e-mail to info@fabik.com.tr.

11.1. Your application must include your name and surname; your signature if the application is in writing; your Republic of Türkiye identity number (passport number for foreigners); your address for service of notice; your e-mail, telephone and fax details, if any; and the subject matter of your request.

11.2. Fabik will conclude your application free of charge as soon as possible and in any event within 30 (thirty) days at the latest, depending on the nature of the request. Where the operation additionally entails a cost, the fee set out in the tariff determined by the Board may be charged.

11.3. If your application is rejected or you find the response given to be insufficient, you have the right to lodge a complaint with the Personal Data Protection Board within 30 (thirty) days from the date you learn of the response; or, where no response at all is given to your application within 30 days, within 30 (thirty) days from the date that period expires; and, in both cases, in any event within 60 (sixty) days from the date of application.

12Cookie Policy

Cookies and similar technologies are used in the Fabik web and mobile applications for the purposes of providing the service and improving the experience. Since the Fabik session operates predominantly on a token-based basis, the use of cookies is kept limited. In the mobile application, software development kits (SDKs) and device identifiers may be used in addition to cookies.

12.1. Mandatory (session / security) cookies: Necessary for maintaining the session, identity verification and security; since these cookies are mandatory for the operation of the service, they do not require explicit consent.

12.2. Functional cookies: Provide ease of use by remembering your preferences.

12.3. Analytical cookies: Used to generate aggregated statistics for the purpose of understanding how the application is used and improving its performance.

12.4. Cookies requiring explicit consent: Non-mandatory analytical and marketing cookies are run only where your consent is present.

12.5. Technologies that may give rise to cross-border transfer: Third-party technologies used in analytics and in the map and notification features (for example, Google) may lead to cross-border data transfers; such transfers are subject to the principles set out in Section 7.2.

12.6. Management of cookies: You may delete or block cookies through your browser settings, or arrange to be warned before a new cookie is placed; in the mobile application, you may manage the relevant identifiers through your device and application permission settings. If mandatory cookies are disabled, some parts of the service may not function properly.

13Data Controller / Data Processor Relationship

With respect to the data that the Subscriber (Buyer) enters into the Fabik platform and which relates to its own commercial activity (for example, personal data belonging to the Subscriber's customers, employees and orders), the Subscriber is the data controller. In respect of such data, Fabik acts as a data processor operating in accordance with the Subscriber's instructions and within the framework of the contract. This arrangement is based on the same principle as the relationship governed by Article 13 of the Distance Sales Agreement. Within this scope, the Subscriber accepts that the obligation to inform its own data subjects and to secure the necessary legal ground (explicit consent where required) rests with the Subscriber.

14Amendments and Entry into Force

14.1. Fabik reserves the right to amend this Information Notice in line with legislative changes and updates to its services and processes. The current text is always published on this page.

14.2. The updated version of the text enters into force on the date it is published on this page and the update date specified. Your continued use of the service means that you have reviewed the text in force.


Related documents: Distance Sales Agreement · Delivery & Refund Policy · Privacy Policy