Business Privacy Notice
Version 1.0
Business Privacy Notice
Data Controller: xBarkod Teknoloji A.Ş. ("xBarkod")
In accordance with the Personal Data Protection Law No. 6698 ("KVKK"), we inform you about the processing of personal data belonging to company representatives and users.
This is a notice, not an agreement; it is not submitted for your approval.
1. Personal Data Processed
- Identity Information: Name, surname, national ID number (company representative)
- Contact Information: Phone number, email address, business address
- Company Information: Tax number, trade registry number, company name
- Transaction Security: IP address, device information, session data, panel activity records
- Payment Information: Credit/debit card details (processed via 3D Secure, card data is not stored)
2. Purposes of Processing
- Providing product verification and anti-counterfeiting services
- Creating and managing barcodes, QR codes, and GS1 DataMatrix
- Company account and user authorisation management
- License and subscription management, billing
- SMS identity verification (OTP)
- Providing customer support services
- Fulfilling legal obligations
- Generating product tracking and statistical reports
3. Data Transfers
- SMS service provider (Netgsm — OTP verification)
- Payment infrastructure (Kuveyt Türk — 3D Secure payments)
- Cloud infrastructure providers (Heroku, AWS — data storage)
- Authorized public institutions (when legally required)
4. Legal Grounds
Your data is processed under Article 5/2 of KVKK: performance of a contract, compliance with legal obligations, and legitimate interests (service security, fraud prevention). Commercial electronic messages are sent only with your separate consent, which you may withdraw at any time.
5. Storage and Security
- Server location: Europe (EU) region — Heroku platform
- Database: MySQL with encrypted connection (SSL/TLS)
- Encryption: Sensitive data (passwords) stored as bcrypt hashes
- Payment data: Card information is NOT stored by xBarkod
- Retention: Active account duration + legal obligation periods (5 years for commercial records)
- HTTPS (TLS 1.2+), JWT-based authentication, rate limiting, brute force protection, access logs and anomaly detection
6. Cookies
Our web panel uses strictly necessary cookies (session management, CSRF protection) and preference cookies (language, theme). No analytics or advertising cookies are used.
7. Your Rights
Under Article 11 of KVKK, you have the right to learn whether your data is processed, request information and correction, request deletion, object to automated decisions, and claim compensation for unlawful processing.
8. Contact
To exercise your rights, please submit a written request to kvkk@xbarkod.com. Your request will be resolved within 30 days at the latest.
9. Changes
We reserve the right to update this notice. The current version is published in the panel and at xbarkod.com.