Privacy policy

PRIVACY POLICY

This clarification text has been prepared by WHİTEBİT TEKNOLOJİ ANONİM ŞİRKETİ (WhiteBIT), the data controller, in accordance with Article 10 of the Law on Protection of Personal Data No. 6698 and the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform.

Dear customers; Personal data is defined as any information related to an identified or identifiable real person, within the scope of the Law on Protection of Personal Data No. 6698 ("Law"), which came into force on 7 April, 2016. Protection of your personal data and informing you about your personal data is one of your fundamental rights under the Constitution of the Republic of Turkey. In this respect, ensuring the security and processing of your personal data is not only a matter of great importance and sensitivity for WhiteBIT but also an obligation. Your data is processed and protected by WhiteBIT in accordance with the Constitution of the Republic of Turkey and the Law.

According to Article 10 of the Law, data controllers are obliged to provide information to the data subjects regarding the identity of the data controller and if any, the identity of his/her representative, the purposes for which personal data will be processed, to whom and for what purposes personal data may be transferred, the method of collecting personal data, the legal basis for processing and other rights under Article 11 of the Law, during the collection of personal data. Therefore, this clarification text has been prepared by WHİTEBİT TEKNOLOJİ ANONİM ŞİRKETİ, which is a data controller within the scope of the Law, for the purpose of informing about personal data processing activities.

1- Data Controller Status

According to Article 3 of the Law, the data controller is defined as the real or legal person who determines the purposes and means of processing personal data, and who is responsible for the establishment and management of the data recording system. WhiteBIT is the data controller for the data related to our users.

2- Your Personal Data Processed by WhiteBIT and Collection Methods

Order Data Category Data Collection Method
1 Identity Data Name, Surname, Turkish ID Number, ID Document Number, Date of Birth, Place of Birth, ID Type, Information on the ID Document, Mother's Name, Father's Name, Nationality, ID Verification Status. All contracts/information forms and other documents, as well as the notifications you will make through applications, third-party service providers, and business partners, are collected entirely or partially by automated methods through written or electronic means, subject to the condition that they are collected through mobile applications.
2 Contact Information Mobile Phone Number, Email Address, Residential Address.
3 Financial Data IBAN, Bank Name, Balance Information, Digital Asset Information
4 Transaction Security Data Password, IP Address, Log Records, Login ID.
5 Professional Experience Data Occupational Information.
6 Customer Transaction Data Deposit Transactions, Withdrawal Transactions, Digital Asset Buying and Selling Transactions, Transaction Date, Transaction Amounts, Customer Number.
7 Audiovisual Recording Data Front and Back Image of ID Document, Selfie Photograph, Image of Residence or Subscription Invoice.
8 Legal Transaction Data Information in Correspondence with Judicial Authorities, Information in Court Case Files.

3- Purpose and Legal Basis of Processing Your Personal Data

The purposes and legal bases for processing your personal data by WhiteBIT are provided in the table below.

Legal Basis Personal Data Category Processing Purpose
Explicitly stipulated in the law (GDPR Art. 5/2-a) Identity Data, Communication Data, Financial Data, Transaction Security Data, Professional Experience Data, Customer Transaction Data, Audiovisual Recording Data, Legal Transaction Data Verification of customer identity for the provision of services, Completion of account registration processes, Compliance with legal and administrative measures, Conducting activities in compliance with legislation, Compliance with information retention, reporting, and disclosure obligations prescribed by all competent judicial and administrative authorities in accordance with legislation, ensuring the fulfillment of requests or decisions that may come from these authorities, Reporting to the relevant authorities for the purpose of investigating, detecting, and preventing violations of the law, Verification of the identity of the person performing the transaction, Making deposits to customer accounts, making withdrawals from customer accounts, tracking digital assets in customer accounts, Protection of customer accounts and archives, prevention of unauthorized access to customer accounts, Pursuing and resolving current and future legal disputes, Tracking and resolving requests and complaints, Conducting storage and archive activities, Preparing information and documents that will form the basis for transactions, Fulfilling obligations under Law No. 5549 and related legislation, ensuring our legitimate interests such as preventing fraud and crime, Conducting financial and accounting operations.
Processing of personal data belonging to the parties of the contract is necessary, provided that it is directly related to the establishment or performance of a contract (GDPR Art. 5/2-c) Identity Data, Communication Data, Financial Data, Transaction Security Data, Professional Experience Data, Customer Transaction Data, Audiovisual Recording Data, Legal Transaction Data Verification of customer identity for the provision of services, Completion of account registration processes, Compliance with legal and administrative measures, Conducting activities in compliance with legislation, Compliance with the obligation to store, report, and inform information as stipulated by all authorized judicial and administrative authorities in accordance with the legislation, ensuring the fulfillment of requests or decisions from these authorities, Verifying the identity of the customer performing the transaction, Making deposits to customer accounts, making withdrawals from customer accounts, monitoring digital assets in customer accounts, Protection and preservation of customer accounts and archives, prevention of unauthorized access to customer accounts, Tracking and resolving current and potential legal disputes, Monitoring and resolving customer requests and complaints, Carrying out storage and archive activities, Preparation of information and documents to be used as a basis for transactions and processes, Compliance with obligations under Law No. 5549 and related legislation, ensuring the fulfillment of legitimate interests such as prevention of fraud and crimes, Conducting financial and accounting operations.
Being mandatory for fulfilling the legal obligation of the data controller (GDPR Art. 5/2-c) Identity Data, Communication Data, Financial Data, Transaction Security Data, Professional Experience Data, Customer Transaction Data, Audiovisual Recording Data, Legal Transaction Data Compliance with legal and administrative measures, Conducting activities in compliance with the legislation, Compliance with information retention, reporting and disclosure obligations prescribed by all competent judicial and administrative authorities in accordance with the legislation, ensuring compliance with requests or decisions that may come from these authorities, Reporting any violations of the law to the competent authorities for the purpose of investigation, detection and prevention, Depositing funds into customer accounts, withdrawing funds from customer accounts, and tracking digital assets in customer accounts, Tracking and resolution of existing and potential legal disputes, Tracking and resolving requests and complaints, Activities related to storage and archiving, Preparation of information and documents to support the transactions and processes to be carried out, Compliance with obligations under the Law No. 5549 and related legislation, and ensuring the realization of legitimate interests such as prevention of fraud and crimes, Execution of financial and accounting operations.
Being necessary for the legitimate interests of the data controller (GDPR Art. 5/2-f) Identity Data, Communication Data, Financial Data, Transaction Security Data, Professional Experience Data, Customer Transaction Data, Audiovisual Recording Data, Legal Transaction Data Protecting customer accounts and archives, preventing unauthorized access to customer accounts, Follow-up and resolution of current and future legal disputes, Follow-up and resolution of requests and complaints, The performance of storage and archiving activities, Preparation of information and documents that will serve as the basis for transactions and processes, Investigating, identifying, and preventing illegal acts in accordance with the law and reporting them to the relevant authorities, Providing services within this scope, verifying the customer's identity, Carrying out account registration procedures, Complying with legal and administrative measures, Conducting activities in accordance with the legislation, Compliance with the obligation to store, report, and inform the information required by all authorized judicial and administrative authorities in accordance with the legislation, and ensuring the fulfillment of requests or decisions from these authorities. Execution of storage and archive activities, Preparation of information and documents that will serve as a basis for the transactions to be carried out. Ensuring compliance with the obligations under Law No. 5549 and related legislation, as well as fulfilling legitimate interests such as preventing fraud and crime. Protecting customer accounts and archives and preventing unauthorized access to customer accounts, Pursuing and resolving current and future legal disputes, Tracking and resolving requests and complaints, Conducting storage and archive activities, Preparing information and documents that will serve as a basis for transactions to be carried out. Fulfilling obligations under Law No. 5549 and related legislation, fulfilling legitimate interests such as preventing fraud and crime. Conducting activities in compliance with the legislation, Complying with information storage, reporting, and notification obligations as prescribed by all competent judicial and administrative authorities in accordance with the legislation and ensuring compliance with requests or decisions from these authorities. Reporting any violations of the law to the relevant authorities for investigation, detection, and prevention purposes, Verifying the identity of the customer who is carrying out the transaction, Making deposits to customer accounts and withdrawals from customer accounts, Protecting customer accounts and archives and preventing unauthorized access to customer accounts, Pursuing and resolving current and future legal disputes, Tracking and resolving requests and complaints, Conducting storage and archive activities, Preparing information and documents that will serve as a basis for transactions to be carried out. Fulfilling obligations under Law No. 5549 and related legislation, fulfilling legitimate interests such as preventing fraud and crime. Conducting activities in compliance with the legislation, Complying with information storage, reporting, and notification obligations as prescribed by all competent judicial and administrative authorities in accordance with the legislation and ensuring compliance with requests or decisions from these authorities. Reporting any violations of the law to the relevant authorities for investigation, detection, and prevention purposes, Pursuing and resolving current and future legal disputes. Evaluating and resolving requests and complaints from a legal perspective, Conducting storage and archive activities, Pursuing and conducting legal affairs. Sending informational/marketing messages via SMS, Sending informational/marketing messages via email.

4- Personal Data Transfer

Your personal data in WhiteBIT is stored safely and is not transferred to third parties except in the following cases.

Legal Basis Personal Data Category Purpose of Transfer Recipient
Explicitly prescribed by the laws (Article 5/2-a of KVKK) Identity Information, Contact Information, Legal Transaction Information, Visual and Audio Recording Information, Financial Information, Transaction Security Information, Customer Transaction Information Providing information to authorized individuals, institutions, and organizations, and ensuring the fulfillment of requests or decisions that may come from these authorities. To persons, institutions, or organizations who are authorized by the laws and regulations, and to any kind of public legal entities and authorities that have the authority to receive personal data as required or allowed by the laws and regulations.
Necessary for the performance or establishment of a contract, provided that it is directly related to the parties of the contract (Article 5/2-c of KVKK) Identity Information, Contact Information, Legal Transaction Information, Visual and Audio Recording Information, Financial Information, Transaction Security Information, Customer Transaction Information Processing personal data belonging to the parties of a contract, necessary for the establishment or performance of the contract (Article 5/2-c of the Law on Protection of Personal Data - KVKK). To third parties within the country from whom support and consultancy is obtained in tax, legal and similar areas for conducting our activities, banks, funds, and domestic institutions from whom independent audit and support services are obtained for conducting our activities.
Fulfillment of the legal obligations of the data controller (Article 5/2-ç of KVKK) Identity Information, Contact Information, Legal Transaction Information, Visual and Audio Recording Information, Financial Information, Transaction Security Information, Customer Transaction Information Processing personal data necessary for the data controller to fulfill their legal obligations (Article 5/2-c of the Turkish Personal Data Protection Law - KVKK). Legal affairs management and execution, evaluation of requests and complaints from a legal perspective, fulfillment of legal obligations, execution of financial, accounting, operational and process-related tasks, ensuring business continuity, conducting audit activities, managing information security processes, and conducting business activities/audits.
Explicit Consent (Article 5/1 of the Law on Protection of Personal Data) Identity Information (Name, Surname), Contact Information (Mobile Phone Number, Email Address) Execution of advertising, campaign and promotion processes. The message has been sent to Yönetim Sistemi Anonim Şirketi (İYS-https://iys.org.tr/).

5- Storage and Disposal of Personal Data

WhiteBIT agrees to take all necessary technical and administrative measures to prevent unauthorized access, incorrect processing, disclosure, alteration or deletion of your personal data, to ensure its protection and security for the purpose of protecting against all unlawful reasons. In case of any attack on the archive and/or servers and/or other systems with your personal data processed by WhiteBIT, and as a result, your personal data is damaged and/or captured/disclosed by third parties, WhiteBIT will inform the relevant persons and the Personal Data Protection Board within 72 hours after becoming aware of such violation.

Your personal data will be stored for the statutory periods prescribed by the legislation starting from the termination of the contract you have signed. In cases where there is no contractual relationship between you and WhiteBIT, your personal data will be stored for a reasonable period required by the purpose of processing. If there are statutory retention periods regarding the storage of your personal data within the scope of the relevant processing process, your data cannot be deleted during the period specified by the relevant regulations.

At the end of the periods specified above, or at the end of the period prescribed by the relevant legislation or required for the purpose of processing, or if the deletion requests of the relevant person result in a positive outcome, your personal data will be deleted, destroyed or anonymized in accordance with the WhiteBIT Personal Data Protection and Confidentiality Procedure and Personal Data Storage and Destruction Procedures in compliance with the legislation for the protection of personal data.

6- Protection, Storage and Destruction of Your Personal Data

You have the following rights under Article 11 of the Law to apply to WhiteBIT and access information about you:

  • The right to learn whether personal data is being processed,
  • The right to request information if personal data has been processed,
  • The right to learn the purpose of processing personal data and whether they are being used for,
  • You have the right to know the third parties to whom your personal data is transferred domestically or abroad,
  • You have the right to request the correction of your personal data if it is incomplete or inaccurate,
  • You also have the right to request the deletion or destruction of your personal data within the framework of the conditions set forth in Article 7 of the Law,
  • You have the right to request that the operations carried out in accordance with subparagraphs (v) and (vi) be notified to the third parties to whom your personal data have been transferred,
  • You have the right to object to a decision that is made against you based solely on the analysis of your personal data through automated systems,
  • Requesting compensation for damages in case of suffering damage due to the processing of personal data in violation of the law.

7- Submitting Requests to the Data Controller

If you wish to make requests regarding your rights as outlined in Article 11 of the Law, please direct your requests to the Data Controller. You can do so through the following methods:

  • In-Person Submission: You may personally submit your request, along with your identity verification, at the WhiteBIT physical address provided below.
  • Electronic Submission: You can electronically submit your request using a secure electronic signature, mobile signature, or using your registration email address by sending an email to support@whitebit-tr.com.

To ensure the processing of your request, please include the following information in your email:

  • Your full name and surname;
  • Date and signature;
  • If you are a Turkish citizen, your 11-digit national ID number (Turkish ID Number);
  • If you are not a Turkish citizen, please provide your residence permit and identification number;
  • Your residential or business address for notification purposes;
  • Your email address and phone number, if available, for notification purposes;
  • The subject of your request, along with all necessary supporting documents and data.*

*It is essential that you clearly state the subject of your request and attach any relevant information and documents in a legible manner.

Your requests will be processed following identity verification by WhiteBIT, and you will receive a written or electronic response within a maximum period of 30 days. Please be aware that, in the case of written applications, the date