İçeriğe geç

Confidentialité Et Politique

DigiPestControl — Global Privacy, Personal Data Protection, and Security Policy
DIGIPESTCONTROL

Global Privacy, Personal Data Protection, and Security Policy

This Policy explains how personal data is collected, used, processed, shared, protected, and the statutory rights available to data subjects within the scope of the DigiPestControl website, web application, mobile applications, SaaS platform, user panels, APIs, support services, and associated digital services.

Nature of the Policy

This Policy has been prepared to provide transparency regarding DigiPestControl's personal data processing activities. The presentation, accessibility, or review of this Policy does not, on its own, constitute the granting of explicit consent for personal data processing activities that legally require explicit consent.

Where explicit consent is required for specific processing operations, data subjects are provided with a separate, distinct, and freely given opt-in mechanism.

Detailed disclosures concerning cookies and tracking technologies are set forth in the separate DigiPestControl Cookie Policy published alongside this Policy.

Policy Title DigiPestControl Global Privacy, Personal Data Protection, and Security Policy
Version V. 2.0
Publication Date 18.08.2026
Effective Date 18.08.2026
Data Protection Contact info@digipestcontrol.com

ARTICLE 1 – Purpose, Scope, and Applicability

1.1. Purpose of the Policy

This Global Privacy, Personal Data Protection, and Security Policy (“Policy”) has been prepared to inform data subjects and explain our data protection governance regarding personal data processing activities carried out by Seçkiner Teknoloji ve Kimya San. ve Tic. A.Ş. under the DigiPestControl brand within the scope of its digital services.

This Policy explains the categories of personal data processed, collection channels and sources, lawful processing purposes and legal bases, recipient categories, cross-border and international data transfers, data retention and disposal practices, information security measures, and the statutory rights of data subjects arising under applicable legislation.

1.2. Services Covered by the Policy

This Policy covers the following DigiPestControl services and communication channels to the extent applicable:

  • the DigiPestControl website and associated web pages;
  • the DigiPestControl cloud-based SaaS web application;
  • DigiPestControl native mobile applications;
  • customer, technician, and administrative management panels;
  • APIs and third-party system integrations;
  • account onboarding and subscription management processes;
  • demo, quote, and product inquiry requests;
  • technical support, training, and customer assistance channels;
  • corporate email and digital communication channels;
  • other online services associated with DigiPestControl.

1.3. Individuals Covered by the Policy

This Policy applies to the following natural persons depending on the nature of the processing activity:

  • website and digital tool visitors;
  • users creating a DigiPestControl account;
  • authorized representatives and executives of customer firms;
  • customer employees, managers, and field technicians;
  • prospective customers and individuals requesting product demos;
  • individuals submitting support tickets or contact inquiries;
  • natural person representatives of suppliers and business partners;
  • natural persons whose personal data is uploaded into the platform by Customers where DigiPestControl acts as Data Processor;
  • natural persons interacting with DigiPestControl through other lawful means.

1.4. Applicable Data Protection Legislation

Our personal data processing activities are conducted in strict compliance with the Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”), secondary regulations, and decisions of the Personal Data Protection Board, as well as the European Union General Data Protection Regulation (“GDPR”), the UK GDPR, and other applicable national or regional data protection laws depending on the geographical context of processing.

Where mandatory data protection legislation in a particular country or jurisdiction provides a higher or more specific standard of protection than this Policy, the provisions of such mandatory local law shall remain reserved and prevail.

ARTICLE 2 – Identity of Data Controller and Data Protection Roles

Data Controller / Service Provider

Commercial Title: Seçkiner Teknoloji ve Kimya San. ve Tic. A.Ş.

Brand: DigiPestControl

Headquarters Address: Adalet Mah. Anadolu Cad. No:41 Megapol Tower 081 BAYRAKLI / İZMİR / Türkiye

Tax Office: Karşıyaka

Tax ID: [TAX NUMBER]

MERSIS No: [MERSIS NUMBER]

General Contact: info@digipestcontrol.com

Data Protection Contact: info@digipestcontrol.com

2.1. Circumstances Where DigiPestControl Acts as Data Controller

Seçkiner Teknoloji ve Kimya San. ve Tic. A.Ş. acts as an independent Data Controller where it determines the purposes and essential means of personal data processing activities.

Processing activities within this scope specifically include:

  • managing website and digital service visitors;
  • user account registration, credential management, and authentication;
  • customer relationship and subscription lifecycle management;
  • invoicing, payment collection, and accounting records;
  • handling customer support, demo requests, and corporate inquiries;
  • maintaining platform information security and infrastructure integrity;
  • preventing fraud, abuse, and security violations;
  • fulfilling statutory tax, commercial, and regulatory obligations;
  • maintaining contract execution and electronic acceptance records;
  • conducting marketing and commercial electronic communications where valid legal consent has been obtained.

2.2. Circumstances Where DigiPestControl Acts as Data Processor

During the use of the DigiPestControl SaaS platform, where the Customer determines the purposes and means of processing personal data uploaded, stored, or processed for its own business operations (such as end-client information, facility layouts, technician field logs, bait station coordinates, and pest records), the Customer acts as Data Controller and DigiPestControl acts as Data Processor on behalf of the Customer.

In this context, DigiPestControl processes personal data strictly in accordance with applicable data protection laws, the DigiPestControl SaaS Service and License Agreement, the relevant Data Processing Agreement (“DPA”), and the Customer's documented lawful instructions.

The Customer remains exclusively responsible for fulfilling its controller obligations towards its own clients, employees, technicians, and other relevant data subjects.

Important: DigiPestControl may hold different data protection roles with respect to different processing activities involving the same individual. For example, while processing field service records of a customer's employee as a Data Processor on behalf of the customer, it may independently process that same employee's login credentials, account security logs, and subscription communications as an independent Data Controller.

ARTICLE 3 – Core Definitions

3.1. Personal Data: Refers to any information relating to an identified or identifiable natural person.

3.2. Data Subject: Refers to the natural person whose personal data is processed.

3.3. Data Controller / Controller: Refers to the natural or legal person who determines the purposes and means of processing personal data.

3.4. Data Processor / Processor: Refers to the natural or legal person who processes personal data on behalf of and under the instructions of the Data Controller.

3.5. Sub-processor: Refers to any third-party service provider engaged by DigiPestControl to carry out specific processing functions on behalf of the Customer.

3.6. Processing: Refers to any operation performed upon personal data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, destruction, or anonymization.

3.7. Customer Data: Refers to all data entered, uploaded, transmitted, or generated through the Software by the Customer or its authorized Users as defined in the SaaS Service and License Agreement.

3.8. Personal Data Breach: Refers to a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.

ARTICLE 4 – Categories of Processed Personal Data

The personal data processed by DigiPestControl varies depending on the nature of the data subject's relationship with DigiPestControl, the services utilized, and the specific modules enabled. Not all categories below are processed for every individual.

4.1. Identity Information

  • first name;
  • last name;
  • user ID or account username;
  • authorized representative identification details.

4.2. Contact Information

  • email address;
  • telephone number;
  • corporate contact details;
  • work or billing address.

4.3. Corporate and Professional Information

  • company or institution name;
  • job title, role, and department;
  • organizational unit details;
  • user role within the platform;
  • authorization levels and access permission profiles.

4.4. Account and Subscription Information

  • account registration metadata;
  • subscription plan, tier, and status;
  • user-organization hierarchy links;
  • electronic agreement acceptance logs and timestamps;
  • account preferences and settings;
  • subscription lifecycle and account transaction histories.

4.5. Billing and Transaction Information

  • billing address and tax registration details;
  • payment status and history;
  • subscription order and package details;
  • transaction, invoice, and collection records;
  • accounting and commercial transaction records required by statutory law.
Payment Card Information:
Credit card transactions are processed directly through licensed, PCI-DSS certified payment service providers (e.g., Iyzico). DigiPestControl does not store full credit card numbers, CVV security codes, or card PINs on its own servers.

4.6. Technical and Security Data

  • IP addresses;
  • device type, operating system, and browser user-agent;
  • session tokens, cookies, and authentication logs;
  • login timestamps and account security event logs;
  • diagnostic error traces and system integrity logs.

4.7. Usage and Interaction Data

  • features, screens, and modules accessed;
  • user interface interaction and navigation statistics;
  • performance metrics and page load statistics;
  • aggregate analytics regarding service utilization.

4.8. Communication and Support Data

  • support ticket contents and email correspondence;
  • demo request forms and feedback submissions;
  • customer service chat logs and technical inquiry details;
  • communication preferences and marketing consent records.

4.9. Operational Data Processed on Behalf of Customers (As Data Processor)

Where the Customer utilizes the SaaS platform for its pest management operations, the following data may be processed on its behalf:

  • customer facility names, addresses, and site contact persons;
  • technician visit schedules, inspection findings, and service logs;
  • bait station, trap, and sensor location coordinates;
  • biocidal product, active ingredient, and dosage application records;
  • technician and client digital signatures;
  • facility inspection photographs and site blueprints;
  • pest trend analytics, heatmaps, and audit compliance reports;
  • IoT sensor telemetry and trap capture notifications.

4.10. Special Categories of Personal Data

DigiPestControl is a B2B pest control operations management software and is not designed for the systematic processing of special category (sensitive) personal data (such as health, biometric, genetic, philosophical, or criminal conviction data).

Where special category personal data is processed, the Customer is strictly required to ensure a valid legal processing basis and implement heightened technical safeguards.

ARTICLE 5 – Methods and Sources of Personal Data Collection

Personal data is collected through automated, semi-automated, or manual methods via electronic and digital channels, depending on the nature of the interaction:

5.1. Data Obtained Directly from Data Subjects

  • information entered during website registration, demo requests, or calculator forms;
  • profile and account information submitted by users;
  • messages and inquiries sent to our support email or ticketing system.

5.2. Data Obtained from Customers and Authorized Users

  • employee and technician profiles created by customer administrators;
  • client contact details and facility records entered by customer staff;
  • field inspection reports and signatures uploaded via the mobile app.

5.3. Automatically Collected Technical Data

  • web server logs, IP addresses, and request headers;
  • device identifiers, operating system details, and browser specifications;
  • system diagnostic and performance monitoring logs.

5.4. Cookies and Tracking Technologies

Session and security cookies necessary for website functionality and authentication are used in accordance with our Cookie Policy.

5.5. Data Obtained from Integrations and Third-Party Providers

  • payment status tokens received from licensed payment gateways;
  • SMS and push notification delivery status receipts;
  • geocoding and mapping coordinates from licensed map service providers.

ARTICLE 6 – Purposes of Processing Personal Data

Personal data is processed strictly for legitimate, explicit, and specified operational and legal purposes, including:

6.1. Provision of Services

Operating the DigiPestControl SaaS platform, delivering core features, managing user roles, generating pest inspection reports, and executing automated PDF/Excel/.sql exports.

6.2. Customer and Subscription Management

Managing corporate customer accounts, subscription renewals, user licensing limits, and administrative communications.

6.3. Invoicing and Financial Operations

Issuing electronic invoices, tracking subscription fees, processing payments, and fulfilling tax accounting requirements.

6.4. Support and Customer Care

Resolving technical support tickets, answering inquiries, providing onboarding assistance, and maintaining service quality.

6.5. Information and Infrastructure Security

Authenticating users, preventing brute-force and credential abuse attacks, securing APIs, mitigating vulnerabilities, and maintaining system audit trails.

6.6. Quality Assurance, Analytics, and Product Development

Diagnosing software bugs, analyzing aggregate usage patterns, optimizing performance, and developing new features.

6.7. Legal and Regulatory Compliance

Complying with commercial, financial, and data protection laws, and responding to lawful requests from judicial or administrative authorities.

6.8. Establishment, Exercise, and Defense of Legal Claims

Preserving transaction records, acceptance timestamps, and logs for potential dispute resolution.

6.9. Marketing and Commercial Communications

Delivering product updates, newsletters, and promotional announcements solely where prior explicit opt-in consent has been granted.

ARTICLE 7 – Legal Bases for Processing Personal Data

7.1. Legal Grounds under KVKK (Law No. 6698, Art. 5)

  • Art. 5/2(c): Processing is necessary for the conclusion or performance of a contract.
  • Art. 5/2(ç): Processing is mandatory for the controller to fulfill its legal obligations.
  • Art. 5/2(e): Processing is mandatory for the establishment, exercise, or protection of a right.
  • Art. 5/2(f): Processing is mandatory for the legitimate interests of the controller, provided it does not harm the fundamental rights and freedoms of the data subject.
  • Art. 5/1: Explicit consent where legally mandated.

7.2. Legal Grounds under GDPR and UK GDPR (Art. 6)

  • Art. 6(1)(b): Performance of a contract to which the data subject is party.
  • Art. 6(1)(c): Compliance with a legal obligation to which the controller is subject.
  • Art. 6(1)(f): Legitimate interests pursued by the controller (e.g., cybersecurity, fraud prevention, infrastructure maintenance).
  • Art. 6(1)(a): Freely given, specific, informed consent where applicable.

7.3. Activity-to-Legal Basis Mapping

Processing Activity Primary Legal Basis (KVKK) Primary Legal Basis (GDPR / UK GDPR)
Account Creation & SaaS Service Delivery Performance of Contract (Art. 5/2-c) Performance of Contract (Art. 6/1-b)
Billing, Tax & Financial Accounting Legal Obligation (Art. 5/2-ç) Legal Obligation (Art. 6/1-c)
System Security, Logs & Abuse Prevention Legitimate Interest (Art. 5/2-f) Legitimate Interest (Art. 6/1-f)
Customer Support & Ticketing Performance of Contract (Art. 5/2-c) Performance of Contract (Art. 6/1-b)
Commercial Marketing Communications Explicit Consent (Art. 5/1) Consent (Art. 6/1-a)

7.4. Special Categories of Personal Data

Any processing of sensitive data strictly requires explicit consent under KVKK Art. 6 or GDPR Art. 9, or a direct statutory exception.

ARTICLE 8 – Data Transfers and Recipient Categories

Personal data is disclosed only on a strict need-to-know basis to the following recipient categories:

8.1. Infrastructure and Technology Service Providers

Cloud hosting providers, data center operators, email delivery gateways, SMS services, and technical monitoring tools bound by contractual confidentiality.

8.2. Payment and Financial Institutions

Licensed payment service providers and banks for billing and payment processing.

8.3. Professional Advisors

Independent certified public accountants, legal counsel, and cybersecurity auditors under statutory or contractual professional secrecy obligations.

8.4. Public Authorities and Judicial Bodies

Courts, law enforcement, and regulatory bodies where legally mandated upon receipt of a valid, binding official order.

8.5. Corporate Transactions

In the event of a merger, acquisition, restructuring, or asset sale, subject to ongoing confidentiality and data protection safeguards.

ARTICLE 9 – International and Cross-Border Personal Data Transfers

9.1. Cross-Border Transfers under KVKK

International transfers subject to KVKK are conducted pursuant to Article 9, relying upon adequacy decisions, official Standard Contracts published by the Personal Data Protection Board, binding corporate rules, or statutory exceptions.

9.2. International Transfers under GDPR

Transfers from the EEA to third countries are governed by European Commission Adequacy Decisions or the European Commission Standard Contractual Clauses (EU SCCs) along with supplementary technical and organizational measures.

9.3. Transfers under UK GDPR

Transfers from the UK utilize the UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs.

9.4. Transfers as Data Processor

Where acting as Data Processor, transfers are executed strictly under the Customer's documented authorization and relevant Data Processing Agreement.

9.5. Sub-processors and Hosting Regions

The active regions and providers utilized for infrastructure hosting are listed in the Sub-processor documentation.

ARTICLE 10 – Personal Data Retention and Determining Retention Periods

10.1. Retention Criteria

Personal data is retained only for as long as necessary to fulfill the operational purposes for which it was collected, enforce agreements, or satisfy statutory tax, accounting, and commercial retention periods.

10.2. Retention Periods by Category

  • Customer Account Data: Retained throughout active subscription plus statutory limitation periods.
  • Invoicing & Tax Records: Retained for 10 years in compliance with the Turkish Tax Procedure Law and Commercial Code.
  • Access & Security Logs: Retained for minimum statutory periods (e.g., 2 years under Law No. 5651) up to operational security needs.
  • Support & Correspondence: Retained during the active customer relationship and relevant legal limitation periods.

10.3. 7-Business-Day Post-Termination Transition Period

Following subscription termination, a 7 (seven) business days export transition period is provided to allow the Customer to retrieve its data (.sql, Excel, PDF), after which active production data is deleted.

10.4. Prohibition of Indefinite Retention

Personal data is never retained indefinitely once processing grounds and statutory limitation periods have expired.

ARTICLE 11 – Deletion, Destruction, and Anonymization of Personal Data

11.1. Deletion

Rendering personal data inaccessible and unrecoverable for the relevant users.

11.2. Destruction

Physical or technological purging of storage media preventing any possible recovery.

11.3. Anonymization

Irreversibly altering data so that it can no longer be associated with an identified or identifiable natural person, even when combined with other data.

11.4. Residual Copies in Technical Backups

Deleted data in disaster recovery backups is overwritten during standard backup lifecycle rotations and cannot be selectively restored.

11.5. User-Deleted Data

Data deleted by the Customer during active subscription terms is purged immediately from active databases.

ARTICLE 12 – Rights of Data Subjects under KVKK

Pursuant to Article 11 of the KVKK, data subjects have the right to:

  • learn whether their personal data is processed;
  • request information if their personal data has been processed;
  • learn the purpose of the processing and whether data is used in accordance with that purpose;
  • know the third parties to whom personal data is transferred domestically or abroad;
  • request rectification of incomplete or inaccurate personal data;
  • request erasure or destruction of personal data pursuant to statutory conditions;
  • request notification of rectification or erasure to third parties to whom data was transferred;
  • object to the occurrence of a result against them through automated decision systems;
  • claim compensation for damages suffered due to unlawful processing.

12.1. Statutory Limits on Rights

Statutory exceptions under Article 28 of the KVKK remain reserved.

ARTICLE 13 – Rights of Data Subjects under GDPR and UK GDPR

Data subjects within the EEA and the United Kingdom possess the following rights:

13.1. Right of Access (Art. 15)

Obtain confirmation as to whether personal data is being processed and receive a copy.

13.2. Right to Rectification (Art. 16)

Request correction of inaccurate data or completion of incomplete data.

13.3. Right to Erasure / Right to be Forgotten (Art. 17)

Request deletion of personal data where legal retention grounds have ceased.

13.4. Right to Restriction of Processing (Art. 18)

Request restriction of processing under statutory circumstances.

13.5. Right to Data Portability (Art. 20)

Receive personal data in a structured, commonly used, machine-readable format.

13.6. Right to Object (Art. 21)

Object at any time to processing based on legitimate interests or direct marketing.

13.7. Right to Withdraw Consent (Art. 7/3)

Withdraw previously granted consent at any time without affecting prior lawful processing.

13.8. Automated Decision-Making and Profiling (Art. 22)

Right not to be subject to a decision based solely on automated processing producing legal effects.

13.9. Right to Lodge a Complaint

Right to lodge a complaint with the competent European Data Protection Authority or the UK Information Commissioner's Office (ICO).

ARTICLE 14 – California and Other Regional Privacy Rights

14.1. California CCPA / CPRA Rights

California residents have the right to know what personal information is collected, request deletion, and request correction.

14.2. Prohibition of Sale and Sharing of Personal Data

DigiPestControl does NOT sell or share personal information for monetary or other valuable consideration.

14.3. Other Regional Rights

Statutory privacy rights under other applicable state or international frameworks are fully respected.

ARTICLE 15 – Data Subject Requests and Exercise of Rights

15.1. Application Channels

Written applications can be submitted to info@digipestcontrol.com or our headquarters address.

15.2. Required Application Details

Applications must include full name, contact information, identity verification details, and clear specification of the requested right.

15.3. Conclusion of KVKK Requests

KVKK requests are concluded free of charge as soon as possible and within 30 (thirty) days at the latest.

15.4. Conclusion of GDPR and UK GDPR Requests

GDPR requests are concluded within 1 (one) month, with an optional 2-month extension for complex requests.

15.5. UK Data Protection Inquiries

Inquiries under UK GDPR may be directed to our designated data protection contact.

15.6. Requests Involving Data Processor Contexts

Where DigiPestControl processes data as a Processor on behalf of a Customer, the applicant will be redirected to the relevant Customer Data Controller.

15.7. Manifestly Unfounded or Excessive Requests

A reasonable statutory administrative fee may be charged for manifestly unfounded or repetitive requests.

ARTICLE 16 – Confidentiality and Commercial Information Protection

16.1. Scope of Confidential Information

Customer operational data, client rosters, station layouts, and chemical formulations are protected as strictly confidential commercial information.

16.2. DigiPestControl Proprietary Information

Source codes, API architectures, trade secrets, and software designs are proprietary confidential property of DigiPestControl.

16.3. Access Restrictions

Access to confidential information is strictly limited to authorized personnel under active non-disclosure obligations.

16.4. Survival of Confidentiality

Confidentiality obligations survive the expiration or termination of customer subscriptions.

ARTICLE 17 – Information Security Approach

DigiPestControl applies a comprehensive, risk-based defense-in-depth security approach aligned with international standards (ISO/IEC 27001).

17.1. Security Objectives

  • Confidentiality: Preventing unauthorized access to personal and commercial data.
  • Integrity: Protecting data against unauthorized modification, corruption, or destruction.
  • Availability: Ensuring authorized users have uninterrupted access to critical operational data.

ARTICLE 18 – Technical Security Measures

18.1. Authentication and Access Control

Role-based access control (RBAC), multi-factor authentication (2FA), strong password hashing algorithms (bcrypt / Argon2), and tenant data isolation.

18.2. Transmission and Communication Security

Mandatory TLS 1.2+ encryption for all web and API traffic, HSTS enforcement, and CSRF token protection.

18.3. Data and System Security

Prepared SQL statements, XSS output filtering, secure .env configuration management, and server hardening.

18.4. Logging and Traceability

Centralized security event logs, administrative audit trails, and automated error diagnostics.

18.5. Backup and Business Continuity

Automated disaster recovery backups with offsite storage and periodic restoration testing.

ARTICLE 19 – Administrative and Organizational Security Measures

19.1. Governance and Responsibility

Information security policies and access controls governed by designated internal security officers.

19.2. Employee Confidentiality

Binding non-disclosure agreements and disciplinary policies for personnel handling personal data.

19.3. Security Awareness

Regular internal training on cybersecurity, phishing prevention, and data privacy compliance.

19.4. Data Minimization and Least Privilege

Access privileges granted strictly on a need-to-know basis and promptly revoked upon employee offboarding.

19.5. Policy Reviews

Periodic audits and updates of security procedures.

ARTICLE 20 – Secure Software Development, Updates, and Vulnerability Management

20.1. Secure SDLC

Software development follows Secure Software Development Lifecycle (SSDLC) principles, including peer code reviews and static security scanning.

20.2. Vulnerability Mitigation

Continuous dependency scanning, prompt patching of known CVEs, and infrastructure hardening.

20.3. Unauthorized Penetration Testing Prohibited

Unauthorized penetration testing, vulnerability scanning, or automated fuzzing against DigiPestControl production systems without prior written authorization is strictly prohibited.

ARTICLE 21 – Security Incidents and Personal Data Breach Management

21.1. Incident Assessment

Operating established procedures for immediate containment, forensic investigation, and risk analysis upon detecting any security anomaly.

21.2. Breaches Where DigiPestControl is Data Controller

Notifying the Turkish Personal Data Protection Authority (KVKK) and/or lead European Supervisory Authorities within statutory timeframes (e.g., within 72 hours where required).

21.3. Notification to Affected Data Subjects

Direct notification to affected individuals where a high risk to their rights and freedoms is identified.

21.4. Breaches Where DigiPestControl is Data Processor

Notifying affected Customer Data Controllers without undue delay upon verifying an incident impacting Customer Data.

21.5. Phased Information Sharing

Providing diagnostic updates progressively as forensic investigation proceeds.

ARTICLE 22 – Sub-processor and Vendor Security

22.1. Vendor Due Diligence

Evaluating third-party technical infrastructure providers against enterprise cybersecurity and data protection standards.

22.2. Contractual Data Protection Safeguards

Executing binding data processing agreements with Sub-processors imposing equivalent data protection duties.

22.3. Sub-processor List Management

Maintaining an up-to-date schedule of authorized Sub-processors.

22.4. International Sub-processors

Applying Standard Contractual Clauses or adequacy mechanisms for cross-border vendor engagements.

ARTICLE 23 – Children's Personal Data

DigiPestControl services are designed exclusively for B2B commercial, agricultural, and industrial pest management operations and are not directed to minors under the age of 18.

We do not knowingly collect, process, or solicit personal data from children.

ARTICLE 24 – Policy Updates and Version Management

24.1. Current Version

This Policy is published on our website and updated periodically to reflect legislative and technical developments.

24.2. Material Changes

Notifying registered account holders via email or in-app dashboard when material revisions occur.

24.3. Version History

Version Publication Date Effective Date Description
V. 2.0 18.08.2026 18.08.2026 Comprehensive revision of KVKK, GDPR, UK GDPR compliance, processing roles, international transfers, retention and disposal rules, data subject rights, security controls, and breach management.

Previous versions are archived to demonstrate compliance and the text in force at specific dates.

ARTICLE 25 – Contact Information

For any inquiries regarding this Policy or our privacy and information security practices, please contact us:

Data Controller / Service Provider

Commercial Title: Seçkiner Teknoloji ve Kimya San. ve Tic. A.Ş.

Brand: DigiPestControl

Address: Adalet Mah. Anadolu Cad. No:41 Megapol Tower 081 Bayraklı / İzmir / Türkiye

General Contact: info@digipestcontrol.com

Data Protection Contact: info@digipestcontrol.com

For submitting statutory data subject requests, please refer to the provisions of Article 15 – Data Subject Requests and Exercise of Rights.

DigiPestControl Privacy and Security Commitment

DigiPestControl is founded on the core principles of lawfulness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality in personal data processing. This Policy, together with the DigiPestControl SaaS Service and License Agreement and relevant data protection documentation, articulates our unified commitment to safeguarding personal data and information security.

HAUT