Warmhaus Privacy Policy
PRIVACY POLICY

Warmhaus is a company incorporated under the laws of Turkey, having its registered office in Istanbul, Turkey ("Warmhaus", "us" or "we"). We are pleased that you are visiting our webpage and thank you for your interest in our company.

Your privacy is of vital importantance to us. In our capacity as data controller, we intend to provide the users of our websites, our home appliances that connect to the Internet (respectively, “Webpages”) and any other individual interacting with us ("Users", "you" or "your"), with information concerning the methods used for collecting and processing personal data, in accordance, with the European General Data Protection Regulation no. 679/2016 ("Regulation") and any other applicable laws and regulations.

Our privacy policy is designed to help you understand the types of information that we collect, how we use and share the information and how the information is protected. This policy covers our use of information that can or could be used to identify you, but it does not cover information which cannot be used to identify you. This policy applies to all Nintendo services that directly reference or link to it, but does not apply to Nintendo services that link to separate privacy policies.

A. INTRODUCTION AND GENERAL INFORMATION

I. Contact Information of the data Controller

If you have any concerns about how we process your data, you can reach out to:
The controller within the meaning of Art. 4 (7) GDPR on behalf of Warmhaus

Website : https://www.warmhaus.com/en
Tel : +90 (216) 300 16 50
Address : Nidakule Ataşehir Kuzey Barbaros Mahallesi, Begonya Sokak No: 3, Kat:19 34746 Ataşehir/İstanbul/Türkiye
E-mail : info@warmhaus.com.tr

If you contact us by e-mail, communication is unencrypted.

II. What is Personal Data and Processing

In accordance with Art. 4 (1) GDPR, “personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”).
“Processing” means any action taken with your personal data (such as collection, recording, organisation, structuring, storage, use or erasure of data).

B. DATA PROCESSING AND PROTECTION

I. What Types of Data Are We Processing?
Personal data processed by Warmhaus differ in accordance with the nature of the legal relationship established with Warmhaus. These are in particular from:

• which we receive from customers, prospective customers, interested parties, service providers, suppliers, business partners or other persons involved in the business relationship in the course of our business relations;
• which we are legally or contractually obliged to collect;
• which we collect during the use of our website;
• which we receive from authorities and other third parties (address traders, credit agencies).
• from publicly available sources;
• from social media

You may choose not to provide certain types of personal data to us. If you choose to do so, this may affect our ability to provide you with, and your ability to make use of Warmhaus appliances. However, unless otherwise specified, your choice not to provide such information will not result in legal consequences for you.

Depending on the nature of the relationship, categories of personal data collected by Warmhaus through all channels, including Digital Environments (social media accounts operated, are as follows:

Identity Information: Personal data such as name, surname, identification number, that you have provided to us while creating accounts and entering into agreement for services offered by Warmhaus.

Contact Information: contact information (such as e-mail address), phone and mobile phone number, Addresses.

Contract Data: such as type of contract, content of contract, type of products and services, order data;

Process Security Information (information relating to application and website password etc. provided in the course of benefiting from products and services offered in digital environments)

Financial Information (bank account information, IBAN information, balance information, credit balance information and other financial information)

Legal Procedure and Compliance Information (information provided within information requests and decisions of judicial and administrative authorities, Agreements, Certificate of Signatures)

Customer Process Information (personal data recorded in channels such as call centers, credit card statements, installation and commissioning, customer instructions including purchase, cancellation, and other changes relating to an instruction or request attributable to a person)

Request/Complaint Management Information (such as information and records collected in relation with requests and complaints concerning our products or services)

Marketing Information (such as reports and evaluations containing information indicating preferences to the data subject and used for the purposes of marketing, targeting information, cookie records, data generated within data enrichment operations, records of surveys, satisfaction surveys, information and evaluations obtained as a result of campaigns and direct marketing activities.)

Interaction and usage data: IP address, browser settings, frequency of visits to the website, duration of visits to the website, search terms, clicks on content, originating website.

Documents and special information for job applications: Letter of motivation, CV and photo, references, diplomas, educational certificates, third party references Interview notes;

Data identifying the appliance – such as, serial number, model, colour etc;

Cookies: We also use cookies or similar technologies on our website, such as pixels (hereinafter referred to as "Cookies"). Cookies are small text files stored by your browser on your device, or image files, such as pixels. The next time you visit our website with the same device, the information stored in cookies will either be returned to our website (hereinafter referred to as "First Party Cookies"). We inform you about the use of cookies and provide you the opportunity to activate non-necessary cookies in advance with a corresponding note on a banner. Furthermore, you will find exhaustive information about the use of cookies and opportunities to activate or deactivate non-necessary cookies in our cookie policy.

II. We process your personal data for the following purposes:
• To fulfil a contract, or take steps linked to a contract we have with you. (According to Art. 6/(1), Subparagraph 1(b) GDPR) This includes:
• Registering on our website: Registered users can access additional services and offer. You can register as a user on our website. Registration is required if you wish to access additional services. We collect and process the following details as part of the registration process:

Required details:
o Title
o First and last name
o Full postal address
o Telephone number
o E-mail address
o Password

Optional details:
o Mobile phone number
o Date of birth
o What made you find us
o Consent to receiving advertising

• Management of Customer, Distributor/Retailer Agreements: When you share your personal data in order to enter into Agreement with Warmhaus, an account through which you may manage the distribution and sale of Warmhaus products is created. In this respect, information concerning your identity and signature is processed for the verification of your identity.
• Establishing communication with our customers, retailers and distributors:
In certain circumstances, we are required to deliver certain information to our customers, retailers and distributors regarding our products and services. For instance, we may be required to establish communication with you via SMS, e-mail or telephone for the purposes of delivery of the products. Additionally, customers, retailers and distributors benefiting from services provided through the Application, may also be communicated by way of in app notifications.
• Improving Customer Relations: Warmhaus values the customer satisfaction and in this regard process communication data in order to build a strong relation with its customers.
• As required to conduct our business and pursue our legitimate interests (According to Art. 6/(1), Subparagraph 1(f) GDPR), in particular:
• Requests and Evaluations: Personal data relating to you may be processed for the purposes of taking necessary actions in order to provide responses to questions, requests through Digital Environments or by other written and verbal channels.
• Conducting financial and accounting operations: Personal data relating to you may be processed for the purposes of complying with obligations to inform including identification and verification of identity and the prevention of fraudulent transactions, receiving payments and where deemed necessary, reimbursement.
• Service Customization: Offering, proposing and introducing the programs, services and products to the related persons and performing the activities for the customization of them according to the usage habits and needs of the related persons.
• For purposes which are required by law (According to Art. 6/(1), Subparagraph 1(c) GDPR) (legal obligations):
• Make an online repair appointment : On our website, you can make a repair appointment directly with a service technician. To do this, we usually need information about your household appliance, a description of the problem, as well as your address and other contact details. The specific data we collect is determined by the booking process.

o As part of the booking process, we verify the correct spelling of your address via the Google Maps database in order to rule out any incorrect entries or mix-ups. No personal data is transmitted.
o Google Maps is a service of Google LLC (previously Google Inc.), 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA ("Google"). Details on the processing of personal data through the use of Google Maps can be found at the following link: http://www.google.de/intl/de/policies/privacy/.

• Guarantee Obligations: Personal data relating to the product you purchased may be processed for the purposes of taking necessary actions in order to fulfil our guarantee obligations and services.
• Process your order and manage your account.
• Ensuring compliance with the national and international legislation to which Warmhaus is subjected and fulfilling the obligations arising from the relevant legislation. In response to requests by government or law enforcement authorities conducting an investigation.
• In such cases, it may be required to comply with commercial or tax-related retention requirements or to fulfill safety-related requirements. • Where you give us consent (According to Art. 6/(1), Subparagraph 1(a) GDPR):
• Marketing Activities: Where required by law, we will send you with your consent direct marketing in relation to our relevant products and services, or other products and services provided by us, our affiliates and carefully selected partners.
• Events and Social Media: Where required by law, we will share videos and photographs of the Events with your consent in relation to our relevant events and activities, or other products and services provided by us.
• Other occasions: On other occasions where we ask you for consent, we will use the data for the purpose which we explain at that time such as when collecting information in relation to special information.

III. Withdrawing consent or otherwise objecting to direct marketing:
Wherever we rely on your consent, you will always be able to withdraw that consent, although we may have other legal grounds for processing your data for other purposes, such as those set out above. You have an absolute right to withdraw your consent from sharing information via social media at any time.

IV. Relying on our legitimate interests:
We have carried out balancing tests for all the data processing we carry out on the basis of our legitimate interests, which we have described above. You can obtain information on any of our balancing tests by contacting us using the details set out later in this Privacy Notice.

V. Integration of Third Party Services
In providing our website, we integrate various content and functional elements (hereinafter also referred to collectively as “services”) that are obtained from the web servers of their respective providers (hereinafter referred to as “third-party providers”). For the proper presentation and provision of the services, it is always necessary that your IP address is transmitted to the respective third-party provider. Although we endeavour to only integrate services where the respective third-party provider only uses the IP address to deliver the services, we have no influence on the further processing by third-party providers. Google Services: On our website, we use various services of Google LLC, based in the USA, or if you have your habitual residence in the European Economic Area (EEA) or Switzerland, Google Ireland Ltd, based in Ireland ("Google"). Google LLC is always responsible for the processing of personal data when using "YouTube" and "Google Maps/Google Earth". We use the following Google services on our websites:

• Google Tag Manager
• Google Analytics
• Google Ads
• Google AdSense
• Google Marketing Platform
• Google Maps/Google Street View
• YouTube

You can find more information about each service below.

Google uses technologies such as cookies, web storage in the browser and tracking pixels, which enable an analysis of your use of our website. The information thus generated about your use of our website may be transmitted to a Google server in the USA or other countries and stored there. For more information on Google's processing and privacy settings, please refer to Google's privacy policy or privacy settings here.

C. COMMUNICATION OF PERSONAL DATA
I. To Whom, Why and Where We Transfer Your Personal Data?
Under certain circumstances, we may transfer your personal data to third parties residing within borders or abroad, in accordance with applicable laws.

Third parties that we may transfer your data can be listed categorically as follows:
• Our business partners or suppliers residing within borders or abroad: Transportation companies, that will provide you products during Agreement.
• Group companies: Certain services offered by Warmhaus are carried out by our affiliates, within this context, your personal data may be shared with our relevant affiliates.
• Suppliers: Your personal data will also be shared with third party service providers, in particular, third party providers of website hosting, software, maintenance, and transportation service providers.
• Government authorities such as tax authorities;

Where information is transferred from inside the EEA to outside the EEA (e.g. Turkey), and where this is to a stakeholder or vendor in a country that is not subject to an adequacy decision by the EU Commission, data is adequately protected by EU Commission approved standard contractual clauses or a vendor's Processor Binding Corporate Rules.

II. How long we will retain your data?
Warmhaus is subject to legal obligations on data retention periods under Turkish law, European Law and depending on the country in which you live or which law applies, national laws of a country (for example, USA, Russia, Germany, Italy, etc.). As Warmhaus, provides services and products to many locations in different countries and the applicable laws change thereafter, the retention periods may therefore vary from country to country. Your personal data are deleted as soon as they are no longer needed for the specified purposes. However, we must sometimes continue to store your data until the retention periods and deadlines set by the legislator or supervisory authorities, up to 20 years which may arise from the Turkish Commercial Code, Tax Code, Turkish Code of Obligations and depending on other applicable European Laws and national laws of a EU-Country. We may also retain your data until the statutory limitation periods have expired (but up to 20 years in some cases), provided that this is necessary for the establishment, exercise or defence of legal claims. After that, the relevant data are periodically deleted.

Where we process personal data for marketing purposes or with your consent, we process the data until you ask us to stop and for a short period after this (to allow us to implement your requests). We also keep a record of the fact that you have asked us not to send you direct marketing or to process your data so that we can respect your request in future.

III. Location of data storage
Unless otherwise expressly stated in this privacy policy, all personal data collected from you in connection with your use of our Warmhaus products and websites or Digital Platforms are generally stored on servers within the territory. It might be possible that your data must be transferred und processed outside the territory of the European Union. In such event, your data will be secured by appropriate safeguards as set forth in Art. 46 (2) GDPR, in particular, but without limitation to, by the use of the Standard Contractual Clauses for the transfer of data between EU and non-EU countries.

12. Data subject rights

Data subjects have various rights under GDPR. These include in particular:

• the right to be informed on the purposes and methods of the processing of your personal data;
• the right of access to your personal data (commonly known as “data subject access request”). This enables you to receive a copy of the personal data we hold about you;

o You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
o We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal information (or to exercise any of your other rights). This is to ensure that personal information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
o We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made several requests. In this case, we will notify you and keep you updated.

• the right to ask for updating or rectification of the personal data we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us;
• the right to request erasure of your personal data. This enables you to ask us to delete or remove your personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request;
• the right to restrict the processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data's accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it;
• the right to object to the processing, wholly or partly, of your personal data where personal data are processed for direct marketing purposes, you have the right to object at any time to processing of your personal data for such marketing, which includes profiling to the extent that it is related to such direct marketing.In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, you may exercise your right to object by automated means using technical specifications data based on Article 6 (1) (e) or (f) of the GDPR.
• where we are relying on consent to process your personal data, the right to revoke the consent to the processing of your personal data freely and at any time, also by clicking on the unsubscribe option at the bottom of our marketing communications;
• the right to data portability of your personal data to you or to a different provider. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format;
• the right to contact us by sending us an email at info@warmhaus.com.tr or using our contact us form and
• the right to lodge a complaint in front of the competent national data protection or judicial authority.

III. Data Security
We take all appropriate technical and organizational measures to safeguard your personal data and to mitigate risks arising in connection with unauthorized access, accidental data loss, deliberate erasure of or damage to personal data. In this respect Warmhaus;
Ensures data security by utilizing protection systems, firewalls and other software and hardware containing intrusion prevention systems against virus and other malicious software,

Access to personal data within our company is carried out in a controlled process in accordance with the nature of the data and within the framework of the authority on the basis of unit / role / practice,
Ensures the conduct of necessary audits to implement the provisions of the GDPR, in accordance with Article 32 of the GDPR,
Ensures the lawfulness of the data processing activities by way of internal policies and procedures,
Applies stricter measures for access to special categories of personal data,
In case of external access to personal data due to procurement of outsource services, Warmhaus obliges the relevant third party to undertake to comply with the provisions of the GDPR,
It takes necessary actions to inform all employees, especially those who have access to personal data, about their duties and responsibilities within the scope of the GDPR.

IV. Use of the website by minors
The Website is intended for an adult audience. Minors, in particular children under the age of 16, are prohibited from submitting personal data to us or registering for a service without the consent of their parents or legal guardians. If we discover that such data has been transmitted to us, it will be deleted from our database. The child's parents (or legal representative) can contact us and request deletion or deregistration. To do so, we need a copy of an official document that identifies you as the parent or legal guardian.

V. Links to websites of other providers
Where there are links to websites of other providers on our website, we have no influence on their content (e.g. Social media pages and other platforms). Therefore, we cannot assume any guarantee or liability for these contents. The respective provider or operator of the pages is always responsible for the content of these pages. The linked pages were checked for possible legal violations and recognisable infringements at the time of linking. Illegal contents were not recognisable at the time of linking. However, permanent monitoring of the content of the linked pages is not reasonable without concrete indications of a legal violation. Such links will be removed immediately if infringements of the law become known.

VI. Changes to our privacy policy
This Privacy Policy reflects the current state of data processing on our website. In the event of changes to data processing, this Data Protection Information will be updated accordingly. We always provide the latest version of this Data Protection Information on our website so that you can find out about the scope of data processing on our website.

VII. How to contact us
Email us at: info@warmhaus.com.tr
Call us: +90 (216) 300 16 50

If you have any questions about our Privacy Notice, the data we hold on you or If you want to exercise your rights, please specify which individual rights according to Art. 15 et seq. you want to exercise. For this purpose, we have to identify you in terms of personal identity. Please provide the following details so that we can identify you:

• Name
• Postal address
• E-mail address

If you send us a copy of your ID, please black out all other information apart from your first and last name and address.

When sending copies of the ID card, it must be clear that this is a copy. Therefore, please make a note on the copy of the ID as following: “This is a copy”. In order to be able to process your request, as well as for identification purposes, please note that we will use your personal data in accordance with Art. 6 para. 1 (c) of the GDPR as legal obligation.

VIII. How to contact the appropriate authority
Should you wish to report a complaint or if you feel that Our Company has not addressed your concern in a satisfactory manner, you may contact the Information Commissioner’s Office.

Email: info@warmhaus.com.tr
Address: Nidakule Ataşehir Kuzey Barbaros Mahallesi, Begonya Sokak No: 3, Kat:19 34746 Ataşehir/İstanbul/Türkiye