1. Who is responsible for your data
The entity below is the data controller under Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and under the EU General Data Protection Regulation (GDPR).
- Website
- https://bios.kocaali.net
2. What data we process
We collect only what the service actually needs. The table below shows where each piece of data comes from and why it is required.
| Data | When collected | Why it is needed |
|---|---|---|
| Email address | At registration or at guest checkout | To create your account and send your download link and invoice |
| Password (hash) | At registration | Secure sign-in. Your actual password is never stored — only an irreversible Argon2id hash |
| Name, phone, city, website, bio, profile photo | Only if you enter them | To show your profile and — if you enable it — your public profile page. These fields are optional |
| Purchase records (which file, which version, when, amount) | At purchase | To build your permanent archive, let you re-download, and issue your invoice |
| Download records (file, date, IP) | On each download | So you can re-download, and so we can detect abuse and link sharing |
| IP address and browser information | While browsing | Security, rate limiting (blocking hundreds of requests per second from one account), and statutory logging duties |
| Payment information | At checkout | Your card details never reach us; they go straight to PayTR. We hold only the order number, amount and payment result |
| Invoice details (name/company, address, tax number) | When an invoice is issued | To issue an e-Archive invoice as required by Turkish tax law |
| Business licence and tax certificate | When applying to the business directory | To verify the application belongs to a real business (the "Trusted Business" badge) |
| Listing details and contact phone | When you post a motherboard listing | To publish the listing so buyer and seller can talk directly |
3. Our purposes and legal bases
Under KVKK Article 5 and GDPR Article 6 every processing activity needs a legal basis. Ours are:
| Purpose | Legal basis |
|---|---|
| Delivering the file you bought, keeping it in your archive, allowing re-downloads | Performance of a contract (KVKK 5/2-c, GDPR 6(1)(b)) |
| Issuing invoices and transmitting them to the Turkish Revenue Administration | Legal obligation (KVKK 5/2-a, GDPR 6(1)(c)) |
| Keeping accounting records | Legal obligation — Turkish Tax Procedure Law and Commercial Code |
| Keeping access and download logs | Legal obligation (Law No. 5651) and legitimate interest (KVKK 5/2-f) |
| Preventing fraud, link sharing and abuse | Legitimate interest (KVKK 5/2-f, GDPR 6(1)(f)) |
| Verifying business directory documents | Contract performance and legitimate interest — the badge has to mean something |
| Analytics cookies | Your explicit consent (KVKK 5/1, GDPR 6(1)(a)) — you can decline in the cookie bar |
| Any announcement or marketing emails | Your explicit consent — every email carries an unsubscribe link |
4. Payment data: we never hold your card
Payments are processed by PayTR Ödeme ve Elektronik Para Hizmetleri A.Ş. Your card number, expiry date and CVC are entered directly into PayTR's secure page or frame; they never reach BiosHelp servers and are never stored by us.
For this transaction PayTR acts as an independent controller and handles card data under its own privacy policy and PCI-DSS standards. All we retain is the order number, amount, currency, whether the payment succeeded, and the payment date.
5. Who we share data with
We do not sell, rent, or transfer your personal data to third parties for advertising. Sharing happens only in the cases below, and only to the extent needed:
| Recipient | Data shared | Reason |
|---|---|---|
| PayTR | Order number, amount, email | To take the payment |
| Turkish Revenue Administration (GİB) | Invoice details | Statutory e-Archive invoicing duty |
| Our email delivery provider | Your email address and the message sent | To deliver download links, invoices and account emails |
| Competent public authorities | The data requested | Only upon a lawful written request, and only to the extent the law requires |
| The other party to a listing | The contact details you chose to publish | So buyer and seller can talk directly — you publish this information |
The business licence and tax certificate you upload are never published. They are stored outside the web root and can be seen only by the staff reviewing the application. After approval the public page shows only the business name, contact details and the badge.
6. International transfers
Our servers are located in Türkiye and, as a rule, your data is not transferred abroad.
There are two possible exceptions: if you consent to analytics cookies, Google Analytics data goes to Google's servers; and if our email delivery provider is located abroad, your email address is transmitted there. In both cases the transfer relies on the conditions in KVKK Article 9 and GDPR Chapter V (explicit consent or standard contractual clauses). If you decline analytics cookies, that transfer never happens.
7. How long we keep data
We do not keep data once its purpose has ended. Some retention periods, however, are set by law and we cannot shorten them:
| Data | Retention period |
|---|---|
| Account details | While your account exists; deleted within 30 days of your deletion request |
| Purchase and invoice records | 10 years — required by the Turkish Commercial Code and Tax Procedure Law. These survive account deletion for the statutory period |
| Download and access logs | 2 years — traffic data obligation under Law No. 5651 |
| Business verification documents | Immediately if the application is rejected; for the membership plus 1 year if approved |
| Your cookie preference | 1 year (in your browser) |
| Delisted marketplace listings | 1 year (in case a dispute arises) |
8. Cookies
We use three kinds of cookies. Essential cookies are required for the site to work and do not need consent:
| Cookie | Type | What it does | Lifetime |
|---|---|---|---|
bh_sess |
Essential | Keeps you signed in and runs the checkout flow | Session / 7 days |
bh_lang |
Essential | Remembers your language choice | 1 year |
bh_consent |
Essential | Remembers your cookie choice so we stop asking | 1 year |
| CSRF token | Essential | Protects forms against cross-site request forgery | Session |
Google Analytics (_ga) |
Optional | Helps us see which pages are useful. IP addresses are anonymised | 2 years |
Analytics cookies load only if you press "Accept" in the cookie bar. If you choose "Essential only", the measurement script is never added to the page at all. You can change your choice at any time by clearing this site's data in your browser.
We self-host our web fonts, so opening a page does not send a request to any third-party font server.
9. How we protect your data
Security here is not a marketing sentence; it is how the product is built. Concrete measures:
- Passwords are hashed with Argon2id; plain-text passwords are never stored or written to logs.
- Files for sale are stored outside the web root. No file can be reached by typing a URL.
- Every download uses a signed, time-limited link that expires shortly after it is issued.
- All database queries use prepared statements (no SQL injection surface).
- Forms are CSRF-protected; session cookies are HttpOnly and SameSite.
- Sign-in, download and search requests are rate limited.
- PayTR and GİB credentials are stored encrypted with AES-256-GCM, shown only masked in the admin panel, and never written to logs.
- Only authorised roles can reach the admin panel, and every administrative action is written to an audit log.
- All traffic is encrypted over HTTPS.
That said, we should be honest: no system is 100% secure. If a breach affecting your data occurs, we will notify the Turkish Data Protection Authority as soon as possible and within 72 hours as required, and inform you directly.
10. Your rights
Under KVKK Article 11 you may ask us to:
- Confirm whether your personal data is being processed,
- Provide information about that processing,
- Explain the purpose and whether the data is used accordingly,
- Identify the third parties, in Türkiye or abroad, to whom the data was transferred,
- Correct data that is incomplete or inaccurate,
- Erase or destroy the data where the statutory conditions are met,
- Notify third parties of any correction, erasure or destruction,
- Object to a result reached solely by automated analysis that works against you,
- Compensate damage arising from unlawful processing.
If you are in the EU, the GDPR additionally gives you the rights to data portability, restriction of processing and objection to processing based on legitimate interests.
Where a statutory retention period still applies (invoice records, for example) we cannot delete that data; we will tell you plainly which data is retained and why.
11. How to contact us
Send your request to the email address below. Please write from the email address registered to your account so that we can verify your identity.
We answer requests within 30 days, free of charge. If a request involves an additional cost we may charge the fee set in the Authority's tariff.
If you are not satisfied with our answer, you retain the right to complain to the Turkish Data Protection Authority, or to your local supervisory authority if you are in the EU.
12. Children's privacy
BiosHelp is aimed at adults working in technical service and electronics repair. We do not knowingly collect personal data from anyone under 18. If we discover such an account, we close it and delete the data.
13. Changes to this policy
We may update this policy as the service develops. The current version is always published on this page with the "last updated" date shown at the top.
If an update materially changes how we process your data, we will tell you by email or a prominent notice on the site before it takes effect.
If you have any question about this policy, please do get in touch.