PRIVACY POLICY
Last updated: 29 May 2026
Bonheur (“Bonheur”, “we”, “us” or “our”) is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, share and safeguard your personal data when you visit bonheur-ww.com, create an account, place an order, subscribe to our newsletter or otherwise interact with us, in accordance with the EU General Data Protection Regulation (“GDPR”) and Türkiye’s Personal Data Protection Law No. 6698 (“KVKK”).
1. Data Controller
The data controller responsible for processing your personal data is:
- Legal Entity: [DATA CONTROLLER]
- Registered Address: [COMPANY ADDRESS]
- Trade Registry / Mersis No: [MERSIS NO]
- Email: info@bonheur-ww.com
- Registered Electronic Mail (KEP): [KEP ADDRESS]
- VERBIS Registration No (KVKK): [VERBIS NO]
2. Personal Data We Collect
Depending on how you interact with us, we may process the following categories of personal data:
- Identity data: first name, last name, date of birth (optional).
- Contact data: email address, phone number, shipping and billing address.
- Transaction data: order history, cart contents, payment method (card details are never stored by us and are processed solely by our payment provider), returns and exchanges.
- Account data: username, hashed password, saved preferences and wishlist.
- Marketing data: newsletter subscription status, email and SMS consents.
- Technical & security data: IP address, session logs, device and browser information.
- Cookie data: browsing behaviour, pages visited, clicks and engagement (see Section 7).
- Communications: messages and emails you send to client care, social media correspondence.
3. Purposes and Legal Bases for Processing
We process your personal data for the following purposes and legal bases:
- Order processing and fulfilment: performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5/2-c).
- Account creation and management: performance of a contract and our legitimate interests.
- Compliance with legal obligations (invoicing, tax, consumer protection): legal obligation (GDPR Art. 6(1)(c); KVKK Art. 5/2-a).
- Client care, returns, exchanges and complaint handling: contract and legitimate interests.
- Marketing, campaigns and newsletters: your explicit consent (GDPR Art. 6(1)(a); KVKK Art. 5/1).
- Analytics, site performance and user experience improvement: consent and legitimate interests.
- Fraud prevention, payment security and protection of legal rights: legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5/2-f).
4. Third Parties With Whom We Share Data
We share your personal data only as necessary and only with the following categories of recipients:
- E-commerce platform: Shopify Inc. (Canada / Ireland) — site hosting, order and customer data management.
- Payment service providers: PCI-DSS certified providers such as Iyzico and Stripe — for payment processing only.
- Logistics and shipping carriers: domestic and international couriers receive name, address and phone number to deliver your order.
- Email and SMS providers: Klaviyo, Shopify Email, SMS gateways — under your explicit consent.
- Analytics and advertising partners: Google Analytics, Google Ads, Meta (Facebook/Instagram), TikTok, Pinterest — under consent and legitimate interests.
- Accounting and e-invoicing providers: Paraşüt, Turkish Revenue Administration (GİB) e-archive — under legal obligations.
- Public authorities: courts, prosecutors, tax authorities, the Turkish Data Protection Authority — only where legally required.
- Professional advisors: legal and accounting consultants under confidentiality obligations.
5. International Data Transfers
Some of our service providers (e.g. Shopify, Google, Meta, Klaviyo, Stripe) operate servers outside of Türkiye and the European Economic Area, primarily in the EU and the United States. Where personal data is transferred outside Türkiye/EEA, we rely on:
- your explicit consent; or
- transfers to countries deemed adequate by the European Commission or the Turkish Data Protection Authority; or
- appropriate safeguards such as EU Standard Contractual Clauses (SCCs) and supplementary measures, in line with GDPR Chapter V and KVKK Art. 9.
6. How We Collect Your Data
We collect personal data through our website, mobile applications, client care channels, social media accounts, email correspondence, cookies and similar technologies, by both automated and non-automated means.
7. Cookies
Our site uses cookies to improve your experience and our services. We use the following categories:
- Strictly necessary cookies: required for core site functionality (session, cart, security).
- Performance / analytics cookies: measure usage statistics (e.g. Google Analytics).
- Functional cookies: remember your preferences (language, currency).
- Marketing / targeting cookies: enable personalised content via partners (Meta Pixel, Google Ads, TikTok Pixel and similar).
Non-essential cookies are activated only with your explicit consent through our cookie banner. You may reject or delete cookies via your browser settings, although certain features of the site may then be limited.
8. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes set out in this Policy and to comply with applicable law:
- Account data: 10 years from termination of membership (Turkish Code of Obligations).
- Order, invoice and financial records: 10 years (Tax Procedure Law and Commercial Code).
- Client care correspondence: 3 years.
- Marketing consents and records: until consent is withdrawn; 3 years thereafter for evidentiary purposes.
- Cookie data: from 24 hours up to 2 years, depending on cookie type.
- Traffic and log records: 2 years (Turkish Law No. 5651).
Once retention periods expire and the purpose of processing ceases, your personal data is deleted, destroyed or anonymised.
9. Your Rights Under GDPR and KVKK
Under GDPR Articles 15–22 and KVKK Article 11, you have the right to:
- be informed whether your personal data is being processed;
- access your personal data and obtain a copy;
- learn the purposes of processing and whether it is used in accordance with such purposes;
- know the third parties to whom your data is transferred, in Türkiye or abroad;
- have inaccurate or incomplete data rectified;
- have your data erased or destroyed where the legal grounds for processing have ceased (“right to be forgotten”);
- request notification of corrections, erasures or destructions to recipients to whom data was transferred;
- object to automated decision-making that produces adverse effects;
- claim compensation for damages arising from unlawful processing;
- withdraw your consent at any time for data processed on the basis of consent;
- data portability (GDPR Art. 20);
- lodge a complaint with the competent supervisory authority (the Turkish DPA, or in the EU, the relevant member-state authority).
10. How to Exercise Your Rights
You may submit your requests, together with documentation verifying your identity, via the following channels:
- Email: info@bonheur-ww.com
- Registered Electronic Mail (KEP): [KEP ADDRESS]
- Postal mail: a signed written request sent to [COMPANY ADDRESS].
Your requests will be processed free of charge as soon as possible and no later than 30 days. Where a request requires additional cost, the fee determined by the Turkish DPA may apply.
11. Data Security
Bonheur applies technical (SSL/TLS encryption, firewalls, access control, logging, regular backups) and organisational measures (confidentiality agreements, staff training, role-based access, supplier audits) to safeguard your personal data against unlawful access, loss or disclosure.
12. Children’s Personal Data
Our services are not directed to individuals under the age of 16. We do not knowingly collect personal data from anyone under 16. If we become aware that we have collected such data, we will delete it promptly.
13. Changes to This Privacy Policy
This Privacy Policy may be updated from time to time to reflect changes in the law or in our services. The current version is always available on this page; for material changes we will notify you by email or via a notice on our website.
14. Contact Us
If you have any questions or feedback regarding our privacy practices, please contact us:
- Email: info@bonheur-ww.com
- Web: bonheur-ww.com