This Privacy Policy (“Policy“) explains how SIGMA OPERASYON VE LOJİSTİK A.Ş. (“Company”, “we”, “us” or “our”) collects, uses, stores, discloses and protects personal data in connection with the operation of www.sigmalojistic.com (the “Website”) and in connection with our business-to-business (“B2B”) commercial relationships, including personal data submitted through the Website, exchanged by email, or provided in the course of a commercial, contractual or professional relationship with us.

We process personal data in accordance with Turkish Personal Data Protection Law No. 6698 (“KVKK”) and the secondary legislation and decisions of the Turkish Personal Data Protection Board (“Board”). Where and to the extent our processing activities fall within its territorial scope (see Section 9 below), we also apply the standards of the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and other applicable data protection laws.

Scope note (B2B activity). The Company’s business is conducted exclusively on a business-to-business basis. We do not offer products or services to consumers, and the Website is not intended for consumer use.

1. Data Controller and Contact Details

The data controller (veri sorumlusu) responsible for the processing of personal data described in this Policy is:

SIGMA OPERASYON VE LOJİSTİK A.Ş.
Registered office: Huzur Mah. Azerbaycan Cad. Skyland Sitesi, B-Blok, No: 4B, Office No: 22, 34396 Sarıyer / İstanbul, Türkiye

Email: info@sigmalojistic.com

VERBİS status: The Company qualifies for the exemption from registration in the Data Controllers’ Registry (VERBİS) under the Board’s Decision No. 2025/1572 dated 04.09.2025 (in force as of 01.10.2025). The Company will re-assess this status periodically and register in VERBİS without delay should the exemption criteria cease to be met.

EU/UK Representative: The Company has no establishment in the EU or UK. Our clients, prospects and Website visitors may be located worldwide, including in the EU/UK; however, our processing of their business contacts’ personal data arises solely from direct business correspondence in connection with actual or potential commercial relationships — we do not run newsletters, marketing mailing lists or lead-generation campaigns and do not otherwise systematically collect personal data of individuals in the EU/UK. This processing is therefore occasional, limited in scale, involves no special categories of data, and is unlikely to result in a risk to data subjects’ rights. On this basis, the Company relies on the exemption under Article 27(2) GDPR / Article 27(2) UK GDPR and has not appointed a representative. We will reassess this position and appoint a representative without delay should our activities change.

2. Personal Data We May Collect

We only collect personal data that you voluntarily provide to us through direct email communication.

The data collected may include:

We do not use cookies, analytics tools, or tracking technologies. We do not use your data for marketing purposes without your explicit consent. We do not sell your personal data. Personal data may be collected automatically, through the technical infrastructure necessary to operate, maintain and secure the Website (e.g., server logs). We may also disclose data where required by law.

3. Data Retention

We retain personal data only for as long as necessary to respond to your enquiry, assess any submitted information, and, where applicable, to establish or maintain a business relationship, or as required by applicable law.
As a general rule, personal data is retained for a period not exceeding 3 years, unless a longer retention period is required or permitted.

4. Your Rights

Under applicable data protection laws you have the right to:

To exercise any of the rights, please contact us at: info@sigmalojistic.com

We will respond to your request within a reasonable timeframe and, in any event, within the period required by applicable law. We may request information reasonably necessary to verify your identity before acting on a request.

5. Data Security

We implement reasonable and appropriate technical and organisational measures designed to protect data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

6. Changes to This Policy

We may update this Policy to reflect changes in our processing activities, services, technology, or applicable legal and regulatory requirements. Where required by law, we will provide additional notice of material changes.

7. Contact Us

If you have any questions regarding this Privacy Policy or the processing of your personal data, please contact us: info@sigmalojistic.com