Last updated: March 2026
1. Introduction
SultanaExpress ("Company", "we", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our B2B marketplace platform ("Platform").
We comply with the General Data Protection Regulation (GDPR), the Turkish Law on Personal Data Protection (KVKK), and other applicable data protection laws.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, phone number, company name, job title, and business address
- Profile Information: Company description, product categories, certifications, and business capabilities
- Transaction Data: RFQ details, quotes, order information, and payment records
- Communications: Messages exchanged through the Platform, support requests, and feedback
- Verification Documents: Business registration, tax ID, and certification documents (for suppliers)
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, search queries, and interaction patterns
- Device Information: Browser type, operating system, device identifiers, and IP address
- Cookies: Session cookies, preference cookies, and analytics cookies (see our Cookie section below)
3. How We Use Your Information
We use collected information for the following purposes:
- Platform Operation: To provide, maintain, and improve the Platform's features and services
- Account Management: To create and manage your account, verify your identity, and process transactions
- Communication: To send transactional notifications (RFQ updates, order status), respond to inquiries, and provide support
- Matching: To connect buyers with relevant suppliers based on product categories and requirements
- Analytics: To understand usage patterns, generate market insights, and improve user experience
- Security: To detect and prevent fraud, abuse, and unauthorized access
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
4. Legal Basis for Processing (GDPR)
We process personal data based on the following legal grounds:
- Contract Performance: Processing necessary to provide our services as agreed in our Terms of Service
- Legitimate Interests: Processing necessary for our business interests (security, analytics, service improvement) where not overridden by your rights
- Consent: Where you have given specific consent (marketing communications, non-essential cookies)
- Legal Obligation: Processing required by applicable laws (tax reporting, anti-fraud regulations)
5. Information Sharing
We do not sell your personal data. We may share information with:
- Other Users: Your public profile, product listings, and business information are visible to other Platform users as part of the marketplace functionality
- Service Providers: Third-party providers who assist with hosting, analytics, payment processing, and logistics (e.g., Yusen Logistics)
- Legal Requirements: When required by law, regulation, or legal process
- Business Transfers: In connection with a merger, acquisition, or sale of assets
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide our services. After account termination:
- Transaction records are retained for 7 years for legal and accounting purposes
- Communication logs are retained for 2 years
- Usage data is anonymized after 1 year
- You may request earlier deletion of your personal data (subject to legal retention requirements)
7. Your Rights
Under GDPR and KVKK, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data ("right to be forgotten")
- Restriction: Request restriction of processing in certain circumstances
- Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing based on legitimate interests or for direct marketing
- Withdraw Consent: Withdraw previously given consent at any time
To exercise these rights, contact us at sc@sultana.express. We will respond within 30 days.
8. Cookies
We use cookies and similar technologies to:
- Essential Cookies: Required for Platform functionality (session management, security)
- Preference Cookies: Remember your settings (language, display preferences)
- Analytics Cookies: Understand how users interact with the Platform to improve our services
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect Platform functionality.
9. Data Security
We implement appropriate technical and organizational measures to protect your data:
- Encryption of data in transit (TLS/SSL) and at rest
- Regular security audits and vulnerability assessments
- Access controls and authentication requirements
- Employee training on data protection practices
While we strive to protect your information, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
10. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence. We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Data processing agreements with all service providers
11. Children's Privacy
The Platform is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or Platform notification. The "Last updated" date at the top reflects the most recent revision.
13. Contact Us
For privacy-related questions, requests, or complaints: