Privacy Policy
This policy explains, in operational terms, who processes personal data within the Beyoğlu Professional PPWR-EPR service, what information we receive, where it comes from, why we use it, who may receive it, how long it is retained, how international transfers are handled and how an individual may exercise data-protection rights.
We collect business and regulatory data because packaging-EPR compliance cannot be operated without identifying the Producer, the relevant company, the packaging, the transaction and the Member State concerned.
We do not sell personal data. We do not describe regulatory data as advertising data. We do not ask customers to provide consumer information that is unnecessary for an EPR task. Where we use a third party, we distinguish whether that party operates for us, for the customer, or as an independent authority, PRO, payment provider or other controller.
1 · Who we are
The public brand and the legal entity are identified separately.
| Service brand | Beyoğlu Professional — PPWR-EPR Compliance Services The public-facing service brand used for the European packaging-EPR compliance programme and platform. |
|---|---|
| Current business entity |
THEMİR MEDYA İNŞAAT İTHALAT İHRACAT
SANAYİ TİCARET ANONİM ŞİRKETİ
The current Turkish legal and administrative entity operating the public service during the present development and rollout stage. |
| Legal / administrative address | Tatlısu Mah. Aziz Blv. Çağrı Sitesi B Blok No:48, İç Kapı No:42, 34774, Ümraniye, İstanbul, Türkiye |
| Tax registration |
Tax No. 8430730980 Alemdağ Vergi Dairesi |
| Current development base | İstanbul, Türkiye |
| European structure | Staged European rollout programme. European entities, branches and statutory representative structures are described as established only after the corresponding legal arrangement has actually been completed. |
| Contracting entity | Confirmed expressly in the applicable Order Form, commercial agreement, regulatory mandate or country-specific representation document. |
| Regulatory scope | Packaging EPR / PPWR Chapter VIII operations. The present service is not marketed as a generic EU product-safety authorised-representative service. |
2 · Data controller
Who is the controller for this website?
For the current public Beyoğlu Professional PPWR-EPR website, contact enquiries, public assessment flows and other processing for which no different entity is expressly identified, the current controller is:
THEMİR MEDYA İNŞAAT İTHALAT İHRACAT
SANAYİ TİCARET ANONİM ŞİRKETİ
Tatlısu Mah. Aziz Blv. Çağrı Sitesi B Blok No:48,
İç Kapı No:42,
34774 Ümraniye, İstanbul, Türkiye.
Electronic privacy enquiries and data-subject requests may be submitted through /ppwr/contact .
A later customer engagement may identify another Beyoğlu group entity or national entity as the controller, joint controller, processor, statutory representative or contracting party for a defined processing operation. Where that occurs, the relevant Order Form, Data Processing Agreement or regulatory mandate identifies that entity and the relationship concerned.
EU representative under GDPR Article 27
The current controller is established in Türkiye, outside the European Union and European Economic Area.
GDPR Article 27 can require a controller subject to Article 3(2) to designate a representative in the Union, unless the statutory exception in Article 27(2) applies.
No EU GDPR Article 27 representative is identified in this notice as of 30 August 2026.
Beyoğlu Professional does not publish a fictional representative before a written appointment has actually been made. The requirement is part of the European rollout compliance work and, where Article 27 requires designation, the representative's name and contact details will be inserted into this Policy after the appointment becomes legally effective.
Data Protection Officer
No Data Protection Officer is identified in this notice as of 30 August 2026.
The requirement for a DPO is reviewed against GDPR Article 37, including whether the company's core activities involve large-scale regular and systematic monitoring or large-scale processing of special-category or criminal-offence data.
If appointment becomes mandatory or a DPO is appointed voluntarily, the DPO's contact details will be published here.
3 · Applicable privacy framework
Our Turkish establishment does not make EU data-protection obligations disappear.
The current Turkish entity is subject to applicable Turkish personal-data legislation, including Law No. 6698 on the Protection of Personal Data where that law applies.
GDPR can additionally apply to processing falling within its territorial scope, including qualifying processing connected with offering goods or services to persons in the Union.
We therefore structure this Policy to provide the disclosures required by GDPR Articles 13 and 14 for the processing described here.
4 · Categories of data
What information can enter the Beyoğlu system?
Business-contact data
Name, surname, business email, telephone number, job title, employer, department and authorised-contact role.
Account and authentication data
Account identifier, login details, authentication events, account role, access permissions and security-related account information.
Corporate and registration information
Legal name, company number, registered address, VAT information, EORI or other identifiers where relevant, authorised signatory information and corporate documents.
Producer and regulatory data
Producer status, national registration information, EPR numbers, PRO memberships, EPR AR mandates, authority correspondence, reporting records and regulatory evidence.
Product and packaging data
SKU, product description, packaging component, material, packaging weight, unit quantities, packaging categories and versioned packaging records.
Order and shipment data
Order and parcel references, destination Member State, shipment date, SKU quantities, fulfilment route, cancellation, return and related transactional events.
Billing and regulatory-payment records
Invoice information, service-fee records, regulatory-contribution calculations, payment status, payment references, wallet reservations and reconciliation records.
Correspondence and support records
Messages, support requests, assessment answers, meeting records, customer instructions and regulatory correspondence.
Device and system information
IP address, browser and device information, timestamps, session information, API events, security logs and diagnostic information.
Consent and preference records
Cookie choices, consent records, communication preferences, opt-outs and other preference history.
Packaging-EPR reporting normally needs information such as destination country, parcel, product, quantity and packaging. It usually does not require the customer's name, private email address or precise residential address. API and import integrations should therefore remove unnecessary end-consumer data before transmission wherever the compliance purpose can be achieved without it.
5 · Where the information comes from
Not all information reaches us directly from the individual concerned.
We may obtain personal data directly from the individual, but also from the organisation that employs or instructs that individual.
Other possible sources include customer APIs and commerce systems, public company registers, Producer registers, competent authorities, PROs, recognised compliance systems, marketplaces, fulfilment providers, payment providers and publicly accessible professional business information.
Where GDPR Article 14 applies because information was not obtained directly from the data subject, the categories and source of the information are disclosed through this Policy and, where required, directly to the person concerned within the time limits prescribed by Article 14.
That generally means within a reasonable period and no later than one month after obtaining the information, or earlier where the data is first used to communicate with the person or first disclosed to another recipient, unless an Article 14 exception lawfully applies.
6 · Purposes and legal bases
We identify why data is used rather than relying on one blanket legal basis for everything.
| Processing purpose | Personal data involved | GDPR legal basis typically relied upon |
|---|---|---|
| Responding to an enquiry or requested assessment | Contact details, company data, information supplied in the enquiry | Article 6(1)(b) where the individual requests pre-contractual steps; Article 6(1)(f) for ordinary B2B correspondence involving representatives of a corporate organisation |
| Creating and administering an account or workspace | Identity, business contact, authentication and account data | Article 6(1)(b) where applicable; Article 6(1)(f) for administration of access provided to employees or other corporate users |
| Producer assessment and country activation | Company, commercial-route, Producer, packaging and contact data | Article 6(1)(b); Article 6(1)(f) where processing relates to the customer's corporate representatives |
| Regulatory registration and reporting | Corporate identifiers, authorised contacts, mandate information, packaging quantities and regulatory records | Article 6(1)(b); Article 6(1)(c) where processing is necessary for a legal obligation applicable to the relevant Beyoğlu entity or statutory representative |
| PRO/system administration and evidence retention | Producer, registration, reporting, contact and evidence data | Articles 6(1)(b), 6(1)(c) and, where appropriate, 6(1)(f) |
| Regulatory-payment calculation and administration | Company, parcel, packaging, invoice and payment data | Articles 6(1)(b) and 6(1)(c); Article 6(1)(f) for audit, reconciliation and fraud-control operations |
| Customer support and service communication | Contact details and correspondence | Articles 6(1)(b) and 6(1)(f) |
| Platform security, abuse prevention and diagnostics | Account, device, IP, API and security log data | Article 6(1)(f); Article 6(1)(c) where a specific security obligation applies |
| Accounting, tax, audit and legal claims | Contract, invoice, payment and correspondence data | Articles 6(1)(c) and 6(1)(f) |
| Optional non-essential analytics | Cookie/device and usage information | Article 6(1)(a) consent where consent is required, together with applicable ePrivacy rules |
| Optional electronic marketing | Business-contact and preference data | Consent or another lawful basis only where permitted by GDPR and the applicable national electronic-marketing law |
Our legitimate interests
Where Article 6(1)(f) is used, our legitimate interests can include operating a B2B service, administering relationships with corporate customers, maintaining service integrity, securing accounts and APIs, preventing fraud or abuse, maintaining regulatory evidence, defending legal claims and improving the reliability of our compliance workflows.
We do not treat legitimate interest as a universal substitute for consent where ePrivacy or another law requires consent.
7 · Is providing the data compulsory?
Some information is optional. Some information is necessary to provide the requested compliance service.
A visitor may read public Knowledge Hub material without providing the corporate and packaging information required for a managed compliance service.
To activate a country, register a Producer, operate reporting, calculate a regulatory contribution or accept a statutory mandate, we must receive the information required for that task.
Where information is a statutory or contractual requirement, failure to provide it may mean that we cannot activate the country, file a declaration, accept a mandate, calculate a reliable EPR amount or continue the affected service.
8 · Recipients
We distinguish regulatory recipients from technical processors.
Depending on the country and service, personal data may be disclosed to the following categories of recipients.
- national environmental authorities and competent authorities;
- national Producer registers and regulatory portals;
- authorised PROs, compliance schemes and EPR system operators;
- deposit-return systems where relevant;
- an eligible EPR Authorised Representative or other country-specific Beyoğlu entity where a lawful local representation structure is used;
- marketplaces and fulfilment providers where the customer instructs us to provide evidence or where the relevant legal process requires the exchange;
- licensed payment service providers, banks and payment infrastructure used for service or regulatory payments;
- cloud, hosting, security, authentication and communications providers;
- accountants, auditors, insurers, lawyers and other professional advisers;
- courts, regulators, law-enforcement bodies or other public authorities where disclosure is legally required.
The current website is built and delivered using Tilda. Tilda's current published Data Processing Agreement identifies, among others, Hetzner Online GmbH for server storage, G-Core Labs SA for storage and backup of projects, and Google Cloud EMEA Limited for information-security functions. Tilda can update its subprocessors under its own contractual framework; therefore its current published DPA remains the authoritative source for its infrastructure list.
9 · International transfers
Türkiye is a third country for GDPR transfer purposes.
The current business entity and development base are in Türkiye. Türkiye is not listed among the countries currently covered by a European Commission GDPR adequacy decision.
Accordingly, where personal data is transferred from the EEA to Türkiye in circumstances governed by GDPR Chapter V, an applicable transfer mechanism must be identified.
Depending on the processing relationship, this may include the European Commission's Standard Contractual Clauses under Article 46, together with any supplementary technical, contractual or organisational measures required by the circumstances of the transfer.
Data may also be processed in other countries through infrastructure providers. For example, Tilda's currently published DPA states that project-related data can be processed in EU Member States and the United States and states that SCCs or other lawful safeguards are used where required.
A data subject may request information about the transfer safeguard applicable to their personal data through our contact channel.
10 · Retention
We retain records according to their function, not under one indefinite retention period.
| Record type | Retention approach |
|---|---|
| Unconverted enquiries | Normally retained for up to 24 months after the last substantive interaction, unless required for a dispute, security matter or legal obligation. |
| Assessment / pre-contract workspace data | Normally retained for up to 24 months after the last relevant activity where no customer engagement follows, unless the user deletes it earlier where deletion is available or a longer period is legally justified. |
| Active customer account data | Retained for the duration of the service and then for the period needed to complete termination, regulatory handover, accounting and claims obligations. |
| Contracts, invoices and accounting records | Retained for the statutory period required under the applicable commercial, accounting and tax regime. Depending on the record, this may extend for several years after the commercial relationship ends. |
| EPR registration, declaration and evidence records | Retained for the country-specific period required by applicable law, authority, register, PRO/system rules or the relevant mandate. No universal EU retention period is asserted. |
| Security and access logs | Retained for a period proportionate to security, troubleshooting and audit requirements and extended where a specific incident, investigation or legal claim requires preservation. |
| Consent records | Retained for as long as necessary to demonstrate the consent and subsequent withdrawal or preference history. |
| Marketing suppression records | A minimal suppression record may be retained after an opt-out so that the opt-out can continue to be respected. |
When a retention period ends, information is deleted, anonymised or otherwise removed from active use unless continued retention is legally justified.
11 · Your GDPR rights
A right request is a legal request, not a customer-support favour.
- request confirmation whether personal data concerning you is being processed and obtain access to that data;
- request correction of inaccurate data and completion of incomplete data;
- request erasure where Article 17 conditions are met;
- request restriction of processing where applicable;
- object to processing based on Article 6(1)(e) or 6(1)(f), subject to the conditions of Article 21;
- object at any time to processing for direct marketing;
- receive data in a structured, commonly used and machine-readable format where the Article 20 portability conditions are met;
- withdraw consent at any time where processing relies on consent, without affecting processing that was lawful before withdrawal;
- exercise applicable safeguards concerning qualifying solely automated decision-making under Article 22;
- obtain information concerning Article 46 safeguards for qualifying international transfers.
How we handle requests
Requests may be made through /ppwr/contact or by writing to the controller at the corporate address above.
We will respond without undue delay and, under GDPR, normally within one month of receiving a valid request.
Where necessary because of complexity or the number of requests, GDPR permits an extension of up to two additional months. If an extension is used, the data subject will be informed within the initial one-month period and told why the extension is necessary.
Data-subject requests are normally handled free of charge. GDPR permits a reasonable fee or refusal only for requests that are manifestly unfounded or excessive, particularly because of repetitive character.
Where we reasonably need to verify the identity of the requester, we may request additional information limited to what is necessary for that verification.
12 · Complaints
You are not required to resolve a GDPR concern only through us.
We encourage individuals to contact us so that we can investigate and correct a problem promptly.
This does not remove the right under GDPR Article 77 to lodge a complaint with a competent supervisory authority, including in the Member State of the individual's habitual residence, place of work or place of the alleged infringement.
Where Turkish Law No. 6698 applies, the rights and complaint mechanisms provided under that law and the Turkish Personal Data Protection Authority framework remain available in accordance with the applicable rules.
13 · Automated processing
Our compliance engine automates calculations and routing; it does not pretend to be a regulator.
The platform can use deterministic rules to determine which country workflow applies, map packaging profiles to shipments, calculate expected regulatory contributions, detect missing information and route an exception for review.
Public checkers and calculators may similarly produce automated results based on the information entered.
These functions are not represented as authority decisions and do not by themselves constitute solely automated legal decisions concerning an individual within the meaning of GDPR Article 22.
As of this Policy version, Beyoğlu does not state that it uses solely automated Article 22 decision-making producing legal or similarly significant effects on individuals.
If this changes, the relevant notice will explain the logic, significance, expected consequences and safeguards, including any applicable right to human intervention.
14 · Special-category and children's data
Our PPWR-EPR service is not designed to collect sensitive personal information or data from children.
Customers should not provide health information, biometric information, political opinions, religious beliefs, sexual-life information, trade-union information or criminal-record information unless a specific lawful compliance purpose requires it and the legal basis has been established in advance.
The service is a professional B2B compliance service and is not directed at children.
15 · Cookies and similar technologies
Optional tracking and necessary infrastructure are not the same thing.
Strictly necessary technologies may be used to provide security, sessions, authentication or a function explicitly requested by the user.
Technologies requiring consent under applicable ePrivacy rules should not be activated until valid consent has been obtained.
See the Cookie & Similar Technologies Policy for the applicable framework.
16 · Security and breaches
Data protection includes what happens when a control fails.
We apply technical and organisational controls appropriate to the nature and risk of the processing. Further information is available in our Data & Security Policy .
Where GDPR applies and a personal-data breach is likely to result in a risk to the rights and freedoms of individuals, the controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach.
Where a breach is likely to result in a high risk to individuals, affected data subjects must also be informed without undue delay unless a statutory exception applies.
Breaches are documented together with their facts, effects and remedial measures as required by applicable law.
17 · Changes to this Policy
Privacy disclosures will change when the operating architecture changes.
We will update this Policy when material changes occur, including appointment of an EU GDPR representative, establishment of a European contracting entity, deployment of production payment infrastructure, changes to material processors, or introduction of a materially different processing purpose.
The effective date and review date will remain visible. Where GDPR requires direct notice of a new processing purpose, publication of a revised web page alone will not be treated as a substitute for that direct notice.
Privacy and data-subject requests
Controller: THEMİR MEDYA İNŞAAT İTHALAT İHRACAT
SANAYİ TİCARET ANONİM ŞİRKETİ
Tatlısu Mah. Aziz Blv. Çağrı Sitesi B Blok No:48,
İç Kapı No:42, 34774 Ümraniye, İstanbul, Türkiye.