Secure Payment and Payment Security Policy
1. GENERAL PRINCIPLES AND SCOPE
The Atelier Emine brand (“the Company”), www.atelieremine.com All sales transactions conducted through the website with the domain name are based on the principles of information security , protection of personal data , financial data confidentiality , and transparency .
This Secure Payment and Payment Security Policy;
Online payments made with credit cards and debit cards.
Third-party payment service providers
Bank transfer / EFT transactions
Processing of personal and financial data
Compliance with national and international legislation.
It includes.
This policy has been prepared within the framework of the Law No. 6698 on the Protection of Personal Data (KVKK) , the European Union General Data Protection Regulation (GDPR – Regulation (EU) 2016/679) , PCI DSS standards and all relevant secondary regulations.
2. PAYMENT INFRASTRUCTURE AND AUTHORIZED PAYMENT SERVICE PROVIDER
All credit and debit card payments made through our website are processed using the infrastructure of iyzico Payment Services Inc.
iyzico;
It has PCI DSS (Payment Card Industry Data Security Standard) certification.
It does not store card information.
Card data is not shared with the Company.
It is subject to the regulations of the Central Bank of the Republic of Turkey and the Banking Regulation and Supervision Agency (BDDK).
It works directly integrated with Türkiye's leading banks.
Payment transactions are processed through iyzico's secure servers, and card information never comes into contact with the company's systems .
3. PCI DSS COMPLIANCE AND PROTECTION OF CARD DATA
PCI DSS is the highest security standard for protecting payment card data, created by Visa, MasterCard, American Express, and other international card organizations.
iyzico infrastructure;
Compliant with PCI DSS Level 1.
It undergoes regular security checks.
It does not store card number, expiration date, or CVV information.
It processes card data using a tokenization method.
In this context;
Card information is not viewed by the Company.
Card information is not saved.
Card information is not stored.
4. 3D SECURE (STRONG CUSTOMER AUTHENTICATION)
For payments made by credit card, your bank uses the 3D Secure verification system.
3D Secure;
It ensures that the payment process is completed only with the cardholder's approval.
Minimizes the risk of unauthorized use.
It provides robust customer validation under PSD2 (Payment Services Directive 2).
During the 3D Secure process;
The cardholder receives a one-time password from the bank.
Payment will not be completed without confirmation.
5. PAYMENT BY BANK TRANSFER / EFT
For customers who prefer not to use a credit card, we offer the option of paying via bank transfer/EFT.
For payments made via bank transfer or EFT;
Payment must be made only to the official bank account registered in the name of the Company.
The description field should include the order number and full name.
Payment receipt or confirmation must be sent to us in order for the order to be processed.
Orders may not be processed until we receive the receipt or payment confirmation.
6. PROCESSING OF PERSONAL DATA AND PRIVACY
Personal data processed during the payment process;
First and last name
Email address
Phone number
Billing and delivery address
Payment method information
It is limited to.
This data;
Performance of the contract
Payment process completed
Fulfillment of legal obligations
They are processed for these purposes.
Personal data;
Not shared with third parties.
It is protected against unauthorized access with technical and administrative measures.
They are deleted, destroyed, or anonymized after the legal time limits expire.
7. DATA SECURITY AND TECHNICAL INFRASTRUCTURE
Companies and payment service providers;
SSL/TLS encryption technologies
Secure server infrastructures
Access control mechanisms
Logging and monitoring systems
It ensures data security by using...
All systems used during payment processing are protected against unauthorized access, data leaks, and malware.
8. COMPLIANCE WITH INTERNATIONAL STANDARDS AND REGULATIONS
Our payment and data security processes;
Personal Data Protection Law (KVKK)
GDPR
PCI DSS
PSD2
Electronic Commerce Legislation
It is in full compliance with.
The company reserves the right to update this policy in accordance with changes in applicable legislation.
9. TRANSPARENCY AND INFORMATION
All information regarding the payment process;
Open
Understandable
Accessible
This is how it is presented to our customers.
Customers are regularly informed throughout the ordering, payment, and billing processes.
10. COMMUNICATION AND SUPPORT
For any questions regarding payment security, privacy, or billing, please contact us.
Email: atelieremine@gmail.com
Phone: +90 531 728 09 02
Our support team will be happy to professionally assist you with all your payment process requests.