TEDARILOG
This document is the agreement between the merchant using the Tedarilog platform and the company operating it. By creating an account you accept these terms. The second part is the Data Processing Addendum, which sets out the controller and processor roles under GDPR and the Turkish data protection law (KVKK).
The platform imports orders from the merchant's e-commerce store, creates shipments with the carrier, tracks delivery, and handles cash-on-delivery collection and merchant settlement. The store connection is established by the merchant's own authorisation and can be revoked by the merchant at any time.
The merchant may request account closure. Uninstalling the app from the store closes the store connection automatically and no further orders are imported. Obligations already incurred for shipping, collection and settlement survive termination.
The platform is not liable for damages caused by the carrier's or the store platform's own fault; liability for its own fault is limited to the service fee charged for the order concerned. This agreement is governed by the laws of the Republic of Türkiye, with the courts of Istanbul having jurisdiction.
For personal data of store customers, the merchant is the controller and Tedarilog is the processor. The platform processes such data only on the merchant's instructions and within this agreement. For the merchant's own company and user details, the platform acts as controller.
| Subject matter | Order fulfilment: shipment creation, tracking, collection and settlement. |
|---|---|
| Duration | While the store is connected, and afterwards for statutory retention periods. |
| Data categories | Recipient name, phone, email, delivery address, order line items and totals. |
| Data subjects | Customers who place orders in the merchant's store. |
No payment card data is processed. Cash-on-delivery amounts are collected by the carrier; only the collected amount reaches the platform.
| Sub-processor | Data shared | Purpose |
|---|---|---|
| Sürat Kargo (carrier) | Recipient name, phone, address, collection amount | Create and deliver the shipment |
| Netgsm (SMS provider) | Recipient phone number, message text | Delivery status notifications |
| Google Cloud (Europe region) | The system as a whole | Server and database hosting |
This list is updated if a new sub-processor is added. By accepting this agreement the merchant approves the sub-processors listed above.
If a personal data breach is identified, its scope and the affected records are established and the merchant is notified without undue delay and within 48 hours at the latest, with the information and support needed for the merchant to meet its own notification duties. The process follows the platform's written security incident response policy.
On a deletion request from a customer or the merchant, identifying data (name, phone, email, street address) is anonymised, while commercial records subject to statutory retention are kept as amounts only. Mandatory compliance webhooks from the store platform (customer data request, customer redact, shop redact) are handled automatically. See the Privacy Policy for details.
The merchant may request information to verify compliance with this addendum, at reasonable intervals and with prior notice; the platform provides the necessary documentation and explanations.
If this document is updated, the version number is increased and merchants are notified in the panel. The version accepted at sign-up and the time of acceptance are recorded.