Effective Date: [EFFECTIVE DATE]
Last Updated: [LAST UPDATED DATE]
This GDPR Data Protection Notice (“GDPR Notice”) provides additional information about how [COMPANY LEGAL NAME] (“Univerax,” “we,” “us,” or “our”) processes personal data where the European Union General Data Protection Regulation (“EU GDPR”), the United Kingdom General Data Protection Regulation (“UK GDPR”), or related data-protection legislation applies.
This Notice supplements the Univerax Privacy Policy. It does not replace the Privacy Policy, Cookie Policy, transaction-specific notices, or any other privacy information provided when personal data is collected.
If there is a conflict between this Notice and the general Privacy Policy concerning processing governed by the EU GDPR or UK GDPR, this Notice will apply to that processing to the extent required by applicable law.
This Notice may apply when:
Personal data is processed in connection with an establishment of Univerax in the European Economic Area (“EEA”) or United Kingdom;
Univerax offers products or services to individuals located in the EEA or United Kingdom;
Univerax monitors the behavior of individuals in the EEA or United Kingdom, to the extent that behavior takes place there; or
Another applicable rule brings the relevant processing activity within the scope of the EU GDPR or UK GDPR.
GDPR applicability is determined by the circumstances of the processing activity and not solely by an individual’s citizenship or nationality.
Unless a specific notice states otherwise, the controller responsible for the processing covered by this Notice is:
Controller: [COMPANY LEGAL NAME]
Registered Address: [REGISTERED ADDRESS]
Privacy Email: [PRIVACY EMAIL]
Privacy Request Form: [PRIVACY REQUEST FORM URL]
Data Protection Officer: [DPO DETAILS, IF APPLICABLE]
If Univerax is required to appoint a representative under Article 27 of the EU GDPR:
EEA Representative: [EEA REPRESENTATIVE NAME]
Address: [EEA REPRESENTATIVE ADDRESS]
Email: [EEA REPRESENTATIVE EMAIL]
If Univerax is required to appoint a representative under the UK GDPR:
UK Representative: [UK REPRESENTATIVE NAME]
Address: [UK REPRESENTATIVE ADDRESS]
Email: [UK REPRESENTATIVE EMAIL]
The requirement to appoint a representative or Data Protection Officer depends on Univerax’s establishment, processing activities, scale, and applicable exemptions.
Univerax operates a marketplace through which independent sellers, authors, experts, and service providers may offer products or services.
An independent seller or provider may act as a separate controller when it determines the purposes and means of processing personal data, including when it:
Communicates with a customer;
Delivers a purchased product or service;
Manages a booking or appointment;
Issues an invoice;
Maintains legally required business records; or
Complies with its own professional or regulatory duties.
The relevant seller or provider should give users appropriate information about its independent processing activities.
Univerax may separately process the same transaction data for Platform operation, payment coordination, safety, support, legal compliance, and dispute resolution.
The precise controller, joint-controller, or processor roles must be determined according to the actual data flow and contractual arrangements rather than the parties’ commercial labels alone.
Depending on how you use the Platform, we may process:
Name;
Username;
Email address;
Telephone number;
Country, language, and time zone;
Account credentials in protected form;
Profile photograph;
Account role and status; and
Communication preferences.
Date of birth;
Country of residence or nationality;
Identity-document information;
Business and trade registration information;
Tax information;
Professional licenses or qualifications;
Verification status; and
Fraud, sanctions, or compliance results.
Biography and professional information;
Skills, portfolio, and experience;
Seller or provider profile;
Listings and product descriptions;
Service availability;
Pricing information;
Ratings and reviews; and
Content submitted to the Platform.
Products and services ordered;
Order and transaction identifiers;
License type;
Price, currency, fees, commissions, and taxes;
Billing and invoice information;
Payment method and payment status;
Masked card or payment details received from payment providers;
Seller or provider earnings;
Refunds, cancellations, disputes, and chargebacks; and
Records of contractual acceptance.
Full payment-card data may be collected directly by an independent payment provider rather than Univerax, depending on the payment architecture.
Project or service requirements;
Proposals and quotations;
Appointment date, time, and time zone;
Session duration and delivery method;
Customer-provided materials;
Completion and revision information;
Cancellation, rescheduling, and no-show records; and
Related communications.
Messages sent through Platform tools;
Support tickets;
Complaints and dispute records;
Emails and attachments;
Reports about users, listings, or transactions; and
Security and service notifications.
IP address;
Device and browser information;
Operating system;
Session identifiers;
Authentication events;
Access times;
Page and feature interactions;
Referral information;
Error and performance logs;
Security and fraud indicators; and
Cookie or similar-technology identifiers.
Univerax does not intend to collect special category data through ordinary account, listing, review, or messaging functions.
Users should not submit health, biometric, genetic, political, religious, trade-union, sexual-life, or other specially protected information unless a specific and lawful feature expressly requires it.
Before any feature processes special category data, Univerax should identify an applicable Article 9 condition, provide specific information, implement appropriate safeguards, and conduct any required assessment.
We may obtain personal data:
Directly from you;
From your activity on the Platform;
From buyers, sellers, authors, or service providers involved in a transaction;
From payment and payout providers;
From identity and compliance verification providers;
From security and fraud-prevention providers;
From a third-party account you choose to connect;
From public sources where lawful; or
From authorities and other parties where permitted or required by law.
Where Article 14 of the GDPR applies because personal data was not collected directly from you, we will provide the required information within the applicable period unless a lawful exception applies.
We process personal data only where an appropriate legal basis applies.
Purpose
Types of data
Potential legal basis
Creating and managing an account
Account, contact, profile and authentication data
Contract; steps before entering into a contract
Providing marketplace functions
Account, listing, transaction, service request and communication data
Contract; legitimate interests
Processing orders and bookings
Transaction, payment, billing and booking data
Contract; legal obligation
Coordinating payments and payouts
Transaction, payment, verification and settlement data
Contract; legal obligation; legitimate interests
Delivering digital access
Account, order, license and access data
Contract
Providing customer support
Account, transaction, communication and support data
Contract; legitimate interests
Preventing fraud and securing the Platform
Technical, security, identity, transaction and communication data
Legitimate interests; legal obligation
Moderating content and enforcing rules
Profile, listing, content, review, communication and complaint data
Legitimate interests; legal obligation
Maintaining tax and accounting records
Identity, business, invoice, transaction and payout data
Legal obligation
Handling legal claims and disputes
Account, transaction, communication, verification and complaint data
Legitimate interests; legal claims
Improving Platform performance
Technical, usage, error and aggregated data
Legitimate interests; consent where required
Optional analytics
Cookie, device and usage data
Consent where required
Marketing communications
Contact, preference and engagement data
Consent or another lawful basis where permitted
Optional integrations
Data required for the selected integration
Consent, contract, or legitimate interests depending on the feature
The precise legal basis must be confirmed for each actual processing activity.
Where we rely on legitimate interests, those interests may include:
Operating and improving the Platform;
Protecting users and transactions;
Preventing fraud and abuse;
Maintaining network and information security;
Providing support;
Enforcing Platform rules;
Protecting legal rights; and
Maintaining appropriate business records.
Before relying on legitimate interests, Univerax should assess the necessity of the processing and balance its interests against the rights and reasonable expectations of affected individuals.
Some personal data is required to:
Create and maintain an account;
Enter into or perform a marketplace transaction;
Deliver a product or service;
Process a payment or provider payout;
Verify a seller or provider;
Issue transaction or tax records;
Prevent fraud; or
Comply with law.
Where information is required, the relevant form or notice should explain whether providing it is mandatory and the possible consequences of not providing it.
Failure to provide necessary information may prevent Univerax or another transaction party from creating an account, processing an order, delivering a service, making a payout, or complying with a legal obligation.
Where processing is based on consent:
Consent will be requested through a clear affirmative action;
The request will be separate from unrelated contractual acceptance;
Consent will be specific to the relevant purpose;
Optional choices will not be preselected;
Refusing consent will not prevent access to an unrelated service unless the processing is genuinely necessary for that service; and
Consent may be withdrawn as easily as it was given.
Withdrawal does not affect the lawfulness of processing performed before withdrawal.
Consent is not the legal basis for every processing activity. Processing necessary to perform a contract, comply with law, protect legitimate interests, or establish legal claims may continue where the relevant legal basis remains valid.
Personal data may be shared with:
Buyers, sellers, authors, or service providers involved in a transaction;
Hosting and cloud infrastructure providers;
Payment gateways, banks, card networks, and payout providers;
Identity, compliance, and fraud-prevention providers;
Email and notification providers;
Customer-support providers;
Security, monitoring, and backup providers;
Analytics providers, if activated and lawfully enabled;
Communication, meeting, or functional integration providers, if activated;
Legal, accounting, audit, insurance, and professional advisers;
Corporate transaction parties under appropriate safeguards; and
Courts, regulators, law-enforcement bodies, or authorities where legally required.
Service providers acting as processors must be subject to appropriate data-processing terms as required by Article 28 of the GDPR.
A recipient acting as an independent controller processes personal data under its own legal responsibilities and privacy information.
Univerax may use providers or infrastructure located outside the EEA or United Kingdom.
Where personal data subject to the EU GDPR or UK GDPR is transferred to a country not recognized as providing an adequate level of protection, we will use an appropriate transfer mechanism where required, such as:
European Commission Standard Contractual Clauses;
The applicable UK International Data Transfer Agreement or UK Addendum;
Binding Corporate Rules;
Another approved safeguard; or
A limited statutory derogation where legally available.
Where appropriate, Univerax will assess the laws and practices of the destination country and implement supplementary contractual, technical, or organizational safeguards.
Information about applicable transfer safeguards may be requested through [PRIVACY EMAIL OR REQUEST FORM], subject to necessary confidentiality protections.
Transfers from Türkiye may simultaneously require compliance with the Turkish Personal Data Protection Law and its international-transfer rules.
Personal data will be retained only for as long as necessary for the relevant purpose.
Retention decisions may consider:
Account duration;
Contract performance;
Digital access or support commitments;
Tax, accounting, consumer, and electronic commerce requirements;
Payment, refund, and chargeback periods;
Fraud and security risks;
Complaint and dispute periods;
Applicable limitation periods;
Legal claims;
Regulatory requests; and
Backup and recovery cycles.
When data is no longer required, it will be deleted, anonymized, or otherwise handled according to applicable law and Univerax’s retention procedures.
Closing an account does not require the immediate deletion of information that must be retained for legal compliance, completed transactions, fraud prevention, dispute resolution, or legal claims.
A category-specific retention schedule should be made available or summarized once the actual data inventory and statutory periods have been confirmed.
Univerax uses appropriate technical and organizational measures designed to protect personal data.
Depending on the nature and risk of processing, these may include:
Access and authorization controls;
Protected password storage;
Encryption in transit and, where appropriate, at rest;
Logging and security monitoring;
Backup and recovery procedures;
Vulnerability management;
Incident-response processes;
Vendor and processor controls;
Confidentiality obligations; and
Staff access restrictions.
Security measures will be reviewed in light of the nature, scope, context, and purposes of processing and the risks to individuals.
No internet-based system can guarantee absolute security. Users should protect their login credentials and promptly report suspected unauthorized access.
When developing or materially changing Platform features, Univerax will seek to apply data-protection principles such as:
Lawfulness, fairness, and transparency;
Purpose limitation;
Data minimization;
Accuracy;
Storage limitation;
Integrity and confidentiality; and
Accountability.
Where processing is likely to create a high risk to individual rights and freedoms, Univerax will assess whether a Data Protection Impact Assessment is required before the processing begins.
Univerax may use automated tools to support:
Fraud and security detection;
Content moderation;
Search and ranking;
Recommendations;
Transaction-risk review;
Account protection; or
Platform analytics.
Unless separately disclosed, these tools are not intended to make decisions based solely on automated processing that produce legal or similarly significant effects.
If such decision-making is introduced, Univerax will provide the information required by law, including meaningful information about the logic involved, the significance and expected consequences, and any applicable right to request human intervention or contest the decision.
Subject to applicable conditions and exceptions, you may have the right to:
You have the right to receive clear information about how your personal data is processed.
You may request confirmation of whether personal data concerning you is processed and obtain access to that data and related information.
You may request correction of inaccurate data and completion of incomplete data.
You may request deletion of personal data where a legal ground for erasure applies.
This right may not apply where processing remains necessary for legal compliance, freedom of expression, public-interest purposes, or legal claims.
You may request restriction of processing in circumstances provided by law, including while the accuracy or lawfulness of processing is being assessed.
Where processing is based on consent or contract and is carried out by automated means, you may request certain personal data in a structured, commonly used, machine-readable format and may have the right to transmit it to another controller.
You may object to processing based on legitimate interests or a public-interest task based on your particular situation.
You may object to direct marketing at any time. Personal data will no longer be processed for direct marketing after a valid objection.
Where applicable, you may have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to statutory exceptions.
Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
You may submit a complaint to the competent data-protection supervisory authority, particularly in the EEA or UK country where you live, work, or believe an infringement occurred.
A list of EEA supervisory authorities is available through the European Data Protection Board. UK complaints may be submitted to the UK Information Commissioner’s Office where the UK GDPR applies.
Requests may be submitted through:
Privacy Email: [PRIVACY EMAIL]
Privacy Request Form: [PRIVACY REQUEST FORM URL]
Postal Address: [PRIVACY REQUEST POSTAL ADDRESS]
EEA Representative: [EEA REPRESENTATIVE CONTACT, IF APPLICABLE]
UK Representative: [UK REPRESENTATIVE CONTACT, IF APPLICABLE]
Please describe the request and identify the relevant account, transaction, or processing activity.
We may request information reasonably necessary to:
Verify your identity;
Confirm your authority to act for another person;
Locate the relevant records; and
Protect personal data against unauthorized disclosure.
We will respond within the period required by applicable law. Under the GDPR, this will generally be within one month, subject to legally permitted extensions for complex or numerous requests.
Requests are generally handled without charge. A reasonable fee may be charged, or a request may be refused, where permitted by law because it is manifestly unfounded or excessive.
The Platform is not intended for children below [MINIMUM AGE] unless a specific service expressly allows their participation and the required parental authorization and safeguards are implemented.
If consent is relied upon for an online service offered directly to a child, the applicable age and parental authorization requirements must be determined according to the relevant EEA or UK law.
If you believe that a child’s personal data has been processed contrary to applicable requirements, contact [PRIVACY EMAIL].
Essential cookies may be used to operate and secure the Platform or provide a function requested by the user.
Optional analytics, functional, or advertising technologies will be managed according to applicable consent requirements.
The use of the Platform or acceptance of the Terms of Use does not by itself constitute consent to optional cookies.
For further information and preference controls, review the Cookie Policy and use:
Cookie Settings: [COOKIE SETTINGS LINK]
We may update this Notice to reflect changes in:
Applicable law or regulatory guidance;
Platform functionality;
Processing activities;
Service providers;
International transfer arrangements; or
Privacy governance practices.
The updated Notice will identify its effective date. Where required, we will provide additional notice or obtain consent before beginning a new processing activity.
Publication of an updated Notice does not replace consent where consent is legally required.
Questions about this GDPR Notice or the processing of personal data may be sent to:
Controller: [COMPANY LEGAL NAME]
Registered Address: [REGISTERED ADDRESS]
Privacy Email: [PRIVACY EMAIL]
Privacy Request Form: [PRIVACY REQUEST FORM URL]
Data Protection Officer: [DPO DETAILS, IF APPLICABLE]
EEA Representative: [EEA REPRESENTATIVE DETAILS, IF APPLICABLE]
UK Representative: [UK REPRESENTATIVE DETAILS, IF APPLICABLE]