Discover digital products, expert services, consulting, training and new opportunities on Univerax. Explore Univerax >>

GDPR Policy

GDPR Data Protection Notice

Effective Date: [EFFECTIVE DATE]
Last Updated: [LAST UPDATED DATE]

This GDPR Data Protection Notice (“GDPR Notice”) provides additional information about how [COMPANY LEGAL NAME] (“Univerax,” “we,” “us,” or “our”) processes personal data where the European Union General Data Protection Regulation (“EU GDPR”), the United Kingdom General Data Protection Regulation (“UK GDPR”), or related data-protection legislation applies.

This Notice supplements the Univerax Privacy Policy. It does not replace the Privacy Policy, Cookie Policy, transaction-specific notices, or any other privacy information provided when personal data is collected.

If there is a conflict between this Notice and the general Privacy Policy concerning processing governed by the EU GDPR or UK GDPR, this Notice will apply to that processing to the extent required by applicable law.

1. When This Notice Applies

This Notice may apply when:

Personal data is processed in connection with an establishment of Univerax in the European Economic Area (“EEA”) or United Kingdom;

Univerax offers products or services to individuals located in the EEA or United Kingdom;

Univerax monitors the behavior of individuals in the EEA or United Kingdom, to the extent that behavior takes place there; or

Another applicable rule brings the relevant processing activity within the scope of the EU GDPR or UK GDPR.

GDPR applicability is determined by the circumstances of the processing activity and not solely by an individual’s citizenship or nationality.

2. Data Controller

Unless a specific notice states otherwise, the controller responsible for the processing covered by this Notice is:

Controller: [COMPANY LEGAL NAME]
Registered Address: [REGISTERED ADDRESS]
Privacy Email: [PRIVACY EMAIL]
Privacy Request Form: [PRIVACY REQUEST FORM URL]
Data Protection Officer: [DPO DETAILS, IF APPLICABLE]

EEA Representative

If Univerax is required to appoint a representative under Article 27 of the EU GDPR:

EEA Representative: [EEA REPRESENTATIVE NAME]
Address: [EEA REPRESENTATIVE ADDRESS]
Email: [EEA REPRESENTATIVE EMAIL]

UK Representative

If Univerax is required to appoint a representative under the UK GDPR:

UK Representative: [UK REPRESENTATIVE NAME]
Address: [UK REPRESENTATIVE ADDRESS]
Email: [UK REPRESENTATIVE EMAIL]

The requirement to appoint a representative or Data Protection Officer depends on Univerax’s establishment, processing activities, scale, and applicable exemptions.

3. Independent Sellers and Service Providers

Univerax operates a marketplace through which independent sellers, authors, experts, and service providers may offer products or services.

An independent seller or provider may act as a separate controller when it determines the purposes and means of processing personal data, including when it:

Communicates with a customer;

Delivers a purchased product or service;

Manages a booking or appointment;

Issues an invoice;

Maintains legally required business records; or

Complies with its own professional or regulatory duties.

The relevant seller or provider should give users appropriate information about its independent processing activities.

Univerax may separately process the same transaction data for Platform operation, payment coordination, safety, support, legal compliance, and dispute resolution.

The precise controller, joint-controller, or processor roles must be determined according to the actual data flow and contractual arrangements rather than the parties’ commercial labels alone.

4. Categories of Personal Data

Depending on how you use the Platform, we may process:

4.1 Account and Contact Data

Name;

Username;

Email address;

Telephone number;

Country, language, and time zone;

Account credentials in protected form;

Profile photograph;

Account role and status; and

Communication preferences.

4.2 Identity and Compliance Data

Date of birth;

Country of residence or nationality;

Identity-document information;

Business and trade registration information;

Tax information;

Professional licenses or qualifications;

Verification status; and

Fraud, sanctions, or compliance results.

4.3 Profile and Marketplace Data

Biography and professional information;

Skills, portfolio, and experience;

Seller or provider profile;

Listings and product descriptions;

Service availability;

Pricing information;

Ratings and reviews; and

Content submitted to the Platform.

4.4 Transaction and Payment Data

Products and services ordered;

Order and transaction identifiers;

License type;

Price, currency, fees, commissions, and taxes;

Billing and invoice information;

Payment method and payment status;

Masked card or payment details received from payment providers;

Seller or provider earnings;

Refunds, cancellations, disputes, and chargebacks; and

Records of contractual acceptance.

Full payment-card data may be collected directly by an independent payment provider rather than Univerax, depending on the payment architecture.

4.5 Service Request and Booking Data

Project or service requirements;

Proposals and quotations;

Appointment date, time, and time zone;

Session duration and delivery method;

Customer-provided materials;

Completion and revision information;

Cancellation, rescheduling, and no-show records; and

Related communications.

4.6 Communications and Support Data

Messages sent through Platform tools;

Support tickets;

Complaints and dispute records;

Emails and attachments;

Reports about users, listings, or transactions; and

Security and service notifications.

4.7 Technical and Usage Data

IP address;

Device and browser information;

Operating system;

Session identifiers;

Authentication events;

Access times;

Page and feature interactions;

Referral information;

Error and performance logs;

Security and fraud indicators; and

Cookie or similar-technology identifiers.

4.8 Special Category Data

Univerax does not intend to collect special category data through ordinary account, listing, review, or messaging functions.

Users should not submit health, biometric, genetic, political, religious, trade-union, sexual-life, or other specially protected information unless a specific and lawful feature expressly requires it.

Before any feature processes special category data, Univerax should identify an applicable Article 9 condition, provide specific information, implement appropriate safeguards, and conduct any required assessment.

5. Sources of Personal Data

We may obtain personal data:

Directly from you;

From your activity on the Platform;

From buyers, sellers, authors, or service providers involved in a transaction;

From payment and payout providers;

From identity and compliance verification providers;

From security and fraud-prevention providers;

From a third-party account you choose to connect;

From public sources where lawful; or

From authorities and other parties where permitted or required by law.

Where Article 14 of the GDPR applies because personal data was not collected directly from you, we will provide the required information within the applicable period unless a lawful exception applies.

6. Purposes and Legal Bases

We process personal data only where an appropriate legal basis applies.

Purpose

Types of data

Potential legal basis

Creating and managing an account

Account, contact, profile and authentication data

Contract; steps before entering into a contract

Providing marketplace functions

Account, listing, transaction, service request and communication data

Contract; legitimate interests

Processing orders and bookings

Transaction, payment, billing and booking data

Contract; legal obligation

Coordinating payments and payouts

Transaction, payment, verification and settlement data

Contract; legal obligation; legitimate interests

Delivering digital access

Account, order, license and access data

Contract

Providing customer support

Account, transaction, communication and support data

Contract; legitimate interests

Preventing fraud and securing the Platform

Technical, security, identity, transaction and communication data

Legitimate interests; legal obligation

Moderating content and enforcing rules

Profile, listing, content, review, communication and complaint data

Legitimate interests; legal obligation

Maintaining tax and accounting records

Identity, business, invoice, transaction and payout data

Legal obligation

Handling legal claims and disputes

Account, transaction, communication, verification and complaint data

Legitimate interests; legal claims

Improving Platform performance

Technical, usage, error and aggregated data

Legitimate interests; consent where required

Optional analytics

Cookie, device and usage data

Consent where required

Marketing communications

Contact, preference and engagement data

Consent or another lawful basis where permitted

Optional integrations

Data required for the selected integration

Consent, contract, or legitimate interests depending on the feature

The precise legal basis must be confirmed for each actual processing activity.

Where we rely on legitimate interests, those interests may include:

Operating and improving the Platform;

Protecting users and transactions;

Preventing fraud and abuse;

Maintaining network and information security;

Providing support;

Enforcing Platform rules;

Protecting legal rights; and

Maintaining appropriate business records.

Before relying on legitimate interests, Univerax should assess the necessity of the processing and balance its interests against the rights and reasonable expectations of affected individuals.

7. Contractual and Statutory Requirements

Some personal data is required to:

Create and maintain an account;

Enter into or perform a marketplace transaction;

Deliver a product or service;

Process a payment or provider payout;

Verify a seller or provider;

Issue transaction or tax records;

Prevent fraud; or

Comply with law.

Where information is required, the relevant form or notice should explain whether providing it is mandatory and the possible consequences of not providing it.

Failure to provide necessary information may prevent Univerax or another transaction party from creating an account, processing an order, delivering a service, making a payout, or complying with a legal obligation.

8. Consent

Where processing is based on consent:

Consent will be requested through a clear affirmative action;

The request will be separate from unrelated contractual acceptance;

Consent will be specific to the relevant purpose;

Optional choices will not be preselected;

Refusing consent will not prevent access to an unrelated service unless the processing is genuinely necessary for that service; and

Consent may be withdrawn as easily as it was given.

Withdrawal does not affect the lawfulness of processing performed before withdrawal.

Consent is not the legal basis for every processing activity. Processing necessary to perform a contract, comply with law, protect legitimate interests, or establish legal claims may continue where the relevant legal basis remains valid.

9. Recipients of Personal Data

Personal data may be shared with:

Buyers, sellers, authors, or service providers involved in a transaction;

Hosting and cloud infrastructure providers;

Payment gateways, banks, card networks, and payout providers;

Identity, compliance, and fraud-prevention providers;

Email and notification providers;

Customer-support providers;

Security, monitoring, and backup providers;

Analytics providers, if activated and lawfully enabled;

Communication, meeting, or functional integration providers, if activated;

Legal, accounting, audit, insurance, and professional advisers;

Corporate transaction parties under appropriate safeguards; and

Courts, regulators, law-enforcement bodies, or authorities where legally required.

Service providers acting as processors must be subject to appropriate data-processing terms as required by Article 28 of the GDPR.

A recipient acting as an independent controller processes personal data under its own legal responsibilities and privacy information.

10. International Data Transfers

Univerax may use providers or infrastructure located outside the EEA or United Kingdom.

Where personal data subject to the EU GDPR or UK GDPR is transferred to a country not recognized as providing an adequate level of protection, we will use an appropriate transfer mechanism where required, such as:

European Commission Standard Contractual Clauses;

The applicable UK International Data Transfer Agreement or UK Addendum;

Binding Corporate Rules;

Another approved safeguard; or

A limited statutory derogation where legally available.

Where appropriate, Univerax will assess the laws and practices of the destination country and implement supplementary contractual, technical, or organizational safeguards.

Information about applicable transfer safeguards may be requested through [PRIVACY EMAIL OR REQUEST FORM], subject to necessary confidentiality protections.

Transfers from Türkiye may simultaneously require compliance with the Turkish Personal Data Protection Law and its international-transfer rules.

11. Data Retention

Personal data will be retained only for as long as necessary for the relevant purpose.

Retention decisions may consider:

Account duration;

Contract performance;

Digital access or support commitments;

Tax, accounting, consumer, and electronic commerce requirements;

Payment, refund, and chargeback periods;

Fraud and security risks;

Complaint and dispute periods;

Applicable limitation periods;

Legal claims;

Regulatory requests; and

Backup and recovery cycles.

When data is no longer required, it will be deleted, anonymized, or otherwise handled according to applicable law and Univerax’s retention procedures.

Closing an account does not require the immediate deletion of information that must be retained for legal compliance, completed transactions, fraud prevention, dispute resolution, or legal claims.

A category-specific retention schedule should be made available or summarized once the actual data inventory and statutory periods have been confirmed.

12. Data Security

Univerax uses appropriate technical and organizational measures designed to protect personal data.

Depending on the nature and risk of processing, these may include:

Access and authorization controls;

Protected password storage;

Encryption in transit and, where appropriate, at rest;

Logging and security monitoring;

Backup and recovery procedures;

Vulnerability management;

Incident-response processes;

Vendor and processor controls;

Confidentiality obligations; and

Staff access restrictions.

Security measures will be reviewed in light of the nature, scope, context, and purposes of processing and the risks to individuals.

No internet-based system can guarantee absolute security. Users should protect their login credentials and promptly report suspected unauthorized access.

13. Data Protection by Design and Default

When developing or materially changing Platform features, Univerax will seek to apply data-protection principles such as:

Lawfulness, fairness, and transparency;

Purpose limitation;

Data minimization;

Accuracy;

Storage limitation;

Integrity and confidentiality; and

Accountability.

Where processing is likely to create a high risk to individual rights and freedoms, Univerax will assess whether a Data Protection Impact Assessment is required before the processing begins.

14. Automated Decision-Making and Profiling

Univerax may use automated tools to support:

Fraud and security detection;

Content moderation;

Search and ranking;

Recommendations;

Transaction-risk review;

Account protection; or

Platform analytics.

Unless separately disclosed, these tools are not intended to make decisions based solely on automated processing that produce legal or similarly significant effects.

If such decision-making is introduced, Univerax will provide the information required by law, including meaningful information about the logic involved, the significance and expected consequences, and any applicable right to request human intervention or contest the decision.

15. Your GDPR Rights

Subject to applicable conditions and exceptions, you may have the right to:

15.1 Right to Be Informed

You have the right to receive clear information about how your personal data is processed.

15.2 Right of Access

You may request confirmation of whether personal data concerning you is processed and obtain access to that data and related information.

15.3 Right to Rectification

You may request correction of inaccurate data and completion of incomplete data.

15.4 Right to Erasure

You may request deletion of personal data where a legal ground for erasure applies.

This right may not apply where processing remains necessary for legal compliance, freedom of expression, public-interest purposes, or legal claims.

15.5 Right to Restriction

You may request restriction of processing in circumstances provided by law, including while the accuracy or lawfulness of processing is being assessed.

15.6 Right to Data Portability

Where processing is based on consent or contract and is carried out by automated means, you may request certain personal data in a structured, commonly used, machine-readable format and may have the right to transmit it to another controller.

15.7 Right to Object

You may object to processing based on legitimate interests or a public-interest task based on your particular situation.

You may object to direct marketing at any time. Personal data will no longer be processed for direct marketing after a valid objection.

15.8 Rights Concerning Automated Decisions

Where applicable, you may have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to statutory exceptions.

15.9 Right to Withdraw Consent

Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.

15.10 Right to Complain

You may submit a complaint to the competent data-protection supervisory authority, particularly in the EEA or UK country where you live, work, or believe an infringement occurred.

A list of EEA supervisory authorities is available through the European Data Protection Board. UK complaints may be submitted to the UK Information Commissioner’s Office where the UK GDPR applies.

16. Exercising Your Rights

Requests may be submitted through:

Privacy Email: [PRIVACY EMAIL]
Privacy Request Form: [PRIVACY REQUEST FORM URL]
Postal Address: [PRIVACY REQUEST POSTAL ADDRESS]
EEA Representative: [EEA REPRESENTATIVE CONTACT, IF APPLICABLE]
UK Representative: [UK REPRESENTATIVE CONTACT, IF APPLICABLE]

Please describe the request and identify the relevant account, transaction, or processing activity.

We may request information reasonably necessary to:

Verify your identity;

Confirm your authority to act for another person;

Locate the relevant records; and

Protect personal data against unauthorized disclosure.

We will respond within the period required by applicable law. Under the GDPR, this will generally be within one month, subject to legally permitted extensions for complex or numerous requests.

Requests are generally handled without charge. A reasonable fee may be charged, or a request may be refused, where permitted by law because it is manifestly unfounded or excessive.

17. Children

The Platform is not intended for children below [MINIMUM AGE] unless a specific service expressly allows their participation and the required parental authorization and safeguards are implemented.

If consent is relied upon for an online service offered directly to a child, the applicable age and parental authorization requirements must be determined according to the relevant EEA or UK law.

If you believe that a child’s personal data has been processed contrary to applicable requirements, contact [PRIVACY EMAIL].

18. Cookies and Similar Technologies

Essential cookies may be used to operate and secure the Platform or provide a function requested by the user.

Optional analytics, functional, or advertising technologies will be managed according to applicable consent requirements.

The use of the Platform or acceptance of the Terms of Use does not by itself constitute consent to optional cookies.

For further information and preference controls, review the Cookie Policy and use:

Cookie Settings: [COOKIE SETTINGS LINK]

19. Changes to This Notice

We may update this Notice to reflect changes in:

Applicable law or regulatory guidance;

Platform functionality;

Processing activities;

Service providers;

International transfer arrangements; or

Privacy governance practices.

The updated Notice will identify its effective date. Where required, we will provide additional notice or obtain consent before beginning a new processing activity.

Publication of an updated Notice does not replace consent where consent is legally required.

20. Contact

Questions about this GDPR Notice or the processing of personal data may be sent to:

Controller: [COMPANY LEGAL NAME]
Registered Address: [REGISTERED ADDRESS]
Privacy Email: [PRIVACY EMAIL]
Privacy Request Form: [PRIVACY REQUEST FORM URL]
Data Protection Officer: [DPO DETAILS, IF APPLICABLE]
EEA Representative: [EEA REPRESENTATIVE DETAILS, IF APPLICABLE]
UK Representative: [UK REPRESENTATIVE DETAILS, IF APPLICABLE]

Deneyiminizi kişiselleştirmek için çerezler kullanıyoruz. Bu web sitesini ziyaret etmeye devam ederek çerez kullanımımızı kabul etmiş olursunuz

Daha Fazla