Protect your brand's authenticity — Start free · KVKK compliant · EU-registered company

Privacy Policy

SahteAvcı · sahteavci.com website and extension · version of 1 July 2026

1. Data controller

This Policy covers the sahteavci.com website, the forms available on it, and the «SahteAvcı» Chrome browser extension, which helps detect potentially counterfeit products on Trendyol, Hepsiburada, n11, Amazon.com.tr, Dolap and Çiçeksepeti.

This Policy is general in nature. The notice required under Article 10 of Law No. 6698 (Aydınlatma Metni) and the Explicit Consent Text (Açık Rıza Metni) are issued as separate documents and presented independently of one another, in accordance with Principle Decision No. 2026/347 of the Turkish Personal Data Protection Board dated 18 February 2026.

2. Applicable law

Where applicable law affords the data subject a higher level of protection, the higher standard applies.

3. Data processed

3.1. Data provided by the user in the extension

3.2. Data processed automatically by the extension

When the user visits a product page on one of the six supported marketplaces, the extension reads publicly available information: title, price, seller name, image addresses, brand field, description and product identifier. Processing takes place locally within the user's browser; this information is not transmitted to the controller's servers.

The extension also keeps local usage statistics — aggregate scan and detection counters — and stores the installation date to calculate the trial period. These data remain solely in the browser.

3.3. Data processed through the website

Both forms are processed by server-side scripts hosted on the sahteavci.com domain, which forward the information to the controller by email. No third-party form services are used.

3.4. Data not collected

The controller does not collect: identity document details, other than those the user provides when making an application under Article 11 of the KVKK; payment card details; browsing history outside the six supported marketplaces; device identifiers, fingerprinting data or telemetry. Special categories of personal data under Article 6 of the KVKK are not processed.

4. Data of sellers and other third parties

When scanning listings, the extension processes information relating to marketplace sellers: the seller's name or trade name, listing content, images and materials the user includes in an evidence package. Some of this information may constitute personal data of natural persons, including sellers registered as sole traders.

5. The BYOK model

Users obtain, pay for and hold their own API keys for artificial intelligence services. When AI features are used, the product title and description — and, for visual analysis, the product images — are transmitted directly from the user's browser to the provider the user has selected. The controller does not route, intercept or store these data and has no access to them. Keys are encrypted locally before being saved.

The controller has no contractual or agency relationship with the artificial intelligence providers. Use of the AI features is voluntary and requires separate explicit consent; the extension's core features operate without them.

6. Recipients of data

The controller does not sell personal data and does not share them with third parties for advertising purposes. Disclosure to competent public authorities and courts takes place in the cases provided for by law.

7. Cross-border transfers

Some recipients are located outside Türkiye. The Personal Data Protection Board has not published a list of countries providing an adequate level of protection, and neither an undertaking (taahhütname) nor the standard contract announced by the Board is relied upon for these transfers. Cross-border transfers are based on the separately obtained explicit consent of the data subject under Article 9 of the KVKK.

For users in the EU and the EEA, transfers to the United States rely on the EU — US Data Privacy Framework and standard contractual clauses (Art. 46 GDPR).

Withholding consent to cross-border transfer does not prevent the use of the extension's core features or the submission of enquiries through the website forms.

8. Retention and deletion

The bulk of the extension's data is stored solely in the user's browser (chrome.storage.local, IndexedDB) and is not transmitted to the controller's servers. API keys are stored in encrypted form. Users may delete all local data using the corresponding function in the extension settings, by removing the extension, or by clearing browser data.

Retention periods for data the controller actually controls are set out in section 3.3. Consent records are retained for 10 years after the end of the relationship for evidentiary purposes. Once the purpose of processing ceases to exist, and upon withdrawal of consent, data are erased, destroyed or anonymised unless another legal ground for retention applies.

9. Security and breach notification

Measures applied include: encryption of API keys (AES-256-GCM, PBKDF2, installation-specific salt); integrity verification of evidence materials using SHA-256; HTTPS-only connections; the absence of any central database of personal data; and restriction of access to the enquiries mailbox to authorised persons.

Where a breach affecting personal data is identified, the controller notifies the Turkish Personal Data Protection Board as soon as possible and no later than 72 hours after becoming aware of it, and the affected data subjects within the shortest reasonable time. The Portuguese supervisory authority (CNPD) is notified in accordance with Articles 33 and 34 of the GDPR.

10. Rights of the data subject

10.1. Rights under Article 11 of the KVKK

The data subject has the right to: learn whether their personal data are being processed; request information where processing has taken place; learn the purpose of processing and whether the data are used accordingly; know the third parties in Türkiye or abroad to whom the data are transferred; request rectification of incomplete or inaccurate data; request erasure or destruction under Article 7 of the KVKK; request that such rectification and erasure be notified to recipients; object to an adverse outcome arising solely from automated analysis; and claim compensation for damage resulting from unlawful processing.

10.2. Rights under the GDPR

For users in the EU and the EEA: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), portability (Art. 20), objection (Art. 21), rights concerning automated decisions (Art. 22), and withdrawal of consent. Complaints may be lodged with the CNPD (cnpd.pt).

10.3. How to apply

Applications may be sent to info@sahteavci.com under the subject line «KVKK Veri Sahibi Başvurusu», or by any other method set out in the Communiqué on the Procedures and Principles of Application to the Data Controller, including through a notary, via a registered electronic mail (KEP) address, or in writing to the controller's address. The application must state the applicant's name and surname, Turkish identity number (or nationality and passport number for foreign nationals), an address for service, and the subject of the request.

Requests are handled as soon as possible and within 30 days at the latest, free of charge; where the request entails an additional cost, a fee may be charged in accordance with the tariff set by the Board. If the application is rejected, the response is considered insufficient, or no response is given in time, the data subject may lodge a complaint with the Authority (kvkk.gov.tr) within 30 days of learning of the response and in any event within 60 days of the date of application.

Most rights concerning local data can be exercised directly in the extension interface: deleting data, exporting them, and changing brand information and settings.

11. Automated processing and artificial intelligence

AI features are used solely to assist in identifying listings that may involve counterfeits. The resulting probability score does not establish that a product is counterfeit, is clearly marked as generated by artificial intelligence, and must be verified by the user. Models are not trained on user data.

The controller does not take decisions concerning users or sellers based solely on automated processing and producing legal effects. The final decision always rests with the user.

12. Cookies

The extension does not use cookies. A separate Cookie Policy applies to the sahteavci.com website.

13. Minors

The service is a professional tool and is not intended for persons under 18. The controller does not knowingly collect data relating to minors. If such data are identified, please write to info@sahteavci.com and they will be deleted without delay.

14. Changes and contact

The controller may update this Policy from time to time; material changes are announced through the extension interface and the website at least 30 days in advance. Earlier versions are retained and provided on request. Contact: info@sahteavci.com. Supervisory authorities: the Turkish Personal Data Protection Authority (kvkk.gov.tr) and the CNPD (cnpd.pt).

© 2026 VENTOS ARQUEÁVEIS UNIPESSOAL LDA. All rights reserved.