Security & Privacy Commitment
Our Privacy Commitment
At BENDAİ TEKNOLOJİ ANONİM ŞİRKETİ (the “Company”, “Obiy”), protecting the privacy of the personal data and payment details of everyone who uses our Platform is an explicit commitment. It goes beyond our obligations under Turkish Personal Data Protection Law no. 6698 and related legislation: it is a promise to our users.
What we commit to
- We process your personal data only for the purposes stated in our Privacy and Personal Data Protection Policy, limited to and proportionate with those purposes.
- We never sell or rent your personal data, and we do not transfer it to third parties for marketing purposes.
- We never view, process or store your card details; payment data is transmitted directly to the licensed payment infrastructure.
- Access to your data is limited to personnel who need it to do their job and who are bound by confidentiality obligations.
- Once the statutory retention periods expire, we erase, destroy or anonymise your personal data.
- If your personal data is unlawfully disclosed, we notify both you and the Turkish Data Protection Authority within the period prescribed by law.
Connection Security — SSL/TLS Encryption
All traffic between you and the Obiy website or mobile application is encrypted end to end with the industry-standard SSL/TLS protocol, so the information exchanged cannot be read or altered by the networks in between.
- The entire site is served over HTTPS; requests arriving over HTTP are automatically redirected to the secure connection.
- A valid SSL certificate is in place — you can verify it and its validity period at any time by clicking the padlock icon in your browser's address bar.
- Session data and form submissions (sign-in, sign-up and the contact form included) travel only over the encrypted connection.
- Your passwords are never stored in plain text; only irreversible hash values are kept.
Payment Security — 3D Secure and PCI DSS
Payments for digital services made through the Platform are collected by credit or debit card on the Akbank T.A.Ş. virtual POS infrastructure. Transactions are carried out in line with the security standards of the card schemes (Visa, Mastercard, Troy) and the requirements of PCI DSS (Payment Card Industry Data Security Standard). Usage-right packages in the mobile application are instead bought by in-app purchase through the Apple App Store and Google Play infrastructures; for those payments your card details are handled directly by the relevant store and no card data reaches Obiy.
3D Secure verification
- Card payments are completed with 3D Secure verification (Verified by Visa / Mastercard Identity Check).
- At the payment step you are redirected to your bank's own secure page to enter your card details, and the transaction is confirmed with the one-time code your bank sends you.
- No amount is charged until verification is complete — an additional layer of protection against unauthorised use of your card.
- Only a “success / failure” result and a transaction reference are returned to Obiy.
We Do Not Store Your Card Details
Obiy does not view, record or store your card number, expiry date, CVV/CVC security code or 3D Secure verification code. That data is processed solely between the payment institution and your bank, over encrypted channels.
- For an order, our systems keep only payment result data such as the amount, the date, the transaction reference and the last four digits of the card.
- Obiy staff can never see your card details, and we never request card information by phone, e-mail or chat.
- Any request that reaches you in Obiy's name asking for a card number, password or verification code is fraudulent — please report it to info@obiyai.com.
System and Data Security
In line with Article 12 of the Turkish Personal Data Protection Law, we take the administrative and technical measures needed to provide an appropriate level of security, preventing unlawful processing of and access to your personal data and ensuring its safekeeping.
- Access control: system access is restricted on a role basis and access rights are reviewed regularly.
- Encryption: data is encrypted both in transit and at rest.
- Logging: system access and critical operations are logged, and unusual activity is monitored.
- Backups: data is backed up regularly and backups are protected in a separate environment.
- Confidentiality: all personnel and suppliers with access to data are bound by confidentiality agreements.
- Patching: the software components we use are kept up to date with security patches.
How to Protect Your Account
Security is a shared responsibility. We recommend the following simple precautions to keep your account safe:
- Choose a strong, unique password for your Obiy account that you do not use on any other service.
- Never share your password or verification codes with anyone — not even with someone contacting you on Obiy's behalf.
- Sign out when you have finished on a shared device.
- When paying, make sure the padlock icon and the obiyai.com domain are shown in your browser's address bar.
- Contact us immediately if you notice a suspicious e-mail, message or transaction.
Reporting a Vulnerability
If you believe you have found a security vulnerability on our Platform, please send your findings to info@obiyai.com. We review reports as quickly as possible and will get back to you.
To help us assess your report, please describe step by step how the issue can be reproduced, and allow us a reasonable period to fix it before disclosing it publicly.
Updates to This Policy
This Security & Privacy Commitment may be revised from time to time to reflect legislative changes and updates to our technical infrastructure. The current text is always published on this page, and the date at the top shows when it was last updated.
For details on how your personal data is processed, see our Privacy and Data Protection page; for the terms governing use of the Platform, see the Terms of Use.