Data Retention and Destruction Policy

This policy explains how long diji.pet retains personal data, who can access it, and how it is deleted, destroyed or anonymised when its retention period ends.

Legal name: MNG Digital Ltd
Brand: diji.pet
Company number: 17330055
Registered in: England and Wales
Istanbul office: Maslak Mah. AOS 55. Sk. 42 Maslak AVM Residence B, Sarıyer/İstanbul
Registered office: Office 403 Screenworks 22 Highbury Grove, London, United Kingdom, N5 2ER
Telephone: +90 850 840 45 61
Email: [email protected]

1. Purpose

This Data Retention and Destruction Policy describes how MNG Digital Ltd retains, deletes, destroys or anonymises personal data processed through diji.pet in line with KVKK and related legislation.

2. Scope

The policy covers the website, mobile apps, all Platform modules, pet owners, professionals, visitors, employees, candidates, suppliers and business partners.

3. Principles

  • Data is retained only for a period proportionate to the processing purpose.
  • Retention periods are determined by legal obligations, contractual needs, legitimate interests and applicable limitation periods.
  • When the purpose and applicable period end, data is securely deleted, destroyed or anonymised.
  • Processing, access and destruction actions are logged where appropriate.

4. Retention Schedule

Data categoryPurposeLegal basisPeriod
Account dataMembership and identity verificationKVKK Art. 5/2(c)While active + 2 years
Veterinary / clinic informationProfessional verification and performanceApplicable professional rules; legitimate interest10 years
Financial data, payments, invoices, Wallet movements, refunds, chargebacks, contract and audit recordsCollection, accounting and tax obligationsTurkish Commercial Code Art. 82; Tax Procedure Law Art. 25310 years
Transfer / transport dataLog-record obligationLaw No. 5651 Art. 51 year
Recruitment dataHiring assessmentKVKK Art. 5/2(c)2 years
Commercial communication consentPermission-based marketing managementLaw No. 6563Until withdrawn
Security-camera footagePhysical securityLegitimate interest30 days
AI module dataDecision-support analyticsLegitimate interestAnonymised for 1 year

5. Retention Practices

  • Expired data is reviewed and destroyed twice a year.
  • Wallet movements, top-ups, refunds and payment disputes are linked to immutable records for financial integrity; closing an account does not automatically erase records required for retention.
  • Destruction actions are documented and backed-up data follows a separate deletion process.
  • Deleted or anonymised data is made irretrievable.

6. Access and Security

Only authorised personnel may access User data and each access is logged. Access levels are managed by role. We use TLS/SSL, firewalls, IDS/IPS, RBAC, encryption, two-factor authentication, awareness training and an incident-response procedure.

7. Backups

Data is backed up daily in encrypted form on cloud servers. Critical backups are retained for 7 days and financial backups for 30 days. Backups are subject to the same security controls as production data.

8. Destruction Methods

MethodDescriptionUse
DeletionAccess is removed when an account closes.User profiles and messages
Physical destructionDestruction of physical media such as disks.Server hardware
AnonymisationData is made incapable of identifying a person.AI analytics and statistical reports

Each action is documented in a destruction report retained for 5 years.

9. Data-Breach Notification

Detected breaches are immediately reported internally, analysed and contained. Where required, the KVKK Authority and affected people are informed within 72 hours, and corrective actions are recorded.

10. Review

This policy is reviewed at least annually. Changes are approved by the responsible privacy function and audits may be carried out internally or independently.

11. Destruction Plan

In January and July each year, a list of data whose retention period has ended is prepared. Listed data is systematically deleted or anonymised and an annual destruction report is added to the KVKK records.

12. Exercising Rights

For rights under KVKK Article 11, contact [email protected]. Requests are answered within 30 days and identity verification may be requested where necessary.

13. Effective Date

This policy took effect on 26 October 2025. Employees and business partners must comply with its provisions. The Turkish text is the governing version in the event of a discrepancy.