This policy explains how long diji.pet retains personal data, who can access it, and how it is deleted, destroyed or anonymised when its retention period ends.
Legal name: MNG Digital Ltd
Brand: diji.pet
Company number: 17330055
Registered in: England and Wales
Istanbul office: Maslak Mah. AOS 55. Sk. 42 Maslak AVM Residence B, Sarıyer/İstanbul
Registered office: Office 403 Screenworks 22 Highbury Grove, London, United Kingdom, N5 2ER
Telephone: +90 850 840 45 61
Email: [email protected]
This Data Retention and Destruction Policy describes how MNG Digital Ltd retains, deletes, destroys or anonymises personal data processed through diji.pet in line with KVKK and related legislation.
The policy covers the website, mobile apps, all Platform modules, pet owners, professionals, visitors, employees, candidates, suppliers and business partners.
| Data category | Purpose | Legal basis | Period |
|---|---|---|---|
| Account data | Membership and identity verification | KVKK Art. 5/2(c) | While active + 2 years |
| Veterinary / clinic information | Professional verification and performance | Applicable professional rules; legitimate interest | 10 years |
| Financial data, payments, invoices, Wallet movements, refunds, chargebacks, contract and audit records | Collection, accounting and tax obligations | Turkish Commercial Code Art. 82; Tax Procedure Law Art. 253 | 10 years |
| Transfer / transport data | Log-record obligation | Law No. 5651 Art. 5 | 1 year |
| Recruitment data | Hiring assessment | KVKK Art. 5/2(c) | 2 years |
| Commercial communication consent | Permission-based marketing management | Law No. 6563 | Until withdrawn |
| Security-camera footage | Physical security | Legitimate interest | 30 days |
| AI module data | Decision-support analytics | Legitimate interest | Anonymised for 1 year |
Only authorised personnel may access User data and each access is logged. Access levels are managed by role. We use TLS/SSL, firewalls, IDS/IPS, RBAC, encryption, two-factor authentication, awareness training and an incident-response procedure.
Data is backed up daily in encrypted form on cloud servers. Critical backups are retained for 7 days and financial backups for 30 days. Backups are subject to the same security controls as production data.
| Method | Description | Use |
|---|---|---|
| Deletion | Access is removed when an account closes. | User profiles and messages |
| Physical destruction | Destruction of physical media such as disks. | Server hardware |
| Anonymisation | Data is made incapable of identifying a person. | AI analytics and statistical reports |
Each action is documented in a destruction report retained for 5 years.
Detected breaches are immediately reported internally, analysed and contained. Where required, the KVKK Authority and affected people are informed within 72 hours, and corrective actions are recorded.
This policy is reviewed at least annually. Changes are approved by the responsible privacy function and audits may be carried out internally or independently.
In January and July each year, a list of data whose retention period has ended is prepared. Listed data is systematically deleted or anonymised and an annual destruction report is added to the KVKK records.
For rights under KVKK Article 11, contact [email protected]. Requests are answered within 30 days and identity verification may be requested where necessary.
This policy took effect on 26 October 2025. Employees and business partners must comply with its provisions. The Turkish text is the governing version in the event of a discrepancy.