1. Scope of this policy
This Privacy and KVKK Policy sets out how Atom Sigorta Insurance Brokerage Services processes personal data in the course of its insurance agency activities. It covers individuals who visit the website at https://atomsigorta.com, contact us by WhatsApp, phone or email, visit our office, or take out a policy through our agency.
Commercial information belonging to companies is not personal data under the KVKK, but the data of the authorised representatives and employees who act on a company’s behalf is covered by this Policy. Where the policyholder and the insured are different people, the party who shares a third person’s information with us confirms that they have informed that person.
2. Who the data controller is
Under the KVKK, your personal data is processed by our agency, acting as data controller, whose details are set out below.
- Registered name
- Atom Sigorta Insurance Brokerage Services
- Business activity
- Insurance agency services
- Address
- Cumhuriyet Mah. Rıhtım Sk. No: 12 Daire: 5, Üsküdar, Istanbul
- Phone
- 0850 303 28 66
- Website
- https://atomsigorta.com
3. Categories of personal data we process
Depending on the insurance product you ask for and the nature of our relationship, we process only the categories below that are actually needed. Not every product requires every type of data.
Identity data
First name, surname, Turkish national ID number, date of birth, gender, nationality.
Contact data
Mobile number, landline number, email address, postal address.
Customer transaction data
The content of your quote request, requests you send us by WhatsApp, email or phone, policy and endorsement records, renewal dates, claim file details, request and complaint records.
Financial data
Premium amount, payment plan and payment status, invoice details. We do not store payment instrument details such as card numbers.
Vehicle and property data
Number plate, registration and licence details, the address of the property to be insured, building and floor area details, national address database (UAVT) code.
Health data (special category)
Only for health and life insurance requests: the medical history you declare and any health declaration the insurance company asks for.
Transaction security data
IP address, browser and device information, records of how you browse our website.
Marketing data
With your explicit consent: your communication preferences and records of campaign and information messages sent to you.
Health data is a special category of personal data within the meaning of Article 6 of the KVKK. We process it only for your health and life insurance requests, with your explicit consent or in the cases provided for by law, and protect it with separate access restrictions.
4. How we collect personal data
Your personal data is obtained wholly or partly by automated means, or by non-automated means as part of a data filing system, through the following channels:
- You send us a message or share documents through our WhatsApp line,
- You call us, or we call you,
- You write to us by email,
- You visit our office, speak to us in person and share documents,
- Transactions are carried out on the agency portals of the insurance companies we work with during the policy process,
- Records are kept automatically through cookies and similar technologies used on our website.
5. Why we process personal data
We process your data only for the purposes below, and only as far as they require:
- Preparing insurance quotes and comparing cover and premiums,
- Issuing policies and handling endorsements, cancellations and renewals,
- Receiving claim notifications and following up the claim with the insurance company,
- Collecting premiums, tracking payments and keeping accounting records,
- Meeting the information and record-keeping obligations arising from insurance legislation,
- Reviewing and resolving requests, suggestions and complaints,
- Reminding you when your policy is about to expire and offering a renewal quote,
- Responding to requests from authorised public bodies within the framework of the law,
- Exercising our right of defence in legal disputes and preserving evidence,
- Keeping our website secure and improving your experience of using it,
- Sending campaigns, announcements and information, where you have given explicit consent.
6. Legal grounds for processing
The processing carried out for the purposes above relies on the following legal grounds listed in Article 5 of the KVKK:
Expressly provided for by law
The record-keeping and reporting obligations placed on agencies by insurance legislation, tax legislation and related secondary regulations.
Entering into or performing a contract
Processing your data is necessary to respond to your quote request, issue your policy and carry out the transactions relating to it.
Complying with a legal obligation
Reporting to the competent authorities, retention and disclosure obligations, and meeting our financial and administrative obligations.
Establishing, exercising or protecting a right
Keeping records so that claims and defences can be proven in any dispute that may arise.
Legitimate interest
Processing that does not harm your fundamental rights and freedoms, such as measuring service quality, sending policy renewal reminders and keeping the website secure.
Where none of the legal grounds in the law applies, for example when sending commercial electronic messages or processing special category health data, we ask for your explicit consent. You can withdraw your consent at any time; withdrawal does not affect processing that was lawfully carried out before it.
7. Sharing your personal data
Provided it stays within the purposes of processing and the necessary security measures are in place, your data may be shared with the following parties:
Insurance companies
The insurance companies we forward your quote request to and that issue your policy receive only the data needed for the quote and policy process.
Authorised public bodies
The Insurance and Private Pension Regulation and Supervision Agency, the Insurance Information and Monitoring Centre, courts, enforcement offices and other bodies authorised by law.
Our service providers
Business partners who provide services such as server and email infrastructure, archiving and office software, and who give the necessary confidentiality and security commitments.
Legal and financial advisers
Our certified public accountant, auditors if an independent audit is carried out, and our lawyers in the event of a dispute.
Messaging channel provider (WhatsApp)
When you write to us on WhatsApp, your messages and any documents you share are transmitted through the infrastructure of WhatsApp (Meta), which provides the service. This is a third-party service, so messages you send via WhatsApp are also subject to WhatsApp’s own privacy terms.
As a rule, your personal data is not transferred abroad. If a transfer abroad becomes necessary because of an infrastructure service we use, we comply with the conditions in Article 9 of the KVKK and, where required, also ask for your explicit consent. Your data is never sold or rented to third parties for marketing purposes under any circumstances.
When you choose to use WhatsApp to contact us, your messages are processed on that service’s infrastructure and under the provider’s own privacy terms; how that infrastructure operates is outside our agency’s control. Before sharing special category data such as health information, you can call us to ask which channel is most suitable.
8. Retention and destruction
We keep your personal data for as long as it is needed for the purpose it was processed for and, in any case, until the limitation periods set by law have expired. The periods below show the general framework we follow in practice:
| Type of data / record | Retention period |
|---|---|
| Policy, endorsement and claim records | 10 years from the end of the contractual relationship |
| Accounting and payment records | 10 years from the end of the relevant financial year |
| Quote requests that did not proceed | 2 years from the date of the request |
| WhatsApp, email and call records | 2 years from the date the record was created |
| Website security logs | For the period required by law |
| Marketing records based on explicit consent | Until consent is withdrawn; 3 years after withdrawal, as proof |
Once the period ends, your personal data is erased, destroyed or anonymised. Destruction is reviewed periodically and every action taken is recorded.
9. Data security measures
We take appropriate administrative and technical measures to prevent unlawful processing of and unlawful access to personal data, and to keep it safe:
- Access to personal data is granted through an authorisation matrix limited to each person’s role.
- Our staff sign a confidentiality undertaking and are briefed regularly.
- Our website is served over an SSL/TLS encrypted connection (HTTPS).
- The software we use is kept up to date, and we use a firewall and a strong password policy against unauthorised access.
- Paper documents are kept in locked cabinets, and documents due for disposal are destroyed so that they cannot be recovered.
- If a data breach is detected, the Personal Data Protection Board and the people concerned are notified within the period set by law.
10. Your rights as a data subject
Under Article 11 of the KVKK, you can apply to our agency, as data controller, to exercise the following rights:
- aFind out whether your personal data is being processed,
- bRequest information about the processing if your personal data has been processed,
- cFind out the purpose of the processing and whether your data is being used in line with that purpose,
- dKnow the third parties in Türkiye or abroad to whom your personal data has been transferred,
- eAsk for your personal data to be corrected if it is incomplete or inaccurate,
- fAsk for your personal data to be erased or destroyed under the conditions set out in Article 7 of the KVKK,
- gAsk for any correction, erasure or destruction to be notified to the third parties to whom your personal data has been transferred,
- hObject to an outcome that is against you and arises from the analysis of your data exclusively through automated systems,
- iClaim compensation for any damage you suffer because your personal data has been processed unlawfully.
11. How to apply
You can send requests about your rights in line with the Communiqué on the Procedures and Principles of Application to the Data Controller, using any of the following methods:
- In writing: Hand-deliver your signed application, or send it through a notary, to Cumhuriyet Mah. Rıhtım Sk. No: 12 Daire: 5, Üsküdar, Istanbul.
- Electronically: Send it from the email address registered with us to hakan@atomsigorta.com.
- By phone: To find out how to submit your application, call us on 0850 303 28 66.
Your application must include the following:
- Your first name, surname and, for written applications, your signature,
- Your Turkish national ID number or, for foreign nationals, your nationality and passport number,
- Your residential or business address for official notifications,
- Your email address, phone and fax number for notifications, if any,
- A clear statement of your request, together with any relevant information and documents.
We will respond to your request free of charge as soon as possible, depending on its nature, and within thirty days at the latest. If the process involves an additional cost, a fee may be charged according to the tariff set by the Personal Data Protection Board. If your application is rejected, you find our answer insufficient or we do not reply in time, you may file a complaint with the Personal Data Protection Board within thirty days of learning of our answer, and in any case within sixty days of the date of your application.
12. Use of cookies
Our website may use strictly necessary cookies that it needs to work, as well as cookies that remember your preferences and measure how the site is used. Non-essential cookies only run with your consent, and you can delete or block cookies at any time in your browser settings.
For cookie types, what they are used for and how to manage them in each browser, see our Cookie Policy.
13. Updates to this policy
We may update this Policy if the law changes, our business processes develop or the technologies we use change. The current version is always published on this page and takes effect on the date it is published. If we make material changes, we will also let you know on our website.
Last updated: September 2026
