Legal

Personal Data Breach Policy

Last updated July 10, 2026

How ResReturn detects, contains, assesses, and reports personal data breaches — and who we notify, how fast, under GDPR and KVKK.

1. Scope and definitions

This Personal Data Breach Response Policy describes how ResReturn (a YourSizer product), operating at Gümüşsuyu Mahallesi İnönü Caddesi Ulusal Apt. No:5 D:5, 34437 Beyoğlu/İstanbul, Türkiye, detects, contains, assesses, and notifies personal data breaches. It is prepared in accordance with the Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and the EU General Data Protection Regulation (GDPR), including the Personal Data Protection Board's Decision No. 2019/10 on breach notification.

A personal data breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to personal data — in other words, any incident affecting the confidentiality, integrity, or availability of personal data we hold. Personal data means any information relating to an identified or identifiable natural person, such as a name, contact details, order history, return records, or account credentials.

ResReturn is a returns and exchange management platform for e-commerce merchants. For shopper data processed through the returns portal and merchant integrations (Shopify, Ticimax, ikas, and other platforms), ResReturn acts as a data processor on behalf of the merchant, who is the data controller. For data relating to our own website visitors and merchant accounts, ResReturn acts as the data controller. This dual role determines who must be notified when a breach occurs, as set out in this Policy.

2. Incident response team and responsibilities

ResReturn maintains an interdisciplinary Data Breach Response Team that takes charge from the moment a breach is suspected, coordinating containment, mitigation, and legal compliance. Its composition can be expanded or narrowed depending on the complexity and scale of the incident.

The senior management representative provides overall coordination and strategic direction, holds final decision-making authority, approves notifications and public statements, and allocates the necessary resources. The technical lead is responsible for technical detection, verification, and scoping of the breach, and coordinates system isolation, vulnerability patching, restoration, log analysis, and forensic investigation. The legal and compliance officer ensures the response complies with KVKK, GDPR, and related legislation, governs the content and timing of notifications, and assesses legal risk. The communications lead prepares clear information for affected parties and manages communication with the public and the media where necessary.

The identities and contact details of team members and external advisers are maintained in restricted-access incident contact lists and an emergency call tree, reviewed at least every six months. Depending on the incident, the team may engage external cybersecurity experts, digital forensics firms, legal advisers, or communications support. All contracts with external service providers include explicit data security, confidentiality, and breach notification obligations.

3. Detection, reporting, and initial assessment

Suspicion of a breach can arise from several sources: anomalies flagged by security monitoring and logging systems (unusual access patterns, unauthorized data transfers), reports from merchants or shoppers about suspicious account activity or apparent data exposure, notices from security researchers, integration partners, or other third parties, and findings from internal audits and vulnerability scans.

Any employee or contractor who suspects a breach must escalate it to the response team immediately. An incident record is opened at once, capturing when the incident started, how it was detected, who reported it, and the initial observations.

The technical team then verifies the suspected breach by examining logs, system metrics, security alerts, and the state of affected systems, evaluating scenarios such as unauthorized access, data leakage, lost credentials, or misuse of data. In parallel, the team works to determine the affected data categories, the estimated number of individuals involved, the systems concerned, and the time frame of the breach — information that is critical for the subsequent risk analysis and notification decisions.

4. Containment and emergency measures

The first operational goal is to stop the breach from spreading, prevent further data loss or unauthorized access, and protect system integrity. Emergency isolation measures are applied within the first hours of detection.

Depending on the incident, these measures may include immediately revoking compromised accounts, sessions, or API keys; isolating affected systems from other critical systems through network segmentation; temporarily suspending or restricting the affected service, integration, or portal; rotating passwords, tokens, and encryption keys that may have been exposed; and blocking traffic from suspicious sources at the firewall.

Where the affected data is processed on behalf of a merchant, containment steps are coordinated so that the merchant's storefront and order operations are impacted as little as reasonably possible while security is restored.

5. Risk classification and analysis

Once the breach is contained, the response team conducts a risk analysis to determine the severity of the incident and its potential impact on affected individuals. This analysis drives the response strategy, the notification obligations, and the corrective measures.

Low-risk incidents involve limited scope and low-sensitivity data (for example, short-lived unauthorized access to anonymized analytics data) with little realistic prospect of harm; internal reporting and corrective action take priority. Medium-risk incidents involve broader exposure of personal data that does not directly identify individuals or enable significant harm — for example, IP addresses, browser data, or email addresses of a limited number of shoppers — and trigger a documented assessment of whether regulator and individual notification is required. High-risk incidents involve identity or contact data at scale, account credentials, financial or payment-related data, or any exposure creating a real risk of identity theft, fraud, discrimination, or reputational damage; these mandate the fastest response and full notification without delay.

The analysis weighs the sensitivity of the affected data categories, the number of individuals affected, the nature and duration of the breach (access, copying, alteration, deletion, or destruction), the potential consequences for the individuals concerned, whether the data was encrypted, masked, or otherwise protected, and how quickly the incident was brought under control.

6. Remediation and recovery

A root cause analysis is conducted to determine the underlying cause of the breach — for example, a software vulnerability, misconfiguration, compromised credential, or human error. The identified vulnerability is remediated immediately through security patches, code changes, or configuration updates. Access controls are reviewed and tightened, authorizations are redefined under the least-privilege principle, and multi-factor authentication is enforced for critical access.

Data integrity is verified, and where loss or corruption is detected, affected systems are restored from secure, clean backups. Services are brought back gradually under close monitoring, initially with restricted access or reduced functionality where prudent.

We work to defined time objectives: initial isolation and emergency measures within the first hours; clarification of scope, affected data categories, and headcount within the first 24 to 48 hours; vulnerability patching and secure restoration within days, depending on severity; and permanent corrective and preventive actions planned and implemented in the weeks following closure of the incident.

7. Notification duties and timelines

Where a breach affects shopper data that ResReturn processes on behalf of a merchant, ResReturn acts as a data processor. We notify the affected merchant without undue delay after becoming aware of the breach, providing the information the merchant needs — the nature of the breach, the data categories and approximate number of individuals affected, likely consequences, and the measures taken — so that the merchant, as data controller, can meet its own obligation to notify the competent supervisory authority within 72 hours and, where required, the affected individuals. We cooperate fully with the merchant throughout, consistent with GDPR Article 33(2) and KVKK Article 12.

Where the breach affects data for which ResReturn is the data controller — such as merchant account data or our own website data — we notify the competent authority directly: the Personal Data Protection Board (KVKK Board) in Türkiye using its Data Breach Notification Form, and the relevant EU supervisory authority under GDPR Article 33, in each case without undue delay and, where feasible, within 72 hours of becoming aware of the breach. If notification is delayed, the reasons are documented and stated in the notification. The notification covers the date and detection time of the breach, its nature, the affected data categories, the estimated number of individuals, the likely consequences, the measures taken or planned, protective steps individuals can take, and contact channels.

Where a breach for which we are the controller is likely to result in a high risk to individuals — for example, exposure of credentials or data enabling identity theft or fraud — we also notify the affected individuals without undue delay, in accordance with GDPR Article 34 and KVKK Article 12/5. This notice is written in plain language and includes a summary of the breach, the data affected, the potential consequences, the measures we have taken, the steps individuals can take to protect themselves (such as changing passwords and reviewing account activity), and how to reach us. Notice is delivered through appropriate channels such as email or in-product announcement.

If all details of a breach cannot be established within 72 hours, we make an initial notification based on the information available and supplement it in phases as the investigation progresses. Where a breach involves personal data transferred internationally, notification obligations are fulfilled within the framework of the applicable transfer safeguards, and our own sub-processors are contractually required to notify us of any breach without undue delay.

8. Documentation and record-keeping

Every stage of a breach response is recorded chronologically in a dedicated breach record: the incident number and date, how the breach was detected and by whom, verification findings, the isolation and emergency steps taken, the affected data categories and estimated number of individuals, the risk analysis outcome, the root cause analysis, the corrective and preventive measures adopted, all notifications sent to merchants, authorities, and individuals (with dates, content, and channels), response-team meeting notes and decisions, and records of communication with external advisers.

These records are kept in a central, encrypted, access-restricted breach log file for at least three years, without prejudice to longer statutory retention obligations. The integrity and immutability of the records are technically protected, as the file is the primary reference in any regulatory audit or legal proceeding. We maintain this register for all breaches, including those that did not meet the threshold for notification, together with the reasoning for that assessment.

9. Preventive measures and ongoing review

Breach response is only as strong as the preventive controls behind it. Technical measures are audited and updated regularly: multi-factor authentication coverage and role-based access controls are reviewed at least every six months; the currency of encryption in transit (TLS) and at rest, together with key management and rotation, is checked periodically; firewall and network segmentation rules and intrusion detection systems are tested and tuned against new threats; vulnerability scans run on a regular schedule with prioritized patching; and backup security, encryption, and rotation, along with the secure destruction of expired backups, are reviewed at least every six months.

Administrative measures address the human factor: all staff receive data protection and breach-response training, evaluated at least every six months, with mandatory onboarding training for new hires; confidentiality agreements and the authorization matrix are checked periodically; sub-processors and other third-party providers that process personal data are reviewed against their contractual security obligations at least once a year; and internal policies — including this Policy, our Privacy Policy, and retention and destruction procedures — are reviewed at least every six months and updated for legislative changes and regulatory decisions.

In line with KVKK Article 12/3, we conduct or commission the audits necessary to verify that these measures are implemented, and the results, identified gaps, and improvement plans are reported to senior management.

10. Post-incident review

Every breach is treated as a learning opportunity. After an incident is closed, the response team prepares a post-incident assessment report covering the lessons learned, weaknesses identified in existing procedures, and recommendations for reducing future risk.

These reports feed directly into the review cycle for our preventive technical and administrative measures, so that each incident permanently strengthens ResReturn's security posture and this Policy itself.

11. Reporting a suspected breach

If you are a merchant, a shopper, a security researcher, or anyone else who suspects a personal data breach involving ResReturn, please contact us immediately at contact@resreturn.com with as much detail as you can safely share. We treat every report seriously, confirm receipt, and investigate under this Policy.

You can also write to us at ResReturn (a YourSizer product), Gümüşsuyu Mahallesi İnönü Caddesi Ulusal Apt. No:5 D:5, 34437 Beyoğlu/İstanbul, Türkiye.

Questions about this document? Contact us.