Turkish source updated: August 4, 2026
Personal Data Protection Notice
This notice explains our personal-data processing activities across the website, mobile apps, call center, and service channels under Turkish data-protection law.
This notice is separate from any explicit-consent statement. Reading or acknowledging it does not constitute explicit consent. This English version is provided for convenience; the Turkish text prevails in case of discrepancy.
Data controller and scope
The data controller that determines the purposes and means of processing is NOWASS YOL YARDIM VE DESTEK HIZMET SANAYI TICARET LIMITED SIRKETI. The data processed varies according to the service used, the breakdown or accident process, membership or package scope, and the request you submit.
Personal-data categories processed
Purposes and legal bases
Website, cookies, and AI-assisted processes
Website and mobile-app data may be processed for membership, service purchases, support, security, and permission preferences. Non-essential cookies are enabled only in line with your choices and applicable legal requirements.
For details about cookies, see the Cookie Policy (opens in a new tab).
AI systems may be used in a controlled manner for request classification, operational decision support, quality and security analysis, and product development. Personal data is not used for a model provider's general model training without a separately defined purpose and an appropriate legal basis; data minimization, access control, human oversight, and auditable decision processes apply.
Collection methods and transfers
Personal data may be collected directly from the data subject through the website and mobile app, phone, e-mail, call center, and service records, and—where required for the service—from inspection, maintenance/repair organizations, agencies, social-media platforms, insurers, sponsors, and business partners by automated or non-automated means.
Data may be shared, limited to the relevant purpose, with dealers, repair shops, parking facilities, towing and recovery providers, assessors, insurers, solution/operations partners, payment and infrastructure providers, communication services, audit and advisory firms, carriers, and competent public authorities under Articles 8 and 9 of Turkish data-protection law.
An international transfer takes place only in a specific technical or operational process that requires it and after an applicable transfer condition or safeguard under Article 9 is in place. The data category, purpose, recipient group, and safeguard may be explained separately in the relevant processing flow.
Retention and security
Personal data is retained for the period required by the processing purpose and applicable contract, consumer, commercial, tax, accounting, dispute, and limitation rules; it is then deleted, destroyed, or anonymized.
Access authorization, transfer security, record integrity, supplier controls, penetration testing, incident response, audit, and necessary technical and organizational measures form part of the data-security program.
Your data-protection rights
Under Article 11, you may ask whether and how your personal data is processed, learn the purposes and recipients, request correction or—where conditions are met—deletion or destruction, object to certain automated-analysis outcomes, and seek compensation for unlawful processing.
You can send your request to info@nowass.com.tr (opens in a new tab) or use the Personal Data Request Form (opens in a new tab) process.