Privacy and Personal Data Policy
Learn how DostGame processes and protects personal data, handles international transfers, KYC verification, analytics and privacy rights.
Last Updated: 19 August 2026
1. Data Controller
Mivo Teknoloji Ticaret Anonim Şirketi is the data controller for personal data processed through DostGame.
Address: Atatürk Mahallesi Ertuğrul Gazi Sokak, Metropol İstanbul C1 Blok No:2 B/376, Ataşehir/İstanbul, Türkiye
Tax Office: Kozyatağı Vergi Dairesi
Tax Number: 621 131 8963
Telephone: +90 536 576 64 86
Email: [email protected]
2. Applicable Law and Scope
This Privacy and Personal Data Policy explains how personal data is collected, used, disclosed, retained and protected when users visit dostgame.com, create an account, purchase digital products, contact support or undergo transaction and identity verification.
Processing is primarily governed by Türkiye's Law No. 6698 on the Protection of Personal Data (“KVKK”). The GDPR, UK GDPR and other mandatory privacy laws may also apply where DostGame offers goods or services to individuals in the relevant jurisdiction or where those laws otherwise apply.
3. Personal Data We Process
3.1. Identity and Contact Data
Name, surname, email address, telephone number, billing details, address where required, date of birth or age information where necessary, and information used to verify identity.
3.2. Account and Membership Data
Account identifier, username, login and account-security records, language, currency, favourites, communication preferences and account activity.
3.3. Order and Transaction Data
Products purchased, order amount, currency, order and delivery status, player ID, game server, region, platform, delivered code records, top-up results, invoices, cancellation, refund and dispute records.
3.4. Payment Data
Payment method, transaction reference, payment status, limited card metadata such as card brand and masked digits where provided by the payment processor, and fraud or chargeback information. Full card numbers and card security codes are processed by authorised payment providers and are not stored by Mivo Teknoloji Ticaret Anonim Şirketi.
3.5. Security and Technical Data
IP address, browser and device data, operating system, session and cookie identifiers, login records, timestamps, security events, risk signals and evidence needed to investigate unauthorised activity.
3.6. Customer Support Data
Messages, complaint and request records, attachments, screenshots, call or correspondence information and support history.
3.7. Marketing and Preference Data
Cookie choices, marketing permissions, campaign interactions and communication preferences. Marketing communications are sent only where permitted by applicable law.
3.8. KYC and Verification Data
Where risk-based verification is required, identity-document data, document images, selfie or video images, liveness and face-matching results, verification result, sanctions/PEP screening results, device and fraud signals, and related audit records may be processed through Didit Identity, Inc.
4. Purposes of Processing
Personal data may be processed to create and secure accounts; receive payment; issue invoices; deliver digital products and top-ups; provide support; handle cancellation, refund and chargeback cases; prevent fraud and unauthorised payments; conduct KYC, sanctions and risk checks; comply with legal and accounting obligations; establish or defend legal claims; improve performance and user experience; obtain and manage cookie or marketing consent; and communicate operational information about orders and accounts.
5. Legal Bases
Depending on the processing activity, personal data is processed because it is necessary to enter into or perform a contract, comply with a legal obligation, establish or protect a legal right, protect users and payment systems, pursue a legitimate interest that does not override individual rights, or because the user has given consent.
Consent is used where required for non-essential analytics and marketing cookies, direct marketing, certain international transfers or special-category processing. Consent may be withdrawn at any time without affecting processing carried out lawfully before withdrawal.
6. How We Collect Personal Data
Data is collected directly from users through registration, checkout, support and verification interfaces; automatically through website, device, security and cookie technologies; and from payment providers, suppliers, publishers, fraud-prevention services, identity-verification providers and competent authorities where lawful.
7. Google Analytics, Meta Pixel and TikTok Pixel
Subject to the user's cookie choices, DostGame uses Google Analytics 4, Meta Pixel and TikTok Pixel to measure visits, page views, product interactions, basket and checkout activity, purchases and advertising performance.
Names, email addresses, telephone numbers, full payment-card data and identity/KYC documents are not intentionally sent directly through these technologies. Cookie identifiers, IP addresses, device data and event information may nevertheless constitute personal or pseudonymous data. Reports may be aggregated or pseudonymous, but this does not mean that all underlying data is anonymous.
Non-essential analytics and marketing technologies are not activated before consent where consent is legally required. Choices may be changed through Cookie Preferences.
8. KYC Processing and Didit
KYC may be required for certain order values, suspicious activity, mismatched information, sanctions screening, chargeback risk or account security. Verification may include document authenticity, selfie, liveness and face matching, and PEP or sanctions screening.
Verification is performed through Didit Identity, Inc. The raw identity document and selfie files used in that process are not intended to be stored on the servers of Mivo Teknoloji Ticaret Anonim Şirketi. Didit may retain KYC records for up to five years in accordance with the configured service, legal obligations and its applicable terms. DostGame receives and retains the verification result and limited audit or risk information needed for security, compliance and dispute handling.
Automated checks may support a decision, but significant adverse outcomes may be referred for human review where required by law or reasonably requested by the user.
9. Recipients
Data may be disclosed, only as necessary, to payment and banking providers; digital product suppliers, game publishers and delivery providers; cloud, hosting, security and customer-support providers; analytics and advertising providers where consent applies; Didit Identity, Inc.; accountants, auditors, legal advisers and insurers; and courts, regulators, law-enforcement or other competent authorities where legally required.
Service providers are required to process data only for authorised purposes and under appropriate confidentiality and security obligations.
10. International Transfers
DostGame operates internationally and some providers, including analytics, advertising, cloud, payment and identity-verification providers, may process personal data outside Türkiye or the user's country.
International transfers are made in accordance with KVKK Article 9 and, where applicable, the GDPR, UK GDPR or other mandatory law, using adequacy decisions, standard contractual clauses, binding safeguards, explicit consent where legally valid, or another recognised transfer mechanism.
11. Retention
Data is retained only for as long as necessary for the relevant purpose and legal obligations. Account data is generally retained for the account relationship and applicable limitation periods. Order, invoice, payment, accounting, delivery, complaint and dispute records are retained for statutory tax, commercial, consumer and evidentiary periods. Security records are kept for a proportionate period based on risk. Cookie retention periods are listed in the Cookie Policy.
Didit may retain KYC records for up to five years. Data is deleted, anonymised or securely restricted when the applicable retention period ends, unless continued retention is legally required.
12. Automated Risk Assessment
Orders and accounts may be scored using transaction amount, device and network signals, account history, payment consistency, previous disputes and verification results. This may lead to additional verification, delayed delivery, manual review, cancellation before delivery or an account restriction. Users may contact DostGame to request human review where applicable.
13. Data Security
Reasonable technical and organisational measures are used to protect personal data against unauthorised access, alteration, disclosure, loss and misuse. Measures may include access controls, logging, encryption in transit, monitoring, segregation of duties, backup, provider review and incident-response procedures. No online system can be guaranteed completely secure.
14. Children's Data
DostGame is not directed at young children. Users under 18 should transact only with the knowledge and consent of a parent or legal representative. Where legally required, age or parental authority may be verified. Data identified as having been collected unlawfully from a child will be deleted or otherwise handled in accordance with applicable law.
15. Rights Under KVKK
Individuals may ask whether their personal data is processed; request information and access; learn the purposes of processing and whether data is used accordingly; learn recipients; request correction, deletion or destruction where conditions are met; request notification of correction or deletion to recipients; object to an adverse result produced exclusively through automated analysis; and claim compensation for damage caused by unlawful processing.
16. Rights Under the GDPR and UK GDPR
Where applicable, individuals may have rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent and complaint to a competent supervisory authority. They may also have rights concerning decisions based solely on automated processing. These rights may be subject to statutory conditions and exemptions.
17. Exercising Your Rights
Requests may be sent to [email protected] or by post to Mivo Teknoloji Ticaret Anonim Şirketi at the address above. A request should include the applicant's name, the subject of the request, the email address or telephone number linked to the account, and a clear description of the requested action.
Limited information may be requested to verify identity and authority. KVKK requests are answered within 30 days where applicable; GDPR and UK GDPR requests are generally answered within one month, subject to lawful extensions.
18. Changes to This Policy
Mivo Teknoloji Ticaret Anonim Şirketi may update this Policy to reflect changes in its services, processing activities or applicable law. The current version and update date will be published on DostGame.
19. Contact
Mivo Teknoloji Ticaret Anonim Şirketi
Atatürk Mahallesi Ertuğrul Gazi Sokak, Metropol İstanbul C1 Blok No:2 B/376, Ataşehir/İstanbul, Türkiye
Telephone: +90 536 576 64 86
Email: [email protected]