Welcome to Toger
Don't have an account yet? Sign Up
- Home
- /
- KVKK Disclosure Text
KVKK Disclosure Text
This Disclosure Notice has been prepared by Mionti Enerji ve Teknoloji Anonim Şirketi, acting as the data controller, pursuant to Article 10 of Personal Data Protection Law No. 6698 ("KVKK") and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform.
1. IDENTITY OF THE DATA CONTROLLER
Pursuant to subparagraph (ı) of the first paragraph of Article 3 of Law No. 6698, the data controller is:
Company Name: Mionti Enerji ve Teknoloji Anonim Şirketi
Trade Name: TOGER
MERSIS Number: 0621109957700001
Address: Başak Mahallesi, 5. Etap, 2. Kısım, Abdülhamithan Caddesi No:5, 34306 Başakşehir/Istanbul
Tax Identification Number: 6211099577
Telephone: (+90) 212 980 01 44
Email: info@mionti.com
Website: www.toger.co
2. CATEGORIES OF PERSONAL DATA PROCESSED
The following categories of personal data are processed within the scope of providing TOGER charging network services:
2.1. Identity Information
First name, surname, Turkish Republic identity number (where legally required), date of birth.
2.2. Contact Information
Mobile telephone number, email address, billing address.
2.3. Vehicle Information
Vehicle licence plate number, make and model information, battery capacity, charging socket type, Autocharge vehicle identification data.
2.4. Financial Information
Masked card information, billing information, TOGER Wallet balance information, payment history and occupancy fee accrual records. Credit card information is not stored on the Company's servers; payment transactions are carried out through PCI DSS-compliant infrastructure providers.
2.5. Charging Transaction Data
Charging start and end times, amount of energy consumed (kWh), charging duration, station and socket information used, charging type (AC/DC), transaction amounts.
2.6. Location Data
Your real-time location information may be processed, subject to your explicit consent, for the purpose of displaying the nearest charging station through the mobile application. Location data is not permanently recorded.
2.7. Digital Usage Data
IP address, browser type and version, operating system information, application version, session information, cookie data, device identification information, access date and time.
2.8. Customer Request and Complaint Data
Support requests, complaint records, satisfaction surveys, call centre conversation records and email correspondence.
3. PURPOSES OF PROCESSING PERSONAL DATA
Your personal data is processed for the following purposes in accordance with the processing conditions set out in Articles 5 and 6 of the KVKK:
3.1. Establishment and Performance of the Agreement (Article 5/2-c of the KVKK)
- Providing electric vehicle charging services
- Creating and managing membership registration
- Providing the TOGER Wallet service
- Carrying out payment and invoicing transactions
- Managing the processes of starting, monitoring and ending charging sessions
- Providing customer support services
3.2. Fulfilment of Legal Obligations (Article 5/2-ç of the KVKK)
- Obligations under Electricity Market Law No. 6446 and the EMRA Charging Service Regulation
- EMRA notification and reporting obligations
- Information obligations under Consumer Protection Law No. 6502
- Invoice issuance and retention obligations under Tax Procedure Law No. 213
- Retention of traffic and transaction records under Internet Law No. 5651
- Responding to information requests from authorized public institutions and organizations
3.3. Legitimate Interest (Article 5/2-f of the KVKK)
- Planning and developing the charging network infrastructure
- Measuring and improving service quality
- Anonymized statistical analyses and market research
- Conducting information security processes
- Preventing fraud and unauthorized access attempts
- Following up legal proceedings
3.4. Explicit Consent (Article 5/1 of the KVKK)
- Information regarding campaigns, promotions and advantageous packages
- Personalized charging recommendations and energy consumption reports
- Information regarding the nearest station based on location data
- Promotion of products and services of third-party business partners
4. METHOD AND LEGAL BASIS OF COLLECTING PERSONAL DATA
Your personal data is collected by automatic or non-automatic means through the following channels:
- Membership transactions carried out through the TOGER mobile application and website
- Transactions carried out at charging stations (QR code, RFID card, Autocharge)
- Customer service channels (telephone, email, in-app support)
- Cookies and similar tracking technologies
- Payment institutions and banking systems
- The EMRA Open Access Platform (within the scope of roaming services)
The legal grounds for processing are: the existence of your explicit consent (Article 5/1), explicit provision by law (Article 5/2-a), establishment or performance of an agreement (Article 5/2-c), fulfilment of a legal obligation (Article 5/2-ç), data having been made public by the data subject (Article 5/2-d), establishment, exercise or protection of a right (Article 5/2-e), and the legitimate interest of the data controller (Article 5/2-f).
5. TRANSFER OF PERSONAL DATA
5.1. Domestic Transfers
Your personal data may be transferred to the following parties in accordance with the conditions set out in Article 8 of the KVKK:
- EMRA and regulatory authorities — within the scope of legal notification and reporting obligations
- Payment institutions and banks — for the secure execution of payment transactions
- Business partners and suppliers — within the scope of operating the charging infrastructure and providing technical support
- Legal advisers and audit firms — within the scope of legal consultancy and audit activities
- Other charging network operators with which roaming agreements are in place — for the purpose of providing reciprocal charging services
- Authorized public institutions and organizations and judicial authorities — where legally required
- SMS delivery platforms, email service providers, push notification infrastructures and customer communication platforms — for the purpose of delivering service notifications
- Cloud infrastructure providers and analytics tools — within the scope of technical infrastructure and service quality analysis
5.2. International Transfers
Your personal data may be transferred abroad within the scope of cloud computing, payment infrastructure or technical support services. Such transfer shall be carried out, within the framework of Article 9 of the KVKK, to countries providing adequate protection or to data controllers undertaking adequate protection, by obtaining your explicit consent or where other conditions stipulated by law are met.
6. RETENTION PERIOD OF PERSONAL DATA
Your personal data is retained for the period required by the purpose of processing and within the limitation periods prescribed under the relevant legislation:
- Commercial books and records: 10 years pursuant to Turkish Commercial Code No. 6102
- Invoices and financial documents: 5 years pursuant to Tax Procedure Law No. 213
- Consumer transaction records: the applicable limitation periods under Law No. 6502
- Internet access and traffic records: 1-2 years pursuant to Law No. 5651
- Periods prescribed under the EMRA Charging Service Regulation
Following the expiry of the relevant periods, your personal data shall be deleted, destroyed or anonymized in accordance with the Regulation on the Deletion, Destruction or Anonymization of Personal Data.
7. MEASURES REGARDING DATA SECURITY
Pursuant to Article 12 of the KVKK, our Company takes the necessary technical and administrative measures to prevent the unlawful processing of and access to personal data and to ensure its secure retention:
Technical Measures
- Secure data communication using 256-bit SSL/TLS encryption
- Firewall and intrusion detection/prevention systems
- Database encryption and access control mechanisms
- Regular backup and disaster recovery procedures
- Periodic penetration tests and vulnerability scans
- Retention and monitoring of log records
Administrative Measures
- Personal data protection training for employees
- Access authorization based on the "need-to-know" principle
- Preparation and regular updating of the personal data processing inventory
- Fulfilment of the VERBIS registration obligation
- Inclusion of personal data protection provisions in agreements signed with data processors
- A personal data breach notification procedure compliant with the 72-hour rule
If a security breach concerning personal data occurs within the systems of Third-Party Service Providers, our Company shall notify the Personal Data Protection Board and the relevant data subjects within no later than 72 hours pursuant to Article 12 of the KVKK. Users shall be informed immediately of unauthorized communications made in the name of TOGER as a result of cyberattacks targeting the systems of Third-Party Service Providers.
8. RIGHTS OF THE DATA SUBJECT
Pursuant to Article 11 of the KVKK, you have the following rights:
- To learn whether your personal data is being processed
- To request information if your personal data has been processed
- To learn the purpose of processing your personal data and whether it is being used in accordance with that purpose
- To know the third parties to whom your personal data has been transferred domestically or abroad
- To request correction of your personal data if it has been processed incompletely or incorrectly
- To request the deletion or destruction of your personal data within the framework of the conditions set out in Article 7 of the KVKK
- To request that correction and deletion operations be notified to third parties to whom your personal data has been transferred
- To object to an outcome arising against you as a result of the analysis of processed data exclusively through automated systems
- To claim compensation for damages if you suffer loss due to the unlawful processing of your personal data
- To learn to which Third-Party Service Providers your personal data has been transferred and to request information regarding such transfers
9. APPLICATION METHOD
You may apply to our Company using one of the following methods in order to exercise the rights stated above:
- By sending an email to info@mionti.com together with information and documents suitable for identity verification
- By submitting a written application through a notary public or by registered mail with return receipt requested to our Company's address at Başak Mahallesi, 5. Etap, 2. Kısım, Abdülhamithan Caddesi No:5, 34306 Başakşehir/Istanbul
- Through our registered electronic mail (KEP) address using a secure electronic signature
Your application must clearly state your first name, surname, Turkish Republic identity number (or passport number or identification number, if any, if you are a foreign national), address for service, email address, if any, telephone number and the subject matter of your request.
Our Company shall conclude your application free of charge as soon as possible, depending on the nature of the request, and within no later than thirty (30) days. If processing the request requires an additional cost, a fee may be charged in accordance with the tariff determined by the Personal Data Protection Board.
If your application is rejected, the response is found insufficient or no response is provided within the prescribed period, you retain the right to lodge a complaint with the Personal Data Protection Board within thirty days from the date on which you learn of the response and, in any event, within sixty days from the date of application.
This KVKK Disclosure Notice was updated in April 2026.

