Privacy Policy
Last updated: April 2026
1. Introduction
Afrosum Holidays Turizm Ltd. Şti. (Turkey) and Afrosum Nigeria Ltd (Nigeria) (together, "Afrosum," "we," "us"), joint operators of the Grossara platform ("Platform"), are committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, store, and protect your personal and business data when you use our Platform.
2. Data We Collect
We collect the following categories of data:
- Account Information: Name, email, phone number, company name, business role, preferred language.
- Business Verification Data: Trade licenses, tax certificates, company registration documents, bank references. For buyers, KYC data collected by our partner bank.
- Transaction Data: Orders, proforma invoices, payment references, shipping details, communication logs between buyers and sellers.
- Usage Data: Pages visited, features used, device information, browser type, IP address, and session duration.
- Communication Data: Messages sent through the Platform messaging system, support tickets, and feedback submissions.
3. How We Use Your Data
- To operate and maintain the Platform and your account.
- To verify business identities and prevent fraud.
- To process transactions, generate proforma invoices, and manage escrow payments.
- To facilitate communication between buyers and sellers.
- To send transactional notifications (order updates, payment confirmations, shipping alerts).
- To improve Platform performance, features, and user experience.
- To comply with legal obligations, including tax reporting and anti-money laundering regulations.
- To resolve disputes between parties on the Platform.
4. Data Sharing
We share your data only in the following circumstances:
- With Trading Partners: When you place or receive an order, relevant business information is shared with the counterparty to facilitate the transaction.
- With Our Partner Bank: Payment and KYC-related data is shared with our partner bank for escrow services and compliance purposes.
- With Service Providers: We use trusted third-party services for email delivery, SMS notifications, hosting, and analytics. These providers are bound by data processing agreements.
- Legal Requirements: We may disclose data when required by law, regulation, court order, or governmental authority.
We never sell your personal data to third parties.
5. Data Security
We implement industry-standard security measures to protect your data, including: SSL/TLS encryption for all data in transit; AES-256 encryption for sensitive data at rest; two-factor authentication options; regular security audits and penetration testing; role-based access controls for our staff; automated daily backups with geographic redundancy. Despite these measures, no system is completely secure. We encourage users to protect their account credentials and report any suspicious activity immediately.
6. Data Retention
We retain your account data for as long as your account is active. Transaction records are retained for a minimum of 7 years to comply with tax and financial regulations. After account deletion, personal data is anonymized within 90 days, except where retention is required by law. You may request data export or deletion at any time by contacting our support team.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to legal retention requirements.
- Portability: Request your data in a structured, machine-readable format.
- Objection: Object to data processing for marketing or profiling purposes.
- Withdrawal of Consent: Withdraw consent for data processing where consent was the legal basis.
To exercise any of these rights, contact us at privacy@grossara.com.
8. International Data Transfers
As a cross-border trade platform, data may be transferred between Turkey, Nigeria, and other countries where our users and service providers operate. We ensure that all international data transfers comply with applicable data protection laws and are protected by appropriate safeguards, including standard contractual clauses.
9. Compliance
This Privacy Policy is designed to comply with the Turkish Personal Data Protection Law (KVKK), the Nigerian Data Protection Regulation (NDPR), and the EU General Data Protection Regulation (GDPR) where applicable.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated via email and platform notifications. The updated policy will be effective upon posting on the Platform.
11. Contact
For privacy-related inquiries, contact our Data Protection Officer:
Email: privacy@grossara.com Afrosum Holidays Turizm Ltd. Şti. Harbiye Mah. Hürriyet Cad. No:52, Çankaya, Ankara, Turkey Afrosum Nigeria Ltd — No. 175 Friday O, Mabushi, Abuja, Nigeria
