Data controller and scope of this notice
The data controller under Turkish Personal Data Protection Law No. 6698 is Boran Karadeniz. The contact and application email is [email protected]; current contact and service-of-notice details are shown below. This notice covers personal data processed during visits, enquiries, quotation and collaboration discussions, technical security checks and copyright or content notices.
This notice is not a request for consent. The form’s acknowledgement records that you have seen the information. It does not authorize marketing, unrestricted transfers or processing for other purposes. Optional device storage requires a separate choice in the preference panel.
Data categories and collection
We may process your name and contact information, enquiry content, relevant company/professional/project details, voluntarily submitted attachments and technical security information. Information is collected through the form, email, HTTP requests and cookies by partly or wholly automated means. You choose the content of attachments and free text; please avoid unnecessary or sensitive data.
Copyright and content notices may also contain the applicant’s capacity, the right claimed, work/content links, evidence and a declaration of accuracy and authority. Unrelated identity and third-party information should not be submitted.
Purposes and legal grounds
| Activity | Purpose | Legal ground |
|---|---|---|
| Collaboration / quotation enquiry | Assessing the enquiry and pre-contract discussions | Law No. 6698, Art.5(2)(c): necessary processing directly related to establishing or performing a contract |
| General correspondence | Answering enquiries and maintaining contact | Art.5(2)(f): legitimate interests that do not harm fundamental rights |
| Copyright / content notice | Assessing claims and establishing, exercising or protecting rights | KVKK Art.5/2-e where necessary; Art.5/2-ç for applicable legal obligations |
| Form and access security | Preventing abuse and security incidents | Necessary and proportionate security processing under Art.5(2)(f) |
| Legal processes | Meeting legal duties and protecting rights | Art.5(2)(ç) and Art.5(2)(e), where their conditions apply |
| Contact draft on your device | Restoring an unfinished form | Your separate, optional consent in the preference panel |
Recipients and purposes
Authorised operator staff reviewing your enquiry and hosting, email or technical-support providers may access information required for their work. Where needed, legal advisers and legally authorised public bodies may receive relevant information on an applicable legal ground. Your message is not used for sales of personal data, advertising targeting or public profiling.
Conditions for international transfers
Hosting, email or content-delivery infrastructure located abroad may involve international transfers of personal data. Requesting an interface resource from jsDelivr discloses the IP address and technical information needed for that request. Opening an external communication link also engages that service’s own processing and transfer arrangements.
International transfers are subject to the current conditions in Article 9 of Law No. 6698. Alongside a valid processing condition, an applicable adequacy decision or an appropriate safeguard—such as a standard contract, binding corporate rules or another safeguard provided by the Law—must be established where required. Exceptions for incidental transfers are not a general basis for continuing infrastructure transfers. Browsing the website or acknowledging this notice is not transfer consent.
This notice does not assert that a safeguard agreement has been executed with a particular provider. Ask [email protected] about recipient groups, transfer scope and the legal mechanism actually applied. Relevant information must be updated if providers or transfer arrangements change.
Retention periods
Enquiries that do not become contracts and their attachments follow a plan of 12 months from recording. Periods reflect the purpose, mandatory law and specific need to protect rights. Records are retained only to the extent necessary; regular maintenance and deletion must implement these periods.
A verification challenge expires after 10 minutes and cannot be reused after an attempt. Administrator sign-in limits use 15-minute windows, while form and verification limits use short or hourly windows depending on the operation. Expired counters are removed during subsequent requests or maintenance. Browser storage periods are listed separately in the Cookie Policy.
Your rights under Turkish data-protection law
- Ask whether your personal data is processed and request information about that processing.
- Learn the purpose, whether data is used for that purpose, and recipients inside or outside Türkiye.
- Request correction of inaccurate or incomplete data, or deletion/destruction when statutory conditions apply.
- Ask that recipients be informed of corrections or deletions.
- Object to adverse results produced exclusively by automated analysis, and seek compensation for harm caused by unlawful processing.
Submitting and resolving applications
Applications may use the methods allowed by Article 13 of Law No. 6698 and the Communiqué on applications to data controllers. Send a written application to the operator’s service-of-notice address or email [email protected] from an address previously provided and recorded in the system. Other legally valid methods, including secure electronic signature, mobile signature or registered electronic mail where available, remain open. Your identity, contact details, request and any representative capacity should be clear. Necessary verification information is requested securely and proportionately.
Applications are resolved as soon as their nature allows and within 30 days. The written or electronic response explains which requests are fulfilled and why any part is refused. A phone conversation does not replace that response. Processing is generally free; where additional costs arise, the tariff set by the Board may apply. Any charged fee is refunded if the application arose from the controller’s error.
Consent and changes
Use the panel below to change your optional draft-storage choice. Declining it does not prevent use of the contact form. Withdrawal stops future optional storage and deletes the draft in this browser; it does not retrospectively affect processing that was lawful before withdrawal.
The final response is delivered in writing or electronically and identifies the action taken and any reasons for refusal. Oral discussions used to clarify the request do not replace the final written or electronic response.
Verification and transaction-security data
The form session processes a verification code, random challenge identifier, issue time and attempt count; a code is valid for 10 minutes. Application rate counters convert IP/email values into keyed hashes. These hashes are not treated as absolutely anonymous. The purpose is to reduce automated abuse and protect the contact service. Processing relies on Article 5(2)(f) of the Turkish Personal Data Protection Law where necessary and proportionate.
A failed technical verification does not itself constitute an individual assessment or rejection of a business proposal. You may use the alternative email channel and request that authorised personnel assess an application concerning your personal data rights.
Sensitive data and information about others
The forms are not intended to collect sensitive personal data. If such information is indispensable to assess a legal request, an appropriate condition under Article 6 and additional safeguards are assessed separately. Entering it in free text does not provide blanket consent or unrestricted permission. Do not submit unrelated health, biometric, criminal-conviction or similar information.
For an application on another person’s behalf, authority and identity are checked using information necessary and proportionate to the request. A full identity-document copy is not a standard requirement for every application.
Responses and statutory remedies
State your name, reply details, request and the information necessary to verify identity or representative authority in accordance with the applicable procedure. Available methods under the relevant Communiqué include written application, registered electronic mail, secure electronic signature, mobile signature, or an email address previously notified and registered in the system. Do not send unnecessary identity data through insecure channels.
An accepted application is acted on and a response is provided; a rejection states the reasons. Final responses are written or electronic. A complaint to the Board is subject to the statutory prior-application and time-limit requirements. Compensation and other judicial remedies remain available under their own legal conditions.