Scope of this policy
This policy explains how personal information is handled when you visit the Boran Karadeniz website or use its contact channels. The publisher and data controller is Boran Karadeniz. Contact [email protected] with questions. The operator’s contact and service-of-notice details appear at the end of this page.
The website presents WordPress, WooCommerce, web development, SEO and digital marketing services and receives enquiries. There are no public visitor accounts or online payments. Data-processing arrangements for a separately commissioned project are agreed within that project’s scope.
Information you share
The form collects your name, email, topic and message. Depending on the enquiry, it may ask for a company, channel URL, format, project goal, budget, date or reason for contacting us. Attachments are optional. Avoid identity documents, health information, passwords, payment details or unnecessary personal information about other people.
Copyright and content notices also include your capacity, the rights holder or affected person, content and original-work links, requested action, evidence notes and a declaration of accuracy and authority. This information is used to assess the notice and protect relevant rights.
Reviewing your enquiry
Information is used to review and answer your enquiry and assess a potential collaboration. Sending the form does not add you to a marketing list. Acknowledging the data-protection notice does not grant advertising permission or blanket consent. Legal grounds and your rights are explained in the data-protection notice.
Email, attachments and references
Messages and validated attachments are stored in a private inbox accessible only to the authorised administrator. When SMTP is configured, a copy is forwarded to the operator’s mailbox. A reference is shown after a successful record. It does not mean the enquiry has been approved, read or made into a contract.
Security measures
The form uses a session, submission verification, abuse limits and file-type/size checks. IP and email values in application counters are represented by keyed hashes. Application error logs omit message content, attachments and SMTP passwords. Hosting and email providers may also maintain their own technical logs and backups.
Retention, deletion and backups
Enquiries that do not become contracts and their attachments follow a retention plan of 12 months from recording. Information may be deleted earlier when its purpose ends or applicable legal conditions are met. Contract, invoice, dispute or legal-claim records are assessed separately against the relevant mandatory retention or limitation period and the minimum information needed.
Enquiry data is held in an access-controlled SQL database, while supporting files are kept outside public access. Operational backups follow a plan of up to 14 copies and 30 days. Deleting an enquiry in the administration area does not automatically delete an email already sent or a provider backup. Mailboxes and backup copies are included in the deletion plan. If data is restored, previously completed deletion requests must be reapplied.
Choices on your device
If you enable optional draft storage, text fields are kept in this browser. Files, verification codes, security tokens and the notice checkbox are excluded. A draft can be restored for 24 hours; it is cleared when that time expires while the page is open, or on your next visit. Successful submission or disabling this choice deletes it. Leave this feature off on shared devices.
Copyright and content notice text is not saved as a browser draft. Selecting this topic also clears an earlier form draft.
Links and service providers
Fonts and icons are served locally. Pinned SweetAlert2, Toastify, Choices and FilePond components load from jsDelivr, with local fallbacks if the connection fails. CDN requests may disclose IP addresses and technical request information to its provider. Advertising pixels and automatic video players are not used. External links follow their providers’ terms. Hosting and email processing is described in the data-protection notice.
Changes and contact
We update these notices and, when needed, preference controls if processing or services change. You may use the contact details below for data-related requests. Your statutory rights of application and complaint remain available.
Verification code and abuse prevention
A five-character letter and digit code is generated on this server and verified only in its corresponding session. The random challenge is valid for up to 10 minutes and consumed on each verification attempt. Expired entries are removed on later requests. The code and answer are not included in emails, browser drafts or analytics.
This check works with submission limits and security controls to reduce spam. It is not used for profiling or marketing. You can refresh an unreadable code or contact us through the email link. Technical barriers do not remove statutory application rights.
Unnecessary information and sensitive documents
Send information about others only where necessary to assess the request and where you have a lawful basis to share it. Sensitive personal data, identity copies, passwords and financial data are not routinely requested. Redact irrelevant parts of supporting documents. If unnecessary data is identified, appropriate deletion or separation is assessed while retaining the part relevant to the request.
Contact details are not published openly. Necessary explanations in a notice may be shared in a limited manner with the relevant content owner or an authorised adviser for assessment. Identity and contact details are not automatically disclosed to every party.
Security incidents and request records
Access is limited by need. Transmission protection, updates, backups and incident handling are applied as appropriate to the service. No technical measure guarantees absolute security. A personal data breach triggers assessment, mitigation and notifications required by applicable law. Security measures do not remove the controller’s statutory responsibility.
A deletion request does not mean that records required by law or necessary to protect a right must always be deleted immediately. Any applicable limitation, its scope, purpose and duration are explained in the response, and use for other purposes is restricted.
Infrastructure providers and direct contact
Hosting and storage services deliver pages, files and enquiries; email providers support email correspondence. Interface components may load from the jsDelivr content-delivery network. Such requests expose the requesting IP address, browser details and requested resource to the provider. Fonts and contact icons are served by this website. No third-party CAPTCHA service is used.
Clicking a phone or WhatsApp link opens the relevant service at your request. WhatsApp conversations are subject to that provider’s terms and data practices. A visit does not automatically open WhatsApp, set advertising cookies or start behavioural analytics. The contact form is available without using those external services.
Automated checks and communication limits
Verification, file-format checks and short-term request limits operate automatically to reduce misuse. Commercial and legal assessments of enquiries are not made solely from these checks. If a request is incorrectly blocked, contact [email protected] or use the phone channel.
Information submitted through the form is not used to build advertising lists, sell personal profiles or train general-purpose AI models. Sending an enquiry does not authorize unsolicited marketing. For a confidential project, appropriate confidentiality and access arrangements can be agreed before detailed documents are shared.