Privacy Policy
Draft for review
This document has not been approved and is not yet a final policy. Highlighted items are company details that must be confirmed before publication.
Draft of 28 September 2026
This policy explains in plain language how personal data is processed on the TÜRKSOY GROUP website (the “Website”). Detailed information under Turkish law is provided in the KVKK Information Notice.
1. Data controller
trade name, Bahçeşehir Mah. Susam Sok. No: 10, 66100 Merkez/Yozgat, Türkiye, MERSİS No: MERSİS number. Contact: info@groupturksoy.com.
2. In brief
- The Website uses no analytics, advertising or social media tracking tools.
- The Website sets no cookies and stores no data in your browser.
- All content, including fonts, is loaded from the Website’s own server; no requests are sent to third-party servers during your visit.
- What you send with the message form on the contact page is forwarded to us as an e-mail via our server; the Website does not store it.
3. What data do we process?
3.1 When you visit the Website
As with any website, your browser sends technical information to the server. The hosting infrastructure may keep this information in server logs:
- IP address,
- date and time,
- the page or file requested and the response status,
- browser and operating system information (user agent),
- the referring page (referrer).
Purpose: Secure and uninterrupted operation of the Website, troubleshooting, and detecting and preventing attacks. Legal basis: KVKK Art. 5(2)(f) (legitimate interest); KVKK Art. 5(2)(ç) where there is a statutory retention obligation. Retention: log retention period of the hosting provider.
3.2 When you contact us through the message form, by e-mail, telephone or fax
In this case, your name, your contact details (e-mail address, telephone or fax number), your company name if any, and the content of your message are processed.
Purpose: To answer your message and follow up your request. Legal basis: KVKK Art. 5(2)(c) where your request concerns the conclusion of a contract; otherwise KVKK Art. 5(2)(f) (legitimate interest). This processing does not rely on explicit consent. Retention: retention period for enquiries (proposal: at most 12 months after the request is concluded, or for the limitation period in the event of a legal dispute).
E-mails are stored with the corporate e-mail service provider used by the Company; they are not kept on the Website’s server.
4. Recipients of data
- Hosting provider: provider name and server location,
- Corporate e-mail service provider: provider name and server location,
- Legally authorised public authorities, only where there is a legal request or obligation.
Personal data is not sold and is not shared for advertising purposes.
5. Transfers abroad
If the servers of the hosting or e-mail provider are located outside Türkiye, personal data is transferred abroad. In that case, the transfer is based on one of the safeguards provided for in KVKK Art. 9 (for example, an adequacy decision or standard contractual clauses notified to the Board). Current status: location of the providers and the transfer mechanism used.
6. Your rights
Your rights under KVKK Art. 11 and how to make a request are explained in the KVKK Information Notice. Requests are concluded free of charge within 30 days at the latest.
Whether the EU General Data Protection Regulation (GDPR) applies to the Company’s activities is still being assessed. If it applies, you may also exercise the rights of access, rectification, erasure, restriction of processing, data portability and objection listed in Articles 15–21 GDPR, and lodge a complaint with the supervisory authority in your country.
7. Security
The Website is served over an encrypted connection (HTTPS) with restrictive security headers (including a content security policy). It has no user accounts or database; messages sent with the message form are forwarded as e-mails and are not stored on the Website. To prevent misuse, your IP address is kept on the server in hashed form for at most one hour. The Website is designed around the principle of data minimisation. No system can guarantee complete security; however, we assess risks regularly and update our measures.
8. Children
The Website is not aimed at children, and no personal data is knowingly collected from children.
9. Cookies
The Website does not use cookies. Details are given in the Cookie Policy.
10. Changes
This policy is updated when the technologies used on the Website or its data processing activities change. The current version is always on this page.
This English version is provided for information. In case of discrepancy, the Turkish version prevails.