LEGAL INFORMATION

Personal Data Protection

Privacy Notice on the Processing and Protection of Your Personal Data under KVKK

Last Updated

This KVKK privacy notice was last updated on 09 September 2025.

1. Identity of the Data Controller

Under Turkish Personal Data Protection Law No. 6698 ("KVKK"), the data controller of your personal data is Enextware Teknoloji Turizm Ticaret Limited Şirketi.

Data Controller Details

  • Trade Name: Enextware Teknoloji Turizm Ticaret Limited Şirketi
  • Registered Address: Saray Mah. Fevziler Sk. Alaettinoğlu Apt. No: 4 İç Kapı No: 11, Alanya / Antalya
  • MERSIS No: 0335095598400001
  • Trade Registry No: 31185 (Alanya Ticaret Sicili Müdürlüğü)
  • Tax Office / No: Alanya Vergi Dairesi / 3350955984
  • Email: info@enextware.com
  • Phone / WhatsApp: +90 536 628 0007
  • Web: enextware.com.tr

Field of Activity

  • Web design and development
  • Software development services
  • Digital marketing consultancy
  • Technical support services

2. Categories of Personal Data Processed

👤 Identity Data

  • Name, surname
  • Turkish ID number (where required for invoicing)
  • Date of birth (where required)
  • Gender (for statistical purposes)
  • Photograph (if there is a profile photo)

📞 Contact Data

  • Email address
  • Phone number
  • WhatsApp number
  • Postal address (where required)
  • Social media profiles (if shared)

🏢 Customer Transaction Data

  • Company/organisation information
  • Project details and preferences
  • Service requests and special requirements
  • Communication history and notes
  • Contract information

💰 Financial Data

  • Billing information
  • Payment method preferences
  • Bank account details (for bank transfers)
  • Tax number (corporate customers)
  • Payment history

🔧 Technical Data

  • IP address
  • Browser type and version
  • Operating system
  • Device information
  • Pages visited
  • On-site activity

3. Purposes of Processing Personal Data

🎯 Core Service Purposes

  • Providing web design services
  • Software development services
  • Providing technical support
  • Project management
  • Quality control and improvement
  • Customer communication
  • Preparing quotations
  • Contract management
  • Invoicing
  • Payment tracking

📊 Analytics and Improvement

  • Measuring website performance
  • Improving the user experience
  • Increasing service quality
  • Customer satisfaction analysis
  • Optimising business processes

📢 Marketing Activities

  • Promoting products and services
  • Campaign announcements
  • Sending newsletters
  • Personalised recommendations
  • Event announcements

⚖️ Legal Obligations

  • Tax legislation requirements
  • Commercial code obligations
  • KVKK compliance
  • Audit and control processes
  • Statutory document retention

4. Legal Grounds for Processing

✅ Legal Grounds under KVKK Article 5/2

a) Explicit Consent

Your explicit consent is obtained for marketing activities, the processing of special categories of data and the collection of optional information.

b) Performance of a Contract

Personal data required for the performance of web design and software development contracts is processed on this basis.

c) Legal Obligation

Fulfilment of obligations arising from tax laws, the commercial code and other legal regulations.

d) Legitimate Interest

Business development, customer relationship management, security measures and improving service quality.

e) Protection of Fundamental Rights and Freedoms

Data processing in emergencies, in response to security threats and where legal protection requires it.

5. Data Transfer and Sharing

🤝 Sharing with Third Parties

Service Providers

  • Hosting Providers: Hosting of websites
  • Cloud Services: Data storage and processing
  • Payment Providers: Payment transactions
  • Email Services: Communication and marketing emails
  • Analytics Tools: Google Analytics, etc.

Disclosures Required by Law

  • Tax Office: Legal obligation
  • Courts and Public Prosecutors: Legal requests
  • Regulatory Authorities: Audit and supervision
  • Law Enforcement: Criminal investigations

🌍 Transfer of Data Abroad

Some of our service providers are located abroad. In this case:

  • We act within the framework of Article 9 of KVKK
  • Transfers to countries with an adequate level of protection are preferred
  • The necessary security measures are taken
  • Transfers are made after explicit consent is obtained

🔒 Data Security

The following security measures are applied to all data transfers:

  • SSL/TLS encryption protocols
  • API security standards
  • Access control and authorisation
  • Logging and monitoring
  • Regular security audits

6. Data Retention Periods

📅 Retention Principles

We delete your personal data once the purpose of processing no longer exists or the statutory retention obligation has ended.

Active Customer Data

  • Contact details: 3 years after the end of the relationship
  • Project data: 10 years after delivery
  • Financial records: 10 years (under the Tax Procedure Law, VUK)
  • Contracts: 10 years (under the Turkish Commercial Code, TTK)

Marketing Data

  • Email list: until consent is withdrawn
  • Communication preferences: for 2 years
  • Analytics data: 1 year
  • Cookie data: between 6 months and 2 years

Technical Data

  • Log records: 1 year
  • Security records: 2 years
  • Backup data: 6 months
  • Temporary files: 30 days

Legal Requirements

  • Litigation files: until the case is concluded
  • Audit records: 5 years
  • Complaint records: 3 years
  • Administrative documents: as required by the relevant law

7. Data Security Measures

🛡️ Technical Security Measures

  • Encryption: SSL/TLS, AES-256
  • Access Control: Multi-factor authentication
  • Network Security: Firewall, VPN
  • Anti-virus: Up-to-date protection software
  • Backups: Automatic daily backups
  • Monitoring: 24/7 system monitoring
  • Updates: Regular security patches
  • Penetration Testing: Annual security tests

👥 Administrative Security Measures

  • Staff Training: KVKK and security training
  • Confidentiality Agreements: For all employees
  • Access Management: Need-to-know principle
  • Data Classification: Separation of critical data
  • Incident Response: Security breach procedures
  • Audit: Regular internal controls

🚨 Data Breaches

In the event of a data security breach:

  • The security vulnerability is closed immediately
  • Affected users are informed
  • The Personal Data Protection Board is notified within 72 hours
  • The causes of the breach are investigated and a report is prepared
  • Measures are taken to prevent similar breaches in the future

8. Rights of the Data Subject (KVKK Article 11)

📋 Your Fundamental Rights

1️⃣ Request Information

You have the right to learn whether your personal data is being processed.

2️⃣ Learn the Purpose of Processing

You can learn for what purpose your data is processed.

3️⃣ Transfer Information

You can learn the third parties to whom your data is transferred.

4️⃣ Request Correction

You can request that inaccurate or incomplete data be corrected.

5️⃣ Request Deletion

Under certain conditions, you can request that your data be deleted.

6️⃣ Request Transfer

You can ask for your data to be transferred to another data controller.

7️⃣ Object

Under certain conditions, you can object to the processing of your data.

8️⃣ Lodge a Complaint

You can lodge a complaint with the Personal Data Protection Board.

📝 Application Process

1

Application Method

By email (info@enextware.com) or in writing

2

Identity Verification

Identity verification with a Turkish ID number or passport

3

Review Period

Your application is assessed within 30 days

4

Response

If the response is negative, the reasons are given

9. Cookies and Online Tracking

🍪 Cookie Policy

Cookies are used on our website to improve the user experience. For detailed information about cookies, please see ourCookie Policy page.

Types of Cookies:

  • Strictly Necessary Cookies: Required for site functionality
  • Analytics Cookies: Google Analytics, usage statistics
  • Functional Cookies: User preferences
  • Marketing Cookies: Advertising and marketing (with consent)

10. Contact and Applications

You can contact us about your KVKK rights and our personal data processing practices:

📧 Application Channels

KVKK Application Email: info@enextware.com

General Enquiries: info@enextware.com

WhatsApp: +90 536 628 0007

Phone: +90 536 628 0007

⏰ Processing Times

Application Acknowledgement: Within 48 hours

Information Request: Within 15 days

Correction/Deletion: Within 30 days

Review of Objections: Within 30 days

11. Updates and Entry into Force

📅 Policy Updates

This KVKK privacy notice may be updated in line with legal changes or developments in our business processes.

  • Significant changes are announced on the website
  • Registered users are notified by email
  • Additional consent may be requested for new rights
  • The current text is always available on the website

⚖️ Legal Compliance

This privacy notice has been prepared in accordance with Turkish Personal Data Protection Law No. 6698 and related legislation. Protecting your personal data is our priority.