Legal Information
Personal Data Protection Notice (KVKK)
- Effective date
- 16.07.2026
- Last updated
- 16.07.2026
01Data controller
For personal data processed through www.servetnamli.com, the data controller under Türkiye’s Law No. 6698 on the Protection of Personal Data (KVKK) is Servet Namlı.
Website: www.servetnamli.com · Email and KVKK application channel: contact@servetnamli.com
This Notice explains how personal data is processed when a person visits the website or contacts Servet Namlı through the contact form or by email.
02Personal data processed
The following personal data may be processed when the website is used or the contact form is submitted:
- Identity information: the user’s name and surname, or the name entered in the form.
- Contact information: email address and any other contact details voluntarily included in the message.
- Communication and request information: message content, subject, request, suggestion, opinion, collaboration proposal and related correspondence.
- Transaction security and technical information: IP address, connection date and time, browser and device information, error and security logs, and server records technically generated by the hosting infrastructure.
- Please do not include unnecessary sensitive information such as health data, biometric data, political opinions, religious beliefs, criminal conviction data, identity numbers, or banking and payment information in the contact form.
03Purposes of processing
Personal data is not used for advertising, electronic marketing, automated profiling or similar purposes unless the user separately requests it or another valid legal basis applies.
- Receiving, evaluating and responding to communication requests
- Managing professional communication and potential collaboration processes
- Conducting necessary correspondence with the requester
- Maintaining the security, integrity and technical continuity of the website
- Preventing spam, misuse, unauthorised access and cybersecurity risks
- Evaluating legal requests and establishing, exercising or protecting a right where necessary
- Responding to lawful requests from authorised public authorities
- Complying with obligations arising from applicable legislation
04Legal grounds for processing
Depending on the nature of the activity, personal data may be processed on the legal grounds set out in Article 5 of Law No. 6698.
Separate explicit consent is not requested for ordinary personal data collected through the contact form. If a separate activity requiring explicit consent is introduced, the data subject will be informed clearly and separately.
- Legitimate interests: receiving and responding to contact requests, securing the website and preventing misuse, provided that the fundamental rights and freedoms of the data subject are not harmed.
- Establishment or performance of a contract: where a message concerns a potential service, project, consultancy, collaboration or other contractual relationship and processing is directly necessary.
- Establishment, exercise or protection of a right: where processing is necessary in connection with a legal request, dispute or claim.
- Legal obligation: where processing is necessary for the data controller to comply with obligations under applicable law.
05Collection methods
Personal data may be provided directly by the data subject or generated automatically through technical processes required for the operation and security of the website.
- The contact form on the website
- Emails sent to contact@servetnamli.com
- Follow-up correspondence with the user
- Server, hosting, security and error logs
- Technical tools and cookies necessary for the operation of the website
06Transfer of personal data
Personal data may be shared with the following recipient groups only to the extent required for the processing purpose and subject to appropriate security measures.
Personal data is not sold, rented or shared for independent advertising or marketing activities.
- Website hosting and server service providers
- Email and communication infrastructure providers
- Cybersecurity, spam prevention, backup and technical-support providers
- Authorised service providers supporting legal, information technology or similar functions
- Public institutions and authorities authorised by law
- Lawyers, advisers, courts and competent authorities for the establishment, exercise or protection of a right
07International data transfers
If servers used for hosting, content delivery, email, spam prevention, security or form transmission are located outside Türkiye, personal data may technically be transferred abroad.
Any such transfer is carried out only where the conditions in Article 9 of Law No. 6698 are satisfied and the required transfer mechanism is in place.
A service for which the necessary international-transfer mechanism cannot be established will not be used, or an alternative infrastructure that does not require the transfer will be preferred.
08Retention periods
Personal data is retained only for as long as necessary for the purpose for which it was processed.
When the retention period ends or the reason for processing no longer exists, the data is deleted, destroyed or anonymised in accordance with applicable law.
The periods below are the maximum periods envisaged for the current website operation; actual email, hosting and backup practices are maintained consistently with these periods.
- Ordinary contact-form records and correspondence: up to 2 years after the last communication
- Server, security and access logs: up to 6 months after creation
- Correspondence that develops into a contractual or business relationship: for the applicable statutory limitation and retention periods after that relationship ends
- Records concerning a legal dispute: until the dispute is finally resolved and the relevant statutory periods expire
09Data security
Appropriate technical and organisational measures are taken to protect personal data against unauthorised access, unlawful processing, loss, alteration or disclosure.
To the extent practicable, the following measures are applied:
No transmission over the internet can be guaranteed to be completely risk-free. Nevertheless, reasonable and appropriate safeguards are used to protect personal data.
- Use of HTTPS on the website
- Delivery of form data only to the authorised email account
- Strong and unique passwords for email and hosting accounts
- Use of multi-factor authentication
- Keeping systems, software and components up to date
- Spam and abuse-prevention controls
- Limiting access rights to need
- Regular deletion of unnecessary personal data
- Restricted access to backups and security logs
10Rights of the data subject
Under Article 11 of Law No. 6698, a personal data subject has the following rights:
- To learn whether personal data is processed
- To request information if personal data has been processed
- To learn the purpose of processing and whether the data is used for that purpose
- To know the third parties to whom personal data is transferred in Türkiye or abroad
- To request correction of incomplete or inaccurate personal data
- To request deletion or destruction when the reasons requiring processing cease to exist
- To request notification of correction, deletion or destruction to third parties to whom the data was transferred
- To object to a result arising against the person through analysis exclusively by automated systems
- To claim compensation for damage resulting from unlawful processing
11Applications to the data controller
KVKK requests may be sent to contact@servetnamli.com from an email address previously notified to the data controller and recorded in the relevant systems.
Only information necessary and proportionate for securely verifying the applicant’s identity will be requested.
Applications are concluded free of charge as soon as possible and within the period prescribed by law, depending on the nature of the request. A fee permitted by applicable legislation may be charged if the process creates an additional cost.
- Name and surname
- Signature if the application is made in writing
- Information sufficient to verify the applicant’s identity
- Address or email address for notification
- Subject and scope of the request
- Supporting information and documents, if any
12Changes to this notice
This Notice may be updated if the website’s technical structure, service providers or personal-data processing activities change.
The current version is always published on the website. The last-updated date is shown when a material change is made.