As Baritci Consulting, we are committed to protecting the privacy of visitors of our website and users of our services. This policy explains how your personal data is collected, processed, stored, and protected. Our policy is prepared in accordance with the Turkish Personal Data Protection Law No. 6698 (KVKK) and relevant legislation.
1. Data We Collect
When you use our website, the following data may be collected:
- Contact information: Name, surname, email address, phone number, company name (via contact form)
- Message content: Requests and messages submitted via the contact form
- Technical data: IP address (anonymized), browser type and version, device information, operating system
- Usage data: Page view statistics, session durations, performance measurements (anonymized)
2. Legal Basis
Your data is processed based on the following legal grounds:
- Legitimate interest: To ensure site security, prevent fraud, and improve performance
- Contractual necessity: To evaluate your request and respond to you
- Explicit consent: For marketing communications and optional analytics cookies (only with your approval)
- Legal obligation: Mandatory data processing activities required by applicable laws
3. Purposes of Processing
Your personal data is processed for the following purposes:
- To respond to your contact requests and provide services
- To manage requests and project processes
- To ensure the security and performance of our website
- To prevent fraud and abuse
- To improve user experience by producing anonymized site statistics
- To fulfill our legal obligations
4. Retention Periods
- Contact data: Retained until the request is concluded and for a reasonable period thereafter
- Technical logs: Retained for up to 90 days for security purposes
- Analytics data: Retained in aggregated/anonymized form for statistical purposes
When legal retention periods expire or the purpose of processing ceases, data is deleted or anonymized.
5. Sharing with Third Parties
Your personal data is never sold or shared with third parties for commercial purposes. It is transferred to authorized public institutions only when legally required. Hosting and infrastructure providers may technically process data; in such cases, appropriate security and confidentiality agreements are ensured.
6. Security Measures
Your data is transmitted via SSL/TLS encryption. Access restrictions, the principle of least privilege, and regular security reviews are applied. Databases are stored encrypted and protected against unauthorized access. Security vulnerabilities are scanned regularly.
7. International Transfers
Your personal data is not transferred abroad by default. If our hosting provider is located abroad, appropriate safeguards required by KVKK (such as standard contractual clauses) are implemented and relevant information is provided.
8. Your Rights
Under KVKK, you have the following rights:
- To learn whether your personal data is processed
- If processed, to request information about it
- To request correction if data is incomplete or inaccurate
- To request deletion or destruction of data
- To request restriction of processing
- To request portability of your data
- To object to automated processing/profiling
- To request compensation for damages
For your requests, you can use our Contact page.
9. Other Matters
Data Controller: Baritci Consulting. You can submit all data protection requests via our contact page.
Children’s Data: We do not knowingly collect personal data from individuals under 18. Without parental/guardian consent, data of minors is not processed.
Profiling: We do not use personalized profiling or automated decision-making. Only aggregated and anonymized measurement is performed.
Complaint: If you cannot obtain a response, you reserve the right to apply to the Personal Data Protection Authority (kvkk.gov.tr).
Updates: This policy may be updated from time to time. Changes are published on this page; major changes may include additional notices.