This is a translation of the Turkish privacy notice. Only the Turkish text is legally binding. Read the Turkish version
The operators of these pages place great importance on the protection of your personal data. We handle your personal data confidentially and in accordance with legal data protection regulations and this privacy policy.
You can generally use our website without providing any personal data. When personal data (such as your name, address, or email address) is collected on our pages, this is always done on a voluntary basis whenever possible. This data will not be transferred to third parties without your explicit consent.
We would like to point out that data transmission over the Internet (such as when communicating via email) may be subject to security vulnerabilities. It is not possible to completely protect data against access by third parties.
If the website uses newsletter tracking, the associated data processing must be addressed separately. The legal basis for data processing is found in Article 6(1)(f) of the GDPR.
When operating a blog with a comment function, additional personal data (e.g., nicknames) is stored. The option to subscribe to comments must also be explained. Posting a comment should not be possible without obtaining consent for the processing of personal data. In this case, a justification under Article 6(1)(a) of the GDPR is possible.
The processing of special category personal data—such as racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership—as well as genetic data, biometric data, health data, or data related to a person’s sex life or sexual orientation, which uniquely identify an individual, is generally prohibited. However, Article 9(2) of the GDPR lists certain exceptions. Website owners must first conduct an assessment if such data is processed on their sites. The relevant consent requirement must also be specified in the privacy policy.
If a website owner provides users with a platform for entering into contracts (e.g., purchase or service agreements), the personal data of the contracting party is generally collected as part of the contract formation process. The website owner must specifically and clearly highlight this data processing. If such data processing is necessary for the performance of the contract, Article 6(1)(b) of the GDPR serves as the legal basis for the data processing.
Many websites use plugins from third-party providers. In such cases, personal data is typically transferred to or automatically transmitted to third parties. The type, scope, purpose, and duration of this personal data processing may vary depending on the situation. Providing a comprehensive list of all instances where personal data is transferred to third parties would exceed the scope of this privacy policy. Therefore, the website owner must individually verify which third-party services are used on their site and whether personal data is transferred in the process.
Accordingly, this data processing must be incorporated into the privacy policy (in accordance with A.II).
Examples of the transfer of personal data to third parties may include:
a) Transfer to service providers
Particularly when contracts are concluded via the website, personal data is typically transferred to service providers (e.g., suppliers). Service providers may also operate solely in the website owner’s interest (e.g., technical support).
b) Payment services and payment methods
The transfer of data to payment services constitutes a specific case of data transfer to service providers.
c) Third-Party Cookies
The use of our own cookies is part of the privacy policy (B.V). In addition, third-party cookies are frequently used. These must be explained in detail. Users must be informed upon accessing the website that third-party cookies are used. Storing these cookies can be prevented through browser settings. The legal basis for the use of third-party cookies is Article 6(1)(f) of the GDPR. Furthermore, the legitimate interest in using the cookies must be specifically stated.
d) Use of Social Media Plugins
When social media plugins are used, users’ personal data is transmitted to social media providers. Under the previous legal framework, it was recommended that such plugins be used only within the scope of a “double-click solution.” In other words, data was transferred only after obtaining prior consent from the user. This approach remains viable and is likely compliant with the law even after the GDPR came into effect. The legal basis for data processing following user consent is Article 6(1)(a) of the GDPR.
e) Website Analytics Services
Website analytics services operated by third parties (e.g., Google Analytics or Adobe Analytics) to improve the efficiency of one’s own website require the transfer of data about website visitors to third parties. In this case, consent is generally not obtained from the user. If the website owner has a legitimate interest, this can be justified under Article 6(1)(f) of the GDPR. To ensure the protection of users’ personal data, it is recommended that data be processed using pseudonyms. In this case, there is generally no obstacle to the use of analytics services or the transfer of pseudonymized data. The exact manner in which analytics services are used must be documented in the privacy policy.
f) Advertising and Marketing Services
If advertisements are displayed on the website, this typically involves the integration of third-party providers (e.g., Google AdSense or AdWords). In this case, the user’s personal data—such as their IP address—is usually transmitted to these third parties. If the advertisements are necessary for the website’s financing, justification is possible under Article 6(1)(f) of the GDPR.
When adding additional elements to the privacy policy, the type, scope, purpose, duration, and options for revocation of the relevant data processing must be specified. The structure could be as follows:
Here, it should be explained in as much detail as possible which personal data is processed on the website, by whom, and how.
This section specifies the legal basis for the processing of personal data. Generally, this basis will be drawn from the list in Article 6(1) of the GDPR.
This section explains in detail the purposes for which the website operator processes personal data. If the processing is justified under Article 6(1)(f) of the GDPR, the legitimate interest for the processing is usually specified here as well. However, in such cases, it must always be verified whether there are less intrusive methods available that cause less harm to the protection of users’ personal data while still achieving the intended purpose.
Generally, data is deleted once the purpose for which it was collected has been fulfilled. However, the specific timing of this deletion must be specified in more detail for each use case. If exact information cannot be provided, at least criteria that facilitate determining the deletion time should be presented.
For every instance of data processing, the user must be informed about how the processing of their data can be prevented or how data that has already been processed can be deleted early. If the user has consented to data processing, this consent must always be revocable. The process of revoking consent should not be more difficult than giving it. The revocation procedure must be explained.
The controller within the meaning of the General Data Protection Regulation (GDPR), other national data protection laws of member states, and other data protection provisions is:
HANTECH GmbH Daimlerstraße 6 76185 Karlsruhe Germany Tel.: 0721 / 90996879 Email: info@hantech.eu Website: www.hantech.eu
The data protection officer of the controller:
Zaim Demirhan Daimlerstraße 6 76185 Karlsruhe Germany Tel.: 0721 / 90996879 Email: info@hantech.eu Website: www.hantech.eu
We process our users’ personal data only to the extent necessary to ensure a functional website and to provide our content and services. The processing of our users’ personal data generally takes place only with the user’s consent. Exceptions apply in cases where obtaining prior consent is not feasible for legitimate reasons and where data processing is permitted by law.
If consent has been obtained from the data subject for the processing of personal data, Article 6(1)(a) of the GDPR serves as the legal basis. If the processing of personal data is necessary for the performance of a contract to which the data subject is a party, Article 6(1)(b) of the GDPR applies as the legal basis. This also applies to processing necessary for pre-contractual measures. If the processing of personal data is necessary to comply with a legal obligation to which our company is subject, Article 6(1)(c) of the GDPR serves as the legal basis. In cases where the processing of personal data is necessary to protect the vital interests of the data subject or another natural person, Article 6(1)(d) of the GDPR serves as the legal basis. If processing is necessary to protect the legitimate interests of our company or a third party, and the data subject’s interests, fundamental rights, and freedoms do not override those interests, Article 6(1)(f) of the GDPR is used as the legal basis for processing.
The data subject’s personal data is erased or blocked once the purpose of retention has ceased. Retention may continue if required by European or national legislation, or by EU regulations, laws, or other regulations to which the controller is subject. When the retention period specified by the standards mentioned above expires, the data is blocked or deleted; otherwise, the data is retained unless its retention is necessary for the conclusion or performance of a contract.
Every time our website is accessed, our system automatically collects data and information from the computer system of the user making the request. The following data is collected during this process:
The data is also stored in our system’s log files. Here, the user’s IP addresses or any other data that could be used to identify a specific user are excluded. This data is not stored together with other personal user data.
The legal basis for the temporary storage of data is Article 6(1)(f) of the GDPR.
The system’s temporary storage of IP addresses is necessary to deliver the website to the user’s computer. For this purpose, the user’s IP address must be stored for the duration of the session.
These purposes also constitute our legitimate interest in data processing pursuant to Article 6(1)(f) of the GDPR.
Data is deleted when it is no longer necessary to achieve the purpose for which it was collected. In the case of data collection for the purpose of providing the website, this applies when the relevant session ends.
The collection of data for the provision of the website and its storage in log files is essential for the operation of the website. Therefore, users have no right to object.
Our website uses cookies. Cookies are text files stored in or by the user’s web browser on the user’s computer system. When a user visits a website, a cookie may be stored on the user’s operating system. This cookie contains a unique string that allows the browser to be uniquely identified when the website is accessed again.
We use cookies to make our website more user-friendly. Certain elements of our website require that the browser making the request can be identified even after a page change.
The following data is stored and transmitted in cookies:
The purpose of using technically necessary cookies is to make websites easier for users to use. Some features of our website cannot be provided without cookies. For these, the browser must be recognized even after a page change.
We require cookies for the following applications:
User data collected through technically necessary cookies is not used to create user profiles.
These purposes constitute our legitimate interest in the processing of personal data pursuant to Article 6(1)(f) of the GDPR.
Cookies are stored on the user’s computer and transmitted from there to our website. As a user, you therefore have full control over the use of cookies. You can disable or restrict the transmission of cookies by changing the settings in your web browser. Cookies that have already been stored can be deleted at any time. This can also be done automatically. If cookies are disabled for our website, not all website features may be fully available.
Our website offers a free newsletter subscription. When you sign up for the newsletter, the data entered in the registration form is transmitted to us.
In addition, the following data is collected during registration:
Your consent is obtained during the registration process for the processing of this data, and reference is made to this privacy policy.
If you purchase a product or service from our website and provide your email address during the transaction, this address may be used later to send you a newsletter. In this case, the newsletter will contain only direct advertisements for our own similar products or services.
No data is transferred to third parties in connection with data processing for newsletter distribution. The data is used solely for the purpose of sending newsletters.
Once a user has subscribed to the newsletter, the legal basis for data processing is Article 6(1)(a) of the GDPR, provided the user has given consent.
The legal basis for sending the newsletter following the sale of a product or service is Section 7(3) of the German Competition Act.
The user’s email address is collected for the purpose of sending the newsletter.
Other personal data collected during the registration process is intended to prevent misuse of the services or the email address provided.
Data is deleted when it is no longer necessary to achieve the purpose for which it was collected. The user’s email address is retained as long as the newsletter subscription remains active.
Other personal data collected during the registration process is generally deleted after seven days.
The newsletter subscription can be canceled by the user at any time. A link for this purpose is included in every newsletter.
Similarly, consent given for the storage of personal data collected during the registration process may be withdrawn.
On our website, we offer users the option to register by providing their personal data. The data is entered into a registration form, transmitted to us, and stored. The data is not transferred to third parties. The following data is collected during the registration process:
The following data is also stored during registration:
During the registration process, the user’s consent to the processing of this data is obtained.
The legal basis for data processing is Article 6(1)(a) of the GDPR, provided the user’s consent is available.
If the registration serves to fulfill a contract to which the user is a party or to implement pre-contractual measures, an additional legal basis for the processing of data is Article 6(1)(b) of the GDPR.
The user’s registration is necessary to provide certain content and services on our website.
Data is deleted when it is no longer necessary to fulfill the purpose for which it was collected.
For data collected during the registration process, this applies when the registration is canceled or modified on our website.
As a user, you have the right to cancel your registration at any time. You may modify the data stored about you at any time.
You may submit your requests for changes or deletion in writing to info@hantech.eu.
Our website features a contact form that can be used for electronic communication. If a user utilizes this feature, the data entered into the form is transmitted to us and stored. This data includes:
The following data is also stored when the message is sent:
Your consent is obtained during the submission process for the processing of this data, and reference is made to this privacy policy.
Alternatively, you may contact us via the email address provided. In this case, any personal data transmitted via email is also stored.
Data is not transferred to third parties in this context. The data is used solely for the purpose of processing the correspondence.
The legal basis for data processing is Article 6(1)(a) of the GDPR, provided that the user has given consent.
The legal basis for processing data transmitted via email is Article 6(1)(f) of the GDPR. If the purpose of the email communication is to enter into a contract, an additional legal basis for data processing is Article 6(1)(b) of the GDPR.
The processing of personal data obtained through the contact form is solely for the purpose of handling the communication request. In the case of communication via email, there is also a legitimate interest in the processing of the data.
Other personal data processed during the submission process is intended to prevent misuse of the contact form and to ensure the security of our information technology systems.
Data is deleted when it is no longer necessary to achieve the purpose for which it was collected. For personal data submitted via the contact form’s input fields or via email, this applies once the relevant correspondence has concluded. The correspondence is deemed to have concluded when it is determined that the matter has been definitively resolved.
Personal data collected additionally during the transmission process is deleted no later than seven days afterward.
The user has the right to withdraw their consent to the processing of personal data at any time. If the user contacts us via email, they may object to the storage of their personal data at any time. In such a case, the communication cannot be continued.
The withdrawal must be submitted in writing to info@hantech.eu and applies to all communications established via the contact form and/or email.
All personal data stored in connection with such communication will be deleted in this case.
If your personal data is being processed, you are considered a data subject under the GDPR and have the following rights against the controller:
You may request confirmation from the controller as to whether personal data concerning you is being processed.
If such processing is taking place, you may request the following information from the controller:
You have the right to request information regarding whether personal data concerning you has been transferred to a third country or an international organization. In this context, you may request to be informed about the appropriate safeguards regarding the transfer in accordance with Article 46 of the GDPR.
If the personal data concerning you is inaccurate or incomplete, you have the right to request that the controller rectify and/or complete it. The controller is required to make the correction without delay.
You have the right to receive the personal data concerning you that you have provided to the controller in a structured, commonly used, and machine-readable format. You also have the right to transmit this data to another controller without any hindrance from the controller to whom the data was provided, provided that
When exercising this right, you may also request that the personal data concerning you be transferred directly from one controller to another, to the extent technically feasible. The freedoms and rights of others must not be adversely affected by this.
The right to data portability does not apply to the processing of personal data necessary for the performance of tasks carried out in the public interest or within the scope of public authority vested in the controller.
You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you pursuant to Article 6(1)(e) or (f) of the GDPR; this also applies to profiling based on these provisions.
The data controller will no longer process the personal data concerning you unless it can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.
If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your data for such marketing purposes; this also applies to profiling to the extent it is related to direct marketing.
If you object to processing for direct marketing purposes, the personal data concerning you will no longer be processed for those purposes.
In connection with the use of information society services—regardless of the “2002/58/EC” Directive—you also have the option to exercise your right to object through automated processes based on technical specifications.
You have the right to withdraw your data protection consent at any time. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent prior to withdrawal.
You have the right not to be subject to a decision based solely on automated processing (including profiling) if that decision produces legal effects concerning you or similarly significantly affects you. This applies if the decision
. However, these decisions may not be based on special categories of personal data under Article 9(1) of the GDPR, unless Article 9(2)(a) or (g) of the GDPR applies and appropriate measures have been taken to protect your rights and freedoms.
In the situations described in paragraphs (1) and (3), the controller shall take appropriate measures to protect your rights and freedoms and legitimate interests, including, at a minimum, your right to request human intervention by the controller, to express your point of view, and to object to the decision.
Regardless of your right to pursue other administrative or judicial remedies, if you believe your personal data has been processed in violation of the GDPR, you have the right to lodge a complaint with a supervisory authority, particularly in the Member State where you reside, work, or where the alleged infringement occurred.
The supervisory authority to which the complaint is submitted shall ensure that the complainant is informed of the status and outcome of the complaint, including the possibility of judicial remedy pursuant to Article 78 of the GDPR.