LEGAL
Privacy Notice
What we do with personal data in the two roles we take: as the controller of our own site and enquiries, and as a processor working on a client’s instructions.
Who we are
Webosentez is a design and engineering studio based in Ankara, Türkiye, working with clients and partners internationally. We operate from Kızılırmak Mah. 1445 Sk. The Paragon No: 2/1 İç Kapı No: 113, Çankaya, Ankara, Türkiye. Every request under this notice reaches us at info@webosentez.com or +90 554 864 46 10, and is answered by a named person rather than a ticket queue.
The two roles we take
The distinction matters, because your rights and our obligations differ between them.
- As a controller. For visitors to webosentez.com, people who write to us, and the contacts at the agencies and brands we correspond with, we decide why and how the data is handled. That is what most of this notice is about.
- As a processor. When we build, host or maintain a system for a client or an agency partner, any personal data inside that system belongs to them. They decide what happens to it; we act only on their documented instructions. If you are an end user of a site we built, the operator of that site is your controller, not us.
What we collect as a controller
- Identity and contact data: the name, company, email address and phone number you give us through the scope form or by email, phone or WhatsApp.
- Enquiry content: what you tell us about the project, your current site address, and a budget range if you choose to share one.
- Booking data: if you book a call, the name, email address and any notes you enter, held by our scheduling provider.
- Security data: the IP address of a form submission, kept briefly to prevent abuse.
- Usage data: if and only if you consent, aggregate visit statistics through analytics cookies. See the cookie policy.
Why we process it, and on what lawful basis
| Purpose | Lawful basis |
|---|---|
| Answering your enquiry, scoping the work and preparing a proposal | Steps taken at your request before entering a contract (GDPR Art. 6(1)(b)) |
| Delivering a project and supporting it after launch | Performance of a contract (GDPR Art. 6(1)(b)) |
| Business correspondence with people at partner organisations | Our legitimate interest in running the studio (GDPR Art. 6(1)(f)) |
| Keeping the site secure and preventing form abuse | Legitimate interest (GDPR Art. 6(1)(f)) |
| Measuring how the site is used | Your consent, withdrawable at any time (GDPR Art. 6(1)(a)) |
| Accounting, invoicing and tax records | Legal obligation under Turkish law (GDPR Art. 6(1)(c)) |
Under Turkish law the same processing rests on KVKK Art. 5/2-c for contract-related data, Art. 5/2-f for legitimate interest, Art. 5/2-ç for legal obligations, and explicit consent under Art. 5/1 for analytics.
Unsolicited business email
If we write to your organisation about working together, every message carries a working one-click unsubscribe header and a link that removes you without a reply. We act on a refusal within three business days and keep only the minimum record needed to make sure we do not write again.
Who else sees the data
We do not sell personal data and we do not share it for anyone else’s marketing. Access is limited to the providers that make the service work:
| Provider | What for | Where |
|---|---|---|
| Hostinger International Limited | The server running this site, its database and our mail | Frankfurt, Germany |
| Cal.com, Inc. | Call scheduling, if you book one | United States |
| Google Ireland Limited and Google LLC | Analytics, only with your consent | Ireland and the United States |
Worth noting for European buyers: this site, its database and our mail all run on a single server in Frankfurt. Enquiry data stays inside the EU at rest. What crosses a border is our own access to it from Ankara, which is the transfer the safeguards below cover.
On client projects the provider list depends on that project’s architecture and is set out in the agreement covering it. We do not add a sub-processor to a client system without telling the client first.
Transfers out of the EU and the UK
We are established in Türkiye. Türkiye is not covered by a European Commission adequacy decision, so sending personal data from the EEA to us is a restricted transfer and needs a safeguard under Chapter V of the GDPR.
- For EEA clients and partners: we sign the Commission’s Standard Contractual Clauses (Implementing Decision (EU) 2021/914) as data importer, together with a transfer impact assessment, before any personal data reaches us.
- For UK clients and partners: we sign the same clauses with the ICO’s International Data Transfer Addendum, or the IDTA on its own.
- In the other direction: when we send personal data out of Türkiye, KVKK Art. 9 as amended in 2024 lets us rely on the Authority’s standard contract, filed with the Personal Data Protection Authority within five business days of signature.
A data processing agreement with the relevant clauses attached is available on request, before a project starts. Ask and we will send the current version the same working day.
How long we keep it
- Enquiries that do not become projects: up to 2 years
- Contract records: 10 years from the end of the relationship, matching the limitation period under the Turkish Code of Obligations
- Accounting and invoice records: 10 years under Turkish tax and commercial law
- Security logs: 1 year
- Analytics cookies: the periods listed in the cookie policy
- Client data we hold as a processor: for as long as the client instructs, then deleted or returned at their choice
Once a period ends, data is deleted, destroyed or anonymised.
How we protect it
Transport is encrypted end to end, credentials are held outside version control, server access is limited to named accounts with key-based authentication, and backups are taken on a schedule and tested. If a breach affects data we hold for a client, we notify that client without undue delay so they can meet their own 72-hour obligation.
Your rights
If the GDPR applies to you, you have the right to access your data, correct it, have it erased, restrict or object to processing, receive it in a portable format, and withdraw consent at any time without affecting processing already carried out. Where we rely on legitimate interest, you can object and we will stop unless we can show compelling grounds that override your rights.
Under Turkish law, KVKK Art. 11 gives you a comparable set: to learn whether your data is processed, to be told the purpose, to know the third parties it has been transferred to in Türkiye or abroad, to have it corrected, erased or destroyed, to have those changes passed on, to object to a decision produced solely by automated analysis, and to claim compensation for unlawful processing.
Making a request
Write to info@webosentez.com with your name, contact details and what you are asking for. We answer within one month under GDPR Art. 12(3) and within thirty days under Turkish law. There is no charge for a first request.
If you are not satisfied with our answer, you can complain to the supervisory authority in your country of residence or work, to the ICO in the United Kingdom, or to the Turkish Personal Data Protection Authority. You can go to a supervisory authority without asking us first.
Last updated: August 2026.