Skip to content
LEGAL · DATA PROTECTION

Personal Data Protection Notice

This notice explains how personal data is processed in the activities carried out through this website, in accordance with Article 10 of Turkish Law No. 6698 on the Protection of Personal Data ("KVKK") and the related Communiqué on the Procedures and Principles for Fulfilling the Disclosure Obligation.

Draft text — not yet in force

This text is a draft; the final legal text will be published here once our identity and application details are complete. Without the data controller's registered trade name, address, MERSIS number, registered electronic mail (KEP) address and application channels, the disclosure obligation cannot be considered fully met. The fields still being confirmed are marked separately below and none of them has been filled in with assumptions.
01

Scope of this notice

This notice concerns the processing of personal data obtained through the website operated under the HANKA COSMETICS brand. It covers visiting the site and contacting us through it, including requests for product information, samples or private-label production.

This website is a showcase site. No membership or user account is created, no orders are taken, and there is no shopping cart or payment process. Consequently, no credit card, bank account or comparable financial data is processed.

Activities carried out outside this website — such as job applications, supplier relations, CCTV recordings and field sales — fall outside the scope of this notice; separate disclosure texts must be prepared for those processes.

02

Identity of the data controller

Under the Law, the data controller is the legal entity operating the HANKA COSMETICS brand and the OVOX product brand presented on this website — that is, our company. The identity and contact details of the data controller are mandatory elements of a disclosure notice.

Data controller identity block — being confirmed

Our registered trade name, MERSIS number, tax office and number, full address, registered electronic mail (KEP) address, telephone number and application e-mail address are being confirmed and will be published here once complete. These fields have been left blank rather than filled in with assumptions. Whether we are subject to registration with the Data Controllers' Registry (VERBİS), and our registry details if so, are being clarified in the same process.
03

Categories of personal data processed

The following categories of personal data may be processed through the site. They consist solely of information shared by the data subject and records generated automatically for technical purposes.

CategoryExample dataMethod of collection
IdentityFirst name, surnameDirectly from the data subject (contact form, e-mail, telephone)
ContactE-mail address, telephone number, company represented, country or cityDirectly from the data subject
Customer transactionContent of the enquiry, details of product, sample or private-label production requests, correspondence recordsDirectly from the data subject
Transaction securityIP address, date and time of access, browser and operating system information, addresses of pages viewed (server log records)Automatically, through the hosting infrastructure

No special categories of personal data (such as health information, biometric data, religion, association or trade-union membership, or criminal convictions) are requested through this site. Please do not include such data in the messages you send us.

04

Purposes of processing

The data above is processed only for the following purposes, and in a manner connected, limited and proportionate to those purposes:

  • Responding to questions, requests and quotation enquiries and carrying out communication activities
  • Evaluating private-label production requests and managing sample and quotation processes
  • Conducting pre-contractual discussions and, where a contract is concluded, managing the contractual process
  • Providing information about our products, production capabilities and certification scope
  • Following up and recording requests and complaints
  • Ensuring the security of the website and detecting misuse or attack attempts (server log records)
  • Fulfilling obligations arising from applicable legislation and responding to requests from competent public authorities
  • Protecting rights and interests in the event of a legal dispute and conducting legal affairs

Your personal data is never sold, rented or transferred to third parties for marketing purposes without your explicit consent.

05

Method of collection and legal grounds

Your personal data is obtained electronically, by wholly or partly automated means, through the contact channels on the website, e-mail and telephone, as well as through records kept automatically by the servers hosting the site.

Processing is based on the following legal grounds set out in Article 5 of the Law:

  • Art. 5/2-(c)Processing is directly related to the conclusion or performance of a contract: conducting quotation, sample and private-label production discussions.
  • Art. 5/2-(ç)Processing is mandatory for the data controller to fulfil its legal obligations: statutory retention, documentation and reporting duties.
  • Art. 5/2-(e)Processing is mandatory for the establishment, exercise or protection of a right: retaining correspondence that may serve as evidence in a dispute.
  • Art. 5/2-(f)Processing is mandatory for the legitimate interests of the data controller, provided it does not harm the fundamental rights and freedoms of the data subject: website security and management of enquiries.
  • Art. 5/1Explicit consent: sought only where none of the grounds above applies. Commercial electronic messages (promotions, newsletters) may only be sent with prior approval under Law No. 6563.
06

Transfer of personal data

In accordance with Articles 8 and 9 of the Law, your personal data may be transferred, strictly limited to the purposes above, to the following parties:

  • Suppliers providing hosting, e-mail and information technology services — as data processors and under contracts compliant with the Law
  • Providers of legal, accounting and audit services
  • Competent public authorities and judicial bodies, upon lawful request

Transfers abroad may take place under Article 9 of the Law where appropriate safeguards exist, such as an adequacy decision, standard contractual clauses, binding corporate rules or a written undertaking. Servers located outside Türkiye may technically constitute a transfer abroad.

Hosting provider and server location — being confirmed

The hosting provider, server location and corporate e-mail infrastructure used for our site are being confirmed and will be published here once complete. If the servers are located abroad, the legal ground for the transfer under Article 9 of the Law will be stated explicitly in this section.
07

Retention periods and erasure

Your personal data is retained for as long as necessary for the purpose of processing, taking into account the minimum periods required by legislation and the applicable statutes of limitation:

  • Enquiries and quotation requests: after the request is concluded, for the limitation period applicable to disputes that may arise from the relationship
  • Server log records: for the period necessary to ensure information security
  • Where a contractual relationship is established, commercial books, records and documents: for the retention periods set out in Turkish Commercial Code No. 6102 and Tax Procedure Law No. 213

Once the retention period expires or the grounds for processing cease to exist, personal data is erased, destroyed or anonymised in accordance with the Regulation on the Erasure, Destruction or Anonymisation of Personal Data.

Retention and destruction policy — being confirmed

The scope of our Personal Data Retention and Destruction Policy, our retention periods per data category and our periodic destruction cycle are being confirmed and will be published in this section as a concrete retention table once complete.
08

Data security measures

Under Article 12 of the Law, administrative and technical measures must be taken to prevent unlawful processing of and access to personal data and to ensure its safekeeping. The following headings are taken as a basis:

  • Serving site traffic over an encrypted connection (HTTPS/TLS)
  • Limiting access to personal data according to job definitions and recording access authorisations
  • Confidentiality undertakings with employees and Law-compliant contracts with data-processing suppliers
  • Notifying the data subject and the Board as soon as possible in the event of a data breach, pursuant to Article 12/5 of the Law

Inventory of applied technical and administrative measures — being confirmed

Our inventory of the measures actually in place — authorisation matrix, confidentiality undertakings, data processor agreements, backup and log management — is being confirmed and this section will be made specific and published here once complete.
09

Rights of the data subject (Article 11)

Every person whose personal data is processed has the right to apply to the data controller and request the following:

  • a)To learn whether their personal data is being processed;
  • b)To request information if their personal data has been processed;
  • c)To learn the purpose of processing and whether the data is used in accordance with that purpose;
  • ç)To know the third parties to whom their personal data is transferred, in Türkiye or abroad;
  • d)To request rectification where their personal data has been processed incompletely or inaccurately;
  • e)To request erasure or destruction of their personal data under the conditions set out in Article 7 of the Law;
  • f)To request that actions taken under (d) and (e) be notified to third parties to whom the data was transferred;
  • g)To object to a result to their detriment arising from the analysis of the processed data exclusively by automated systems;
  • ğ)To claim compensation for damage suffered as a result of unlawful processing of their personal data.
10

How to apply and applicable time limits

Requests relating to the rights above are submitted to the data controller in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller. An application must contain the following:

  1. 01Name, surname and, if the application is in writing, a signature
  2. 02Turkish ID number for Turkish citizens; nationality, passport number or, if any, identity number for foreign nationals
  3. 03Address of residence or place of business for service of notice
  4. 04If any, e-mail address, telephone and fax number for notification
  5. 05A clear statement of the subject of the request

An application may be submitted in person or through a notary by signed written petition, or by using a registered electronic mail (KEP) address, secure electronic signature, mobile signature, or an e-mail address previously registered in the data controller's system.

Applications are concluded free of charge as soon as possible and in any event within thirty days, depending on the nature of the request. Where the process entails an additional cost, the fee set out in the tariff determined by the Personal Data Protection Board may be charged.

Application address and channels — being confirmed

Our postal address, registered electronic mail (KEP) address, e-mail address and any application form link to which applications should be sent are being confirmed and will be published here once complete. These details have been left blank rather than filled in with assumptions and must be completed before the text enters into force.
11

Complaint to the Personal Data Protection Board

If the application is rejected, the response is found insufficient, or no response is given within the prescribed period, the data subject may lodge a complaint with the Personal Data Protection Board within thirty days of learning of the response and, in any case, within sixty days of the date of application (Article 14). Under Article 13, applying to the data controller is a prerequisite before lodging a complaint with the Board.

12

Entry into force and updates

This notice may be updated in line with changes in legislation and business processes. The current version is always published on this page. Detailed information about cookies and similar technologies is provided in the Cookie Policy, while the site's general privacy approach is set out in the Privacy Policy.

This text is provided for information purposes only and does not constitute legal advice. Before it enters into force, our data controller identity details will be completed and the final version will be approved by our legal counsel.

Other legal texts

The legal texts on this site complement one another; please refer to them for cookie usage and the general privacy approach.