Draft text — not yet in force
Scope of this notice
This notice concerns the processing of personal data obtained through the website operated under the HANKA COSMETICS brand. It covers visiting the site and contacting us through it, including requests for product information, samples or private-label production.
This website is a showcase site. No membership or user account is created, no orders are taken, and there is no shopping cart or payment process. Consequently, no credit card, bank account or comparable financial data is processed.
Activities carried out outside this website — such as job applications, supplier relations, CCTV recordings and field sales — fall outside the scope of this notice; separate disclosure texts must be prepared for those processes.
Identity of the data controller
Under the Law, the data controller is the legal entity operating the HANKA COSMETICS brand and the OVOX product brand presented on this website — that is, our company. The identity and contact details of the data controller are mandatory elements of a disclosure notice.
Data controller identity block — being confirmed
Categories of personal data processed
The following categories of personal data may be processed through the site. They consist solely of information shared by the data subject and records generated automatically for technical purposes.
| Category | Example data | Method of collection |
|---|---|---|
| Identity | First name, surname | Directly from the data subject (contact form, e-mail, telephone) |
| Contact | E-mail address, telephone number, company represented, country or city | Directly from the data subject |
| Customer transaction | Content of the enquiry, details of product, sample or private-label production requests, correspondence records | Directly from the data subject |
| Transaction security | IP address, date and time of access, browser and operating system information, addresses of pages viewed (server log records) | Automatically, through the hosting infrastructure |
No special categories of personal data (such as health information, biometric data, religion, association or trade-union membership, or criminal convictions) are requested through this site. Please do not include such data in the messages you send us.
Purposes of processing
The data above is processed only for the following purposes, and in a manner connected, limited and proportionate to those purposes:
- Responding to questions, requests and quotation enquiries and carrying out communication activities
- Evaluating private-label production requests and managing sample and quotation processes
- Conducting pre-contractual discussions and, where a contract is concluded, managing the contractual process
- Providing information about our products, production capabilities and certification scope
- Following up and recording requests and complaints
- Ensuring the security of the website and detecting misuse or attack attempts (server log records)
- Fulfilling obligations arising from applicable legislation and responding to requests from competent public authorities
- Protecting rights and interests in the event of a legal dispute and conducting legal affairs
Your personal data is never sold, rented or transferred to third parties for marketing purposes without your explicit consent.
Method of collection and legal grounds
Your personal data is obtained electronically, by wholly or partly automated means, through the contact channels on the website, e-mail and telephone, as well as through records kept automatically by the servers hosting the site.
Processing is based on the following legal grounds set out in Article 5 of the Law:
- Art. 5/2-(c)Processing is directly related to the conclusion or performance of a contract: conducting quotation, sample and private-label production discussions.
- Art. 5/2-(ç)Processing is mandatory for the data controller to fulfil its legal obligations: statutory retention, documentation and reporting duties.
- Art. 5/2-(e)Processing is mandatory for the establishment, exercise or protection of a right: retaining correspondence that may serve as evidence in a dispute.
- Art. 5/2-(f)Processing is mandatory for the legitimate interests of the data controller, provided it does not harm the fundamental rights and freedoms of the data subject: website security and management of enquiries.
- Art. 5/1Explicit consent: sought only where none of the grounds above applies. Commercial electronic messages (promotions, newsletters) may only be sent with prior approval under Law No. 6563.
Transfer of personal data
In accordance with Articles 8 and 9 of the Law, your personal data may be transferred, strictly limited to the purposes above, to the following parties:
- Suppliers providing hosting, e-mail and information technology services — as data processors and under contracts compliant with the Law
- Providers of legal, accounting and audit services
- Competent public authorities and judicial bodies, upon lawful request
Transfers abroad may take place under Article 9 of the Law where appropriate safeguards exist, such as an adequacy decision, standard contractual clauses, binding corporate rules or a written undertaking. Servers located outside Türkiye may technically constitute a transfer abroad.
Hosting provider and server location — being confirmed
Retention periods and erasure
Your personal data is retained for as long as necessary for the purpose of processing, taking into account the minimum periods required by legislation and the applicable statutes of limitation:
- Enquiries and quotation requests: after the request is concluded, for the limitation period applicable to disputes that may arise from the relationship
- Server log records: for the period necessary to ensure information security
- Where a contractual relationship is established, commercial books, records and documents: for the retention periods set out in Turkish Commercial Code No. 6102 and Tax Procedure Law No. 213
Once the retention period expires or the grounds for processing cease to exist, personal data is erased, destroyed or anonymised in accordance with the Regulation on the Erasure, Destruction or Anonymisation of Personal Data.
Retention and destruction policy — being confirmed
Data security measures
Under Article 12 of the Law, administrative and technical measures must be taken to prevent unlawful processing of and access to personal data and to ensure its safekeeping. The following headings are taken as a basis:
- Serving site traffic over an encrypted connection (HTTPS/TLS)
- Limiting access to personal data according to job definitions and recording access authorisations
- Confidentiality undertakings with employees and Law-compliant contracts with data-processing suppliers
- Notifying the data subject and the Board as soon as possible in the event of a data breach, pursuant to Article 12/5 of the Law
Inventory of applied technical and administrative measures — being confirmed
Rights of the data subject (Article 11)
Every person whose personal data is processed has the right to apply to the data controller and request the following:
- a)To learn whether their personal data is being processed;
- b)To request information if their personal data has been processed;
- c)To learn the purpose of processing and whether the data is used in accordance with that purpose;
- ç)To know the third parties to whom their personal data is transferred, in Türkiye or abroad;
- d)To request rectification where their personal data has been processed incompletely or inaccurately;
- e)To request erasure or destruction of their personal data under the conditions set out in Article 7 of the Law;
- f)To request that actions taken under (d) and (e) be notified to third parties to whom the data was transferred;
- g)To object to a result to their detriment arising from the analysis of the processed data exclusively by automated systems;
- ğ)To claim compensation for damage suffered as a result of unlawful processing of their personal data.
How to apply and applicable time limits
Requests relating to the rights above are submitted to the data controller in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller. An application must contain the following:
- 01Name, surname and, if the application is in writing, a signature
- 02Turkish ID number for Turkish citizens; nationality, passport number or, if any, identity number for foreign nationals
- 03Address of residence or place of business for service of notice
- 04If any, e-mail address, telephone and fax number for notification
- 05A clear statement of the subject of the request
An application may be submitted in person or through a notary by signed written petition, or by using a registered electronic mail (KEP) address, secure electronic signature, mobile signature, or an e-mail address previously registered in the data controller's system.
Applications are concluded free of charge as soon as possible and in any event within thirty days, depending on the nature of the request. Where the process entails an additional cost, the fee set out in the tariff determined by the Personal Data Protection Board may be charged.
Application address and channels — being confirmed
Complaint to the Personal Data Protection Board
If the application is rejected, the response is found insufficient, or no response is given within the prescribed period, the data subject may lodge a complaint with the Personal Data Protection Board within thirty days of learning of the response and, in any case, within sixty days of the date of application (Article 14). Under Article 13, applying to the data controller is a prerequisite before lodging a complaint with the Board.
Entry into force and updates
This notice may be updated in line with changes in legislation and business processes. The current version is always published on this page. Detailed information about cookies and similar technologies is provided in the Cookie Policy, while the site's general privacy approach is set out in the Privacy Policy.
This text is provided for information purposes only and does not constitute legal advice. Before it enters into force, our data controller identity details will be completed and the final version will be approved by our legal counsel.

