Privacy Policy

Who we are and how to reach us

KuarkTek Digital ("KuarkTek", "we", "us") is a digital design studio based in Ankara, Türkiye. For the purposes of the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the EU General Data Protection Regulation ("GDPR"), KuarkTek Digital is the data controller of the personal data described in this policy.

Questions about this policy, requests about your data and complaints should be sent to the email address above with the subject line "Personal data". We reply to every request.

What this policy covers

This policy applies to the website at kuarktek.digital and its subpages, to the enquiry forms on the site, and to the personal data we handle when you email, call or meet us about a project. It does not cover the websites we link to, or the data our clients collect on the websites and applications we build for them. Those are governed by each owner's own privacy notice.

When we build or run a website, campaign or application for a client, we usually act as a data processor on the client's instructions. Our role in that setting, and the safeguards that apply, are described in our GDPR Policy.

The data we collect

We collect personal data in three ways: you give it to us, it is created automatically when you use the site, or it is shared with us during a project.

Data you give us

When you send the "Start a Project" form, the "Let's talk" form or an email, we receive what you type:

  • your name and email address;
  • your company name, if you provide it;
  • the budget range you select, if you provide it;
  • the description of your project or your message;
  • a file you attach, if any (up to 5 MB);
  • anything else you choose to tell us, including on the phone or in a meeting.

Both forms contain a hidden field that is invisible to people and exists only to catch automated spam. It is not used for anything else.

Data created when you use the site

Like every website, kuarktek.digital is served by a web server that records standard technical logs: your IP address, the pages requested, the date and time, the browser and device type, and the referring page. These logs are kept by our hosting provider for security and troubleshooting and are not combined with the contents of your enquiries.

When you submit a form, a hashed (one-way, unreadable) form of your IP address is held on the server for fifteen minutes so that the form cannot be flooded. The original address is not stored by the form.

The site stores two small technical values in your browser's session storage: one that remembers the site's opening animation has already played, and one that remembers your device asked for a lighter animation mode. They contain no personal data, are never sent to us, and are removed when you close the tab. We do not use analytics cookies, advertising pixels or tracking scripts. Full detail is in our Cookie Policy.

Data shared during a project

If we work together, we will process the names, business contact details and roles of the people involved, the contents of the briefs, documents and assets you share, and the personal data contained in the materials we design, write or film for you (for example, team portraits or testimonials). Where that data belongs to your customers or users, we handle it under the written agreement between us.

PurposeData usedLegal basis (KVKK / GDPR)
Answering your enquiry and assessing whether we can helpForm and email contentsSteps taken at your request before a contract (KVKK Art. 5(2)(c); GDPR Art. 6(1)(b))
Preparing proposals, delivering projects, invoicingContact details, project materialsPerformance of a contract; legal obligations on invoicing and record-keeping (KVKK Art. 5(2)(a), (c), (ç); GDPR Art. 6(1)(b), (c))
Keeping the site available and secure, preventing spam and abuseServer logs, hashed IP, honeypot fieldOur legitimate interest in running a safe service (KVKK Art. 5(2)(f); GDPR Art. 6(1)(f))
Staying in touch after a project about relevant workBusiness contact detailsOur legitimate interest in maintaining client relationships; you can object at any time (KVKK Art. 5(2)(f); GDPR Art. 6(1)(f))
Publishing a case study or testimonial that names youName, role, company, likeness, quotesYour explicit consent, which you can withdraw (KVKK Art. 5(1); GDPR Art. 6(1)(a))
Meeting legal obligations or responding to lawful requestsAs requiredLegal obligation (KVKK Art. 5(2)(ç); GDPR Art. 6(1)(c))

We do not use your data for automated decision-making or profiling, and we never sell or rent personal data.

Who can see your data

Your data is seen only by the KuarkTek team members who need it for the purposes above, and by a small number of service providers who process it on our instructions:

  • Hosting. kuarktek.digital is hosted by Hostinger International Ltd. Server logs and form submissions pass through its infrastructure. Hostinger operates data centres in several regions, including the European Union.
  • Email. Form submissions are delivered to our mailbox at info@kuarktek.digital. Correspondence is stored by our email service provider.
  • Project tools. During a project we may use file-sharing, design, project-management and video-conferencing tools to collaborate with you. Each provider is bound by its own data-processing terms.
  • Professional advisers. Accountants, lawyers and insurers, where necessary and under confidentiality.
  • Authorities. Courts, regulators or law-enforcement bodies when the law requires it.

We do not share personal data with advertising networks or data brokers.

International transfers

KuarkTek is based in Türkiye. If you contact us from the European Economic Area, the United Kingdom or Switzerland, your data will be transferred to Türkiye, which has not received an adequacy decision from the European Commission. We rely on the transfer being necessary to respond to your request and to perform a contract with you (GDPR Art. 49(1)(b)) and, where we sign a data-processing agreement with a client, on the European Commission's Standard Contractual Clauses.

Where our service providers store data outside Türkiye, we transfer it in line with the safeguards required by KVKK Art. 9 and the decisions of the Personal Data Protection Board.

How long we keep your data

  • Enquiries that do not become projects: up to 3 years after our last exchange, so we can pick up the conversation if you return. Earlier on request.
  • Client projects: for the life of the relationship and then for 10 years after the last invoice, as required by the Turkish Commercial Code and the Tax Procedure Law for commercial records.
  • Server logs: kept by our hosting provider for a limited period, typically no more than a few months, unless needed to investigate a security incident.
  • Anti-spam IP hash: 15 minutes.
  • Published case studies and testimonials: until you withdraw consent or ask us to remove them.

When the retention period ends, data is deleted or anonymised.

How we protect your data

The site is served over HTTPS only. Form submissions are size-limited, validated, rate-limited and accepted only from our own domain. Access to our mailbox, project tools and files is restricted to the team members who need it and protected by strong authentication. Source files, drafts and internal documents are never published to the web server. We review these measures as the site and our tools change.

No method of transmission or storage is completely secure. If we become aware of a breach that puts your rights at risk, we will notify you and the competent authority as the law requires.

Your rights

Under KVKK Art. 11 and GDPR Arts. 15–22, you have the right to:

  • learn whether we process your personal data and, if so, request information about it;
  • learn the purpose of processing and whether the data is used for that purpose;
  • know the third parties in Türkiye or abroad to whom the data has been transferred;
  • request correction of incomplete or inaccurate data;
  • request deletion or destruction of the data where the conditions in the law are met;
  • request that corrections and deletions be communicated to the third parties who received the data;
  • object to a result that was produced against you by the exclusive analysis of the data through automated systems;
  • claim compensation for damage caused by unlawful processing;
  • under the GDPR, additionally request restriction of processing, receive your data in a portable format, object to processing based on legitimate interests, and withdraw consent at any time without affecting earlier processing.

To exercise any of these rights, email info@kuarktek.digital or write to our postal address. We may ask you to confirm your identity before acting on a request. We answer within 30 days (KVKK) or one month (GDPR), free of charge unless a request is manifestly unfounded or excessive.

If you are not satisfied with our response, you can lodge a complaint with the Turkish Personal Data Protection Board (Kişisel Verileri Koruma Kurulu, kvkk.gov.tr) or, if you are in the EEA, with the supervisory authority of your country of residence.

Children

kuarktek.digital is a business-to-business website and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.

The site links to client websites, award platforms and social networks. We do not control those sites and are not responsible for their privacy practices. Read their notices before sharing data with them.

Changes to this policy

We will update this policy when our practices, our tools or the law change. The date at the top of the page shows the latest version. Significant changes will be announced on this page; continued use of the site after a change means the updated policy applies.