NATO Facility Security Cleared Production Erenler / SAKARYA
TREN
+90 542 826 28 60 [email protected]
  1. Home
  2. Data Protection Notice
Protection of Personal Data

Data Protection Notice

Prepared in accordance with Article 10 of Turkish Law No. 6698 on the Protection of Personal Data.

1. Identity of the Data Controller

Data Controller: Kovansan Metal İşleme ve Makina Pazarlama Sanayi Ticaret A.Ş.
Address: Küçükesence Mah. 30 No'lu Cad. No:29, Erenler / SAKARYA
E-mail: [email protected]
Phone: +90 542 826 28 60

Under Turkish Law No. 6698 on the Protection of Personal Data, your personal data is processed by our company, whose details appear above, acting as data controller and within the scope explained below.

2. Categories of Personal Data Processed

Only the data you submit is processed through our website. There is no membership, payment or profile creation on the site.

  • Identity data: First name, surname
  • Contact data: E-mail address, telephone number
  • Customer transaction data: Company name, the calibre or product enquired about, and information you share in the message body (quantity, tolerance, delivery schedule and similar)
  • Transaction security data: IP address, access time and browser information held in server logs

No special categories of personal data are requested through our site. Please do not enter special category data such as health, biometric or criminal conviction information into the form fields.

3. Purposes of Processing

  • Responding to your quotation, price and technical information requests
  • Conducting the sale of goods and services and enabling pre-contractual discussions
  • Managing communication activities and handling requests and complaints
  • Operating information security processes and ensuring site security
  • Providing information to authorised persons and institutions and fulfilling legal obligations

4. Legal Grounds

Your personal data is processed on the following legal grounds set out in Article 5 of the Law:

  • Art. 5/2-c: processing is necessary for personal data of the parties to a contract, provided it is directly related to the conclusion or performance of that contract
  • Art. 5/2-ç: processing is mandatory for the data controller to fulfil its legal obligations
  • Art. 5/2-e: processing is mandatory for the establishment, exercise or protection of a right
  • Art. 5/2-f: processing is mandatory for the legitimate interests of the data controller, provided it does not harm the fundamental rights and freedoms of the data subject
  • Art. 5/1: for non-essential cookies and third-party embedded content, your explicit consent

5. Collection Method

Your personal data is collected through the quotation and contact form on our website, e-mail, telephone and WhatsApp channels, electronically and by automated means .

6. Transfer of Personal Data

Your personal data is never sold or rented to third parties for marketing purposes. Transfers take place only in the following cases and in accordance with Articles 8 and 9 of the Law:

  • To our hosting and e-mail service providers — for the operation of the technical infrastructure, acting as data processors
  • To authorised public institutions — within the scope of statutory information and document requests
  • To our legal, accounting and audit service providers — for the fulfilment of legal obligations and the protection of rights

If you choose to use the embedded map service, your IP address and browser information are transmitted directly to the third party providing that content (Google Ireland Ltd.). This transfer takes place only with your explicit consent ; the map is not loaded unless you give consent. For details see the Cookie Policy.

7. Retention Periods

  • Quotation and contact form records: From the conclusion of the enquiry, 2 yearswhere no commercial relationship is established; where one is established, 10 years from the end of the relationship (Turkish Code of Obligations limitation period)
  • Server access logs: 2 years
  • Cookie and accessibility preferences: Stored in your browser; cookie consent is renewed after 12 months . This data is not transmitted to our servers.

At the end of the period your personal data is deleted, destroyed or anonymised, either automatically or upon your request.

8. Your Rights as a Data Subject (Article 11)

By applying to the data controller you have the right to:

  • learn whether your personal data is being processed,
  • request information if it has been processed,
  • learn the purpose of processing and whether the data is used in line with that purpose,
  • know the third parties to whom the data is transferred domestically or abroad,
  • request correction if the data is incomplete or incorrectly processed,
  • request deletion or destruction within the conditions set out in Article 7,
  • request that correction, deletion and destruction be notified to third parties to whom the data was transferred,
  • object to a result arising against you from analysis carried out solely by automated systems,
  • claim compensation if you suffer damage due to unlawful processing

.

9. Application Procedure

You may submit your requests in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller , together with information identifying you, your full address, the subject of your request and any supporting documents:

  • In writing: by wet-signed petition to Küçükesence Mah. 30 No'lu Cad. No:29, Erenler / Sakarya, Türkiye,
  • By e-mail: [email protected] ,
  • By registered electronic mail (KEP), secure electronic signature or mobile signature

Your application will be concluded free of charge within 30 days at the latest , depending on the nature of the request. Where the process incurs an additional cost, the fee in the tariff set by the Board may be charged. If your application is rejected or not answered in time, you retain the right to lodge a complaint with the Personal Data Protection Board.

10. Data Security

Appropriate technical and organisational measures are taken to prevent unlawful processing of and access to your personal data and to ensure its safekeeping, including TLS/HTTPS encryption in transit, an authorisation matrix and access restrictions, application of current software and security patches, regular backups, staff confidentiality undertakings and awareness training.

This document was last updated on 2026-09-14 . Changes take effect as soon as they are published on this page.