Privacy policy and KVKK notice
This notice sets out what personal data Baki Bilisim processes, for which purposes and on which legal ground, how long it is kept, who it reaches, and how you exercise your rights under Turkish data protection law. The controller is Baki Bilisim; requests go to bilgi@bakibilisim.com.
Who and what does this notice cover?
This notice covers visitors to bakibilisim.com, corporate enquirers who complete a form here, and anyone who contacts us by email, phone or WhatsApp. It does not cover end-user data inside client projects: there the client organisation is the controller and Baki Bilisim acts only as a processor. Version 1.3, in force 15 September 2026.
The distinction matters, so we state it first. When we build a website, a mobile application or a dealer portal for you, the visitor and customer data collected in that system belongs to your controllership; we act as a processor bound by contract. How that responsibility is divided is written out clause by clause in the contract section of our working model. The text below describes only our own processing.
Written for a reader who already knows the GDPR: clause 02 maps the Turkish regime onto the concepts you use daily, and states plainly where the two diverge.
Who is the data controller?
The controller under Law No. 6698 on the Protection of Personal Data is Baki Bilisim, Karabaş Mah. Salim Dervişoğlu Cad., Ncity AVM, Floor 2, İzmit / Kocaeli, Turkey. Email bilgi@bakibilisim.com, telephone +90 507 817 27 17. Every request concerning your personal data is handled through these contact details.
This notice applies to the bakibilisim.com domain and its subpages, and to the email, telephone and WhatsApp correspondence conducted from that address. The full contact record and the application procedure appear in the requests section below; the company record is also set out on our about page.
Baki Bilisim is a digital agency that builds corporate websites, mobile applications and brand identity systems, and engineers visibility in search, answer and generative engines. Because of that focus, the personal data we handle is overwhelmingly corporate: company name, role in the organisation, work email and work telephone. We do not sell a consumer product, so we keep no large customer database.
How does KVKK compare with the GDPR?
KVKK is Turkey's data protection law, in force since 2016 and drafted along the lines of the earlier EU Directive 95/46/EC. Its structure will feel familiar: controllers, processors, lawful grounds, data subject rights, security duties. It is not the GDPR, and Turkey holds no EU adequacy decision. The parallels below are described without any claim of equivalence.
We include this clause because most readers of the English version of this site sit in an EU, UK or global procurement function and evaluate a Turkish supplier against a framework they already know. The table is an orientation aid, nothing more.
| Topic | Under KVKK (Law No. 6698) | The counterpart you know |
|---|---|---|
| Instrument | Law No. 6698 on the Protection of Personal Data, published 7 April 2016, together with secondary regulations and Board decisions. | Regulation (EU) 2016/679, applicable from 25 May 2018. |
| Roles | veri sorumlusu (data controller) and veri işleyen (data processor). | Controller and processor, with the same division of duties. |
| Lawful grounds | Article 5: explicit consent, or one of the six listed conditions. The list is exhaustive. | Article 6: six lawful bases, also exhaustive. |
| Consent | Explicit consent must be informed, freely given and specific to the processing; it is a separate ground, not a catch-all. | Articles 4(11) and 7, with the same conditions of validity. |
| Data subject rights | Article 11 lists nine headings. There is no separately named right to data portability. | Articles 15 to 22, including portability under Article 20. |
| Response deadline | At the latest 30 days from the application, free of charge (Article 13). | One month, extendable in defined cases (Article 12(3)). |
| Supervisory authority | The Personal Data Protection Board. A complaint is admissible only after you have first applied to the controller (Article 14). | The competent national supervisory authority, which you may address directly (Article 77). |
| Breach notification | Notification to the Board as soon as possible; the Board's decision sets that period at 72 hours (Article 12/5). | 72 hours to the supervisory authority (Article 33). |
| Transfers abroad | Article 9, as amended in 2024: an adequacy decision, appropriate safeguards such as a standard contract, or one of the exceptions listed in the law. | Chapter V, Articles 44 to 49. |
| Adequacy status | Turkey is not covered by an EU adequacy decision. | Transfers to Turkey therefore rest on safeguards or derogations under Chapter V. |
The two regimes differ in scope, definitions, exemptions, sanctions and enforcement practice. Nothing in this table should be read as a statement that compliance with one satisfies the other. Where a project we deliver has to face GDPR obligations on your side, the arrangement is agreed in the project contract and in a separate processing agreement, not in this notice.
Which personal data is processed?
Three groups: the corporate and contact details you type into a form on this site, the content of your email, telephone or WhatsApp correspondence, and the technical access records the server writes automatically. No special categories of personal data are collected; please do not enter health, belief, membership or biometric information into the forms.
The site carries two forms: the project brief form on the contact page and the request form for the free digital asset audit. Both ask only for the fields needed to assess your request and reply to you, and every field is listed by category in the table below. Nothing is collected outside those forms: the site has no registration, membership, comment, search or basket function.
| Data category | Fields collected | Source |
|---|---|---|
| Identity | First name and surname. | The person completing the form: you, directly. |
| Contact | Email address, telephone number and, optionally, preferred contact channel. | You, directly. The same data arises when you write to us by email, telephone or WhatsApp. |
| Enquiry and customer transaction | Company name, industry, web address, number of locations and languages, existing digital assets, need headings, request type, employee count band, timeline, budget band, role in the organisation, decision process, and whatever you write in the free-text field. | You, directly, through the form. |
| Transaction security (technical log) | IP address, requested address, date and time, HTTP status code, browser and operating system string, referring address where present. | The hosting server's automatic access log. We run no additional tracking code. |
| Consent record | The fact that the data protection consent box was ticked on submission, plus the date and time of submission. | The form submission; retained as proof that explicit consent was given. |
| Preference kept on your device | The light or dark theme you chose (bb-theme). |
Your browser's local storage. It is never sent to the server and we cannot read it. |
If you choose to correspond over WhatsApp, the content of your message and your telephone number are also processed on WhatsApp's own infrastructure; if you would rather avoid that channel, email and telephone carry the same response commitment. The site is not directed at people under 18 and we do not knowingly process children's data.
For which purposes and on which legal ground?
Five purposes: assessing and answering your enquiry, delivering the project once a contract exists, meeting accounting and legal obligations, keeping the site secure, and defending a claim if a dispute arises. The lawful ground differs by purpose and is cited by article below. Advertising, profiling and mailing-list building are not among them.
| Purpose | Data used | Ground (KVKK Art. 5) | Nearest GDPR article |
|---|---|---|---|
| Assessing your proposal or audit request and replying to you | Identity, contact and enquiry data | Art. 5/2-c — directly related to the conclusion of a contract. The consent box on the form additionally constitutes explicit consent under Art. 5/1. | Art. 6(1)(b), with Art. 6(1)(a) alongside |
| Delivering the project, handover and support once a contract exists | Identity, contact, project and correspondence data | Art. 5/2-c — necessary for the performance of the contract | Art. 6(1)(b) |
| Invoicing, accounting records and statutory retention | Identity, contact and invoice data | Art. 5/2-ç — a legal obligation expressly laid down by law (Tax Procedure Law, Commercial Code) | Art. 6(1)(c) |
| Site security, abuse detection and blocking automated attacks | Technical access logs, submission timing | Art. 5/2-f — legitimate interest, provided your fundamental rights are not harmed | Art. 6(1)(f) |
| Establishing, exercising or defending a right in a dispute | Contract, proposal and correspondence records | Art. 5/2-e — necessary for the establishment, exercise or protection of a right | No direct counterpart; normally handled under Art. 6(1)(f) |
| Visit statistics (not active on the effective date of this notice) | Anonymised visit measurement | Art. 5/1 — explicit consent. Until consent is given, no measurement request is made at all. | Art. 6(1)(a) |
No data is processed for any purpose outside this list. Concretely: the email address you give is not added to a marketing list, no newsletter subscription is opened, nothing is sent to purchased or rented lists, and your data is not sold. Completing a form is not consent to commercial messaging; once your enquiry is closed, no further message is sent to you for another purpose.
No decision producing an adverse effect on you is taken solely by automated means. The budget band on the form is not an automated filter either: when a band below our threshold is selected the page simply shows an informational note, and the enquiry is still read and answered by a person.
Who is your data shared with?
Your form and correspondence data is not sold, and is not passed to advertising networks, scoring services, data enrichment vendors or third-party CRM tools. Access arises in three cases only: our hosting and corporate email provider, our accountant and where necessary our lawyer, and public authorities entitled to request it under Turkish law.
Every transfer takes place under KVKK Article 8, for the purposes listed in clause 04 and limited to what those purposes require. The recipient groups are:
- Hosting and corporate email provider. As a processor, and only to the extent the service requires. Which provider is used, and the country in which its servers are located, is disclosed to you in writing on request.
- Accountant, and legal counsel where needed. Only for invoicing, bookkeeping and dispute matters; both are bound by professional confidentiality.
- Authorised public institutions. Only where expressly provided by law, and where the request cites the provision it relies on.
- Contracted subcontractors. Where they work on your project; each is named in the contract and bound by a confidentiality undertaking. Proposal-stage form data is never passed to a subcontractor.
Is data transferred outside Turkey?
On the effective date of this notice the site contains no third-party code that sends data abroad without your action: no analytics script, advertising pixel, embedded map, embedded video, third-party web font, chat widget or CAPTCHA. Fonts and all images are served from our own origin, so opening a page makes no outbound request whatsoever. You can confirm this yourself in your browser's network panel; the method is written up on the proof page.
Directions and WhatsApp links on the site only reach the relevant service when you click them, and from that point the provider's own privacy policy applies. If a tool requiring transfer abroad is adopted later, the transfer will be made in line with KVKK Article 9 — an adequacy decision, appropriate safeguards, or a statutory exception — and with your explicit consent where that is the ground relied on. This notice would be updated the same day.
How long is your data kept?
Each record is kept only as long as its purpose requires, then deleted or anonymised. Enquiries that do not become contracts are kept 12 months after the last correspondence; contract records 10 years after the relationship ends; server access logs a maximum of 12 months. Form submissions reach our team as an email notification; so that a request is not lost if that notification fails for technical reasons, a copy of the same content is kept on our hosting server, outside the publicly accessible area, in a file only we can access. This copy contains no IP address and follows the same 12-month period that applies to enquiries. The table below gives the basis for each period.
| Data | Retention period | Basis for the period |
|---|---|---|
| Proposal and audit enquiries that do not become contracts | 12 months from the last correspondence | So the enquiry can be reassessed and any objection answered; deleted at the end of the period. |
| Customer records and project correspondence under a contract | 10 years from the end of the relationship | General limitation period — Code of Obligations No. 6098, Art. 146. |
| Invoices and financial records | 10 years | Commercial Code No. 6102, Art. 82. Tax Procedure Law No. 213, Art. 253 requires at least five years; the longer period is applied. |
| Server access logs | 12 months at most | Transaction security and abuse investigation; deleted at the end of the period. |
| Explicit consent and confirmation records | For the statutory limitation period following withdrawal of consent | The obligation to be able to prove that consent was obtained. |
Theme preference on your device (bb-theme) |
Until you clear your browser data | It stays on your device and is never transferred to us; the retention period is entirely under your control. |
You do not have to wait for a period to expire before asking for erasure. If no other legal ground requires retention, your request is carried out within 30 days at the latest and confirmed to you in writing. If a record cannot be deleted because a statutory retention duty applies, we tell you which record it is and on what basis it is being held.
Which security measures are in place?
The site is published as static files: no database, no admin panel, no third-party plugins, so the classic attack surface largely disappears. All traffic is encrypted with HTTPS, the form can post only to our own domain, and access is limited to the people handling your request. A breach is notified to the Board within 72 hours.
The technical measures taken under KVKK Article 12 that you can verify for yourself are listed below — every one of them is visible in the server response headers:
- Enforced HTTPS and HSTS. Unencrypted requests are permanently redirected to the encrypted address; the
Strict-Transport-Securityheader tells the browser to open the domain over HTTPS only. - Content Security Policy. The origins for scripts, styles, images, fonts and connections are restricted to our own domain. The
form-action 'self'directive prevents the form from being posted anywhere else. - Additional security headers.
X-Content-Type-Options: nosniff,Referrer-Policy: strict-origin-when-cross-origin,Cross-Origin-Opener-Policy: same-origin, and aPermissions-Policythat switches off camera, microphone, geolocation and payment access. - No third-party scripts. Form data leaves your browser for our server and nothing else; there is no form service, validation service or tag manager in between.
- Server-side checks instead of CAPTCHA. Automated submissions are filtered with a hidden field and a submission-timing check. We do not use CAPTCHA, because CAPTCHA sends a visitor's data to a third party.
On the organisational side: access to data is limited to the people handling the request, corporate email accounts use multi-factor authentication, a confidentiality undertaking is written into the contract whenever a subcontractor is engaged, and redundant copies are deleted at the end of a project.
If a breach occurs despite these measures, notification is made to the Personal Data Protection Board as soon as possible — within the 72-hour period set by the Board's decision — under KVKK Article 12/5, and the affected individuals are informed directly within the shortest reasonable time.
Which rights do you hold under KVKK Article 11?
Article 11 gives you nine rights: to learn whether your data is processed, to request information about it, to learn the purpose, to know the recipients at home and abroad, to have inaccurate data corrected, to have data erased or destroyed, to have those actions notified onward, to object to automated decisions, and to claim damages.
As a data subject you may apply to Baki Bilisim and request the following:
- To learn whether your personal data is being processed.
- To request information if your personal data has been processed.
- To learn the purpose of processing and whether the data is used in line with that purpose.
- To know the third parties in Turkey or abroad to whom your data has been transferred.
- To request correction where your data has been processed incompletely or inaccurately.
- To request erasure or destruction of your data under the conditions in Article 7 of the Law.
- To request that correction, erasure and destruction be notified to the third parties to whom the data was transferred.
- To object to a result reached against you through analysis carried out solely by automated systems.
- To claim compensation where you suffer loss because your data was processed unlawfully.
Can you withdraw your explicit consent?
Yes. Where processing rests on explicit consent you may withdraw it at any time, without giving a reason; a single email is enough. Withdrawal takes effect going forward: processing carried out while the consent was valid remains lawful, but once your request reaches us the data is no longer processed for that consent-based purpose. If your request would require erasure of data we must retain under a contractual or statutory duty, we explain in writing which record is retained and why.
What about the GDPR rights that KVKK does not name?
KVKK Article 11 contains no separately named right to data portability, and no general right to restriction of processing in the GDPR sense. In practice this changes little here: the data we hold about you is limited to what you sent us. If you ask, we will send you a copy in a common machine-readable format. We do that as a matter of practice, not because Turkish law obliges us to, and we would rather say so than imply a right that the Law does not grant.
Cookies and what is stored in your browser
This site sets no advertising or tracking cookies. On the effective date of this notice the only record kept in your browser is the light or dark theme you selected, and it never leaves your device. If visit statistics are ever switched on, they will run on explicit consent only; without consent no third-party request is made.
The mechanism used is not a cookie but the browser's local storage: your theme preference is held on your device under the key bb-theme and is never attached to a server request. To remove it, clear the site data in your browser; once cleared, the site falls back to the light or dark setting of your operating system.
Cookie categories, durations, consent management and consent withdrawal are set out in detail on the cookie policy page. For the conditions on using and quoting the content of this site, see the terms of use.
What happens when this notice changes?
When the text changes, the version number and the in-force and last-updated dates at the top of the page change with it, and the previous version ceases to apply. If processing based on explicit consent is widened, the change is not applied until consent has been taken again. Version 1.3 is dated 15 September 2026.
A change in legislation, an extension of our service scope or the adoption of a new tool can all make an update necessary. When that happens, a summary of the change is entered in the table below, so you can see retrospectively what changed and when. If a clause that affects you directly changes while a client relationship is running, the change is also notified by email.
This English text is published for readers who do not work in Turkish. The Turkish version at gizlilik ve KVKK is the version in force; where the two differ in meaning, the Turkish text prevails.
| Version | In force from | Change |
|---|---|---|
| 1.0 | 29 July 2026 | First publication. The notice entered into force together with the rebuilt version of the site. |
| 1.1 | 14 September 2026 | States that, in addition to the email notification, a backup copy of form submissions is kept on our hosting server outside the publicly accessible area and without IP addresses (clause 6). Purposes, data categories, legal grounds, recipients and retention periods are unchanged; the change is a security measure that stops a request being lost if the notification fails for technical reasons. |
| 1.2 | 14 September 2026 | Telephone number became a required field on the site's forms; in the contact details row the word "optional" was removed from the telephone number and added to the preferred contact channel, which is not required (clause 3). The number is used only to schedule a call; purposes, legal grounds, recipients and retention periods are unchanged. |
| 1.3 | 15 September 2026 | The description of the forms was corrected: the audit request form is used to assess the request and reply to you, not to prepare a proposal, and both forms are now described as asking only for the fields needed for that purpose (clause 3). Data categories, purposes, legal grounds, recipients and retention periods are unchanged. |
Where and how do you exercise your rights?
Send your request in writing to our office address, or by email to bilgi@bakibilisim.com from an address you have previously given us. It is concluded free of charge within 30 days at the latest. If it is refused or left unanswered, you may complain to the Personal Data Protection Board — but only after applying to us first.
- Data controller
- Baki Bilisim
- Address
- Karabaş Mah. Salim Dervişoğlu Cad.
Ncity AVM, Floor 2 (Bowlingo level)
İzmit / Kocaeli, Turkey - bilgi@bakibilisim.com
- Telephone
- +90 507 817 27 17
- Subject of application
- Requests under KVKK Art. 11, withdrawal of consent, erasure and correction requests
- Response time
- 30 days at the latest · free of charge
What must your application contain?
Under the Communiqué on the Procedures and Principles of Application to the Data Controller, your application should include:
- Your name and surname, and your signature if the application is made on paper.
- For Turkish citizens, the national identity number; for foreign nationals, nationality, passport number or identity number where one exists.
- Your place of residence or business address for service of the reply.
- Your email address, telephone and fax number for notification, where available.
- The subject of your request; writing each request out separately and concretely speeds up the process.
Any relevant information and documents are attached to the application. If we cannot confirm that the application comes from you, we may ask for further information to verify your identity — that request exists to keep your data from being disclosed to someone else.
How does the process run?
Your request is concluded as quickly as its nature allows and in any case within 30 days. Applications are free; where the operation involves an additional cost, the fee set in the tariff of the Personal Data Protection Board may be charged. Our reply is sent in writing or electronically, matching the channel you used.
If your application is refused, the reply is inadequate, or no reply arrives within 30 days, you may complain to the Personal Data Protection Board ↗ within 30 days of learning the reply and in any case within 60 days of the application date (KVKK Art. 14). The route to the Board opens only after you have applied to the controller, that is to us.
For questions about a project or a proposal — anything other than a personal data request — use the contact page; the reply commitment there is two working days at the latest.
Baki Bilisim · Data ControllerVersion 1.3In force: 2026-09-15Last updated: 15 September 2026Türkçe: Gizlilik ve KVKK
See the measured state of your website within five working days.
The audit is free and creates no obligation to work with us. The report itemises findings on AEO answerability, AI crawler access, lab-measured Core Web Vitals, structured data validity and accessibility (automated scan).
We work with corporate-scale, multi-location or multilingual organisations. One-off small jobs fall outside our scope; in that case we point you to smaller studios.