Privacy Policy
Last updated: October 7, 2026
1. Who We Are
DIGITRRIX YAZILIM TEKNOLOJİ HİZMETLERİ VE TİCARET LİMİTED ŞİRKETİ (“Digitrrix”, “we”, “us”) is the data controller responsible for the personal data processed through https://digitrrix.com and in the course of the services we provide. We process personal data in accordance with Turkish Personal Data Protection Law No. 6698 (“KVKK”) and, where it applies to you, the EU General Data Protection Regulation (“GDPR”).
You can reach us at [email protected] or by post at Izmir, Türkiye.
2. Data We Collect
Information you give us
When you fill in a contact form, request a quote, subscribe to updates, or correspond with us: your name, email address, telephone number, company name, the service you are interested in, and anything else you choose to include in your message.
Information we collect automatically
When you visit the site: IP address, approximate location derived from it, browser and device type, operating system, referring page, the pages you view, and the date and time of your visit. This data is collected through server logs and, where enabled, analytics cookies.
Information from client projects
While delivering a project we may be given access to systems that contain personal data belonging to our client’s own users. In those cases we act as a data processor on our client’s instructions, under a separate data processing agreement, and we do not use that data for our own purposes.
What we do not collect
We never store payment card numbers, CVV codes, or bank credentials. Card payments are handled entirely by a licensed payment service provider on its own infrastructure.
3. Why We Process It and on What Legal Basis
- To answer enquiries and prepare proposals — necessary for taking steps at your request prior to entering into a contract.
- To deliver and support the services you order — necessary for the performance of our contract with you.
- To issue invoices and meet accounting, tax, and consumer-law obligations — necessary for compliance with a legal obligation.
- To keep the site secure, prevent abuse, and understand how it is used — necessary for our legitimate interests in running a safe and functioning website.
- To send marketing messages and set non-essential cookies — only with your explicit consent, which you may withdraw at any time.
4. Cookies and Similar Technologies
Strictly necessary cookies keep the site working and are set without consent. Analytics and preference cookies are only set where you have agreed to them. You can clear or block cookies at any time through your browser settings; if you block strictly necessary cookies, parts of the site may stop working correctly.
5. Who We Share It With
We do not sell personal data, and we do not share it for third-party advertising. We disclose it only to:
- service providers acting on our instructions — hosting and infrastructure, email delivery, analytics, payment processing, and accounting;
- professional advisers such as lawyers and auditors, where necessary;
- public authorities and courts, where disclosure is required by law or to establish, exercise, or defend legal claims.
Each provider is bound by contract to process the data only for the purpose we specify and to keep it secure.
6. International Transfers
Our servers are located in the European Union. Some of our service providers may process data outside Türkiye or the EEA. Where that happens, the transfer is made on the basis of an adequacy decision, standard contractual clauses, or your explicit consent, together with the safeguards required under Article 9 of the KVKK.
7. How Long We Keep It
We keep personal data only for as long as the purpose requires. Contact form submissions and enquiry correspondence are kept for up to three years from our last exchange. Records relating to contracts, invoices, and accounting are kept for ten years, as required by Turkish commercial and tax legislation. Server logs are kept for up to twelve months. At the end of the relevant period the data is deleted or irreversibly anonymised.
8. How We Protect It
We apply technical and organisational measures appropriate to the risk: encryption in transit over TLS, access limited to staff who need it, isolated production environments, regular backups, rate limiting on public endpoints, and confidentiality obligations for everyone who handles the data. No method of transmission or storage is completely secure, but we review these measures regularly.
If a breach occurs that is likely to put your rights and freedoms at risk, we will notify the competent authority and, where required, inform you directly without undue delay.
9. Your Rights
Under Article 11 of the KVKK and the corresponding provisions of the GDPR, you have the right to:
- learn whether we process your personal data, and request access to it;
- know the purpose of the processing and whether it is used accordingly;
- know the third parties, in Türkiye or abroad, to whom it is disclosed;
- have incomplete or inaccurate data corrected;
- request erasure or destruction when the grounds for processing no longer apply, and have that notified to recipients;
- object to processing based on legitimate interests, and withdraw consent at any time;
- object to a decision produced solely by automated analysis that produces an adverse result for you;
- receive a copy of data you provided in a portable format;
- claim compensation for damage arising from unlawful processing.
10. Exercising Your Rights
Send your request to [email protected] or in writing to Izmir, Türkiye, with enough detail for us to identify you and understand what you are asking for. We respond free of charge and at the latest within thirty (30) days. If you are not satisfied with our response, you may lodge a complaint with the Turkish Personal Data Protection Authority (KVKK Kurumu) or, where the GDPR applies to you, with your local supervisory authority.
11. Children
Our services are directed at businesses and are not intended for children under the age of 18. We do not knowingly collect their personal data. If you believe a child has provided us with data, contact us and we will delete it.
12. Third-Party Links
Our site links to external websites and social media profiles we do not control. This policy does not cover them, and we encourage you to read the privacy notice of any site you visit from here.
13. Changes to This Policy
We may update this policy as our services or the law change. The current version is always published on this page with the date it took effect. Where a change materially affects your rights, we will give you notice before it takes effect.
14. Contact
DIGITRRIX YAZILIM TEKNOLOJİ HİZMETLERİ VE TİCARET LİMİTED ŞİRKETİ
Izmir, Türkiye
[email protected]
See also our Delivery and Return Terms and Distance Sales Agreement.