WhatsApp İletişim

Arama yapmak için yazmaya başlayın

GDPR & KVKK Compliant

Privacy Policy

At Berasoft, we prioritize the privacy and security of your personal data. This policy explains how we collect, use, and protect your information.

Last Updated: October 12, 2025

1. General Information

This Privacy Policy applies to the berasoft.com website and services operated by Berasoft. We are committed to protecting your personal data in accordance with the Turkish Personal Data Protection Law (KVKK Law No. 6698) and the European Union General Data Protection Regulation (GDPR).

Data Controller

Berasoft
Address: Cevizlidere Mah. 1244 Sk. No:1, Çankaya/ANKARA, Turkey
Email: [email protected]
Phone: +90 (506) 777 06 93

2. Personal Data We Collect

When you use our website, we may collect the following personal data:

Data Category Examples Collection Method
Identity Information Name, surname, ID number (when required) Contact form, contract
Contact Information Email, phone, address Contact form, registration
Security Information IP address, cookie ID, session data Automatic collection (cookies)
Marketing Information Interests, service preferences Forms, surveys, behavioral analysis
Transaction Information Project details, payment information Contract, invoice

3. How We Use Your Data

We use your personal data only for the following purposes:

  • Service Delivery: Providing requested software, web design, and SEO services
  • Communication: Responding to inquiries, technical support, project updates
  • Contract Management: Executing commercial agreements, invoicing
  • Legal Obligations: Fulfilling tax, accounting, and legal requirements
  • Security: Preventing cyberattacks, fraud detection
  • Improvement: Website performance, user experience optimization
  • Marketing: Product/service promotions (opt-in email only, with your consent)

4. Cookie Policy

Our website uses the following types of cookies:

Cookie Type Purpose Duration
Essential Cookies Session management, security (CSRF protection) Session / 24 hours
Analytics Cookies Visitor statistics (Google Analytics) 26 months
Functional Cookies Language preference, theme settings 12 months
Marketing Cookies Targeted advertising (consent required) 6 months

You can manage or disable cookies through your browser settings. However, some features may not work properly.

5. Data Sharing and Transfer

We never sell your personal data to third parties. However, we may share data in the following cases:

  • Service Providers: Server hosting (AWS, Google Cloud), email services, payment systems
  • Legal Requirements: Court orders, investigation requests
  • Business Partners: With your explicit consent, based on project requirements (e.g., SEO analysis tools)
International Data Transfer

Some of our service providers (e.g., Google Analytics, AWS) are located in the EU/US. All transfers comply with GDPR Articles 44-50, protected by Standard Contractual Clauses (SCC).

6. Data Security

We implement the following technical and organizational measures to protect your data:

  • SSL/TLS Encryption: 256-bit encryption for all data transmission
  • Secure Servers: ISO 27001 certified data centers
  • Access Control: Multi-factor authentication (MFA), role-based authorization
  • Data Minimization: Collecting only necessary data
  • Regular Audits: Penetration testing, vulnerability scans
  • Backup: Daily automatic backups, disaster recovery plan

7. Data Retention Periods

Data Type Retention Period Legal Basis
Contact form data 6 months (if no relationship), 10 years (if customer) Business communication, tax law
Contract and invoice data 10 years Tax law, Commercial Code
Analytics cookies 26 months GDPR Article 6(1)(f) - Legitimate interest
IP address and logs 6 months Internet Law No. 5651
Marketing consent Until consent withdrawn (max 3 years) GDPR Article 6(1)(a) - Consent

8. Your Rights (KVKK & GDPR)

You have the following rights regarding your personal data:

  • Right to Information: Learn what data we process
  • Right of Access: Request a copy of your data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your data
  • Right to Restriction: Request limitation of processing in certain cases
  • Right to Data Portability: Receive your data in a structured format
  • Right to Object: Object to automated decision-making processes
  • Right to Withdraw Consent: Cancel marketing permissions anytime
How to Submit a Request

To exercise your rights, send a written request to [email protected] with identity verification. We will respond within 30 days.

9. Children's Privacy

Our services are not intended for individuals under 18 years old. We do not knowingly collect data from children. If a parent/guardian discovers their child has provided data, please contact us; the data will be deleted immediately.

10. Third-Party Services and Links

Our website may use the following third-party services:

  • Google Analytics: Visitor analytics (anonymized IP)
  • Google Fonts: Web fonts
  • Lucide Icons: SVG icons (self-hosted)
  • Email Services: Automated notifications

We are not responsible for the privacy policies of third-party websites we link to. Please review their policies before visiting.

11. Policy Updates

We may update this Privacy Policy for legal compliance or service changes. For significant updates:

  • We will publish a notice on the website
  • Registered users will receive email notification
  • The new policy will take effect after 7 days

We recommend checking this policy regularly for updates.

12. Complaint and Supervisory Authorities

If you believe your data protection rights have been violated:

  • Personal Data Protection Authority (KVKK): www.kvkk.gov.tr
  • Data Protection Authority (DPA): Contact your local DPA in EU countries
  • Berasoft Internal Request: [email protected] (please contact us first for resolution)

For Privacy-Related Questions

Address: Cevizlidere Mah. 1244 Sk. No:1, Çankaya/ANKARA, Turkey
Response Time: Within 48 hours