Privacy, explained.
Codlean’s notice on the collection, use, protection and lawful handling of personal data under Turkish data protection law.
Controller and scope
This notice is provided under Türkiye’s Personal Data Protection Law No. 6698 (KVKK). Codlean Teknoloji Anonim Şirketi acts as data controller for the processing described here and determines the purposes and means of that processing.
It applies to personal data received through the Codlean Cloud public website, contact channels, product enquiries, commercial relationships, visits, events and related business interactions. A specific product, employment or supplier process may also provide a more detailed notice.
Data we may process
The data collected depends on your relationship and interaction with Codlean.
- 01Identity and contact data, such as name, business email, telephone number and address.
- 02Company and professional data, such as employer, role, department and business needs.
- 03Request and communication data, including messages, meeting notes, support context and preferences.
- 04Commercial and transaction data connected with offers, contracts, services and customer relationships.
- 05Technical and security data, such as IP address, device/browser details, access records and security events.
- 06Visit, event or image data where relevant and lawfully collected.
Why we process data
We process personal data only for specified, explicit and legitimate purposes connected with our activities.
- 01Respond to enquiries, arrange demonstrations and manage sales, contracts, delivery and support.
- 02Operate, secure, troubleshoot and improve websites, products, infrastructure and customer experience.
- 03Manage customer, supplier, partner, visitor and event relationships.
- 04Keep business, finance, accounting, audit, quality and security records.
- 05Meet legal obligations, establish or defend rights and respond to authorized public bodies.
- 06Send commercial electronic communications only where the applicable permission or other lawful condition exists.
Legal bases and collection
Data may be collected directly from you, your organization, forms and communications, our products and systems, visits and events, service providers, partners, public sources or automatically through website technologies.
Depending on the activity, processing is based on an express legal requirement, performance or formation of a contract, compliance with a legal obligation, establishment or protection of a right, our legitimate interests where your fundamental rights are not harmed, data made public by you, or explicit consent where required. Special-category personal data is processed only under the conditions and safeguards permitted by law.
Sharing and transfers
Personal data may be shared, only to the extent necessary, with authorized employees, group or business partners, customers, suppliers, professional advisers, hosting and technology providers, financial institutions and legally authorized public or private bodies.
Domestic and international transfers are carried out under KVKK Articles 8 and 9 and the applicable transfer mechanism, including adequacy decisions, appropriate safeguards, standard contracts or explicit consent where that is the lawful route.
Retention and security
We retain personal data for the period required by the processing purpose, contract and applicable limitation or statutory retention rules. When no continuing legal or business reason remains, data is deleted, destroyed or anonymized in line with our retention and disposal practices.
We apply risk-based organizational, technical and physical safeguards designed to prevent unlawful processing or access and accidental loss, alteration or disclosure. Access is restricted by role, and incidents are handled through defined response processes.
Your rights
Under KVKK Article 11, you may apply to the data controller to:
- 01Learn whether your personal data is processed and request information about processing.
- 02Learn the purpose of processing and whether data is used in line with that purpose.
- 03Learn the third parties to whom data is transferred in Türkiye or abroad.
- 04Request correction of incomplete or inaccurate data.
- 05Request deletion or destruction where the legal conditions are met and notification of that action to recipients.
- 06Object to a result against you arising solely from automated analysis.
- 07Claim compensation if you suffer damage because personal data was processed unlawfully.
Applications and contact
Submit a request using a method permitted by the Regulation on Application Procedures and Principles to the Data Controller. Your application should clearly identify you, the right you wish to exercise and the information needed to assess the request. We may ask for proportionate verification to protect your data.
Applications are answered as soon as possible and no later than 30 days, depending on their nature. The response is normally free of charge; an official tariff may apply where the process creates an additional cost.