1. Overview
C4 Software Studio is committed to protecting your personal data and ensuring compliance with applicable data protection regulations. We process personal data in accordance with:
- General Data Protection Regulation (GDPR) - EU Regulation 2016/679
- Turkish Personal Data Protection Law (KVKK) - Law No. 6698
This page explains your rights under these regulations and how to exercise them.
2. GDPR Compliance (EU/EEA)
The General Data Protection Regulation (GDPR) is a comprehensive data protection law that applies to organizations processing personal data of individuals in the European Union and European Economic Area.
Key GDPR Principles We Follow
Lawfulness & Transparency
We process data lawfully, fairly, and transparently.
Purpose Limitation
Data is collected for specified, explicit purposes only.
Data Minimization
We only collect data that is necessary.
Security
Appropriate security measures protect your data.
3. KVKK Compliance (Turkey)
The Turkish Personal Data Protection Law (KVKK) is Turkey's primary data protection legislation, modeled after the GDPR. As a company based in Turkey, we fully comply with KVKK requirements.
Our KVKK Obligations
- Registration with the Data Controllers Registry (VERBİS)
- Informing data subjects about data processing activities
- Obtaining explicit consent where required
- Implementing data security measures
- Responding to data subject requests within 30 days
- Reporting data breaches to the Personal Data Protection Authority
4. Your Data Protection Rights
Right to Access
You have the right to obtain confirmation as to whether your personal data is being processed and access to that data.
Right to Rectification
You have the right to have inaccurate personal data corrected and incomplete data completed.
Right to Erasure
You have the right to request the deletion of your personal data under certain circumstances.
Right to Restrict Processing
You have the right to request the restriction of processing of your personal data.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used format.
Right to Object
You have the right to object to the processing of your personal data based on legitimate interests.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time.
Right to Complain
You have the right to lodge a complaint with a supervisory authority.
5. Data Processing Activities
We process personal data for the following purposes:
| Purpose | Data Categories | Legal Basis |
|---|---|---|
| Service Delivery | Name, Email, Phone, Project Details | Contract Performance |
| Customer Support | Contact Information, Communication History | Legitimate Interest |
| Marketing Communications | Name, Email | Consent |
| Website Analytics | IP Address, Browser Info, Usage Data | Legitimate Interest |
| Legal Compliance | Transaction Records, Communications | Legal Obligation |
6. Legal Basis for Processing
We process personal data based on one or more of the following legal grounds:
- Consent: You have given explicit consent for a specific purpose.
- Contract: Processing is necessary for the performance of a contract with you.
- Legal Obligation: Processing is necessary for compliance with legal obligations.
- Legitimate Interest: Processing is necessary for our legitimate business interests.
7. International Data Transfers
When we transfer personal data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules for intra-group transfers
- Adequacy decisions by the European Commission or Turkish DPA
- Your explicit consent for specific transfers
8. Security Measures
We implement comprehensive technical and organizational security measures:
Technical Measures
- End-to-end encryption (TLS 1.3)
- AES-256 encryption at rest
- Multi-factor authentication
- Intrusion detection systems
- Regular penetration testing
- Automated backup systems
Organizational Measures
- Access control policies
- Employee training programs
- Confidentiality agreements
- Incident response procedures
- Regular security audits
- Vendor due diligence
9. Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and ensuring compliance with GDPR and KVKK requirements.
Data Protection Officer
C4 Software Studio
Email: dpo@c4softwarestudio.com
Phone: +90 (553) 837 45 82
Address: Istanbul, Turkey
10. Submit a Data Subject Request
To exercise any of your data protection rights, you can submit a request through the following methods:
Send your request to: privacy@c4softwarestudio.com
C4 Software Studio
Data Protection Team
Istanbul, Turkey
Online Form
Use our contact form and select "Data Protection Request"
We will respond to your request within 30 days. In complex cases, this may be extended by an additional 60 days, in which case we will inform you of the extension and the reasons for it.
Supervisory Authorities
If you are not satisfied with our response, you have the right to lodge a complaint with the relevant supervisory authority:
- Turkey: Kişisel Verileri Koruma Kurumu (KVKK) - www.kvkk.gov.tr
- EU: Your local Data Protection Authority