ENESBAHADIR.DESIGN
PRIVACY AND PERSONAL DATA PROTECTION POLICY
DISCLOSURE STATEMENT UNDER LAW NO. 6698 AND REGULATION (EU) 2016/679
- Document No
- EB-GP-2026/1
- Date of Adoption
- 25/06/2026
- Entry into Force
- 25/06/2026
- Legal Basis
- Law No. 6698 (KVKK) — Reg. (EU) 2016/679 (GDPR)
- Data Controller
- İbrahim Enes Bahadır
PREAMBLE
This Privacy and Personal Data Protection Policy (hereinafter “the Policy”) has been enacted and promulgated, upon the basis of Law No. 6698 on the Protection of Personal Data and Regulation (EU) 2016/679 (the General Data Protection Regulation), in order to ensure that personal data obtained through the website at enesbahadir.design (hereinafter “the Site”) are processed lawfully and in accordance with the rules of good faith; to safeguard the fundamental rights and freedoms of the data subject, and in particular the privacy of their private life; and to establish the principles of transparency, proportionality and accountability in all data-processing activities.
The data controller undertakes to abide by the principles declared herein to the extent required by the applicable law. No provision of this Policy shall be construed so as to abolish any of the rights granted to the data subject by the legislation in force, nor so as to impose upon the data controller any obligation not imposed by law.
PART ONE
General Provisions
I. Purpose and Scope
Article 1 – The purpose of this Policy is to inform the data subject, in accordance with the legislation, of the conditions and manner in which the personal data of visitors of the Site and of natural persons who use the contact form are processed.
This Policy applies, to the extent compatible with their nature, to legal persons, to anonymous and aggregated data, and to data made public by the data subject of their own accord.
II. Legal Basis
Article 2 – This Policy is founded upon Law No. 6698 on the Protection of Personal Data (KVKK), the secondary legislation enacted thereunder, Regulation (EU) 2016/679 (the GDPR), and other mandatory provisions.
III. Definitions
Article 3 – In the application of this Policy, the following definitions apply:
(a) “Law” means Law No. 6698 on the Protection of Personal Data;
(b) “GDPR” means Regulation (EU) 2016/679;
(c) “Authority/Board” means the Personal Data Protection Authority and the Personal Data Protection Board;
(d) “Data controller” means İbrahim Enes Bahadır, who determines the purposes and means of processing;
(e) “Data processor” means the natural or legal person who processes personal data on behalf of the data controller upon its authority;
(f) “Data subject” means the natural person whose personal data are processed;
(g) “Personal data” means any information relating to an identified or identifiable natural person;
(h) “Processing” means any operation performed upon personal data, from collection to destruction;
(i) “Site” means the website at the domain enesbahadir.design and its sub-pages;
(j) “Explicit consent” means consent relating to a specific matter, based upon information and declared by free will;
and shall be interpreted accordingly.
IV. Identity of the Data Controller
Article 4 – The data controller is İbrahim Enes Bahadır. Every request, question and application shall be addressed to the data controller through the electronic-mail address hello@enesbahadir.design.
PART TWO
Principles Governing the Processing of Personal Data
V. General Principles
Article 5 – Personal data are processed in compliance with the principles of lawfulness and fairness; accuracy and, where necessary, currency; processing for specified, explicit and legitimate purposes; relevance, limitation and proportionality to the purposes of processing; and retention only for the period prescribed by the relevant legislation or necessary for the purposes of processing.
VI. Categories of Data Processed and Methods of Collection
Article 6 – Through the contact form the following are collected: name, electronic-mail address, message content, project-type preference, language preference and time of submission; such data are stored in a Cloudflare D1 database.
Data relating to transaction security are processed only to the extent of request headers and the hashed IP value obtained by the method laid down in Article 8 below.
Personal data are obtained, by wholly or partly automated means, only where the data subject completes the form upon the Site or contacts the data controller directly. The data controller shall not be liable for the accuracy of the data declared by the data subject.
VII. Purposes and Legal Bases of Processing
Article 7 – Responding to the data subject's request and maintaining communication are carried out upon the explicit consent obtained through the consent checkbox in the form, pursuant to Article 5/2 of the Law and Article 6(1)(a) of the GDPR.
Activities relating to the maintenance of security, the fulfilment of legal obligations and the prevention of abuse (rate limiting, bot protection, audit logging and the establishment of rights) rest upon the legal-obligation and legitimate-interest bases laid down in Articles 6(1)(c) and 6(1)(f) of the Law and the GDPR.
The data subject may withdraw their explicit consent at any time; however, such withdrawal does not affect the lawfulness of the processing carried out up to the moment of withdrawal.
VIII. IP Address and Transaction-Security Data
Article 8 – The IP address shall under no circumstances be stored in raw form. It is used only transiently, in the form of a salted, non-reversible and truncated hash, for the sole purpose of preventing abuse (unsolicited messages and brute-force attempts), and the original IP address is discarded forthwith.
This processing rests solely upon the legitimate interest of securing the Site and its data subjects, and is not used for marketing or profiling purposes.
IX. Cookies
Article 9 – Site analytics are provided by the cookieless Cloudflare Web Analytics service, which performs no cross-site tracking and produces only aggregate and anonymous statistics.
The principles concerning cookies are separately set out in the Cookie Policy, which constitutes an annex to and an integral part of this Policy.
PART THREE
Retention, Transfer and Security
X. Retention and Destruction Periods
Article 10 – Contact messages are automatically deleted after twelve (12) months at the latest.
Administrative audit logs are retained for twelve (12) months at the latest.
Analytics data are subject to Cloudflare's own retention policy. At the end of the period, personal data are deleted, destroyed or anonymised, save where the original purpose of processing requires otherwise.
XI. Domestic and Cross-Border Transfer; Data Processors
Article 11 – Hosting, database (D1), storage (KV), electronic-mail routing, bot protection (Turnstile) and analytics services are provided by Cloudflare in the capacity of data processor; as required by the service, data may be processed upon Cloudflare's global infrastructure and hosted on servers located abroad.
Cross-border transfer is carried out within the framework of the transfer provisions of the Law and the GDPR and where appropriate safeguards exist. Personal data shall not be transferred, assigned or sold to third parties for marketing purposes.
XII. Measures Concerning Data Security
Article 12 – The data controller takes reasonable technical and administrative measures (including encryption, access restriction, rate limiting and logging) appropriate to ensure a suitable level of security, in order to prevent the unlawful processing of and access to personal data and to ensure their preservation.
By reason of the nature of the internet, the absolute security of data transmission cannot be guaranteed; by transmitting their data through the Site, the data subject acknowledges this fact. Notwithstanding the data controller's adoption of the requisite measures, its liability for breaches occurring without its fault as a result of the acts of third parties is limited to the maximum extent permitted by the applicable law.
XIII. Data Relating to Minors
Article 13 – The Site is not directed at persons under the age of eighteen and does not knowingly collect their personal data. Where it is established that data relating to a minor have been transmitted without consent, such data are destroyed at the first opportunity.
PART FOUR
Rights of the Data Subject and Application
XIV. Rights of the Data Subject
Article 14 – Pursuant to Article 11 of the Law and Articles 15 to 22 of the GDPR, the data subject has the right to learn whether their personal data are processed, to request information thereon if processed, to learn the purpose of processing and whether the data are used in accordance therewith, to access their data; to request the rectification, erasure or anonymisation thereof; to object to the processing, to request the portability of their data, and to request the redress of any damage arising from unlawful processing.
XV. Procedure and Time Limits for Application
Article 15 – The data subject shall submit requests concerning the rights enumerated in Article 14, together with information establishing their identity, in writing to hello@enesbahadir.design.
Requests are concluded free of charge as soon as possible and in any event within thirty (30) days at the latest, according to their nature. However, where the operation entails an additional cost, the fee in the tariff set by the Board may be charged. Where a request is manifestly unfounded or excessive, the data controller may charge a reasonable fee or refuse the request.
XVI. Authorities for Complaint
Article 16 – Where the application is refused, the answer given is found insufficient, or no answer is given within the period, the data subject is entitled to lodge a complaint with the Personal Data Protection Board in the Republic of Türkiye and, under the GDPR, with the competent supervisory authority.
PART FIVE
Liability and Final Provisions
XVII. Third-Party Links and Limitation of Liability
Article 17 – The Site may contain links to the websites or platforms of third parties. The privacy practices and content of such sites are the responsibility of their respective owners, and the data controller bears no responsibility in this regard.
In the discharge of its obligations arising from this Policy, the data controller is liable to the maximum extent permitted by the applicable law; it shall not be liable for indirect damages, loss of profit or unforeseeable damages. The limitations in this Article do not cover liability arising from mandatory provisions or from the intent or gross negligence of the data controller.
XVIII. Force Majeure
Article 18 – In cases of force majeure beyond the parties' reasonable control that affect the data-processing activity — such as natural disaster, epidemic, cyber-attack, or interruption originating from infrastructure or a service provider — the obligations of the data controller are suspended for the duration of, and limited to, the force-majeure event.
XIX. Integrity, Amendment and Entry into Force
Article 19 – This Policy is effective as of its date of entry into force and may be updated unilaterally by the data controller where deemed necessary. The version currently in force is published on this page, and the date of update is shown in the masthead of this document.
The invalidity of any provision of this Policy shall not affect the validity of the remaining provisions. No provision of this Policy shall be construed so as to limit the rights granted to the data subject by the legislation in force.