KVKK Disclosure Notice
This disclosure notice has been prepared by C3T Teknoloji AŞ
(Istanbul / Türkiye), in its capacity as data controller, pursuant to the Personal Data
Protection Law No. 6698 ("KVKK"). Our aim is to explain transparently the scope, purposes
and legal grounds on which we process your personal data through the c3t.com.tr website.
1. Identity of the Data Controller
Data controller: C3T Teknoloji AŞ
Address: Istanbul / Türkiye
E-mail: [email protected]
2. Categories of Personal Data Processed
This website is a promotional site. Only the following data is processed from visitors:
- Contact form data: organization/company name, full name, e-mail address
and/or telephone number, together with the content of the message you submit via the form.
- Transaction security / log data: technical records automatically logged
by the server when you access the site, such as IP address, date and time, requested page
and browser information.
- Cookie data: the strictly necessary and functional cookies used to operate
the site and remember your preferences, together with (where used) anonymous/aggregate
analytics cookies. See the "Cookie Policy" tab for details.
Personal data processed within the enterprise AI and custom software solutions offered by
C3T falls outside the scope of this notice: as a rule, these solutions run on the customer's
own servers (on-premise), and in such projects personal data is processed within the relevant
organization's own infrastructure, under that organization's responsibility as data
controller. Data sovereignty remains with the customer organization.
3. Purposes of Processing
- To respond to the requests, questions or proposal enquiries you submit via the contact form.
- To communicate with you and conduct potential business discussions.
- To ensure the security of the website, troubleshoot errors and prevent misuse.
- To improve site performance and user experience (at an anonymous/aggregate level).
- To fulfil obligations arising from applicable legislation.
4. Legal Grounds for Processing (KVKK Art. 5)
- Explicit consent: for non-essential (e.g. analytics) cookies and
optional communication.
- Being directly related to the establishment or performance of a contract:
in conducting proposal and business discussions.
- Legitimate interest of the data controller: for site security, log
records and service improvement.
- Legal obligation: for the retention and notification obligations
required by legislation.
5. Transfer of Personal Data
As a rule, your personal data is not transferred to third parties and is not sold.
Exceptionally, data may be shared with the infrastructure/hosting providers from which we
obtain services for hosting the website, solely for the purpose of technically delivering
the service and subject to the necessary security measures. In addition, requests from
legally authorised public institutions and organisations that are based on legislation
are fulfilled.
6. Retention Period
Your personal data is retained for as long as the purpose of processing requires and
within the limitation/retention periods stipulated in the applicable legislation. Contact
form data is deleted, destroyed or anonymised within a reasonable period after the request
has been concluded. Log records are kept for a limited period within the framework of
security and legislative requirements.
7. Rights of the Data Subject (KVKK Art. 11)
Pursuant to Article 11 of the KVKK, by applying to C3T you have the right to:
- Learn whether your personal data is being processed,
- Request information regarding such processing, if it has been processed,
- Learn the purpose of processing and whether the data is used in accordance with that purpose,
- Know the third parties to whom the data has been transferred, domestically or abroad,
- Request rectification if the data has been processed incompletely or inaccurately,
- Request erasure or destruction of the data where the required conditions are met,
- Request that rectification/erasure operations be notified to the third parties to whom the data has been transferred,
- Object to a result arising to your detriment from analysis carried out exclusively by automated systems,
- Claim compensation for damages in the event that you suffer damage due to unlawful processing.
These rights are granted to you under the law.
8. Method of Application
You may exercise your requests regarding the rights above by sending them to
[email protected]. Your applications are concluded
within the periods stipulated in the KVKK and the relevant legislation.
Privacy Policy
At C3T Teknoloji AŞ, we value your privacy. This policy explains which data is collected
when you visit the c3t.com.tr website, why it is collected and how it is protected. Data
sovereignty lies at the heart of our business model: our enterprise solutions mostly run on
the customer's own servers, and customer data never leaves the organization.
1. What Data Do We Collect?
- When you provide it: the organization name, full name, e-mail/telephone
and message content you share via the contact form.
- Automatically: technical log data recorded by the server during your
visit (IP, date and time, page, browser) and basic usage information collected via
cookies.
2. Why Do We Use the Data?
We use your data solely to respond to your request, communicate with you, keep the site
secure and improve the user experience. We do not sell your data to third parties for
marketing purposes.
3. How Do We Protect the Data?
We apply reasonable administrative and technical measures to protect your personal data
against unauthorised access, loss and misuse: access restriction, up-to-date
infrastructure, encrypted connections (HTTPS) and the principle of collecting data only to
the extent necessary (data minimisation).
4. Third Parties
We may rely on a limited number of service providers to operate the site:
- Hosting / infrastructure provider: for serving the site. In this
context, technical data may be processed on the provider's infrastructure as required
by the service.
- Analytics (where used): to measure visit statistics at an
anonymous/aggregate level. Analytics cookies run only with your explicit consent.
Sharing with these providers is limited solely to the purpose of delivering the service
and is subject to the necessary confidentiality obligations.
5. Your Rights
You have all the rights under KVKK Art. 11, including the right to access, rectify and
erase your personal data and to object to its processing. See the "KVKK Disclosure" tab
for details.
6. Contact
For any questions or requests regarding privacy, you can reach us at
[email protected].
Cookie Policy
Cookies are small text files stored in your browser when you visit a website. c3t.com.tr
uses a limited number of cookies to ensure the site works properly and to improve your
experience.
1. Cookie Categories
- Strictly necessary cookies: required for the core functions and security
of the site. The site does not work properly without them; therefore they do not require
consent.
- Functional cookies: used to remember your preferences (for example, your
light/dark theme choice) and make your experience easier.
- Analytics cookies: to measure visit statistics at an aggregate level and
improve the use of the site, we use Google Analytics (via Google Tag Manager)
and Microsoft Clarity. Google Analytics measures visit and page statistics;
Microsoft Clarity measures aggregate usage analysis (heatmaps and anonymised session
behaviour). These cookies are loaded only with your explicit consent; if you
do not give consent or you decline, no analytics cookie or measurement code is executed.
The measurement is not intended to identify you personally. Within this scope, limited
technical data (e.g. truncated IP, page views, click/scroll interactions) is processed by
Google and Microsoft; since these providers' servers may be located abroad, data may be
transferred abroad; this transfer is based solely on your explicit consent.
2. What Do We Use Cookies For?
We use cookies to keep the site running securely and reliably, to remember your
preferences and (subject to your consent) to improve the content by understanding how the
site is used. We do not carry out advertising tracking or sell data to third parties via
cookies.
3. How Do You Manage Your Cookie Preferences?
A cookie consent notice is displayed on your first visit to the site; you
can manage analytics cookies there using the "Accept" or
"Decline" options. If you decline, analytics measurement is never started;
only the strictly necessary and functional cookies required for the site to work are used.
If you wish to withdraw the consent you have given, simply clear your browser's cookie and
local storage (localStorage) data for this site — the consent notice will be shown again on
your next visit.
You can also delete or block cookies at any time through your browser settings. Most
browsers allow you to manage cookies and clear existing ones. If you block strictly
necessary cookies, some parts of the site may not work as expected. Some settings, such as
your theme preference, are kept in your browser's local storage (localStorage) area, and
you can clear these from your browser settings as well.
4. Updates
This cookie policy may be updated in line with changes in legislation or in the operation
of the site. The current version is always published on this page.
Terms of Use
By using this website (c3t.com.tr), you are deemed to have accepted the following terms.
If you do not accept the terms, we kindly ask you not to use the site.
1. Purpose and Use of the Site
c3t.com.tr is an informational site presenting the enterprise AI and custom software
solutions of C3T Teknoloji AŞ. You agree to use the site lawfully, solely for information
and contact purposes, and not to engage in any attempt that would compromise the security
or operation of the site.
2. Intellectual Property
All content on the site — texts, images, logo, design, software and layout — belongs to
C3T Teknoloji AŞ unless otherwise stated and is protected by intellectual property
legislation. This content may not be copied, reproduced, distributed or used for commercial
purposes without the prior written permission of C3T.
3. Limitation of Liability
The information on the site is for general information purposes and does not constitute a
binding commitment or offer. C3T exercises reasonable care to keep the content current and
accurate; however, it does not guarantee that the site will be uninterrupted or error-free,
or that it is fit for a particular purpose. To the extent permitted by applicable law, C3T
cannot be held liable for indirect damages that may arise from the use of the site. C3T is
not responsible for the content of third-party sites linked from the site.
4. Right to Amend
C3T reserves the right to change these terms of use and the content of the site without
prior notice. The current terms take effect from the moment they are published on this
page; your continued use of the site means that you accept the changes.
5. Governing Law and Jurisdiction
These terms are governed by the laws of the Republic of Türkiye. The courts and
enforcement offices of Istanbul have jurisdiction over any disputes that may arise from
these terms or from the use of the site.
6. Contact
For questions regarding the terms of use, you can reach us at
[email protected].
Mutual Non-Disclosure Agreement (NDA)
The text below is the mutual non-disclosure agreement that C3T Teknoloji
AŞ uses in projects conducted with its enterprise customers. It is based on the principle
of protecting the information shared by the parties before a project discussion, discovery
study or technical assessment. For a specific project, the agreement is signed mutually
with the parties' identity and signature details added.
1. Parties
This Non-Disclosure Agreement (the "Agreement") is concluded between
C3T Teknoloji AŞ ("C3T"), headquartered in Istanbul / Türkiye, on the one
side, and the Organization / Customer ("Organization") sharing information,
on the other side. C3T and the Organization are referred to together as the "Parties" and
individually as a "Party". The Agreement covers the information the Parties mutually disclose
to one another; either Party may act as both the disclosing and the receiving party.
2. Purpose
The purpose of this Agreement is to set out the rights and obligations regarding the
protection of confidential information exchanged between the Parties within the scope of a
potential or existing business relationship, project discussion, technical discovery,
development or integration work (the "Purpose").
3. Definition of Confidential Information
"Confidential Information" covers all information and data conveyed by one Party to the
other in written, oral, visual, electronic or any other form that is confidential by its
nature or is marked as confidential. This includes, in particular, the following:
- Technical information: source code, software architecture, algorithms,
model weights, data schemas, system design, infrastructure and network configurations,
technical documentation and know-how.
- Commercial information: business plans, pricing, proposal and contract
terms, customer and supplier information, marketing and strategy documents.
- Organization data: data relating to the Organization's business
processes, operations and activities, together with the content of any corporate database
accessed within the scope of the project.
- Personal data: any personal data relating to natural persons that falls
within the scope of Law No. 6698 (KVKK) and the relevant legislation.
4. Obligations of the Parties
With respect to the Confidential Information it receives, the receiving Party agrees and undertakes:
-
To keep the Confidential Information confidential; not to disclose, publish or transfer
it to third parties without the prior written permission of the other Party,
-
To use the Confidential Information solely for the Purpose defined in this Agreement; not
to use it for any other purpose, whether for its own benefit or that of a third party,
-
To ensure that only employees, authorised persons and subcontractors who need to know it
for the Purpose have access to the Confidential Information; and to bind such persons by
confidentiality obligations at least as binding as those in this Agreement,
-
To apply reasonable administrative, technical and physical security measures to protect
the Confidential Information, with no less care than it applies to its own confidential
information,
-
To notify the other Party without delay in the event of unauthorised disclosure or loss
of the Confidential Information, and to take reasonable measures to mitigate the damage.
The foregoing obligations are accepted and undertaken by the receiving Party.
5. Exceptions
In the following cases, the information in question is not considered Confidential
Information within the meaning of this Agreement or falls outside the scope of the
confidentiality obligation. The burden of proving this lies with the receiving Party:
- Information that is publicly available at the time of disclosure, or subsequently becomes public through no fault of the receiving Party,
- Information already lawfully known to the receiving Party prior to disclosure, without any confidentiality obligation,
- Information independently developed by the receiving Party without reliance on the Confidential Information,
- Information lawfully obtained from an authorised third party that is not under a confidentiality obligation,
-
Information whose disclosure is legally required by law, court order or the request of a
competent public authority. In such a case, the receiving Party shall, to the extent
possible and unless legally prevented, notify the other Party before disclosure and limit
the disclosure to the scope required.
6. Personal Data, KVKK and Data Sovereignty
Where personal data is processed within the scope of the project, the Parties undertake to
act in accordance with the KVKK (Law No. 6698) and the relevant secondary legislation.
C3T's working model is based on the principle of data sovereignty: as a rule, C3T
solutions run on the Organization's own servers (on-premise); organization data and personal
data remain within the Organization's own infrastructure and are not taken outside.
In these projects the Organization is the data controller, and C3T — to the extent it
processes data — acts as the data processor and processes personal data solely in
accordance with the Organization's instructions and the Purpose.
C3T takes appropriate technical and administrative measures with respect to the personal
data it accesses; it does not use the data beyond the Purpose, does not share it with
unauthorised persons, and deletes or returns it at the end of the project in accordance
with the Organization's instructions.
7. Ownership and Licence
Disclosure of Confidential Information does not grant the receiving Party any ownership,
licence or intellectual property right in that information. All Confidential Information
remains the property of the disclosing Party.
8. Term and Survival of Confidentiality
This Agreement enters into force on the date of signature and remains valid for the
duration of the Parties' business relationship. The confidentiality obligations continue
for a period of five (5) years from the termination of the Agreement or of
the business relationship between the Parties. With respect to information constituting a
trade secret and to personal data, the confidentiality obligation remains in force
indefinitely for as long as such nature or protection continues under the relevant
legislation.
9. Return and Destruction
Upon termination of the Agreement or upon the written request of the disclosing Party, the
receiving Party shall, within a reasonable period, return or permanently destroy all
Confidential Information and copies in its possession. Copies that technically and
unavoidably remain in backup systems continue to be subject to the confidentiality
obligations of this Agreement.
10. Breach and Liability
In the event of a breach of the confidentiality obligations, the breaching Party is liable
to compensate the direct damages suffered by the other Party as a result. With respect to
damages that cannot be measured in monetary terms, the injured Party may, without prejudice
to its right to compensation, resort to all remedies provided by law, including injunctive
relief.
11. Governing Law and Jurisdiction
This Agreement is governed by the laws of the Republic of Türkiye. The courts and
enforcement offices of Istanbul have jurisdiction over the resolution of any
dispute arising from or in connection with the Agreement.
12. Other Provisions
The invalidity of any provision of this Agreement does not affect the validity of the
remaining provisions. Amendments to the Agreement are valid only when made in writing and by
mutual agreement. A Party's failure to exercise any right does not constitute a waiver of
that right.
For information about the non-disclosure agreement process for your enterprise projects,
you can contact us at [email protected].