Effective Creative Works processes and protects personal data in accordance with applicable data protection principles. This page explains processing purposes, legal grounds, retention periods and your rights.
1. Data controller and scope of this notice
The data controller under Turkish Personal Data Protection Law No. 6698 is Effective Creative Works, which provides its services under the Effective Dijital brand. The controller can be reached at Konacık Mah. Kanuni S.S. Cad. No:11 A4, Arbor Derin İş Merkezi, Bodrum/MUĞLA, by e-mail at merhaba@effectivecreativeworks.com or by telephone at +90 (540) 560 49 45. The website is available at https://effectivedijital.com.
This notice covers website visitors, prospective customers, current and former customers, employees or authorised representatives of customers, customer portal users, newsletter subscribers, supplier and business partner contacts, and natural persons who interact with Effective Dijital through social media or other communication channels.
The duty to inform is fulfilled at the time data is collected and, where appropriate, for the particular activity. If a form, contract, campaign, production or other process includes a more specific notice, that specific notice takes priority for that activity. Where explicit consent is required, the notice and consent request are presented separately; consent is not made a condition for portions of a service that rely on another lawful ground.
2. Collection methods and groups of data subjects
Personal data is obtained through enquiry and proposal forms, e-mail, telephone, messaging applications, in-person or online meetings, contracting and ordering flows, the customer portal, support requests, CRM records, newsletter forms, cookies and similar technologies, social media platforms, project files, invoices and payment records. Collection may be wholly or partly automated, or non-automated where the information forms part of a filing system.
If a customer provides data about an employee, representative, influencer, participant or another person appearing in content, the customer must ensure that it is authorised to provide that data, has supplied any necessary notice and, where required, has obtained lawful consent. Effective Creative Works separately remains responsible for the obligations that apply to its own role.
- Data obtained directly from the individual, including form fields, meeting notes, requests, approvals, revisions and portal use.
- Data supplied by a customer organisation, including authorised users, team members, brand representatives and billing contacts.
- Data from public sources, including corporate websites, public social media profiles and lawfully accessible trade registry information.
- Data generated by service providers, including hosting logs, analytics measurements, e-mail delivery records and İyzico payment or subscription results.
3. Categories of personal data processed
| Category | Examples and scope |
|---|---|
| Identity | Name, surname, role or title, representation and authority details where a person acts for a customer or supplier, and tax or identity-verification details where legally necessary. |
| Contact | E-mail address, telephone number, business address, service address and communication channel preferences. |
| Customer transaction and contract | Proposal, order, package, service period, contract, approval, revision, delivery, support request, meeting note, portal activity and relationship history. This includes the IP address and browser or user-agent string recorded when legal terms or an order are accepted, together with the accepted version and timestamp. |
| Finance and payment | Invoice and tax details, amount, currency, payment date, İyzico transaction or subscription reference, payment status, failure code and, where made available, masked card digits. Full card number, expiry date and security code are processed in the İyzico payment environment; Effective Creative Works does not seek to store them in its systems. |
| Digital trace and security | IP address, date and time, request and error logs, session identifier, device, operating system and browser or user-agent type, approximate location, security event, sign-in and verification records. |
| Marketing and preference | Newsletter subscription, commercial communication consent or objection, campaign engagement, cookie preferences and service interests. |
| Visual, audio and content | Photographs, video, audio, brand assets, social media handles, comments, messages, production footage and people appearing in content supplied for a project. |
| Professional and organisational | Company, sector, position, expertise, brand account, project responsibility and business contact information. |
| Legal transaction and compliance | Notices, claims, complaints, disputes, audits, consent and notice records, evidence of acceptance and legal matter files. |
| Special categories | Not requested as a rule. If such data necessarily appears in a production, accessibility request or content, it is processed only under an applicable condition of the Law, in a purpose-limited manner and with enhanced safeguards. |
4. Purposes and legal grounds
The condition under the Law that is most appropriate to each processing activity is used. If the same data is processed for more than one purpose, each purpose is assessed separately for legal basis and retention. Explicit consent is not used as an unlimited or fallback ground when performance of a contract, legal obligation or another condition applies.
| Activity and purpose | Principal data | Legal ground under Law No. 6698 |
|---|---|---|
| Responding to an enquiry, analysing needs, preparing a proposal and pre-contract discussions | Identity, contact, professional details and request content | Direct relation to establishing a contract under Article 5(2)(c); legitimate interests under Article 5(2)(f) where appropriate. |
| Social media management, content planning, design, production, advertising operations, reporting and operation of the customer portal | Customer transaction, contact, content and digital trace | Establishment or performance of a contract under Article 5(2)(c); legitimate interests in service quality and operations under Article 5(2)(f), provided fundamental rights are not harmed. |
| Creating weekly, monthly or annual subscriptions, recurring card collection through İyzico, payment reconciliation and invoicing | Identity, contact, finance and transaction references | Contract performance under Article 5(2)(c); tax, accounting and consumer-law duties under Article 5(2)(ç); establishment or protection of rights under Article 5(2)(e). |
| Recording the version of legal terms accepted in checkout, the timestamp, acceptance IP and acceptance user-agent, and proving the order and recurring-payment authority | Contract record, IP address, browser or device signature and transaction details | Establishment or performance of a contract under Article 5(2)(c) and establishment, exercise or protection of legal rights under Article 5(2)(e). |
| CRM records, customer relationship management, service history, support and quality follow-up | Identity, contact, customer transaction, meeting and support records | Contract performance under Article 5(2)(c); legitimate interests in organisational continuity, request tracking and service improvement under Article 5(2)(f). |
| Account and portal security, abuse prevention, logging, backup and incident response | Digital trace, security and account data | Legal obligation under Article 5(2)(ç); establishment or protection of rights under Article 5(2)(e); legitimate interests in information security under Article 5(2)(f). |
| Non-essential analytics cookies and measurement through Google Analytics or Google Tag Manager | Online identifiers, device, usage event and approximate location | Specific, informed and withdrawable explicit consent collected through the cookie panel under Article 5(1). |
| Newsletters, promotions and commercial electronic messages | Name, e-mail, telephone, preference and engagement | Explicit consent under Article 5(1) where required and permission under Law No. 6563; existing-customer exceptions only within limits allowed by law. |
| Legal claims, audits, evidence, fraud and dispute management | Transaction, finance, contact, logs and legal transaction data | Legal obligations under Article 5(2)(ç) and establishment, exercise or protection of rights under Article 5(2)(e). |
5. Processing principles, minimisation and accuracy
- Data is processed lawfully, fairly, accurately and kept up to date where necessary.
- Purposes are specific, explicit and legitimate; processing remains relevant, limited and proportionate.
- Information unnecessary for a service is not made mandatory, and special-category information is not requested in free-text fields.
- Incorrect or changed contact, invoicing or authority details may be corrected by contacting merhaba@effectivecreativeworks.com.
- When retention is no longer justified, data is handled under deletion, destruction or anonymisation procedures.
6. Domestic recipients and purposes of disclosure
Personal data is disclosed only to recipients who need it for service delivery, payment, security, legal compliance or another disclosed purpose, and only to the extent necessary. Confidentiality, security, processing and deletion obligations are addressed contractually with service providers, and access is restricted by role and need.
- İyzico and participants in the payment ecosystem for subscription registration, payment authorisation, fraud checks, collection, cancellation and refunds.
- Hosting, domain, e-mail, backup, security, support, CRM, accounting and e-invoicing providers for the relevant technical or operational service.
- Social media, advertising, design, file-sharing, production and publishing platforms approved by the customer to produce, review or publish content.
- Accountants, legal advisers, auditors, banks and insurers for financial operations, advice, risk management and protection of rights.
- Public authorities, courts and enforcement offices where an express legal duty or duly issued request applies.
Where a third party determines its own purposes and means, it may be an independent controller and its own privacy notice will apply.
7. International transfers
Social networks, Google Analytics or Tag Manager, international cloud, e-mail, video, mapping, file-sharing and project tools may use servers or support teams outside Türkiye. Enabling those services may make personal data, including account or device identifiers, accessible abroad.
International transfers follow the tiered framework in Article 9 of the Law. An adequacy decision by the Board is considered first. Where no adequacy decision exists, an applicable safeguard such as the Board-approved standard contract, binding corporate rules or another safeguard prescribed by law is established and any required notification is made. In the absence of both adequacy and an appropriate safeguard, a statutory occasional-transfer exception is used only if its actual conditions are met and the transfer is not continuous.
Where explicit consent is required, the individual is informed in advance about likely risks, the recipient or recipient group, country and purpose. Non-essential analytics and third-party embeds do not load before the relevant choice is made. Withdrawing consent does not affect past lawful processing but stops future transfers that rely on that consent.
8. Retention periods and disposal approach
The periods below are general planning criteria. A longer statutory period, current dispute, audit, legal claim or limitation period may require a record to be retained longer with access restricted to that purpose. At expiry, data is deleted, destroyed or irreversibly anonymised. Copies in backups are securely overwritten within the normal backup cycle.
| Record group | General retention criterion |
|---|---|
| Unconverted enquiries and proposals | Generally 2 years after the last interaction, or less where deletion is requested earlier or the purpose expires. |
| Contracts, projects, approvals, deliveries and portal records | For the relationship and generally 10 years after it ends, taking account of limitation and evidentiary needs. |
| Checkout evidence, including accepted legal version, acceptance timestamp, acceptance IP and acceptance user-agent | For the subscription or contractual relationship and thereafter generally up to 10 years, or through the applicable limitation and dispute period where different. |
| Invoice, accounting, tax and payment records | For mandatory periods under tax, commercial and accounting law, generally up to 10 years. |
| İyzico subscription and transaction references | For the subscription, then for financial duties, objections, chargebacks and applicable limitation periods. |
| Portal and security logs | Generally 6 months to 2 years according to risk; longer where required for an incident or legal claim. |
| Newsletter and marketing records | Until permission is withdrawn or the purpose ends; permission and objection evidence for the applicable statutory period. |
| Cookie preference record | As needed to remember and demonstrate the choice; an earlier record may be retained only for a limited audit need after preferences change. |
| Disputes and KVKK request files | For relevant administrative and legal limitation periods after the matter closes. |
9. Technical and organisational safeguards
- Access matrices, unique user accounts, strong passwords, multi-factor authentication where appropriate and periodic access review.
- Current encryption protocols in transit, secure backups, log monitoring, malware protection and vulnerability management.
- Session handling, CSRF protection, rate limiting and secure development controls for customer portal and administrative areas.
- Confidentiality duties, least privilege, awareness and incident-reporting procedures for staff and service providers.
- Separation of physical and digital project files by customer, and time or access limits for public sharing links.
- Assessment, containment, documentation and, when required, notification to the Board and affected individuals following a suspected personal data breach.
No system can guarantee absolute security. Effective Creative Works applies reasonable, current and risk-proportionate measures; users must not share portal credentials and should promptly report suspicious access.
10. Your rights under Article 11 of the KVKK
- Learn whether your personal data is processed and, if so, request information about that processing.
- Learn the purpose of processing and whether the data is used in accordance with that purpose.
- Know the third parties in Türkiye or abroad to whom personal data is transferred.
- Request correction of incomplete or inaccurate data and notification of the correction to recipients.
- Request deletion or destruction when the statutory conditions apply, and notification of that operation to recipients.
- Object to a result against you arising from analysis exclusively through automated systems.
- Claim compensation if you suffer damage because personal data was processed unlawfully.
11. Request method and response procedure
You may submit a request with information sufficient to verify your identity and understand the request, addressed to Effective Creative Works at Konacık Mah. Kanuni S.S. Cad. No:11 A4, Arbor Derin İş Merkezi, Bodrum/MUĞLA in writing or by an accepted method under the Communiqué on the Procedures and Principles of Application to the Data Controller at merhaba@effectivecreativeworks.com. The request should contain name and surname, signature where the method requires one, Turkish identity number for Turkish citizens, nationality and passport or other identification number for foreign nationals, service address, e-mail and telephone where applicable, and the subject of the request.
Additional information may be requested depending on the nature of the request, but disproportionate identification evidence will not be required. Requests are concluded free of charge as soon as possible and no later than 30 days. A fee under the tariff set by the Board may apply if the operation creates an additional cost. If a request is rejected, the response is inadequate or no timely response is supplied, you may complain to the Personal Data Protection Board under the statutory time limits and conditions.
Withdrawal from marketing, changing a cookie choice or cancelling a subscription may also be completed through their separate operational channels. Those options do not restrict the right to make a KVKK request.
12. Automated decisions and children’s data
Effective Creative Works does not intend to make decisions producing legal or similarly significant effects solely through automated processing. Fraud or security signals may place a transaction under temporary review, and human review may be requested for the final assessment.
Services are generally intended for businesses and people aged 18 or over. Data about children in social media or production content is processed only with the legal basis and parent or guardian permissions determined with the customer, taking the child’s best interests into account. Suspected unauthorised sharing of a child’s data should be reported immediately to merhaba@effectivecreativeworks.com.
13. Updates and contact
This notice may be updated if processing activities, service providers or law changes. Material changes are announced through the website, portal or registered communication channel where appropriate. The version and effective date shown above identify the current text.
For questions about this notice, contact merhaba@effectivecreativeworks.com, call +90 (540) 560 49 45 or write to Konacık Mah. Kanuni S.S. Cad. No:11 A4, Arbor Derin İş Merkezi, Bodrum/MUĞLA.
Official legal sources
The following primary sources were used when preparing this document. Amendments to mandatory law prevail over this text.