Privacy and Protection of Personal Data
LAST UPDATED: 24 JULY 2026
Note: This text is a draft based on the site's actual data flow. The legal entity name, address and tax identifiers must be completed, and the text reviewed by legal counsel before publication.
1. Data controller
Trust (hereinafter "Trust") is the data controller under the GDPR (EU) 2016/679 and Turkish Personal Data Protection Law No. 6698 ("KVKK").
- Legal entity: [to be completed]
- Address: [to be completed]
- Email: gokhan.sahin@trustgida.com
- Web: www.trustgida.com
2. What data we process, and why
| Data | Source | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Name, email, company, area of interest, message content | Contact form | Responding to your request, proposal or meeting process | Consent — GDPR Art. 6(1)(a) / KVKK Art. 5/1 (form checkbox) | 24 months at most; deleted immediately on request |
| IP address, country code, browser data, request timestamp | Server / CDN log | Security, abuse prevention and bot blocking | Legitimate interest — GDPR Art. 6(1)(f) / KVKK Art. 5/2-f | 30 days at most |
Language preference (trust.lang) | Browser localStorage | Remembering the selected language | Strictly necessary function — never leaves your device | Until you clear it (in the browser) |
No automated decision-making or advertising tracking is used to profile visitors. No facial recognition, biometric data or special categories of personal data are collected.
3. Cookies
The Trust website uses no marketing or analytics cookies. The only locally stored item is the trust.lang key holding your language preference; it is not a cookie and is never sent to the server.
Our infrastructure provider Cloudflare may set strictly necessary security cookies such as __cf_bm to distinguish malicious traffic. These are short-lived and are not used for advertising.
4. Data transfers
To deliver your form submission, your data passes through the infrastructure of the following providers:
- Cloudflare, Inc. — web hosting, CDN, bot protection (servers in the EU/US).
- Resend (email delivery) — delivering the form message to Trust by email.
- Our email provider — storing the message in the inbox.
Because some of these providers are located outside Türkiye, submitting the form involves an international transfer. The transfer relies on your explicit consent and/or standard contractual clauses (GDPR Art. 46 / KVKK Art. 9). The form cannot be submitted without ticking the consent box.
5. Your rights (GDPR Art. 15–22 / KVKK Art. 11)
- To learn whether your personal data is processed and, if so, to request information about it
- To learn the purpose of processing and whether the data is used accordingly
- To know the third parties, domestic or abroad, to whom the data is transferred
- To request rectification if the data is incomplete or inaccurate
- To request erasure or destruction; to withdraw your consent at any time
- To request that rectification or erasure be notified to the recipients
- To claim compensation for damage suffered
Send your requests to gokhan.sahin@trustgida.com. They are answered within 30 days at the latest.
6. Security
- All traffic is encrypted with HTTPS/TLS; HSTS is enforced.
- Content Security Policy (CSP), framing protection and MIME-sniffing protection are applied.
- Fonts and third-party libraries are served from our own origin; visitor IPs never reach third-party CDNs.
- Form submissions are protected by bot verification and a per-IP rate limit.
- Form messages are not stored permanently on the server; they are only delivered by email.
7. Changes
This text may be updated. The current version is always published on this page; the date above shows the last update.