Privacy Policy

This notice explains which personal data we process when you visit keydesignart.com, for which purposes and on which legal grounds we process it, whom we share it with, how long we keep it, and how you can exercise your rights.

Our website has no membership, user account, registration, sign-in, ordering, payment or subscription. The data we collect is therefore limited: our only personal data collection point is the contact form; besides that, there are server logs and strictly necessary cookies.

  1. Purpose and Scope

    This document is both our privacy policy and the information notice required under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data (KVKK) and the Communiqué on the Procedures and Principles to be Followed in Fulfilling the Obligation to Inform. It applies to both the Turkish and English versions of keydesignart.com.

    This document is not a consent declaration. The personal data processed on the site relies not on your explicit consent but on the other lawful grounds explained one by one below. For that reason you are not asked to tick any consent box in order to use the contact form.

    Keysletter is a separate product served on a separate domain and is governed by its own privacy and usage documents; this notice does not cover Keysletter.

  2. Data Controller

    The controller of the processing activities described in this notice is the business identified below. You may use the contact channels below for any question, request or data protection application concerning this notice.

    • Name: Key Design&Art
    • Address: Osmanağa Mah. Söğütlüçeşme Cad. No:64/82 Kadıköy / İstanbul, Türkiye
    • Phone: +90 552 735 83 48
    • Email: info@keydesignart.com
    • Tax number: 9520788545
  3. Personal Data We Collect

    We obtain your personal data from only three sources: the contact form you fill in and submit, the server logs generated by the requests you make to the site, and the strictly necessary cookies placed in your browser.

    Contact forms

    There are two different forms on the site. The full form on the contact page contains Full name (required), Email address (required), Phone (optional), Subject (optional) and Message (required). The shortened form in the footer of the other pages contains only Full name, Email address and Message. On the contact page the footer form is hidden, so two forms are never shown on the same page.

    When you submit the form, we also store the IP address you connected from, together with the message record, in order to prevent abuse. Your message is stored in our database and also delivered to our company e-mail address over SMTP.

    The message field is free text. Please do not enter special categories of personal data (such as health, belief or membership information) or information belonging to third parties; we do not intend to process such data.

    Server logs

    The site keeps structured server logs for security and error tracking. These logs contain the IP address, date and time, the requested address, the server response code, the response time and browser information (user agent). The name, e-mail address and message content you enter in the contact form are not written to the server logs; the logs contain only a record identifier and technical information.

    Data we do not collect

    Because the site has no membership, payment, ordering or comment system, we do not collect national identity numbers, dates of birth, identity documents, card or invoice details, location data or special categories of personal data. We do not profile visitors, and no decision producing an adverse effect on you is taken solely by automated analysis.

    Method of collection

    Your data is collected entirely in electronic form, by automated and partly automated means: through the contact form when you enter it yourself, through server logs when you make requests to the site, and through strictly necessary cookies via your browser.

  4. Purposes of Processing

    We process your personal data only for the purposes listed below; this is a closed list, and if we ever wish to extend it we will inform you separately.

    1. Responding to your enquiry by e-mail or telephone.
    2. Holding preliminary discussions and preparing a proposal for the service you requested.
    3. Preventing spam, automated or abusive submissions of the form (through a honeypot field, a form token, rate limiting and a daily submission cap).
    4. Maintaining server and network security and detecting and resolving faults and errors.
    5. Concluding data protection requests you submit to us and, where necessary, exercising our right of defence in a legal dispute.

    We do not process your data for any purpose beyond these; if our purpose changes, we will update this notice and inform you.

  5. Legal Grounds We Rely On

    The legal ground we rely on for each processing activity is shown in the table below. None of our processing activities relies on explicit consent.

    Processing activityLegal ground (KVKK)
    Processing contact form data to answer your enquiry and hold preliminary discussions or prepare a proposalArt. 5/2-(c): Directly related to the conclusion or performance of a contract
    Processing form data, the IP address and anti-spam mechanisms to prevent abuseArt. 5/2-(f): Our legitimate interest, provided your fundamental rights are not harmed — that interest being the prevention of spam and automated abuse
    Keeping server logs for security and error trackingArt. 5/2-(f): Our legitimate interest — ensuring system and network security
    Use of strictly necessary cookiesArt. 5/2-(f): Our legitimate interest — secure operation of the site as you requested it
    Answering your data protection requestArt. 5/2-(ç): Compliance with our legal obligation
    Measuring visit statistics with analytics cookies and transferring measurement data abroadArt. 5/1 and Art. 9: Your explicit consent — no processing takes place unless you give it
  6. Cookies Used on the Site

    A cookie is a small text file that a website places in your browser. Strictly necessary cookies always run on our site; analytics cookies are created only if you give your consent in the cookie preference window. The table below states each cookie's purpose, lifetime and whether it requires consent.

    CookiePurposeLifetime
    .AspNetCore.Antiforgery.<random>Prevents cross-site request forgery (CSRF) on form submissions; the random string at the end of the name is generated by the applicationSession (deleted when the browser closes)
    KeyDesignArt.AuthCreated only when signing in to the internal admin panel; never created for visitors7 days
    kda_consentRemembers the Accept / Reject answer you give in the cookie preference window; created only when that window is displayed and you give an answer180 days
    _gaGoogle Analytics; holds the identifier that distinguishes a visitor. Created only if you give consent in the cookie preference window2 years
    _ga_<measurement id>Google Analytics; holds session state. Created only if you give consent in the cookie preference window2 years

    On your first visit a cookie preference window is shown; until you give consent no measurement script runs and no analytics cookie is created. That window offers only Accept and Reject; it does not provide category-by-category selection.

    Language selection on the site is handled through the URL structure rather than a cookie (Turkish pages have no prefix, English pages begin with /en), so no language preference cookie is placed either.

    You can delete or block cookies through your browser settings (Chrome, Firefox, Safari, Edge). If you block strictly necessary cookies, functions such as form submission may stop working.

  7. Parties We Share Data With

    We share your personal data only with the parties that are strictly required for the service to be delivered, and within the framework of obligations arising from legislation.

    • Our hosting infrastructure: the site and database are hosted on servers located in Türkiye, so the data is technically accessible through that infrastructure.
    • Our e-mail (SMTP) infrastructure: your contact form message passes through this infrastructure when it is delivered to our company e-mail address.
    • Competent public authorities: only where there is a request or obligation arising from legislation.

    Apart from these, we never sell or rent your personal data to any third party, and we do not share it with any third party for marketing purposes.

  8. Transfers Abroad

    The site and database are hosted on servers located in Türkiye. If you consent to analytics measurement, visit data is transferred to Google's servers abroad; this transfer relies solely on your explicit consent and does not take place unless you give it.

    The fonts used on the pages are hosted on our own server and no request is sent to external sources such as Google Fonts.

  9. Retention Periods

    We keep your personal data for as long as the processing purpose requires, taking into account the limitation periods set out in legislation. The periods we apply are as follows.

    DataRetention period
    Contact form message and the IP address stored with it (database)2 years
    Copy of the message in the company mailbox2 years
    Server access logs14 days
    Server error and warning logs30 days
    CookiesThe lifetimes shown in the cookie table above

    We keep server logs solely for security purposes, that is, to detect and investigate unauthorised access attempts and abuse. If an enquiry turns into a project, the related data is then assessed within the scope of the contractual relationship and is kept according to its own retention periods under the contract and under commercial and tax legislation. Once the period expires, the data is deleted, destroyed or anonymised.

  10. Security Measures We Apply

    We apply the following technical and organisational measures to prevent the unlawful processing of your personal data and unauthorised access to it.

    • The site is served entirely over HTTPS.
    • A strict Content Security Policy is applied; no unauthorised script can be loaded into a page and the site cannot be embedded in another site's frame.
    • Fonts are hosted on our own server; no request is sent to Google Fonts.
    • The contact form uses a honeypot field, a single-use form token, rate limiting and a daily submission cap.
    • Form content is never written to server logs; administrator sign-in records store the e-mail address in masked form.
    • The admin panel is for internal company use only and is closed to visitors.
  11. Your Rights Under the KVKK

    Under Article 11 of the Law, by applying to us you have the right to:

    1. Learn whether your personal data is being processed.
    2. Request information if it has been processed.
    3. Learn the purpose of processing and whether the data is used in line with that purpose.
    4. Know the third parties in Türkiye or abroad to whom your data has been transferred.
    5. Request rectification if the data is incomplete or inaccurate.
    6. Request erasure or destruction under the conditions in Article 7 of the Law.
    7. Request that rectification, erasure and destruction be notified to the third parties to whom the data was transferred.
    8. Object to an adverse outcome arising from the analysis of your data solely by automated systems.
    9. Claim compensation if you suffer damage due to unlawful processing.

    We do not carry out profiling, nor any processing that produces an adverse outcome for you solely through automated analysis.

  12. How to Submit a Request

    In line with the Communiqué on the Procedures and Principles of Application to the Data Controller, you may submit your request as follows:

    • In writing with a wet signature: in person, through a notary, or by registered mail with return receipt to Osmanağa Mah. Söğütlüçeşme Cad. No:64/82 Kadıköy / İstanbul.
    • Electronically: using a secure electronic signature or mobile signature, or from an e-mail address already registered in our systems, to info@keydesignart.com.

    Your request must include your name and surname, your signature if submitted in writing, your Turkish identity number (for foreign nationals, nationality and passport or identity number), your address for notification, your e-mail address and phone number if applicable, and the subject of your request. Where we cannot verify your identity, we may ask for additional information.

    We conclude requests free of charge, as soon as possible and within thirty days at the latest. If the process entails an additional cost, we may charge the fee set out in the tariff determined by the Board; for written replies no fee is charged for up to ten pages, and a processing fee of 1 Turkish Lira per page may be requested beyond ten pages.

    If your request is rejected, if you find our reply insufficient, or if no reply is given within the period, you may lodge a complaint with the Personal Data Protection Board within thirty days from the date you learn of our reply and, in any case, within sixty days from the date of your application. By law you must apply to us first; a complaint cannot be filed with the Board before that route is exhausted.

  13. Changes to This Notice

    We may update this notice due to legislative developments or technical changes on the site. The current version is always published on this page, with its effective date shown below.

    Visit statistics on the site are measured with Google Analytics 4 through Google Tag Manager. Your preference is stored for 180 days in a cookie named kda_consent; you can change it at any time from the "Cookie preferences" link in the footer. If the measurement tools used on the site change, this notice will be updated.

    In case of any discrepancy between the Turkish and English versions of this notice, the Turkish version prevails.

    Last updated: 6 August 2026