Thank you for visiting our web site and reading our privacy and security statement.
CottGroup®’s network of companies (CottGroup®) has dedicated itself to ensuring the security of your personal data in all of its information systems. For CottGroup®, confidentiality and security matters form the basis of the relation between us and our customers. CottGroup® understands your particular concern about the your confidentiality and security and place utmost importance on that matter.
CottGroup® consists of multiple independent members which provide various sections of the websites in CottGroup®’s network of members. Please click here to see our current member companies. New members to be added to the CottGroup®’s network of members in future will also be viewable by clicking the same link.
Information that you will be disclosing when using this web site may also be controlled by any other firm among the members of CottGroup®’s network in order to enable us to secure the control, inspection and security of the said data at the utmost level. Each independent member shall be legally liable for any data controlled and inspected by it.
CottGroup® Privacy Statement is applicable to all data processed by CottGroup®, including Personal Data collected or transmitted via our web sites in CottGroup®’s network, our software and self-service applications, mobile applications or social media accounts and other online or off-line channels.
CottGroup® acts in the capacity of a data controller in line with the Personal Data Protection Law no. 6698 and provisions of any other legislation applicable to the protection of personal data. Accordingly, personal data shall be processed only by CottGroup® personnel authorized to implement any privacy and security policy as well as services falling within the scope of duty of CottGroup®’s management office and the personnel named in the privacy and security authorization matrices, and those natural/legal persons authorized by CottGroup® for such purpose by fulfilling the condition of informing the data subjects. For details, please click the "Personal Data Protection and Processing Protocol".
Subject to communication consents provided by you during your communication with us regarding electronic (e-mail) messages and through any other CottGroup® channel, you will be deemed to have accepted to receive e-mail messages through your contact details, for the promotion of services offered by CottGroup® and its business partners, information on new products and services, announcements on issues regarding legislation, and other matters that may be of interest for you. In this respect, you may contact CottGroup® to request that messages are no longer sent to you through one or more than one communication channel.
Cookies are program bits that are usually in the form of text files that may be embedded in laptops, desktop PCs and mobile devices, which collect various data.
Cookies may be used to collect the following data:
We may use your personal data which we record during your visits to our website, via automated or non-automated means, or which you may disclose to us in communication forms, e-mails or via other electronic transactions, primarily for the purpose of satisfying your requests and subsequently for ensuring improvement of the services offered to you. Overall purposes of use of such data may be listed as follows:
Please do not disclose such data that you would not want us to collect for the purposes above. Please remember that unless you provide such data, we will be unable to contact you, and that your certain data may still be collected by means of cookies during your visit to this website.
CottGroup® places utmost importance on the security of your data. CottGroup® places utmost importance on the security of your data. We take measures conforming to sector standards to prevent unauthorized collection and use of your data. Exchange of information on the İnternet is not generally secure. Therefore, we recommend you to exercise due care by user when exchanging information through our websites and online systems. If you don't take this care, CottGroup® cannot guarantee you about security of your information and communication on the web-site or capture them by third parties.
When your information arrives at CottGroup®, it is protected in accordance with our security and privacy standards.
Your data are stored for the purposes set out above and only for the durations required by the needs of our business process or as prescribed by law.
We may transfer the personal information we collect about you to other countries different from the country we collect the data, as we use their services of the internet service providers, hosting companies, e-mail providers, domain providers (for example: Microsoft 365). Data protection laws and regulations applied in these countries may differ from the laws applicable in Turkey.
We support parents willing to supervise and control online activities of their children. In no event do we ask children on purpose to share their personal data. If we come to know that a person whose personal data are collected by us is younger than 13 years old, we may use such data to try to promptly inform his/her parents. This rule shall be applicable for age 16 under the European Union General Data Protection Regulation (GDPR).
CottGroup® takes the most appropriate technological and organizational measures to ensure confidentiality when developing new systems and applies necessary developments for the processing of personal data in line with their intended purposes (Privacy by design).
The main objective of this Personal Data Protection Policy (the “Policy”) is to provide explanations regarding the personal data processing activities carried out by the Company pursuant to the law and the systems adopted for the protection of personal data and, in this context, to provide transparency by informing the people whose personal data is being processed by our company.
This Policy applies to all activities managed by the Company regarding the processing and protection of personal data by the Company along with the relevant detailed data procedures.
PDPL: 6698 numbered the Personal Data Protection Law (hereinafter referred to as “KVKK”)
GDPR: EU General Data Protection Regulation
Data Processor: The natural person or legal entity that process data on behalf of the data controller with the authority given by the data controller
Data Controller: the one who defines the purpose and the means of processing personal data controller and responsible of the data recording system management
Data Subject: a natural person, includes but not limited to an employee, customer, business partners, stakeholders, authorities, leads, candidate for recruitment, intern, visitors, suppliers, employee of business partners, third parties whose data is processed.
Explicit Consent: consent that is related to a specific issue based on information and expressed with free will.
Personal Data: all information related to a real person whose identity is known or could be identified.
Sensitive Personal Data: Biometric and genetic information related with race, ethnicity, political or philosophical opinions, religion, sect or other believes, appearance, union memberships, health, sex life, convictions and security measures etc.
Processing Personal Data: any kind of transaction performed on the data such as obtaining, saving, storing, protecting, modifying, editing, describing, transferring, receiving, making available, classifying or blocking the use of the data with including them into totally or partially an automatic recording system.
Anonymizing Personal Data: to render data in such a way that it can no longer be associated with an identified or identifiable person even when the personal data is matched with other data.
Deleting Personal Data: to delete or to render personal data in such a way that it is no longer accessible or reusable for the users.
Destroying Personal Data: rendering the personal data to make it inaccessible, unrecoverable and not useable by anyone
Company: Data responsible CottGroup® companies.
KVK Board: Turkish Personal Data Protection Board
KVK Authority: Turkish Personal Data Protection Authority
The Company has different policies that cover protection of personal data along with the information security as regards certain work activities and functions. Unless this Policy has additional provisions or higher standards for the protection of personal data, the other different data protection provisions of the company shall prevail.
The relevant regulation provisions shall be first to apply in processing and protecting personal data; and if there happens any contradiction between the articles of this Policy and the legislation, then current legislation clauses shall prevail.
Herein this Policy is prepared in accordance with the rules and procedures foreseen in the KVKK and related law for the protection of personal data. In this manner, under KVKK the data controller should take every technical and administrative measures to prevent illegal processing and access of the personal data.
Our Company acts in accordance with the following general principles in all of its Personal Data Processing activities:
Your personal data collected by our company varies according to the quality of the relationship with our company and the legal obligations. Your personal data collected can be listed as follows:
The Company shall inform data subjects during acquiring the personal data due to KVKK and related legislation. In this manner, the Company makes a notification/information regarding the purpose of data processing, transfer of the data and to whom the data shall be transferred, the method of collecting personal data and the legal purpose of collecting personal data.
The purpose of processing personal data information varies according to the relationship between the company and data subject and legal nature of the business.
The purposes of processing personal data by the Company are as follows:
Personal data can be obtained/received by parties who are the data subject and/or third parties who have explicit consent from the data subject. The obtained personal data can be processed by collecting, saving, editing, configuring, storing, adapting, changing, using, transferring, deleting, destroying and anonymizing.
Personal Data may be processed by one or more of the above methods without the explicit consent of the data subject in the presence of one the legitimate reasons listed in Article 5 of the KVKK:
Without prejudice to any situation in which it is obligatory to transfer personal data to administrative of judicial authorities under KVKK or related law, the Company shall transfer personal data with obtaining data subject’s explicit consent unless it is an issue mentioned in the Art. 5 and/or 6 of the KVKK.
Personal data is not transferred to any third party without an explicit consent, unless it is legally required due to the KVKK, relevant legislation and cases where it is mandatory to be shared with the external parties due to administrative / juridical cases. However, as per to the Article 5 and Article 6 of the KVKK, in case legal grounds are present and it is legally required, on third party transferred, consent / explicit consent will not be observed.
Our Company fulfills its obligation to inform the Data Subject regarding this transfer. Accordingly, the institutions, organizations and / or persons that can be transferred are listed below.
The Company may transfer the personal data abroad by obtaining explicit consent of the data subject along with taking appropriate and necessary security measures foreseen in the KVKK and related legislation. For the situations in which the explicit consent of the data subject is not sought, it is considered whether the country that the data will be transferred, is in “adequate country” stature and has enough protection or not. If the Authority considers that the transferee country is not in adequate country statute, the Authority approval should be taken, and a data transfer protocol should be signed to guarantee enough protection.
Our company takes technical and administrative measures to prevent data breaches to ensure the security of personal data. In this context, our Company;
CottGroup® has established a data inventory as part of its approach to address risks and opportunities throughout its KVKK and GDPR compliance project. CottGroup®’s data inventory determines:
Within the scope of Article 11 of the KVKK the data subject has the following rights and if he / she wishes, he / she can use his / her rights by reaching the data controller in the methods determined by him / her:
In accordance with KVKK regulations; in cases you have inquiries on your rights, mentioned hereinbelow, by completing the Data Subject Application Form you can send it to the address; Astoria Towers Kempinski Residences Büyükdere Caddesi No:127 B Kule Kat:8 34394 Şişli-İstanbul/Türkiye along with ID verification documents either by hand or via postage services or by sending an e-mail to email@example.com. All queries will be answered within 30 days of receipt.
If the transaction also requires a cost, the tariff set by the KVKK will be charged.