Privacy
- Home
- /
- Privacy
Approved:9 September 2026, contact corrected 14 September 2026 — effective when published
This policy explains how Maksellent Bilişim Ltd. Şti. processes personal data through maksellent.com. It covers the public website only; authenticated Maksellent applications, customer tenant data and employee data have separate notices.
1. Controller and contact
- Controller: Maksellent Bilişim Ltd. Şti., trading as Maksellent Bilişim ve Saha Hizmetleri.
- Address: Kozyatağı Mah. Gülbahar Sok. AR Plaza C Blok No:13/3/4, Kadıköy, İstanbul, Türkiye.
- Trade Registry No: 781066. Tax Identification No (VKN): 611 053 0623. Tax Office: Erenköy.
- Privacy and rights requests: support@maksellent.com.
- No separate data-protection officer or local representative is identified for this website. Maksellent will reassess and publish representative details before processing that legally requires an EEA or UK representative.
2. Data, purposes, lawful bases and retention
- Website delivery and security: IP address, requested URL, time, browser/device and error/security data are processed to deliver and protect the site under KVKK 5(2)(f) and GDPR/UK GDPR 6(1)(f). Request/security logs are kept for up to 90 days; isolated incident evidence for up to 3 years after closure.
- Localization and public content: language/catalog requests, ordinary request metadata and an on-device browser locale suggestion are used to display localized content and country options under legitimate interests. Browser locale lasts for the session; service logs are kept up to 90 days.
- Enquiries, once Lead intake is released: name, business email, telephone, country, company, department, product interest, request type, message, notice/consent version, time and anti-abuse metadata are used to answer and route the request under KVKK 5(2)(c)/(f) and GDPR/UK GDPR 6(1)(b)/(f). Unconverted enquiries are kept for 24 months after the last meaningful interaction; abuse evidence for 90 days. Converted records follow the customer notice.
- Optional marketing, once enabled: contact details, interests and consent/withdrawal evidence are processed only with explicit consent under KVKK 5(1) and GDPR/UK GDPR 6(1)(a). Data is kept until withdrawal or 24 months without meaningful engagement; minimal suppression evidence for 3 years.
- Privacy/legal requests: identity, contact, request, verification, correspondence and outcome are processed for legal obligations and legal rights under KVKK 5(2)(ç)/(e) and GDPR/UK GDPR 6(1)(c)/(f), and kept for 3 years after closure unless a legal hold requires longer.
- Consent-controlled Google Ads conversion tracking, if approved: an online identifier via Google's `_gcl` cookie, the requested page URL and referrer are used only with explicit consent, to attribute site visits to Google Ads campaigns. This is Google Tag Manager container GTM-N7T4GXX's complete exported tag inventory as of 2026-09-15, not a placeholder. Consent/withdrawal evidence is kept for 3 years. Contact-form values are never used for this.
3. Legitimate interests
For processing based on legitimate interests, Maksellent documents a necessity and balancing assessment. The interests are secure website delivery, service reliability, localization, enquiry administration, fraud and abuse prevention, and the establishment or defence of legal rights. You may object on grounds relating to your situation. We will stop the processing unless we demonstrate compelling overriding grounds or need the data for legal claims.
4. Recipients and providers
- Authorized Maksellent operations, sales, support, privacy and legal personnel receive only the data needed for their roles.
- Google/Firebase provides website hosting, delivery and infrastructure logging. Google-hosted Fonts/Material Icons currently deliver visual resources.
- Maksellent Tenant lookup supplies country options; Maksellent Note/content supplies public content; Maksellent Lead will receive enquiries only after its approved release.
- Google Tag Manager (container GTM-N7T4GXX) and its one exported tag, Google Ads conversion tracking, remain disabled until consent controls are implemented.
- Authorities, courts, advisers, auditors or a corporate successor receive data only when legally required or necessary for legal rights or a controlled transaction. We do not sell personal data.
5. International transfers
Providers may process data outside Türkiye or the visitor’s country. A European Firebase region does not by itself guarantee that support, telemetry or subprocessors remain there. Maksellent permits a transfer only after recording an applicable KVKK Article 9 mechanism and, where relevant, an adequacy decision, Standard Contractual Clauses, UK IDTA/Addendum and supplementary measures. Safeguard information may be requested from support@maksellent.com. Optional analytics remains disabled until its transfers are verified.
6. Your rights
- You may request confirmation, access, correction, deletion, restriction and information about purposes and recipients, subject to legal conditions.
- You may object to legitimate-interest processing for reasons relating to your situation and object to direct marketing at any time.
- You may withdraw consent at any time without affecting earlier processing and request portability where automated processing is based on consent or contract.
- You may challenge a qualifying solely automated decision, request recipient notification of correction/deletion, seek compensation where permitted and complain to the KVKK or another competent supervisory authority.
- Send requests to support@maksellent.com. We may request proportionate identity or authority verification.
7. Automated decisions and profiling
The public website does not make solely automated decisions producing legal or similarly significant effects. Locale suggestion, security screening and aggregate analytics are not used for such decisions. Marketing profiling requires separate approval, explanation and applicable objection or human-review rights before activation.
8. Security and deletion
We apply risk-appropriate access control, transport security, least privilege, logging, backup and incident-response measures, without guaranteeing absolute security. At the end of a retention period, data is deleted, anonymized or isolated under a legal hold. Provider backup deletion follows the documented provider cycle.
9. Children
The website and business enquiry form are not directed to children, and we do not knowingly request children’s data. Contact us if you believe a child submitted data. Any age threshold depends on the service, territory and lawful basis.
10. Changes and prior versions
Approved versions are immutable. Material changes to purposes, legal bases, providers, transfers, retention or rights are reviewed before activation. We identify the current version, retain prior-version evidence and provide prominent notice or obtain new consent where required.