Personal Data Processing Notice under the KVKK
Fidan Property Emlak Danışmanlığı Limited Şirketi
Date: 02.10.2026
This Personal Data Processing Notice (“Notice”) has been prepared under Article 10 of Turkish Personal Data Protection Law No. 6698 (“KVKK”) and the Communiqué on the Procedures and Principles to Be Followed in Fulfilling the Obligation to Inform (“Communiqué”). It transparently, clearly and fairly informs Data Subjects about processing purposes, legal bases, collection methods, recipients, actual retention periods and statutory rights relating to personal data collected through fidanproperty.com, contact/listing forms and physical, digital and operational channels by Fidan Property Emlak Danışmanlığı Limited Şirketi (the “Company”), acting as Data Controller.
ARTICLE 1 — DATA CONTROLLER AND CONTACT DETAILS
1.1. Your personal data is processed by the Company as Data Controller:
| Detail | Information |
|---|---|
| Legal name | Fidan Property Emlak Danışmanlığı Limited Şirketi |
| MERSİS number | 0387121494900001 |
| Trade registry | İstanbul Trade Registry Directorate — No. 291299-5 |
| Tax office / number | Bakırköy Tax Office — 3871214949 |
| Registered address | Ataköy 7-8-9-10. Kısım Mah. Çobançeşme E-5 Yan Yol Cad. B No:6/1 D:43 Bakırköy / İstanbul |
| [email protected] | |
| Registered Electronic Mail (KEP) | [email protected] |
| Telephone | +90 552 866 55 57 |
ARTICLE 2 — GENERAL PROCESSING PRINCIPLES
2.1. Under Article 4, personal data is processed lawfully and fairly, accurately and kept up to date where necessary, for specific, explicit and legitimate purposes, and in a relevant, limited and proportionate manner. Data unnecessary for achieving the purpose is not collected or processed.
2.2. Data is retained for the maximum period prescribed by laws/secondary legislation or required by legitimate processing purposes. Hypothetical future possibilities cannot justify arbitrary or indefinite retention. When the purpose and legal bases have fully ceased, data is deleted, destroyed or anonymised, on the Company’s initiative or upon request, according to legislation, its Personal Data Retention and Destruction Policy and periodic destruction schedule.
2.3. Informing is a unilateral obligation independent of explicit consent, commercial electronic-message approval and cookie choices. Presenting this Notice or acknowledging that it has been read can never constitute a combined or implied consent/marketing approval. Information and consent processes are strictly separate.
2.4. Property consultancy, listing review, portfolio monitoring and form requests cannot be conditional on optional analytics/marketing-cookie consent or acceptance of commercial electronic messages. Rejection is offered on completely equal terms, at the same interface level and without added difficulty.
ARTICLE 3 — DATA, PURPOSES AND LEGAL BASES BY ACTIVITY
Data categories, purposes, collection methods and specific legal bases under Article 5 are directly matched to the following activities:
3.1. Site visitors, server infrastructure and security records
Data: transaction-security data is separated by infrastructure layer:
- Local access/error records — Premier Data Center, İstanbul: source/destination IP, HTTP headers, access date/time, requested page URLs, referrer, browser/operating system, connection/HTTP status, transferred data size, server errors and CRM web-service (IIS) access records on dedicated web/CRM servers.
- Edge/cloud security — Cloudflare Free: without raw visitor-request archives (Logpush/Logpull), basic security telemetry, threat analysis, IP reputation/country information and aggregated security events visible for approximately 30–31 days, protecting against DDoS, malicious bots and cyber threats.
Collection: automatically during visits through Premier Data Center dedicated web-server hardware, IIS services and Cloudflare edge servers.
Purposes: technical operation and uninterrupted publication; web/CRM information security in İstanbul; detecting/fixing server errors; preventing DDoS, bots and unauthorised access; statutory system/traffic security.
Legal bases: Article 5/2-f, legitimate interests without harming fundamental rights/freedoms, for operation, network/server security and attack prevention; Article 5/2-ç, necessary fulfilment of legal obligations, where technical-record/log retention is mandatory under Law No. 5651 Article 2/1-j and related legislation.
3.2. Cookies and similar tracking technologies
Essential/functional: cookies required for navigation, session security, language and technical recording of Complianz choices are processed automatically without explicit consent under Articles 5/2-f (legitimate interests) and 5/2-c (performance of the service as requested).
Optional — Analytics, Marketing, External Media: GA4, Ads/DoubleClick, Meta Pixel, YouTube and CARTO/OpenStreetMap technologies are strictly blocked by default (opt-in). They never run or collect data without active, clear, specific and freely given Complianz consent. Online identifiers and Site behavioural data are processed exclusively on explicit consent under Article 5/1.
Management: users can withdraw consent or change choices at any time through the Site CMP, independently of browser settings. Types, purposes and configurations are transparently set out in the Cookie Policy.
3.3. Contact, listing and consultancy-request forms
Data: identity (name/surname); contact (telephone, country/country calling code, email where requested); customer transactions (message/request, listing of interest, portfolio number, budget and location preference); transaction security (submission IP, session ID, timestamp).
Collection: partly automatic, through forms manually completed and digitally submitted by users on fidanproperty.com.
Purposes: answering consultancy, information and portfolio-review requests; arranging presentations/viewings; detailed property information; pre-contract negotiations.
Legal bases: Article 5/2-c, processing necessary for establishing/performing a contract and directly relating to its parties; Article 5/2-f, legitimate interests in responding and establishing customer relationships.
Integration: form data is temporarily stored in the website database through CFDB7 and transferred by API to the dedicated CRM server (crm.fidanproperty.com) at Premier Data Center. Completing forms cannot be conditional on receiving commercial electronic messages.
3.4. Property customers, owners and contracts
Data: identity (name, Turkish identity number, passport/foreign identity number, signature); contact (service address, phone, business/personal email); financial (bank accounts, IBAN, billing/payment); property/legal transactions (title registration, block/parcel/independent-unit records, Property Viewing Document, brokerage/intermediation agreement, authorisation agreement, power-of-attorney copies and disputes).
Collection: non-automatic or partly automatic through preparation of physical/electronic contracts, viewing documents and official papers.
Purposes: concluding/performing purchase, sale and rental brokerage/consultancy contracts; tracking title registration/transfers; statutory property obligations, especially the Regulation on Real Estate Trade; invoicing/financial operations; evidence in potential disputes.
Legal bases: Article 5/2-c, contract establishment/performance; 5/2-ç, legal obligations; 5/2-e, establishment, exercise or protection of a right.
3.5. Marketing, promotion and commercial electronic messages
Data: contact details (phone/email); marketing (approvals, rejection notices, sending timestamps and portfolio interests).
Collection: electronic or written through website checkboxes or physical forms.
Purposes: sending current portfolios, investment opportunities, newsletters and campaigns by SMS, email or calls.
Legal bases: commercial electronic-message approval obtained to Message Management System (İYS) standards under Law No. 6563 on the Regulation of Electronic Commerce, and freely given explicit consent under Article 5/1.
Safeguards: approval is obtained separately from the Notice through unchecked boxes. Rejection is free and may be exercised anytime without a reason. All commercial messages stop within at most three business days of the Company or İYS receiving rejection.
3.6. Direct messaging — WhatsApp and Telegram
Data: contact/profile (telephone, username/profile name, photo); communications (messages, voice recordings, images, property documents); metadata (date, time, delivery status).
Collection: directly through the platform’s infrastructure when users voluntarily click wa.me or t.me links on the Site.
Purposes/legal bases: immediate answers, property consultancy and pre-contract negotiations under Article 5/2-c (contract establishment/performance) and 5/2-f (legitimate interests).
Free choice: no user is compelled to use these channels. Local alternatives — Site forms, Türkiye-based corporate email [email protected] and corporate landline/mobile +90 552 866 55 57 — are equally accessible.
ARTICLE 4 — PRINCIPLE OF NOT PROCESSING SPECIAL-CATEGORY DATA
4.1. The Company neither requests nor processes biometric data (fingerprints, facial recognition, retina etc.), genetic/health data, religion/sect, association/foundation/union membership or criminal convictions through the Site, forms, cookies or ordinary consultancy.
4.2. Special-category data voluntarily sent in messages, email or documents without an explicit statutory basis is immediately destroyed, not transferred to any recording system and not processed.
4.3. Except where authorities/legislation require it in exceptional title-registration, notarised power-of-attorney or inheritance-transfer cases, special-category data is not processed. Where mandatory, all Article 6 and Board-prescribed adequate safeguards are fully applied.
ARTICLE 5 — TRANSFERS ABROAD AND TRANSFER MECHANISMS
5.1. Transfers fully comply with Article 9 and the Regulation on the Procedures and Principles Regarding the Transfer of Personal Data Abroad. Standard Contracts used as safeguards are notified to the Personal Data Protection Authority within five business days of signing under Article 9/5; notification obligations are fully fulfilled.
5.2. Technical, operational and analytical transfers involve the following providers, purposes and grounds:
5.2.1. Optional cookies/external media — Google, Meta, YouTube, CARTO
- Google Ireland Ltd. / Google LLC (GA4, Ads, YouTube): performance measurement, targeted-ad analysis and external video. Technologies are off by default. Transfers occur exclusively upon freely given explicit category consent through the CMP under Article 9, or under statutory appropriate safeguards (Standard Contract).
- Meta Platforms Ireland Ltd. (Pixel): conversion measurement/targeting; transfers only upon explicit Marketing consent through the CMP under Article 9.
- CARTO / OpenStreetMap: interactive property-location maps; transfers to map servers only with External Media consent. Without it, no data is sent.
5.2.2. Security, CDN and media storage — Cloudflare Inc.
Cloudflare is essential from the initial Site load for TLS encryption, global DNS, DDoS protection and core cybersecurity checks.
Media sent through direct WhatsApp messaging — images, portfolio videos and property documents — is hosted in Cloudflare R2 secure object storage in Eastern Europe (EEUR). Uncontrolled direct access is blocked. The cross-border access layer uses serverless Cloudflare Workers, HMAC-SHA256 signed authorisation and time-limited access controls. Processing/storage relies on appropriate safeguards under Article 9/4, including Authority Standard Contract provisions and corporate undertakings.
5.2.3. Operational CRM — Groq Inc., timelines.ai, Telegram
The CRM (crm.fidanproperty.com) runs on dedicated servers at Premier Data Center in Türkiye.
For operational efficiency, AI-assisted customer-request/correspondence summarisation sends data to Groq Inc.’s secure API in the USA; WhatsApp correspondence/call records are integrated through timelines.ai; and authorised CRM logins use Telegram FZ-LLC for two-factor authentication (2FA) and security notifications. Transfers operate under Standard Contracts pursuant to Article 9, Board notifications under Article 9/5 and legally compliant technical security protocols.
ARTICLE 6 — RECIPIENT GROUPS AND PURPOSES
6.1. Under Articles 8 and 9 and data minimisation, transfers are limited to these recipients and purposes:
- Authorised public bodies: statutory notifications, investigations, court requests, title/cadastre procedures and Real Estate Trade Regulation inspections. Competent recipients include the Ministries of Environment, Urbanisation and Climate Change and of Trade, General Directorate of Land Registry and Cadastre, judicial/administrative courts and enforcement offices.
- Accountants, auditors, legal advisers: accounting/tax duties, independent audits, protecting rights and handling disputes; lawyers, independent accountants/financial advisers and certified public accountants bound by confidentiality.
- Property transaction parties: buyers, sellers, tenants and representatives, restricted to minimum identity, title and contact information essential to completing sale, purchase or rental under brokerage/consultancy contracts.
- Infrastructure/service providers (processors): dedicated web/email/CRM hosting at Premier Data Center, İstanbul; CRM development, maintenance and technical management by Hostmaden Bilişim Teknolojileri; secure Türkiye-based corporate email through Hostmaden; Cloudflare CDN/DNS and R2 secure storage in Eastern Europe/EEUR; Groq text-summary API, timelines.ai messaging and Telegram 2FA notifications.
- Optional analytics/advertising/external-media partners: Google Ireland Ltd. / Google LLC, Meta Platforms Ireland Ltd., YouTube and CARTO, only with explicit CMP consent on the Site.
ARTICLE 7 — DATA SECURITY AND PROCESSORS
7.1. Under Article 12, all necessary technical/administrative measures prevent unlawful processing/access and ensure preservation:
- Site contact/request forms transfer to CRM over HTTPS and secret-token-protected API endpoints.
- R2 direct-messaging media is closed to public internet access and provided only to authorised CRM users through temporary HMAC-SHA256 signed URLs valid for at most two hours.
- Access is limited by role-based authorisation, least privilege and strong passwords/2FA.
7.2. Contracts with Premier Data Center, Hostmaden and other providers include binding security provisions under Article 12/2. Processors must follow only written Company instructions, preserve confidentiality/security and securely return or destroy all data at termination.
7.3. Integration/API authentication keys are never kept in general source code. They are held in encrypted environment variables and secure server configurations and rotated periodically.
ARTICLE 8 — BREACH NOTIFICATION
8.1. If personal data is found to have been unlawfully obtained by others, the Company notifies the Board without delay and within 72 hours of becoming aware.
8.2. Affected Data Subjects are also notified without delay by legally compliant methods, including likely consequences and measures taken.
ARTICLE 9 — ACTUAL RETENTION AND DESTRUCTION
Under Article 4/2-d, data minimisation and time-limitation principles prohibit indefinite retention. Periods below align with actual infrastructure, log rotation and applicable legislation:
| Activity / data | Infrastructure / location | Retention and destruction |
|---|---|---|
| Site access/error logs | Web server, Premier Data Center, İstanbul | Account-level archives: minimum one, maximum two years under Law No. 5651 Articles 2/1-j and 6, with log rotation/periodic cleaning; securely deleted in the destruction cycle upon expiry. |
| CRM web-service (IIS) access logs | CRM server, Premier Data Center, İstanbul | Maximum two years for security, unauthorised-access checks and stability, with automatic rotation; expired logs permanently deleted periodically. |
| CRM operating-system/security logs | Windows Server security records | Circular architecture with a 20 MB limit: approximately a few days to two weeks depending on event volume; newer entries automatically overwrite older ones. |
| CRM in-application transactions | MS SQL CRM database | Indefinite logs prohibited. To document customer history and prove property disputes, retained during the underlying relationship and at most ten years after contractual/commercial termination, in line with Turkish Code of Obligations/Commercial Code limitation periods; then destroyed. |
| Cloudflare security/analytics | Free Plan dashboard | No raw request records; events/analytics visible at most 30–31 days, then automatically deleted by Cloudflare. |
| Website forms (CFDB7) | WordPress database, Premier Data Center | After successful CRM transfer, held in the web database at most six months for minimisation, then automatically/manually cleaned. |
| WhatsApp media: images, videos, documents | Cloudflare R2, EEUR | Automatically deleted 180 days after upload under lifecycle rules. Correspondence text/voice recordings remain in CRM for transaction tracking during the contract. |
| Leads without contracts | CRM, Premier Data Center | Requests/contact records not resulting in a contractual/commercial relationship: maximum two years from last active contact. |
| Brokerage/intermediation/portfolio records | Physical archive and CRM | Ten years from relationship termination under the Real Estate Trade Regulation and Commercial Code/Code of Obligations limitation provisions. |
| Commercial-message approvals/rejections | CRM and İYS | Three years from expiry of approval or exercise of rejection, under legislation. |
| Cookie consent/preferences | Complianz CMP / database | Maximum three years from consent or withdrawal to fulfil the burden of proof. |
| Destruction and Data Subject applications | Information-security archive | Deletion/destruction actions and application/response records: three years from the action for audit purposes. |
9.12. Log rotation: indefinite/uncertain storage is prevented. Web, IIS and application logs use periodic archiving, size-based circular overwriting and automatic destruction/cleaning at maximum expiry. No log remains archived beyond its legal retention period.
9.13. Periodic destruction: every three months, the Company securely deletes, destroys or anonymises data whose retention has expired or processing basis ceased, under the Regulation on the Deletion, Destruction or Anonymisation of Personal Data.
ARTICLE 10 — STATUTORY RIGHTS
10.1. Under Article 11, Data Subjects may apply to the Company to:
- Learn whether their personal data is processed.
- Request information if it has been processed.
- Learn purposes and whether data is used accordingly.
- Learn third-party recipients in Türkiye or abroad.
- Request correction of incomplete/inaccurate data.
- Request deletion/destruction under Article 7.
- Request notification of correction/deletion/destruction to recipients.
- Object to a detrimental result arising exclusively from automated analysis.
- Seek compensation for harm caused by unlawful processing.
ARTICLE 11 — APPLICATION PROCEDURE
11.1. Under Article 13 and the application Communiqué, requests may be submitted:
- Personally with identity-verifying documents and a wet-signed petition, or through a notary, to Ataköy 7-8-9-10. Kısım Mah. Çobançeşme E-5 Yan Yol Cad. B No:6/1 D:43 Bakırköy / İstanbul.
- To the Company’s KEP address: [email protected].
- To [email protected] from an address registered in the Company’s system, using a secure electronic/mobile signature.
11.2. Required information: name, surname, signature, Turkish identity number (passport number for foreigners), residential/business address for service, notification email/telephone and the request.
11.3. The Company resolves requests as soon as possible, within at most 30 days, free of charge according to their nature. Reasoned replies are communicated in a documentable written/electronic form. If additional costs arise, the Board’s tariff may apply.
ARTICLE 12 — EFFECTIVE DATE AND UPDATES
12.1. This Notice entered into force on 02.10.2026, the date of publication on fidanproperty.com.
12.2. It is revised in response to legislation, judicial/Board decisions, infrastructure updates or developments in processing. Updated text takes effect upon website publication.
Data Controller: Fidan Property Emlak Danışmanlığı Limited Şirketi