Privacy Policy
How we collect, use and protect personal data, and the rights you have over it under the GDPR and the Turkish Personal Data Protection Law No. 6698 (KVKK).
Last updated: 25 July 2026Who We Are
Horizentis Technology A.S. operates this website and is the data controller for the personal data described in this policy. In this document "we", "us" and "our" refer to Horizentis Technology A.S., and "you" refers to any visitor to https://www.horizentis.com.
We are established in Türkiye, so our processing is governed by the Personal Data Protection Law No. 6698 (KVKK). Where we process the personal data of visitors located in the European Economic Area, the General Data Protection Regulation (EU) 2016/679 (GDPR) also applies. This policy is written to satisfy both.
Data We Process
This website does not require you to create an account, and nothing on it is behind a sign-up. Most visitors can browse the entire site without giving us any information about themselves, and the site carries no public form. The data we do process falls into three groups.
Technical and Connection Data
Our web servers keep standard access logs. These record your IP address, the date and time of the request, the page or file requested, the HTTP status returned, the referring page and your browser user agent string. This happens automatically for every request and is a normal part of operating a web server securely.
Usage and Measurement Data
We use Google Analytics to understand which pages are read, which products draw interest and which languages are in use. This produces aggregate statistics about page paths, approximate location at city or country level, device type, browser and referral source. We do not use this data to build advertising profiles, and we run no advertising network on this site.
Data You Send Us Directly
If you contact us by email, telephone or WhatsApp using the details published on our contact page, we process whatever you choose to include: typically your name, your company, your contact details and the content of your enquiry. We only ask for what is needed to answer you.
Data We Do Not Collect
We do not process special categories of personal data, we do not knowingly collect data from children, we do not sell personal data to anyone, and we do not run advertising, remarketing or cross-site tracking technologies.
Purposes and Legal Grounds
We process personal data only for the purposes listed below, and only where a legal ground under KVKK Article 5 and GDPR Article 6 applies.
| Purpose | Legal Ground |
|---|---|
| Delivering the website, its language versions and its downloads to your browser | Legitimate interest, KVKK Art. 5/2-f and GDPR Art. 6(1)(f) |
| Keeping the site secure, detecting abuse and diagnosing faults from server logs | Legitimate interest, KVKK Art. 5/2-f and GDPR Art. 6(1)(f) |
| Measuring how the site is used so we can improve its content and structure | Consent, KVKK Art. 5/1 and GDPR Art. 6(1)(a) |
| Answering enquiries you send us about products, integration or support | Legitimate interest and, where a sale follows, performance of a contract, GDPR Art. 6(1)(b) |
| Meeting our accounting, tax and other statutory record-keeping duties | Legal obligation, KVKK Art. 5/2-ç and GDPR Art. 6(1)(c) |
Cookies and Similar Technologies
Cookies are small text files stored on your device by your browser. We use a small number of them, plus one browser storage entry. We do not use advertising cookies of any kind.
| Cookie Name | Category | Purpose | Duration |
|---|---|---|---|
theme | Essential, browser local storage | Remembers whether you chose the light or dark appearance | Until you clear it |
.AspNetCore.Antiforgery.* | Essential | Protects form submissions against cross-site request forgery | Session |
.AspNetCore.Identity.* | Essential | Keeps administrators signed in to the private management area, never set for ordinary visitors | Session or until sign-out |
_ga, _ga_* | Analytics, Google Analytics | Distinguishes visitors and sessions to produce aggregate usage statistics | Up to 2 years |
Essential cookies are required for the site to work and cannot be switched off from within the site. Analytics cookies are optional. You can block or delete any of them through your browser settings, and you can opt out of Google Analytics entirely using the browser add-on published by Google at tools.google.com/dlpage/gaoptout. Blocking essential cookies may stop parts of the site from working correctly.
Your language is selected from the address of the site you visit rather than from a cookie, so no identifier is stored for that.
Sharing and International Transfers
We do not sell, rent or trade personal data. We share it only with the service providers needed to run this website, and with public authorities where the law requires it.
| Recipient | Role | Data Involved |
|---|---|---|
| Hosting provider | Runs the servers this site is delivered from | Server log data |
| Google Analytics | Aggregate usage measurement | Pseudonymous identifiers, page paths, approximate location |
| Google Maps | Renders the embedded map on our contact page | IP address and browser data, sent to Google when that page loads |
Google processes data on servers outside Türkiye and outside the European Economic Area. Those transfers rely on the European Commission Standard Contractual Clauses and, for transfers from Türkiye, on the transfer mechanisms set out in KVKK Article 9. Google's own privacy notice is at policies.google.com/privacy.
Our website links to third party sites, including the sites of distributors and partners. Once you follow such a link, the privacy policy of that site applies and we have no control over it.
How Long We Keep Data
We keep personal data only as long as the purpose it was collected for requires, and then delete or anonymise it.
- Server access logs are retained for up to 12 months for security and troubleshooting.
- Google Analytics data is retained for 14 months, after which it is deleted by Google.
- Business correspondence is kept for the duration of the commercial relationship and for the statutory retention periods that follow it, generally 10 years under Turkish commercial and tax law.
- Anything you ask us to delete is removed within 30 days unless we are legally required to retain it.
Security
All traffic to this site is encrypted with TLS. Access to the systems that hold personal data is restricted to the individuals who need it, protected by strong authentication, and reviewed regularly. We keep our platform patched and we log administrative access.
No system can be guaranteed absolutely secure. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, you, within the deadlines set by KVKK and the GDPR.
Your Rights
Under KVKK Article 11 and Chapter III of the GDPR you may exercise the following rights in relation to your personal data.
- Learn whether we process your personal data and, if so, request access to it.
- Ask for information on the purpose of the processing and whether the data is used accordingly.
- Know the third parties in Türkiye or abroad to whom the data has been transferred.
- Request that incomplete or inaccurate data be corrected.
- Request erasure or destruction of your data where the grounds for processing no longer exist.
- Ask that any correction, erasure or destruction be communicated to the parties the data was transferred to.
- Object to a decision that produces an adverse result for you and is based solely on automated analysis. We do not carry out such automated decision making.
- Claim compensation for damage arising from unlawful processing.
- Where the GDPR applies, additionally request restriction of processing, receive your data in a portable format, object to processing based on legitimate interest, and withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
Making a Request
Send your request to info@horizentis.com, or in writing to the address given at the top of this policy. Please describe the right you wish to exercise and include enough detail for us to identify you. We do not charge for this.
We answer within 30 days under KVKK Article 13 and within one month under GDPR Article 12. If a request is unusually complex we may extend that period and will tell you why before the original deadline passes.
If you are not satisfied with our response you may complain to the Turkish Personal Data Protection Authority (KVKK, kvkk.gov.tr) or, if you are in the European Economic Area, to the supervisory authority of the country where you live or work.
Changes to This Policy
We review this policy whenever our products, our tooling or the applicable law changes, and we publish the revised version on this page with a new date. Material changes will be highlighted on the site. The version in force is always the one shown here.
Last updated: 25 July 2026.