1. Scope and data controller
This policy covers the nexviastudio.com corporate website, contact form, project-request flow and technical services on the same domain. External platforms such as WhatsApp, Instagram, LinkedIn and GitHub are governed by their own privacy terms.
The applications of products promoted on the site—such as Mercan Adisyon, Anılarım Güvende, Place Trove and Nexvia One—and systems developed for clients are outside this policy. Their distinct processing activities require separate privacy notices and policies.
The data controller under KVKK is NEXVIA Yazılım ve Tasarım Hizmetleri. Contact: [email protected] · +90 531 311 6892
2. What data do we collect?
| Category | Examples | Source |
|---|---|---|
| Identity | Full name | The contact or project-request form you complete |
| Contact | Email; optional telephone and company details | The contact or project-request form you complete |
| Request and transaction | Selected service; project goal and sub-goal; message content; communication and quote-process records | The contact or project-request form you complete |
| Transaction and network security | IP address and secret-keyed IP hash, request time and URL, referring page, browser/device and user-agent details, Cloudflare security signals and security events | Automatically when you access the website |
| Preferences | Language, theme, privacy-notice status and preloader-animation status | Cookie and browser storage |
3. Why and on what legal grounds do we process it?
- Reviewing and responding to questions, partnership and quote requests
- Managing the pre-contract process for the requested service
- Operating the website and applying language and theme preferences
- Preventing spam, attacks and abuse; maintaining system security and troubleshooting
- Meeting legal obligations and establishing, exercising or protecting a right
Requests and pre-contract communications rely on KVKK Art. 5/2(c) or Art. 5/2(f); website functions and security on Art. 5/2(f); legal obligations on Art. 5/2(ç); and records needed to establish, exercise or protect a right on Art. 5/2(e). Any non-essential analytics or marketing tool will remain off until a separate, active and withdrawable consent choice is provided.
4. Cookies and browser storage
Storage mechanisms that may be used by the site and its security provider are listed below. NEXVIA uses none of them to build advertising profiles.
| Name | Type | Purpose | Duration |
|---|---|---|---|
NEXVIA_LOCALE | First-party cookie | Remembering your selected language on the server | Up to 1 year |
nexvia-theme | localStorage | Remembering the light/dark theme preference | Until cleared in the browser |
nexvia_cerez | localStorage | Remembering that you have seen the privacy notice | Until cleared in the browser |
nexvia_preloader_seen | sessionStorage | Avoiding repeat preloader animation in the same tab | Until the tab/session closes |
cf_clearance, __cf_bm, cf_chl_* | Essential security cookie (Cloudflare) | Detecting bots or abuse and remembering the result of a security challenge, only when the relevant Cloudflare protection is triggered | __cf_bm: 30 minutes of inactivity; cf_clearance and cf_chl_*: the period required by the security configuration |
__Host-nexvia_admin_session | First-party cookie | Secure session for the authorised admin panel only | 30 minutes idle; 12 hours maximum |
nexvia_admin_csrf | sessionStorage | Protecting state-changing requests in the authorised admin panel against request forgery | Until the tab/session closes |
You can remove theme and notice records by clearing this site's browser data. You can remove the language cookie in browser settings; blocking required storage may prevent language or preference features from working as expected.
5. Who do we share it with?
Data may be transferred to the following recipient groups, only as required for the purpose and under restricted access controls:
- Authorised NEXVIA team members
- Cloudflare (DNS, content delivery and security) plus DigitalOcean and relevant infrastructure suppliers (hosting, database, object storage and backup)
- Legally authorised public bodies, judicial authorities and, in a dispute, authorised legal/advisory providers
Cloudflare's global network and overseas-based hosting/infrastructure suppliers can cause technical connection and hosted data to be processed outside Türkiye. Regular transfers require an adequacy decision or appropriate safeguard under KVKK Art. 9—including a standard contract; exceptional grounds are used only for genuinely occasional cases specifically covered by law.
6. External links
NEXVIA does not send your form data to WhatsApp, Instagram, LinkedIn or GitHub unless you click the relevant link. After you click, the platform may process your IP address, device/browser details and link information under its own terms; you should review those notices separately.
7. Retention and deletion
- Contact and quote requests that do not become a contract: up to 2 years after the last communication
- Contract, invoice and commercial/legal relationship records: for applicable statutory and limitation periods after the relationship ends; normally up to 10 years
- Security, access and IP-hash records: up to 1 year unless a security incident or legal requirement applies
- KVKK request and deletion-operation records: at least 3 years after completion or any longer applicable statutory period
- Cloudflare and hosting-provider operational/security logs: the necessary period in the service configuration and contract; copies controlled by NEXVIA are erased when their purpose ends
If the processing condition ends earlier, data is deleted, destroyed or anonymised without waiting for the maximum period. Backup copies are made inaccessible and securely erased within the recovery cycle.
8. Data security
Risk-appropriate technical and organisational measures include encryption in transit, role- and session-based access controls, multi-factor authentication for administrators, server-side input validation, rate limiting, logging and audit trails, network security, backups and restricted permissions. IP data is written to the application database as a secret-keyed one-way hash rather than in clear text; this pseudonymises but does not anonymise it.
9. Your rights and contact
You may exercise your KVKK Art. 11 rights to information, correction, deletion/destruction, notification to recipients, objection to automated decisions and compensation. The activity-specific notice explains the detailed application method, timing and required information.
Applications: [email protected]. You may use the same channel for urgent security or personal-data breach reports.
10. Children's data
The website and services are not directed at children. If you are a parent or guardian and believe a child's data was sent to us, contact us to request deletion.
11. Changes
If processing purposes, tools or recipient groups change, this policy will be updated before the change takes effect; a separate choice will be requested for any new activity requiring explicit consent. The current version and effective date are always published on this page.