Privacy Policy
Last updated: 25 August 2026
This Privacy Policy explains how Straitcore Teknoloji Anonim Şirketi ("Straitcore", "we", "us") processes personal data in connection with its corporate website at straitcore.com. It is written primarily under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and, for visitors located in the European Economic Area, under the General Data Protection Regulation ("GDPR"). This website is a static corporate presentation site: it sets no cookies, runs no analytics, and contains no forms. It covers the straitcore.com root address only; our products, including those running on subdomains of straitcore.com, publish their own legal documents. The short version is that browsing these pages leaves us with almost nothing about you, and the sections below set out exactly what does and does not happen with your data.
1. Data Controller
The data controller responsible for the processing described in this policy is the legal entity below. Any question, request or complaint concerning this policy can be addressed to the contact points listed here.
- Legal entity
- Straitcore Teknoloji Anonim Şirketi (STRAITCORE TEKNOLOJİ A.Ş.)
- Address
- Fulya Mah. Büyükdere Cad. Quasar No: 76, İç Kapı No: 188, Şişli / İstanbul 34394, Türkiye
- Tax office & number
- Mecidiyeköy Tax Office / 7811154317
- General contact
- hello@straitcore.com
- Billing
- fatura@straitcore.com
- Website
- straitcore.com
2. Scope of This Policy
This policy applies only to the straitcore.com root address, our corporate website. This site presents who we are, what we build and how to reach us. It does not sell anything, does not host an application, and does not create user accounts. Products that we run on subdomains of straitcore.com, such as zoneflow.straitcore.com and shelfstock.straitcore.com, are separate applications with their own interfaces and their own legal documents, and they fall outside the scope of this policy.
Our products also run on their own separate domains and are governed by their own legal documents. Straitcore operates Adspotz (adspotz.com), Horecas (horecas.com), TripaWise (tripawise.com) and OtOrder (otorder.com), among others. Subscription sales, payment processing and the handling of customer and end-user data take place on those platforms, under the legal documents published there, which include at least a privacy notice and terms of service. Nothing in this policy describes or limits how personal data is processed within those products.
There is one narrow overlap. If you write to hello@straitcore.com or fatura@straitcore.com about one of our products, an invoice or a possible engagement, that message arrives in our corporate mailbox, and the message itself is handled as described in Section 4 of this policy. The customer account, order and payment data held inside the product platform is a separate matter and remains governed by the privacy notice published on that product's own website. This policy never becomes the notice for a product simply because you emailed us about it.
This site also links to our profiles on LinkedIn and Instagram. Once you follow an external link, you are on a third-party platform and that platform's own privacy policy applies. We have no control over, and accept no responsibility for, the data practices of those platforms.
3. What This Website Does Not Collect
We consider the absence of tracking to be a feature of this site rather than an omission, so we state it plainly and in the affirmative. On the straitcore.com root address:
- No cookies are used. We set no cookies of any kind, first-party or third-party. This is why you see no cookie banner or consent prompt on this site.
- No analytics or tracking tools are used. There is no Google Analytics, Google Tag Manager, Meta/Facebook Pixel, Plausible, PostHog, Hotjar or any comparable measurement, heatmap or session-recording service.
- No browser storage is used. We do not write to localStorage, sessionStorage or IndexedDB, and we do not use device fingerprinting.
- No forms exist. There is no contact form, newsletter form, quote request or survey. Nothing on this site submits data to us.
- No accounts, no payments. There is no registration, login, subscription checkout or e-commerce function on this website.
- Fonts and assets are served from our own servers. The site does not load fonts, scripts or images from external content delivery networks, so displaying these pages does not cause your browser to contact third-party servers for us.
- No advertising, profiling or automated decision-making takes place on this site, and we do not sell, rent or trade personal data.
4. If You Write to Us by Email
The only way this website invites you to contact us is a plain mailto link to hello@straitcore.com, with fatura@straitcore.com available for billing matters. If you choose to write to us, your message reaches our corporate mailbox and we process the personal data it contains.
The categories of data involved are those you choose to include: your name and, where you provide them, your job title and organisation; your email address; the content of your message and of any attachments; and the technical details that accompany every email, such as the date, time and message headers.
We process this data for the following purposes: to read, evaluate and answer your message; to conduct pre-contractual discussions where you are enquiring about our products or a possible business relationship; to keep an accurate record of our correspondence; and, where relevant, to establish, exercise or defend legal claims.
The legal basis is our legitimate interest in responding to communications addressed to us and in managing our business relationships, under Article 5(2)(f) of the KVKK and Article 6(1)(f) of the GDPR. Where the correspondence concerns the conclusion or performance of a contract with you, the basis is Article 5(2)(c) of the KVKK, the sub-paragraph on processing directly related to the conclusion or performance of a contract, and Article 6(1)(b) of the GDPR.
Because you control the content of your message, please send only the information relevant to your request. We ask that you do not send special categories of personal data (such as health, biometric, religious or trade-union data) or third-party personal data that is not necessary for us to answer you.
5. Server Access Logs
Like every web server, the server that delivers this site keeps standard access records. This is a technical necessity of operating a website securely; it is not a tracking mechanism and it is not linked to any analytics system.
For each request, the server may record: the IP address the request came from, the date and time, the requested address, the HTTP response code, the volume of data transferred, the browser and operating system identifier (user-agent), and the referring address where the browser supplies one.
These records are used only to keep the service available and secure: detecting and investigating attacks, abuse and unusual traffic; diagnosing errors; and capacity planning. We do not use access logs to build visitor profiles, we do not combine them with other data sets, and we do not attempt to identify individual visitors from them, except where this becomes necessary to investigate a concrete security incident or to comply with a legally binding request.
The legal basis is our legitimate interest in the security and continuity of our systems, under Article 5(2)(f) of the KVKK and Article 6(1)(f) of the GDPR. Where the retention or disclosure of these records is required by law, two different sub-paragraphs of the KVKK apply: Article 5(2)(a), where the processing is expressly provided for in legislation, and Article 5(2)(ç), the sub-paragraph on processing that is mandatory for the data controller to fulfil a legal obligation, where we are compelled to disclose the records. For visitors located in the European Economic Area, the corresponding basis is Article 6(1)(c) of the GDPR.
6. Retention Periods
We keep personal data only for as long as the purpose that justified collecting it remains valid, and then for any additional period imposed by law. The periods we apply are set out below.
- Server access logs
- Maximum 12 months from the date of the record, after which they are deleted or overwritten in the ordinary course of log rotation.
- Email correspondence
- For the duration of the exchange and up to 2 years after the last message, unless the correspondence relates to a contract, a claim or a legal obligation.
- Email correspondence connected to a contract or claim
- For the term of the relationship and thereafter for the applicable statutory limitation and record-keeping periods under Turkish law. This row covers the messages in our mailbox only; the account, order and payment records held inside a product platform are governed by that product's own privacy notice.
- Data subject requests and our responses
- Up to 3 years, so that we can demonstrate that requests were handled properly.
7. Disclosure and Transfers
We do not sell, rent or trade personal data, and we do not share it with advertising networks or data brokers. Personal data connected with this website is disclosed only in the limited situations below.
Service providers acting on our instructions. The company that hosts this website and provides the underlying infrastructure has access to the server on which access logs are generated, and the provider that operates our corporate email service processes messages sent to us. Both act as data processors on our behalf, under contractual confidentiality and security obligations, and are not permitted to use the data for their own purposes.
Professional advisers. Where necessary, our legal and financial advisers may access relevant correspondence in order to establish, exercise or defend a legal claim, subject to professional confidentiality.
Competent authorities. We disclose data to courts, prosecutors, regulators or other public authorities where we are legally obliged to do so, and we limit any such disclosure to what the request actually requires.
International transfers. Where a service provider processes data on servers located outside Türkiye, the transfer is carried out in accordance with Article 9 of the KVKK. For personal data of visitors located in the European Economic Area, any transfer to a third country is made subject to the safeguards required by Chapter V of the GDPR.
8. Security Measures
We apply technical and organisational measures appropriate to the very limited scope of the processing described here.
- The site is served exclusively over an encrypted HTTPS/TLS connection.
- The site is a static export with no database, no application backend and no user input path, which removes the most common categories of web vulnerability by design.
- Administrative access to the server is restricted to authorised personnel and uses key-based authentication rather than shared passwords.
- Access logs are stored on the server with restricted access, are not exported to third-party analytics platforms, and are deleted on the schedule stated in Section 6.
- Corporate email accounts are protected with strong authentication, and correspondence is accessible only to the personnel who need it to answer you.
- We keep our server software and dependencies patched and review our configuration periodically.
9. Data Breach Notification and Residual Risk
If a personal data breach occurs despite these measures, we investigate it without delay and take steps to contain it. We notify the Turkish Personal Data Protection Authority as soon as possible and in any event within seventy-two hours of becoming aware of the breach, in line with Article 12(5) of the KVKK and the decisions of the Personal Data Protection Board, and we inform the affected persons where the breach is likely to create a risk for them. For visitors located in the European Economic Area, notification is made in accordance with Articles 33 and 34 of the GDPR.
No method of transmission or storage is completely secure, and email in particular is not an inherently confidential channel. Please do not send credentials, financial account details or other sensitive information to us by unencrypted email; if a matter requires it, write to us first and we will agree a secure method.
10. Children's Privacy
This website is addressed to business audiences: companies, partners, candidates and professional visitors. It is not directed at children, and it offers no function that would invite a child to submit information.
We do not knowingly process the personal data of children. If a parent or legal guardian believes that a child has sent personal data to one of our email addresses, please contact us at hello@straitcore.com and we will delete the message and any data it contains without undue delay.
11. Your Rights
Your rights come from two sources. If you are located in the European Economic Area, the GDPR gives you the rights of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing based on legitimate interests; our GDPR notice at straitcore.com/gdpr/ describes them in more detail. The rights listed below are those granted by Article 11 of the KVKK, and they are available to you regardless of where you are located.
Under Article 11 of the KVKK, you have the right to:
- learn whether your personal data is being processed and, if so, request information about that processing;
- learn the purpose of the processing and whether the data is used in accordance with that purpose;
- know the third parties, in Türkiye or abroad, to whom your personal data has been transferred;
- request correction of incomplete or inaccurate data, and request that the correction be notified to the third parties to whom the data was transferred;
- request erasure or destruction of your personal data where the grounds for processing have ceased to exist, and request that this be notified to those third parties;
- object to a result produced solely by automated analysis of your data that is to your detriment;
- claim compensation for damage arising from unlawful processing.
12. How to Exercise Your Rights
To exercise any of these rights, write to hello@straitcore.com from the email address the request concerns, or send a signed written request to our registered address given in Section 1. Please describe your request clearly so that we can act on it. We may ask for information reasonably necessary to confirm your identity before we respond, in order to avoid disclosing data to the wrong person.
The Communiqué on the Procedures and Principles of Application to the Data Controller also recognises other application channels, including a registered electronic mail (KEP) address, a secure electronic signature, a mobile signature, and an email address that you have previously notified to us and that is already recorded in our systems. We do not operate a KEP address or a signature-based application channel for this website, so the routes actually available here are the email address and the written application described above; a request that reaches us by either route is treated as a valid application under the KVKK.
We respond within 30 days at the latest, in accordance with Article 13 of the KVKK, and within one month for requests made under the GDPR. Our responses are provided free of charge unless the request requires an exceptional cost, in which case the tariff set by the Personal Data Protection Board may be applied.
Under Article 14 of the KVKK, a complaint to the Turkish Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu) is possible only after you have first applied to us: the application to the data controller must be exhausted before the Board will examine a complaint. If we reject your request, if our answer is insufficient, or if we do not reply within thirty days, you may lodge a complaint within thirty days of learning of our response and, in any event, within sixty days of the date of your application to us. These periods are strict, so a complaint brought after they have run may not be examined.
The GDPR imposes no such precondition. If you are located in the European Economic Area, you may lodge a complaint with the supervisory authority of your country of residence, of your place of work, or of the place of the alleged infringement, at any time and without contacting us first, and you may also seek a judicial remedy. We would still prefer that you write to us first, because that is usually the fastest way to put a problem right.
13. Changes to This Policy and Contact
We may update this policy when our practices, our infrastructure or the applicable law change. The version published on this page is always the version currently in force, and any revision takes effect from the moment it is published here. The date shown at the top of this page is the date of the version currently in force. If a change materially affects how we handle personal data, we will make that clear on this page rather than revising the text silently. We recommend reviewing this page when you next contact us.
For any question about this policy or about how we handle personal data on this website, write to us at hello@straitcore.com. Billing-related correspondence should be sent to fatura@straitcore.com. Written requests may also be sent to Straitcore Teknoloji Anonim Şirketi, Fulya Mah. Büyükdere Cad. Quasar No: 76, İç Kapı No: 188, Şişli / İstanbul 34394, Türkiye.
This policy is published at straitcore.com/privacy/. The other legal documents for this website sit alongside it: the Terms of Service at straitcore.com/terms/, the Cookie Policy at straitcore.com/cookies/ and the GDPR notice at straitcore.com/gdpr/.
For matters concerning Adspotz, Horecas, TripaWise, OtOrder or any other Straitcore product, please refer to the privacy notice published on that product's own website, since the processing carried out there is not covered by this document.