01Data Controller
Under KVKK Art. 10 we share the following information:
- Brand
- Orchesta
- [email protected]
- Web
- orchesta.io
A registered legal entity is not yet in place. This notice will be updated with full registration details (entity name, registered address, tax number, MERSIS registry) once those are established.
02Categories of Personal Data
orchesta.io is a static informational website with no account, sign-up or data-storing forms. We process only:
- Transaction security
- IP address, browser/device info, requested pages and timestamps — recorded in server and Cloudflare access logs.
- Usage data
- Aggregate analytics via Google Analytics, collected only after explicit consent. IP addresses are anonymised.
- Communication
- If you email us, your email address and message content — processed only because you chose to contact us.
We do not process special categories of personal data (health, biometric, religious belief, union membership, etc.).
03Purposes of Processing
- Operating and securing the website (including blocking malicious traffic)
- Understanding aggregate usage to improve the site — only with your consent
- Responding to messages you send us by email
- Complying with legal obligations and lawful requests from authorities
04Legal Basis
Your personal data is processed under KVKK Art. 5 on the following grounds:
- Legitimate interest (KVKK Art. 5/2-f) — site security and technical operation
- Explicit consent (KVKK Art. 5/1) — analytics, granted via the cookie banner
- Establishment / protection of a right (KVKK Art. 5/2-e) — handling email correspondence you initiate
- Legal obligation (KVKK Art. 5/2-ç) — responding to requests from authorities
05Method of Collection
Access logs are collected automatically by our server and by Cloudflare as you browse. Analytics data is collected through Google Analytics tags that load only after you accept the cookie banner. Communication data is collected only when you email us.
06Transfers of Data
The site is self-hosted on our own server. Data is shared, strictly to operate and secure the service, with:
- Cloudflare
- DNS, CDN and security / DDoS protection. Global infrastructure.
- Google Analytics
- Aggregate analytics by Google LLC (United States) — loaded only after consent.
These providers operate outside Türkiye, so data may be transferred abroad under GDPR-compliant safeguards consistent with KVKK Art. 9. Data may also be shared with authorised public bodies where legally required.
07Data Subject Rights (KVKK Art. 11)
Under KVKK Art. 11 you have the right to:
- Learn whether your personal data is processed
- Request information about the processing
- Learn the purpose and whether data is used in accordance with it
- Know the third parties to whom data has been transferred
- Request correction of incomplete or inaccurate data
- Request erasure / destruction under KVKK Art. 7
- Request notification of correction / erasure to the recipients of the data
- Object to outcomes against you produced solely by automated processing
- Claim compensation for damages from unlawful processing
08How to Apply
Under KVKK Art. 13 and the "Communiqué on Application Procedures to Data Controllers", you may exercise your rights by writing to [email protected].
Your application must clearly state your identity and request. We respond in writing or electronically within 30 days at the latest. Applications are generally free; if the process requires a separate cost, the fee set by the Personal Data Protection Authority may apply.
If your application is rejected or its response is inadequate, you may file a complaint with the Personal Data Protection Board.
09Retention
- Server & access logs: short-term, rotated out typically within 30 days.
- Analytics data: retained by Google Analytics per its configured window (default 14 months).
- Email correspondence: kept as long as needed to handle your request and for reasonable follow-up.
Records subject to a legal retention requirement are kept for the period prescribed by the relevant legislation and destroyed at the end of that period.
10Changes
This notice may be updated as needed. The current version is always on this page.