Skip to content

Data protection

Effective date:
11 September 2026
Last updated:

How Fellow Data approaches data protection under Türkiye's Personal Data Protection Law No. 6698 (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR).

Our approach

Fellow Data maintains data-processing practices designed to comply with applicable data-protection requirements, including Türkiye's Personal Data Protection Law No. 6698 (KVKK) and, where applicable, the EU General Data Protection Regulation (GDPR).

Specific obligations depend on the relevant entity, jurisdiction, processing activity and contractual arrangement. This page summarises our approach; our Privacy policy describes what we collect and why.

GDPR

Where the GDPR applies, our processing follows its principles:

  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

We identify a legal basis for each processing activity rather than one basis for everything. The bases we rely on are listed in the Privacy policy.

Türkiye: KVKK

Türkiye's Personal Data Protection Law No. 6698 (KVKK) was adopted on 24 March 2016 and published in the Official Gazette on 7 April 2016. It is supervised by the Personal Data Protection Authority. Where KVKK applies, Fellow Data processes personal data in line with its general principles and informs data subjects as the law requires.

We collect personal data electronically, through our website, its forms and email. Under Article 5 of KVKK, we process it where it is necessary to set up or perform a contract (Article 5(2)(c)), to meet a legal obligation (Article 5(2)(ç)), to establish, exercise or protect a right (Article 5(2)(e)), or for our legitimate interests (Article 5(2)(f)). We ask for your explicit consent (Article 5(1)) before using optional cookies.

Under Article 11 of KVKK, data subjects may:

  • Learn whether their personal data is processed
  • Request information about the processing
  • Learn the purpose of the processing and whether the data is used for that purpose
  • Know the third parties, in Türkiye or abroad, to whom the data is transferred
  • Request correction of incomplete or inaccurate data
  • Request deletion or destruction of the data under the conditions set out in the law
  • Request that third parties who received the data are told about a correction or deletion
  • Object to a result against them that arises solely from automated analysis of the data
  • Claim compensation for damage caused by unlawful processing

International transfers

Our website and email are hosted on servers in Frankfurt, Germany (EU), and our team works from Türkiye. Our products may also use infrastructure, service providers and technology partners in other countries.

Where personal data is transferred internationally, Fellow Data will implement appropriate safeguards required by applicable data-protection law. The European Commission has not adopted an adequacy decision for Türkiye. Türkiye's rules on transfers abroad were amended in 2024 and now include mechanisms such as standard contracts; under the GDPR, mechanisms include adequacy decisions and standard contractual clauses.

Data subject requests

To exercise a right, email info@fellowdata.com with the subject "Data subject request". Please include:

  • Your name and contact details
  • The right you want to exercise
  • The personal data or processing your request concerns

We may need to verify your identity before we respond. We reply within the time the applicable law requires: generally one month under the GDPR, which can be extended in some cases, and 30 days under KVKK.

Data retention

We keep personal data only as long as it is needed. Our retention periods are listed in our Privacy policy. They depend on:

  • The purpose for which it was collected
  • Our contracts with customers and partners
  • Legal obligations, such as accounting and tax records
  • Security requirements
  • The resolution of disputes
  • Operational requirements

When personal data is no longer needed, we delete, destroy or anonymise it.

Security

We protect personal data with technical and organisational measures appropriate to the risk, such as encryption in transit and access controls. Read more on our Security page.

Processing for customers

When Fellow Data processes personal data on behalf of a customer through its products, the customer usually acts as the data controller and Fellow Data as the data processor. Each party's role and obligations are set out in a written agreement, such as a data processing agreement.

Contact

Questions about data protection: info@fellowdata.com.

Fellowdata Teknoloji Limited Şirketi, Maslak Mah. Ahi Evran Cad. No: 11/2, 34485 Sarıyer/İstanbul, Türkiye.