Privacy Policy
This Privacy Policy explains how Nezni collects, uses, protects and shares personal data when you visit nezni.com, contact our team or submit information about a business or custom bag project.
Privacy Policy contents
- 01Who We Are & Scope
- 02Data We Collect
- 03How We Collect Data
- 04Purposes & Legal Bases
- 05Forms & File Uploads
- 06Security & Turnstile
- 07Cookies & Tracking
- 08Sharing Personal Data
- 09International Transfers
- 10Retention & Security
- 11Your Privacy Rights
- 12Third-Party Services
- 13Changes to This Policy
- 14Contact Us
Who We Are & Scope of This Policy
The data controller for nezni.com is NEZNI TEKSTIL KUY. AMB. SAN. VE TIC. LTD. STI. (referred to in this policy as “Nezni”, “we”, “us” or “our”). Our head office is located at Inonu Mah. 415. Sok. No: 13/A, Bagcilar, Istanbul, Turkey.
This Privacy Policy applies to personal data processed through nezni.com, including our general contact form, Request a Quote form, product and project enquiries, reference-file uploads, email communications, phone communications and website links that allow you to start a WhatsApp conversation with our team.
For the purposes of Turkey’s Personal Data Protection Law No. 6698 (“KVKK”), Nezni acts as the data controller for personal data for which it determines the purposes and means of processing. Where the EU General Data Protection Regulation (“GDPR”), UK GDPR or another applicable privacy law applies, Nezni acts in the corresponding controller role unless otherwise stated.
Personal Data We Collect
The personal data we collect depends on how you interact with Nezni. We aim to collect only information reasonably necessary for the relevant business, communication, security or legal purpose.
Identity & Contact Data
Full name, company name, business email address, country, phone number or WhatsApp number, and other contact details you choose to provide.
Project & Enquiry Data
Product category, estimated quantity, material or construction requirements, branding details, project notes, requested delivery information and other enquiry content.
Files & Correspondence
Artwork, logos, reference images or documents uploaded with a quotation request, plus messages and business correspondence exchanged with our team.
Technical & Security Data
Server and security information such as IP-related data, browser or device information, timestamps, request logs and anti-bot signals used to operate and protect the website.
We do not ask you to provide special categories of personal data through our website forms. Please avoid uploading government identification documents, health information or other sensitive and unrelated personal data unless Nezni has specifically requested it for a legitimate and lawful purpose.
How We Collect Personal Data
We may collect personal data in the following ways:
- Directly from you when you complete a form, request a quotation, upload a reference file, send an email, call us or communicate with our team.
- Automatically through website operation and security systems, including standard server logs and anti-abuse or bot-detection technologies.
- Through business communications when you or your organisation correspond with Nezni about quotations, samples, orders, production, delivery, support or other B2B matters.
- From another person within your organisation where they provide your business contact details for a legitimate project, order or working relationship.
If you provide personal data about another individual, you should ensure that you are authorised to do so and, where required, that the individual has been appropriately informed about the disclosure.
Why We Use Personal Data & Our Legal Bases
We process personal data only where there is a legitimate business or legal reason to do so. Depending on the applicable law and the circumstances, our legal basis may include taking steps at your request before entering into a contract, performing a contract, complying with a legal obligation, protecting or exercising legal rights, pursuing legitimate interests that do not override your rights, or obtaining consent where consent is required.
For individuals covered by the GDPR or UK GDPR, relevant legal bases may include Article 6(1)(b), 6(1)(c) and 6(1)(f), and Article 6(1)(a) where consent is used. Under KVKK, processing is carried out under the applicable processing conditions in Law No. 6698, including where processing is necessary for a contract, compliance with a legal obligation, establishment or protection of a right, legitimate interests that do not prejudice fundamental rights and freedoms, or explicit consent where required.
Contact Forms, Quote Requests & File Uploads
Our general contact form is intended for company information, product guidance, order support and other general questions. Our Request a Quote form is designed for custom manufacturing enquiries and may ask for your full name, company name, business email, country, phone or WhatsApp number, product category, estimated quantity, project details and optional artwork or reference files.
We use this information to review your request, understand your production requirements, prepare or discuss a quotation, communicate with you about the project and, where the project proceeds, manage the related commercial relationship.
Files uploaded through the quotation process may contain logos, artwork, product references or project documents. Please upload only information necessary for your project. If an uploaded file contains personal data, that data will be handled as part of the relevant enquiry or project and retained only for as long as reasonably necessary or legally required.
Form consent and acknowledgement
Where our forms ask you to acknowledge that you have read this Privacy Policy, that acknowledgement confirms that privacy information has been presented to you. It does not convert every processing activity into consent-based processing; Nezni may rely on another lawful basis where appropriate and permitted by law.
Website Security & Cloudflare Turnstile
Nezni uses Cloudflare Turnstile on website forms to help distinguish legitimate visitors from automated or abusive traffic and to reduce spam, fraud and malicious submissions.
When Turnstile operates, Cloudflare may process client-side security signals such as the client IP address, TLS fingerprint, User-Agent header, site key and associated origin. These signals are used for bot detection and website security. Cloudflare may act as a processor when providing the Turnstile service to website operators and may also process certain Turnstile signals for its own security-improvement purposes as described in its privacy information.
Our use of Turnstile is based on our legitimate interest in protecting the website, our forms and users against abuse and automated attacks, subject to applicable law. For more information, you can review the Cloudflare Turnstile Privacy Addendum.
Cookies, Analytics & Tracking Technologies
Nezni uses strictly necessary technical and security technologies for core website functions, consent-preference storage, form protection and abuse prevention. Nezni also uses the Google tag for Google Ads conversion measurement (tag ID AW-10991315186) only after a visitor grants Advertising consent.
Cloudflare security products may use strictly necessary technologies in connection with bot detection and security. The exact technologies used can depend on Cloudflare configuration and may change as security services evolve.
Nezni uses Basic Consent Mode v2. Before Advertising consent is granted, the Google Ads tag is blocked and no information is sent to Google through that tag. After consent, Google may receive browser or device information, timestamps, page and referrer information, ad-click identifiers such as GCLID or DCLID, consent state and configured conversion-event information. Google may also set first-party cookies on nezni.com to support conversion measurement.
Google Analytics, Meta Pixel, X Pixel, enhanced conversions, customer-data uploads and newsletter tracking are not currently enabled through the consent plugin. If Nezni later introduces any of these or another non-essential analytics, advertising, remarketing or personalisation technology, we will update this Privacy Policy and our Cookie Policy as appropriate before activation.
Please see our Cookie Policy for more specific information about cookies and similar technologies used on nezni.com.
When We Share Personal Data
We do not disclose personal data simply because a third party asks for it. We may share personal data only where reasonably necessary for a legitimate business or legal purpose, including with:
- Authorised Nezni personnel who need the information for sales, quotation, project planning, production, customer support, administration or compliance.
- Website, hosting, email, security and technical service providers that process information on our behalf or provide infrastructure needed to operate our website and communications.
- Professional advisers, such as legal, accounting or audit advisers, where necessary for legitimate business, compliance or legal purposes.
- Production, logistics or commercial service providers where sharing is necessary to plan, manufacture, prepare or deliver an order and the recipient has a legitimate need for the relevant information.
- Public authorities, courts or regulators where disclosure is required by law or reasonably necessary to establish, exercise or defend legal rights.
We expect service providers acting on our behalf to process personal data only for authorised purposes and to apply appropriate confidentiality and security measures. When a visitor grants Advertising consent, Google receives information for Google Ads conversion measurement and related functions under Google’s applicable terms and privacy information. Nezni does not currently send visitor data through Meta Pixel, X Pixel or a separate website analytics platform.
International Transfers of Personal Data
Nezni is established in Turkey and serves international B2B customers. Some technology or communication providers used to operate and protect the website may have infrastructure, group companies or service locations in other countries. As a result, personal data may in some circumstances be processed or made accessible outside the country in which you are located.
Where a cross-border transfer is subject to KVKK, GDPR, UK GDPR or another applicable data protection law, Nezni will take reasonable steps to use a legally permitted transfer mechanism and appropriate safeguards as required for the relevant transfer. These safeguards may include an applicable adequacy mechanism, approved contractual safeguards, standard contractual clauses or another lawful transfer basis available under the relevant legislation.
Under Turkey’s current framework, transfers abroad are subject to Article 9 of Law No. 6698 and the applicable rules governing adequacy decisions, appropriate safeguards and permitted exceptions. Transfer mechanisms may change over time as laws, regulatory decisions and service-provider arrangements change.
Data Retention & Security
How long we keep information
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and for any additional period required or permitted by applicable law. The appropriate retention period depends on the nature of the information and the context in which it is processed.
- General enquiries may be retained while we respond and for a reasonable period afterwards for business continuity and follow-up.
- Quotation, project and order records may be retained for the duration of the business relationship and for applicable commercial, tax, accounting, warranty, dispute or legal-claim periods.
- Uploaded reference files may be kept while necessary to evaluate or manage the relevant project, then deleted, archived or otherwise disposed of according to our operational and legal requirements.
- Security and technical logs are retained for a limited period appropriate to security, troubleshooting, fraud prevention and system integrity, unless longer retention is required for an incident or legal matter.
How we protect information
We use reasonable technical and organisational measures designed to protect personal data against accidental loss, unauthorised access, misuse, alteration or disclosure. These measures may include access controls, authenticated email transmission, form security, anti-bot protection, software maintenance and administrative safeguards.
No website, transmission method or storage system can be guaranteed to be completely secure. If you believe personal data you provided to Nezni has been compromised, please contact us promptly using the details at the end of this policy.
Your Privacy Rights
Your rights depend on the privacy law that applies to you and may be subject to legal conditions, limitations or exemptions. We may need to verify your identity before completing a request.
Rights under KVKK
Subject to Article 11 of Turkey’s Personal Data Protection Law No. 6698, you may have the right to ask whether your personal data is processed; request information about processing; learn the purpose of processing and whether data is used in accordance with that purpose; learn the third parties to whom data is transferred in Turkey or abroad; request correction of incomplete or inaccurate data; request deletion or destruction where the legal conditions are met; request notification of certain corrections, deletions or destructions to relevant third parties; object to a result arising against you from analysis exclusively by automated systems; and claim compensation where you suffer damage due to unlawful processing.
Rights under GDPR / UK GDPR where applicable
Depending on the circumstances, you may have rights of access, rectification, erasure, restriction, objection and data portability. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. You may also have the right to lodge a complaint with the competent data protection authority in your country.
Nezni does not currently use the website to make decisions about individuals solely by automated means that produce legal effects or similarly significant effects. Automated security tools may, however, evaluate technical signals to detect bots, spam or malicious activity.
How to make a request
You can contact Nezni using the details in Section 14. Under KVKK, requests to the data controller are handled in accordance with the applicable request procedure and statutory response period. Depending on your jurisdiction, you may also contact the relevant supervisory authority if you believe your privacy rights have been infringed.
Third-Party Links & Communication Services
The website may contain links to third-party websites or services, including WhatsApp and Google Maps. When you choose to open or use a third-party service, that provider may collect or process information under its own privacy terms and technical environment. Nezni does not control the independent privacy practices of those third parties.
Starting a WhatsApp conversation is optional. If you choose WhatsApp, information you send through the service is processed through WhatsApp’s systems in accordance with its applicable terms and privacy information. You may instead contact Nezni by email, phone or our website forms.
Google provides the Google Ads conversion-measurement service used on nezni.com after Advertising consent. Google may process information on infrastructure located outside the visitor’s country and may use the information in accordance with the Google Privacy Policy and applicable Google Ads terms. Nezni uses this service to measure advertising outcomes and does not currently enable enhanced conversions or upload customer contact data to Google.
Our website and services are directed primarily to businesses and professional contacts and are not intended to solicit personal data from children. If we become aware that personal data from a child has been submitted without an appropriate lawful basis, we will take reasonable steps to address the information in accordance with applicable law.
Changes to This Privacy Policy
We may update this Privacy Policy when our website, business processes, service providers or legal obligations change. The “Last updated” date at the top of the page shows when this policy was most recently revised.
If we introduce a new processing activity that materially changes how personal data is used—such as Google Analytics, Meta Pixel, X Pixel, additional advertising or remarketing technologies, enhanced conversions or a newsletter subscription system—we will update the relevant privacy information before or when that processing begins, as required by applicable law. Where consent is legally required, the relevant processing will be subject to an appropriate consent mechanism.
We encourage you to review this page periodically, particularly before providing personal data through a new or materially changed website feature.
Contact Nezni About Privacy
If you have a question about this Privacy Policy, want to exercise an applicable privacy right or believe personal data has been handled incorrectly, contact us using the details below. Please include enough information for us to understand your request, but do not send unnecessary sensitive information by email.
For information about rights and procedures under Turkey’s Personal Data Protection Law, you may also consult the official Personal Data Protection Authority at kvkk.gov.tr.