Privacy Policy & Data Protection Notice
Protecting your personal information and ensuring transparent data governance is central to our values.
Detailed overview of personal data processing activities, statutory subject rights, and technical safeguards under GDPR and applicable laws.
🔒 Core Privacy Principles
Natustech strictly refrains from monetizing, selling, or unauthorized sharing of your data. All systems are protected using enterprise-grade encryption and audited infrastructure aligned with international security best practices.
1. Identity of the Data Controller
In accordance with applicable data protection legislation including the GDPR and relevant local regulations, Natustech Teknoloji A.Ş. ("Natustech") acts as the data controller and is committed to ensuring the highest standards of data privacy, security, and integrity across all digital operations.
2. Categories of Personal Data Processed
When interacting with our corporate website or contacting us, we may collect and process:
- ✓Identity Information: Full name and corporate role.
- ✓Contact Details: Business email address, corporate telephone number, and organization name.
- ✓Inquiry & Consultation Data: Information submitted through our demo and contact forms.
- ✓Technical & Security Logs: IP address, access timestamps, browser specifications, and device metadata.
3. Processing Purposes and Legal Grounds
Your personal data is processed strictly for:
- ✓Providing architectural advisory, workflow platforms, SaaS integrations, and technical proposals,
- ✓Responding to client inquiries and scheduling project consultations (contractual necessity or legitimate business interest),
- ✓Ensuring web platform security, threat mitigation, and infrastructure reliability,
- ✓Complying with statutory reporting requirements and regulatory obligations.
4. Data Transfers & Confidentiality
Natustech never sells, licenses, or commercializes personal data to third parties. Data is only shared with trusted, SOC2/ISO 27001 certified cloud infrastructure providers under strict Data Processing Agreements (DPAs) or when legally required by authorized regulatory bodies.
5. Security Measures & Data Retention
We implement robust technical and operational controls:
- ✓Mandatory TLS 1.3 encrypted transit and AES-256 encrypted storage,
- ✓Role-based access management (RBAC) and audited system access logs,
- ✓Data is retained only as long as required to fulfill the stated business purpose or statutory retention periods, after which it is irreversibly purged or anonymized.
6. Your Data Subject Rights
Under the GDPR and global privacy frameworks, you have the right to access, rectify, or erase your personal data, restrict or object to its processing, and request data portability.
7. Inquiries and Contact
To exercise your rights or request further details about our data protection governance, contact our team at info@natustech.com. We respond to all formal inquiries within 30 days.
