24/7 SERVICE LINE
[ LEGAL · 02 ]

Privacy Policy.

Data collected when you visit our website or contact us and how we protect it.

Effective date: 4 August 2026

1. Introduction

At Hydroport Mühendislik A.Ş. ("Hydroport", "we") we take the privacy of our visitors and customers seriously. This policy explains the data we collect through the hydroport.com.tr domain, the purposes for which we use it, and your rights.

For the detailed clarification text under the KVKK, please see the KVKK Clarification Text page.

2. Data We Collect

2.1 Data you share directly

Through the contact form, by e-mail or in a telephone conversation you may share the following information:

  • First name, surname, company name
  • E-mail address, telephone number
  • Subject of the request, message content, attached files

2.2 Automatically collected data

When you visit our site, the following information is received automatically from your browser:

  • IP address (for the analytics measurement signal, IP masking is applied by Google on its own side)
  • Browser type and version
  • Pages visited and time spent
  • Referring site (referrer)
  • Operating system and device type
  • Error and diagnostic records (when an application error occurs)

This data is used for statistical analysis and security purposes. For details see the Cookie Policy.

3. How We Use the Data

We use the collected data only for the following purposes:

  • Responding to your quotation requests and providing technical support
  • Managing order, shipment and service processes
  • Fulfilling legal obligations (invoicing, ETBİS, tax legislation)
  • Measuring and improving the performance of the website
  • Detecting and preventing security threats (malicious bots, DDoS, etc.)
  • Marketing communication within the scope of explicit consent (newsletter — only with your approval)

We do not sell your data. It is not rented out or transferred to third parties for marketing purposes.

4. Security Measures

We apply the following technical and administrative measures to protect your personal data:

  • All web traffic is encrypted with HTTPS / TLS 1.3
  • Encryption at rest (AES-256) and row-level security (RLS) in the database
  • A strong password policy and two-factor authentication (in the admin panel)
  • Periodic security audits and backups
  • Role-based authorisation to prevent unauthorised access
  • Employee training and confidentiality agreements
  • An incident response plan — notification to the Personal Data Protection Board within 72 hours in the event of a data breach

5. Third-Party Services

We work with the following trusted third parties in order to provide our services:

  • fly.io Inc. (a US company) — site hosting; servers in the Frankfurt/fra region
  • Supabase Inc. (USA) — database and authentication infrastructure
  • Cloudflare Inc. (USA) — bot protection and DDoS security
  • Sentry (Functional Software, Inc., a US company) — application error monitoring; servers in the Germany/EU region. The transfer is protected within the scope of Article 9 of the KVKK.
  • Resend (Resend, Inc., a US company) — delivery of contact form notification e-mails. The transfer is protected within the scope of Article 9 of the KVKK.
  • Google Ireland Ltd. / Google LLC (USA) — anonymous traffic and usage analytics via Google Analytics 4 and advertising measurement via Google Ads; acts as a data processor — analytics and advertising are separate consent categories. Unless consent is given, no cookie is placed on your device and your visits are not linked to one another; only a cookieless, non-identifying measurement signal (covering page views as well as interaction events such as form submissions, product views and clicks on contact links) is sent. That signal contains the technically necessary connection information (including your IP address) and is turned into aggregate statistics by Google. The transfer is carried out under Standard Contractual Clauses (SCC) within the scope of Article 9 of the KVKK.
  • Google Maps — map display on the contact page

These providers operate under standard contractual clauses (SCC) and GDPR-compliant conditions. They do not use your data for their own purposes; they process it only on our behalf.

6. Children's Privacy

Our services are not directed at persons under the age of 18. We do not knowingly collect personal data from children. If you believe we have collected a child's data, please contact us.

7. Rights of the Data Subject

Under Article 11 of the KVKK you have rights such as accessing, rectifying and erasing your data and restricting its transfer. For details and application channels, please visit the KVKK Clarification Text page.

8. Policy Updates

This privacy policy may be updated when necessary. Significant changes are announced on the site and the effective date is updated.

9. Contact

For questions about our privacy policy:

  • E-mail: kvkk@hydroport.com.tr
  • Telephone: +90 262 502 06 13 · +90 538 983 1290
  • Address: Çerkeşli OSB Mah. İmes 1 Bulvarı No 2/6, 41455 Dilovası / Kocaeli
[ CONTACT ]

Do you have questions about privacy?

We are here to answer any questions about our data processing processes, security measures or your rights.

GET A QUOTE