Privacy Policy
Version 1.1 · effective 28 August 2026
This page explains what is collected when you visit ktsd.org.tr or use the member area, what it is used for, and how long it is kept. For the legal framework around processing personal data and for your rights, see the Personal Data Protection Notice; for the conditions of using the site, see the Terms of Use.
Who is responsible
The data controller is the Cosmetics and Cleaning Products Manufacturers Association (KTSD), of Sahrayıcedit Atatürk Caddesi, Dilkum 6 Sitesi No: 57 Kat: 1 D: 11, Kadıköy / İstanbul. For any question or request: info@ktsd.org.tr
Browsing the site
You do not need an account, a form or any information from you in order to read this site.
As on any website, our servers keep a technical record of requests. That record includes things like the type of browser you use, your operating system and the link you arrived from. On its own it does not identify you.
When you submit a form
There are three kinds of form on the site: contact, membership application and document request. When you submit one, we keep:
- What you wrote — your name, your email address, your message: whichever fields you filled in.
- Your IP address, to prevent abuse and automated submissions. It is the only way to establish afterwards where a submission came from.
- When it was sent, and whether anyone has replied to you.
Submissions are stored so that they cannot be edited in the panel: they stay exactly as the sender wrote them.
The forms use Cloudflare Turnstile to tell automated submissions apart from real ones. Turnstile does not set a cookie and does not track you across sites.
When you use the member area
Signing in is passwordless: a one-time code is sent to your email address. There is no password stored, so there is no password to steal.
When you sign in, a session record is created. It holds a hash of the session token (not the token itself), which account it belongs to, when it was opened, when it was last used, when it expires, your browser information and your IP address. This is for the security of the session — so that it is possible to see where an account is being used from, and to end the session if something looks wrong.
When you download a document, who downloaded what, and when is recorded. That record is the association's own audit trail and outlives the document itself: the confidentiality of what is shared with members depends on knowing who received it.
Cookies
There are three categories, and you are asked about them on your first visit:
- Necessary — these cannot be switched off. They keep you signed in, remember your language, and store your cookie choice itself. The site does not work without them.
- Analytics — only if you allow them. They are used to see, in aggregate, which pages are read. If you decline, no analytics script is loaded at all.
- Embedded content — material from other sites, such as maps and video. Even when allowed, it loads only when you open that content.
You can change your choice at any time from the link in the footer. Declining does not restrict your reading of the site in any way.
Who we share it with
We do not sell your personal data and we do not share it with third parties for advertising.
We use providers to run the service: email delivery, server hosting and file storage. Those providers access data only in order to do that work. Beyond this, we share data only on a properly made request from a public authority legally entitled to it, and only to the extent the request requires.
How long we keep it
- Form submissions — deleted once they have been answered and no longer have any record value.
- Membership records — for as long as the membership lasts and, after it ends, for the limitation periods the legislation provides.
- Session records — when the session expires.
- Download records — for longer than the document itself. Who read what is a record whose usefulness is not bounded by the life of the file.
Data that has reached the end of that period is erased, destroyed, or anonymised for further use.
Security
Documents in the member area are held privately: their addresses cannot be guessed to download them, and a short-lived signed link is created for each read. Traffic across the site is encrypted. In the panel, every account's permissions are limited by its role.
No system is perfect. If there is a security incident, we will inform the people affected and the Personal Data Protection Authority as the legislation requires.
Your rights
All of the rights listed in Article 11 of the KVKK — to learn whether your data is being processed, to have it corrected, to have it erased, and the rest — are set out in full in the Personal Data Protection Notice. To exercise them, write to info@ktsd.org.tr or send a written request to the postal address above.
If this page changes
When we update these principles we change the effective date on the page. If a change materially affects you, we will tell our members separately.
