GDPR & CCPA COMPLIANCE

1. Our Commitment to Data Privacy

At Raddomeku, we take your privacy seriously. We are committed to protecting your personal data and respecting your privacy rights, no matter where you are in the world.

This page explains:

Your rights under GDPR and CCPA

How we comply with these regulations

How to exercise your rights

How to contact us with privacy concerns

We comply with:

GDPR (General Data Protection Regulation - EU Regulation 2016/679)

CCPA (California Consumer Privacy Act - California Civil Code § 1798.100)

KVKK (Turkish Personal Data Protection Law No. 6698)

ePrivacy Directive (Directive 2002/58/EC)

2. Your Rights Under GDPR

If you are a resident of the European Union or the European Economic Area, you have the following rights under GDPR:

2.1. Right to Access (GDPR Article 15)

You have the right to request a copy of the personal data we hold about you.

How to exercise: Email [email protected] with subject "GDPR Access Request"

What you'll receive:

Confirmation of whether we process your data

A copy of your personal data

Information about how we use it

Who we share it with

How long we keep it

Response time: Within 30 days

Cost: Free for the first request

2.2. Right to Rectification (GDPR Article 16)

You have the right to correct inaccurate or incomplete personal data.

How to exercise: Email [email protected] with subject "GDPR Rectification Request"

What you need to provide:

The data you believe is incorrect

The correct information

Response time: Within 30 days

2.3. Right to Erasure (GDPR Article 17) - "Right to be Forgotten"

You have the right to request deletion of your personal data under certain circumstances.

When we will delete your data:

Data is no longer necessary for the purpose we collected it

You withdraw consent (where consent is the legal basis)

You object to processing and there are no overriding legitimate grounds

Data was processed unlawfully

Data must be deleted to comply with a legal obligation

When we may NOT delete your data:

We need it to comply with a legal obligation

We need it to establish, exercise, or defend legal claims

We have an overriding legitimate interest

How to exercise: Email [email protected] with subject "GDPR Erasure Request"

Response time: Within 30 days

2.4. Right to Restriction of Processing (GDPR Article 18)

You have the right to restrict how we process your data.

When you can restrict:

You contest the accuracy of the data (until we verify it)

Processing is unlawful, but you prefer restriction over erasure

We no longer need the data, but you need it for legal claims

You object to processing (pending verification of legitimate interests)

How to exercise: Email [email protected] with subject "GDPR Restriction Request"

Response time: Within 30 days

2.5. Right to Data Portability (GDPR Article 20)

You have the right to receive your data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.

What you'll receive:

Your data in CSV or JSON format

Where technically feasible, we will transfer it directly to another controller

How to exercise: Email [email protected] with subject "GDPR Portability Request"

Response time: Within 30 days

Cost: Free

2.6. Right to Object (GDPR Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes.

What happens next:

We will stop processing unless we demonstrate compelling legitimate grounds

For marketing: We will stop immediately

How to exercise: Email [email protected] with subject "GDPR Objection Request"

Response time: Within 30 days

2.7. Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time.

How to exercise:

Click "Unsubscribe" in any marketing email

Email [email protected] with subject "Withdraw Consent"

Update your cookie preferences via our cookie banner

Effect: Withdrawal does not affect the lawfulness of processing before withdrawal

2.8. Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection authority.

Relevant Supervisory Authorities:

Country Authority Website
European Union European Data Protection Board edpb.europa.eu
United Kingdom ICO ico.org.uk
Germany BfDI bfdi.bund.de
France CNIL cnil.fr
Türkiye KVKK kvkk.gov.tr
H3: 3. Your Rights Under CCPA

If you are a resident of California, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

3.1. Right to Know (CCPA § 1798.100)

You have the right to request disclosure of:

The categories of personal data we collect

The specific pieces of personal data we hold

The categories of sources from which we collect data

The business or commercial purpose for collecting data

The categories of third parties with whom we share data

The categories of data disclosed for a business purpose

How to exercise: Email [email protected] with subject "CCPA Access Request"

Verification: We may verify your identity before responding

Response time: Within 45 days

Cost: Free (up to twice per 12-month period)

3.2. Right to Delete (CCPA § 1798.105)

You have the right to request deletion of personal data we hold about you.

Exceptions: We may retain data if necessary for:

Completing a transaction

Detecting security incidents

Debugging errors

Exercising free speech

Complying with legal obligations

Internal research (in the public interest)

Internal uses compatible with the context of collection

How to exercise: Email [email protected] with subject "CCPA Deletion Request"

Response time: Within 45 days

3.3. Right to Opt-Out of Sale (CCPA § 1798.120)

You have the right to opt-out of the sale of your personal data to third parties.

Important: Raddomeku does not sell personal data to third parties. We never have, and we never will.

How to exercise: Even though we don't sell data, you can contact us at [email protected]

3.4. Right to Non-Discrimination (CCPA § 1798.125)

We will not discriminate against you for exercising your CCPA rights. This means:

We will not deny you services

We will not charge you different prices

We will not provide a different level of service

We will not retaliate in any way

3.5. Right to Correct (CPRA - effective 2023)

You have the right to request correction of inaccurate personal data.

How to exercise: Email [email protected] with subject "CCPA Correction Request"

3.6. Right to Limit Use of Sensitive Personal Information (CPRA)

You have the right to limit the use of sensitive personal information.

Our practice: We do not collect sensitive personal information (SSN, driver's license, financial account numbers, precise geolocation, etc.) without explicit consent.

4. What Data We Collect (GDPR & CCPA Summary)

Here's a clear summary of our data collection practices:

Category Data Collected Purpose Legal Basis (GDPR) CCPA Category
Identity Data Name, company name Service delivery, communication Contract / Legitimate Interest Identifiers
Contact Data Email, phone, address Communication, marketing Consent / Contract Identifiers
Company Data Revenue, industry, size Service customization Legitimate Interest Commercial Information
Inquiry Data Challenge description Service recommendation Legitimate Interest Commercial Information
Website Data IP address, browser, pages visited Analytics, improvement Consent Internet Activity
Cookie Data Preferences, session Functionality, analytics Consent Geolocation (IP)
Client Data Financials, operations, contracts Service delivery Contract Commercial Information
5. How We Comply with GDPR

GDPR Requirement How Raddomeku Complies
Lawful Basis We always identify a lawful basis for processing (Consent, Contract, Legitimate Interest, Legal Obligation)
Transparency We provide clear, accessible privacy information
Data Minimization We collect only what we need
Storage Limitation We retain data only as long as necessary (see retention periods in Privacy Policy)
Integrity & Confidentiality We implement security measures to protect data
Accountability We document our compliance and designate a Data Protection Officer (DPO)
Data Protection Impact Assessments We conduct DPIAs for high-risk processing
Breach Notification We report breaches to authorities within 72 hours
Processor Agreements We have GDPR-compliant agreements with all third-party processors
6. How We Comply with CCPA

CCPA Requirement How Raddomeku Complies
Notice at Collection We inform you at the point of data collection
Right to Know We respond to access requests within 45 days
Right to Delete We honor deletion requests (with legal exceptions)
Opt-Out of Sale We do not sell data - no opt-out needed
Non-Discrimination We do not discriminate against exercising rights
Verification We verify identity for certain requests
Authorized Agents We accept requests from authorized agents
Do Not Sell My Personal Information We have a clear "Do Not Sell" policy (even though we don't sell)
Financial Incentives We do not offer financial incentives for data collection
7. Data Subject Access Requests (DSAR) - How to Exercise Your Rights

Step-by-step guide to submitting a request:

Step 1: Identify Your Request Type

Decide which right you want to exercise:

Access Request (know what data we hold)

Deletion Request (delete your data)

Correction Request (fix incorrect data)

Portability Request (get your data in a file)

Objection Request (stop processing)

Withdraw Consent (revoke permission)

Step 2: Submit Your Request

Email us at: [email protected]

Template Email:

text
Subject: [GDPR/CCPA] [Type of Request]

To the Raddomeku Data Protection Officer,

I am submitting a request under [GDPR / CCPA] to [access / delete / correct / port / object] my personal data.

My details:
- Full Name: [Your full name]
- Email Address: [Email you used with us]
- Phone Number: [Optional]
- Company: [Optional]

Please confirm receipt of this request and provide a timeline for response.

Thank you,
[Your Name]
Step 3: Identity Verification

For security, we may verify your identity before processing your request. We may ask:

For additional identification

Confirmation of data you have previously provided

Verification of your email address

Step 4: Response Timeline

Regulation Timeline
GDPR Within 30 days
CCPA Within 45 days
We will:

Acknowledge receipt within 5 business days (CCPA)

Respond within the required timeline

Provide the requested information or action

Explain if we cannot fulfill your request (with reason)

Step 5: If You Are Unsatisfied

If you are unhappy with our response, you can:

Contact us again for clarification

Escalate to the relevant Data Protection Authority

Lodge a complaint with your local supervisory authority

8. Third-Party Processors (GDPR Article 28)

We use trusted third-party processors who are contractually bound to protect your data:

Provider Purpose GDPR Compliant Location
Google Workspace Email & document management ✅ SCCs USA / EU
Google Analytics Website analytics ✅ SCCs + IP Anonymization USA
Zoom Video consultations ✅ SCCs USA
Calendly Scheduling ✅ SCCs USA
Mailchimp Email marketing ✅ SCCs USA
Stripe Payment processing (if used) ✅ SCCs USA
Microsoft Cloud services (if used) ✅ SCCs Global
All providers have:

Standard Contractual Clauses (SCCs) approved by the European Commission

Data Processing Agreements (DPAs) in place

Appropriate security measures

9. International Data Transfers

When we transfer data outside of the European Economic Area (EEA), we ensure appropriate safeguards:

Safeguards we use:

Standard Contractual Clauses (SCCs) adopted by the European Commission

EU-U.S. Data Privacy Framework (for US-based processors)

Adequacy decisions (for countries recognized by the EU)

Explicit consent (where required)

For transfers to Türkiye:

Türkiye is not yet recognized as "adequate" by the EU

We rely on SCCs and your explicit consent for any data transferred to our Turkish headquarters

10. Data Protection Impact Assessments (DPIA)

We conduct Data Protection Impact Assessments for any processing that may present a high risk to your rights and freedoms.

When we conduct a DPIA:

Before implementing new technologies

When processing sensitive data (if applicable)

When using new third-party processors

For significant changes to our processing activities

11. Data Breach Notification

If a data breach occurs:

Timeline Action
Within 24 hours Internal investigation initiated
Within 72 hours Breach reported to relevant Data Protection Authority
Without undue delay Affected individuals notified (if high risk)
We maintain an incident response plan and conduct regular security audits.

12. Your California Privacy Rights (Shine the Light)

Under California's "Shine the Light" law (California Civil Code § 1798.83), California residents can request information about:

Categories of personal data shared with third parties for direct marketing

Names and addresses of those third parties

Our practice: We do not share personal data with third parties for their direct marketing purposes.

To request information: Email [email protected] with subject "California Shine the Light Request"

13. Your Nevada Privacy Rights

Under Nevada law (NRS 603A), Nevada residents can opt-out of the sale of their personal data.

Our practice: We do not sell personal data.

To opt-out (even though we don't sell): Email [email protected] with subject "Nevada Opt-Out"

14. Children's Data (GDPR Article 8 & CCPA)

We do not knowingly collect data from children under the age of 16.

GDPR: Children under 16 require parental consent

CCPA: Children under 16 require opt-in consent

Under 13: We never collect data from children under 13

If you believe we have collected data from a child, please contact us immediately at [email protected]. We will delete it.

15. Summary of Your Rights - Quick Reference

Right GDPR CCPA How to Exercise
Access ✅ ✅ Email [email protected]
Rectification ✅ ✅ (Correction) Email [email protected]
Erasure / Deletion ✅ ✅ Email [email protected]
Restriction ✅ ❌ Email [email protected]
Portability ✅ ❌ Email [email protected]
Object ✅ ❌ Email [email protected]
Withdraw Consent ✅ ❌ Email [email protected]
Opt-Out of Sale N/A ✅ Email [email protected] (even though we don't sell)
Non-Discrimination ✅ ✅ Automatic — we don't discriminate
Lodge Complaint ✅ ✅ Contact local authority
H3: 16. Contact Our Data Protection Officer

For all privacy-related inquiries, requests, or concerns:

Data Protection Officer (DPO):
Phone: +90 555 044 88 77

General Inquiries:

Postal Address:
Raddomeku
Impact Hub Istanbul
Levent Sanayi, Yeşilce, Emirşah Sokagi No:21, D:21
34418 Kağıthane/İstanbul, Türkiye

17. Regulatory Authorities

You have the right to lodge a complaint with a supervisory authority:

Authority Region Website
European Data Protection Board EU edpb.europa.eu
UK Information Commissioner's Office UK ico.org.uk
CNIL France cnil.fr
BfDI Germany bfdi.bund.de
KVKK Türkiye kvkk.gov.tr
California Privacy Protection Agency USA cppa.ca.gov
18. Policy Updates

Version Date Changes
1.0 August 26, 2026 Initial version
We may update this policy to reflect changes in laws, regulations, or our practices. Significant changes will be notified via email or website banner.

19. Quick Compliance Checklist

✅ Requirement Status
✅ Designated Data Protection Officer ✓
✅ Clear Privacy Policy ✓
✅ Cookie Banner with Consent ✓
✅ Cookie Policy ✓
✅ Terms of Service ✓
✅ Data Processing Agreements with Processors ✓
✅ Breach Notification Protocol ✓
✅ DSAR Procedure ✓
✅ Data Protection Impact Assessments ✓
✅ International Transfer Safeguards ✓
✅ Retention Policy ✓
✅ Security Measures ✓
✅ GDPR Compliance ✓
✅ CCPA Compliance ✓
✅ KVKK (Turkish) Compliance ✓

AI Website Generator