1. Our Commitment to Data Privacy
At Raddomeku, we take your privacy seriously. We are committed to protecting your personal data and respecting your privacy rights, no matter where you are in the world.
This page explains:
Your rights under GDPR and CCPA
How we comply with these regulations
How to exercise your rights
How to contact us with privacy concerns
We comply with:
GDPR (General Data Protection Regulation - EU Regulation 2016/679)
CCPA (California Consumer Privacy Act - California Civil Code § 1798.100)
KVKK (Turkish Personal Data Protection Law No. 6698)
ePrivacy Directive (Directive 2002/58/EC)
2. Your Rights Under GDPR
If you are a resident of the European Union or the European Economic Area, you have the following rights under GDPR:
2.1. Right to Access (GDPR Article 15)
You have the right to request a copy of the personal data we hold about you.
What you'll receive:
Confirmation of whether we process your data
A copy of your personal data
Information about how we use it
Who we share it with
How long we keep it
Response time: Within 30 days
Cost: Free for the first request
2.2. Right to Rectification (GDPR Article 16)
You have the right to correct inaccurate or incomplete personal data.
What you need to provide:
The data you believe is incorrect
The correct information
Response time: Within 30 days
2.3. Right to Erasure (GDPR Article 17) - "Right to be Forgotten"
You have the right to request deletion of your personal data under certain circumstances.
When we will delete your data:
Data is no longer necessary for the purpose we collected it
You withdraw consent (where consent is the legal basis)
You object to processing and there are no overriding legitimate grounds
Data was processed unlawfully
Data must be deleted to comply with a legal obligation
When we may NOT delete your data:
We need it to comply with a legal obligation
We need it to establish, exercise, or defend legal claims
We have an overriding legitimate interest
Response time: Within 30 days
2.4. Right to Restriction of Processing (GDPR Article 18)
You have the right to restrict how we process your data.
When you can restrict:
You contest the accuracy of the data (until we verify it)
Processing is unlawful, but you prefer restriction over erasure
We no longer need the data, but you need it for legal claims
You object to processing (pending verification of legitimate interests)
Response time: Within 30 days
2.5. Right to Data Portability (GDPR Article 20)
You have the right to receive your data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
What you'll receive:
Your data in CSV or JSON format
Where technically feasible, we will transfer it directly to another controller
Response time: Within 30 days
Cost: Free
2.6. Right to Object (GDPR Article 21)
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
What happens next:
We will stop processing unless we demonstrate compelling legitimate grounds
For marketing: We will stop immediately
Response time: Within 30 days
2.7. Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw that consent at any time.
How to exercise:
Click "Unsubscribe" in any marketing email
Update your cookie preferences via our cookie banner
Effect: Withdrawal does not affect the lawfulness of processing before withdrawal
2.8. Right to Lodge a Complaint
You have the right to lodge a complaint with your local data protection authority.
Relevant Supervisory Authorities:
Country Authority Website
European Union European Data Protection Board edpb.europa.eu
United Kingdom ICO ico.org.uk
Germany BfDI bfdi.bund.de
France CNIL cnil.fr
Türkiye KVKK kvkk.gov.tr
H3: 3. Your Rights Under CCPA
If you are a resident of California, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
3.1. Right to Know (CCPA § 1798.100)
You have the right to request disclosure of:
The categories of personal data we collect
The specific pieces of personal data we hold
The categories of sources from which we collect data
The business or commercial purpose for collecting data
The categories of third parties with whom we share data
The categories of data disclosed for a business purpose
Verification: We may verify your identity before responding
Response time: Within 45 days
Cost: Free (up to twice per 12-month period)
3.2. Right to Delete (CCPA § 1798.105)
You have the right to request deletion of personal data we hold about you.
Exceptions: We may retain data if necessary for:
Completing a transaction
Detecting security incidents
Debugging errors
Exercising free speech
Complying with legal obligations
Internal research (in the public interest)
Internal uses compatible with the context of collection
Response time: Within 45 days
3.3. Right to Opt-Out of Sale (CCPA § 1798.120)
You have the right to opt-out of the sale of your personal data to third parties.
Important: Raddomeku does not sell personal data to third parties. We never have, and we never will.
How to exercise: Even though we don't sell data, you can contact us at
[email protected]
3.4. Right to Non-Discrimination (CCPA § 1798.125)
We will not discriminate against you for exercising your CCPA rights. This means:
We will not deny you services
We will not charge you different prices
We will not provide a different level of service
We will not retaliate in any way
3.5. Right to Correct (CPRA - effective 2023)
You have the right to request correction of inaccurate personal data.
3.6. Right to Limit Use of Sensitive Personal Information (CPRA)
You have the right to limit the use of sensitive personal information.
Our practice: We do not collect sensitive personal information (SSN, driver's license, financial account numbers, precise geolocation, etc.) without explicit consent.
4. What Data We Collect (GDPR & CCPA Summary)
Here's a clear summary of our data collection practices:
Category Data Collected Purpose Legal Basis (GDPR) CCPA Category
Identity Data Name, company name Service delivery, communication Contract / Legitimate Interest Identifiers
Contact Data Email, phone, address Communication, marketing Consent / Contract Identifiers
Company Data Revenue, industry, size Service customization Legitimate Interest Commercial Information
Inquiry Data Challenge description Service recommendation Legitimate Interest Commercial Information
Website Data IP address, browser, pages visited Analytics, improvement Consent Internet Activity
Cookie Data Preferences, session Functionality, analytics Consent Geolocation (IP)
Client Data Financials, operations, contracts Service delivery Contract Commercial Information
5. How We Comply with GDPR
GDPR Requirement How Raddomeku Complies
Lawful Basis We always identify a lawful basis for processing (Consent, Contract, Legitimate Interest, Legal Obligation)
Transparency We provide clear, accessible privacy information
Data Minimization We collect only what we need
Storage Limitation We retain data only as long as necessary (see retention periods in Privacy Policy)
Integrity & Confidentiality We implement security measures to protect data
Accountability We document our compliance and designate a Data Protection Officer (DPO)
Data Protection Impact Assessments We conduct DPIAs for high-risk processing
Breach Notification We report breaches to authorities within 72 hours
Processor Agreements We have GDPR-compliant agreements with all third-party processors
6. How We Comply with CCPA
CCPA Requirement How Raddomeku Complies
Notice at Collection We inform you at the point of data collection
Right to Know We respond to access requests within 45 days
Right to Delete We honor deletion requests (with legal exceptions)
Opt-Out of Sale We do not sell data - no opt-out needed
Non-Discrimination We do not discriminate against exercising rights
Verification We verify identity for certain requests
Authorized Agents We accept requests from authorized agents
Do Not Sell My Personal Information We have a clear "Do Not Sell" policy (even though we don't sell)
Financial Incentives We do not offer financial incentives for data collection
7. Data Subject Access Requests (DSAR) - How to Exercise Your Rights
Step-by-step guide to submitting a request:
Step 1: Identify Your Request Type
Decide which right you want to exercise:
Access Request (know what data we hold)
Deletion Request (delete your data)
Correction Request (fix incorrect data)
Portability Request (get your data in a file)
Objection Request (stop processing)
Withdraw Consent (revoke permission)
Step 2: Submit Your Request
Template Email:
text
Subject: [GDPR/CCPA] [Type of Request]
To the Raddomeku Data Protection Officer,
I am submitting a request under [GDPR / CCPA] to [access / delete / correct / port / object] my personal data.
My details:
- Full Name: [Your full name]
- Email Address: [Email you used with us]
- Phone Number: [Optional]
- Company: [Optional]
Please confirm receipt of this request and provide a timeline for response.
Thank you,
[Your Name]
Step 3: Identity Verification
For security, we may verify your identity before processing your request. We may ask:
For additional identification
Confirmation of data you have previously provided
Verification of your email address
Step 4: Response Timeline
Regulation Timeline
GDPR Within 30 days
CCPA Within 45 days
We will:
Acknowledge receipt within 5 business days (CCPA)
Respond within the required timeline
Provide the requested information or action
Explain if we cannot fulfill your request (with reason)
Step 5: If You Are Unsatisfied
If you are unhappy with our response, you can:
Contact us again for clarification
Escalate to the relevant Data Protection Authority
Lodge a complaint with your local supervisory authority
8. Third-Party Processors (GDPR Article 28)
We use trusted third-party processors who are contractually bound to protect your data:
Provider Purpose GDPR Compliant Location
Google Workspace Email & document management ✅ SCCs USA / EU
Google Analytics Website analytics ✅ SCCs + IP Anonymization USA
Zoom Video consultations ✅ SCCs USA
Calendly Scheduling ✅ SCCs USA
Mailchimp Email marketing ✅ SCCs USA
Stripe Payment processing (if used) ✅ SCCs USA
Microsoft Cloud services (if used) ✅ SCCs Global
All providers have:
Standard Contractual Clauses (SCCs) approved by the European Commission
Data Processing Agreements (DPAs) in place
Appropriate security measures
9. International Data Transfers
When we transfer data outside of the European Economic Area (EEA), we ensure appropriate safeguards:
Safeguards we use:
Standard Contractual Clauses (SCCs) adopted by the European Commission
EU-U.S. Data Privacy Framework (for US-based processors)
Adequacy decisions (for countries recognized by the EU)
Explicit consent (where required)
For transfers to Türkiye:
Türkiye is not yet recognized as "adequate" by the EU
We rely on SCCs and your explicit consent for any data transferred to our Turkish headquarters
10. Data Protection Impact Assessments (DPIA)
We conduct Data Protection Impact Assessments for any processing that may present a high risk to your rights and freedoms.
When we conduct a DPIA:
Before implementing new technologies
When processing sensitive data (if applicable)
When using new third-party processors
For significant changes to our processing activities
11. Data Breach Notification
If a data breach occurs:
Timeline Action
Within 24 hours Internal investigation initiated
Within 72 hours Breach reported to relevant Data Protection Authority
Without undue delay Affected individuals notified (if high risk)
We maintain an incident response plan and conduct regular security audits.
12. Your California Privacy Rights (Shine the Light)
Under California's "Shine the Light" law (California Civil Code § 1798.83), California residents can request information about:
Categories of personal data shared with third parties for direct marketing
Names and addresses of those third parties
Our practice: We do not share personal data with third parties for their direct marketing purposes.
To request information: Email
[email protected] with subject "California Shine the Light Request"
13. Your Nevada Privacy Rights
Under Nevada law (NRS 603A), Nevada residents can opt-out of the sale of their personal data.
Our practice: We do not sell personal data.
To opt-out (even though we don't sell): Email
[email protected] with subject "Nevada Opt-Out"
14. Children's Data (GDPR Article 8 & CCPA)
We do not knowingly collect data from children under the age of 16.
GDPR: Children under 16 require parental consent
CCPA: Children under 16 require opt-in consent
Under 13: We never collect data from children under 13
If you believe we have collected data from a child, please contact us immediately at
[email protected]. We will delete it.
15. Summary of Your Rights - Quick Reference
Right GDPR CCPA How to Exercise
Non-Discrimination ✅ ✅ Automatic — we don't discriminate
Lodge Complaint ✅ ✅ Contact local authority
H3: 16. Contact Our Data Protection Officer
For all privacy-related inquiries, requests, or concerns:
Data Protection Officer (DPO):
Phone: +90 555 044 88 77
General Inquiries:
Postal Address:
Raddomeku
Impact Hub Istanbul
Levent Sanayi, Yeşilce, Emirşah Sokagi No:21, D:21
34418 Kağıthane/İstanbul, Türkiye
17. Regulatory Authorities
You have the right to lodge a complaint with a supervisory authority:
Authority Region Website
European Data Protection Board EU edpb.europa.eu
UK Information Commissioner's Office UK ico.org.uk
CNIL France cnil.fr
BfDI Germany bfdi.bund.de
KVKK Türkiye kvkk.gov.tr
California Privacy Protection Agency USA cppa.ca.gov
18. Policy Updates
Version Date Changes
1.0 August 26, 2026 Initial version
We may update this policy to reflect changes in laws, regulations, or our practices. Significant changes will be notified via email or website banner.
19. Quick Compliance Checklist
✅ Requirement Status
✅ Designated Data Protection Officer ✓
✅ Clear Privacy Policy ✓
✅ Cookie Banner with Consent ✓
✅ Cookie Policy ✓
✅ Terms of Service ✓
✅ Data Processing Agreements with Processors ✓
✅ Breach Notification Protocol ✓
✅ DSAR Procedure ✓
✅ Data Protection Impact Assessments ✓
✅ International Transfer Safeguards ✓
✅ Retention Policy ✓
✅ Security Measures ✓
✅ GDPR Compliance ✓
✅ CCPA Compliance ✓
✅ KVKK (Turkish) Compliance ✓