[legal]

Privacy Policy

1. Controller

The controller responsible for data processing on this website is:

Nabi Caner Aybaş
Friedrichstr. 226, 10969, Berlin, Almanya

+491729897808, caneraybas@gmail.com


2. General information

We treat your personal data confidentially and in accordance with statutory data protection provisions and this privacy policy. Personal data is any data that can be used to identify you personally.

Please note that data transmission over the internet — for example when communicating by email — may have security vulnerabilities. Complete protection of data against access by third parties is not possible.

Although our services are directed at businesses, the individuals who contact us on behalf of those businesses are natural persons, and their data is protected accordingly.


3. Hosting

This website is hosted by an external service provider:

Framer B.V. Overtoom 197, 1054 HT Amsterdam, Netherlands

Framer processes server log files on our behalf, which your browser transmits automatically:

  • IP address (shortened or anonymised)

  • Date and time of access

  • Page or file requested

  • Referrer URL

  • Browser type and version

  • Operating system used

This data is not merged with other data sources. The legal basis is Art. 6 (1) (f) GDPR — we have a legitimate interest in the technically error-free and secure presentation of our website. We have concluded a data processing agreement with Framer pursuant to Art. 28 GDPR.


4. Briefing and contact forms

For our forms we use the service Tally:

Tally BV Rerum Novarumlaan 5, 3010 Kessel-Lo, Belgium

When you complete a form on our website, the data you enter is stored on Tally's servers within the EU and transmitted to us. This includes:

  • Name and contact details (email address, phone or WhatsApp number)

  • Company or brand name

  • Information about your project, target audience and intended use

  • Image files and reference material you upload

  • Links you provide to external material

  • Technical metadata (IP address, timestamp of submission)

Legal basis: Art. 6 (1) (b) GDPR insofar as processing is necessary for the performance of a contract or for steps taken prior to entering into a contract. In all other cases, Art. 6 (1) (f) GDPR — our legitimate interest in responding to enquiries.

Retention: We store your form data and the uploaded image files for the duration of the project and beyond that where statutory retention obligations require it — in particular commercial and tax retention periods of up to ten years pursuant to § 147 German Fiscal Code and § 257 German Commercial Code. Project files not subject to a retention obligation are deleted no later than [12 / 24] months after project completion, unless you expressly agree to longer storage.

A data processing agreement pursuant to Art. 28 GDPR is in place with Tally.


5. Communication by email and WhatsApp

We use the contact details you provide to communicate with you about your project — clarifying briefing details, confirming revisions, and delivering results.

Where you provide a WhatsApp number, communication takes place via WhatsApp Ireland Limited, 4 Grand Canal Square, Dublin, Ireland. Message content is end-to-end encrypted; however, metadata is processed by WhatsApp under its own privacy policy: https://www.whatsapp.com/legal/privacy-policy-eea


Legal basis: Art. 6 (1) (b) GDPR (performance of the contract). If you prefer not to be contacted via WhatsApp, please tell us and we will communicate by email only.

We will only send you promotional messages if you have given separate, explicit consent (Art. 6 (1) (a) GDPR). You may withdraw that consent at any time with effect for the future, without affecting the lawfulness of processing carried out beforehand.


6. Payment processing

For payment processing we use:

Stripe Payments Europe, Limited 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, Ireland

When you initiate a payment, you are directed to a payment page hosted by Stripe. Your payment details — card number, security code and similar — are entered exclusively with Stripe; we do not receive complete payment data. From Stripe we receive:

  • Name and email address

  • Billing address, where collected

  • Amount, currency, time and status of the payment

  • The last four digits of the card number and the card type

Legal basis: Art. 6 (1) (b) GDPR (performance of the contract).

Stripe may transfer data to Stripe, Inc. in the United States. Such transfers take place on the basis of the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. Further information is available in Stripe's privacy policy: https://stripe.com/privacy


7. Cookies

We use both strictly necessary cookies and, with your consent, analytics and advertising cookies. Full details, including providers, purposes and retention periods, are set out in our Cookie Policy.


8. Your rights

You have the right at any time to:

  • Obtain information about the data stored about you (Art. 15 GDPR)

  • Request rectification of inaccurate data (Art. 16 GDPR)

  • Request erasure of your data (Art. 17 GDPR)

  • Request restriction of processing (Art. 18 GDPR)

  • Request data portability (Art. 20 GDPR)

  • Object to processing (Art. 21 GDPR)

  • Withdraw consent you have given at any time (Art. 7 (3) GDPR)

To exercise these rights, an email to [E-POSTA ADRESİ] is sufficient.


9. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Berliner Beauftragte für Datenschutz und Informationsfreiheit Alt-Moabit 59-61, 10555 Berlin, Germany https://www.datenschutz-berlin.de


10. SSL/TLS encryption

For security reasons, this site uses SSL or TLS encryption. You can recognise an encrypted connection by the browser address bar changing from "http://" to "https://".


11. Changes to this privacy policy

We reserve the right to amend this privacy policy so that it always complies with current legal requirements.


Last updated: 08,2026