Privacy Policy and Personal Data Notice
This document explains for what purposes and on what legal grounds your personal data is processed when you use nataliakangotan.com and its online grooming courses, who that data is shared with, how long it is kept, and what rights you have under Turkish Law No. 6698 on the Protection of Personal Data (KVKK); the site's privacy policy and its KVKK notice are combined into a single document.
| PROVIDER / DATA CONTROLLER | GROOMIMI EVCİL HAYVAN ÜRÜNLERİ VE BAKIMI İTHALAT İHRACAT TİCARET LİMİTED ŞİRKETİ |
|---|---|
| WEBSITE | https://nataliakangotan.com |
| PUBLICATION DATE | 6 September 2026 |
| DOCUMENT STATUS | translation of the Turkish master text • privacy policy and KVKK notice • version 1.0 |
1. The data controller and the scope of this document
1.1. The data controller is GROOMIMI EVCİL HAYVAN ÜRÜNLERİ VE BAKIMI İTHALAT İHRACAT TİCARET LİMİTED ŞİRKETİ (the «Provider»). Tax office: Alanya; tax number: 4111017047; address: Şekerhane Mah., Kaptanoğlu Sk., Alkan Apt. No: 9/A, Alanya/Antalya, Türkiye; telephone: +90 552 485 5884; e-mail: [email protected].
1.2. This document covers the personal data processed when you visit the site, create a user account, use the cart and payment steps, the student cabinet, the lesson player and the lesson materials, and when the Provider sends you transactional e-mails. Third-party sites reached through links on this site are governed by their own privacy documents.
1.3. For sales terms, the right of withdrawal and the access period, see the Distance Sales Agreement; for the details of cookies, see the Cookie Policy. This document complements those texts.
1.4. Registration status in the data controllers' registry (VERBİS): [TO BE COMPLETED: whether the Provider is required to register with VERBİS and, if so, its registry number].
2. The personal data processed and where it comes from
2.1. Account data
Collected directly from you when you complete the registration form and use the profile page:
- full name and e-mail address (mandatory at registration);
- only the bcrypt hash of your password — the password itself is never stored in the database in clear text;
- a telephone number, if you choose to add one to your profile;
- interface language (tr / ru / en), account role (student or administrator), the e-mail verification timestamp and the technical token behind the «remember me» feature.
2.2. Order and payment data
Collected from you at the payment step and from the payment provider's notification:
- order number, the names and prices of the courses ordered, subtotal, discount, total amount and currency;
- order status (pending, paid, failed, cancelled, refunded), the payment method chosen, the transaction reference at the payment provider and the payment date;
- the billing/contact details you enter at the payment step: full name and telephone number;
- the transaction data reported by the payment provider (amount, currency, payment type, number of instalments, result code and reason).
Card details — card number, expiry date, CVV — never reach this site at any stage; they are entered directly on the payment provider's own page or frame and are neither seen nor stored by the Provider.
2.3. Learning and usage data
Generated automatically when you buy a course and watch lessons:
- the courses you are enrolled in, the access expiry date (6 months from payment), the completion date and the progress percentage;
- per lesson, the last viewing position (in seconds), the time watched and whether the lesson has been completed — this record exists so that you can resume where you left off and so that completion can be verified;
- the certificate number and its issue date, where a certificate has been issued.
2.4. Technical data and logs
Generated automatically as you use the site:
- session record: session identifier, your user identifier if any, IP address, browser identification string (user agent), last activity time and session content (for example the course identifiers in your cart). Sessions are stored in the database on the server, not in your browser;
- server and application logs: error records, the recipient address when an e-mail cannot be delivered, the request IP address of a payment notification with an invalid signature, and payment start-up errors;
- request counters kept on the password-reset and certificate-verification forms to prevent abuse (based on a hash of the e-mail address and the IP address).
2.5. Correspondence data
The name, contact details and message content you provide when you contact us by e-mail or telephone.
2.6. Data that is not collected
The site does not request and does not intend to process special categories of personal data such as health data, biometric data, religious belief or membership; please do not include such information in support correspondence. The site does not track visitors for profiling or advertising purposes.
2.7. Administrator activity
Lesson videos are uploaded by the Provider's staff through the admin panel; the upload record keeps the uploading user, the original file name, the file size and the processing status. These records concern the Provider's staff, not students.
3. Purposes of processing
- creating your user account, authenticating you and maintaining your session;
- taking your order, starting the payment and confirming its result, and opening 6 months of access to the digital product you bought;
- playing lesson videos only to an entitled student, resuming playback where you left off, and delivering lesson materials;
- verifying completion, issuing a certificate and allowing a certificate to be checked by its number;
- sending transactional e-mails about account creation, a new password, and order and access information;
- handling requests, questions, complaints, withdrawal and refund applications;
- meeting record-keeping and retention obligations under accounting, tax and consumer legislation, and responding to requests from competent authorities;
- keeping the site and the payment flow secure, preventing fraud and abuse, and diagnosing technical faults;
- sending commercial electronic messages only where you have given explicit consent (no such messages are sent today).
4. Legal grounds (KVKK article 5)
4.1. Directly related to the conclusion or performance of a contract (art. 5/2-c): account data, order and payment data, access and progress records, certificate data and transactional e-mails.
4.2. Necessary for the controller to fulfil its legal obligations (art. 5/2-ç): retaining financial records and order and payment documents for the periods required by legislation, and providing information to competent public authorities.
4.3. Necessary for the establishment, exercise or protection of a right (art. 5/2-e): keeping records relating to disputes, objections, withdrawal and refund claims.
4.4. Legitimate interests, provided the fundamental rights and freedoms of the data subject are not harmed (art. 5/2-f): session and error logs, rate-limiting counters, signature verification of payment notifications, continuity and security of the service, and the ability to verify a certificate by its number.
4.5. Explicit consent (art. 5/1): only for marketing commercial electronic messages and for running any non-essential cookie or analytics tool that may be added in the future. Explicit consent may be withdrawn at any time; withdrawal does not invalidate processing carried out beforehand.
4.6. No processing of special categories of personal data is envisaged; if such data is sent to us by you, KVKK article 6 applies.
5. Cookies and similar technologies
5.1. The site uses strictly necessary cookies: the session cookie that carries your session, the XSRF-TOKEN cookie that protects forms, and the remember-me cookie created if you tick that box on the login screen. Session content is held in the database on the server, not in your browser.
5.2. As of today no Google Analytics, Meta pixel or comparable measurement or tracking tool is installed on the site; the «head scripts» field in the admin panel is empty. If such a tool is added, this document and the Cookie Policy will be updated and explicit consent will be obtained where required.
5.3. The site's fonts are loaded through Google Fonts, and the promotional video on the home page opens in a YouTube frame only after you press play. In both cases your IP address and browser information reach Google, and YouTube may set its own cookies.
5.4. For details, see the Cookie Policy.
6. Who personal data is shared with
6.1. Payment service providers. Payment takes place off this site, in the payment provider's own infrastructure. When the PayTR infrastructure is used (Turkish and international cards), your full name, e-mail address, telephone number, address field, the IP address you are using at the time, the basket contents and the amount are transmitted to the payment provider. When the Turinvoice infrastructure is used (payment methods for the Russian market), the order number, amount and currency are transmitted. In both cases card details are entered only on the payment provider's page and never reach this site.
6.2. E-mail (SMTP) provider. Transactional e-mails are sent through the SMTP server configured for the site's domain, so your e-mail address and the content of the message are processed by that e-mail service provider. [TO BE COMPLETED: the trade name of the e-mail/SMTP service provider and the country its servers are in].
6.3. Hosting and infrastructure. The site, the database, the lesson videos and the materials are held on a hosting provider's servers. [TO BE COMPLETED: the trade name of the hosting provider and the country the servers are in]. Site traffic also passes through a CDN/security service. [TO BE COMPLETED: the trade name and country of the CDN/security provider — a technical review found Cloudflare in use; this must be confirmed against the contract].
6.4. Google. Because of the fonts and the promotional video, the technical data described in 5.3 is transferred to Google.
6.5. Professional advisers and public authorities. The Provider's accountant, legal counsel where needed, and competent public authorities making requests under applicable legislation.
6.6. Certificate verification. The certificate verification page is public: when a valid certificate number is entered, the holder's full name, the course name and the issue date are displayed. This exists so that third parties can confirm a certificate; the page offers no search or listing — only a certificate whose number is already known can be looked up.
6.7. Your personal data is never sold, rented out, or transferred to third parties for advertising purposes.
7. Transfers abroad
7.1. Because of the font and video services described in 5.3 and 6.4, your IP address and browser information are transferred to Google servers outside Türkiye.
7.2. If the hosting, e-mail and CDN servers are located outside Türkiye, the data processed through those services is also transferred abroad. [TO BE COMPLETED: the scope of transfers abroad once the server locations of the providers named in 6.2 and 6.3 are confirmed].
7.3. With the payment method aimed at the Russian market, order data is transmitted to that payment infrastructure. [TO BE COMPLETED: the legal name of the entity operating the Turinvoice service, the country where it is established and the basis for the transfer].
7.4. Transfers abroad are made on the basis of your explicit consent or of the safeguards provided in KVKK article 9 (adequacy decision, standard contract, written undertaking and similar). [TO BE COMPLETED: which transfer mechanism the Provider relies on and, if applicable, the date it was notified to the Board].
8. Retention periods
8.1. Personal data is kept for as long as it is needed for the purpose it was processed for, and never beyond the maximum periods set by legislation; once the purpose has ceased, the data is deleted, destroyed or anonymised.
8.2. Account, enrolment and progress data is kept for as long as your account exists. [TO BE COMPLETED: how long account, enrolment and lesson-progress data is kept after the account is closed or the last access period ends].
8.3. Order, payment and invoice records are kept for the book and document retention periods required by commercial and tax legislation. [TO BE COMPLETED: the exact retention period to be set with the Provider's accountant on the basis of the Turkish Tax Procedure Law and the Turkish Commercial Code].
8.4. Session records are cleared by the system once the session expires (the application is configured with a 120-minute inactivity period).
8.5. Server and application logs are kept for security and fault investigation. [TO BE COMPLETED: the retention period for log records].
8.6. You can delete your account yourself on the profile page. Deleting the account also removes the order and enrolment records linked to it from the system. [TO BE COMPLETED: how records that legislation requires to be retained will be kept once an account has been deleted].
9. Security measures
9.1. The whole site is served over HTTPS; unencrypted connections are redirected to the secure address.
9.2. Passwords are stored in the database only as a bcrypt hash; no clear-text password is retained.
9.3. Lesson videos are hosted on the Provider's own server rather than on a third-party platform, and are played only through signed, time-limited links. Every request re-checks your session and whether you hold a valid enrolment in the course concerned.
9.4. Lesson materials are held in a private directory that the web server cannot reach directly; files are served only through a download address that enforces an access check, and are marked so that shared caches do not keep a copy.
9.5. Only accounts with the administrator role can reach the admin panel; forms are protected against CSRF; password-reset and certificate-verification requests are rate-limited; notifications from payment providers are not processed unless they pass signature or secret-key verification.
9.6. Passwords sent by e-mail. To be clear about this: when registration is completed, the system sends the password you chose back to you in the welcome e-mail; and in the «forgot my password» flow the server generates a new password, sets it on your account and sends it in plain text inside the e-mail. E-mail is not a secure channel. We therefore recommend that after logging in you delete those e-mails from your mailbox, change your password, and never reuse that password on any other service.
9.7. Despite these measures, no transmission or storage over the internet is 100 % secure; the Provider undertakes to apply reasonable and up-to-date technical and organisational measures to the systems under its control.
10. Commercial electronic messages and explicit consent
10.1. As of today the site sends transactional e-mails only: notice that the account has been created together with the login details, a new password, and order and access information. No newsletter, campaign or advertising message is sent.
10.2. The «unsubscribe» link at the foot of those transactional e-mails displays a confirmation page; because these messages are necessary to deliver the service and to keep your account secure, they continue to be sent for as long as the service lasts.
10.3. If marketing commercial electronic messages are introduced in the future, they will be sent only on the basis of explicit consent obtained in advance; every message will carry a working opt-out and the records required by legislation will be kept. [TO BE COMPLETED: if marketing messages are launched, registration with the Message Management System (İYS) and how consent will be collected].
11. Rights of the data subject (KVKK article 11)
Anyone whose personal data is processed may apply to the Provider and request:
- to learn whether their personal data is being processed;
- to request information about that processing, where it has taken place;
- to learn the purpose of the processing and whether the data is used in line with that purpose;
- to know the third parties in Türkiye or abroad to whom the data has been transferred;
- to request that incomplete or inaccurately processed data be corrected;
- to request erasure or destruction of the data under the conditions set out in KVKK article 7;
- to request that corrections, erasures and destructions be notified to the third parties the data was transferred to;
- to object to an adverse outcome reached by analysing the data exclusively through automated systems;
- to claim compensation for damage suffered as a result of unlawful processing.
12. How to exercise these rights
12.1. You may send your application in writing to Şekerhane Mah., Kaptanoğlu Sk., Alkan Apt. No: 9/A, Alanya/Antalya, or by e-mail to [email protected] from the address registered on your account. The application should clearly state your full name, contact details, the subject of the request and, where relevant, your order number.
12.2. Requests are concluded as quickly as their nature allows and in any event within 30 (thirty) days of the application reaching the Provider. Where responding involves an additional cost, a fee set out in the tariff published by the Personal Data Protection Board may be charged.
12.3. If your application is rejected, the answer you receive is inadequate, or no answer is given in time, you may complain to the Personal Data Protection Board within 30 days of learning of the answer and in any event within 60 days of the date of your application.
12.4. Some rights can be exercised directly from your account: on the profile page you can update your name, e-mail address and telephone number, and delete your account.
13. Personal data of minors
13.1. The site is intended for people aged 18 or over. People under 18 may order only with the approval of their legal representative; this matches clause 1.2 of the Distance Sales Agreement.
13.2. Age is not verified technically; the declaration made at registration and at checkout is relied upon.
13.3. If it emerges that the data of a person under 18 has been processed without the approval of a legal representative, the account and data concerned will be deleted within a reasonable time. Please send any such notice to [email protected].
14. Changes and entry into force
14.1. This document was published on 6 September 2026 as version 1.0 and applies from the moment of publication.
14.2. It is updated when legislation changes, new services are introduced or the providers used change; the current version is always published on this page, with the publication date and version number shown in the table above.
14.3. Where there is a material change in the data processed or in the parties data is shared with, registered users are informed by e-mail.
15. Data controller details
| Trade name | GROOMIMI EVCİL HAYVAN ÜRÜNLERİ VE BAKIMI İTHALAT İHRACAT TİCARET LİMİTED ŞİRKETİ |
|---|---|
| Tax office | Alanya Tax Office (Alanya Vergi Dairesi) |
| Tax number | 4111017047 |
| Address | Şekerhane Mah., Kaptanoğlu Sk., Alkan Apt. No: 9/A, Alanya, Antalya, Türkiye |
| Phone | +90 552 485 5884 |
| [email protected] | |
| Website | https://nataliakangotan.com |