How DZDSoft meets the European Union's General Data Protection Regulation — the principles we follow, the roles we play, and the rights we protect. We treat the GDPR as a baseline for good engineering, not a box to tick.
DZDSoft handles personal data with the same care we put into our code. The EU General Data Protection Regulation — Regulation (EU) 2016/679 — sets the standard for how personal data should be collected, used, and protected, and we treat it as a baseline rather than a hurdle.
This statement explains how we meet those obligations — both for the data we control ourselves and the data we process on behalf of clients. It sits alongside our Privacy Policy, which describes the specific personal data we collect through this website.
The GDPR protects people in the European Union and European Economic Area — wherever the organisation processing their data happens to be based. So even though DZDSoft is based in Türkiye, the regulation reaches the personal data of EU and EEA residents that we handle.
Because we serve clients and users across Europe — and work in German alongside Turkish and English — we apply GDPR standards to that data as a matter of course. Where other applicable law adds further protections, we meet those as well.
The GDPR draws a clear line between the controller, who decides why and how personal data is processed, and the processor, who acts only on the controller's instructions. DZDSoft plays both roles, depending on the work:
Article 5 sets out seven principles for processing personal data. They shape every decision we make about data:
Under Article 6, every processing activity needs a lawful basis. We rely on one of the following, and we identify which one applies to each activity:
We do not process special categories of data without an additional condition under Article 9, and we avoid collecting such data altogether wherever we can.
The GDPR gives you strong, enforceable rights over your personal data. You have the right to:
To exercise any of your rights, email us at info@dzdsoft.com with a short description of what you'd like. There's no special form to fill in.
Some of our service providers may process data outside the EEA, and DZDSoft itself is based in Türkiye. Whenever we transfer personal data protected by the GDPR outside the EEA, we make sure an appropriate safeguard under Chapter V is in place — such as an adequacy decision or the European Commission's Standard Contractual Clauses.
The aim is simple: your data should keep an essentially equivalent level of protection wherever it travels. You can ask us about the safeguard for any specific transfer.
We rely on a small number of trusted providers — for hosting, email delivery, and analytics — to run our services. Under Article 28, we only use processors who give sufficient guarantees that they meet the GDPR, and we put a written contract in place with each of them.
When we act as a processor for a client, we apply the same discipline to any sub-processor we engage, and we remain accountable to the client throughout. We don't add or change sub-processors without the controller's knowledge.
Article 25 asks organisations to build data protection in from the start — not bolt it on at the end. As engineers, that's how we prefer to work anyway.
In practice that means designing systems to minimise the personal data they touch, pseudonymising or aggregating data where it's practical, defaulting to the most privacy-protective settings, and limiting access to those who genuinely need it. Privacy is a design constraint we account for before the first line of code, not a feature we add later.
Article 32 requires appropriate technical and organisational measures to keep personal data secure. We use encryption in transit, access controls on a least-privilege basis, monitoring, and regular backups, and we review these measures as systems evolve.
If a personal data breach occurs and is likely to risk people's rights and freedoms, we will notify the relevant supervisory authority without undue delay — and, where feasible, within 72 hours of becoming aware of it. Where the risk is high, we will also inform the affected individuals directly.
Accountability runs through the whole regulation: it isn't enough to comply, you have to be able to show it. We keep records of our processing activities, document the lawful basis and purpose for each, and maintain our data-processing agreements with clients and providers.
We review our practices periodically and update them as our work, our tools, or the law change — so this statement reflects how we actually operate, not how we'd like to look.
For any question about this statement, your rights, or how we handle a particular dataset, contact us at info@dzdsoft.com, by phone on 0 850 840 99 11, or by post at ODTÜ Teknokent, Çankaya, Ankara, Türkiye.
If you are in the EEA, Article 77 also gives you the right to lodge a complaint with your local data protection supervisory authority. We'd genuinely appreciate the chance to put things right first, so please reach out to us before you do.
DZDSoft owns and operates a family of domains and the platforms built on them. They're grouped by area below — the studio itself, our façade-industry platforms, and our data-centre work. Each link opens in a new tab. An accent dot marks the primary, live platform in each group; the remaining entries are supporting or defensively registered domains, so not all of them host a live site yet.
All of the domains listed above, the websites and software built on them, and their source code, designs, databases, and content are the exclusive property of DZDSoft. All intellectual-property rights in them — including copyright, trademarks, database rights, and any patents or patentable inventions — are reserved by DZDSoft. Nothing on these properties transfers any such right to a visitor or user.
This GDPR Statement applies directly to personal data that DZDSoft processes across these domains and platforms. Where a specific platform publishes its own privacy or GDPR notice, that notice governs for that platform, and this Statement applies to anything it does not cover.
This site uses only essential cookies to keep it running — no tracking, no ads. Cookie Policy