Scope of this notice
This notice explains personal-data processing through the EMC Group website and Contact channel. Turkish Law No. 6698 applies to relevant processing in Türkiye; the GDPR applies where processing is connected with offering goods or services to people in the EU/EEA.
Controller
EMC GROUP GERİ DÖNÜŞÜM MAKİNA İNŞAAT OTOMOTİV VE TİCARET LİMİTED ŞİRKETİ
Verified legal-entity details are published on the Legal Information page. The published privacy email may be used for privacy and data-rights requests.
View legal identityPersonal data processed
Identity and contact
Name, company, email address and, when provided, telephone number.
Technical / commercial enquiry
Subject selection, message content and any project, component, material, geometry, quantity or timing information that you choose to provide.
Communication records
Correspondence and the records needed to review and respond to the request.
Security and transaction
Request identifiers, timestamps, notice reference, security logs and technical data required to prevent abuse.
Do not send special-category personal data or third-party personal data unless it is strictly necessary for the communication and you are authorised to share it.
Purposes and legal bases
- Receive, assess and respond to B2B enquiries and take requested pre-contractual steps where relevant — GDPR Art. 6(1)(b) and/or 6(1)(f), with the applicable conditions under Turkish Law No. 6698.
- Protect website and Contact-channel security, prevent abuse and maintain record integrity — GDPR Art. 6(1)(f) and applicable Turkish-law legitimate-interest or legal-obligation conditions.
- Establish, exercise or defend legal rights and keep necessary records — the applicable GDPR and Turkish-law bases.
- Comply with legally binding requests from competent public authorities — GDPR Art. 6(1)(c) and applicable Turkish-law legal-obligation conditions.
The legal basis depends on the real processing context. Optional analytics or other consent-based processing is handled through a separate preference mechanism.
Recipients and international data flows
Personal data may be accessible to authorised EMC personnel and contracted service providers used in the real production stack where necessary. A person in the EU/EEA submitting data directly to EMC in Türkiye is not, by itself, described as a separate GDPR Chapter V transfer by EMC to another controller or processor. Any disclosure or remote access by a separate third-country service provider is assessed against the real vendor and data flow under the applicable GDPR and Turkish cross-border rules.
Collection method
Data is collected electronically through the contact form, email or telephone correspondence, essential cookies and security logs. Processing may be wholly or partly automated, or non-automated where the data forms part of a filing system.
Data security
Contact records are stored outside public access and are accessible only to personnel authorised for their duties. Historical technical files retained from the retired RFQ period, where retention is legally or operationally required, also remain outside public access.
Your rights
Depending on the law applicable to the processing and its conditions, you may have rights to:
- obtain information about and access to your personal data;
- request rectification of inaccurate or incomplete data;
- request erasure or destruction where the legal conditions are met;
- where the GDPR applies, request restriction of processing and object to processing;
- where the GDPR applies, receive data portability in applicable cases;
- withdraw consent for processing based on consent; lodge a complaint with the competent data-protection authority under applicable law.