Skip to content

Legal

Data Protection Notice

This notice is issued under Article 13 of the GDPR and Article 10 of Turkish Law No. 6698 on the Protection of Personal Data. It tells you how we process the personal data of people who contact us through this website, and what you can do about it.

Updated:

1. Identity of the controller

The controller is [Full registered company name], the company operating the MoonCRM brand, referred to below as “Moon Workshop”.

  • Registered office: Güzeloba Mah. Çağlayangil Cad. Hatice Güleser İş Merkezi No:39 İç Kapı No:104 Muratpaşa/Antalya, Türkiye
  • Email: [email protected]
  • Phone: +90 535 455 32 10
  • Trade registry number: [Trade registry number]
  • MERSIS number: [MERSIS number]
  • VERBIS registration number: [VERBIS registration number]
  • Registered electronic mail (KEP) address: [KEP address]

2. Who this notice applies to

It applies to website visitors, people who complete our contact or demo forms, representatives of customers and prospective customers, and anyone who contacts us by phone or email.

It does not apply to the patient and lead data that customers enter into the MoonCRM application. There, the customer business is the controller and Moon Workshop acts as processor under the subscription agreement.

3. Categories of personal data

No special-category data within the meaning of Article 9 of the GDPR is collected through this website.

Identity
Name, surname and job title where provided.
Contact
Email address, phone number, the name of the company you work for and, where needed, a postal address.
Customer transaction
Enquiry and complaint records, demo and meeting notes, and information relating to any quote prepared for you.
Transaction security
IP address, browser and device information, access times and server log records.
Marketing
Consent records and communication preferences, held only where you have opted in.

4. Purposes of processing

  • Answering enquiries, arranging demos and scheduling meetings
  • Presenting the product, preparing quotes and managing contract processes
  • Delivering onboarding, training and technical support
  • Managing the customer relationship and tracking requests and complaints
  • Maintaining information security and preventing misuse of the site
  • Meeting legal obligations and responding to competent authorities
  • Sending product news and marketing material where you have consented

5. Lawful bases

Each purpose above rests on one of the following bases under Article 6(1) of the GDPR, with the corresponding provision of Article 5(2) of Law No. 6698 applying in Türkiye.

  • Performance of a contract, or steps taken at your request before entering into one (Art. 6(1)(b))
  • Compliance with a legal obligation to which we are subject (Art. 6(1)(c))
  • Our legitimate interests in running and securing our business, where these are not overridden by your rights (Art. 6(1)(f))
  • The establishment, exercise or defence of legal claims
  • Your consent, where none of the above applies (Art. 6(1)(a))

6. How we collect personal data

Data is obtained through these channels by partly automated and partly non-automated means.

  • Contact and demo request forms on the website
  • Correspondence by email, phone and messaging applications
  • Meetings and events, held in person or online
  • System and security logs generated automatically on the server

7. Recipients and transfers

Personal data is shared only where necessary for the purposes above, and only with the following categories of recipient.

  • Hosting and infrastructure suppliers
  • Business email and messaging providers
  • Professional advisers such as accountants, auditors and lawyers
  • Competent public authorities and courts, where there is a lawful request
Transfers outside Türkiye and the EEA
Some suppliers host data outside Türkiye or the EEA. Such transfers are made under Article 9 of Law No. 6698 and, where the GDPR applies, under Chapter V, relying on an adequacy decision or on appropriate safeguards such as standard contractual clauses.

8. Retention and erasure

We keep personal data only as long as the purpose requires, taking statutory limitation periods into account.

  • Enquiries that do not proceed: up to 24 months after the request is closed
  • Records connected to a contract: for the statutory periods following the end of the relationship
  • Transaction security records: a maximum of 2 years
  • Marketing consent records: 3 years after consent is withdrawn

9. Your rights as a data subject

  • Right of access to your personal data and to information about how it is processed (Art. 15)
  • Right to rectification of inaccurate or incomplete data (Art. 16)
  • Right to erasure where the conditions are met (Art. 17)
  • Right to restriction of processing (Art. 18)
  • Right to be informed of rectification, erasure or restriction passed on to recipients (Art. 19)
  • Right to data portability for data you provided (Art. 20)
  • Right to object to processing based on legitimate interests, and to direct marketing at any time (Art. 21)
  • Right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22)
  • Right to withdraw consent at any time, without affecting processing already carried out

10. How to make a request

Requests can be sent to [email protected] or in writing to the registered office. Under the Turkish Communiqué on the Procedures and Principles of Application to the Data Controller, a request should include the following.

  • Your name and surname, and a signature if the request is submitted on paper
  • Turkish ID number for Turkish citizens; nationality, passport number or identity number for others
  • Your address for service, or your place of business
  • Your email address, phone or fax number, if you have one for notifications
  • A clear statement of what you are asking for
  • Any supporting information or documents

11. Channels, response times and complaints

We respond as quickly as possible and within thirty days at the latest. Requests are handled free of charge, unless the action genuinely incurs a cost, in which case a fee set by the supervisory authority may apply.

If your request is refused, our answer is unsatisfactory or we fail to respond in time, you may complain to the Turkish Personal Data Protection Board within thirty days of learning our response and in any case within sixty days of your original request.

In the European Economic Area or the United Kingdom you may also lodge a complaint with the supervisory authority where you live or work, or where the alleged infringement took place.

  • In person or via a notary, with a signed petition, to the registered office above
  • By registered electronic mail (KEP) to [KEP address]
  • By email signed with a secure electronic signature or mobile signature to [email protected]
  • From an email address you have previously registered with us, to [email protected]

12. Updates and disclaimer

This notice may be revised as legislation or our processes change, and the current version is always published on this page.

It is provided for information only and does not constitute legal advice. For a definitive assessment of your own situation, please consult your legal adviser.