GDPR & KVKK COMPLIANT

Privacy and Personal Data Protection Policy

Last Updated: October 2026•Dijital Departman Compliance

Digital Department ("We", "Agency"), operating as a Fractional Digital Operations Agency, is strictly committed to protecting the privacy, confidentiality, and integrity of your data in full compliance with GDPR and applicable international regulations.

1. Data Controller & Scope

This Privacy Policy applies to all digital interaction points operated by Digital Department, including our website, fractional operations consultation, e-commerce management, digital audit tools, and booking channels.

We act as the Data Controller with respect to personal information gathered through our public forms and consultation workflows.

2. Information We Collect

Identity & Contact Details: Full name, business email, phone number, company name, and official website URL.

Operations Scope: E-commerce platforms utilized (Shopify, WooCommerce, ikas, etc.), marketplace channels (Amazon, eBay, etc.), and operational scope required.

Discovery & Audit Notes: Consultation briefs and discovery session notes logged via our online scheduling calendar system.

Technical & Browsing Data: Anonymized IP addresses, browser specifications, session duration, and essential performance cookies.

3. Purposes of Processing

Conducting 30-minute digital operations audits and delivering actionable operational health reports.

Formulating tailored fractional retainer agreements and executing dedicated digital workflow tasks.

Scheduling discovery conferences, sending calendar reminders, and delivering operational SLA updates.

Fulfilling statutory accounting, tax, and legal obligations.

4. Client Infrastructure Access & Security Protocols

Strict Least-Privilege Access: Delegated credentials to client store backends, marketplace APIs, or ad accounts are strictly confined to the exact operational tasks required, reinforced with mandatory Multi-Factor Authentication (MFA).

Payment & Cardholder Data Isolation: Digital Department NEVER has access to, processes, or stores your end-customers credit card numbers, CVVs, or bank secrets. All transactions are securely routed through PCI-DSS certified payment gateways.

Encrypted Architecture: All communication and data transfer channels are secured with modern TLS 1.3 protocol standards.

5. Third-Party Disclosures

We do not sell, rent, or trade your personal or business data to any third-party marketing entities under any circumstances.

Data is only processed with trusted technical infrastructure providers (such as secure scheduling infrastructure and cloud hosting) bound by strict confidentiality terms.

6. Data Subject Rights (GDPR & KVKK)

You hold the right to access, rectify, or request the deletion of your personal data at any time.

To exercise your rights, contact our privacy team at destek@digitaldepartman.com.tr. Requests are processed within 30 days without fee.

Need an NDA or Custom Data Processing Agreement?

We sign formal reciprocal non-disclosure agreements before reviewing store databases or marketing dashboards.