Privacy Policy
Clarification Text on the Processing of Personal Data
Version: v2026.07.17 — Last updated: 07/17/2026
1. Data Controller
The data controller of your personal data under Law No. 6698 on the Protection of Personal Data is:
Legal name: 9 Dijital Baskı San. Tic. Ltd. Şti.
Brand: DESENIX
Address: Atakent Mah. 221. Sk. Rota Office A Blok No: 3/1 İç Kapı No: 17 Küçükçekmece/İstanbul
Web: desenix.com
Email: [email protected]
Where available, the MERSIS number, tax office/number, and registered e-mail (KEP) address, if any, are shown automatically in this section from the central company settings.
DESENIX is a brand operated by 9 Dijital Baskı San. Tic. Ltd. Şti..
2. Scope of This Clarification Text
This text has been prepared to provide information regarding the processing of personal data of persons who visit the DESENIX website, create an account, review products, place orders, request quotes or samples, upload designs, and use the communication channels.
Personal data is processed only for specific, explicit, and legitimate purposes, and in a manner connected to, limited to, and proportionate with the purpose for which it is processed.
3. Personal Data That May Be Processed
Depending on your use of DESENIX services, the following categories of data may be processed:
Identity Information
- Name and surname
- Company representative information
- Tax identification information required for invoicing
Contact Information
- Email address
- Phone number
- Shipping address
- Billing address
Membership and Account Information
- User account information
- Account creation date
- Favorites and saved designs
- Session and verification information
Customer Transaction Information
- Order number
- Order history
- Cart information
- Return and cancellation requests
- Quote and sample requests
- Customer service records
Product and Production Information
- Selected pattern and pattern code
- Fabric type
- Color variant
- Size and meterage
- Delivery and order notes
Design and File Information
- Designs uploaded by the user
- Reference images, sketches, logos
- Color palettes and technical files
- Work created within the Product Design Studio
Financial Transaction Information
- Payment status
- Collection and refund amount
- Invoice information
- Transaction and reference information obtained from the payment institution
The full credit card number, security code (CVV), and card password are not stored on DESENIX servers; they are transmitted directly to the payment institution during the payment process.
Transaction Security Information
- IP address
- Device and browser information
- Login and logout records
- Security and error logs
Marketing Preferences
- Commercial communication consent
- Email and campaign preferences
- Opt-out records
Legal Transaction Information
- Agreement approvals and the date/time of approval
- Objection, dispute, and legal application records
4. Purposes of Processing Personal Data
Personal data may be processed for the following purposes:
- Creating the user account and verifying identity/contact information
- Receiving and managing orders and recording pattern/fabric/meterage preferences
- Carrying out digital printing and production processes
- Completing payment, collection, invoicing, and accounting transactions
- Preparing and delivering products and managing shipping processes
- Evaluating quote and sample requests and custom design requests
- Generating design codes and facilitating reorder processes
- Protecting the confidentiality of uploaded designs
- Responding to customer support requests
- Carrying out cancellation, return, and dispute processes
- Ensuring system and account security and preventing unauthorized access
- Fulfilling legal obligations and providing information to authorized institutions
- Improving service quality and user experience
- Sending campaign and promotional communications where explicit consent exists
5. Legal Grounds
Depending on the processing activity, personal data is processed based on the following legal grounds:
- Being explicitly provided for in the law
- Being necessary for the establishment or performance of a contract
- Being necessary for the data controller to fulfill its legal obligation
- Being mandatory for the establishment, exercise, or protection of a right
- The data controller's legitimate interest, provided it does not harm the data subject's fundamental rights and freedoms
- The explicit consent of the data subject where required
Confirmation of having read the Privacy Policy, marketing consent, and cookie preference are obtained through independent, separate consents; consent for commercial communication is given separately and explicitly. Consent checkboxes are never pre-checked.
6. Methods of Collecting Personal Data
Personal data may be collected electronically or physically through the following channels:
- Membership and login forms
- Order and payment screens
- Quote, sample, and contact forms
- Design upload areas and the Product Design Studio
- Email correspondence and customer service conversations
- Shipping and delivery transactions
- Payment institution
- Cookies and technical logs
- Authorized transactions in the admin panel
- Legally authorized institutions
7. Confidentiality of Designs and Files
Designs, logos, sketches, images, and technical files uploaded by the user are used solely for the purposes of reviewing the request, carrying out production, fulfilling the order, and facilitating the reorder process.
Custom designs uploaded by the user are not published in the public pattern archive or catalog without your separate, explicit consent.
Custom designs are shared only with the authorized personnel who need access for the order and production process.
When a user requests deletion of their design, the file is deleted or rendered inaccessible unless it needs to be retained for an ongoing order, a legal obligation, or the protection of rights.
8. Transfer of Personal Data
Personal data may be transferred to the following categories of recipients, provided that the transfer is necessary and limited to carrying out the relevant transaction:
- The payment institution and related banks
- Shipping and logistics companies
- Fabric suppliers and printing/production service providers
- Hosting and cloud service providers
- Email service provider
- Legal, audit, and consultancy service providers where necessary
- Authorized public institutions and organizations in the event of a legal requirement
Customer information that is not necessary for fulfilling the order is not transferred to suppliers or production partners; only the pattern, fabric, size, meterage, and delivery information necessary for production is shared.
9. Transfer of Data Abroad
DESENIX uses service providers based abroad for some components while providing its services:
- Database hosting: all personal data is hosted on a cloud-based database service.
- Email delivery: order, account, and notification emails are sent through an email delivery service based abroad; in this context, your email address and the relevant message content are processed.
- Content delivery and security: website traffic is routed through a content delivery and security service (CDN) based abroad; during this process, your IP address and connection metadata may be processed.
The site has a tag management infrastructure (Google Tag Manager); this infrastructure calls a technical script when the page loads, during which your IP address may be transmitted to servers abroad. As of the date this text was prepared, there is no active analytics or marketing tag running through this infrastructure.
These transfers are carried out in accordance with the conditions set out in Article 9 of Law No. 6698, based on your explicit consent, or, where adequate protection does or does not exist in the country to which the personal data is transferred, by providing one of the appropriate safeguards accepted by the Personal Data Protection Board.
10. Retention of Personal Data
Personal data is retained for the period stipulated in the applicable legislation or for the period necessary for the purpose for which it is processed. When the processing purpose and the legal retention obligation end, personal data is deleted, destroyed, or anonymized in accordance with the applicable legislation. The general framework is as follows:
- Membership and account records: for as long as the account is active; retained after the account is closed, subject to the applicable statutory limitation periods.
- Order, cancellation, and return records: for the period necessary to track the order and any potential disputes, subject to the applicable statutory limitation periods.
- Invoice and accounting records: for the period stipulated by the Tax Procedure Law and the Turkish Commercial Code.
- Payment transaction records: for the period necessary to verify the transaction and fulfill legal obligations; records held by the payment institution are subject to their own separate retention period.
- Communication and support records: for the period necessary to resolve the request and track similar requests.
- Designs and uploaded files: for the duration of the order and production process; deleted or rendered inaccessible after the process is complete, unless a legal obligation or a rights-related retention period requires otherwise.
- Security and system logs: for the period necessary to detect security breaches and fulfill legal obligations.
- Marketing consent and opt-out records: until consent is withdrawn or the account is closed; opt-out requests are retained indefinitely to ensure no further contact is made.
11. Cookies and Analytics Data
Necessary cookies may be used for the site's core functions and security. Analytics, performance, and marketing cookies are only run according to the user's cookie preference.
You may review the Cookie Policy page for detailed information on cookie types, their purposes of use, and how you can change your preferences.
You may change your cookie preferences at any time afterward.
12. Commercial Electronic Communications
Campaign, promotional, and marketing messages are sent only where the necessary consent exists.
You may withdraw your commercial communication consent at any time. Withdrawing consent does not affect your membership or the execution of your existing orders.
Order, payment, security, and delivery notifications are not considered marketing messages and are sent independently of commercial communication consent.
13. Special Categories of Personal Data
DESENIX does not request special categories of personal data for the normal use of its services.
Health, biometric, religious belief, political opinion, or similar special categories of personal data should not be uploaded to the design, description, or file upload fields.
If such data is inadvertently transmitted, it will be securely deleted unless there is a legal obligation to retain it.
14. Data Security
DESENIX takes appropriate technical and administrative measures to prevent the unlawful processing of and access to personal data and to ensure that data is stored securely:
- Role-based access control and admin authorization
- Encrypted (hashed) password storage and secure authentication
- Encrypted data transmission (HTTPS)
- Maintaining access and transaction logs
- Regular backups
- File access restrictions and security updates
Despite the measures taken, we remind you that no method of data transmission or storage over the internet can guarantee absolute security.
15. Rights of the Data Subject
Under Article 11 of Law No. 6698, data subjects have the right to:
- Learn whether their personal data is being processed
- Request information regarding the processing, if any
- Learn the purpose of processing and whether the data is used in accordance with that purpose
- Know the third parties to whom the data is transferred domestically or abroad
- Request correction of incomplete or incorrectly processed data
- Request the deletion or destruction of data within the framework of the conditions set out in the law
- Request that correction or deletion be notified to third parties to whom the data has been transferred
- Object to a result that is to their detriment arising from analysis carried out through automated systems
- Request compensation for damages in the event of harm arising from unlawful processing
These rights are held by the data subject.
16. How to Apply
Applications regarding personal data may be made through the following methods:
- The email address [email protected]
- The Contact page on the site
- A written application to the data controller
- An application sent with a secure electronic signature or mobile signature
- The email address the user has previously notified to DESENIX and that is registered in the system
The application should include the following information:
- Name and surname
- Contact information
- Information sufficient to verify identity
- A clear description of the request
No more personal data than necessary is requested for identity verification purposes.
Applications are concluded as soon as possible and within 30 days at the latest, depending on the nature of the request. A reasoned response is given if the application is rejected.
17. Updates to the Policy
This policy may be updated in the event of changes to the applicable legislation or to DESENIX's personal data processing procedures. The current version and update date are shown automatically at the top of the page. Users may be notified through appropriate channels in the event of significant changes.
18. Contact
Data Controller: 9 Dijital Baskı San. Tic. Ltd. Şti.
Brand: DESENIX
Address: Atakent Mah. 221. Sk. Rota Office A Blok No: 3/1 İç Kapı No: 17 Küçükçekmece/İstanbul
Email: [email protected]
Web: desenix.com