VENOXIS / LEGAL
Privacy notice
How Venoxis handles enquiries, business contacts, accounts and project information.
Service provider and data controller
Özcan Hacımustafaoğlu – Mythra Craft
Seyrani Mah, Bekir Yıldız Blv, Bademaltı Sk, No: 162/A, 38040 Kocasinan/Kayseri, TürkiyeTax office / tax number: Gevher Nesibe / 4540344464
Contact and privacy requests
Use our contact form or write to the postal address above. For privacy requests, identify the request and your relationship with us. We may request proportionate verification through a secure channel; do not send passwords, card details or identity documents through the public form. Let’s talk
Updated: 2026-10-05
Customer reviews and publication
If you submit a review, we store its text, star rating, chosen public display name, optional company name, language, related project/account and publication permission. Only reviews with documented permission and administrator approval are shown publicly. The review, rating and public name/company become accessible on the Internet; others may copy or index them. Publication permission is separate from the service contract and can be withdrawn in Customer reviews in your workspace, or by contacting us; administrator-entered feedback requires documented permission. Withdrawal removes the review from our public display and clears publication permission, but is not automatic deletion of the internal record. We cannot directly erase copies held by independent third parties. Ask through the privacy contact route for correction or erasure; the provider evaluates applicable deletion duties and any limited retention needed for moderation, permission disputes or legal claims. Restricted records are not republished without valid permission.
Who is responsible
Özcan Hacımustafaoğlu – Mythra Craft · Seyrani Mah, Bekir Yıldız Blv, Bademaltı Sk, No: 162/A, 38040 Kocasinan/Kayseri, Türkiye. Venoxis is the public brand of this Türkiye-based provider. We act as controller for our own enquiries, business development, accounts, service administration and billing records. A customer normally controls personal data on its own website; our processor duties are covered by the agreed project and data-processing terms.
Information, sources and purposes
You provide your name, email, optional business name, service interest and message when making an enquiry. Invited accounts use contact details, password hashes, role permissions, authentication/session records and security activity. Business operations can include publicly available business contacts, call notes, availability, meeting records, project files, revisions, support, proposals and invoice/payment status. Website requests can produce IP addresses, user-agent information and security logs. We use these records to answer requests, negotiate and deliver services, manage access, keep records and prevent abuse. We do not collect payment-card details on this website. Do not submit health, biometric, payment or other sensitive information in public forms.
Legal grounds
Under Turkish Law No. 6698, processing is based, as appropriate, on necessity to establish or perform a contract directly related to its parties, legal obligations, establishment/exercise/protection of a right, or legitimate interests balanced against individual rights. Public business data is used only consistently with the purpose for which it was made public; public availability is not blanket permission. Where an activity needs consent, that consent is requested separately and may be withdrawn without affecting earlier lawful processing. An enquiry is not marketing consent.
Recipients and international processing
Authorized personnel access records according to their duties. DigitalOcean provides hosting infrastructure in New York, United States; authorized administration takes place from Türkiye. Service providers process only data needed for their work under applicable arrangements. We may disclose necessary information to professional advisers or competent authorities when lawful. Data is not sold or shared for cross-site advertising. Hosting or access outside Türkiye is an international transfer: the applicable Article 9 safeguard must be established before regular transfers; this notice and a cookie choice do not themselves create that safeguard. Details of the applicable arrangement may be requested using the contact route above.
Retention and security
Records are kept only as long as their purpose, the active service relationship, a legal record-keeping duty or a legitimate claim requires. Unneeded enquiries and research are reviewed for deletion; security logs and backup copies are subject to limited operational retention and access. A legal hold may temporarily prevent deletion. Account permissions, password hashing, staff two-step authentication and restricted file access protect records; no system is absolutely secure.
Your rights and requests
Under KVKK Article 11 you may ask whether data is processed, obtain information about it, learn purposes and recipients, request correction, erasure/destruction when conditions apply and notification to recipients, object to an adverse result based solely on automated analysis, and seek compensation for unlawful processing. Send a request through the contact form or the postal address above. We provide the applicable formal submission/verification requirements and respond within the legal period, ordinarily no later than 30 days under KVKK. You may complain to the Turkish supervisory authority under the statutory procedure.
Other jurisdictions and updates
Where EU/UK or US-state law applies to a particular activity, its additional access, objection, restriction, portability, deletion or appeal rights remain available as applicable; a contract cannot waive mandatory protection. The site is aimed at business services and does not knowingly seek information from children. We do not make decisions with legal or similarly significant effect solely through automated profiling. Material changes are reflected in the document version; new consent is sought when a changed activity requires it.