Privacy Notice
Effective date: 26 August 2026 Version: 2.0 Applies to: monneva.com and all forms, e-mail and correspondence connected to it
At a glance
If you read nothing else, this is the substance of it.
| Question | Answer |
|---|---|
| Who holds your data? | Oz Ra Tekstil İhracat, trading as MONNEVA — Denizli, Türkiye |
| What do we collect? | Your name, business e-mail, company, and what you want quoted |
| Why? | To prepare your quotation. Nothing else |
| On what legal basis? | Steps taken at your request before entering into a contract (GDPR Art. 6(1)(b)) |
| Do we sell it? | No. Never, to anyone |
| Do we track you for advertising? | No. We hold no advertising account and run no profiling |
| Where is it stored? | Servers in Germany (EU); accessed by us from Türkiye |
| How long? | 24 months, unless we do business together |
| Can you have it deleted? | Yes — write to [email protected], we answer within 30 days |
| Payment data? | We collect none. There is no checkout on this site |
The sections below set all of this out in full, as the law requires.
1. Who we are
MONNEVA is the brand under which the company below manufactures and sells made-to-order hospitality and promotional textiles.
| Data controller | Oz Ra Tekstil İhracat, trading under the brand MONNEVA |
| Address | Kuşpınar Mah. Muammer Aksoy Cd. No 11/8, 20150 Pamukkale / Denizli, Türkiye |
| [email protected] | |
| Telephone | +90 536 921 80 66 |
We are established in Türkiye. Because we offer our products to businesses in the European Economic Area and the United Kingdom, we apply the EU General Data Protection Regulation (GDPR) and the UK GDPR alongside Turkish Law No. 6698 on the Protection of Personal Data (KVKK). Where these frameworks differ, we apply the stricter standard.
2. What this notice covers — and what it does not
monneva.com is a business-to-business quotation site. It has no shopping cart, no checkout and no payment function. We therefore never collect, process or store:
- payment card numbers, bank details or any financial account data
- national identity numbers, passport data or identity documents
- special category data as defined in GDPR Article 9 (health, biometrics, religious or political beliefs, trade union membership, sexual orientation and similar)
- data relating to children — our services are directed exclusively at businesses
There is no user registration on this site. We do not sell, rent or trade personal data, and we do not use it for advertising networks or profiling.
3. What we collect
3.1 Information you give us
When you submit the Request a Quote form, or when you contact us by e-mail, telephone or WhatsApp, we receive:
| Data | Necessary? |
|---|---|
| Name and surname | Yes — we need to know who we are replying to |
| Business e-mail address | Yes — this is how the quotation is delivered |
| Company name and country | Yes — pricing, minimum quantities and shipping depend on it |
| Telephone number | Optional |
| Product category, quantity and technical specification | Yes — this is the substance of your enquiry |
| Free-text notes | Optional |
If you choose not to provide the fields marked necessary, we will not be able to prepare a quotation. There is no statutory obligation to give us this information; providing it is entirely your decision.
3.2 Information collected automatically
- Security and server logs: IP address, browser and device type, requested pages, timestamps. Used to detect attacks and diagnose faults.
- Analytics: aggregated visit statistics through Google Analytics 4. This runs only if you accept analytics cookies. If you decline, no analytics script is loaded at all. We hold no advertising platform account, Google Signals is disabled, and we use neither remarketing, audience sharing nor cross-device tracking. See our Cookie Policy.
- Bot protection: our quotation form is protected by Cloudflare Turnstile, which performs an invisible check to distinguish humans from automated scripts. It presents no puzzle and requires no action from you.
4. Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR) | Legal basis (KVKK) |
|---|---|---|
| Preparing and sending your quotation; answering your enquiry | Art. 6(1)(b) — steps taken at your request before entering into a contract | Art. 5(2)(c) — necessary for a contract |
| Managing the enquiry through its lifecycle (revisions, cancellation, archiving) | Art. 6(1)(b) | Art. 5(2)(c) |
| Keeping the site secure; preventing fraud and automated abuse | Art. 6(1)(f) — our legitimate interest in protecting our systems and your data | Art. 5(2)(f) — legitimate interest |
| Retaining commercial records where a business relationship results | Art. 6(1)(c) — legal obligation | Art. 5(2)(a) — expressly provided by law |
| Understanding how the site is used | Art. 6(1)(a) — your consent | Art. 5(1) — explicit consent |
Where we rely on legitimate interest, we have weighed that interest against your rights and concluded it does not override them: the processing is limited to security and abuse prevention, involves no profiling, and produces no decision about you.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out beforehand.
We do not carry out automated decision-making or profiling that produces legal effects for you. Every quotation is prepared by a person.
5. Where your data is held
Your data is processed through the service providers below. All of them act as processors on our documented instructions and may not use your data for their own purposes.
| Category of recipient | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH — hosting | Running the website and database | Germany (EU) |
| Migadu — e-mail | Delivering your enquiry and correspondence | Switzerland |
| Cloudflare — infrastructure, security, backups | Attack filtering, encryption, off-site backups | Global infrastructure |
| Google — analytics | Aggregated visit statistics — only with your consent | United States |
Our servers are located inside the European Union. You may request a copy of the safeguards and data processing agreements in place at [email protected].
The record of your enquiry exists in more than one location: the website database, the mailbox and the backups. This protects against data loss if one location fails; where you ask for erasure, all locations are cleared together.
6. International transfers
Your data is transferred outside the EEA in three ways:
- Hosting (Germany). Site data is held on servers inside the European Union. This transfer is necessary to handle your enquiry.
- Analytics (United States). Aggregated statistics are processed only if you accept analytics cookies. If you decline, this transfer does not occur at all.
- Türkiye. We are established in Türkiye and our staff access enquiries from there.
Türkiye has not received an adequacy decision from the European Commission. This transfer is therefore made under GDPR Article 49(1)(b): it is necessary for the performance of a contract with you, or to take steps at your request before entering into one. Put simply — we cannot prepare your quotation without reading your enquiry. The transfer is limited to what that requires.
You may request further information about the safeguards in place using the contact details in Section 1.
7. How long we keep it
| Record | Retention period |
|---|---|
| Quotation enquiry and related correspondence, no business relationship | 24 months from last contact |
| Records where a business relationship followed | 10 years from the end of that relationship — required by Turkish commercial legislation |
| Security and server logs | 6 months |
| Analytics data | Maximum 14 months |
At the end of the applicable period the record is deleted or irreversibly anonymised. Deletion covers every location where the data is held, including the e-mail copy. We run this review at fixed six-month intervals. The full list of locations, disposal methods and procedure is set out in our Data Retention and Disposal Policy.
A note on backups: if you ask us to erase your data, we delete it from live systems immediately and it disappears from backups as those expire within 30 days. We do not restore deleted data from backups.
8. Your rights
Under the GDPR and the KVKK you have the right to:
- be informed about how your data is used — that is the purpose of this notice
- access the personal data we hold about you and obtain a copy
- have inaccurate data corrected, and incomplete data completed
- have your data erased where there is no continuing legal basis to keep it
- restrict processing while a dispute about accuracy or legitimacy is resolved
- object to processing carried out on the basis of legitimate interest
- receive your data in a portable, machine-readable format
- withdraw consent at any time, where processing rests on consent
- not be subject to a decision based solely on automated processing — we do not carry out such processing
- lodge a complaint with a supervisory authority
Under the KVKK you additionally have the right to learn whether your data has been processed, to be told to whom it has been transferred, to have corrections notified to those recipients, and to claim compensation for damage arising from unlawful processing.
How to exercise them. Write to [email protected], or use our Data Subject Request Form. We reply within 30 days. There is no charge; we will only make one if a request is manifestly unfounded or excessive, and we will tell you before doing so. We may ask for information to confirm your identity — this protects you from someone else obtaining your data.
If you are not satisfied. In the EEA you may complain to the data protection authority of your country of residence, work or of the alleged infringement. In the UK, to the Information Commissioner's Office. In Türkiye, to the Personal Data Protection Authority (Kişisel Verileri Koruma Kurumu). You may complain without contacting us first, though we would prefer the chance to put things right.
9. How we protect your data
Security is not a claim we make in the abstract, so here is what is actually in place:
- The site is served exclusively over encrypted connections; unencrypted access is refused. Encryption is enforced on both legs — visitor to edge, and edge to origin server.
- The server sits behind two independent firewalls. Administrative access is restricted to a single authorised address and requires a cryptographic key; password login and direct root login are disabled.
- Repeated failed login attempts are blocked automatically.
- Known WordPress information-disclosure routes — user enumeration, author archives, legacy remote interfaces — have been closed and verified by measurement.
- Backups are encrypted in transit, integrity-checked after every upload, and restoration has been tested on a live system rather than assumed.
- Access to enquiry records is limited to authorised personnel with individual accounts.
- E-mail is authenticated with SPF, DKIM and DMARC, so no third party can send messages that appear to come from monneva.com.
One honest limitation. E-mail is encrypted while in transit but not end-to-end. This means that while a message is stored on a mail server, the provider is technically capable of accessing it. This is true of all standard e-mail — ours included — and we prefer to state it rather than imply a protection that does not exist. For this reason, the authoritative and permanent record of your enquiry is held in our own system, not in an e-mail inbox, and we ask that you do not send us information by e-mail that you would not want stored on a mail server.
10. Data breaches
If a breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and we will inform you directly without undue delay where the risk is high. As at the date of this notice, no personal data breach has occurred.
11. Changes to this notice
We will update this notice when our processing changes. The version number and effective date at the top always show the current version. Where a change materially affects your rights, we will draw attention to it on the site rather than relying on you to notice.
12. A note on business contacts
You may be reading this on behalf of a company rather than for yourself. Data protection law does not distinguish: your name, your work e-mail address and your direct line are your personal data even when they identify you in a professional capacity. Every right in Section 8 belongs to you personally, and you may exercise it without your employer's involvement.
Information that identifies only the company — its trading name, registered address, VAT number, catalogue requirements — is not personal data and falls outside this notice.
13. Links to other websites
Our site may link to third-party websites, including social media platforms. Once you follow such a link, your data is handled under that site's own terms and this notice no longer applies. We have no control over, and accept no responsibility for, the privacy practices of sites we do not operate.
14. Version history
| Version | Date | What changed |
|---|---|---|
| 1.0 | 26 August 2026 | First publication |
| 2.0 | 26 August 2026 | Summary layer added; recipients named individually; business-contact and third-party link sections added; version history introduced |
We keep every superseded version. If you need to see the notice that was in force on a particular date, ask us and we will send it.
15. Contact
Questions about this notice, or about how your data is handled, go to [email protected]. We have not appointed a Data Protection Officer, as our processing does not meet the thresholds that would require one; enquiries are handled by the company management at the address in Section 1.