Privacy Policy & Legal Notice
Effective Date: February 18, 2026
1. Introduction
EndoGrup ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, process, and protect your information when you visit our website endogrup.com (the "Website") or use our services.
This policy complies with the EU General Data Protection Regulation (GDPR), Turkish Personal Data Protection Law No. 6698 (KVKK), Swiss Federal Act on Data Protection (FADP), and other applicable data protection laws.
By accessing or continuing to use this Website, you acknowledge that analytics, advertising measurement, and security logging technologies may process technical and usage data from the start of your session as part of our service operation, fraud prevention, and performance measurement.
2. Data Controller
Gülbahar
Salih Tozan Sk. No:3
34394 Şişli/Istanbul, Turkey
Email: info@endogrup.com
Phone: +90 506 741 18 57
3. Information We Collect
3.1 Information You Provide Directly
- Contact Forms: Name, email address, subject, and message content
- Training Registration: Name, company name, job title, contact details, and training preferences
- Service Requests: Technical information about equipment requiring repair or service
- WhatsApp Communications: Messages sent via WhatsApp contact links
3.2 Information Collected Automatically
- Log Data: IP address, browser type, operating system, referring URLs, pages visited, and timestamps
- Cookies: Session cookies, preference cookies, and analytics cookies (see Cookie Policy below)
- Analytics Data: Google Analytics data including user behavior, demographics, and interests
- Device Information: Device type, screen resolution, and language preferences
- Visitor Intelligence: For security and service improvement purposes, we collect approximate geographic location (country, region, city), Internet Service Provider (ISP) information, and page visit patterns via server-side processing. This data is derived from your IP address using third-party geolocation services and is stored in secure server logs accessible only to authorized personnel
3.3 Third-Party Sources
- Social Media: Public profile information if you interact with us on social platforms
- Business Partners: Information from authorized distributors or training partners
4. How We Use Your Information
4.1 Legal Basis for Processing (GDPR Article 6)
We process your personal data based on:
- Contract Performance / Pre-Contractual Steps: Processing is necessary to provide requested services and operate core website functions
- Legitimate Interests: Processing is necessary for security, fraud prevention, service improvement, campaign measurement, and business continuity
- Legal Obligation: Processing is required to comply with applicable legal and regulatory requirements
- Consent (where required by law): Used for specific optional activities such as certain direct marketing communications
4.2 Purposes of Processing
- Responding to inquiries and providing customer support
- Processing training registrations and course administration
- Providing technical service and repair services
- Sending service-related communications and updates
- Improving our website and services through analytics
- Marketing communications (only with your consent)
- Complying with legal and regulatory requirements
- Preventing fraud and ensuring website security
5. Cookies and Browser Storage
5.1 What Are Cookies?
Cookies are small text files stored on your device when you visit our website. They help us provide you with a better experience and allow certain features to function properly.
5.2 Types of Cookies We Use
- Essential Cookies: Required for basic website functionality (cannot be disabled)
- Analytics Cookies: Google Analytics to understand how visitors use our site
- Functional Cookies: Remember your preferences and settings
- Marketing and Measurement Cookies: Google Ads conversion and attribution tracking
5.3 Third-Party Cookies and Analytics
- Google Analytics: Website traffic analysis and user behavior
- Google Maps: Interactive maps on our Contact page
- YouTube: Embedded videos on our Video References page
- Social Media: Social sharing buttons (Facebook, Twitter, Instagram)
- Cloudflare Web Analytics: Privacy-focused website performance and traffic analytics provided by Cloudflare, Inc. This service collects anonymized page load metrics and does not use cookies or track individual users across sites
5.4 Mandatory Analytics and Advertising Measurement
Our website uses Google Analytics, Google Ads measurement technologies, and related logging controls as part of our standard service delivery, security monitoring, and campaign performance operations. These technologies may begin processing technical and behavioral data when you access the Website.
By using the Website, you acknowledge and accept this processing as part of our service terms and this Privacy Policy. If you do not agree, you must discontinue use of the Website and services.
5.5 Browser Controls and Data Rights
You may use browser and device settings to manage or block certain cookies and tracking technologies. Please note that restricting these technologies may limit website functionality, analytics quality, fraud prevention capability, or service availability.
Where local law grants additional rights regarding tracking technologies, you may exercise those rights by contacting us using the details in this Policy.
5.6 Browser Storage
Two items may be stored in your browser by the language features of this site, and neither is stored until you act. endogrup_lang_suggest_dismissed is kept in your browser's local storage. It is written when you close a bar that offers this page in another language, or when you follow that offer, and it stops that offer being shown to you again. Local storage is not attached to requests, so this item stays on your device until you remove it.
endogrup_lang_choice is a cookie. It records which language you chose, either from that bar or from the language menu at the top of every page, and like every cookie it is sent to our server with each request to this site. It expires one year after it is set. Neither item contains anything that identifies you, and you can remove both at any time by clearing this website's data in your browser settings.
The list continues below, and together with the two items above it covers everything this site's own code stores in your browser. The outside services named in 5.3, such as Google and YouTube, may store items of their own when their content loads on a page. Those are set by those companies under their own names and are not listed here.
Answering the cookie banner writes five cookies at once, and none of them is written before you answer. endogrup_consent_choice holds your answer, as either accepted or rejected, and it is the only one of the five the site reads back: while it is there, the banner does not ask you again. endogrup_analytics_consent and endogrup_marketing_consent hold that same answer separately for analytics and for advertising, each as either true or false. endogrup_cookie_consent and endogrup_privacy_notice_seen hold version numbers, and record which version of this policy and of the banner was in place when you answered. Those last four are records only, and nothing on the site reads them back. All five expire one year after you answer, and answering again through the Cookie settings link in the footer rewrites all five. We treat all five as strictly necessary, so they are not themselves governed by the banner.
eg_cta_seen is a cookie written by the training panel that opens from the tab at the side of the page. It is written when you open that panel, it holds only the number 1, and its only effect is that the small notice dot on that tab, and the reminder bubble that appears beside it, stop showing again. It expires thirty days after it is set. It is a functional cookie: it holds nothing about you, and the cookie itself is not used for analytics or for advertising.
__Host-eg_tk is a cookie our own server sets, rather than any script on the page. It is there to show that a recorded visit came from a real page of this site. It lasts about twenty-four hours and is renewed while you keep visiting, and we treat it as strictly necessary. Section 13 below describes it in full, including what its value holds and what it cannot do.
PHPSESSID is a cookie set by the software that runs our contact forms, and only when one of those forms is submitted. Ordinary browsing does not set it. It holds a session number that the server uses to count how many messages have arrived from one browser in a short time, which is how we limit automated form spam. It holds no name, address or message text. Unlike the other items in this section its value is unique to your browser rather than one of a few fixed values, and it is removed when you close your browser. We treat it as strictly necessary.
6. Data Sharing and Disclosure
6.1 We Share Data With:
- Service Providers: Hosting providers, email services, analytics platforms
- IP Geolocation Provider: ipinfo.io (used to derive approximate country/region/city and ISP from IP address for security logging)
- Payment Processors: For processing training fees and service payments
- Legal Authorities: When required by law or to protect our rights
- Business Partners: Authorized training centers and service partners (with your consent)
6.2 International Data Transfers
Your data may be transferred to and processed in countries outside the EU/EEA. We ensure appropriate safeguards are in place, including:
- EU Standard Contractual Clauses
- Adequacy decisions by the European Commission
- EU-US Data Privacy Framework (where applicable)
7. Data Retention
We retain your personal data only as long as necessary:
- Contact Inquiries: 2 years from last contact
- Training Records: 7 years for certification purposes
- Service Records: 5 years for warranty and quality assurance
- Analytics Data: 26 months (Google Analytics default)
- Marketing Consent: Until consent is withdrawn
- Visitor Intelligence Logs (IP, page, device, approximate location): Up to 12 months
- Security Audit Logs (blocked abuse/injection attempts): Up to 12 months
- Application Error Logs: Up to 12 months
- Mail Transport Logs: Up to 24 months
Where legally required (for example, dispute resolution, fraud investigations, or regulatory obligations), certain records may be retained for longer and then securely deleted or anonymized.
8. Your Rights (GDPR, Swiss FADP & KVKK)
You have the following rights regarding your personal data:
8.1 Right of Access
Request a copy of the personal data we hold about you
8.2 Right to Rectification
Request correction of inaccurate or incomplete data
8.3 Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data (subject to legal obligations)
8.4 Right to Restriction
Request limitation of processing in certain circumstances
8.5 Right to Data Portability
Receive your data in a structured, machine-readable format
8.6 Right to Object
Object to processing based on legitimate interests or for marketing purposes
8.7 Right to Withdraw Consent
Where a processing activity is based on consent under applicable law, you may withdraw that consent at any time (without affecting the lawfulness of processing carried out before withdrawal).
8.8 Right to Lodge a Complaint
File a complaint with your local data protection authority
8.9 Turkish KVKK Article 11 Rights
If you are in Turkey, you may also exercise your rights under Law No. 6698 (KVKK), including learning whether your personal data is processed, requesting information about processing, requesting correction or deletion where conditions are met, and objecting to results produced exclusively by automated systems.
Email: info@endogrup.com
Subject: "Data Protection Request"
We will respond within 30 days of receiving your request.
9. Data Security
We implement appropriate technical and organizational measures to protect your data:
- SSL/TLS encryption for data transmission
- Secure server infrastructure with regular security updates
- Access controls and authentication mechanisms
- Regular security audits and vulnerability assessments
- Employee training on data protection
- Incident response procedures
10. Children's Privacy
Our services are not directed to individuals under 16 years of age (or 18 where required by local law, such as the Turkish Personal Data Protection Law No. 6698). We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately and we will promptly delete such information.
11. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Article 33)
- Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms (GDPR Article 34)
- Notify the Turkish Personal Data Protection Authority (KVKK) as soon as possible in accordance with Article 12 of Law No. 6698
- Document all breaches and the remedial actions taken
12. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.
13. Server-Side Visitor Logging (Always-On): KVKK Aydınlatma & Legitimate Interest
Independently of the cookie/consent banner, our server keeps a first-party security and traffic log (via tracker.php) for every visitor, from the start of each page request. This logging is always active and is not controlled by your Accept/Reject choice, because it does not rely on consent (see the legal basis below). It is a separate layer from the consent-driven analytics and advertising technologies described in the Cookie Policy above.
This logging sets one strictly necessary cookie, named __Host-eg_tk. Its only purpose is to show that a recorded click came from a real page of this website. It does not make our traffic figures impossible to forge, and we do not claim that: it makes forging them cost more than one request, impossible from a third-party page, and visible to us when it is attempted. The cookie holds nothing except the hour in which it was issued, so every browser that first reaches the site within the same hour receives exactly the same value, and it identifies neither you nor your device. It lasts about 24 hours and is renewed while you keep visiting, it cannot be read by any script or by any other website, and its value is never written into the log. It carries no identity, and it exists only to keep our own records honest. We treat it as strictly necessary, so it is not governed by the cookie banner. If you disagree with that classification, write to us and we will explain it in full.
13.1 What the server log records
- IP address and Internet Service Provider (ISP) information
- Device type, for example Windows, Mac, Linux or mobile. The full browser user-agent string is not stored.
- Pages visited, navigation patterns, and timestamps
- The language your browser asks for, as sent in its Accept-Language header
- Which kind of event the request was: a page view, a page that was not found, a form submission, a WhatsApp click or a phone-number click
- Whether the request carried a valid ticket cookie, recorded as one of four fixed values and never as the cookie value itself. Events that fail this check are written to a separate rejected-events file.
- Referral source (referring domain)
- Approximate geographic location (country, region, city) derived from the IP address using a third-party IP-geolocation service (ipinfo.io)
13.2 Purposes
- Security: detecting and investigating attacks, intrusion attempts, and abuse
- Fraud prevention: identifying malicious or fraudulent activity
- Own-site statistics: understanding aggregate traffic to operate and improve the website
13.3 Legal basis
- Legal obligation: Turkish Law No. 5651 (Regulation of Publications on the Internet) and its secondary legislation require providers to retain certain traffic/access logs (KVKK Art. 5/2-(ç): processing necessary to comply with a legal obligation)
- Legitimate interest (meşru menfaat): GDPR Article 6(1)(f) and KVKK Article 5/2-(f): processing necessary for our legitimate interests in network and information security, fraud prevention, and the proper operation and improvement of our own website
Because this logging rests on a legal obligation and our legitimate interest, it operates whether you accept, reject, or ignore the cookie banner. Where applicable law grants a right to object to legitimate-interest processing, you may object by contacting us using the details in this Policy; records required by Law No. 5651 must still be retained for the statutory period.
13.4 Retention
Server-side visitor/traffic logs are retained for up to 12 months (and longer only where a legal obligation, dispute, or investigation requires it), after which they are securely deleted or anonymized. See Section 7 (Data Retention).
13.5 Strict separation from advertising (no ad profiling)
This always-on server log is used only for the security, fraud-prevention, and own-site statistics purposes above. It is never fed into, combined with, or used for advertising profiling, remarketing or marketing audiences, ad personalization, or any third-party marketing tag (including Google Analytics or Google Ads). The server log and the consent-driven Google analytics/advertising layer are kept strictly separate in our code paths.
13.6 Cross-border transfer note (KVKK Article 9)
The consent-driven Google Analytics / Google Ads layer sends fully-identified data only after you Accept, and this involves transferring certain data to Google LLC and its infrastructure outside Türkiye. Such transfers are made on the basis of your explicit consent and/or appropriate safeguards in accordance with KVKK Article 9 (transfer of personal data abroad), together with the international-transfer safeguards in Section 6.2. The always-on server log described in this Section is processed on our own server infrastructure and is not part of that advertising transfer; the IP-geolocation lookup in Section 13.1 is limited to deriving approximate location for security logging.
14. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. Please review their privacy policies before providing any personal data.
15. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by:
- Posting the updated policy on our website
- Updating the "Last Updated" date
- Sending email notifications for material changes (if you have provided your email)
16. Contact Information
EndoGrup
Gülbahar, Salih Tozan Sk. No:3
34394 Şişli/Istanbul, Turkey
Email: info@endogrup.com
Phone: +90 506 741 18 57
WhatsApp: +90 506 741 18 57
17. Supervisory Authorities
Turkey: Personal Data Protection Authority (KVKK - Kisisel Verileri Koruma Kurumu)
Website: www.kvkk.gov.tr
EU: Your local Data Protection Authority
List: EDPB Members
Switzerland: Federal Data Protection and Information Commissioner (FDPIC)
Website: www.edoeb.admin.ch
18. Legal Basis Summary
| Processing Activity | Legal Basis |
|---|---|
| Contact form processing | Consent / Contract performance |
| Training registration | Contract performance |
| Website analytics | Legitimate interest / Contract performance (service operation) |
| Marketing communications | Consent |
| Security logging | Legitimate interest |
By accessing or using our website, you acknowledge and accept the data processing practices described in this Privacy Policy, including analytics, advertising measurement, and security logging as part of service operation.
If you do not agree with this policy, please do not use our website or services.