Mediadoor™ is committed to processing personal data lawfully, fairly and transparently. This statement sets out how we comply with the EU and UK General Data Protection Regulation (GDPR) and, for our Turkish market, the Personal Data Protection Law (KVKK), and the rights these laws give you.
1. Data Controller
Mediadoor™ acts as the data controller for the personal data collected through this website, meaning we decide why and how your data is processed. You can reach our team using the contact details at the bottom of this page for any data-related request.
2. Principles of Processing
We process all personal data in line with the core principles of the GDPR:
- Lawfulness, fairness and transparency.
- Purpose limitation — collected for specified, explicit purposes only.
- Data minimisation — only what is adequate and necessary.
- Accuracy — kept correct and up to date.
- Storage limitation — kept no longer than needed.
- Integrity and confidentiality — protected with appropriate security.
3. Lawful Bases
Every processing activity rests on a lawful basis: your consent, the performance of a contract, our legitimate interests, or compliance with a legal obligation. Where we rely on consent, you are free to withdraw it at any time.
4. Your Rights Under GDPR
As a data subject you have the following rights, which we honour free of charge:
- The right to be informed about how your data is used.
- The right of access to the data we hold about you.
- The right to rectification of inaccurate data.
- The right to erasure (the "right to be forgotten").
- The right to restrict processing.
- The right to data portability.
- The right to object to processing.
- Rights relating to automated decision-making and profiling.
5. KVKK (Türkiye)
For visitors and clients in Türkiye, we also comply with Law No. 6698 on the Protection of Personal Data (KVKK). The principles and rights it grants closely mirror the GDPR, including the right to learn whether your data is processed, to request correction or deletion, and to object to outcomes that work against you.
6. International Data Transfers
Where personal data is transferred between countries in which we operate, we apply appropriate safeguards — such as Standard Contractual Clauses or recognised adequacy decisions — to ensure your data remains protected to GDPR standards wherever it travels.
7. Data Breach Procedures
We maintain procedures to detect, investigate and respond to personal data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority — and, where required, you — without undue delay.
8. Exercising Your Rights
To exercise any of your rights, contact us using the details below. We will respond within one month, as required by the GDPR. You also have the right to lodge a complaint with a supervisory authority — in the UK, the Information Commissioner's Office (ICO); in Türkiye, the Personal Data Protection Authority (KVKK Kurumu).