This notice is issued under Article 10 of Turkish Law No. 6698 on the Protection of Personal Data and the Communiqué on the Procedures and Principles for Fulfilling the Disclosure Obligation. Its purpose is to tell you, before processing begins, why we process your personal data, which lawful ground we rely on, and to whom we transfer it.
The Turkish text of this notice is the authoritative version; this English version is provided for information. Where the two differ, the Turkish text governs.
This is a disclosure notice, not a consent form. Under principle decision 2026/347 of the Personal Data Protection Board, dated 18 February 2026, disclosure and explicit consent must be set out in separate documents. Where we rely on your explicit consent, that consent is obtained separately and expressly at the moment of the relevant processing.
1. Identity of the data controller
The data controller is VARANTECH ENERJİ SAN. TİC. LTD. ŞTİ. ("the Company", "Quote3D").
We have no appointed representative outside Türkiye for the purposes of this Law; a controller established in Türkiye is not required to appoint one.
- Address: Fevzi Çakmak Mah. Orhan Gazi Cad. No:92/A, Sincan, Ankara, Türkiye
- Email: [email protected]
- Registered electronic mail (KEP) address: [email protected]
- MERSİS number: 0922154514600001
2. Who this notice covers
There are three different groups of data subjects, and the party you address your rights to depends on which group you are in.
- People who sign up to Quote3D directly, request quotes, use the API or contact support: the Company is the controller and this notice covers you.
- Visitors to quote3d.com: the Company is the controller and this notice covers you.
- End-users who upload a file through a Quote3D widget embedded on another company's website: that company is the controller and we are its data processor. Exercise your rights with them. If you contact us, we cannot decide your request on the merits; we will direct you to the controller and tell them you asked.
3. Data processed, purposes, lawful grounds and transfers
For each category of data, the purpose, the processing condition relied on under Article 5 of the Law, the recipient group and the collection method are stated separately. Purposes are named by the operation actually performed rather than in general terms.
Identity and contact data
Name or display name, email address, profile image, language preference, password hash.
- Purpose: creating the membership record, authentication, account management, and delivering service notifications.
- Lawful ground: Art. 5(2)(c) — directly related to the conclusion or performance of a contract.
- Transfer: to our hosting and database provider, so that the service can be delivered; to our email delivery provider, so that notifications can be sent.
- Collection method: through web forms and API calls, by wholly automated means.
Federated sign-in data
If you choose to sign in with a Google or Meta account: account identifier, email address, display name and, where you permit it, profile image.
- Purpose: authentication and creation of the membership record.
- Lawful ground: Art. 5(2)(c) — conclusion or performance of a contract. Using this method is not mandatory; you may register with an email address and password instead.
- Transfer: we receive this data from the provider; your password is not transmitted to the provider by us.
- Collection method: not from the data subject but from the identity provider you choose, by wholly automated means.
Uploaded file and quote data
The 3D model file itself (STL, OBJ, 3MF), its name, size and format, metadata written into the file by the originating software, geometry measurements derived from it, the quote output and the quote parameters.
- Purpose: analysing the file, simulating slicing, computing the price, producing and presenting the quote, and keeping your quote history available to you.
- Lawful ground: Art. 5(2)(c) — performance of a contract. No quote can be produced without the file.
- Transfer: to our hosting and database provider, so that the service can be delivered. Your files are not transferred to the artificial intelligence provider, nor to advertising or analytics providers.
- Collection method: through a web form, the widget or an API call, by wholly automated means.
- Please note: we do not strip information written into the file by design or scanning software. If your software recorded a name or a machine identifier in the file, it reaches us.
Transaction security and log data
IP address, browser and device information, session records, API request records, quota counters, failed sign-in counters, abuse and security logs, reCAPTCHA risk signals.
- Purpose: securing accounts, preventing unauthorised access and automated abuse, enforcing quota and fair-use limits, and diagnosing faults.
- Lawful ground: Art. 5(2)(ç) — compliance with a legal obligation, as regards system-security duties; and Art. 5(2)(f) — our legitimate interest, provided it does not harm your fundamental rights and freedoms, in preventing abuse of an upload-based service. This data is not used to profile you.
- Transfer: to the Google reCAPTCHA service, so that bot protection can operate; to our hosting provider.
- Collection method: by our servers and your browser, by wholly automated means.
Subscription and financial data
Selected plan, subscription status, renewal and cancellation dates, plan limits, billing country and billing profile details, provider reference identifiers.
- Purpose: establishing and maintaining the subscription, collecting payment, issuing invoices, handling renewals and cancellations, and keeping accounting and tax records.
- Lawful ground: Art. 5(2)(c) — performance of a contract; and for accounting, invoicing and tax records, Art. 5(2)(a) — expressly provided for by law, and Art. 5(2)(ç) — compliance with a legal obligation.
- Transfer: to Lemon Squeezy, for payment, tax and invoicing processes; and to competent authorities within statutory retention and reporting duties.
- Card numbers and equivalent payment credentials never reach us; they are processed by the payment provider.
- Collection method: through the payment provider's screens and our web forms, by wholly automated means. Some of it is obtained from the payment provider rather than from you.
Support and AI assistant data
Support requests, contact form contents, feedback; the full text of the messages you type into the AI live-support assistant, the assistant's replies, the session identifier, your IP address and browser information.
- Purpose: handling your support request and diagnosing and resolving the issue.
- Lawful ground: for handling the support request, Art. 5(2)(c) — performance of a contract. For use of the AI assistant, Art. 5(1) — your explicit consent, obtained separately before you use the assistant and withdrawable at any time.
- Transfer: the full text of your messages to the assistant is transferred to Google's Gemini API service so that a reply can be generated. Your uploaded files, geometry data, credentials and financial data are not transferred to that provider.
- Collection method: through the chat interface and web forms, by wholly automated means.
- For this reason we recommend that you do not type confidential information, or personal data belonging to other people, into the assistant.
Consent and acceptance records
Which legal document you accepted, in which version and language, when, from which IP address and browser; a verbatim copy of the text as it stood at that moment; your cookie preferences.
- Purpose: being able to prove consent and acceptance under the Law and consumer legislation, and establishing or defending a right in the event of a dispute.
- Lawful ground: Art. 5(2)(ç) — compliance with a legal obligation, since the burden of proof lies with the controller; and Art. 5(2)(e) — processing necessary for the establishment, exercise or protection of a right.
- Transfer: as a rule none; submitted to a competent authority only in the event of a dispute.
- Collection method: at the moment you give your acceptance, by wholly automated means.
4. Transfers abroad
Some of our service providers are located outside Türkiye, so the data whose recipient group is identified above may be transferred abroad.
Under Article 9 of the Law, unless and until an adequacy decision exists for the relevant country, such transfers are made on the appropriate safeguards provided for in that Article. To obtain information about the standard contracts signed and the notifications made in that context, write to [email protected].
The main recipient groups abroad are: the payment and invoicing provider, the artificial intelligence provider, the bot-protection provider, the email delivery provider, the hosting and infrastructure provider, and — subject to your explicit consent — the analytics and advertising providers. Their names and the data each receives are published at /legal/subprocessors.
5. Retention periods
Personal data is retained for as long as necessary for the purpose and for any period required by law. The periods below are actually enforced by scheduled jobs.
Data whose retention period has expired is deleted, destroyed or anonymised.
- Uploaded files that produced no quote: deleted 24 hours after upload. This is an operator setting; if it is changed, this policy is changed with it, and you can ask us what it is set to today.
- Uploaded files that produced a quote: deleted 365 days after last use. Requesting a new quote from the same file restarts that period.
- Quote records (price, parameters and measurements, without the file): retained while your account is open.
- Audit logs, API usage logs and system logs: 90 days. This is an operator setting; if it is changed, this policy is changed with it, and you can ask us what it is set to today.
- Password reset and email verification tokens: 7 days. Used upload sessions: 24 hours.
- Membership data: retained while your account is open; deleted within 30 days if you request deletion of your account.
- Consent and acceptance records: 3 years after the subscription ends.
- Invoice, accounting and tax records: for the period required by the applicable legislation, which continues after the account is closed.
- Encrypted backups: removed by rotation no later than 35 days after deletion from the live system, and used only for disaster recovery in the meantime.
6. Security of personal data
The technical and administrative measures taken under Article 12 of the Law are described as actually implemented, so that no overstated security claim is made.
The limit of this protection must be stated plainly: encryption at rest protects the storage medium. It is not end-to-end encryption. Because the system must decrypt a file in order to produce a quote, file content is technically accessible.
- Uploaded files are stored encrypted with AES-256-GCM using a key derived for each individual file; key derivation uses HKDF-SHA256 and a random per-file salt.
- The encrypted file format carries the key identifier within itself, so master keys can be rotated without rewriting existing files.
- Files are stored in authenticated 256 KB blocks; each block carries its own authentication tag, and the block's position and the end-of-file marker are bound into that tag, so blocks cannot be reordered, dropped, or the stream truncated.
- Traffic to and from our public interfaces is protected with TLS.
- Access to production data is role-based and granted only on a need-to-know basis; files are isolated per account and directory permissions are restricted; API tokens are scoped and rate-limited; accounts lock after repeated failed sign-ins.
- Backups are encrypted, availability is monitored, and retention periods are enforced by scheduled jobs.
7. Analysis by automated systems
A price quote is produced entirely automatically, without review by a person: the system slices your model and computes the price.
Article 11(1)(g) of the Law gives you the right to object to a result that arises against you through analysis carried out solely by automated systems. If you consider that a quote produces a result against you, write to [email protected] to object, to ask for the basis of the quote to be explained, and to ask for it to be reviewed by a person.
8. Your rights under Article 11
Under Article 11 of the Law you may apply to the Company to exercise the following rights:
How to exercise these rights, the information your application must contain and our response time are set out on the Data Subject Application Form page. Requests are concluded as soon as possible and in any event within thirty days, free of charge.
If your application is refused, if you find our reply insufficient, or if we do not reply in time, you may lodge a complaint with the Personal Data Protection Board within thirty days of learning of the reply and in any event within sixty days of the date of your application.
- to learn whether your personal data is processed;
- to request information if it has been processed;
- to learn the purpose of processing and whether the data is used in accordance with that purpose;
- to know the third parties to whom the data is transferred, in Türkiye or abroad;
- to request correction where the data is incomplete or inaccurate;
- to request deletion or destruction within the conditions of Article 7;
- to request that correction, deletion and destruction be notified to the third parties to whom the data was transferred;
- to object to a result arising against you through analysis carried out solely by automated systems;
- to claim compensation for damage suffered as a result of unlawful processing.
9. Changes to this notice
The effective date at the top of this page is the date on which the current wording took effect, and it changes only when the wording changes.
If the purpose of processing changes, a separate disclosure is made before the processing activity, as required by Article 5(b) of the Communiqué. Earlier versions are available on request.