In short: This website uses no advertising cookies, tracking pixels or third-party analytics software. Personal data is collected only when you submit one of our forms (quote, distributorship, career) or email us. We never sell your data or transfer it to third parties for marketing purposes.
1. Data controller and scope
Under the Turkish Personal Data Protection Law No. 6698 ("KVKK") and, where applicable, the EU General Data Protection Regulation ("GDPR"), the data controller is EFBA ("EFBA", "we", "us").
This policy covers:
- all pages and forms under the efbailac.com domain,
- messages sent to EFBA's corporate email addresses,
- interactions on EFBA's official social media accounts (see Section 9).
Links on this site that lead to third-party services not operated by EFBA fall outside the scope of this policy; the privacy policies of those services apply instead.
2. Personal data we collect
We collect personal data only when you provide it to us directly, or where it is technically necessary for the site to operate. The site has no user accounts, no payment processing and no user profiles.
2.1. Data you submit through forms
| Form |
Data collected |
Quote request (/en/request-quote/) |
Full name, company/clinic name, phone, email, product of interest, request details |
Distributorship application (/en/distributorship/) |
Company details (legal name, type, field of activity, year established, website, number of employees), contact person details (full name, title, phone, email), requested region and product group, commercial experience and capacity statements, and any documents you choose to upload (e.g. tax certificate, trade registry document) |
Career / interview form (/kariyer/) |
Full name, contact details and the free-text answers you give to the application questions (professional experience, competencies, assessment answers) |
Please do not send us special categories of personal data (health information, religion, union membership, biometric data and similar) that are not requested in the forms. If such data reaches us through free-text fields and is not necessary for the processing purpose, it will be deleted.
2.2. Technical data generated automatically
- Server access logs: IP address, request time, requested URL, HTTP status code, browser and operating system information (user agent). These logs are created automatically by the hosting server and kept for security, error diagnosis and abuse detection.
- Form abuse controls: To block automated submissions, the number of submissions per hour from your IP address and the time taken to fill in the form are checked at submission time.
2.3. What you send by email or social media
When you email us or write a comment or direct message to our social media accounts, the content of your message and any contact details you disclose to us are processed.
3. Purposes and legal bases
| Purpose |
Legal basis |
| Evaluating quote and distributorship requests, contacting you, conducting commercial discussions |
Necessary for the conclusion or performance of a contract (KVKK Art. 5/2-c; GDPR Art. 6(1)(b)) |
| Evaluating job applications and running recruitment processes |
Pre-contractual steps and legitimate interests (KVKK Art. 5/2-c and 5/2-f; GDPR Art. 6(1)(b) and 6(1)(f)) |
| Securing the site and form infrastructure, preventing abuse and automated attacks |
Legitimate interests (KVKK Art. 5/2-f; GDPR Art. 6(1)(f)) |
| Complying with legal obligations, responding to requests from competent authorities, establishing and defending legal claims |
Legal obligation and establishment/defence of legal claims (KVKK Art. 5/2-a, ç and e; GDPR Art. 6(1)(c) and 6(1)(f)) |
| Providing information at your request |
Consent or legitimate interests (KVKK Art. 5/1 and 5/2-f) |
Our forms also ask you to confirm, via a checkbox, that you have read the data protection notice. That confirmation relates solely to processing your submission for evaluation purposes; it is not marketing consent.
4. Cookies and browser storage
This site uses no advertising, profiling or tracking cookies. There are no third-party measurement or advertising tags such as Google Analytics, Meta Pixel or TikTok Pixel on this site.
For the site to function, only the following items are stored in your browser's local storage (localStorage). This data stays on your device and is never sent to our servers:
- Language preference: whether you want to view the site in Turkish or English.
- Form draft: a temporary copy of your answers in longer forms (quote, distributorship, career) so that your input is not lost. The draft is deleted once the form is submitted successfully, and you can remove it at any time by clearing site data in your browser.
Web fonts used on the site are loaded via Google Fonts; your IP address is disclosed to that provider as part of the font request. No personal data beyond what is required to deliver the font files is transferred to that provider.
5. Sharing of data
We never sell, rent or transfer your personal data to third parties for advertising purposes. Data is shared only in the following limited cases:
- Hosting provider: the provider of the server infrastructure on which the site and form records are hosted.
- Email infrastructure: the email/SMTP service provider used to deliver form notifications to the EFBA team.
- Competent authorities: where required by law, limited strictly to the scope of the request.
- Legal advisers: in the event of a dispute, for the establishment or defence of legal claims, under a duty of confidentiality.
Contractual safeguards requiring service providers to process data only on our instructions are applied.
6. Retention periods
We do not keep data longer than the purpose of collection requires.
- Quote and distributorship applications: for the statutory retention periods where a commercial relationship has been established; otherwise deleted or anonymised within a reasonable period (no more than 2 years) after the evaluation is completed.
- Documents uploaded with a distributorship application: deleted once the evaluation is completed if the application is unsuccessful.
- Career applications: up to 2 years from the evaluation; during that period they may be reconsidered for suitable openings.
- Server access logs: kept for a short period for security and diagnostic purposes, then rotated and overwritten by the server.
- Email correspondence: for a period limited to the subject of the correspondence and the requirements of the commercial relationship.
Upon a deletion request, data for which no legal retention obligation exists is deleted (see Section 8).
7. Data security
Technical and organisational measures we apply to protect personal data against unlawful access, loss and alteration include:
- All site traffic is encrypted with TLS, and HTTPS is enforced through HSTS.
- A Content Security Policy (CSP), framing protection and related security headers are enabled on the browser side.
- Form records and uploaded documents are stored outside the web server's publicly served directory (DocumentRoot) and cannot be downloaded directly over the internet.
- The content type of uploaded files is verified server-side; only permitted document types are accepted.
- Rate limiting, automated-submission detection and duplicate-submission protection are applied to the form endpoints.
- Access to data is restricted to a limited number of authorised staff on a need-to-know basis.
No method of transmission or storage is absolutely secure; nevertheless, in the event of a data breach we make the notifications required by law without undue delay.
8. Your rights (KVKK and GDPR)
Under Article 11 of the KVKK, as a data subject you have the right to:
- learn whether your personal data is being processed and, if so, request information about it,
- learn the purpose of processing and whether the data is used in line with that purpose,
- know the third parties to whom the data is transferred domestically or abroad,
- request rectification of incomplete or inaccurate data,
- request erasure or destruction of the data within the conditions set out in the law,
- request that rectification, erasure and destruction be notified to the third parties to whom the data was transferred,
- object to a result arising against you from analysis carried out exclusively by automated means,
- claim compensation for damage suffered as a result of unlawful processing.
Where the GDPR applies, you additionally have the rights of access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and objection to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out beforehand.
You can send your requests to info@efbailac.com. Provided we can verify your identity, requests are concluded within 30 days at the latest. If you are not satisfied with the outcome, you retain the right to lodge a complaint with the Turkish Personal Data Protection Authority or, where applicable, your local supervisory authority.
9. Our social media accounts
EFBA may operate corporate accounts on platforms such as TikTok, Instagram, YouTube and LinkedIn. When you interact with us through those accounts:
- your profile name and the content of your comment or direct message reach us, and are processed solely to respond to your enquiry;
- the platform's own processing activities (e.g. view statistics, recommendation algorithms, ad measurement) are governed by that platform's own privacy policy and are outside our control;
- platforms provide us only with de-identified aggregate statistics (views, reach, engagement counts), which are not used to identify any individual.
We recommend sending sensitive or personal information to info@efbailac.com rather than through social media.
10. Children's privacy
Our site and services are intended for healthcare professionals, clinics and commercial partners; they are not directed at persons under the age of 18, and we do not knowingly collect personal data from that age group. If we become aware that data belonging to a person under 18 has reached us, we delete it without delay. Please contact us if you are aware of such a case.
11. International transfers
Your data is primarily stored on servers located in Türkiye. Where technical services such as hosting, email or web fonts are provided through infrastructure located abroad, transfers are made in line with the KVKK provisions on cross-border transfers and, under the GDPR, subject to appropriate safeguards (e.g. standard contractual clauses). Interactions conducted through social media platforms may involve processing by the platform outside Türkiye; such processing is subject to the relevant platform's own policies.
12. Changes to this policy
We may update this policy in line with legal developments or changes to our services. The current version is always published at this address and the "last updated" date at the top of the page is refreshed. In the case of a material change, we will also announce it on the site where possible.
13. Contact
For any question or request regarding this policy, the processing of your data or the exercise of your rights:
You may also want to read our Terms of Use.