GDPR Policy
Last Updated: January 2025
Company: NextDGT
1. Introduction
NextDGT is committed to compliance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This GDPR Policy explains how we collect, process, store, and protect personal data in accordance with GDPR requirements.
2. Data Controller Information
Data Controller: NextDGT
Address: Barbaros Mah. Şebboy Sk. No: 4/1 İç Kapı No: 2, Ataşehir / İstanbul 34742
Email: info@nextdgt.com
Phone: +90-531-306-89-54
3. Legal Basis for Processing
We process personal data based on the following legal bases under GDPR:
- Consent: When you have given clear consent for us to process your personal data
- Contract: When processing is necessary for the performance of a contract or to take steps before entering into a contract
- Legal Obligation: When processing is necessary for compliance with a legal obligation
- Legitimate Interests: When processing is necessary for our legitimate interests or those of a third party
4. Your Rights Under GDPR
As a data subject, you have the following rights:
4.1 Right of Access
You have the right to obtain confirmation as to whether or not personal data concerning you is being processed, and access to that personal data.
4.2 Right to Rectification
You have the right to have inaccurate personal data corrected and incomplete personal data completed.
4.3 Right to Erasure ("Right to be Forgotten")
You have the right to request the deletion of your personal data when:
- The data is no longer necessary for the original purpose
- You withdraw consent and there is no other legal basis
- The data has been unlawfully processed
- Deletion is required to comply with a legal obligation
4.4 Right to Restrict Processing
You have the right to restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
4.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
4.6 Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
4.7 Rights Related to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you.
5. How to Exercise Your Rights
To exercise any of your GDPR rights, please contact us at info@nextdgt.com. We will respond to your request within one month of receipt. If your request is complex or we receive multiple requests, we may extend this period by up to two additional months.
6. Data We Collect
In the course of providing our services (Digital Transformation, Software Development, Industrial Automation & IoT, and AI Solutions), we may collect:
- Contact information (name, email, phone, address)
- Business information (company name, job title, industry)
- Project and service-related information
- Technical data (IP address, browser type, device information)
- Communication records (emails, meeting notes, project discussions)
7. How We Use Your Data
We use your personal data to:
- Provide and deliver our services
- Communicate with you about our services
- Process and manage service agreements
- Improve our services and website
- Comply with legal and regulatory obligations
- Protect our rights and prevent fraud
8. Data Sharing and Transfers
8.1 Data Sharing
We may share your personal data with:
- Service providers who assist us in operating our business
- Professional advisors (lawyers, accountants, consultants)
- Government authorities when required by law
8.2 International Transfers
If we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions by the European Commission
- Other appropriate safeguards as required by GDPR
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit and at rest
- Access controls and authentication
- Regular security assessments and updates
- Employee training on data protection
- Secure data storage and backup procedures
10. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- For the duration of our business relationship
- As required by legal and regulatory obligations
- For legitimate business purposes (e.g., dispute resolution)
When data is no longer needed, we securely delete or anonymize it.
11. Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, and in any event within 72 hours of becoming aware of the breach, where feasible.
12. Children's Data
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will take steps to delete such information promptly.
13. Supervisory Authority
If you are located in the EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
14. Updates to This Policy
We may update this GDPR Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on our website and updating the "Last Updated" date.
15. Contact Us
For any questions, concerns, or requests regarding your personal data and GDPR compliance, please contact us:
NextDGT
Barbaros Mah. Şebboy Sk. No: 4/1 İç Kapı No: 2
Ataşehir / İstanbul 34742
Email: info@nextdgt.com
Phone: +90-531-306-89-54