Privacy Policy

Türkçe sürüm

This policy explains what personal data blackramaudio.com collects, why, who we share it with and what you can do about it. It is written to satisfy the EU and UK General Data Protection Regulation and Turkish Law No. 6698 on the Protection of Personal Data, under which we are the controller.

We have tried to keep it readable. A privacy policy nobody finishes protects nobody.

1. Who we are

Controller{{UNVAN}}
Address{{ADRES}}
Email{{EPOSTA}}
Phone{{TELEFON}}
Tax office / number{{VERGI_DAIRESI}} / {{VERGI_NO}}

We are established in Türkiye. We have not appointed an EU or UK representative under Article 27 GDPR; if that becomes a requirement for our volume of EU business, this section will be updated.

2. What we collect, why, and on what legal basis

2.1 Visiting the site

Data: IP address, browser and operating system, time of request, page requested.

Purpose: keeping the site up, fixing faults, blocking attacks and abuse.

Legal basis: legitimate interests (Art. 6(1)(f) GDPR) in operating a secure service.

Retention: server and security logs are deleted after {{LOG_SAKLAMA}}.

2.2 Subscribing to the mailing list

Data: your email address; the exact wording of the consent checkbox; the date and time you ticked it; the page you subscribed from.

Purpose: sending news about new releases, discounts and free content, and being able to prove afterwards that you asked for them.

Legal basis: consent (Art. 6(1)(a) GDPR). Nothing else. Withdraw it and the emails stop.

Retention: until you unsubscribe. We then delete your record and keep only the minimum needed to avoid mailing the same address again.

Note: we add your address to the list without sending a confirmation email first. Every message carries a one-click unsubscribe link.

2.3 Using the contact form

Data: your name, email address, the subject you chose, your message, the consent wording and the time you accepted it, and the page you sent it from.

Purpose: answering you, and keeping a record of what was asked.

Legal basis: performance of a contract or steps taken at your request (Art. 6(1)(b) GDPR), and our legitimate interest in keeping a support record (Art. 6(1)(f)).

We do not store your IP address. To stop the form being abused, an irreversible hash of your IP is held briefly as an hourly counter key. The address cannot be recovered from it.

Retention: {{MESAJ_SAKLAMA}}.

2.4 Creating an account and placing an order

Data: name, email address, billing details, order history, download and licence key records.

Purpose: taking the order, delivering the product, issuing the invoice, providing support, and keeping the books the law requires us to keep.

Legal basis: performance of a contract (Art. 6(1)(b)) and compliance with legal obligations under Turkish tax and commercial law (Art. 6(1)(c)).

Retention: records subject to Turkish tax law are kept for five years and those subject to the Turkish Commercial Code for ten years, then deleted.

Our products are digital and there is no shipping, so we never ask for a delivery address.

2.5 Paying

Your card number, expiry date and security code never reach us and are never stored on our systems. Payment is taken by {{ODEME_SAGLAYICI}} on their own infrastructure. We receive the outcome of the payment, the order reference and the details needed for the invoice.

2.6 Cookies

Set out separately in the Cookie Policy. In short: strictly necessary cookies only, no advertising, no banner. Visitor numbers are measured with Cloudflare Web Analytics, which uses no cookies and does not identify individuals.

3. Who we share data with

We do not sell your data and we do not pass it to advertisers. The recipients below are service providers we need in order to operate, and the list is exhaustive:

RecipientWhat forWhere processed
{{HOSTING_SAGLAYICI}}Website hosting and backupsGermany (Frankfurt)
Cloudflare, Inc.DNS, firewall, product file delivery, cookieless visitor measurementUnited States and global edge network
Brevo (Sendinblue SAS)Sending newsletter and notification emailFrance / European Union
Google LLCServing web fonts (your IP address only)United States
{{ODEME_SAGLAYICI}}Taking payment, invoicing{{SAGLAYICI_ULKE}}
{{MUHASEBE}}Statutory accounts and filingsTürkiye

We will also disclose data to public authorities where they are legally entitled to it.

4. International transfers

We are based in Türkiye, which the European Commission has not made an adequacy decision for. Where we transfer personal data out of the EEA or the UK, we rely on {{AKTARIM_DAYANAGI_EN}}.

In the other direction, transfers out of Türkiye are governed by Article 9 of Law No. 6698 as amended by Law No. 7499 of 12 March 2024, which requires an adequacy decision from the Turkish Data Protection Board, failing that appropriate safeguards such as standard contractual clauses or binding corporate rules, and failing those one of the derogations listed in that article. The Board has issued no adequacy decision for the countries in the table above, so we rely on {{AKTARIM_DAYANAGI_EN}}.

5. How we collect data

Entirely by automated means and entirely from you: the requests your browser makes, the forms you complete, the account you open and the orders you place. We buy no data and enrich our records from no external source.

6. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased, where one of the grounds in Article 17 applies;
  • restrict processing while a dispute about accuracy or legitimate interests is resolved;
  • receive your data in a portable format, and have it transmitted to another controller;
  • object to processing based on legitimate interests;
  • withdraw consent at any time, without affecting processing carried out before you withdrew it.

Turkish data subjects hold the equivalent rights under Article 11 of Law No. 6698; the procedure for exercising them is set out in our Turkish-language KVKK Aydınlatma Metni.

7. How to exercise them

Write to {{EPOSTA}}. We answer within one month under the GDPR, and within thirty days under Turkish law. We do not charge for this unless a request is manifestly unfounded or excessive.

If you are not satisfied with our answer you may complain to a supervisory authority:

  • in the EU, the data protection authority of your country of residence or workplace;
  • in the UK, the Information Commissioner’s Office (ico.org.uk);
  • in Türkiye, the Personal Data Protection Board (kvkk.gov.tr).

8. Security

The site is served over HTTPS only and sits behind Cloudflare’s firewall. Administrative accounts are individual rather than shared, editing theme and plugin files from the browser is disabled, and the contact form is protected by a request token, a honeypot field and a rate limit. Product files are not served from the web server; they are delivered from separate object storage through links that expire.

No arrangement is perfect. If you believe you have found a security problem, please write to {{DESTEK_EPOSTA}} before disclosing it publicly, and we will work with you on it.

9. Children

The site is not aimed at children and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, write to {{EPOSTA}} and we will delete it.

10. Changes

We update this policy when what we do with data changes. The date at the bottom shows the last revision. Where a change materially affects you, we will say so on the site and, if you are on the mailing list, by email.



Last updated: 2026-09-02