Anya Dahan Studio · Data

Data protection policy v. 01

Version 2026-10-04 · Published 04 October 2026 · Miami, FL, USA

4. Cybersecurity and Data Protection Policy

4.1 Applicable Frameworks

Personal data is handled consistent with Türkiye's Personal Data Protection Law No. 6698 (KVKK) as the primary applicable regime, and with EU GDPR principles as a best-practice benchmark for any EU-resident customers, even where GDPR does not directly apply.

4.2 Notice to Data Subjects

A separate Privacy Notice (linked from every page that collects data) identifies: the data controller (Anya Dahan) and any processor (the Turkish Company, for local operations); the categories of data collected; the purpose and legal basis for each category; recipients, including payment processors; retention periods by category (Section 4.6); and the data subject's rights under KVKK Article 11, including access, correction, and deletion requests, submitted to studio@anyadahan.blog and answered within 30 days.

4.3 Technical and Organizational Controls

  • Multi-factor authentication on all administrative, email, and payment-processor accounts;
  • Encryption of stored and transmitted personal data, including identity-verification images;
  • No storage of identity documents in ordinary email or unsecured personal file storage - verification images are stored only in an access-controlled, encrypted location with a defined deletion trigger;
  • Least-privilege access: only the responsible officer (and, for defined administrative tasks, the Turkish Company acting as processor) may access identity-verification records;
  • Regular software patching, credential rotation, and phishing awareness for anyone with administrative access;
  • Encrypted backups with periodic restoration testing;
  • Logging of administrative access to customer and donor records.

4.4 Incident Response

  1. Contain: isolate the affected system or account and preserve logs;
  2. Assess: determine what data categories and how many individuals are affected;
  3. Notify: where the breach creates a risk to individuals' rights and freedoms, notify the Turkish Data Protection Authority (KVKK Board) as required and, given the sensitivity of refugee, gender-identity, and health-related data potentially at stake, notify affected individuals directly using a heightened-risk protocol (secure, non-outing channel of contact) rather than a public notice;
  4. Remediate: close the vulnerability and document lessons learned;
  5. Review: the responsible officer documents the incident and any control changes in the internal governance log referenced in Section 8.

4.5 Vendor and Processor Management

Payment processors, hosting providers, and any third-party tool that touches customer or donor personal data are selected with a documented, minimal data-sharing agreement, and are reviewed at least annually for continued suitability, including whether they operate in or route data through any sanctioned jurisdiction.

4.6 Differentiated Retention Schedule

Data categoryRetentionNotes
Order, invoice, and payment records 5 years from transaction close Required financial/AML baseline (Section 2.6).
Raw identity-document images (ID/passport scans) Deleted immediately once verification is complete; not retained for the full 5-year period Highest-sensitivity category; access restricted per Section 4.3.
AML investigation notes 5 years from case closure Confidential; excluded from routine data-subject access requests where disclosure would tip off a subject of a live investigation.
General customer communications 2 years from last contact Deleted or anonymized thereafter absent an active dispute.
Security and access logs 1 year Extended only if needed for an active incident investigation.
Advocacy participant / UGC personal stories Until consent is withdrawn, or 3 years of inactivity Subject to the heightened consent standard in Section 3.5.
Health-related or HIV-advocacy-related personal data Only as long as necessary for the specific disclosed purpose; reviewed every 12 months Never used for a secondary purpose without new consent.

Questions about this policy? Email studio@anyadahan.blog or write to Anya Dahan Studio, Miami, FL, USA.