X DIAMOND

Privacy Policy

1. Data Controller

X Diamond mücevherat (the “Company”) acts as the data controller under the Turkish Personal Data Protection Law No. 6698 (KVKK).

2. Data Collected

The following data is collected in connection with membership, orders, communications and cookie use:
• Identity information (first name, surname)
• Contact information (email, telephone, address)
• Payment information (the Company does not store card numbers; they are processed by the payment provider)
• Website usage data (cookies, IP address, browsing)

3. Purposes of Data Processing

Order and payment processing, product delivery, customer support, legal obligations and marketing (with consent).

4. Data Sharing

Your data may be shared with payment providers, shipping companies and cloud infrastructure providers (Cloudflare, R2). It is not sold to third parties.

5. Cookies

Essential cookies (session, basket, security) are always used on our website. Analytics (Google Analytics) and marketing (Meta Pixel) cookies are loaded only with your explicit consent. You can manage your cookie preferences at /gizlilik#cerez-tercihleri.

6. Your Rights (KVKK Article 11)

You have the following rights regarding your data:
• To learn whether it is being processed
• To request information if it has been processed
• To learn the purpose of processing and whether it is used in accordance with that purpose
• To learn which third parties it has been transferred to, domestically or abroad
• To request correction of incomplete or incorrect data
• To request its deletion or destruction when the relevant conditions are met
• To object to analyses conducted by automated systems that produce an adverse result for you

You can submit your requests through the contact page (/iletisim) or to info@xdiamond.com.tr. Under KVKK Article 13, your request will be resolved within 30 days at the latest.

7. Data Security

Your data is protected using modern security standards on Cloudflare infrastructure (D1 database, R2 storage). HTTPS is mandatory (HSTS), and admin access is protected by HMAC + CSRF.

8. Manage Cookie Preferences

You can change your cookie preferences through your browser or the banner at the bottom of the website.

Last updated: August 2026