Legal
Privacy notice
This notice explains what United Armor Xperts A.Ş. (“UAX”) does, and does not do, with personal data in connection with uax.com.tr. It is written to be verifiable against the site itself: everything stated here can be confirmed from the page source and network activity of this site.
These notices are published in English, which is the governing version. Turkish and Japanese translations are in preparation with counsel; where a translation is later published, the English text prevails in the event of any discrepancy.
Scope
This notice covers the public website at uax.com.tr. It does not cover correspondence conducted after an institutional engagement has begun under a separate agreement, which is governed by that agreement.
UAX is the data controller for personal data processed under this notice. UAX is established in Türkiye and treats the Turkish Personal Data Protection Law No. 6698 (KVKK) as the primary framework. Other laws may apply depending on the visitor and transaction; qualified counsel must confirm that position for a specific case.
What this site does not do
This site sets no cookies and uses no third-party analytics, tag manager, advertising pixel or session recording. It embeds no third-party map, video platform, scheduling widget or social plug-in.
The site's Content-Security-Policy restricts scripts, forms and data connections to the UAX origin. Following an outbound source link is a deliberate navigation to that external site; no external resource is loaded merely because you read a UAX page.
Enquiry form and public briefs
The same-origin enquiry form collects only the interest category, organisation, country, name, role, corporate or official email address and one-line general end use that you submit. It accepts no attachment. The record also carries the selected interface language, submission time, acknowledgement reference and the privacy-notice version acknowledged with the form.
The form data is stored in access-controlled, append-only server storage outside the public web root. It is used to assess, acknowledge and respond to the enquiry, to protect the service against abuse and, if both sides proceed, to support pre-contract engagement. A public brief may be opened or downloaded without completing the form.
UAX does not sell enquiry data or use it for unrelated advertising. The supplied V13 server policy removes unprogressed enquiry records after 180 days. Records connected with an active engagement or a legal, tax, export-control or security obligation may need to be kept longer under the applicable record schedule.
Cookieless first-party measurement
To understand whether the public journey is useful, the UAX server records a small closed vocabulary of events: audience-route view, public-brief use, enquiry submission and controlled-path step. It records no page text, form content or advertising identifier.
For rough daily deduplication and abuse control, the server derives a short salted day identifier from the requesting network address and browser user-agent. The raw address and user-agent are not written to the funnel log, and the identifier changes each UTC day. Because a derived identifier can still be personal data in some jurisdictions, this notice describes it as pseudonymous rather than anonymous. Funnel records are removed after 30 days. Browser Do-Not-Track signals disable optional client-side events.
Information stored in your browser
Two preferences are stored locally in your own browser using localStorage: your chosen interface language and your chosen light or dark theme. These values stay on your device, are readable only by this site, and are never transmitted to UAX or to any third party. Clearing your browser's site data removes them.
If you contact us by email
If you use email instead of the form, UAX processes the personal data contained in your message — typically your name, organisation, role, country, email address and whatever you choose to write — to assess and respond to the enquiry.
Depending on the facts and applicable law, the processing basis may include responding to a legitimate business enquiry and taking steps requested before a possible contract. This notice is not a substitute for transaction-specific privacy advice.
Email correspondence follows the same operational retention principle as form enquiries: delete unprogressed enquiries when they are no longer needed, and retain active or regulated records only for the period required by the applicable schedule.
Your message reaches a mailbox operated for UAX by its email service provider. UAX does not sell personal data, does not use it for marketing, and does not transfer it to any third party except where a specific legal or regulatory obligation requires it, or where you have asked us to involve a named adviser.
What you must not send
Do not send classified information, export-controlled technical data, proprietary geometries, formulations, test data, passwords, credentials, identity documents, or any special category of personal data by email or through any public channel of this site. Email is not an authorised channel for controlled material.
Identity and authority verification, any non-disclosure agreement, and any applicable export-control or sanctions review are conducted through separate secure channels after an enquiry is accepted — never through this website.
Your rights
Under KVKK Art. 11 and, where applicable, GDPR Chapter III, you may ask UAX to confirm whether it holds personal data about you; to give you a copy; to correct it; to erase it; to restrict or object to its processing; and to provide it in a portable form. You may also lodge a complaint with the Turkish Personal Data Protection Authority (KVKK Kurumu) or, where the GDPR applies, with your local supervisory authority.
To exercise any of these rights, write to engagement@uax.com.tr and state clearly which right you are exercising. UAX responds within the period required by the law that applies to the request.
Security and changes
This site is served over HTTPS. Its PHP endpoints accept only the defined same-origin form and event fields, reject attachments, rate-limit writes and keep operational records outside the public web root. The site stores no authentication or session token in the visitor's browser.
This notice may be updated. The effective date and version above always identify the operative version; material changes are reflected in a new version number rather than a silent edit.
Questions about this notice should be directed to the engagement desk through the controlled engagement pathway.