How MELIQ LABS collects, uses, and protects your personal data.
Last updated: May 11, 2026
MELIQ LABS LLC is the data controller responsible for the personal data described in this policy. The company is a limited liability company registered in the State of Wyoming, United States, building custom websites, mobile applications, and admin panels for businesses worldwide.
When you submit our contact form, we collect your name, email address, company name (if provided), selected service type, and message content. This information is provided voluntarily and is necessary for us to respond to your inquiry.
With your consent, we use Google Analytics to understand how visitors interact with our website. This includes page views, session duration, device type, browser information, approximate geographic location, and referral source. Data is collected in an aggregated, anonymised form.
We detect your approximate country based on your IP address to deliver a localised experience (language, theme). This detection is performed server-side and no granular location data is stored.
Our website uses a limited number of cookies to function properly. See Section 9 for a detailed breakdown.
We process personal data under the following legal bases (GDPR Article 6 and KVKK Article 5):
We never sell, trade, or rent your personal data. We share data only with the following service providers (sub-processors) strictly for the operation of the website:
| Sub-processor | Purpose | Region |
|---|---|---|
| Resend, Inc. | Transactional email delivery for contact form submissions | United States (EU SCC) |
| Google LLC (Analytics 4) | Anonymous website traffic analysis (consent required) | United States (EU SCC) |
| Cloudflare, Inc. | DNS, CDN, DDoS protection, edge security | United States / Global |
| Hetzner / Coolify VPS | Application hosting and server logs | European Union (Germany / Finland) |
| MaxMind, Inc. | GeoIP country detection database (offline lookup) | United States |
All transfers outside the European Union take place under Standard Contractual Clauses (SCC) or equivalent safeguards. You may request an up-to-date sub-processor list at any time via the contact email listed in Section 1.
Because some of our sub-processors are located in the United States, your personal data may be transferred outside the European Economic Area (EEA) and Türkiye. Each transfer is protected by Standard Contractual Clauses approved by the European Commission (or equivalent contractual safeguards under KVKK Article 9).
If you are a resident of the European Union or European Economic Area, you have the following rights:
If you reside in Türkiye, under the Personal Data Protection Law (No. 6698 / KVKK) you have all the rights listed above, including the right to lodge a complaint with the Personal Data Protection Board (KVKK Kurulu).
To exercise any of these rights, please contact [email protected]. We respond to all verified requests within 30 days.
| Cookie | Purpose | Duration |
|---|---|---|
| MELIQ_CONSENT | Stores your cookie consent preference (accepted or rejected) | 1 year |
| MELIQ_THEME | Stores your selected visual theme (light/dark, gold/turquoise) | 1 year |
| NEXT_LOCALE | Stores your preferred language (en or tr) | Session |
All cookies above are strictly functional. We do not use advertising or tracking cookies other than Google Analytics, which is only loaded after you grant consent.
We use industry-standard technical and organisational measures to protect your personal data: HTTPS by default, hashed authentication secrets, dependency updates, restricted server access, and daily backups. No internet transmission can be 100% secure, but we continuously improve our security posture.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it (GDPR Article 33) and the KVKK Board where applicable. If the breach is likely to result in a high risk to you, we will also notify you directly without undue delay (GDPR Article 34).
Our website is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us so we can delete it.
We may update this privacy policy from time to time to reflect changes in our practices or applicable laws. When we make material changes, we will update the "Last updated" date at the top of this page. We encourage you to review this page periodically.
For any questions about this privacy policy, your personal data, or to exercise your rights, please contact us at [email protected].