Legal Center

Privacy Policy

Last updated:

Purpose and scope

This Privacy Policy explains how personal data is handled during your interaction with the https://grouptaiga.com website operated by TAIGA TEKNOLOJİ ANONİM ŞİRKETİ, its communication channels and its corporate digital assets. For the mandatory information under Law No. 6698 on the Protection of Personal Data (“KVKK”), please also review the “KVKK Privacy Notice for the Website and Contact Form”; for cookies, please review the “Cookie Notice and Policy”.

Information we may collect

  • Contact and request information: first name, last name, email, phone, company, subject, message, and files or links you share.
  • Professional information: job title, the organization you work for, project role and information relating to the proposal process.
  • Technical and usage information: IP address, device, browser, operating system, date and time, referring page, visit and interaction records, error and security logs.
  • Preference and consent information: language, cookie preferences, privacy notice version, commercial message preference and the related timestamps.
  • Career information: CV, education, experience, portfolio, profile links and information you voluntarily provide in your application.
  • Client and business partner data: proposal, contract, invoicing, project communication, delivery and support records.

Purposes of use

  • To receive and respond to contact, meeting, proposal, collaboration and support requests.
  • To plan services, conclude and perform contracts, and manage project and client relationships.
  • To operate the Site, ensure its security, prevent misuse and resolve technical issues.
  • Where you have given your explicit preference, to measure site performance, improve content and evaluate marketing effectiveness.
  • Where you have given explicit and valid consent to commercial messages, to communicate about campaigns, content and events.
  • To evaluate candidate applications and contact candidates about suitable positions.
  • To fulfil legal obligations and to establish, exercise or protect our rights.

Sharing

Your data may be shared, only to the extent necessary, with hosting, email, security, analytics, customer relationship, meeting, file sharing, recruitment and technical support providers; financial and legal advisors; subcontractors authorized within the scope of a project; legally authorized institutions; and the parties to a dispute. Personal data is not sold.

International transfers

The infrastructure of some cloud, analytics, communication, meeting, artificial intelligence or security providers may be located outside Türkiye. Transfers abroad are carried out where, pursuant to Article 9 of KVKK, there is an adequacy decision, appropriate safeguards (for example, the standard contract published by the Personal Data Protection Authority or binding corporate rules), or one of the incidental transfer cases set out in the law. Explicit consent is not used as the default solution for continuous and routine transfers. Requests for information about the appropriate safeguards may be sent to privacy@grouptaiga.com.

Retention

Data is retained only for as long as necessary for the purpose and for legal obligations. Retention periods are determined by taking into account the purpose of processing and the applicable legislation. When the period expires and no other legal ground remains, the data is deleted, destroyed or anonymized.

Security

Technical and administrative measures appropriate to the risk are applied, such as access authorization, multi-factor authentication, encryption, backups, log monitoring, supplier assessment and staff confidentiality obligations. No method of transmission or storage over the internet guarantees absolute security.

Rights and contact

To exercise your rights under Article 11 of KVKK, you may obtain information at privacy@grouptaiga.com or use the KVKK Application Form on our website. Applications are concluded within 30 days at the latest after identity and authority verification. Where the GDPR applies to individuals in the European Economic Area, the rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent and lodging a complaint with the competent supervisory authority may also apply.

Children and changes

The corporate site is not directly aimed at children. Persons under the age of 18 are expected to have the support of a parent/legal representative for applications or project communication. When the Policy is updated, the date is changed; significant changes are announced through appropriate channels.