1. Introduction / Giriş
EN: This GDPR Compliance Statement explains how ("we," "us," "our") processes personal data of individuals in the European Economic Area (EEA), the United Kingdom, and Switzerland in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and applicable national data protection laws.
TR: Bu GDPR Uyumluluk Beyanı, Avrupa Ekonomik Alanı (AEA), Birleşik Krallık ve İsviçre'deki gerçek kişilerin kişisel verilerinin tarafından nasıl işlendiğini, Genel Veri Koruma Tüzüğü (Regulation (EU) 2016/679, "GDPR") ve geçerli ulusal veri koruma mevzuatına uygun şekilde açıklamaktadır.
2. Data Controller / Veri Kontrolörü
The data controller for the purposes of GDPR is:
- Entity:
- Headquarters: Istanbul, Türkiye (with EU operations through partners)
- Email:
- EU Representative: Designated upon request for EEA-resident data subjects (per GDPR Article 27)
3. Lawful Bases for Processing (Article 6 GDPR)
We process personal data only when we have a lawful basis under Article 6 of the GDPR:
- (a) Consent: For marketing communications and non-essential cookies — freely given, specific, informed, and unambiguous
- (b) Contract performance: To deliver products and services you have requested
- (c) Legal obligation: To comply with applicable laws (tax, accounting, regulatory)
- (f) Legitimate interests: To operate, secure, and improve our services, balanced against your rights and freedoms
For special categories of data (Article 9 GDPR), we rely on explicit consent or other applicable legal grounds.
4. Categories of Personal Data Processed
- Identity data: Name, professional title
- Contact data: Business email, phone, company affiliation
- Technical data: IP address, browser type, device information, cookie identifiers
- Usage data: Pages visited, content interaction, demo participation
- Communication data: Emails, meeting notes, support tickets
5. Data Subject Rights (Articles 15–22 GDPR)
If you are an EEA, UK, or Swiss data subject, you have the following rights:
- Right of access (Art. 15): Obtain confirmation and a copy of your processed data
- Right to rectification (Art. 16): Correct inaccurate or incomplete data
- Right to erasure / "right to be forgotten" (Art. 17): Request deletion under specified conditions
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interests or for direct marketing
- Right not to be subject to automated decision-making (Art. 22)
- Right to withdraw consent at any time (where consent is the basis)
- Right to lodge a complaint with a supervisory authority in your Member State of residence
To exercise these rights, contact: — we respond within 30 days as required by Article 12(3).
6. International Data Transfers (Chapter V GDPR)
As our headquarters is in Türkiye (a country not subject to a European Commission adequacy decision as of the date of this document), transfers of personal data from the EEA to us are conducted under appropriate safeguards:
- Standard Contractual Clauses (SCCs) as adopted by the European Commission Decision 2021/914
- Supplementary technical and organizational measures assessed via Transfer Impact Assessments (TIA) following the EDPB Recommendations 01/2020
- Encryption in transit and at rest for all transferred personal data
- Pseudonymization where compatible with the processing purpose
A copy of the SCCs and our TIA documentation is available to data subjects and customers upon written request.
7. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, in accordance with applicable retention requirements:
- Customer contractual data: Duration of contract + 10 years (legal/tax)
- Marketing data: Until consent withdrawal
- Website analytics: Maximum 14 months (aggregated)
- Support communications: 3 years from last interaction
8. Security Measures (Article 32 GDPR)
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk:
- Information security controls aligned with ISO 27001 principles
- Encryption (AES-256 at-rest, TLS 1.3 in-transit)
- Role-based access controls and least privilege
- Regular penetration testing and vulnerability management
- Personnel training and confidentiality agreements
- Incident response and breach notification procedures (Articles 33–34)
9. Data Breach Notification
In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority within 72 hours (per Article 33). If the breach poses a high risk, affected data subjects will also be notified without undue delay (per Article 34).
10. Children's Data
Our services are directed at business and enterprise users. We do not knowingly collect personal data from children under the age of 16. If we become aware of such collection, we will take steps to delete the data.
11. Cookies and Tracking
Detailed information on our use of cookies, including categories, retention periods, and your choices, is available in our Cookie Policy.
12. Contact and Complaints
For any questions about this statement or to exercise your rights:
- Email:
- DPO contact: dpo@cpiteknoloji.com.tr
- Postal: CPI Teknoloji Yazılım Arge ve Danışmanlık Tic. Ltd Şti., Maslak, İstanbul, Türkiye
You also have the right to lodge a complaint with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement.
Note: This GDPR Compliance Statement is provided for informational purposes. Data subjects and customers requiring formal documentation, Standard Contractual Clauses, Data Processing Agreements (DPAs), or audit reports may request these from .