GDPR Information Notice

Last update:

Company: Nodeflame OU
Address: Kesklinna district, Tallinn city, Harju county, Viru väljak 2, 10111, Estonia
Contact: info@nodeflame.com

I. DATA PRIVACY COMMITMENT

1.1.

This Personal Data Protection Policy (the “Policy”) sets out the principles, rules, and processes of Nodeflame OU (the “Company”) regarding the protection of personal data in accordance with Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”) and applicable legislation.

1.2.

The Company undertakes to comply with this Policy and related internal procedures with respect to all personal data it processes.

Role Distinction: The Company acts as the data controller with respect to website visitor data. For customer end-user data processed within the scope of B2B software/AI solutions provided to customers, the Company acts as a data processor on a contractual basis (a separate Data Processing Agreement/DPA applies).

II. PURPOSE OF THE POLICY

To establish the methods, principles, and processes regarding the processing and protection of personal data.

III. SCOPE OF THE POLICY

3.1.

This Policy applies to all personal data processing activities carried out by the Company.

3.2.

Data that does not qualify as personal data is outside the scope of this Policy.

3.3.

This Policy may be updated with management approval in accordance with applicable legislation or operational requirements.

In the event of any conflict between applicable legislation and this Policy, the applicable legislation shall prevail.

IV. DEFINITIONS (SUMMARY)

The terms Explicit Consent, Anonymization, Obligation to Inform, Personal Data/Personal Data of a Special Nature, Processing, Data Controller, Data Processor, and Deletion/Destruction shall be interpreted and applied in accordance with their respective definitions under the KVKK.

Where necessary, roles such as committee members or contact persons may be defined in internal guidelines.

V. PRINCIPLES OF PERSONAL DATA PROCESSING

  • Lawfulness, fairness, and proportionality

  • Accuracy and keeping data up to date, with correction processes in place

  • Processing for specific, explicit, and legitimate purposes, with explicit consent obtained where required

  • Processing in connection with, limited to, and proportionate to the purpose, in accordance with the principle of data minimization

  • Deletion, destruction, or anonymization upon expiry of the applicable retention period

VI. PROCESSING OF PERSONAL DATA

6.1. Processing with Explicit Consent

Where required, explicit consent is obtained following the provision of the relevant privacy notice and is retained in a manner that allows it to be demonstrated.

6.2. Processing Without Explicit Consent

Personal data may be processed without explicit consent in accordance with the exceptions under Articles 5/2 and 6/3 of the KVKK, including legal requirements, actual impossibility, performance of a contract, fulfillment of legal obligations, data being made public by the data subject, establishment or protection of a right, and legitimate interests, provided that fundamental rights and freedoms are not adversely affected.

VII. PERSONAL DATA OF A SPECIAL NATURE

  • As a general rule, explicit consent is required, subject to statutory exceptions.

  • Health and sexual life data may only be processed under the specific conditions prescribed by law and by authorized persons.

  • Technical and administrative measures prescribed by the Turkish Data Protection Board are implemented, including cryptography, access controls, logging, two-factor authentication (2FA), physical security, testing and patch management, training, and confidentiality undertakings.

VIII. RETENTION PERIODS

Personal data is retained for the period required by the relevant purposes and applicable legislation. Once the purpose or applicable retention period expires, the data is deleted, destroyed, or anonymized.

Further details are set out in the Personal Data Retention and Destruction Policy.

IX. DELETION, DESTRUCTION, AND ANONYMIZATION

When the legitimate purpose or applicable retention period expires, the relevant destruction processes are carried out.

Compliance is also ensured with respect to copies held by third parties.

Personal data is not retained merely as a precaution without a legitimate purpose or legal basis.

X. TRANSFERS AND PROCESSING BY THIRD PARTIES

  • Transfers within Türkiye: Conducted in accordance with the KVKK and supported by contractual security provisions.

  • International transfers: Conducted in accordance with the requirements of Article 9 of the KVKK, including adequate protection, undertakings and Turkish Data Protection Board authorization, or explicit consent, as applicable.

  • Suppliers: For suppliers providing hosting, security, email, analytics, and similar services, appropriate technical and administrative measures are implemented and relevant records are maintained.

XI. OBLIGATION TO INFORM

When personal data is collected, the information required under Article 10 of the KVKK is provided, including the identity of the data controller, processing purposes, recipient groups, collection methods and legal grounds, and the rights of the data subject.

Where third parties process or transfer personal data on behalf of the Company, appropriate contractual and instruction mechanisms are implemented.

XII. DATA SUBJECT APPLICATIONS AND RIGHTS

The rights set forth under Article 11 of the KVKK include the right to:

  • Access personal data and obtain information;

  • Request information regarding the purposes and suitability of processing;

  • Learn the third parties to whom personal data has been transferred;

  • Request correction;

  • Request deletion or destruction and notification of such actions to relevant third parties;

  • Object to a result arising against the data subject through exclusively automated processing; and

  • Claim compensation for damages.

Application Channel: info@nodeflame.com

Applications will be responded to within no later than 30 days. Where additional costs arise, the tariff determined by the Turkish Data Protection Board may apply.

XIII. DATA MANAGEMENT, SECURITY, AND ACCESS

Appropriate technical and administrative measures are implemented, including authorization, encryption, backups, firewalls, malware protection, logging, security patches, and testing.

Personnel training, confidentiality obligations, and the principle of granting access only to the extent necessary are fundamental.

Access to personal data of a special nature is restricted, and periodic controls are conducted.

XIV. TRAINING

Personnel receive regular training regarding the KVKK and internal procedures. Processes involving personal data of a special nature are addressed separately.

XV. AUDIT

Compliance with this Policy and applicable legislation is reviewed through periodic internal audits. Improvements are implemented based on audit findings.

XVI. INCIDENT AND BREACH MANAGEMENT

Internal reporting channels are used for data breaches or suspected breaches.

Incident management, impact assessments, and, where necessary, notification procedures to the Turkish Data Protection Authority and relevant data subjects are carried out in accordance with applicable legislation.

Corrective and preventive actions are implemented as necessary.

XVII. PUBLICATION OF CHANGES

This Policy may be updated with management approval.

The current version is published on www.nodeflame.com and/or shared with employees.

XVIII. EFFECTIVE DATE

This Policy entered into force on 13/10/2025.

Contact: info@nodeflame.com
Address: Kesklinna district, Tallinn city, Harju county, Viru väljak 2, 10111, Estonia