Privacy Policy
Last update:
This Privacy Notice and Privacy Policy (the “Policy”) has been prepared by Nodeflame, acting as the data controller pursuant to the Turkish Law No. 6698 on the Protection of Personal Data (“KVKK”), to explain the procedures and principles regarding the processing of personal data collected during the operation of the website located at https://www.nodeflame.com and its associated subdomains (collectively, the “Site”).
Our Role: We are the data controller for visitor data processed within the scope of the Site. Where Nodeflame processes end-user data on behalf of its customers within the scope of the B2B software/AI products it provides, Nodeflame acts as a data processor in respect of such data, contractually (a separate Data Processing Agreement/DPA applies).
Legal Entity: Nodeflame OU
Address: Kesklinna district, Tallinn city, Harju county, Viru väljak 2, 10111, Estonia
Contact: info@nodeflame.com
1) Changes to the Policy
The current version of this Policy shall apply each time you use the Site. We will announce updates through the Site.
For questions regarding this Policy, you may contact us at info@nodeflame.com.
2) Identity of the Data Controller
Pursuant to the KVKK, Nodeflame is the data controller. Our contact details are provided above.
3) Categories of Data Collected and Methods of Collection
Visit/technical data: IP address, browser/device information, log records, cookie identifiers.
Communication/form data: Full name, email address, telephone number, company/title, message content.
Marketing preferences (optional): Newsletter/marketing communication consent and opt-out preferences.
Career data (where applicable): Application and CV information.
Methods: Website forms, cookies and similar technologies, system logs, and support channels.
(For details regarding cookies, please see the “Cookies” section.)
4) Purposes of Processing and Legal Grounds
Your personal data may be processed for the following purposes and on the legal grounds set forth under Article 5/2 of the KVKK:
Provision, security, and performance of the Site: Logging, attack prevention, and error tracking (legitimate interest – Article 5/2-f).
Responding to communications and pre-contractual processes: Requests/quotes, demos, and responses (performance of a contract – Article 5/2-c, or legitimate interest – Article 5/2-f).
Fulfillment of legal obligations (Article 5/2-ç).
Marketing communications/newsletters (optional): Only where you have provided your explicit consent (explicit consent – Article 5/1).
Except where explicit consent is required, we observe the principle of data minimization.
5) Transfers and Categories of Recipients
To the extent necessary and limited to the purposes specified above, your personal data may be transferred to our service providers for hosting, security, email/communication management, analytics, maintenance, and consulting services, as well as to legally authorized public institutions and organizations.
Where an international transfer of personal data is required, we act in accordance with the applicable requirements under Article 9 of the KVKK, including explicit consent or safeguards determined by the Turkish Data Protection Board.
You may request our current list of subcontractors/service providers by contacting us at info@nodeflame.com.
6) Retention Periods
Visit/Log data: [12–24 months]
Communication/Form data: [3 years]
Marketing consent/opt-out records: For the period required under applicable legislation
Career applications: [1 year] (in case of rejection; may be retained for a longer period with your explicit consent)
Retention periods are determined by taking into account legal obligations and the balance of legitimate interests. When the relevant purpose ceases to exist and/or the applicable retention period expires, the data will be destroyed in accordance with applicable legislation through deletion or anonymization.
7) Data Security
We seek to protect your personal data through appropriate technical and administrative measures, including access controls, encryption, logging/monitoring, contractual security provisions, and data minimization.
Although 100% security of data transmitted over the Internet cannot be guaranteed, we apply reasonable industry-standard security practices.
8) Rights of Data Subjects (KVKK Article 11)
You have the following rights:
The right to access your personal data and request information regarding its processing;
The right to request correction;
The right to request deletion or destruction;
The right to request restriction of processing;
The right to know the third parties to whom your personal data has been transferred;
The right to object to a result arising against you from the analysis of your personal data exclusively through automated systems;
The right to claim compensation in the event of damage; and
Where applicable, the right to withdraw your consent.
Application: You may submit your request to info@nodeflame.com together with information verifying your identity.
Response Period: We will respond to your request within no later than 30 days. Where additional costs arise, a fee may be charged in accordance with the tariff determined by the Turkish Data Protection Board.
9) Third-Party Links
The Site may contain links to third-party websites/tools. Nodeflame is not responsible for the content or privacy practices of such third parties. We recommend that you review their respective privacy policies.
10) Cookies and Similar Technologies
The Site may use essential cookies (session and security), as well as optional functional and analytics cookies. Where required, your explicit consent will be obtained for analytics/functional cookies, and you may manage your preferences through the cookie banner/settings.
Example categories:
Essential: Required for the operation of the Site (consent is not required).
Analytics/Performance: Used for traffic measurement and improvements (consent required).
Functional: Used to remember user preferences (consent required).
The analytics/measurement tools we use collect and report personal data in a manner that does not directly identify you, based on how these tools are configured.
The tools/cookies we use may change. You may request the current list by contacting us at info@nodeflame.com.
You may delete or disable cookies through your browser settings. Please note that doing so may restrict certain functionalities of the Site.
11) Processing Period
Your personal data will be processed for the retention periods prescribed by applicable legislation or specified in this Policy, and for as long as the relevant processing purposes continue. When the purpose and/or retention period expires, the data will be destroyed in accordance with applicable legislation.
12) Note for B2B Products (Data Processor Role)
With respect to end-user data processed within the scope of the enterprise software/AI solutions provided by Nodeflame to its customers, Nodeflame acts as a data processor. The scope, instructions, security measures, and subcontractor provisions are governed separately under a Data Processing Agreement (DPA).
13) Contact
Nodeflame – Data Controller
Address: Kesklinna district, Tallinn city, Harju county, Viru väljak 2, 10111, Estonia
Email: info@nodeflame.com
