Legal
Privacy policy
Last updated: 20 July 2026
This is a translation provided for convenience; the Turkish version is the governing version.
This privacy policy explains how Corpshore Türkiye processes personal data through corpshore.tr and within the scope of its commercial relationships. The policy is based jointly on the Personal Data Protection Law No. 6698 (KVKK) and its secondary legislation and, for customers whose data subjects are located in the European Union, on the requirements of the General Data Protection Regulation (GDPR).
Identity of the data controller
The data controller is Corpshore Türkiye, the Türkiye operation acting on behalf of Corpshore Solutions Corporation. Registered address: The Exchange Tower, 130 King Street West, Suite 1900, Toronto, Ontario M5X 2A2, Canada. The data controller representative in Türkiye and the VERBİS registration details will be updated in this text once the relevant appointment is complete.
For any question, request or application under this policy, data subjects may use the application methods set out at the end of this text. Contact addresses relating to Türkiye operations and the data controller representative details will be published once the appointment is complete.
Categories of personal data processed
Customer and prospective customer data: first name, last name, work email, telephone, company, country, sector, requested service line, team size, language needs, target start time and free text content. This data is processed to carry out proposal, meeting and pre-contractual processes.
Candidate data: first name, last name, contact details, city and district, work permit status, language competencies and levels, experience, position applied for, resume and cover letter content. Candidate data is addressed separately in the candidate information notice.
Visitor data: technical data relating to site use, information collected through cookies and, where explicit consent has been given, analytics data. Cookies are explained separately in the cookie policy.
Commercial electronic message data: contact details and preference data processed within the scope of the explicit consent given for newsletters and marketing communications.
Processing purposes and legal grounds
Personal data is processed on the legal grounds set out in Articles 5 and 6 of the Law. The carrying out of proposal and pre-contractual processes relies on the ground that it is directly related to the establishment or performance of a contract.
The fulfilment of legal obligations is a ground for processing in respect of obligations arising from the legislation to which the data controller is subject. The legitimate interest ground is applied on a limited basis, for purposes such as ensuring service quality and security, provided that it does not harm the fundamental rights and freedoms of the data subject.
In consent-based processing such as marketing communications, explicit consent is taken as the legal ground and consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out up to the moment of withdrawal.
Transfer of personal data
Personal data may be transferred, to the extent required by the service and in compliance with the relevant legislation, to suppliers acting in the capacity of data processor. These include the Zoho platforms used for customer and candidate relationship management and the hosting service provider.
Where a transfer abroad is involved, the transfer is carried out on the basis of an appropriate mechanism such as a standard contract, binding corporate rules or an adequacy decision, within the framework of the relevant provisions of the Law and the current secondary legislation. Transfer abroad is explained in detail in the data transfer policy.
Personal data is transferred to the relevant authorities only within the scope of a legal obligation or the duly made requests of authorized public institutions.
Retention periods
Prospective customer and proposal data is retained, depending on the nature of the relationship, for a maximum of three years from the conclusion of the proposal process, and is deleted, destroyed or anonymized at the end of that period.
In relationships that turn into a contract, data is retained throughout the contractual relationship and the limitation periods prescribed by the relevant legislation. Data relating to commercial books and records is kept for the periods prescribed by the Turkish Commercial Code (No. 6102).
Candidate data is retained for the periods stated in the candidate information notice. Consent-based marketing data is retained until consent is withdrawn or, at most, until the specified periodic review period.
Rights of the data subject
Under Article 11 of the Law, the data subject has the right to learn whether their personal data is being processed, to request information if it has been processed, to learn the purpose of processing and whether the data is used in accordance with that purpose, to know the third parties to whom it has been transferred domestically or abroad, and to request its correction if it has been processed incompletely or incorrectly.
The data subject also has the right, within the conditions prescribed by the Law, to request the deletion or destruction of their personal data, to request that correction, deletion and destruction operations be notified to the third parties to whom the data has been transferred, to object to a result arising against them from the analysis of the processed data solely through automated systems, and to demand that the damage be remedied if they suffer any loss.
Applications are submitted through the methods set out at the end of this text, and requests are concluded, depending on their nature, as soon as possible and within thirty days at the latest. If the application is rejected, the data subject has the right to file a complaint with the Personal Data Protection Board.
Automated decision making
In the processes carried out through the site, no decision that produces a legal consequence against the data subject or significantly affects the person in a similar way, and that is based solely on automated processing, is made. Any scoring for the prioritization of requests is used in a manner that supports human assessment and does not replace final decisions.
Security measures
Corpshore Türkiye takes appropriate technical and administrative measures to prevent the unlawful processing of and access to personal data and to ensure its safekeeping. These measures are detailed in the information security policy and cover transfer security, access management, record keeping and regular review.
In the event of a breach, the breach is notified to the Personal Data Protection Board and, where necessary, to the data subjects, in accordance with the periods and procedures prescribed by the relevant legislation.
Children's data
The site and services are not directed at children and personal data belonging to children is not knowingly collected. If it is determined that data belonging to a child has been submitted without consent, the data is deleted without delay.
Changes and applications
This policy may be revised in line with legislative changes and updates to processing activities. The current version is always published on this page and its effective date is stated.
The application channels relating to Türkiye operations, for exercising your rights and submitting your questions, will be set out in this section once published. Until then, applications may be made through the group contact channels.
These documents are drafted to a professional standard and will be reviewed by Turkish legal counsel before going live. They are not legal advice.
