CONSENT, DATA PROCESSING AND PRIVACY NOTICE
(Ultimate Global Compliance Version – GDPR + KVKK + CCPA + LGPD Compliant)**
Profylee (“Platform”, “we”, “us”) is committed to processing, storing and protecting your personal data in accordance with the highest international privacy and security standards.
This Privacy Notice and Consent Statement has been prepared in compliance with:
GDPR (EU Regulation 2016/679), KVKK (Turkish Data Protection Law No. 6698), CCPA/CPRA, LGPD (Brazil), OECD Privacy Principles, ISO/IEC 27701 and other global data protection regulations.
Please read this document carefully before using the Platform.
1. DATA CONTROLLER
Since the company establishment process is ongoing, the Platform currently operates under the name Profylee.
Data Controller: Profylee
E-mail: [contact@example.com]
Address: [To be added upon company establishment]
Data Protection Officer (DPO): To be appointed. Until then, all requests should be submitted to the contact address above.
2. CATEGORIES OF PERSONAL DATA PROCESSED
The following categories of personal data may be collected, processed, stored and transferred for the operation of all Platform modules (Wallet, Flow, Works, Showcase, Publish, Analytics, Insight, Wall, Message, Calendar, AI Digital Identity, Search Engine):
2.1. Identity Data
- Name, surname
- Age / year of birth
- Gender (optional)
- Profile name / username
2.2. Contact Data
- E-mail address
- Phone number
- Location information (country/city)
- IP address
2.3. CV & Professional Career Data
(Required for the core functionality of the Platform)
- Education details
- Work experience
- Certificates and documents
- References
- Skills and competencies
- Foreign language proficiency
- All CV content uploaded by the user
**2.4. User-Generated or Uploaded Content
(Publish, Showcase, Works, Wall Modules)**
- Articles, writings, posts
- Project files and works
- Portfolio items
- Job listing details
- Announcements, posts, texts and images shared through Wall
- Comments, likes, interactions
- Uploaded files, visuals, documents, videos
Wall Module Clause:
“Content, posts, text, images, comments, likes and interaction data shared by the user through the Wall module are processed as User-Generated Content (UGC).”
2.5. Visual / Audio Data
- Profile photo
- Video CV (optional)
2.6. Messaging Data (Message Module)
- Direct message content
- Conversation records
- Timestamp information
Note: All message content is protected through robust security measures.
2.7. Wallet & Payment Data (Wallet Module)
- Wallet balance
- Credits used
- Transaction history
- Payment provider transaction ID (PayTR, Paddle)
- Invoice information
Credit card details are not stored by Profylee.
**2.8. Behavioral and Technical Data
(Analytics, Insight, AI, Search)**
- Platform usage behavior
- Search history
- Employer interaction logs
- Clickstream data
- IP, device, browser information
- Cookies
- Session logs (retained for 15 days)
- Heatmap, scroll and interaction data (anonymous)
**2.9. AI Model Processing Data
(Using OpenAI infrastructure)**
- Automated CV analysis
- Summarization, classification, tagging
- Matching score generation
- Profile optimization suggestions
- Embedding (vector) generation for search algorithms
Personal data is anonymized before processing.
No data is used for model training.
2.10. Calendar Integration (Google Calendar API – Full Scope)
- Event reading
- Event creation
- Event updating / deletion
- Meeting synchronization
Profylee fully complies with Google Calendar API Restricted Scope Requirements.
3. LEGAL BASIS FOR PROCESSING PERSONAL DATA
3.1. Explicit Consent (GDPR 6/1-a, KVKK 5/1)
- CV processing
- Profile matching
- AI-based analysis and summarization
- Global visibility
- Google Calendar API access
- Storage of Wallet transaction history
- Retention of message content
3.2. Performance of a Contract (GDPR 6/1-b, KVKK 5/2-c)
- Account creation
- CV sharing
- Job search and job posting
- Service exchange through Works module
- Operation of Flow, Pool and employer dashboards
3.3. Legitimate Interest (GDPR 6/1-f, KVKK 5/2-f)
- Fraud prevention
- Security logging
- Fake account detection
- Analytics and performance measurement
3.4. Legal Obligations (GDPR 6/1-c, KVKK 5/2-ç)
- Regulatory requests
- Government investigations
- Mandatory record retention (financial and legal)
4. PURPOSES OF PROCESSING PERSONAL DATA
4.1. Platform Services
- Creating digital CVs
- Profile visibility
- Job matching
- Job posting – application – offer processes
- Freelancer–employer interactions
- Content sharing through Wall
- Creating company/freelancer showcases
- Publishing articles and content
- Flow (Pipeline management)
- Pool (Candidate database)
4.2. AI-Based Processing
- CV analysis
- Recommendation generation
- Tag extraction
- Matching score generation
- Creating SEO-friendly digital identity
- Search engine optimization
4.3. Wallet Operations
- Credit movements
- Purchases
- Invoice generation
- PayTR / Paddle payment transactions
4.4. Security and Operational Purposes
- Fraud prevention
- IP log retention (15 days)
- Account security
5. SHARING PERSONAL DATA WITH THIRD PARTIES
5.1. Service Providers
- OpenAI (anonymized processing)
- PayTR
- Paddle
- Server/hosting providers
- Google Calendar API
5.2. Employers and HR Companies
Your profile may be viewed by global employers solely for job-related purposes.
There is no premium visibility system; all visibility is equal.
5.3. Government Authorities
Only when legally required.
5.4. International Transfers
Transfers outside Türkiye or the EU are carried out under:
- Standard Contractual Clauses (SCC)
- Data minimization
- Anonymization
6. DATA RETENTION PERIODS
- Profile & CV data: Active account + 1 year
- Wallet transactions: As required by financial regulations
- Logs: 15 days
- Message content: Until account deletion
- Flow / Pool data: 1 year
- Calendar data: Until user deletion request
All data is securely destroyed at the end of retention periods.
7. USER RIGHTS
Under GDPR (Articles 15–22), KVKK, CCPA, and LGPD, you have the right to:
- Request information
- Access your data
- Request correction
- Request deletion (“right to be forgotten”)
- Restrict processing
- Request data portability
- Object to processing
- Withdraw consent
- File a complaint with data protection authorities
Requests: [contact@example.com]
8. SECURITY MEASURES
Profylee implements:
- ISO/IEC 27001 & 27701 aligned security framework
- SSL/TLS encryption
- Two-factor authentication (2FA)
- Token-based API security
- Access log monitoring
- Data minimization
- Secure storage and access policies
9. CONSENT STATEMENT
(Required for the core functionalities of the Platform)
“I have read and understood the Privacy Notice.
I hereby give my explicit consent for Profylee to process my personal data for the purposes of:
Creating and managing my CV, profile, job matching, AI-powered analysis, messaging, search engine functions, calendar integration, wallet operations, security measures, global visibility, sharing with employers, and the operation of all Platform modules.
I consent to sharing my data with service providers such as PayTR, Paddle and OpenAI.
I consent to the anonymized processing of my data for AI-based operations.
I consent to the access and management of my calendar information through the Google Calendar API.”
☐ I Accept
☐ I Do Not Accept
Full Name:
Date:
(Digital confirmation is sufficient; no signature required.)