PROFYLEE PERSONAL DATA PROTECTION AND PROCESSING POLICY
1. DEFINITIONS AND SCOPE
- Data Controller: [Company Name], [Trade Registry No], [Tax No], [Address]
- EU Representative (GDPR Art. 27): [Name & Contact Information]
- Contact: info@profylee.com | +90 501 010 93 80
- Scope: This policy applies to all personal data processing activities of individual and corporate users within Profylee’s digital services.
2. DATA CATEGORIES AND PROCESSING PURPOSES
| Category | Examples | Description |
| Identity Data | Name, national ID, date of birth | Parental consent required under age 16 |
| Professional Data | CV, education, experience, certificates | Used for candidate-job matching |
| Financial Data | Credit card, IBAN, invoice details | Encrypted via PCI-DSS compliant systems |
| Behavioral Data | Clicks, session logs, IP address | For AI analysis and security monitoring |
| Visual Data | Photo, video, screenshot | Only for optional content uploads |
Processing Purposes: Membership management, AI-based matching, legal compliance, analytics, fraud prevention, marketing (with consent)
3. LEGAL BASES AND INTERNATIONAL TRANSFERS
| Purpose | KVKK | GDPR |
| Explicit Consent | Art. 5/1 | Art. 6/1(a) |
| Contractual Necessity | Art. 5/2(c) | Art. 6/1(b) |
| Legal Obligation | Art. 5/2(ç) | Art. 6/1(c) |
| Legitimate Interests | Art. 5/2(f) | Art. 6/1(f) |
International Transfers:
Data is transferred outside the EEA only using SCCs (Standard Contractual Clauses) and technical/organizational safeguards. The data protection adequacy of recipients is evaluated in advance.
4. DATA RETENTION
| Data Type | Retention Period | Deletion Process |
| Account Information | Until account deletion | Fully deleted within 90 days |
| Billing Information | 10 years (statutory obligation) | Stored in encrypted archives |
| CVs & Content | 2 years (after inactivity) | Auto-tagged and deleted |
5. USER RIGHTS
- Access, correction, deletion, portability
- Withdrawal of consent, objection to automated decisions
- Complaint and compensation claims
How to Exercise Rights:
🔹 Online: [profylee.com/data-rights]
🔹 Email: privacy@profylee.com
🔹 Mail: [Address] (with notary approval)
🕓 Response Time: 30 days (KVKK) / 1 month (GDPR)
6. SECURITY & BREACH MANAGEMENT
- ISO/IEC 27001, 27701 certified infrastructure
- AES-256 encryption, TLS, 2FA, IP filtering
- Monthly penetration testing
Breach Notification:
- To authorities: within 72 hours
- To users: within 7 days (if risk is present)
7. CHILDREN’S DATA & SPECIAL CATEGORIES
- Users under 16 must provide verified parental consent
- Special categories (health, belief, etc.) processed only with explicit consent
- Aligned with COPPA and GDPR Art. 8
8. THIRD PARTIES & SUB-PROCESSORS
| Provider | Service | Data Type | Country |
| AWS | Hosting | Encrypted data | EU / USA |
| Google Cloud | Integrations | User content | EU |
| Stripe | Payments | Tokenized card data | USA |
| Google Analytics | Analytics | Anonymized usage data | Global |
| SendGrid | Email delivery | Email addresses | USA |
| Cloudflare | Security | IP & session information | Global |
9. UPDATES & NOTIFICATION
- Policy updates will be communicated via email 30 days in advance
- Latest version available at: [profylee.com/privacy]
10. JURISDICTION & DISPUTE RESOLUTION
| User Location | Competent Court | Applicable Law |
| Türkiye | Istanbul Çağlayan Courts | Turkish Law |
| EU / UK | London Commercial Court | English and Welsh Law |
| USA | Delaware State Courts | Delaware Law |
| Other Countries | ICC Arbitration (Paris) | UNCITRAL Rules |
ANNEXES
- Annex A: Data Processing Inventory
- Annex B: AI Transparency Report
- Annex C: Data Breach Notification Procedure
- Annex D: Extended Cookie Policy
ANNEXES
ANNEX A: DATA PROCESSING INVENTORY
| Data Type | Purpose | Legal Basis | Retention Period | Transfer Status |
| Name, Surname | Identity verification, account creation | Contract, Legitimate interest | Until account deletion | No |
| Email, Phone | Communication, notifications | Contract, Consent | Until account deletion | Yes (SendGrid) |
| IP, Browser Info | Security, traffic control | Legitimate interest | 1 year | Yes (Cloudflare) |
| CV, Education, Exp. | Matching, profiling, analytics | Contract, Legitimate interest | 2 years (for inactive) | Yes (AI infrastructure) |
| Credit Card Data | Payment transactions | Consent, Legal obligation | Deleted by Stripe instantly | Yes (Stripe) |
| System Logs | Legal evidence, breach analysis | Legitimate interest | 2 years | Upon request |
| Profile Images | Profile and content display | Consent | Until account deletion | No |
ANNEX B: AI ALGORITHM TRANSPARENCY REPORT
| Application Area | Description |
| CV-Position Matching | AI suggests based on tags, skills, experience similarity, and success scores |
| Profile Scoring | Calculated from engagement history, publication quality, feedback signals |
| Recommendation Engine | Personalized job/content suggestions based on interactions |
| User Challenge Rights | Users can query decisions at privacy@profylee.com |
| Training Dataset | Trained on anonymized, opt-in user data only |
| Human Oversight | AI cannot make binding decisions without human review |
ANNEX C: DATA BREACH NOTIFICATION PROCEDURE
1. Definition:
A personal data breach is unauthorized access, alteration, deletion, loss, or misuse.
2. Detection:
Technical team detects issues via logs within 24 hours.
3. Notification Timeline:
| Recipient | Deadline |
| DPA (KVKK/GDPR) | Within 72 hours |
| Affected Users | Within 7 days |
4. Measures Taken:
- Immediate access suspension
- Mandatory password resets
- Access privileges reviewed
- Detailed disclosure to affected users
ANNEX D: DETAILED COOKIE POLICY
| Cookie Name | Type | Retention | Purpose |
| session_id | Strictly necessary | Session | Session control, authentication |
| _ga, _gid | Analytics | 1 year / 24 hr | Google Analytics traffic data |
| language_pref | Functional | 6 months | Stores UI language choice |
| consent_cookie | Essential | 12 months | Stores user cookie preference |
| utm_* | Tracking | 30 days | Campaign tracking (not used by default) |
Note: Profylee does not use marketing/tracking cookies.
All cookies can be managed through user dashboard or browser settings.