Privacy & cookie notice / Updated 7 October 2026
Clear purposes.
Accountable handling.
This notice explains how personal information is used when you visit EnterTurkey, contact our team, purchase a review or appear in supplier research. It covers business contact information as well as customer accounts and documents.
Contact us about your information→The EnterTurkey operation
EnterTurkey is the business name of the research and consulting operation described on this website. The operation is managed by Recep Çevik, Co-Founder and General Manager, and coordinated from Ankara, Türkiye. EnterTurkey determines the purposes and means of handling customer and enquiry information described here.
Send a message directly to our management review queue through the personal information request page. No membership, payment or appointment is needed. Include your review reference where relevant and a contact email for our response.
Where a review is commissioned for a business customer, that customer remains responsible for the lawfulness of the personal information it supplies. Any separately agreed data-processing terms for a particular engagement apply alongside this notice.
What we collect, and where it comes from
- Business enquiries: your name, business email, company and any optional phone, location, timing or description you provide.
- Customer accounts and purchases: account identifiers, login email, selected package, order and payment status, purchase reference and related service correspondence. Authentication and payment processing take place through our platform providers; passwords and payment card information should never be placed in a supplier brief.
- Review context: supplier company and representative names, sector, product and product type, requested checks, source records, relevant correspondence, photographs and documents.
- Supplier-related information: professional roles and business relationships found in public or official company records, information supplied by the customer or supplier, and observations obtained within the agreed field-review scope. A public record may still contain personal information.
- Technical information: security and session information, browser settings and platform operational logs generated when the service is used.
Required fields are identified when you submit information. Without the information necessary for a requested service, we may be unable to respond, verify a purchase or complete the review. Optional fields can be left blank. Do not submit unrelated health information, identity-document copies, banking credentials or private employee records.
Each use has a defined purpose
| Purpose | Information used | Applicable ground |
|---|---|---|
| Respond to an enquiry or prepare a requested proposal | Contact details and requirements | Steps requested before a contract; legitimate interests in responding to business contacts |
| Provide a purchased review and communicate progress | Order, account, supplier context and relevant evidence | Contract performance where the person is a party; legitimate interests in providing the service to a business customer |
| Research business identity and agreed supplier questions | Relevant public records, business relationships and observations | Legitimate interests in independently establishing commercial information, subject to necessity and the rights of the people concerned |
| Protect accounts, private evidence and the service | Identity checks, access records and technical signals | Legitimate interests in security and fraud prevention; applicable legal obligations |
| Maintain accounting records and handle rights or legal claims | Necessary transaction and correspondence records | Legal obligations and, where applicable, the establishment, exercise or defence of legal claims |
| Optional marketing or non-essential tracking | Only the details covered by the relevant permission | Consent where required; a service enquiry does not itself subscribe you to marketing |
The interests above are limited to the service, business communication, reliable research and protection of the operation. They do not justify collecting unrelated information. Where consent is the basis, you may withdraw it without affecting processing that occurred lawfully before withdrawal. Under Türkiye’s Law No. 6698, the corresponding processing condition must also be satisfied for the particular activity.
Our service guide provides informational answers; it does not make legally significant automated decisions about individuals. Supplier findings require human review and do not certify or guarantee a business.
Keep information for its purpose
| Record | Retention period or determining criterion |
|---|---|
| Uncommissioned service enquiries | Review for deletion or anonymisation six months after receipt. Retain longer only for an active proposal, continuing correspondence or a documented legal reason. |
| Completed supplier reviews and supporting working evidence | Review for deletion or anonymisation 24 months after delivery, unless a continuing engagement, agreed customer requirement or documented legal claim requires retention. |
| Account information | While the account is used. After closure, retain only records needed for outstanding services, transaction duties, security or legal claims; closure does not remove mandatory business records. |
| Invoices, transactions and legally required records | The statutory accounting, tax or limitation period applicable to that record and jurisdiction. Relevant holds end when the duty or claim requiring them ends. |
| Privacy requests | The correspondence needed to resolve the request and demonstrate how it was handled; restrict any further retention to the applicable complaint or legal-claim period. |
| Checkout brief in your browser | Usable for up to 24 hours in the same tab. Cleared when a verified purchase is attached; stale entries are removed when the draft is next checked. Closing the browser session clears session storage. |
These are record-review limits, not a promise that every record is removed by an automatic timer. The responsible team reviews whether deletion, anonymisation or a documented retention exception is appropriate. Backup and provider records may follow their separate recovery and security cycles. A specific hold must not be used to retain unrelated information indefinitely.
A controlled review file
Customer requests are connected to the authenticated purchase owner. Team access requires an authorised role, and staff-only drafts and evidence are withheld from the customer until the report is approved and delivered. Private PDF, JPEG and PNG uploads are limited to 5 MB; authorised download links expire after five minutes.
Public sample reports contain fictional cases and illustrative records. Checkout return links use an opaque reference and do not include the supplier brief or contact details. Security measures reduce risk, but no online system can be guaranteed completely secure. Let us know promptly if you believe information has been accessed incorrectly.
Make a request without a purchase
Depending on the law applicable to your information, you may request access or a copy, correction of inaccurate information, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent for consent-based processing. Rights can be limited where a legal obligation, the rights of another person or a valid legal claim requires continued handling.
Use the personal information request page. We may seek proportionate confirmation of identity before disclosing or changing personal information. Do not send an identity document in the initial message. Where GDPR applies, the normal response period is one month; a permitted extension will be explained within that first month. Requests under Türkiye’s Law No. 6698 are handled within the applicable legal response period, normally no later than 30 days.
You may complain to the data protection authority competent for your residence or the matter concerned, including your relevant EU/EEA supervisory authority where GDPR applies, or Türkiye’s Kişisel Verileri Koruma Kurumu under its applicable procedures. See EU/EEA supervisory authorities and KVKK. Contacting us does not waive your statutory rights.
Send a privacy request→Questions stay connected to the team
We update this notice when service handling changes and identify the revision date above. Material changes affecting an active engagement should be communicated through its service contact channel. A new use of information requires an appropriate purpose and lawful basis.
This notice is structured with reference to GDPR Articles 12–14, EDPB guidance on individuals’ rights and KVKK’s information-duty guidance. These sources do not certify EnterTurkey’s operational compliance.
Contact the privacy review team ↗