Privacy & Security Policy
Last updated: 5 October 2026
1. Scope
This policy explains how personal data is processed across tingdea.com, the chat assistant, contact and project forms, email correspondence and services delivered by our Istanbul, London and Delaware offices.
It follows Turkish Law No. 6698 (KVKK) for users in Türkiye, UK GDPR / GDPR for users in the UK and EU, and applicable US state privacy laws (e.g. CCPA/CPRA) for users in the US.
2. Information we collect
Identity and contact: name, email, phone, company and job title.
Request content: form and chat messages, project budget and details.
Customer transactions: orders, invoices and payment status (excluding card details).
Technical data: IP address, browser/device information, pages visited and cookie choices.
Candidate data: CVs and application details sent to hr@tingdea.com.
3. How we use it
To answer your requests and prepare quotes.
To form contracts, deliver services and invoice.
To secure the site and prevent abuse and fraud.
With your consent, to send campaigns and newsletters.
To meet legal retention and reporting obligations.
4. Which email address is used for what?
hi@tingdea.com: general information, quotes and project correspondence.
contact@tingdea.com: data protection requests, legal notices, breach reports and complaints.
istanbul@tingdea.com, london@tingdea.com, delaware@tingdea.com: regional client correspondence; personal data requests received here are forwarded to contact@tingdea.com.
hr@tingdea.com: job applications; candidate data is visible only to the HR team.
5. Security measures
All traffic is encrypted with TLS/SSL, with HSTS and secure headers.
Form submissions are write-only on the server and cannot be read from the browser.
Access to data is limited to staff who need it, with role-based permissions and two-factor authentication.
Regular backups, updates and security scans are performed.
Payments are processed by a PCI-DSS compliant provider; card details are not stored on tingdea servers.
6. Third parties and international transfers
Data is shared only as needed with hosting, cloud, email, payment, analytics and AI chat providers, and is never sold.
Some providers may host data abroad. Such transfers rely on standard contractual clauses and appropriate safeguards under KVKK Article 9 and GDPR.
Transfers between our offices are covered by intra-group confidentiality commitments.
7. Retention periods
Contact requests: 2 years from the last correspondence.
Contracts and invoices: 10 years under tax and commercial law.
Job applications: 1 year from application (up to 2 years with consent).
After these periods, data is deleted, destroyed or anonymised.
8. Your rights
You may exercise your rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent by writing to contact@tingdea.com.
Requests are answered free of charge within 30 days.
You may also complain to the Turkish Personal Data Protection Authority, the UK ICO or your local supervisory authority.
9. Children's privacy
Our services are not directed at people under 18, and we do not knowingly collect children's data.
10. Reporting a security issue
If you notice a vulnerability or data breach, please report it immediately to contact@tingdea.com. Breaches are notified to authorities and affected people within legal deadlines (at most 72 hours).
11. Changes
This policy is updated as needed; the current version is published here and material changes are announced by email.
Our contact channels
General information, quotes and new projects: hi@tingdea.com
Legal notices, data protection requests, withdrawal, refunds and complaints: contact@tingdea.com
Istanbul office (clients in Türkiye): istanbul@tingdea.com
London office (UK and European clients): london@tingdea.com
Delaware office (US and North American clients): delaware@tingdea.com
Careers and candidate data: hr@tingdea.com