Privacy & Security Policy

Last updated: 5 October 2026

1. Scope

This policy explains how personal data is processed across tingdea.com, the chat assistant, contact and project forms, email correspondence and services delivered by our Istanbul, London and Delaware offices.

It follows Turkish Law No. 6698 (KVKK) for users in Türkiye, UK GDPR / GDPR for users in the UK and EU, and applicable US state privacy laws (e.g. CCPA/CPRA) for users in the US.

2. Information we collect

Identity and contact: name, email, phone, company and job title.

Request content: form and chat messages, project budget and details.

Customer transactions: orders, invoices and payment status (excluding card details).

Technical data: IP address, browser/device information, pages visited and cookie choices.

Candidate data: CVs and application details sent to hr@tingdea.com.

3. How we use it

To answer your requests and prepare quotes.

To form contracts, deliver services and invoice.

To secure the site and prevent abuse and fraud.

With your consent, to send campaigns and newsletters.

To meet legal retention and reporting obligations.

4. Which email address is used for what?

hi@tingdea.com: general information, quotes and project correspondence.

contact@tingdea.com: data protection requests, legal notices, breach reports and complaints.

istanbul@tingdea.com, london@tingdea.com, delaware@tingdea.com: regional client correspondence; personal data requests received here are forwarded to contact@tingdea.com.

hr@tingdea.com: job applications; candidate data is visible only to the HR team.

5. Security measures

All traffic is encrypted with TLS/SSL, with HSTS and secure headers.

Form submissions are write-only on the server and cannot be read from the browser.

Access to data is limited to staff who need it, with role-based permissions and two-factor authentication.

Regular backups, updates and security scans are performed.

Payments are processed by a PCI-DSS compliant provider; card details are not stored on tingdea servers.

6. Third parties and international transfers

Data is shared only as needed with hosting, cloud, email, payment, analytics and AI chat providers, and is never sold.

Some providers may host data abroad. Such transfers rely on standard contractual clauses and appropriate safeguards under KVKK Article 9 and GDPR.

Transfers between our offices are covered by intra-group confidentiality commitments.

7. Retention periods

Contact requests: 2 years from the last correspondence.

Contracts and invoices: 10 years under tax and commercial law.

Job applications: 1 year from application (up to 2 years with consent).

After these periods, data is deleted, destroyed or anonymised.

8. Your rights

You may exercise your rights of access, rectification, erasure, restriction, objection, portability and withdrawal of consent by writing to contact@tingdea.com.

Requests are answered free of charge within 30 days.

You may also complain to the Turkish Personal Data Protection Authority, the UK ICO or your local supervisory authority.

9. Children's privacy

Our services are not directed at people under 18, and we do not knowingly collect children's data.

10. Reporting a security issue

If you notice a vulnerability or data breach, please report it immediately to contact@tingdea.com. Breaches are notified to authorities and affected people within legal deadlines (at most 72 hours).

11. Changes

This policy is updated as needed; the current version is published here and material changes are announced by email.

Our contact channels

General information, quotes and new projects: hi@tingdea.com

Legal notices, data protection requests, withdrawal, refunds and complaints: contact@tingdea.com

Istanbul office (clients in Türkiye): istanbul@tingdea.com

London office (UK and European clients): london@tingdea.com

Delaware office (US and North American clients): delaware@tingdea.com

Careers and candidate data: hr@tingdea.com