Skip to content

Legal text

Personal Data Processing and Protection Policy

Last updated: · FIX Danışmanlık A.Ş.

The Turkish version of this text is authoritative. This translation is provided for information purposes. In case of any discrepancy, the Turkish text shall prevail.

FIX Danışmanlık Anonim Şirketi · Version: 2.1 · Previous version: 26 September 2026

1. Purpose and scope

1.1. This Policy sets out the principles that FIX Danışmanlık Anonim Şirketi ("FIX" or the "Company") follows when processing personal data under Personal Data Protection Law No. 6698 (KVKK) (the "Law") and secondary legislation.

1.2. The Policy covers the representatives of clients and prospective clients, website visitors, persons who write to our WhatsApp line, the representatives of companies we contact for the first time, job applicants, the representatives of suppliers and business partners, and other natural persons whose personal data FIX processes in the course of its activities. Processing activities relating to employees are carried out separately under internal company regulations.

1.3. The Policy is binding on all FIX employees. Provisions consistent with this Policy are included in contracts with service providers that process data on behalf of FIX.

2. Definitions

The terms used in this Policy have the meanings given to them in Article 3 of the Law. The main ones are:

  • Explicit consent: Consent relating to a specific matter, given on an informed basis and expressed of one’s own free will.
  • Data subject: The natural person whose personal data is processed.
  • Personal data: Any information relating to an identified or identifiable natural person.
  • Special categories of personal data: Data relating to race, ethnic origin, political opinion, philosophical belief, religion, sect or other beliefs, appearance and dress, membership of associations, foundations or trade unions, health, sexual life, criminal convictions and security measures, as well as biometric and genetic data.
  • Data processor: A natural or legal person who processes personal data on behalf of the data controller on the basis of the authority granted by the data controller (e.g. cloud service providers).
  • Data controller: The person who determines the purposes and means of processing personal data; for the purposes of this Policy, FIX.
  • Board / Authority: Personal Data Protection Board / Personal Data Protection Authority.

3. Basic principles (Article 4 of the Law)

FIX processes personal data: a) lawfully and in accordance with the rules of good faith, b) accurately and, where necessary, keeping it up to date, c) for specified, explicit and legitimate purposes, ç) in a manner that is relevant, limited and proportionate to the purposes for which it is processed, d) retaining it for the period laid down in the relevant legislation or necessary for the purpose for which it is processed. No data is collected for undefined purposes that may arise in the future; the forms ask only the questions necessary for the assessment.

4. Conditions for processing

4.1. Personal data (Article 5 of the Law) is processed with explicit consent or where one of the following conditions exists: it is expressly provided for by law; vital interest in the case of actual impossibility; it is directly related to the establishment or performance of a contract; legal obligation; it has been made public by the data subject themselves; the establishment, exercise or protection of a right; FIX’s legitimate interest, provided that it does not harm the fundamental rights and freedoms of the data subject.

4.2. FIX does not request explicit consent where a condition other than explicit consent exists, and does not make explicit consent a precondition of the service. Where explicit consent is required, it is obtained separately from the provision of information, for a specific matter, and is recorded. Explicit consent may be withdrawn at any time. On the website, for visits from EU/EEA countries, the United Kingdom and Switzerland, analytics and marketing tools (Google Analytics, Google Ads, Meta Pixel, Microsoft Clarity and FIX attribution cookies) run only with the permission the visitor gives in the cookie panel; for these visitors the legal basis for this processing is explicit consent, and these tools do not run before consent is given. In other regions the same processing is based on legitimate interest, and the data subject can reject it in the cookie panel. Details: Cookie Policy.

4.3. Special categories of personal data (Article 6 of the Law, as amended by Law No. 7499): their processing is prohibited. However, they may be processed where one of the following applies: explicit consent; it is expressly provided for by law; vital interest in the case of actual impossibility; data made public by the data subject, in line with their intention to make it public; necessity for the establishment, exercise or protection of a right; necessity for the purposes of health services by persons under an obligation of confidentiality; or necessity for the fulfilment of legal obligations in the fields of employment, occupational health and safety, and social security. In all cases, the adequate measures determined by the Board are taken. FIX’s ordinary activities do not require special categories of data; such data is not requested on forms or in CV assessment.

5. Informing data subjects

5.1. When obtaining personal data, FIX informs data subjects, in accordance with Article 10 of the Law and the Communiqué on the Obligation to Inform, of the identity of the data controller, the purposes of processing, the groups of recipients to which data is transferred and the purpose of transfer, the method of collection and the legal basis, and the rights of the data subject.

5.2. Information is provided on the website through the Privacy Notice, the Privacy Notice for Job Applicants and the Cookie Policy; through the link below the forms; through the notice sent at the start of a WhatsApp conversation; and, where the data is not obtained from the data subject (first-contact e-mails), at the time of first communication.

6. Transfers

6.1. Domestic transfers (Article 8 of the Law) are carried out with explicit consent or where one of the conditions in Article 5(2) exists; for special categories of data, subject to the conditions in Article 6(3) and adequate measures.

6.2. Transfers abroad (Article 9 of the Law, as amended by Law No. 7499; Regulation on the Procedures and Principles for the Transfer of Personal Data Abroad): FIX transfers personal data abroad only where a processing condition under Article 5 or 6 exists and on one of the following bases: a) an adequacy decision of the Board concerning the country, sector or international organisation to which the data is transferred (no such decision has been issued to date); b) in the absence of an adequacy decision, appropriate safeguards, provided that the data subject can also exercise their rights and have access to effective legal remedies in the country of transfer: a standard contract announced by the Board (used without amendment and notified to the Authority within five business days of signature), binding corporate rules, or a written undertaking with the Board’s authorisation; c) where neither of these exists, only in incidental (non-regular, non-continuous) transfers, the cases listed in Article 9(6) of the Law.

6.3. The transfers FIX makes to the providers from which it receives hosting, e-mail, CRM, automation, messaging, artificial intelligence, measurement and advertising services are continuous and are based on the Board’s standard contracts. These contracts have been signed and notified to the Authority. Before work with a new provider begins, the same procedure is completed.

6.4. It is ensured by contract that the safeguards under the Law are also provided in onward transfers of data transferred abroad.

7. Data processors

FIX has accepted the data processing agreements of the service providers that process data on its behalf. These agreements provide that data is processed only on FIX’s instructions and for the specified purpose, and govern confidentiality, security measures, the use of sub-processors, data breach notification and the return or deletion of data at the end of the service. Under Article 12(2) of the Law, FIX is jointly responsible with these persons for the security measures.

8. Automated assessment and use of artificial intelligence

8.1. Requests received via the web form, the WhatsApp line and the AIx® Incentive Robot receive an automated pre-assessment score based on the answers given. The score determines only to whom (a specialist or the WhatsApp assistant) and with what priority the request is routed; it does not produce any result against the data subject, such as refusal of the service. Under Article 11(1)(g) of the Law, the data subject may object to a result arising against them through analysis exclusively by automated means; in the event of an objection, the assessment is carried out by an employee.

8.2. Anthropic’s artificial intelligence service is used to interpret free-text answers in the WhatsApp assistant and to prepare drafts of first-contact messages. Only the data required for the task is sent to this service; Anthropic does not use data sent via its API for model training. The programme matching of the AIx® Incentive Robot is carried out not with artificial intelligence but with rules prepared by FIX.

9. Commercial electronic messages

FIX does not send commercial electronic messages to individuals. It sends promotional messages addressed to companies within the framework of Law No. 6563 on the Regulation of Electronic Commerce and the provision of the Regulation on Commercial Communication and Commercial Electronic Messages concerning merchants and tradespersons. Recipients’ electronic communication addresses are registered in the Message Management System (İYS No: 758063). Every message contains FIX’s identity and a free means of opting out. Sending is stopped upon opt-out notifications submitted via İYS or directly to FIX.

10. Data security (Article 12 of the Law)

FIX applies the following measures, based on the Board’s Personal Data Security Guide:

Technical: authorisation and the principle of least privilege; two-factor authentication on cloud accounts; encryption in transit (HTTPS/TLS); storage of secrets and API keys separately from code; access and activity logs; up-to-date software; backups; malware protection; filtering of unwanted submissions on forms.

Administrative: confidentiality undertakings and awareness training for employees; contracts with data processors; removal of access for employees who leave; keeping the data processing inventory up to date; periodic internal audits.

Data breach: If processed personal data is obtained by others through unlawful means, FIX notifies the Board as soon as possible and, in accordance with the Board’s decision, no later than 72 hours after becoming aware of it, and notifies the data subjects within the shortest reasonable time.

11. Retention and destruction

Personal data is retained for the periods specified in the Personal Data Retention and Destruction Policy; when the conditions for processing cease to exist, it is erased, destroyed or anonymised ex officio or at the request of the data subject.

12. Rights of the data subject and applications

Data subjects may exercise their rights listed in Article 11 of the Law by the means set out in section 9 of the Privacy Notice (written application or KEP). FIX concludes applications free of charge within 30 days at the latest, in accordance with the Communiqué on the Procedures and Principles of Application to the Data Controller; applications and responses are recorded.

13. Responsibility

Ahmet Ersoy (Co-Founder) is responsible for the implementation of this Policy and for concluding data subject applications.

14. Amendments

FIX updates this Policy in the event of changes in legislation or in its activities. The current version is published on the website together with its date; previous versions are archived.

Data controller contact details

FIX Danışmanlık Anonim Şirketi · MERSİS: 0387127764100001 · Address: Çukurambar Mahallesi 1480. Sokak No: 2A, Besa Kule İş Merkezi A Blok İç Kapı No: 70, 06510 Çankaya / Ankara · KEP: fixconsultingdanismanlik@hs01.kep.tr · Phone: +90 312 511 33 66 · E-mail: fix@fixdanismanlik.com

Pre-assessment

Let’s find the right service for your company

A few short questions, about 2 minutes. Your details are used to assess your request.

Step 1
Your contact details

We use your details only to get back to you. If you don’t finish the form, we may call you once to help. For details, see our Privacy Notice.

We don’t show scores or programme names, and we never promise approval.

Once the file is complete, a specialist will contact you. If you’d rather not wait, message us on WhatsApp.

Pre-assessment

Let’s find the right service for your company

A few short questions, about 2 minutes. Your details are used to assess your request.

Step 1
Your contact details

We use your details only to get back to you. If you don’t finish the form, we may call you once to help. For details, see our Privacy Notice.

We don’t show scores or programme names, and we never promise approval.

Once the file is complete, a specialist will contact you. If you’d rather not wait, message us on WhatsApp.