PRIVACY NOTICE REGARDING THE PROCESSING OF PERSONAL DATA
Last updated: [07.07.2026]
1. Data Controller
For the purposes of Law No. 6698 on the Protection of Personal Data, the data controller is:
Full legal name: Kriko Bilişim ve Bilgi Teknolojileri Ticaret Ltd. Şti.
MERSIS number: 05890797658000001
Registered address: Küçükbakkalköy Mah. Selvili Sk. No:4/48 Canan Business – Ataşehir/İstanbul
Website: kriko.io
Email address: hi@kriko.io
Registered electronic mail address: krikobilisim@hs01.kep.tr
The company is referred to in this Notice as “Kriko” or the “Company”.
This Privacy Notice has been prepared to inform visitors to the kriko.io website and individuals who submit communication, quotation, meeting, or service requests about the processing of their personal data.
2. Personal Data Processed
Depending on the nature of your interaction with the website, the following personal data may be processed:
Identity information: First name and surname.
Contact information: Email address, telephone number, company information, and job title.
Request and transaction information: Contact form messages, requested services, quotation or meeting requests, correspondence, and meeting records.
Transaction security information: IP address, date and time information, access and system logs, browser and device information, error logs, security records, and consent records.
Website usage information: Pages visited, traffic source, session information, website interactions, and performance data.
Advertising and marketing information: Cookie identifiers, advertising identifiers, campaign, source and channel information, advertising interactions, and conversion information. Such data is processed only where the applicable legal conditions have been satisfied.
The Company does not request the submission of special categories of personal data through the website. Information relating to health, biometric data, political opinions, religious or philosophical beliefs, and similar special categories of personal data should not be entered into contact forms or message fields.
3. Purposes and Legal Grounds for Processing Personal Data
Your personal data may be processed for the following purposes and on the following legal grounds.
Managing communication and service requests
Personal data may be processed to respond to enquiries, arrange meetings, prepare quotations, and conduct preliminary discussions regarding requested services.
Such processing is based on the legal grounds that processing is necessary for the establishment or performance of a contract, for the establishment, exercise, or protection of a right, or for the legitimate interests of the Company, provided that such processing does not harm your fundamental rights and freedoms.
Ensuring website security
Transaction security data may be processed to detect unauthorised access, misuse, fraud, spam traffic, and cybersecurity threats, to ensure system security, and to resolve technical problems.
Such processing is based on the Company’s legal obligations and legitimate interests, provided that your fundamental rights and freedoms are not adversely affected.
Managing legal processes
Personal data may be processed to respond to requests from public authorities, manage legal disputes, exercise legal rights, and comply with legal obligations.
Such processing is based on the legal grounds that processing is expressly provided for by law, necessary for the Company to fulfil its legal obligations, or necessary for the establishment, exercise, or protection of a right.
Analytics, personalisation, and advertising activities
Personal data may be processed to analyse website usage, improve visitor experience, measure advertising performance, conduct remarketing activities, and display advertisements based on user interests.
Processing performed through non-essential analytics, functionality, and advertising cookies is based on your explicit consent where required. Refusing to provide explicit consent does not prevent you from using the essential features of the website.
Sending commercial electronic communications
Promotional communications regarding campaigns, services, events, or marketing may be sent based on separate commercial electronic communication consent, except where otherwise permitted by applicable legislation.
Submitting a contact form does not, by itself, constitute consent to receive advertising, promotional, or marketing communications.
4. Methods of Collecting Personal Data
Your personal data may be collected through:
- Contact and application forms on the website,
- Email, telephone, and online meetings,
- Server, network, and security logs,
- Cookies, pixels, tags, and similar online technologies,
- Advertising, analytics, CRM, and communication platforms.
Personal data may be collected automatically, partially automatically, or through non-automated methods provided that the data forms part of a data filing system.
5. Transfers of Personal Data
Your personal data may be transferred, on a limited and proportionate basis, to the following categories of recipients:
- Hosting, server, IT, cybersecurity, and technical support providers,
- Email, communication, CRM, and meeting service providers,
- Analytics and advertising technology providers,
- Financial advisers, lawyers, auditors, and professional consultants,
- Legally authorised public authorities, courts, and administrative bodies.
Access restrictions, confidentiality obligations, data processing agreements, and appropriate technical and organisational measures are implemented in connection with such transfers.
6. Transfers of Personal Data Abroad
Where hosting, cloud, analytics, email, or advertising technologies used on the website operate through servers or companies located abroad, your personal data may be transferred outside Türkiye.
The service providers actually used by the Company include:
- Google Ireland Limited
- Meta Platforms Ireland Limited
- Microsoft
- HubSpot
- Cloudflare
Transfers of personal data abroad are carried out in reliance on an appropriate mechanism under Article 9 of the Personal Data Protection Law. These mechanisms may include an adequacy decision, standard contractual clauses, binding corporate rules, an undertaking approved by the Personal Data Protection Board, or one of the limited statutory exceptions.
Where an overseas transfer relies on explicit consent, such consent is obtained separately from this Privacy Notice.
7. Retention and Destruction of Personal Data
Personal data is retained for the period required for the purpose for which it was processed and for any statutory retention period under applicable legislation.
The following baseline retention periods are recommended:
| Data or process | Retention period |
|---|---|
| Completed general communication requests | 2 years from the final response |
| Quotation and business development records | 3 years from the closure of the process |
| Customer records resulting in a contractual relationship | For the applicable legal period, generally up to 10 years after termination of the relationship |
| Website security and access logs | 1 year |
| Explicit consent and withdrawal records | 3 years following termination or withdrawal of consent |
| Cookie records | For the period specified in the cookie table |
| Records relating to legal disputes | Until the dispute and applicable limitation periods have expired |
Where the reasons requiring processing cease to exist, personal data is deleted, destroyed, or anonymised ex officio or upon the request of the data subject.
8. Rights of Data Subjects
Under Article 11 of the Personal Data Protection Law, you have the right to apply to the Company and:
- Learn whether your personal data is being processed,
- Request information where your personal data has been processed,
- Learn the purpose of processing and whether the data is being used in accordance with that purpose,
- Learn the third parties to whom your personal data has been transferred,
- Request the correction of incomplete or inaccurate personal data,
- Request deletion or destruction where the applicable conditions have been satisfied,
- Request notification of correction, deletion, or destruction to third parties to whom the data has been transferred,
- Object to an adverse result arising from analysis conducted exclusively through automated systems,
- Claim compensation where you have suffered damage due to unlawful processing.
9. Application Methods
You may submit your requests through the following methods:
Written application: Küçükbakkalköy Mah. Selvili Sk. No:4/48 Canan Business – Ataşehir/İstanbul
Registered electronic mail: krikobilisim@hs01.kep.tr
Registered email address: hi@kriko.io
Your application should include your first name, surname, contact details, the subject of your request, and information necessary to verify your identity.
The Company will respond to applications as soon as possible and no later than 30 days, depending on the nature of the request.
10. Data Security
The Company implements appropriate technical and organisational measures to prevent unlawful processing of and access to personal data, to ensure its secure retention, and to detect security incidents.
However, data transmissions conducted over the internet cannot be guaranteed to be completely secure. The Company’s statutory obligations and liabilities remain reserved.
11. Amendments to This Notice
This Privacy Notice may be updated in response to changes in personal data processing activities or applicable legislation.
The current version will be published on the website together with its effective date. Where there is a material change to a processing purpose, legal ground, or transfer activity, the required information will be provided before the new processing activity begins.