Legal

Privacy Policy

1. Document Control

This document is the official Privacy Policy published by Personel Antalya Consulting & Foreign Trade Ltd. (operating as EURASIA EXECUTION LAB).

2. Purpose

This Privacy Policy establishes the principles governing the collection, processing, storage, transfer, and protection of personal data in compliance with applicable data protection laws, including KVKK No. 6698 and GDPR where applicable.

3. Scope

This Policy applies to all personal data processed via the website eurasialab.tr (and associated pages), including data of users located in multiple jurisdictions.

4. Definitions

  • Personal Data: Any information relating to an identified or identifiable individual.
  • Processing: Any operation performed on personal data.
  • Data Controller: Entity determining purposes and means of processing.
  • Data Subject: Individual whose data is processed.

5. Data Controller

Email: info@eurasialab.tr

6. Categories of Personal Data

The following categories of personal data may be processed:

  • Identity Data (name, surname)
  • Contact Data (email, phone number)
  • Technical Data (IP address, device, browser)
  • Usage Data (interaction logs)
  • Voluntarily Provided Data

7. Legal Basis for Processing

Processing is carried out on the following legal grounds:

  • Explicit consent
  • Performance of a contract
  • Compliance with legal obligations
  • Legitimate interests (subject to balancing test)

8. Purpose of Processing

Personal data is processed for:

  • service provision and operation
  • user communication
  • contractual performance
  • service improvement and analytics
  • security and fraud prevention
  • legal compliance

9. Data Storage and Localization

Personal data is stored on servers located in Turkey.

Where applicable, storage and processing comply with local data localization and transfer regulations.

10. Cross-Border Data Transfers

Personal data may be transferred internationally.

Safeguards include:

  • contractual agreements with processors
  • KVKK-compliant transfer mechanisms
  • Standard Contractual Clauses (SCCs) where required under GDPR

11. Data Retention

Data is retained based on:

  • purpose of processing
  • legal requirements
  • business necessity

Data is securely deleted or anonymized after retention periods expire.

12. Data Sharing

Personal data may be shared with:

  • hosting providers
  • IT service providers
  • analytics providers
  • CRM systems
  • regulatory authorities

All processors are bound by data protection obligations.

13. Cookies and Tracking

Cookies are used for:

  • essential website functionality
  • analytics
  • performance optimization

Non-essential cookies are used only with user consent where required.

14. Information Security Measures

The organization implements appropriate technical and organizational controls, including:

  • encryption (in transit and where applicable at rest)
  • access control and authentication
  • logging and monitoring
  • vulnerability management
  • data minimization
  • backup and recovery procedures

15. Data Subject Rights

Under KVKK

  • right to be informed
  • right of access
  • right to correction
  • right to deletion
  • right to object

Under GDPR

  • right of access
  • right to rectification
  • right to erasure
  • right to restriction
  • right to data portability
  • right to object
  • right to withdraw consent

Requests can be submitted to: info@eurasialab.tr

16. Incident and Breach Management

In case of a personal data breach:

  • incidents are assessed and documented
  • competent authorities are notified as required
  • affected data subjects are informed where applicable

17. Third-Party Websites

The website may contain links to third-party resources. The organization is not responsible for their data practices.

18. Policy Updates

This Policy is reviewed periodically and updated as necessary.

19. Contact

info@eurasialab.tr

20. Applicable Law

This Policy is governed by applicable data protection legislation, including KVKK and GDPR.