Privacy Policy
ACHORD designs enterprise architecture for enterprise organizations. We apply the same discipline to data privacy. We collect minimal personal data, do not set non-essential cookies without explicit consent, and respect your statutory rights under GDPR and KVKK.
Data Controller
Achord Yazılım ve Bilişim Teknolojileri Ltd. Şti. ('ACHORD') acts as the data controller for personal data collected through this website and related digital communications.
You can contact our dedicated data protection team directly at [email protected] for all compliance matters. For general enterprise correspondence, use [email protected].
External Platform Links
Our website contains plain outbound links to our official profiles on LinkedIn, X, and GitHub.
These links are standard HTML links with rel="noopener noreferrer" security attributes. We do not embed external social widgets or feed iframes on our pages. The only social tracking script is the LinkedIn Insight Tag, and it loads only after you grant the Personalized Marketing category.
When you click an outbound link to visit a third-party platform, that platform's privacy policy and terms govern your visit. We advise you to review their terms directly.
Personal Data We Collect and Why
We collect personal data only when you submit information to us through our contact form, diagnostic request form, or direct email correspondence.
Inquiry and Assessment Data
When you request an Architecture Diagnostic or send a message, we collect the details you provide. The fields depend on the form you use.
- First name and last name.
- Work email address.
- Phone number (contact form).
- Company or organization name and job title.
- Country (contact form).
- Area of interest, project scope, and message text.
Purpose of Processing
We process this information to evaluate your architecture requirements, schedule discovery sessions, communicate proposals, and manage our business relationship with you.
After you submit a form, we send one confirmation email to the address you provide.
Technical Server Logs
When you access our website, our servers automatically record basic technical access logs. These logs include IP address, request timestamp, HTTP status code, and resource path.
We use these technical logs exclusively to maintain network security, mitigate denial-of-service attacks, and ensure system uptime. We purge server logs on a strict rotational schedule.
Service Providers and International Transfers
We use a small number of service providers to operate this website. They process personal data only for the purposes below and on our instructions.
- Cloudflare, Inc. (network, security, and bot protection): all website traffic passes through the Cloudflare network. Cloudflare Turnstile checks form submissions and processes technical signals, such as IP address and browser characteristics, to confirm that a person sends the form.
- Resend (email delivery): when you submit a form, Resend delivers your message to our team and sends your confirmation email. Resend processes your name, email address, and form content.
- Google LLC / Google Ireland Ltd. (Google Analytics 4): only if you accept the Analytics Cookies category. Google processes usage data such as pages viewed, device and browser information, and an approximate location.
- LinkedIn Ireland Unlimited Company (LinkedIn Insight Tag): only if you accept the Personalized Marketing category. LinkedIn processes the page URL, referrer, IP address, device and browser information, and LinkedIn cookies. If you are signed in to LinkedIn, LinkedIn can link the visit to your LinkedIn account. We receive only aggregated reports.
- Umami (visit statistics): runs on our own server. No third party receives this data.
These providers can process personal data on servers outside Türkiye and the European Economic Area, including in the United States. We make these transfers in accordance with Article 9 of KVKK and Chapter V of the GDPR, based on appropriate safeguards such as standard contractual clauses, or on your explicit consent where the law requires it.
Legal Bases for Processing
We process personal data under lawful bases recognized by international data protection laws, including the European Union General Data Protection Regulation (GDPR) and Turkish Law No. 6698 (KVKK).
- Pre-contractual and Contractual Performance: processing inquiries and architecture assessment requests at your direction before entering an enterprise contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
- Legitimate Interests: operating secure enterprise services, defending against cyber threats, and answering corporate correspondence (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
- Legitimate Interests: counting website visits in aggregate with cookieless analytics (Umami), which stores no personal data (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
- Consent: analytics cookies and the LinkedIn Insight Tag, only after you opt in through the Cookie Preferences panel (GDPR Art. 6(1)(a); KVKK Art. 5(1)).
- Legal Obligations: complying with mandatory statutory accounting, tax, and law enforcement directives where applicable by law.
Data Security and Retention
We implement technical and organizational security controls to protect your data against unauthorized access, loss, alteration, or disclosure.
All data transmissions use TLS encryption (version 1.2 or higher). We store records on hardened cloud infrastructure with role-based access control.
We retain personal data only for as long as necessary to fulfill the business purposes described in this policy, or to satisfy legal retention periods. When data is no longer required, we securely delete or anonymize it.
Your Rights Under GDPR (Articles 15–22)
If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, you hold statutory rights under the GDPR. You can exercise these rights at any time by contacting [email protected].
- Right of Access (Article 15): you can request confirmation of processing and obtain a copy of your personal data.
- Right to Rectification (Article 16): you can demand correction of inaccurate or incomplete personal data.
- Right to Erasure / Right to be Forgotten (Article 17): you can ask us to delete your personal data when it is no longer necessary for original purposes.
- Right to Restriction of Processing (Article 18): you can request that we restrict processing in specific legal circumstances.
- Right to Data Portability (Article 20): you can receive your data in a structured, machine-readable format.
- Right to Object (Article 21): you can object to processing based on legitimate interests at any time.
- Automated Decision-Making and Profiling (Article 22): ACHORD does not perform automated decision-making or profiling on individuals.
- Right to Lodge a Complaint: you can lodge a formal complaint with your local EU data protection supervisory authority.
Your Rights Under Turkish Law No. 6698 (KVKK Madde 11)
Under Article 11 of the Turkish Personal Data Protection Law No. 6698 (KVKK), natural persons whose data is processed hold statutory rights against the data controller.
- Learn whether your personal data is processed.
- Request information if your personal data has been processed.
- Learn the purpose of processing and whether data is used according to purpose.
- Know the third parties to whom personal data is transferred domestically or abroad.
- Request correction of personal data if it is incomplete or incorrectly processed.
- Request deletion or destruction of personal data under conditions in KVKK Article 7.
- Request notification of correction, deletion, or destruction to third parties who received your data.
- Object to an outcome against you through analysis carried out exclusively by automated systems.
- Claim compensation for damages arising from unlawful processing of your personal data.
Questions and Data Protection Requests
To exercise your statutory rights or ask questions about our data practices, write to our legal team. We respond within thirty days without fee.