Legal & ComplianceEffective Date: September 2026

Privacy Policy

ACHORD designs enterprise architecture for enterprise organizations. We apply the same discipline to data privacy. We collect minimal personal data, do not set non-essential cookies without explicit consent, and respect your statutory rights under GDPR and KVKK.

01

Data Controller

Achord Yazılım ve Bilişim Teknolojileri Ltd. Şti. ('ACHORD') acts as the data controller for personal data collected through this website and related digital communications.

You can contact our dedicated data protection team directly at [email protected] for all compliance matters. For general enterprise correspondence, use [email protected].

04

Personal Data We Collect and Why

We collect personal data only when you submit information to us through our contact form, diagnostic request form, or direct email correspondence.

Inquiry and Assessment Data

When you request an Architecture Diagnostic or send a message, we collect the details you provide. The fields depend on the form you use.

  • First name and last name.
  • Work email address.
  • Phone number (contact form).
  • Company or organization name and job title.
  • Country (contact form).
  • Area of interest, project scope, and message text.

Purpose of Processing

We process this information to evaluate your architecture requirements, schedule discovery sessions, communicate proposals, and manage our business relationship with you.

After you submit a form, we send one confirmation email to the address you provide.

Technical Server Logs

When you access our website, our servers automatically record basic technical access logs. These logs include IP address, request timestamp, HTTP status code, and resource path.

We use these technical logs exclusively to maintain network security, mitigate denial-of-service attacks, and ensure system uptime. We purge server logs on a strict rotational schedule.

05

Service Providers and International Transfers

We use a small number of service providers to operate this website. They process personal data only for the purposes below and on our instructions.

  • Cloudflare, Inc. (network, security, and bot protection): all website traffic passes through the Cloudflare network. Cloudflare Turnstile checks form submissions and processes technical signals, such as IP address and browser characteristics, to confirm that a person sends the form.
  • Resend (email delivery): when you submit a form, Resend delivers your message to our team and sends your confirmation email. Resend processes your name, email address, and form content.
  • Google LLC / Google Ireland Ltd. (Google Analytics 4): only if you accept the Analytics Cookies category. Google processes usage data such as pages viewed, device and browser information, and an approximate location.
  • LinkedIn Ireland Unlimited Company (LinkedIn Insight Tag): only if you accept the Personalized Marketing category. LinkedIn processes the page URL, referrer, IP address, device and browser information, and LinkedIn cookies. If you are signed in to LinkedIn, LinkedIn can link the visit to your LinkedIn account. We receive only aggregated reports.
  • Umami (visit statistics): runs on our own server. No third party receives this data.
Transfers Outside Türkiye and the EEA

These providers can process personal data on servers outside Türkiye and the European Economic Area, including in the United States. We make these transfers in accordance with Article 9 of KVKK and Chapter V of the GDPR, based on appropriate safeguards such as standard contractual clauses, or on your explicit consent where the law requires it.

07

Data Security and Retention

We implement technical and organizational security controls to protect your data against unauthorized access, loss, alteration, or disclosure.

All data transmissions use TLS encryption (version 1.2 or higher). We store records on hardened cloud infrastructure with role-based access control.

We retain personal data only for as long as necessary to fulfill the business purposes described in this policy, or to satisfy legal retention periods. When data is no longer required, we securely delete or anonymize it.

08

Your Rights Under GDPR (Articles 15–22)

If you reside in the European Economic Area (EEA), United Kingdom, or Switzerland, you hold statutory rights under the GDPR. You can exercise these rights at any time by contacting [email protected].

  • Right of Access (Article 15): you can request confirmation of processing and obtain a copy of your personal data.
  • Right to Rectification (Article 16): you can demand correction of inaccurate or incomplete personal data.
  • Right to Erasure / Right to be Forgotten (Article 17): you can ask us to delete your personal data when it is no longer necessary for original purposes.
  • Right to Restriction of Processing (Article 18): you can request that we restrict processing in specific legal circumstances.
  • Right to Data Portability (Article 20): you can receive your data in a structured, machine-readable format.
  • Right to Object (Article 21): you can object to processing based on legitimate interests at any time.
  • Automated Decision-Making and Profiling (Article 22): ACHORD does not perform automated decision-making or profiling on individuals.
  • Right to Lodge a Complaint: you can lodge a formal complaint with your local EU data protection supervisory authority.
09

Your Rights Under Turkish Law No. 6698 (KVKK Madde 11)

Under Article 11 of the Turkish Personal Data Protection Law No. 6698 (KVKK), natural persons whose data is processed hold statutory rights against the data controller.

  • Learn whether your personal data is processed.
  • Request information if your personal data has been processed.
  • Learn the purpose of processing and whether data is used according to purpose.
  • Know the third parties to whom personal data is transferred domestically or abroad.
  • Request correction of personal data if it is incomplete or incorrectly processed.
  • Request deletion or destruction of personal data under conditions in KVKK Article 7.
  • Request notification of correction, deletion, or destruction to third parties who received your data.
  • Object to an outcome against you through analysis carried out exclusively by automated systems.
  • Claim compensation for damages arising from unlawful processing of your personal data.

Questions and Data Protection Requests

To exercise your statutory rights or ask questions about our data practices, write to our legal team. We respond within thirty days without fee.