DATA PROTECTION

Privacy & Data Protection

We handle personal data lawfully, fairly, accurately, securely and only to the extent necessary for defined purposes.

TIRUWA GROUP

Clear, limited and secure data stewardship.

This page explains the general data-protection approach used under the TIRUWA brand. The TIRUWA group company that collects and determines the use of personal data for a specific activity acts as the data controller for that activity.

The controller’s full legal name, contact details, purposes and legal grounds must be identified in the activity-specific privacy notice presented when data is collected. This general policy does not replace that notice.

01

Data categories

Depending on the service or relationship, identity and contact data, correspondence, recruitment information, security records and legal-compliance records may be processed.

02

Purposes

Purposes may include responding to enquiries, assessing applications, managing contracts and business relationships, protecting systems and meeting legal obligations.

03

Collection and legal grounds

Data may be collected through forms, email, telephone, contracts and digital systems. Processing relies on an applicable legal ground; consent is requested separately where required.

04

Sharing

Data may be shared, only where necessary and with safeguards, with authorities, professional service providers, business partners or relevant TIRUWA group companies. International transfers require an applicable lawful transfer mechanism.

05

Retention and security

Data is retained only as long as required by law, purpose and legal-claim needs, then deleted, destroyed or anonymised. Proportionate technical and organisational safeguards apply.

06

Your rights

You may request information, access, correction, deletion or restriction where applicable, object to certain processing and seek remedies under applicable data-protection law.

07

Contact

Contact tiruwa@tiruwa.com.tr so your request can be directed to the appropriate group company. Formal data-subject requests must follow the verified methods published in the relevant company activity-specific notice and include sufficient identity information. Valid requests are handled within applicable statutory periods.

08

Updates

This framework is reviewed as activities, law and processing operations change. Last updated: 30 July 2026.

For official guidance and current legislation, visit the Turkish Data Protection Authority.