This notice explains how ProgemLife Global Trade & Investment (“ProgemLife”, “we”, “us”) handles personal data through progemlife.com, its contact channels and related business correspondence.
It is intended to meet the information requirements of Turkish Personal Data Protection Law No. 6698 (“KVKK”). Where the EU General Data Protection Regulation (“GDPR”) applies to a particular activity, the additional GDPR rights described below also apply.
1. Data Controller and Contact
The data controller is PROGEM LİFE İNŞAAT PROJE DANIŞMANLIK MÜHENDİSLİK TURİZM VE SANAYİ DIŞ TİCARET LİMİTED ŞİRKETİ. Its registered address is HUZUR MAH. 1127 SOK. NO:6/8 ÇANKAYA - ANKARA / TÜRKİYE.
Privacy contact: info@progemlife.com. Telephone: +90 530 237 90 11. Please use “Privacy Request” in the subject line when contacting us about personal data.
2. Scope
This notice covers visitors to the public website, people who submit an enquiry, and business contacts who correspond with us in connection with a potential or existing mandate.
Separate notices may apply to employees, candidates, suppliers or programme participants where their processing requires more specific information.
3. Personal Data We Handle
Depending on how you interact with us, we may handle the following categories of personal data.
We do not ask for special-category or highly sensitive personal data through the public contact form. Please do not include health information, biometric data, political or religious views, criminal-record information, government identity numbers, bank details, passwords, trade secrets or legally privileged material in an initial enquiry.
- Identity and business details: name, organisation, role and professional context that you provide.
- Contact details: email address, telephone number and preferred contact route.
- Enquiry information: enquiry type, priority market, sector, objective, message, language, submission time and subsequent correspondence.
- Technical and security data: session identifier, IP address or a cryptographic hash derived from it for abuse prevention, request time, requested page, browser or user-agent information, response status and related security records. Some of these records may be generated by our hosting provider.
- Mandate and relationship records: meeting notes, due-diligence material, decisions and correspondence where a conversation progresses into a documented business relationship.
4. How We Collect Data
We collect data directly when you complete the contact form, email or telephone us, or communicate with our team. We also receive limited technical data automatically when the website or its security functions respond to a request.
In a business context, we may receive professional contact information from your organisation, a mutual business contact, a chamber or institution, or a lawfully accessible public source. When required, we provide the relevant information notice at or before the first substantive contact.
5. Purposes and Legal Grounds
We process only the data reasonably needed for the purposes set out below.
We do not use website enquiry data for automated decision-making or profiling that produces legal or similarly significant effects. We do not send marketing communications merely because someone submitted an enquiry.
- Receiving, routing and responding to enquiries: to take steps at your request before a possible engagement and to pursue the legitimate interest of managing relevant B2B communications. The corresponding grounds are KVKK Article 5(2)(c) and, following a balancing assessment, Article 5(2)(f); where applicable, GDPR Articles 6(1)(b) and 6(1)(f).
- Assessing a proposed mandate or institutional programme: to understand scope, market, counterparties and next steps before any commitment. The same pre-contractual and legitimate-interest grounds may apply.
- Operating and protecting the website: to maintain sessions, prevent automated abuse, rate-limit submissions, diagnose faults and protect our systems and users. We rely on a balanced legitimate interest under KVKK Article 5(2)(f) and, where applicable, GDPR Article 6(1)(f).
- Meeting legal and compliance duties: to keep required records, respond to lawful authorities, conduct proportionate counterparty checks, and establish, exercise or defend legal rights. The grounds may include KVKK Articles 5(2)(a), 5(2)(ç) and 5(2)(e), and GDPR Articles 6(1)(c) and 6(1)(f), as applicable.
- Activities based on consent: if we later ask to use data for an optional purpose that has no other valid ground, we will request separate, specific and informed consent. Refusing or withdrawing optional consent will not affect ordinary enquiry handling.
6. Recipients
Access is limited according to role and need. Personal data may be disclosed to the following recipient groups.
We do not sell personal data.
- Authorised ProgemLife personnel responsible for the enquiry or mandate.
- Hosting, email, backup, cybersecurity and professional IT suppliers acting under appropriate confidentiality and data-processing terms.
- Independent professional advisers, including legal, audit or compliance advisers, where their involvement is necessary and appropriately scoped.
- A chamber, institution, potential counterparty or programme participant only when this is relevant to the requested work and there is a lawful basis, appropriate notice and, where required, your instruction or consent.
- Courts, regulators, law-enforcement bodies or other competent authorities where disclosure is legally required or necessary to protect legal rights.
7. International Transfers
Our focus markets and some infrastructure or professional suppliers may be outside Türkiye. An international transfer is made only where it is necessary for a stated purpose and a mechanism permitted by KVKK Article 9 is in place, such as an applicable adequacy decision or an appropriate safeguard, including the relevant standard contract.
Incidental-transfer exceptions are used only within their statutory limits. Where the GDPR applies, transfers are also handled in accordance with GDPR Chapter V. You may ask for information about the safeguard relevant to your data, subject to legitimate confidentiality limits.
8. Retention
We retain data for no longer than is reasonably necessary for its purpose. When a period ends, data is securely erased, destroyed or anonymised.
Data in protected backups is removed through the applicable backup cycle and is not restored for ordinary use. A legal hold may temporarily suspend deletion for the material within its documented scope.
- Contact-form records and related correspondence: normally two years from the last substantive interaction if no mandate is established.
- Session cookies: until the browser session ends.
- Rate-limit hashes: within the rolling ten-minute protection window.
- Ordinary web security logs: normally no more than 90 days, unless a documented incident or legal requirement justifies longer retention.
- Email-delivery and outbox status: normally 90 days after final delivery or final failure.
- Records connected with a contract, compliance review or legal claim: for the applicable statutory limitation or record-keeping period.
9. Your Rights
Under KVKK Article 11, you may ask whether we process your personal data, request information about the processing, learn its purpose and whether it is used accordingly, learn the recipients in Türkiye or abroad, request correction, request erasure or destruction where the legal conditions are met, ask that correction or deletion be notified to recipients, object to a result produced exclusively by automated analysis, and claim compensation where unlawful processing causes damage.
Where the GDPR applies, you may also have rights of access, rectification, erasure, restriction, objection and data portability, the right to withdraw consent at any time, and the right to complain to the competent supervisory authority. Withdrawal does not affect processing already carried out lawfully.
Formal requests under KVKK may be submitted in writing and signed, in person or by post or courier, to PROGEM LİFE İNŞAAT PROJE DANIŞMANLIK MÜHENDİSLİK TURİZM VE SANAYİ DIŞ TİCARET LİMİTED ŞİRKETİ at HUZUR MAH. 1127 SOK. NO:6/8 ÇANKAYA - ANKARA / TÜRKİYE, or sent electronically to info@progemlife.com with a secure electronic signature or mobile signature. An ordinary email sent to info@progemlife.com constitutes a formal application under KVKK Article 13 only if it is sent from an email address that you previously notified to the Company and that is recorded in its systems. If the Company publishes a verified KEP address or a dedicated application tool, those channels may also be used.
State your full name; signature for a written request; Turkish identity number, or nationality and passport or other identity number for non-Turkish applicants; address for service; available email, telephone and fax details; and the specific request. Attach relevant supporting information only. Do not send a copy of an identity document unless it is specifically, necessarily and lawfully requested.
Requests under KVKK Article 13 are answered as soon as possible and no later than the statutory 30-day limit, subject to the permitted fee rules.
10. Security
We use role-based access, hardened sessions, encrypted transport, request validation, rate limiting, restricted storage, logging and controlled backups to protect personal data.
No internet service is risk-free. Please use the contact form only for information appropriate to an initial business enquiry.
11. Children
This is a B2B website for professional and institutional audiences and is not directed to children. If you believe a child has provided personal data, contact us so that we can assess and remove it where appropriate.
12. Third-Party Sites and Updates
Links to third-party sites are governed by those parties’ privacy notices.
We may update this notice when our processing, suppliers or legal obligations change. The date at the top identifies the current version; material changes will be presented appropriately.