1. Scope
This notice explains how personal data is handled when you visit www.type-of.com. It serves as the disclosure required by Article 10 of Turkish Law No. 6698 on the Protection of Personal Data (KVKK). If you are in the European Union or the United Kingdom, your GDPR rights are set out in section 9.
It covers this website only. Contracts signed for a client engagement, and the data-processing terms attached to them, are separate and are not replaced by this page.
2. Controller and contact
This site is operated by TYPE-OF. The registered trade name, registry details, and service address will be published in this section; until registration is complete, the channel for reaching us is the contact form on this site.
Data-protection requests can be sent through the same form; writing “data request” in your message is enough to route it correctly. This section will be updated with a postal address for written applications once it is published.
3. What we process, why, and on what basis
Personal data is processed on this site only when you submit a form. Browsing the site, reading the service pages, or completing the AI Opportunity Assessment requires no personal data and asks for none.
| Category | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Contact request | Name, email, company, role, your message; optional telephone; optional context selections (interest, company size, project stage, desired start, scope) | Answering your request, judging the appropriate next step, and conducting the conversation | KVKK Art. 5/2-c and GDPR Art. 6(1)(b) (steps prior to a contract), together with the consent you give in the form | At most 24 months after the request is closed, unless a statutory retention period applies |
| Consent record | The moment you tick the box and the version label of the text you agreed to | Being able to demonstrate that consent was obtained | KVKK Art. 5/2-ç and 5/2-f; GDPR Art. 6(1)(c) and 6(1)(f) | Same period as the related request |
| Attribution | Campaign parameters present in the address bar (utm_source, utm_medium, utm_campaign, utm_term, utm_content, partner) and the site language you were using | Understanding which channel a request came through | KVKK Art. 5/2-f; GDPR Art. 6(1)(f) (legitimate interests) | Same period as the related request |
| Abuse prevention | While the protection is active, an irreversible SHA-256 digest derived from your connection address; the address itself is not stored | Limiting automated abuse of the form endpoints | KVKK Art. 5/2-f; GDPR Art. 6(1)(f) (legitimate interests) | Held in memory for the counting window only (60 seconds by default), then discarded |
Beyond the required fields, please do not send sensitive personal data, confidential information, or trade secrets through the form. We do not collect special categories of personal data and do not expect to receive any.
5. The AI Opportunity Assessment
The assessment is a two-stage flow of bounded questions that narrows according to your answers. The answers and up to five recent report snapshots are held in browser session storage, and deterministic rules evaluate them on your device. No contact details or account are required to see the full report.
When you press Share, bounded answers, package versions, and the decision fingerprint are sent to our same-origin server endpoint. The server recomputes the decision, removes the raw answer map from the public report projection, encrypts that projection, and returns an expiring link. This does not create a persistent report record.
Anyone holding the encrypted share link can read the report's visible evidence until the link expires. The link is marked noindex but is not a password, so share it carefully. Stateless links cannot be revoked individually. No language-model provider is used to create or render the shared report.
6. Transfers, including outside Türkiye
We do not sell, rent, or share your data for advertising. Transfers happen only in the following two cases, and only as far as the purpose requires:
- Hosting: the site runs on our infrastructure provider's servers. For security and availability, the provider keeps connection records (IP address, timestamp, browser information) in its own technical logs. Those servers may be located outside Türkiye.
- Request delivery: a contact request is not stored on our server. It is delivered in a single signed, encrypted HTTPS request to one pre-declared destination — the workflow in which we handle requests. If that destination is not configured, the form does not work; nothing is written quietly somewhere else.
To the extent a transfer abroad occurs, it is made on the conditions of Article 9 of the KVKK (appropriate safeguards or your explicit consent) and, where GDPR applies, on an Article 46 transfer mechanism. We do not otherwise transfer your data to third parties, except where disclosure to a competent public authority is legally required.
7. Analytics and profiling
No analytics tool, measurement pixel, advertising tag, or user tracking runs on this site. The pages make no request to any third-party origin: every asset, fonts included, is served from our own domain, and the content security policy already forbids the browser from connecting anywhere else.
We carry out no automated decision-making and no profiling. The assessment scores by transparent rules, runs in your browser, and builds no profile of you; you are the only person who sees the result.
8. Security
The concrete technical measures in place are:
- All traffic is carried over HTTPS and enforced with HSTS.
- A content security policy, a framing ban, MIME-type pinning, and a restricted permissions policy are applied.
- Form endpoints accept same-origin requests only, request bodies are size-limited, and every field is schema-validated.
- Request delivery is signed (HMAC-SHA256) to a pre-allowlisted destination; in production an unsigned or non-allowlisted destination is refused.
- There is no persistent request database on our server: data we do not keep cannot leak.
9. Your rights and how to exercise them
Under Article 11 of the KVKK you may apply to the controller to:
- Learn whether your personal data is processed and, if so, request information about it.
- Learn the purpose of processing and whether the data is used accordingly.
- Know the third parties to whom data is transferred, in Türkiye or abroad.
- Request that incomplete or inaccurate data be corrected.
- Request erasure or destruction within the conditions set by the law.
- Request that corrections and erasures be notified to the third parties concerned.
- Object to a result produced against you solely by automated analysis.
- Claim compensation for damage caused by unlawful processing.
Send your application through the contact form on this site; writing “data request” in the message speeds it up. Applications are concluded within thirty days at the latest. If you are not satisfied with the outcome, you may complain to the Turkish Personal Data Protection Board.
If you are in the European Union or the United Kingdom, you also have the GDPR rights of access, rectification, erasure, restriction of processing, data portability, and objection, together with the right to withdraw consent and to lodge a complaint with your supervisory authority. Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
10. Children
This site addresses a business audience and is not directed at children. We do not knowingly collect personal data from children; if we notice that such data has reached us, we delete it.
11. Changes
We update this notice whenever the site's behaviour changes. The effective date and version number appear at the top of the page; a material change raises the version number.