Skip to content

Legal document

Cookie Policy

Which cookies are written on the GoTeam site, which of them are strictly necessary for the service to work, which of them need your permission and how you change your preference.

Effective date: 3 August 20269 sectionsVersion cerez-politikasi-v1 (2026-08-17)

Which version binds depends on where you are: English for the European Union and the United Kingdom, Turkish for every other country. Other languages are translations provided for information.

1. What a cookie is and who is responsible on this site

A cookie is a small text record that the site you visit writes into your browser. On your next request the browser sends that record back and the site recognises you. That is why you are not asked for your password again on every page after you log in.

The data controller for the cookies on this site is Motivex Intelligence Bilişim Yazılım Robotik Sanayi ve Ticaret Anonim Şirketi. Its registered address is Muradiye Mah. Celal Bayar Üniversitesi Kampüsü Küme Evleri Teknokent No: 22 Ofis No: Z-27, 45140 Yunusemre / Manisa and its tax record is Mesir Vergi Dairesi 6232288048. You can send your questions about cookies to [email protected] or to 0551 406 11 90.

This policy was written on the basis of Article 51 of Electronic Communications Law No. 5809, Personal Data Protection Law No. 6698 (KVKK, the Turkish Data Protection Law) and the Guidelines on Cookie Practices of the Personal Data Protection Authority. No cookie that is not strictly necessary runs before you explicitly allow it.

Which personal data is processed beyond cookies is set out on the Privacy Policy and KVKK Privacy Notice pages.

2. The full list of cookies we use

The list below is all of the cookies actually written on the site. No advertising cookies, remarketing cookies or social media pixel tracking are used, so they are not on the list.

Strictly necessary cookies

These are required for the service to work and are not subject to consent. The reasoning is in the next section.

  • next-auth.session-token (on a secure connection __Secure-next-auth.session-token), GoTeam, first party. Carries the session of the user who logs in to the management panel. Duration 24 hours.
  • next-auth.csrf-token (on a secure connection __Host-next-auth.csrf-token), GoTeam, first party. Verifies that the login request was not sent from another site. Deleted when the browser closes.
  • next-auth.callback-url (on a secure connection __Secure-next-auth.callback-url), GoTeam, first party. Holds the address of the page to return to once login is complete. Deleted when the browser closes.
  • goteam_acting_company, GoTeam, first party. Holds which customer account a platform administrator is working on; it is created only for platform administrators. Duration 12 hours.
  • cvcheck_session, GoTeam, first party. Carries the e-mail verified session of a person using CV Analysis, so that you can come back to your report later with that record. Duration 30 days.
  • Bot verification record, bot protection provider, third party. Verifies that application and contact forms were filled in by a person. It expires once the verification is complete.

Analytics cookies

These are written only when you allow them. If you do not allow them, the measurement script is never loaded onto the page and these two cookies are not created.

  • _ga, site usage measurement provider, third party. The script writes the cookie to the goteamx.app domain, and the data read is transferred to the provider's infrastructure abroad. It holds the identifier that distinguishes one visitor from another. Duration 2 years.
  • _ga_F9S906DBZ4, site usage measurement provider, third party. Holds the state of the measurement session; the last part of its name is the measurement identifier we use. Duration 2 years.

Your cookie decision is not written to a cookie

The decision you give on the banner is not held in a cookie. Your decision is written to your browser's local storage, in a record named goteam.cookie-consent. The reason is simple: writing a cookie in order to store consent would be writing a cookie before you gave permission.

The record carries only two things: which category you allowed and the date on which you decided. It does not carry your identity and it is not sent to the server.

The record is valid for 1 year. At the end of that period the record expires and you are asked for your preference again. If you clear your browser's site data, the record is deleted earlier; the banner then appears again and only strictly necessary cookies run until you decide.

3. Strictly necessary cookies and why no consent is asked for them

No consent is asked for the first category. The reason is the exception the guidelines recognise: cookies that are strictly necessary for providing the service the user has explicitly requested are not subject to explicit consent (Article 51 of Law No. 5809 and the Guidelines on Cookie Practices).

Without these cookies the service does not work partially, it does not work at all. Without the session cookie you cannot log in to the panel. Without the verification cookie an application form cannot be submitted.

None of the strictly necessary cookies is used to track you across other sites, to build an interest profile or to show advertisements. The legal grounds are Articles 5/2-c and 5/2-f of Law No. 6698: the formation and performance of a contract, and the legitimate interest in the security of the service.

4. Analytics cookies and why explicit consent is required

For the analytics category we ask for explicit consent. Before consent is given the measurement script is not placed on the page, which means that measurement never starts if you do not allow it.

The guidelines treat first party analytics cookies, where measurement is carried out on the site's own infrastructure, as lower risk. That assessment does not apply in our case. Even though the cookie is written to the goteamx.app domain, the measurement is carried out by a site usage measurement provider established abroad and the data is transferred to that provider's infrastructure and processed there. Because the measurement does not stay on our own server, the condition for the exception is not met.

The legal ground for analytics cookies is therefore your explicit consent under Article 5/1 of Law No. 6698. If you do not give consent, no part of the site closes and no feature is restricted, your visit simply does not enter measurement.

The data collected in analytics is as follows: the page addresses viewed, device and browser information, approximate location at city level, and the order in which you browsed. We do not send your name, e-mail address, CV or application content to the measurement provider.

5. The rules of the cookie banner

The cookie banner that appears on your first visit works according to the rules below. These are not design choices, they are conditions for the validity of consent.

  • Categories arrive switched off by default. The analytics box opens unticked. A pre-ticked box or a sentence such as "by continuing to browse you are deemed to have accepted" does not count as consent.
  • "Accept all" and "Reject all" sit on the same screen, at the same size, in the same type size and with the same visual weight. Rejecting takes no more clicks than accepting.
  • Closing, scrolling past or ignoring the banner does not count as consent. For as long as you browse without deciding, only strictly necessary cookies run.
  • Your decision is written with its date to your browser's local storage, not to a cookie. That record holds only which category you allowed, not your identity.

6. How to change your preference

You can change your decision at any time. The Cookie preferences link in the footer of every page is there permanently for that purpose and reopens the banner.

You can also manage it from your browser settings. In Chrome follow Settings > Privacy and security > Third-party cookies, in Safari Settings > Privacy, in Firefox Settings > Privacy & Security, and in Edge Settings > Cookies and site permissions. A change you make in a browser affects only that browser.

If you block all cookies in your browser, the strictly necessary cookies are blocked as well. In that case you cannot log in to the panel and an application form cannot be submitted.

Clearing your browser's site data also deletes the record of your cookie decision. Because the decision sits in local storage rather than in a cookie, deleting only cookies does not delete the decision.

7. Withdrawing consent is as easy as giving it

Consent is withdrawn from the same place and with the same number of clicks as it is given. Opening the link in the footer and switching the analytics category off is enough.

Measurement stops the moment you switch it off: the measurement script is not placed on the page on the next page load, no new measurement record is created and no new data goes to the provider's infrastructure.

Measurement cookies written earlier are deleted at the same moment. When you switch the permission off, the _ga and _gid cookies on the goteamx.app domain are removed from your browser; you do not have to wait for them to expire on their own. If you see a remnant that was not deleted, you can also remove it from your browser's cookie clearing screen, and the route is set out in the previous section.

Withdrawal has no retroactive effect. The measurement records collected while your consent was valid were collected lawfully. You can separately ask for those records to be deleted, and the route is set out in the request section below.

8. Transfer of analytics data abroad

When you allow analytics cookies, your visit data is processed by site usage measurement provider and transferred to servers outside Türkiye.

The transfer rests on your explicit consent under Article 9 of Law No. 6698. As long as you do not give permission, no cookie is created and therefore no data arises to be transferred.

The full list of the providers that touch your data is published in the sub-processor list, and that list is the first place updated when it changes.

The transfer abroad of CV and document files is a separate matter, has nothing to do with cookies, and is explained in the KVKK Privacy Notice.

9. Your rights and how to apply

Data processed through cookies is personal data. All of the rights under Article 11 of Law No. 6698 over that data are yours.

  • To learn whether your personal data is processed and to request information if it is.
  • To learn the purpose of the processing and whether the data is used in line with that purpose.
  • To know the third parties in Türkiye and abroad to whom the data has been transferred.
  • To request correction of data processed incompletely or incorrectly.
  • To request deletion or destruction of the data and to request that this be notified to the third parties the data was transferred to.
  • To object to a result arising to your detriment from analysis carried out exclusively by automated systems.
  • To claim compensation if you suffer loss because the data was processed unlawfully.

How to file the request

You may send your requests under Article 11 of Law No. 6698 (KVKK, the Turkish Data Protection Law) to [email protected]. Your request is concluded within 30 days at the latest. How the request is made and which information it must carry is set out on the Data Subject Request page.

10. Region-specific terms

These terms apply according to where you are. All of them are written out below; each heading says which country it covers.

Türkiye annex: Law No. 6698

Which rules you are reading under

If you are accessing from Türkiye, this text is read under Law No. 6698 on the Protection of Personal Data. The data controller is the company named in the common body.

The full list of processing purposes, legal grounds, retention periods and your rights lives in a separate document: KVKK Privacy Notice. We do not repeat that list here so the two texts cannot drift apart.

Requests and transfer abroad

You submit requests under Article 11 through the channel described on the Data Subject Request page.

Where CV files are processed outside Türkiye, and the ground for it (Article 9), is explained in the transfer section of the common body.

Azerbaijan annex: Law No. 998-IIIQ

Your rights (Article 7.1)

If you are accessing from Azerbaijan, this text is read under Law No. 998-IIIQ on Personal Data.

  • To know whether your personal data exists, and who its owner and operator are.
  • To ask for the legal ground and the consequences of collection, processing and disclosure to third parties.
  • To see the content of the data; to know the purpose, duration and method of processing and who has access.
  • To ask for correction and destruction of the data, and to apply for it to be archived.
  • To ask for collection and processing to be prohibited.
  • To know the source of the data and to ask for the lawfulness of processing to be proven.

Objection and automated decisions (Articles 7.2 and 7.3)

Where processing is not mandatory under law you may object in writing; you do not need to give a reason, and the processing stops the moment we receive the objection.

The CV analysis score is calculated automatically. The score does not replace a human decision; you may object to an automated decision and ask for the result to be reviewed by a person.

Cross border transfer (Articles 14.3 and 14.4)

Your personal data is transferred outside the Republic of Azerbaijan. The main place of processing is the Republic of Türkiye; transfers are also made to the countries of the providers listed as groups in the common body.

Regardless of the level of protection, the transfer rests on the separate consent you give. If you withdraw that consent the service cannot technically be provided; on its own this leads to no other consequence.

Compliance certificate and state registration (Articles 11.2.4, 7.1, 15)

We state it plainly: there is no compliance certificate and no state expert review has been carried out.

The company is established in Türkiye and has no legal entity in Azerbaijan. Whether the state registration duty in Article 15 arises in this case will be determined by local legal opinion.

European Union and United Kingdom annex

Binding version of this section: English.

Your rights under the GDPR and UK GDPR

If you are accessing from the EU or the United Kingdom, your rights of access, rectification, erasure, restriction, portability and objection, and your rights concerning automated decisions, are set out one by one on the GDPR Notice page. We do not repeat that list here.

Your right to complain to a supervisory authority and the time in which a request is answered are explained on the same page.