Skip to content

Legal document

Privacy Policy

In the GoTeam service: where the data goes, who sees it, how it is protected and how long it stays.

Effective date: 3 August 20268 sectionsVersion gizlilik-v1 (2026-08-17)

Which version binds depends on where you are: English for the European Union and the United Kingdom, Turkish for every other country. Other languages are translations provided for information.

1. What this policy covers and how it relates to the privacy notice

This policy describes how data is actually processed in the GoTeam service offered at goteamx.app: which records we keep, which provider sees what, where the data sits and how long it stays.

It is not the same document as the KVKK Privacy Notice. That notice lists the identity of the data controller, the processing purposes, the legal grounds and your rights under Article 10 of Law No. 6698. This page does not repeat those lists, it describes the practice. If the two read differently on a point, the privacy notice governs as far as the legal ground is concerned.

For the candidate data that our employer customers upload to the panel, the customer is the data controller and we are the data processor. The boundaries of that division of duties are set out in the Data Processing Agreement. If you applied to a posting as a candidate, the privacy notice of the company you applied to is shown separately on the application page.

2. The data we collect

Data arrives in two ways: either you type it into a form, or it is produced while the service runs. The four sets below are all of it.

Account and company details

During sign-up we take your full name, work e-mail, phone number and the name of the company you represent. When you add a colleague to the panel, their name, e-mail and role are recorded. These fields exist so that the account can be opened, the login can be verified and you can be reached.

Usage and transaction records

Login attempts, session information and error logs are kept. Changes made in the panel are also written to the audit trail: which user, when, which field of which record they changed, and what the old and new values were. That record is not a surveillance tool but an accountability tool: it is kept so that there is an answer when someone asks who changed a candidate's status.

Payment and invoice details

Your card details are never recorded, processed or displayed on goteamx.app servers at any stage. The payment page is provided by PayTR.

So that an invoice can be issued, we take the trade name, tax office, tax identification number, invoice address and e-mail address. Under the Tax Procedure Law these fields are mandatory elements of an invoice; if they are incomplete the document cannot be issued.

CV and candidate data

The file taken from a candidate is in PDF format. The file itself and the text extracted from it are analysed together with the criteria of the position applied to. In the CV Analysis product, the e-mail address of the person uploading and the file they upload are processed; the analysis does not start before the e-mail is verified.

The assessment is AI assisted. The score is produced against a fixed, evidence based rubric, and the final decision always belongs to a person. If you believe that an exclusively automated analysis has produced a result to your detriment, you may object under Article 11 of Law No. 6698 (KVKK, the Turkish Data Protection Law).

3. Third parties that see your data

Apart from the companies below, no personal data is transferred to any third party. Your data is not sold, rented or shared with advertising networks, data brokers or any other party that trains models. Each line says what that provider sees.

  • Cloud file storage provider established outside Türkiye: Storing the CV and document files that are uploaded. Data it sees: CV and document files. The data is processed outside Türkiye.
  • AI analysis provider established outside Türkiye: Analysing and scoring CV content. Data it sees: CV text and position criteria. The data is processed outside Türkiye.
  • Site usage measurement provider established outside Türkiye: Measuring how the site is used. Data it sees: Device, browser and browsing data. The data is processed outside Türkiye.
  • Bot protection provider established outside Türkiye: Verifying that forms are filled in by a person. Data it sees: IP address and browser verification record. The data is processed outside Türkiye.
  • PayTR Ödeme ve Elektronik Para Kuruluşu A.Ş.: Collecting the payment. Data it sees: Full name, e-mail, transaction amount and payment result. It is a company established in Türkiye.
  • ePlatform Bulut Bilişim A.Ş. (Turkcell e-Şirket): Issuing the official e-Arşiv invoice. Data it sees: Invoice title, tax details, address, e-mail and amount. It is a company established in Türkiye.

Two notes on payment and site measurement

The payment infrastructure is provided by PayTR Ödeme ve Elektronik Para Kuruluşu A.Ş., authorised by the Central Bank of the Republic of Türkiye under Law No. 6493. PCI-DSS compliance for card data security rests with the payment institution.

The measurement tool only counts page views and button clicks. No name, e-mail, candidate record or CV content is sent to the measurement code; what it sees is the device, the browser, where you came from and which page was opened.

The full list of the providers that touch your data is published in the sub-processor list, and that list is the first place updated when it changes.

4. Where the data is hosted

CV files are hosted by our cloud file storage provider established outside Türkiye and are sent to our AI provider established outside Türkiye for analysis. These two providers are the places where the data is processed outside Türkiye. The transfer falls within Article 9 of Law No. 6698 (KVKK, the Turkish Data Protection Law) and is necessary for the service to be provided; for the analysis service your explicit consent is obtained in addition. You can learn the identity of the providers through the channel described on the Data Subject Request page. If you do not give consent, no analysis can be carried out; on its own this leads to no other consequence.

The part processed outside Türkiye is these three: storing CV files, analysing CV content and measuring site usage. Payment collection and the issuing of official invoices run through companies established in Türkiye. Account records, postings, applications and audit records are held in the GoTeam database and are not sent to any provider outside the three tasks above.

5. Security measures

The measures we take are listed one by one below. We do not claim here a certificate or an audit report that we do not hold.

  • All traffic is carried over an encrypted connection (HTTPS/TLS); an unencrypted connection is not accepted.
  • Permissions are granted through roles. Every user belongs to a role and every role to a set of individually defined permissions; a user without a permission does not see the screen, and their request is refused on the server as well.
  • The least privilege principle is applied: a role is never given more permission than the work requires.
  • The company boundary is enforced on the server. One customer's data never appears in another customer's panel; every query is limited by the identity of the account.
  • Critical changes are written to the audit trail and the record cannot be edited afterwards.
  • In KVKK masking mode, candidate identity details are hidden on screen. Masking does more than cover the view: the delete and export buttons disappear for a masked user, and masking is applied on the server as well.
  • The payment page is not our page, it is the payment institution's page; card data never passes through our servers at any stage.

If there is a breach

No measure reduces risk to zero. If we detect a breach affecting personal data, under Article 12/5 of Law No. 6698 we notify the Personal Data Protection Board as soon as possible and within 72 hours at the latest, and we reach the affected people in the shortest reasonable time.

6. Retention periods

Your data is kept for the duration of the relationship between us and throughout the limitation periods set out in the legislation. Payment and invoice records are kept for 10 years under Article 82 of the Turkish Commercial Code (at least 5 years under Article 253 of the Tax Procedure Law); even if you delete your account, these records are held for that period and are then anonymised by severing the links to you.

The periods below are the concrete form of that rule. A record whose period has expired is deleted, destroyed or anonymised by severing its link to a person.

  • Unverified CV Analysis upload: a record left without the e-mail address being verified is deleted together with its file at the end of 7 days.
  • Distance transaction records: 3 years.
  • Electronic commerce transaction records under Article 11/3 of Law No. 6563: 10 years.
  • Candidate data: the employer customer sets the retention period and we delete on that instruction. Requests about the period and about deletion are addressed to the company applied to.

7. Cookies

Mandatory cookies exist to keep the session open and for security and bot protection; without them you cannot log in. On the measurement side there is a single tool and it runs only when you allow it. We use no advertising network cookies and no profiling trackers.

What each cookie does, how long it stays and how to change your preference are set out on the Cookie Policy page.

8. Contact

You can send your questions about this policy to [email protected] or reach us on 0551 406 11 90.

Data controller: Motivex Intelligence Bilişim Yazılım Robotik Sanayi ve Ticaret Anonim Şirketi. Address: Muradiye Mah. Celal Bayar Üniversitesi Kampüsü Küme Evleri Teknokent No: 22 Ofis No: Z-27, 45140 Yunusemre / Manisa. Tax office and number: Mesir Vergi Dairesi / 6232288048.

You may send your requests under Article 11 of Law No. 6698 (KVKK, the Turkish Data Protection Law) to [email protected]. Your request is concluded within 30 days at the latest. How the request is made and which information it must carry is set out on the Data Subject Request page.

9. Region-specific terms

These terms apply according to where you are. All of them are written out below; each heading says which country it covers.

Türkiye annex: Law No. 6698

Which rules you are reading under

If you are accessing from Türkiye, this text is read under Law No. 6698 on the Protection of Personal Data. The data controller is the company named in the common body.

The full list of processing purposes, legal grounds, retention periods and your rights lives in a separate document: KVKK Privacy Notice. We do not repeat that list here so the two texts cannot drift apart.

Requests and transfer abroad

You submit requests under Article 11 through the channel described on the Data Subject Request page.

Where CV files are processed outside Türkiye, and the ground for it (Article 9), is explained in the transfer section of the common body.

Azerbaijan annex: Law No. 998-IIIQ

Your rights (Article 7.1)

If you are accessing from Azerbaijan, this text is read under Law No. 998-IIIQ on Personal Data.

  • To know whether your personal data exists, and who its owner and operator are.
  • To ask for the legal ground and the consequences of collection, processing and disclosure to third parties.
  • To see the content of the data; to know the purpose, duration and method of processing and who has access.
  • To ask for correction and destruction of the data, and to apply for it to be archived.
  • To ask for collection and processing to be prohibited.
  • To know the source of the data and to ask for the lawfulness of processing to be proven.

Objection and automated decisions (Articles 7.2 and 7.3)

Where processing is not mandatory under law you may object in writing; you do not need to give a reason, and the processing stops the moment we receive the objection.

The CV analysis score is calculated automatically. The score does not replace a human decision; you may object to an automated decision and ask for the result to be reviewed by a person.

Cross border transfer (Articles 14.3 and 14.4)

Your personal data is transferred outside the Republic of Azerbaijan. The main place of processing is the Republic of Türkiye; transfers are also made to the countries of the providers listed as groups in the common body.

Regardless of the level of protection, the transfer rests on the separate consent you give. If you withdraw that consent the service cannot technically be provided; on its own this leads to no other consequence.

Compliance certificate and state registration (Articles 11.2.4, 7.1, 15)

We state it plainly: there is no compliance certificate and no state expert review has been carried out.

The company is established in Türkiye and has no legal entity in Azerbaijan. Whether the state registration duty in Article 15 arises in this case will be determined by local legal opinion.

European Union and United Kingdom annex

Binding version of this section: English.

Your rights under the GDPR and UK GDPR

If you are accessing from the EU or the United Kingdom, your rights of access, rectification, erasure, restriction, portability and objection, and your rights concerning automated decisions, are set out one by one on the GDPR Notice page. We do not repeat that list here.

Your right to complain to a supervisory authority and the time in which a request is answered are explained on the same page.