Privacy notice
How Global Talent Journey uses personal data: what it can and cannot read, why, on what legal basis, who receives it, how long it is kept and how to use your rights under the UK GDPR, the EU GDPR and Turkish KVKK.
This page will be reviewed by a qualified lawyer before registration opens. Last updated .
Who is responsible for your data
- Operator
- Furkan Efe Genç
- Trade name
- Furkan Efe Genç
- Legal form
- sole proprietorship (şahıs işletmesi), self-employed professional (serbest meslek erbabı)
- Registration
- Self-employed professional (serbest meslek erbabı)
- Address
- Ahlatlıbel Mahallesi, 1859. Cadde No 44/32 (Stüdyo Kolej Binası), 06850 Çankaya/Ankara, Türkiye
- Telephone
- +90 531 835 00 80
- Tax office
- Doğanbey Vergi Dairesi
- Tax number
- 3920781168
- Brand
- Global Talent Journey
The operator named above is the controller of your personal data under the UK GDPR and the EU GDPR, and the veri sorumlusu under Turkish Law No. 6698 on the Protection of Personal Data (KVKK). Global Talent Journey (GTJ) is the brand of this business.
No representative in the United Kingdom or in the European Union has been appointed yet. The operator will name them here before accounts are offered to people in those countries. Registration is not open yet: today only test accounts and the owner’s own accounts exist.
Contact for anything on this page: hello@globaltalentjourney.com or the contact form, which needs no sign-in.
GTJ intends to show this notice as a link on the sign-up page and in the app before an account is created, separately from any consent. It does not ask you to tick that you have read it.
What GTJ can and cannot read
GTJ cannot read the contents of your vault. That does not mean GTJ processes no personal data: the account around the vault, the community and the logs are ordinary personal data, listed here.
| Data | Can GTJ read it? | Why |
|---|---|---|
| Your e-mail address, username and name | Yes | Needed to run your account and send account e-mails. |
| IP addresses and usage logs held by the community engine | Yes | Kept by the engine for security and abuse prevention. |
| How many files you store, their encrypted sizes and upload times | Yes | Needed for storage limits, versions and deletion. |
| Community posts, comments, polls and reactions | Yes | They are written for other members to read and are not encrypted. |
| Reports, appeals and moderation decisions | Yes | Needed to run moderation and to tell you the outcome. |
| Contact requests to professionals and professional applications | Yes | They are delivered or reviewed by people, so they are not encrypted. |
| Requests sent through the contact form | Yes | The operator reads and answers them. |
| The contents and names of files in your vault | No | Encrypted on your device with a key the operator does not hold. |
| Your workspace (checklist, targets, notes) and private profile | No | Encrypted on your device before they are stored. |
The vault is not open for real sensitive documents yet. Its encryption is waiting for an independent security review; until then only test documents are stored. If you lose both your vault passphrase and your recovery key, nobody, including GTJ, can open your encrypted files.
What is processed, why, on what basis and for how long
Each activity below names the personal data, why it is used, the legal basis under the UK and EU GDPR, the ground under KVKK Art. 5, and how long it is kept. Where legitimate interests are used, GTJ has weighed them against your interests, and you can object (see your rights).
| Activity | Personal data | Purpose | UK GDPR / EU GDPR basis | KVKK ground (Art. 5(2)) | How long |
|---|---|---|---|---|---|
| Account | E-mail, username, name, password hash or passkey, sessions, IP at sign-in | Create and run your account | Contract, Art. 6(1)(b) | (c) necessary for the contract | While the account exists |
| Vault storage | Encrypted files and keys; file count, encrypted sizes and times | Store your documents so only you can open them | Contract, Art. 6(1)(b) | (c) necessary for the contract | Until you delete them; trash is emptied 7 to 8 days after you move a file there |
| Workspace and private profile | Encrypted records; revision and times | Your preparation checklist, targets and CV fields | Contract, Art. 6(1)(b) | (c) necessary for the contract | Until you delete them or the account |
| Community posting | Posts, titles, polls, reactions, labels, times | Let members share work, ask and give feedback | Contract, Art. 6(1)(b) | (c) necessary for the contract | Until you delete them; at account deletion you choose delete or anonymise |
| Community profile photo (not available yet) | An optional small photo you choose. Your device and the server each decode it and save it again as a new image, so location, camera details and the original file name are removed. It is stored under a random name in a separate storage bucket in EU jurisdiction and shown only to people who can see your community profile | Show other members who is posting | Contract, Art. 6(1)(b) | (c) necessary for the contract | Until you remove or replace it, or delete your account. A copy whose removal failed is deleted by a daily clean-up |
| Moderation, reports and appeals | Reports with reason and text, hidden or removed state, appeals, moderator’s reason, rules versions you accepted | Keep the community lawful and safe; tell reporters the outcome; hear appeals | Legitimate interests, Art. 6(1)(f), and legal obligations where online safety law applies | (ç) legal obligation where one applies, (e) establishing or defending a right, (f) legitimate interest | Acceptances and appeals: while the account exists. Reports: kept with the engine’s review record; a fixed period is still to be set |
| Professional applications and licence checks | Professional name, jurisdiction, register number, regulator link, firm, professional e-mail, scope, languages, check records | Check a professional’s registration before listing | Contract, Art. 6(1)(b); legitimate interests for re-checks and complaints | (c) contract, (f) legitimate interest | While the application or the account exists |
| Contact requests to a professional | The name, e-mail address and message you choose to share | Deliver your message to the one professional you chose | Contract, Art. 6(1)(b) | (c) necessary for the contract | Record: until account deletion. The e-mail copy the professional receives cannot be recalled or deleted by GTJ |
| Contact form without sign-in | Request type, e-mail, optional name, message, content link, good-faith statement, a keyed hash of your IP address | Answer questions, data-rights and deletion requests, illegal-content notices and complaints | Legal obligation, Art. 6(1)(c), for rights requests and notices; legitimate interests for other questions and abuse prevention | (ç) legal obligation (KVKK Art. 13), (f) legitimate interest | 12 months from receipt (a proposal checked by the lawyer) |
| Security and service logs | IP addresses, browser type, sign-in, search and page-view logs, staff actions | Protect accounts and investigate abuse | Legitimate interests, Art. 6(1)(f) | (ç) legal obligation where Law No. 5651 applies, (f) legitimate interest | No fixed period yet; your IP rows are cleared when your account is deleted |
| Backups | A daily copy of the engine database, kept in EU jurisdiction storage (no vault file contents) | Restore the service after a failure | Legitimate interests, Art. 6(1)(f) | (f) legitimate interest | One copy a day; the newest seven are kept, so a copy is deleted after about a week |
| Deletion records | Account number, a random reference of the deletion, creation and deletion time, and whether you chose to delete or anonymise your posts; no name, e-mail or content. A copy is kept in storage separate from the database | Stop a restored backup from bringing a deleted account back | Legitimate interests, Art. 6(1)(f) | (ç) KVKK Art. 7, (f) legitimate interest | As long as a backup older than the deletion can be restored |
| Reminders you set | A random reminder number and the time it is due. The words of the reminder stay encrypted in your workspace | Tell you when a reminder you set is due | Contract, Art. 6(1)(b) | (c) necessary for the contract | Until you delete it, and at the latest 30 days after its time; also removed when you reset your vault or delete your account |
| Push notifications on a phone (not available yet) | For each phone where you turn them on: the notification token of this app, the platform and the notification types you chose for that phone | Send a notification with neutral text to that phone | Contract, Art. 6(1)(b) | (c) necessary for the contract | Until you turn them off on that phone, sign out there, remove the device or delete your account |
| Account e-mails | Recipient address, name, e-mail content | Confirm your address, sign-in and password e-mails, notifications, delivering contact requests | Contract, Art. 6(1)(b) | (c) necessary for the contract | The sending provider’s log period has not been checked yet |
| This website and the contact address | Request data at the delivery network; sender, subject and content of e-mail you send | Serve these pages and forward your e-mail to the operator | Legitimate interests, Art. 6(1)(f) | (f) legitimate interest | E-mail routing logs 30 to 31 days at the provider; e-mails in the operator’s inbox while the request is handled |
How data is collected
- From you, by automated means: what you type and upload in the member app, on the sign-up page and in the contact form.
- Automatically, while you use the service: sign-in, security and usage logs recorded by the community engine.
- From other people: members may mention you in a post or report a post of yours; a professional’s registration details are checked against public registers.
Collection is automated in every case (KVKK Tebliğ Art. 5(1)(i)). No decision about you is made by automated means (see below).
Sensitive data in your documents
GTJ does not ask for health, religion, ethnic origin, political opinion, biometric data or criminal records. Documents you choose to keep in your vault, such as a passport, a medical certificate or a criminal-record certificate, can contain such data, and so can documents about other people (referees, employers, family). GTJ treats vault contents as possibly containing special-category data. They are encrypted on your device, the operator holds no key and cannot read them, and encryption is used as a safeguard, never as a reason to say no personal data is processed. Whether storing encrypted special-category data counts as processing it under KVKK Art. 6 and GDPR Art. 9 is one of the questions put to the lawyer.
Please do not upload documents about other people, or unnecessary pages about your family or children, unless your preparation really needs them.
Who receives data
GTJ uses these service providers. They process data on the operator’s instructions; none of them can read the contents of your vault.
| Provider | What for | Personal data | Where | Transfer safeguard | Agreement status |
|---|---|---|---|---|---|
| Railway Corporation 548 Market St PMB 68956, San Francisco, California 94104, United States Provider’s terms (checked ) | Hosting the community engine: the application servers, the database and the cache that hold accounts, community posts, moderation records, encrypted workspace and profile records, file metadata and server logs | Account data (e-mail address, username, name), community content, moderation and appeal records, professional applications and contact requests, IP addresses and usage logs, encrypted records the operator cannot read | EU West region (Amsterdam, Netherlands). Railway's own volume backups are not used; database backups are kept in Cloudflare R2 storage in the EU jurisdiction | EU–US Data Privacy Framework and its UK Extension (Railway listed as active), with the EU Standard Contractual Clauses and UK Addendum in Railway's DPA as fallback. KVKK standard contract: not signed | Railway's data processing agreement has not been signed yet (it is completed through Railway's signature form) |
| Cloudflare, Inc. 101 Townsend St, San Francisco, CA 94107, United States Provider’s terms (checked ) | Registration of the domain name, DNS, delivery of this website, storage of encrypted vault files, storage of the community engine's database backups and deletion records, and forwarding of e-mail sent to the contact address | IP addresses and request data of website visitors; encrypted vault files the operator cannot read; daily copies of the community engine's database (account data, community content, moderation and professional records, logs with IP addresses, and the encrypted records), and deletion records holding an account number and times; the sender, recipient, subject and content of e-mail sent to the contact address | Encrypted vault files, database backups and deletion records: EU jurisdiction storage. Website delivery, DNS and e-mail forwarding: Cloudflare's global network | EU–US Data Privacy Framework and its UK Extension (Cloudflare listed as active; recertification due 23 September 2026), with the EU Standard Contractual Clauses and UK Addendum in Cloudflare's DPA as fallback. KVKK standard contract: not signed | Cloudflare's data processing addendum (version 6.4) is part of its self-serve agreement; the date GTJ accepted it has not been recorded yet |
| Plus Five Five, Inc. (Resend) 2261 Market Street #5039, San Francisco, CA 94114, United States Provider’s terms (checked ) | Sending account e-mails from the community engine: address confirmation, sign-in links, password resets, notifications and contact requests delivered to a professional | Recipient e-mail address and name, and the content of those e-mails (for a contact request to a professional: the name, e-mail address and message the member chose to share) | Sending region EU (Ireland). Resend's regions page states that all account data, including e-mail metadata, logs and API records, is stored in the United States whatever the sending region, and its agreement states that its primary processing takes place in the United States | EU Standard Contractual Clauses, UK Addendum and the EU–US Data Privacy Framework with its UK Extension, as named in Resend's DPA; Resend's framework listing not yet checked by GTJ. KVKK standard contract: not signed | Resend's data processing addendum takes effect when its terms are accepted; the GTJ sending domain is set up and the engine has sent through it since 13 September 2026, but the date GTJ accepted the terms has not been recorded |
- A professional you choose receives the name, e-mail address and message you decide to share, by e-mail.
- Other members see what you post in the community. The community is not public and is not indexed by search engines.
- Authorities receive data only when a binding legal order requires it; the operator checks each order and, unless the law forbids it, tells the person concerned. Encrypted vault contents could only ever be handed over in encrypted form.
- Push notifications are not available yet. When they are and you turn them on for a phone, Apple (iPhone) or Google (Android) delivers them: they receive that phone’s notification token and the neutral text, never the content of a reminder, a post or a document. They will be listed above before that happens.
- No data is sold, and none is used for advertising or to train artificial intelligence. No payment provider is used today.
Transfers outside Türkiye, the UK and the EU
The operator is in Türkiye and every service provider above is a company in the United States, so your data is transferred abroad. The servers GTJ chose are in the European Union where the provider allows it (Amsterdam for the engine, EU jurisdiction storage for vault files and database backups), but a provider can still access data from the United States.
- UK GDPR and EU GDPR: Railway and Cloudflare are listed as active under the EU–US Data Privacy Framework and its UK Extension; Resend’s agreement names the Framework too, but GTJ has not yet checked its listing. Each provider’s agreement adds the EU Standard Contractual Clauses and the UK Addendum, which apply if the Framework does not.
- KVKK: the Turkish Personal Data Protection Board has not declared any country adequate, so a transfer needs one of the safeguards in KVKK Art. 9, normally the Board’s standard contract notified within five business days. That standard contract has not been signed with any of the providers yet. The operator is asking them, and this is an open item that must be resolved before registration opens.
How long data is kept
Personal data is kept only as long as its purpose needs. The periods for each activity are in the table above. In short:
- Your account, vault, workspace, profile and community records stay until you delete them or your account. Deleting the account starts at once.
- Contact-form requests: 12 months from receipt.
- Security logs and reports do not have a fixed period yet. This is a known gap; the periods will be set and published here before registration opens.
- Database backups are taken once a day and the newest seven are kept, so a backup can still contain a deleted account for about a week; after any restore, deletions are applied again so a deleted account does not come back.
- Reminders: at the latest 30 days after their time.
- No billing records exist, because no payment is taken. If payments start, the periods the law sets for commercial records will be added here first.
Your rights
Under the UK GDPR and EU GDPR you can ask to:
- see the personal data GTJ holds about you and get a copy (access);
- correct data that is wrong or incomplete;
- have your data erased;
- restrict how it is used while a question is being settled;
- receive the data you gave in a structured, machine-readable form (portability: the in-app export does this);
- object to processing based on legitimate interests;
- withdraw consent where consent is used (GTJ does not rely on consent today).
Under KVKK Art. 11 you have the right to:
- learn whether your personal data is processed;
- request information if it has been processed;
- learn the purpose of processing and whether it is used in line with that purpose;
- know the third parties in Türkiye or abroad to whom it is transferred;
- ask for correction if it is incomplete or inaccurate;
- ask for deletion or destruction under the conditions of KVKK Art. 7;
- ask that the third parties it was transferred to are told of a correction, deletion or destruction;
- object to a result against you that arises only from automated analysis;
- claim compensation if you suffer damage because of unlawful processing.
How to use your rights
- In the app: My profile → Settings → Account and data → Download my data, or Delete my account.
- Without signing in: the contact form, choosing “Privacy and data rights” or “Account deletion”.
- By e-mail: hello@globaltalentjourney.com
Exercising your rights is free. GTJ answers within one month under the GDPR and within 30 days under KVKK Art. 13, and tells you if a complex request needs longer and why. GTJ may ask you to confirm that the account is yours, for example by replying from the account’s e-mail address; it does not ask for identity documents for this.
Complaints
You can complain to GTJ first, through the contact form (type “Complaint” or “Privacy and data rights”) or by e-mail. GTJ acknowledges a complaint within 30 days and tells you the outcome. You can also complain to a supervisory authority at any time:
- Türkiye: the Personal Data Protection Board (kvkk.gov.tr). Under KVKK Art. 14 you first apply to GTJ, then complain within 30 days of GTJ’s answer, or within 60 days of your application if there is no answer.
- United Kingdom: the Information Commissioner’s Office (ico.org.uk).
- European Union: the data protection authority of the country where you live or work (list of authorities).
Automated decisions
GTJ makes no decision about you by automated means and does not profile you. The preparation percentage in the workspace only counts the tasks you marked done; it is not an assessment of your case. Posts can be hidden automatically when several members report them; a moderator then reviews them and you can appeal.
Minimum age
Accounts are for people aged 18 or over. GTJ does not ask for an identity document to check this. If you believe a person under 18 has an account, tell GTJ through the contact form and the account will be reviewed.
E-mails
GTJ sends no marketing e-mails. Account e-mails (address confirmation, sign-in, password, notifications you chose) are part of the service. If marketing messages are ever offered, they will need a separate, optional choice that is off by default.
Changes to this notice
Every change to this notice is dated at the top of the page. A change that affects what data is used or why is announced in the app and by e-mail before it takes effect, and a new purpose is described here before data is used for it. Continuing to use the service is never treated as agreeing to such a change.