Skip to content
Global Talent Journey
  • How it works
  • Pathways
  • Membership
  • Professionals
Türkçe
Sign in

Privacy notice

How Global Talent Journey uses personal data: what it can and cannot read, why, on what legal basis, who receives it, how long it is kept and how to use your rights under the UK GDPR, the EU GDPR and Turkish KVKK.

This page will be reviewed by a qualified lawyer before registration opens. Last updated 13 September 2026.

On this page

  • Who is responsible for your data
  • What GTJ can and cannot read
  • What is processed, why, on what basis and for how long
  • How data is collected
  • Sensitive data in your documents
  • Who receives data
  • Transfers outside Türkiye, the UK and the EU
  • How long data is kept
  • Your rights
  • How to use your rights
  • Complaints
  • Automated decisions
  • Cookies and browser storage
  • Minimum age
  • E-mails
  • Changes to this notice

Who is responsible for your data

Operator
Furkan Efe Genç
Trade name
Furkan Efe Genç
Legal form
sole proprietorship (şahıs işletmesi), self-employed professional (serbest meslek erbabı)
Registration
Self-employed professional (serbest meslek erbabı)
Address
Ahlatlıbel Mahallesi, 1859. Cadde No 44/32 (Stüdyo Kolej Binası), 06850 Çankaya/Ankara, Türkiye
E-mail
hello@globaltalentjourney.com
Telephone
+90 531 835 00 80
Tax office
Doğanbey Vergi Dairesi
Tax number
3920781168
Brand
Global Talent Journey

The operator named above is the controller of your personal data under the UK GDPR and the EU GDPR, and the veri sorumlusu under Turkish Law No. 6698 on the Protection of Personal Data (KVKK). Global Talent Journey (GTJ) is the brand of this business.

No representative in the United Kingdom or in the European Union has been appointed yet. The operator will name them here before accounts are offered to people in those countries. Registration is not open yet: today only test accounts and the owner’s own accounts exist.

Contact for anything on this page: hello@globaltalentjourney.com or the contact form, which needs no sign-in.

GTJ intends to show this notice as a link on the sign-up page and in the app before an account is created, separately from any consent. It does not ask you to tick that you have read it.

What GTJ can and cannot read

GTJ cannot read the contents of your vault. That does not mean GTJ processes no personal data: the account around the vault, the community and the logs are ordinary personal data, listed here.

DataCan GTJ read it?Why
Your e-mail address, username and nameYesNeeded to run your account and send account e-mails.
IP addresses and usage logs held by the community engineYesKept by the engine for security and abuse prevention.
How many files you store, their encrypted sizes and upload timesYesNeeded for storage limits, versions and deletion.
Community posts, comments, polls and reactionsYesThey are written for other members to read and are not encrypted.
Reports, appeals and moderation decisionsYesNeeded to run moderation and to tell you the outcome.
Contact requests to professionals and professional applicationsYesThey are delivered or reviewed by people, so they are not encrypted.
Requests sent through the contact formYesThe operator reads and answers them.
The contents and names of files in your vaultNoEncrypted on your device with a key the operator does not hold.
Your workspace (checklist, targets, notes) and private profileNoEncrypted on your device before they are stored.

The vault is not open for real sensitive documents yet. Its encryption is waiting for an independent security review; until then only test documents are stored. If you lose both your vault passphrase and your recovery key, nobody, including GTJ, can open your encrypted files.

What is processed, why, on what basis and for how long

Each activity below names the personal data, why it is used, the legal basis under the UK and EU GDPR, the ground under KVKK Art. 5, and how long it is kept. Where legitimate interests are used, GTJ has weighed them against your interests, and you can object (see your rights).

ActivityPersonal dataPurposeUK GDPR / EU GDPR basisKVKK ground (Art. 5(2))How long
AccountE-mail, username, name, password hash or passkey, sessions, IP at sign-inCreate and run your accountContract, Art. 6(1)(b)(c) necessary for the contractWhile the account exists
Vault storageEncrypted files and keys; file count, encrypted sizes and timesStore your documents so only you can open themContract, Art. 6(1)(b)(c) necessary for the contractUntil you delete them; trash is emptied 7 to 8 days after you move a file there
Workspace and private profileEncrypted records; revision and timesYour preparation checklist, targets and CV fieldsContract, Art. 6(1)(b)(c) necessary for the contractUntil you delete them or the account
Community postingPosts, titles, polls, reactions, labels, timesLet members share work, ask and give feedbackContract, Art. 6(1)(b)(c) necessary for the contractUntil you delete them; at account deletion you choose delete or anonymise
Community profile photo (not available yet)An optional small photo you choose. Your device and the server each decode it and save it again as a new image, so location, camera details and the original file name are removed. It is stored under a random name in a separate storage bucket in EU jurisdiction and shown only to people who can see your community profileShow other members who is postingContract, Art. 6(1)(b)(c) necessary for the contractUntil you remove or replace it, or delete your account. A copy whose removal failed is deleted by a daily clean-up
Moderation, reports and appealsReports with reason and text, hidden or removed state, appeals, moderator’s reason, rules versions you acceptedKeep the community lawful and safe; tell reporters the outcome; hear appealsLegitimate interests, Art. 6(1)(f), and legal obligations where online safety law applies(ç) legal obligation where one applies, (e) establishing or defending a right, (f) legitimate interestAcceptances and appeals: while the account exists. Reports: kept with the engine’s review record; a fixed period is still to be set
Professional applications and licence checksProfessional name, jurisdiction, register number, regulator link, firm, professional e-mail, scope, languages, check recordsCheck a professional’s registration before listingContract, Art. 6(1)(b); legitimate interests for re-checks and complaints(c) contract, (f) legitimate interestWhile the application or the account exists
Contact requests to a professionalThe name, e-mail address and message you choose to shareDeliver your message to the one professional you choseContract, Art. 6(1)(b)(c) necessary for the contractRecord: until account deletion. The e-mail copy the professional receives cannot be recalled or deleted by GTJ
Contact form without sign-inRequest type, e-mail, optional name, message, content link, good-faith statement, a keyed hash of your IP addressAnswer questions, data-rights and deletion requests, illegal-content notices and complaintsLegal obligation, Art. 6(1)(c), for rights requests and notices; legitimate interests for other questions and abuse prevention(ç) legal obligation (KVKK Art. 13), (f) legitimate interest12 months from receipt (a proposal checked by the lawyer)
Security and service logsIP addresses, browser type, sign-in, search and page-view logs, staff actionsProtect accounts and investigate abuseLegitimate interests, Art. 6(1)(f)(ç) legal obligation where Law No. 5651 applies, (f) legitimate interestNo fixed period yet; your IP rows are cleared when your account is deleted
BackupsA daily copy of the engine database, kept in EU jurisdiction storage (no vault file contents)Restore the service after a failureLegitimate interests, Art. 6(1)(f)(f) legitimate interestOne copy a day; the newest seven are kept, so a copy is deleted after about a week
Deletion recordsAccount number, a random reference of the deletion, creation and deletion time, and whether you chose to delete or anonymise your posts; no name, e-mail or content. A copy is kept in storage separate from the databaseStop a restored backup from bringing a deleted account backLegitimate interests, Art. 6(1)(f)(ç) KVKK Art. 7, (f) legitimate interestAs long as a backup older than the deletion can be restored
Reminders you setA random reminder number and the time it is due. The words of the reminder stay encrypted in your workspaceTell you when a reminder you set is dueContract, Art. 6(1)(b)(c) necessary for the contractUntil you delete it, and at the latest 30 days after its time; also removed when you reset your vault or delete your account
Push notifications on a phone (not available yet)For each phone where you turn them on: the notification token of this app, the platform and the notification types you chose for that phoneSend a notification with neutral text to that phoneContract, Art. 6(1)(b)(c) necessary for the contractUntil you turn them off on that phone, sign out there, remove the device or delete your account
Account e-mailsRecipient address, name, e-mail contentConfirm your address, sign-in and password e-mails, notifications, delivering contact requestsContract, Art. 6(1)(b)(c) necessary for the contractThe sending provider’s log period has not been checked yet
This website and the contact addressRequest data at the delivery network; sender, subject and content of e-mail you sendServe these pages and forward your e-mail to the operatorLegitimate interests, Art. 6(1)(f)(f) legitimate interestE-mail routing logs 30 to 31 days at the provider; e-mails in the operator’s inbox while the request is handled

How data is collected

  • From you, by automated means: what you type and upload in the member app, on the sign-up page and in the contact form.
  • Automatically, while you use the service: sign-in, security and usage logs recorded by the community engine.
  • From other people: members may mention you in a post or report a post of yours; a professional’s registration details are checked against public registers.

Collection is automated in every case (KVKK Tebliğ Art. 5(1)(i)). No decision about you is made by automated means (see below).

Sensitive data in your documents

GTJ does not ask for health, religion, ethnic origin, political opinion, biometric data or criminal records. Documents you choose to keep in your vault, such as a passport, a medical certificate or a criminal-record certificate, can contain such data, and so can documents about other people (referees, employers, family). GTJ treats vault contents as possibly containing special-category data. They are encrypted on your device, the operator holds no key and cannot read them, and encryption is used as a safeguard, never as a reason to say no personal data is processed. Whether storing encrypted special-category data counts as processing it under KVKK Art. 6 and GDPR Art. 9 is one of the questions put to the lawyer.

Please do not upload documents about other people, or unnecessary pages about your family or children, unless your preparation really needs them.

Who receives data

GTJ uses these service providers. They process data on the operator’s instructions; none of them can read the contents of your vault.

ProviderWhat forPersonal dataWhereTransfer safeguardAgreement status
Railway Corporation
548 Market St PMB 68956, San Francisco, California 94104, United States
Provider’s terms (checked 13 September 2026)
Hosting the community engine: the application servers, the database and the cache that hold accounts, community posts, moderation records, encrypted workspace and profile records, file metadata and server logsAccount data (e-mail address, username, name), community content, moderation and appeal records, professional applications and contact requests, IP addresses and usage logs, encrypted records the operator cannot readEU West region (Amsterdam, Netherlands). Railway's own volume backups are not used; database backups are kept in Cloudflare R2 storage in the EU jurisdictionEU–US Data Privacy Framework and its UK Extension (Railway listed as active), with the EU Standard Contractual Clauses and UK Addendum in Railway's DPA as fallback. KVKK standard contract: not signedRailway's data processing agreement has not been signed yet (it is completed through Railway's signature form)
Cloudflare, Inc.
101 Townsend St, San Francisco, CA 94107, United States
Provider’s terms (checked 13 September 2026)
Registration of the domain name, DNS, delivery of this website, storage of encrypted vault files, storage of the community engine's database backups and deletion records, and forwarding of e-mail sent to the contact addressIP addresses and request data of website visitors; encrypted vault files the operator cannot read; daily copies of the community engine's database (account data, community content, moderation and professional records, logs with IP addresses, and the encrypted records), and deletion records holding an account number and times; the sender, recipient, subject and content of e-mail sent to the contact addressEncrypted vault files, database backups and deletion records: EU jurisdiction storage. Website delivery, DNS and e-mail forwarding: Cloudflare's global networkEU–US Data Privacy Framework and its UK Extension (Cloudflare listed as active; recertification due 23 September 2026), with the EU Standard Contractual Clauses and UK Addendum in Cloudflare's DPA as fallback. KVKK standard contract: not signedCloudflare's data processing addendum (version 6.4) is part of its self-serve agreement; the date GTJ accepted it has not been recorded yet
Plus Five Five, Inc. (Resend)
2261 Market Street #5039, San Francisco, CA 94114, United States
Provider’s terms (checked 13 September 2026)
Sending account e-mails from the community engine: address confirmation, sign-in links, password resets, notifications and contact requests delivered to a professionalRecipient e-mail address and name, and the content of those e-mails (for a contact request to a professional: the name, e-mail address and message the member chose to share)Sending region EU (Ireland). Resend's regions page states that all account data, including e-mail metadata, logs and API records, is stored in the United States whatever the sending region, and its agreement states that its primary processing takes place in the United StatesEU Standard Contractual Clauses, UK Addendum and the EU–US Data Privacy Framework with its UK Extension, as named in Resend's DPA; Resend's framework listing not yet checked by GTJ. KVKK standard contract: not signedResend's data processing addendum takes effect when its terms are accepted; the GTJ sending domain is set up and the engine has sent through it since 13 September 2026, but the date GTJ accepted the terms has not been recorded
  • A professional you choose receives the name, e-mail address and message you decide to share, by e-mail.
  • Other members see what you post in the community. The community is not public and is not indexed by search engines.
  • Authorities receive data only when a binding legal order requires it; the operator checks each order and, unless the law forbids it, tells the person concerned. Encrypted vault contents could only ever be handed over in encrypted form.
  • Push notifications are not available yet. When they are and you turn them on for a phone, Apple (iPhone) or Google (Android) delivers them: they receive that phone’s notification token and the neutral text, never the content of a reminder, a post or a document. They will be listed above before that happens.
  • No data is sold, and none is used for advertising or to train artificial intelligence. No payment provider is used today.

Transfers outside Türkiye, the UK and the EU

The operator is in Türkiye and every service provider above is a company in the United States, so your data is transferred abroad. The servers GTJ chose are in the European Union where the provider allows it (Amsterdam for the engine, EU jurisdiction storage for vault files and database backups), but a provider can still access data from the United States.

  • UK GDPR and EU GDPR: Railway and Cloudflare are listed as active under the EU–US Data Privacy Framework and its UK Extension; Resend’s agreement names the Framework too, but GTJ has not yet checked its listing. Each provider’s agreement adds the EU Standard Contractual Clauses and the UK Addendum, which apply if the Framework does not.
  • KVKK: the Turkish Personal Data Protection Board has not declared any country adequate, so a transfer needs one of the safeguards in KVKK Art. 9, normally the Board’s standard contract notified within five business days. That standard contract has not been signed with any of the providers yet. The operator is asking them, and this is an open item that must be resolved before registration opens.

How long data is kept

Personal data is kept only as long as its purpose needs. The periods for each activity are in the table above. In short:

  • Your account, vault, workspace, profile and community records stay until you delete them or your account. Deleting the account starts at once.
  • Contact-form requests: 12 months from receipt.
  • Security logs and reports do not have a fixed period yet. This is a known gap; the periods will be set and published here before registration opens.
  • Database backups are taken once a day and the newest seven are kept, so a backup can still contain a deleted account for about a week; after any restore, deletions are applied again so a deleted account does not come back.
  • Reminders: at the latest 30 days after their time.
  • No billing records exist, because no payment is taken. If payments start, the periods the law sets for commercial records will be added here first.

Your rights

Under the UK GDPR and EU GDPR you can ask to:

  • see the personal data GTJ holds about you and get a copy (access);
  • correct data that is wrong or incomplete;
  • have your data erased;
  • restrict how it is used while a question is being settled;
  • receive the data you gave in a structured, machine-readable form (portability: the in-app export does this);
  • object to processing based on legitimate interests;
  • withdraw consent where consent is used (GTJ does not rely on consent today).

Under KVKK Art. 11 you have the right to:

  1. learn whether your personal data is processed;
  2. request information if it has been processed;
  3. learn the purpose of processing and whether it is used in line with that purpose;
  4. know the third parties in Türkiye or abroad to whom it is transferred;
  5. ask for correction if it is incomplete or inaccurate;
  6. ask for deletion or destruction under the conditions of KVKK Art. 7;
  7. ask that the third parties it was transferred to are told of a correction, deletion or destruction;
  8. object to a result against you that arises only from automated analysis;
  9. claim compensation if you suffer damage because of unlawful processing.

How to use your rights

  • In the app: My profile → Settings → Account and data → Download my data, or Delete my account.
  • Without signing in: the contact form, choosing “Privacy and data rights” or “Account deletion”.
  • By e-mail: hello@globaltalentjourney.com

Exercising your rights is free. GTJ answers within one month under the GDPR and within 30 days under KVKK Art. 13, and tells you if a complex request needs longer and why. GTJ may ask you to confirm that the account is yours, for example by replying from the account’s e-mail address; it does not ask for identity documents for this.

How account deletion works

Complaints

You can complain to GTJ first, through the contact form (type “Complaint” or “Privacy and data rights”) or by e-mail. GTJ acknowledges a complaint within 30 days and tells you the outcome. You can also complain to a supervisory authority at any time:

  • Türkiye: the Personal Data Protection Board (kvkk.gov.tr). Under KVKK Art. 14 you first apply to GTJ, then complain within 30 days of GTJ’s answer, or within 60 days of your application if there is no answer.
  • United Kingdom: the Information Commissioner’s Office (ico.org.uk).
  • European Union: the data protection authority of the country where you live or work (list of authorities).

Automated decisions

GTJ makes no decision about you by automated means and does not profile you. The preparation percentage in the workspace only counts the tasks you marked done; it is not an assessment of your case. Posts can be hidden automatically when several members report them; a moderator then reviews them and you can appeal.

Cookies and browser storage

This website sets no cookies and runs no analytics. If you choose Light or Dark, that choice is stored in your browser. The member app uses only the sign-in cookies it needs to keep you signed in.

Cookies and storage in detail

Minimum age

Accounts are for people aged 18 or over. GTJ does not ask for an identity document to check this. If you believe a person under 18 has an account, tell GTJ through the contact form and the account will be reviewed.

E-mails

GTJ sends no marketing e-mails. Account e-mails (address confirmation, sign-in, password, notifications you chose) are part of the service. If marketing messages are ever offered, they will need a separate, optional choice that is off by default.

Changes to this notice

Every change to this notice is dated at the top of the page. A change that affects what data is used or why is announced in the app and by e-mail before it takes effect, and a new purpose is described here before data is used for it. Continuing to use the service is never treated as agreeing to such a change.

Global Talent Journey

Global Talent Journey is an independent product. It is not a government service, a law firm or an endorsing body, and it does not decide or predict anyone’s eligibility.

Operated by Furkan Efe Genç, sole proprietorship (şahıs işletmesi), self-employed professional (serbest meslek erbabı), Türkiye.

This website sets no cookies and loads nothing from other websites.

Product

  • Home
  • How it works
  • Pathways
  • Membership
  • Resources
  • Operator and contact

Rules, privacy and your data

  • Privacy
  • Terms of use
  • Community rules
  • Refunds and cancellation
  • Verification methodology
  • Account deletion
  • Cookies and storage
  • Service providers
  • Accessibility